fix(deps): update all dependencies - #1791
Open
red-hat-konflux[bot] wants to merge 1 commit into
Open
Conversation
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
24 times, most recently
from
July 2, 2026 05:22
911ac8f to
f8b995e
Compare
Contributor
Author
ℹ️ Artifact update noticeFile name: go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
5 times, most recently
from
July 3, 2026 09:16
3294628 to
068352a
Compare
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
23 times, most recently
from
July 10, 2026 13:15
34fed82 to
3442808
Compare
Contributor
Author
|
red-hat-konflux
Bot
force-pushed
the
konflux/mintmaker/master/all
branch
5 times, most recently
from
July 11, 2026 10:36
278a903 to
78209e4
Compare
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v7.0.0→v7.0.1v6.2.0→v6.2.3v0.25.2→v0.25.3v0.20.0→v0.23.1v5.0.3→v7.0.0v1.20.2→v1.21.1v1.1.0→v2.3.0v1.6.4→v1.6.5v3.19.0→v3.20.0v1.6.2→v4.9.6v2.2007.4→v4.9.6v0.2.0→v2.4.2v3.0.5→v4.1.4v1.4.3→v1.4.4v0.23.1→v1.0.0v0.21.6→v1.0.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v0.26.1→v0.28.0v4.5.2→v5.3.1v0.28.1→v0.31.07023385→ef3492dv0.3.16→v0.3.20v2.22.0→v2.23.0v2.29.0→v2.30.0v1.18.7→v1.19.2v2.3.0→v2.4.0v0.0.22→v0.0.24v7.2.0→v7.2.1v7.3.0v2.32.0→v2.32.1v1.42.0→v1.42.1v0.12.0→v0.15.0v1.23.2→v1.24.1v0.20.1→v0.21.1v0.60.0→v0.61.0v1.9.4→v1.10.0v1.10.3→v1.11.0v0.25.0→v0.26.0v0.2.1→v0.2.3v1.11.1→v1.12.0v1.22.17→v3.10.1v3.11.0v0.69.0→v0.70.0v0.69.0→v0.70.0v0.69.0→v0.70.0v1.44.0→v1.45.0v0.20.0→v0.21.0v0.20.0→v0.21.0v1.44.0→v1.45.0v1.44.0→v1.45.0v1.44.0→v1.45.0v1.44.0→v1.45.0v1.44.0→v1.45.0v0.66.0→v0.67.0v0.20.0→v0.21.0v1.44.0→v1.45.0v1.44.0→v1.45.0v0.20.0→v0.21.0v1.44.0→v1.45.0v1.44.0→v1.45.0v0.20.0→v0.21.0v1.44.0→v1.45.0v1.44.0→v1.45.0v1.10.0→v1.11.0v0.83.0→v0.88.0v0.89.0v2.4.4→v3.0.5v3.0.4→v3.0.5v0.53.0→v0.55.0c48552f→c1d0aacv0.37.0→v0.40.0v0.56.0→v0.58.0v0.21.0→v0.22.0v0.46.0→v0.47.0v0.44.0→v0.45.0v0.39.0→v0.41.0v0.47.0→v0.49.0v9.2.1→v9.3.0v2.5.0→v3.0.1v0.286.0→v0.293.0v1.82.1→v1.83.0v1.36.11→v1.36.12v4.13.0→v5.9.11v2.4.0→v3.0.1v0.35.6→v0.36.3v2.0.0-20250922181213-ec3ebc5fd46b→v2.0.0-20260408192533-25e2208e0dc30b43c5e→d427ff9a95e086→cf1189d39ebae2→521cb339.8-1785777232→9.8-17869875219.8-1785339117→9.8-1786987521v1.13.2→v1.14.0v1.5.1→v1.6.1v6.4.0→v6.4.2Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
aws-actions/configure-aws-credentials (aws-actions/configure-aws-credentials)
v6.2.3Compare Source
Bug Fixes
v6.2.2Compare Source
Miscellaneous Chores
v6.2.2Compare Source
Miscellaneous Chores
v6.2.1Compare Source
Bug Fixes
cel-expr/cel-spec (cel.dev/expr)
v0.25.3Compare Source
What's Changed
New Contributors
Full Changelog: cel-expr/cel-spec@v0.25.2...v0.25.3
googleapis/google-cloud-go (cloud.google.com/go/auth)
v0.23.0Compare Source
v0.22.0Compare Source
bigtable:
bigquery:
datastore:
dlp:
which is now out of beta.
firestore:
iam:
profiler:
pubsub:
redis:
spanner:
speech:
storage:
v0.21.0Compare Source
bigquery:
firestore:
whose Exists method returns false. DocumentRef.Get and Transaction.Get
return the non-nil DocumentSnapshot in addition to a NotFound error.
DocumentRef.GetAll and Transaction.GetAll return a non-nil
DocumentSnapshot instead of nil.
DocumentIterator.
notification of updates. See https://cloud.google.com/firestore/docs/query-data/listen.
spanner:
CommitTimestamp, which supports inserting the commit timestamp of atransaction into a column.
cenkalti/backoff (github.com/cenkalti/backoff/v5)
v7.0.0Compare Source
v6.0.1Compare Source
v6.0.0Compare Source
cert-manager/cert-manager (github.com/cert-manager/cert-manager)
v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)v1.21.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values — review them carefully before upgrading.
Known Issues
renewal.policy: Disabled: the new Certificate renewal policies feature (#8258) causes a nil pointer dereference panic in the trigger controller whenever a Certificate'sspec.renewal.policyis set toDisabled—pki.RenewalTime()returns(nil, nil)for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. Workaround: do not setrenewal.policy: Disabledon any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See #9031 for details.filteredEventHandlertype assertion failures ("OnAdd missing Object","OnUpdate missing ObjectOld","OnDelete missing Object") for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. This is cosmetic only — the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See #8994 for details.Ready: False, Reason: InvalidSolverand never self-correct: new eager validation of ACME solver Secrets (#8255) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly reportReady: False, but creating the missing Secret afterwards does not trigger re-reconciliation — the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. Workaround: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See #9036 for details and a fix proposal.Major Themes
Default
tokenrequestRBAC removed from Helm chartThe Helm chart no longer creates a default
RoleandRoleBindinggranting the cert-manager controller permission to create tokens for its own ServiceAccount (serviceaccounts/token: create). No documented workflow requires this RBAC — the Route53 docs section that motivated it was removed in 2024.If you use
serviceAccountRef.namepointing at the controller ServiceAccount, you must now either create your ownRole/RoleBindinggrantingserviceaccounts/token: create, or migrate to a dedicated ServiceAccount (recommended — see the Vault or Route53 documentation).Restrict Challenge and Order RBAC in
cert-manager-editClusterRoleThe
cert-manager-editaggregate ClusterRole no longer grantscreateforchallenges.acme.cert-manager.ioorcreate,patch,updatefororders.acme.cert-manager.io(GHSA-8rvj-mm4h-c258). These resources are internal to cert-manager's ACME workflow. Challengepatchandupdateare retained because users may need them to remove stuck finalizers.This change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant tho
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.