build(deps): bump the go-dependencies group in /controller with 16 updates#609
build(deps): bump the go-dependencies group in /controller with 16 updates#609dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Dependabot PR Review Summary — K8s Version Bumpcc @mangelajo @bzlotnik @kirkbrauer — This PR bumps Kubernetes dependencies, please review. OverviewThis PR bumps 16 Go dependencies in Why is this bump requested?
K8s 1.35 Breaking API Changes(Same as noted in PR #610)
CI Failures Analysis1. The CI's 2. The test target builds both controller AND operator. The operator's 3. 4.
|
| Subproject | Current k8s | This PR | Needs Update? |
|---|---|---|---|
controller/go.mod |
0.33.0 | 0.35.4 | ✅ (this PR) |
controller/deploy/operator/go.mod |
0.34.1 | unchanged | |
e2e/test/go.mod |
(no k8s deps) | unchanged | No |
Also: PR #610 bumps operator to k8s 0.35.2
PR #610 bumps the operator's k8s deps to 0.35.2. These two PRs target different minor versions (0.35.4 vs 0.35.2) and should be coordinated into a single PR with aligned versions across both go.mod files.
Recommendation
- Combine with PR build(deps): bump the go-operator-dependencies group across 1 directory with 9 updates #610 — or at minimum, add a commit here updating
controller/deploy/operator/go.modto match (k8s 0.35.4, cert-manager 1.20.2, controller-runtime 0.23.3). - Update CI toolchain to Go 1.25 — golangci-lint, setup-go action, etc.
- Test for
gogo/protobufbreakage — verify controller code doesn't rely on gogo type registry. - Consider the scope: this is a 2-minor-version jump (1.33 → 1.35). If there's no CVE urgency, a staged approach (1.33 → 1.34 first, then 1.34 → 1.35) might reduce risk.
Bumps the go-dependencies group in /controller with 16 updates: | Package | From | To | | --- | --- | --- | | [github.com/gin-gonic/gin](https://github.com/gin-gonic/gin) | `1.10.0` | `1.12.0` | | [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) | `4.1.3` | `4.1.4` | | [github.com/grpc-ecosystem/go-grpc-middleware/v2](https://github.com/grpc-ecosystem/go-grpc-middleware) | `2.2.0` | `2.3.3` | | [github.com/grpc-ecosystem/grpc-gateway/v2](https://github.com/grpc-ecosystem/grpc-gateway) | `2.24.0` | `2.29.0` | | [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) | `2.22.2` | `2.28.1` | | [github.com/onsi/gomega](https://github.com/onsi/gomega) | `1.36.2` | `1.39.0` | | [github.com/zitadel/oidc/v3](https://github.com/zitadel/oidc) | `3.34.1` | `3.47.4` | | [golang.org/x/sync](https://github.com/golang/sync) | `0.19.0` | `0.20.0` | | [google.golang.org/genproto/googleapis/api](https://github.com/googleapis/go-genproto) | `0.0.0-20260120221211-b8f7ae30c516` | `0.0.0-20260414002931-afd174a4e478` | | [k8s.io/api](https://github.com/kubernetes/api) | `0.33.0` | `0.35.4` | | [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.33.0` | `0.35.4` | | [k8s.io/apiserver](https://github.com/kubernetes/apiserver) | `0.33.0` | `0.35.4` | | [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.33.0` | `0.35.4` | | [k8s.io/utils](https://github.com/kubernetes/utils) | `0.0.0-20241104100929-3ea5e8cea738` | `0.0.0-20251002143259-bc988d571ff4` | | [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.21.0` | `0.23.3` | | [sigs.k8s.io/yaml](https://github.com/kubernetes-sigs/yaml) | `1.4.0` | `1.6.0` | Updates `github.com/gin-gonic/gin` from 1.10.0 to 1.12.0 - [Release notes](https://github.com/gin-gonic/gin/releases) - [Changelog](https://github.com/gin-gonic/gin/blob/master/CHANGELOG.md) - [Commits](gin-gonic/gin@v1.10.0...v1.12.0) Updates `github.com/go-jose/go-jose/v4` from 4.1.3 to 4.1.4 - [Release notes](https://github.com/go-jose/go-jose/releases) - [Commits](go-jose/go-jose@v4.1.3...v4.1.4) Updates `github.com/grpc-ecosystem/go-grpc-middleware/v2` from 2.2.0 to 2.3.3 - [Release notes](https://github.com/grpc-ecosystem/go-grpc-middleware/releases) - [Commits](grpc-ecosystem/go-grpc-middleware@v2.2.0...v2.3.3) Updates `github.com/grpc-ecosystem/grpc-gateway/v2` from 2.24.0 to 2.29.0 - [Release notes](https://github.com/grpc-ecosystem/grpc-gateway/releases) - [Commits](grpc-ecosystem/grpc-gateway@v2.24.0...v2.29.0) Updates `github.com/onsi/ginkgo/v2` from 2.22.2 to 2.28.1 - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.22.2...v2.28.1) Updates `github.com/onsi/gomega` from 1.36.2 to 1.39.0 - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.36.2...v1.39.0) Updates `github.com/zitadel/oidc/v3` from 3.34.1 to 3.47.4 - [Release notes](https://github.com/zitadel/oidc/releases) - [Commits](zitadel/oidc@v3.34.1...v3.47.4) Updates `golang.org/x/sync` from 0.19.0 to 0.20.0 - [Commits](golang/sync@v0.19.0...v0.20.0) Updates `google.golang.org/genproto/googleapis/api` from 0.0.0-20260120221211-b8f7ae30c516 to 0.0.0-20260414002931-afd174a4e478 - [Commits](https://github.com/googleapis/go-genproto/commits) Updates `k8s.io/api` from 0.33.0 to 0.35.4 - [Commits](kubernetes/api@v0.33.0...v0.35.4) Updates `k8s.io/apimachinery` from 0.33.0 to 0.35.4 - [Commits](kubernetes/apimachinery@v0.33.0...v0.35.4) Updates `k8s.io/apiserver` from 0.33.0 to 0.35.4 - [Commits](kubernetes/apiserver@v0.33.0...v0.35.4) Updates `k8s.io/client-go` from 0.33.0 to 0.35.4 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.33.0...v0.35.4) Updates `k8s.io/utils` from 0.0.0-20241104100929-3ea5e8cea738 to 0.0.0-20251002143259-bc988d571ff4 - [Commits](https://github.com/kubernetes/utils/commits) Updates `sigs.k8s.io/controller-runtime` from 0.21.0 to 0.23.3 - [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases) - [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/controller-runtime@v0.21.0...v0.23.3) Updates `sigs.k8s.io/yaml` from 1.4.0 to 1.6.0 - [Release notes](https://github.com/kubernetes-sigs/yaml/releases) - [Changelog](https://github.com/kubernetes-sigs/yaml/blob/master/RELEASE.md) - [Commits](kubernetes-sigs/yaml@v1.4.0...v1.6.0) --- updated-dependencies: - dependency-name: github.com/gin-gonic/gin dependency-version: 1.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/go-jose/go-jose/v4 dependency-version: 4.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: github.com/grpc-ecosystem/go-grpc-middleware/v2 dependency-version: 2.3.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/grpc-ecosystem/grpc-gateway/v2 dependency-version: 2.29.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.28.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/onsi/gomega dependency-version: 1.39.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: github.com/zitadel/oidc/v3 dependency-version: 3.47.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/sync dependency-version: 0.20.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: google.golang.org/genproto/googleapis/api dependency-version: 0.0.0-20260414002931-afd174a4e478 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: k8s.io/api dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: k8s.io/apimachinery dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: k8s.io/apiserver dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: k8s.io/client-go dependency-version: 0.35.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: k8s.io/utils dependency-version: 0.0.0-20251002143259-bc988d571ff4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies - dependency-name: sigs.k8s.io/controller-runtime dependency-version: 0.23.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: sigs.k8s.io/yaml dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
e946ef6 to
19b0339
Compare
Bumps the go-dependencies group in /controller with 16 updates:
1.10.01.12.04.1.34.1.42.2.02.3.32.24.02.29.02.22.22.28.11.36.21.39.03.34.13.47.40.19.00.20.00.0.0-20260120221211-b8f7ae30c5160.0.0-20260414002931-afd174a4e4780.33.00.35.40.33.00.35.40.33.00.35.40.33.00.35.40.0.0-20241104100929-3ea5e8cea7380.0.0-20251002143259-bc988d571ff40.21.00.23.31.4.01.6.0Updates
github.com/gin-gonic/ginfrom 1.10.0 to 1.12.0Release notes
Sourced from github.com/gin-gonic/gin's releases.
... (truncated)
Changelog
Sourced from github.com/gin-gonic/gin's changelog.
... (truncated)
Commits
73726dcdocs: update documentation to reflect Go version changes (#4552)e292e5cdocs: document and finalize Gin v1.12.0 release (#4551)ae3f524ci: update Go version support to 1.25+ across CI and docs (#4550)38534e2chore(deps): bump golang.org/x/net from 0.50.0 to 0.51.0 (#4548)472d086fix(tree): panic in findCaseInsensitivePathRec with RedirectFixedPath (#4535)fb25834test(context): use http.StatusContinue constant instead of magic number 100 (...6f1d5fetest(render): add comprehensive error handling tests (#4541)5c00df8fix(render): write content length in Data.Render (#4206)db30908chore(logger): allow skipping query string output (#4547)ba093d1chore(binding): upgrade bson dependency to mongo-driver v2 (#4549)Updates
github.com/go-jose/go-jose/v4from 4.1.3 to 4.1.4Release notes
Sourced from github.com/go-jose/go-jose/v4's releases.
Commits
0e59876Merge commit from forkddffdbcBump actions/checkout from 5 to 6 (#213)Updates
github.com/grpc-ecosystem/go-grpc-middleware/v2from 2.2.0 to 2.3.3Release notes
Sourced from github.com/grpc-ecosystem/go-grpc-middleware/v2's releases.
... (truncated)
Commits
390bcefavoid unnecessary logging field creation when payload logging is disabled (#809)748e2b2fix metric label initialize (#810)af451d0fix(ci): tidy module before linting (#808)2dc9821feat: add ContextLabels to ClientMetrics (#798)2338d5afix(#794): Wrapping codes.OK should not cause panic (#795)6ec6dd3chore: use actions/setup-go native cache (#787)f7911ccchore: enable hugeParam rule from go-critic (#786)e2d5773build(deps): bump google.golang.org/grpc from 1.67.1 to 1.74.2 (#785)d75e7d9chore: enable usetesting linter (#784)c8a612bchore: enable promlinter linter (#771)Updates
github.com/grpc-ecosystem/grpc-gateway/v2from 2.24.0 to 2.29.0Release notes
Sourced from github.com/grpc-ecosystem/grpc-gateway/v2's releases.
... (truncated)
Commits
ba9b55cchore(deps): update dependency rules_shell to v0.8.0 (#6626)284a82echore(deps): update googleapis digest to bcfcbda (#6625)f74bc7fchore(deps): update google/oss-fuzz digest to d58fd64 (#6624)efb665dAdd edition 2024 support (#6622)c58da15chore(deps): update google/oss-fuzz digest to 32b8df7 (#6621)42997a1Deprecate fields and methods if file is deprecated (#6613)6f4af8bchore(deps): update googleapis digest to bf85cad (#6620)68fde5fchore(deps): update google/oss-fuzz digest to 7b814a1 (#6619)6da2a46chore(deps): update googleapis digest to 898f25c (#6617)c9c7ad4chore(deps): update googleapis digest to fc96870 (#6616)Updates
github.com/onsi/ginkgo/v2from 2.22.2 to 2.28.1Release notes
Sourced from github.com/onsi/ginkgo/v2's releases.
... (truncated)
Changelog
Sourced from github.com/onsi/ginkgo/v2's changelog.
... (truncated)
Commits
5d1d628v2.28.1676f985update test mu language8032100appease go vet41ca807bump dependencies2b2305bv2.28.071d2d89feat: support component semantic version filtering8cbbcb4Fix doclink for ginkgo runa928307v2.27.50d0e96ddon't make a new formatter for each GinkgoT(); that's just silly and uses pre...867ce95v2.27.4Updates
github.com/onsi/gomegafrom 1.36.2 to 1.39.0Release notes
Sourced from github.com/onsi/gomega's releases.
... (truncated)
Changelog
Sourced from github.com/onsi/gomega's changelog.
... (truncated)
Commits
49561adv1.39.08f7f425document MatchErrorStrictlybae643dadd matcher relecting errors.Is behaviora3ca2cav1.38.34dada36fix failing have http testsd40c691make string formatitng more consistent for users who use format.Object directly2a37b46doc: fix typosee26170docs: fix HaveValue examplecc85c05Bump actions/setup-go from 5 to 6 (#866)8905788Bump github.com/onsi/ginkgo/v2 from 2.25.1 to 2.25.3 (#865)Updates
github.com/zitadel/oidc/v3from 3.34.1 to 3.47.4Release notes
Sourced from github.com/zitadel/oidc/v3's releases.
... (truncated)
Commits
178e018fix: URL-encode client credentials in Basic Auth per RFC 6749 §2.3.1 (#873)49664bffix: propagate signature verification errors correctly (#872)5f70efffix: tolerate string amr claims from external providers (#855)97b71d3chore(deps): bump golang.org/x/text from 0.35.0 to 0.36.0 (#869)d118dd7fix: oidc server error to http status mapping (#865)2534f81docs: update semantic title requirements (#863)d016375example: set device cookie httpOnly (#868)b4cf422Merge commit from fork0bf0adechore: package upgrades (#866)4fae59bfeat: Allow for reuse of cookie creation + decouple creation from http writer...Updates
golang.org/x/syncfrom 0.19.0 to 0.20.0Commits
ec11c4aerrgroup: fix a typo in the documentation1a58307all: modernize interface{} -> any3172ca5all: upgrade go directive to at least 1.25.0 [generated]Updates
google.golang.org/genproto/googleapis/apifrom 0.0.0-20260120221211-b8f7ae30c516 to 0.0.0-20260414002931-afd174a4e478Commits
Updates
k8s.io/apifrom 0.33.0 to 0.35.4Commits
e8f0e9fUpdate dependencies to v0.35.4 tag0b2a75eMerge pull request #138356 from dims/update-moby-spdystream-v0.5.1-1.35e1ef9bcUpdate github.com/moby/spdystream from v0.5.0 to v0.5.1bbcbaa8Merge remote-tracking branch 'origin/master' into release-1.355bced61Bump golang.org/x/crypto to v...Description has been truncated