-
Notifications
You must be signed in to change notification settings - Fork 1
🌱 Bump the dependencies group across 1 directory with 11 updates #1002
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
🌱 Bump the dependencies group across 1 directory with 11 updates #1002
Conversation
Bumps the dependencies group with 10 updates in the /hack/tools directory: | Package | From | To | | --- | --- | --- | | [github.com/a8m/envsubst](https://github.com/a8m/envsubst) | `1.4.2` | `1.4.3` | | [github.com/itchyny/gojq](https://github.com/itchyny/gojq) | `0.12.17` | `0.12.18` | | [github.com/joelanford/go-apidiff](https://github.com/joelanford/go-apidiff) | `0.8.2` | `0.8.3` | | [github.com/mikefarah/yq/v4](https://github.com/mikefarah/yq) | `4.44.6` | `4.50.1` | | [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.31.4` | `0.31.14` | | [k8s.io/code-generator](https://github.com/kubernetes/code-generator) | `0.31.2` | `0.31.14` | | [sigs.k8s.io/controller-tools](https://github.com/kubernetes-sigs/controller-tools) | `0.16.5` | `0.20.0` | | [sigs.k8s.io/kind](https://github.com/kubernetes-sigs/kind) | `0.26.0` | `0.31.0` | | [sigs.k8s.io/kustomize/kustomize/v5](https://github.com/kubernetes-sigs/kustomize) | `5.5.0` | `5.8.0` | | [sigs.k8s.io/promo-tools/v4](https://github.com/kubernetes-sigs/promo-tools) | `4.0.5` | `4.1.0` | Updates `github.com/a8m/envsubst` from 1.4.2 to 1.4.3 - [Release notes](https://github.com/a8m/envsubst/releases) - [Commits](a8m/envsubst@v1.4.2...v1.4.3) Updates `github.com/itchyny/gojq` from 0.12.17 to 0.12.18 - [Release notes](https://github.com/itchyny/gojq/releases) - [Changelog](https://github.com/itchyny/gojq/blob/main/CHANGELOG.md) - [Commits](itchyny/gojq@v0.12.17...v0.12.18) Updates `github.com/joelanford/go-apidiff` from 0.8.2 to 0.8.3 - [Release notes](https://github.com/joelanford/go-apidiff/releases) - [Commits](joelanford/go-apidiff@v0.8.2...v0.8.3) Updates `github.com/mikefarah/yq/v4` from 4.44.6 to 4.50.1 - [Release notes](https://github.com/mikefarah/yq/releases) - [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt) - [Commits](mikefarah/yq@v4.44.6...v4.50.1) Updates `github.com/spf13/pflag` from 1.0.5 to 1.0.10 - [Release notes](https://github.com/spf13/pflag/releases) - [Commits](spf13/pflag@v1.0.5...v1.0.10) Updates `k8s.io/apimachinery` from 0.31.4 to 0.31.14 - [Commits](kubernetes/apimachinery@v0.31.4...v0.31.14) Updates `k8s.io/code-generator` from 0.31.2 to 0.31.14 - [Commits](kubernetes/code-generator@v0.31.2...v0.31.14) Updates `sigs.k8s.io/controller-tools` from 0.16.5 to 0.20.0 - [Release notes](https://github.com/kubernetes-sigs/controller-tools/releases) - [Changelog](https://github.com/kubernetes-sigs/controller-tools/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/controller-tools@v0.16.5...v0.20.0) Updates `sigs.k8s.io/kind` from 0.26.0 to 0.31.0 - [Release notes](https://github.com/kubernetes-sigs/kind/releases) - [Commits](kubernetes-sigs/kind@v0.26.0...v0.31.0) Updates `sigs.k8s.io/kustomize/kustomize/v5` from 5.5.0 to 5.8.0 - [Release notes](https://github.com/kubernetes-sigs/kustomize/releases) - [Commits](kubernetes-sigs/kustomize@kustomize/v5.5.0...kustomize/v5.8.0) Updates `sigs.k8s.io/promo-tools/v4` from 4.0.5 to 4.1.0 - [Release notes](https://github.com/kubernetes-sigs/promo-tools/releases) - [Changelog](https://github.com/kubernetes-sigs/promo-tools/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/promo-tools@v4.0.5...v4.1.0) --- updated-dependencies: - dependency-name: github.com/a8m/envsubst dependency-version: 1.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/itchyny/gojq dependency-version: 0.12.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/joelanford/go-apidiff dependency-version: 0.8.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/mikefarah/yq/v4 dependency-version: 4.50.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/spf13/pflag dependency-version: 1.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: k8s.io/apimachinery dependency-version: 0.31.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: k8s.io/code-generator dependency-version: 0.31.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: sigs.k8s.io/controller-tools dependency-version: 0.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: sigs.k8s.io/kind dependency-version: 0.31.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: sigs.k8s.io/kustomize/kustomize/v5 dependency-version: 5.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: sigs.k8s.io/promo-tools/v4 dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <[email protected]>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a spectrocloud member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- GO-2025-3754
- Module: github.com/cloudflare/circl
- Found in: v1.3.7
- Fixed in: v1.6.1
- Example Traces:
1. test/helpers/kubernetesversions/template.go:37:2: kubernetesversions.init calls framework.init, which eventually calls ecc.init
2. test/helpers/kubernetesversions/template.go:37:2: kubernetesversions.init calls framework.init, which eventually calls ed448.init
3. test/helpers/kubernetesversions/template.go:37:2: kubernetesversions.init calls framework.init, which eventually calls x25519.init
4. test/helpers/kubernetesversions/template.go:37:2: kubernetesversions.init calls framework.init, which eventually calls ed25519.init
5. test/helpers/kubernetesversions/template.go:37:2: kubernetesversions.init calls framework.init, which eventually calls ecc.init
- GO-2025-3553
- Module: github.com/golang-jwt/jwt/v4
- Found in: v4.5.1
- Fixed in: v4.5.2
- Example Traces:
1. pkg/rosa/client.go:51:70: rosa.NewOCMClient calls ocm.Build, which eventually calls authentication.Build
- GO-2025-3595
- Module: golang.org/x/net
- Found in: v0.33.0
- Fixed in: v0.38.0
- Example Traces:
1. pkg/rosa/externalauthproviders.go:52:35: rosa.UpdateExternalAuth calls v1.Send, which eventually calls bluemonday.sanitize
- GO-2025-4123
- Module: github.com/dvsekhvalnov/jose2go
- Found in: v1.6.0
- Fixed in: v1.7.0
- Example Traces:
1. pkg/rosa/client.go:51:70: rosa.NewOCMClient calls ocm.Build, which eventually calls keyring.Get
Please review these findings and fix the issues before merging.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- G401: Use of weak cryptographic primitive, Severity: MEDIUM
-
- File: /home/runner/work/bulwark/bulwark/target-repo/pkg/cloud/services/eks/iam/iam.go:499:13
-
- G505: Blocklisted import crypto/sha1: weak cryptographic primitive, Severity: MEDIUM
-
- File: /home/runner/work/bulwark/bulwark/target-repo/pkg/cloud/services/eks/iam/iam.go:22:2
-
Please review these findings and fix the issues before merging.
Bumps the dependencies group with 10 updates in the /hack/tools directory:
1.4.21.4.30.12.170.12.180.8.20.8.34.44.64.50.10.31.40.31.140.31.20.31.140.16.50.20.00.26.00.31.05.5.05.8.04.0.54.1.0Updates
github.com/a8m/envsubstfrom 1.4.2 to 1.4.3Release notes
Sourced from github.com/a8m/envsubst's releases.
Commits
2aa6422go: update to v1.24 (#66)c413ce2go: upgrade version above1.19(#57)124db18doc: fix table formatting (#51)594e4b4doc: fix typos (#52)Updates
github.com/itchyny/gojqfrom 0.12.17 to 0.12.18Release notes
Sourced from github.com/itchyny/gojq's releases.
Changelog
Sourced from github.com/itchyny/gojq's changelog.
Commits
fa534a1bump up version to 0.12.18d7e1531update CHANGELOG.md for v0.12.18672cc79update dependencies2263e18update actions/checkout to v65d8a53cadd more tests for empty strings and NO_COLOR97274d3make use of cmp package for comparisons3e31863merge identical cases for getting operator functionse4d456bavoid variable names that shadow built-in functions19a3975stop replacing capturing group syntax5bb6d33support binding expressions with binary operators (fix #283)Updates
github.com/joelanford/go-apidifffrom 0.8.2 to 0.8.3Release notes
Sourced from github.com/joelanford/go-apidiff's releases.
Commits
60c4206bump dependencies (#91)4a78e82build(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#71)f8f3eaabuild(deps): bump golang.org/x/sys from 0.26.0 to 0.28.0 (#74)bb5ff5abuild(deps): bump github.com/spf13/cobra from 1.8.0 to 1.8.1 (#67)537ad9cbuild(deps): bump golang.org/x/sys from 0.18.0 to 0.26.0 (#69)0b76013build(deps): bump golang.org/x/net from 0.20.0 to 0.23.0 (#61)2fa2592build(deps): bump github.com/go-git/go-git/v5 from 5.11.0 to 5.12.0 (#58)00f8d2ebuild(deps): bump golang.org/x/sys from 0.16.0 to 0.17.0 (#53)Updates
github.com/mikefarah/yq/v4from 4.44.6 to 4.50.1Release notes
Sourced from github.com/mikefarah/yq/v4's releases.
... (truncated)
Changelog
Sourced from github.com/mikefarah/yq/v4's changelog.
... (truncated)
Commits
065b200Bumping version745a7ffPreparing releasea305d70Bump golang.org/x/net from 0.47.0 to 0.48.00671ccdBump github.com/zclconf/go-cty from 1.16.3 to 1.17.04d8cd45Bump golang.org/x/text from 0.31.0 to 0.32.0d2d657eHCL improvementsf4fd8c5Better roundtriping of HCLe4bf8a1Simplifying HCL decoderfd40574Add build tag to hcl_test.go to skip tests when HCL is disabled51ddf8dUpdate pkg/yqlib/format.goUpdates
github.com/spf13/pflagfrom 1.0.5 to 1.0.10Release notes
Sourced from github.com/spf13/pflag's releases.
... (truncated)
Commits
0491e57Merge pull request #448 from thaJeztah/fix_go_version72abab1Merge pull request #447 from thaJeztah/fix_deprecation_comment7e4dfb1Test on Go 1.1218a9d17move Func, BoolFunc, tests as they require go1.21c5b9e98remove uses of errors.Is, which requires go1.1345a4873fix deprecation comment for (FlagSet.)ParseErrorsWhitelist1043857Merge pull request #446 from spf13/fix-backwards-compat7412009fix: Restore ParseErrorsWhitelist name for nowb9c16faMerge pull request #444 from spf13/reset-args-even-if-empty40abc49Merge pull request #443 from spf13/silence-errhelpUpdates
k8s.io/apimachineryfrom 0.31.4 to 0.31.14Commits
Updates
k8s.io/code-generatorfrom 0.31.2 to 0.31.14Commits
d16750bUpdate dependencies to v0.31.14 tag16efc01Merge pull request #129741bobsongplus/automated-cherry-pick-of-#1296290ebe3efFix: touch /dev/null permission denied on macosUpdates
sigs.k8s.io/controller-toolsfrom 0.16.5 to 0.20.0Release notes
Sourced from sigs.k8s.io/controller-tools's releases.
... (truncated)
Commits
60c448eMerge pull request #1319 from sbueringer/pr-promo-envtest-1.35b7d3668Promotion of envtest release for Kubernetes v1.35.0b5f217fMerge pull request #1317 from dongjiang1989/envtest-v1.35.0-rc.13cbb76eMerge pull request #1318 from sbueringer/pr-bump-1.3552f5e83add envtest version10c819cAdjust to changes in validation error messages9f6a8baAdjust generated ApplyConfigurations to v0.351c6de27Bump to k8s.io/* v0.35.0ed0bc4fMerge pull request #1316 from kubernetes-sigs/dependabot/github_actions/all-g...17ef504Merge pull request #1315 from kubernetes-sigs/dependabot/go_modules/all-go-mo...Updates
sigs.k8s.io/kindfrom 0.26.0 to 0.31.0Release notes
Sourced from sigs.k8s.io/kind's releases.
... (truncated)
Commits
a323333version v0.31.032124c6Merge pull request #4077 from BenTheElder/135b088420drop almalinux 8b1b15edbump node image to 1.35.0c17c183Merge pull request #4069 from BenTheElder/latest-images36ee7a6update node image to 1.34.3 with runc 1.2.x1f8526cMerge pull request #4073 from aoxn/typoa47cf1elicense typo57ed4dause base image with runc 1.2.x5e1c871downgrade runc to 1.2.9 due to broken Kubernetes 1.33 testsUpdates
sigs.k8s.io/kustomize/kustomize/v5from 5.5.0 to 5.8.0Release notes
Sourced from sigs.k8s.io/kustomize/kustomize/v5's releases.
... (truncated)
Commits
0054b5eMerge pull request #6009 from koba1t/pinToApi16391f3Update api to v0.21.06661fefMerge pull request #6008 from koba1t/pinToCmdConfig3c59244Update cmd/config to v0.21.0ade7bd6Merge pull request #6007 from koba1t/pinToKyaml0fc7554Update kyaml to v0.21.08761791fix(kyaml/yaml): minor nil safety fix for RNode.Content etc (#5985)153a372Merge pull request #5679 from koba1t/implements_to_replacements_value_in_the_...de01137Merge pull request #5991 from isarns/fix/labels-without-selector-duplicate-ke...4d37afestyle(cmd-edit-add-label): lint multiple labels without selector testUpdates
sigs.k8s.io/promo-tools/v4from 4.0.5 to 4.1.0Release notes
Sourced from sigs.k8s.io/promo-tools/v4's releases.
Commits
2cce8c6Merge pull request #1633 from justaugustus/releasee6eda12Release commit: [email protected]77bb51dgo.mod: Update go directive to1.24.9d64da5aMerge pull request #1632 from kubernetes-sigs/dependabot/go_modules/gomod-18c...a7bb7c2build(deps): bump sigs.k8s.io/release-sdk in the gomod groupb18e879Merge pull request #1631 from kubernetes-sigs/dependabot/go_modules/golang.or...ad0cd3dbuild(deps): bump golang.org/x/time from 0.13.0 to 0.14.01fb5447Merge pull request #1630 from kubernetes-sigs/dependabot/go_modules/golang.or...825b158Merge pull request #1629 from kubernetes-sigs/dependabot/go_modules/gomod-6f1...b518b82build(deps): bump golang.org/x/oauth2 from 0.31.0 to 0.32.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill...Description has been truncated