gomod(deps): bump the kubernetes-e2e group in /tests/e2e with 5 updates#330
gomod(deps): bump the kubernetes-e2e group in /tests/e2e with 5 updates#330dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the kubernetes-e2e group in /tests/e2e with 5 updates: | Package | From | To | | --- | --- | --- | | [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.29.8` | `0.35.2` | | [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.29.8` | `0.35.2` | | [k8s.io/kubernetes](https://github.com/kubernetes/kubernetes) | `1.29.14` | `1.35.2` | | [k8s.io/pod-security-admission](https://github.com/kubernetes/pod-security-admission) | `0.29.8` | `0.35.2` | | [k8s.io/utils](https://github.com/kubernetes/utils) | `0.0.0-20240711033017-18e509b52bc8` | `0.0.0-20251002143259-bc988d571ff4` | Updates `k8s.io/apimachinery` from 0.29.8 to 0.35.2 - [Commits](kubernetes/apimachinery@v0.29.8...v0.35.2) Updates `k8s.io/client-go` from 0.29.8 to 0.35.2 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.29.8...v0.35.2) Updates `k8s.io/kubernetes` from 1.29.14 to 1.35.2 - [Release notes](https://github.com/kubernetes/kubernetes/releases) - [Commits](kubernetes/kubernetes@v1.29.14...v1.35.2) Updates `k8s.io/pod-security-admission` from 0.29.8 to 0.35.2 - [Commits](kubernetes/pod-security-admission@v0.29.8...v0.35.2) Updates `k8s.io/utils` from 0.0.0-20240711033017-18e509b52bc8 to 0.0.0-20251002143259-bc988d571ff4 - [Commits](https://github.com/kubernetes/utils/commits) --- updated-dependencies: - dependency-name: k8s.io/apimachinery dependency-version: 0.35.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: kubernetes-e2e - dependency-name: k8s.io/client-go dependency-version: 0.35.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: kubernetes-e2e - dependency-name: k8s.io/kubernetes dependency-version: 1.35.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: kubernetes-e2e - dependency-name: k8s.io/pod-security-admission dependency-version: 0.35.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: kubernetes-e2e - dependency-name: k8s.io/utils dependency-version: 0.0.0-20251002143259-bc988d571ff4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: kubernetes-e2e ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Bugbot Free Tier Details
Your team is on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle for each member of your team.
To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.
Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
| k8s.io/kube-openapi v0.0.0-20250910181357-589584f1c912 // indirect | ||
| k8s.io/kubectl v0.29.8 // indirect | ||
| k8s.io/kubelet v0.29.8 // indirect | ||
| k8s.io/kubelet v0.35.2 // indirect |
There was a problem hiding this comment.
Kubernetes indirect dependencies left at incompatible v0.29.8
High Severity
Six k8s.io/* indirect dependencies (apiextensions-apiserver, cloud-provider, controller-manager, csi-translation-lib, kubectl, mount-utils) remain pinned at v0.29.8 while direct dependencies and other indirect ones were bumped to v0.35.2. In the Kubernetes ecosystem, all k8s.io/* packages from a release must use matching versions. These v0.29.8 packages were compiled against v0.29.8 of k8s.io/apiserver, k8s.io/api, etc., but Go's MVS will resolve those to v0.35.2, likely causing compilation failures or type incompatibilities due to API changes across 6 minor versions.


Bumps the kubernetes-e2e group in /tests/e2e with 5 updates:
0.29.80.35.20.29.80.35.21.29.141.35.20.29.80.35.20.0.0-20240711033017-18e509b52bc80.0.0-20251002143259-bc988d571ff4Updates
k8s.io/apimachineryfrom 0.29.8 to 0.35.2Commits
72d71eaMerge remote-tracking branch 'origin/master' into release-1.35e2a2dbcBump golang.org/x/crypto to v0.45.02e9c228Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fixf274aacvendor: update vendor and license metadata after replacing BeTrue usage in cs...9445443Resolve lint restriction on BeTrue by introducing Succeed() with contextual e...52154f7Update vendored dependencies5a348c5KEP-5471: Extend tolerations operators (#134665)6f89492Merge pull request #133648 from richabanker/merged-discoveryc77dde2util/sort: Add MergePreservingRelativeOrder for topological sorting729c13dMerge pull request #134624 from yt2985/podcertificates-betaUpdates
k8s.io/client-gofrom 0.29.8 to 0.35.2Commits
a21b329Update dependencies to v0.35.2 tag2d83546Merge remote-tracking branch 'origin/master' into release-1.3556b4af2Merge pull request #135591 from p0lyn0mial/upstream-watchlist-reflector-log-f...891f94cMerge remote-tracking branch 'origin/master' into release-1.3565ffe04Merge pull request #135580 from serathius/client-go-transformer2fe4ac2downgrade reflector watchlist fallback log to V(4)97256a6Bump golang.org/x/crypto to v0.45.046360b5Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix171ef8cUse transformer in consistency checker3878a64vendor: update vendor and license metadata after replacing BeTrue usage in cs...Updates
k8s.io/kubernetesfrom 1.29.14 to 1.35.2Release notes
Sourced from k8s.io/kubernetes's releases.
... (truncated)
Commits
fdc9d74Release commit for Kubernetes v1.35.255c0a83Merge pull request #136985 from cpanato/update-go-rel13569d9b9bBump images and versions to go 1.25.7 and distroless iptablesde51841Update CHANGELOG/CHANGELOG-1.35.md for v1.35.18fea90bRelease commit for Kubernetes v1.35.1a83897dMerge pull request #136491AutuSnow/automated-cherry-pick-of-#136325b7392aaMerge pull request #136463 from rogowski-piotr/automated-cherry-pick-of-#1359...3824a91Merge pull request #136280 from seekskyworld/automated-cherry-pick-of-#135918...64610fdMerge pull request #136348dlipovetsky/automated-cherry-pick-of-#136014e33a0a8Merge pull request #136373 from princepereira/automated-cherry-pick-of-#13624...Updates
k8s.io/pod-security-admissionfrom 0.29.8 to 0.35.2Commits
50c5bbdUpdate dependencies to v0.35.2 tag5fa7aafMerge remote-tracking branch 'origin/master' into release-1.354aaaf07Bump golang.org/x/crypto to v0.45.0c673328vendor: update vendor and license metadata after replacing BeTrue usage in cs...73bdfccResolve lint restriction on BeTrue by introducing Succeed() with contextual e...4d82a4eUpdate vendored dependencies139af0eMerge pull request #132157 from haircommander/drop-userns-psa30dd564Allow PSA controller tests to handle failure cases as errorsc405b04Merge pull request #134881 from pohly/e2e-slow-priorityd9fe59cdependencies: ginkgo v2.27.2, gomega v1.38.2Updates
k8s.io/utilsfrom 0.0.0-20240711033017-18e509b52bc8 to 0.0.0-20251002143259-bc988d571ff4Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsNote
Medium Risk
Large Kubernetes dependency jump for the e2e test module (v1.29 -> v1.35) may change API behavior and test harness expectations, potentially breaking CI even though production code is untouched.
Overview
Updates the
tests/e2eGo module to target newer Kubernetes libraries, bumpingk8s.io/*dependencies to the0.35.2/v1.35.2release line and refreshing related e2e/test deps (includingginkgo/gomega).Regenerates
go.sumto reflect the new dependency graph, pulling in a broad set of updated/transitive modules (e.g.,etcd,opentelemetry,grpc, and container/runtime libs).Written by Cursor Bugbot for commit ff0c68f. This will update automatically on new commits. Configure here.