🌱 Bump the dependencies group across 1 directory with 33 updates#1003
🌱 Bump the dependencies group across 1 directory with 33 updates#1003dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the dependencies group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [github.com/aws/amazon-vpc-cni-k8s](https://github.com/aws/amazon-vpc-cni-k8s) | `1.15.5` | `1.21.1` | | [github.com/aws/aws-lambda-go](https://github.com/aws/aws-lambda-go) | `1.41.0` | `1.52.0` | | [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go) | `1.55.5` | `1.55.8` | | [github.com/coreos/ignition/v2](https://github.com/coreos/ignition) | `2.16.2` | `2.25.1` | | [github.com/gofrs/flock](https://github.com/gofrs/flock) | `0.8.1` | `0.13.0` | | [github.com/openshift/rosa](https://github.com/openshift/rosa) | `1.2.48-rc1` | `1.2.48` | | [github.com/sergi/go-diff](https://github.com/sergi/go-diff) | `1.3.1` | `1.4.0` | | [github.com/sirupsen/logrus](https://github.com/sirupsen/logrus) | `1.9.3` | `1.9.4` | | [github.com/zgalor/weberr](https://github.com/zgalor/weberr) | `0.8.2` | `0.9.0` | | [sigs.k8s.io/aws-iam-authenticator](https://github.com/kubernetes-sigs/aws-iam-authenticator) | `0.6.13` | `0.7.10` | | [sigs.k8s.io/cluster-api](https://github.com/kubernetes-sigs/cluster-api) | `1.9.4` | `1.9.11` | | [sigs.k8s.io/cluster-api/test](https://github.com/kubernetes-sigs/cluster-api) | `1.9.4` | `1.9.11` | Updates `github.com/aws/amazon-vpc-cni-k8s` from 1.15.5 to 1.21.1 - [Release notes](https://github.com/aws/amazon-vpc-cni-k8s/releases) - [Changelog](https://github.com/aws/amazon-vpc-cni-k8s/blob/master/CHANGELOG.md) - [Commits](aws/amazon-vpc-cni-k8s@v1.15.5...v1.21.1) Updates `github.com/aws/aws-lambda-go` from 1.41.0 to 1.52.0 - [Release notes](https://github.com/aws/aws-lambda-go/releases) - [Commits](aws/aws-lambda-go@v1.41.0...v1.52.0) Updates `github.com/aws/aws-sdk-go` from 1.55.5 to 1.55.8 - [Release notes](https://github.com/aws/aws-sdk-go/releases) - [Changelog](https://github.com/aws/aws-sdk-go/blob/main/CHANGELOG_PENDING.md) - [Commits](aws/aws-sdk-go@v1.55.5...v1.55.8) Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.28.6 to 1.38.6 - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@config/v1.28.6...service/sts/v1.38.6) Updates `github.com/coreos/ignition/v2` from 2.16.2 to 2.25.1 - [Release notes](https://github.com/coreos/ignition/releases) - [Changelog](https://github.com/coreos/ignition/blob/main/docs/release-notes.md) - [Commits](coreos/ignition@v2.16.2...v2.25.1) Updates `github.com/go-logr/logr` from 1.4.2 to 1.4.3 - [Release notes](https://github.com/go-logr/logr/releases) - [Changelog](https://github.com/go-logr/logr/blob/master/CHANGELOG.md) - [Commits](go-logr/logr@v1.4.2...v1.4.3) Updates `github.com/gofrs/flock` from 0.8.1 to 0.13.0 - [Release notes](https://github.com/gofrs/flock/releases) - [Commits](gofrs/flock@v0.8.1...v0.13.0) Updates `github.com/google/go-cmp` from 0.6.0 to 0.7.0 - [Release notes](https://github.com/google/go-cmp/releases) - [Commits](google/go-cmp@v0.6.0...v0.7.0) Updates `github.com/onsi/ginkgo/v2` from 2.22.0 to 2.23.4 - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.22.0...v2.23.4) Updates `github.com/onsi/gomega` from 1.36.0 to 1.37.0 - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.36.0...v1.37.0) Updates `github.com/openshift/rosa` from 1.2.48-rc1 to 1.2.48 - [Release notes](https://github.com/openshift/rosa/releases) - [Commits](openshift/rosa@v1.2.48-rc1...v1.2.48) Updates `github.com/prometheus/client_golang` from 1.19.1 to 1.22.0 - [Release notes](https://github.com/prometheus/client_golang/releases) - [Changelog](https://github.com/prometheus/client_golang/blob/main/CHANGELOG.md) - [Commits](prometheus/client_golang@v1.19.1...v1.22.0) Updates `github.com/sergi/go-diff` from 1.3.1 to 1.4.0 - [Commits](sergi/go-diff@v1.3.1...v1.4.0) Updates `github.com/sirupsen/logrus` from 1.9.3 to 1.9.4 - [Release notes](https://github.com/sirupsen/logrus/releases) - [Changelog](https://github.com/sirupsen/logrus/blob/master/CHANGELOG.md) - [Commits](sirupsen/logrus@v1.9.3...v1.9.4) Updates `github.com/spf13/cobra` from 1.8.1 to 1.9.1 - [Release notes](https://github.com/spf13/cobra/releases) - [Commits](spf13/cobra@v1.8.1...v1.9.1) Updates `github.com/spf13/pflag` from 1.0.6-0.20210604193023-d5e0c0615ace to 1.0.10 - [Release notes](https://github.com/spf13/pflag/releases) - [Commits](https://github.com/spf13/pflag/commits/v1.0.10) Updates `github.com/zgalor/weberr` from 0.8.2 to 0.9.0 - [Release notes](https://github.com/zgalor/weberr/releases) - [Commits](openshift-online/weberr@v0.8.2...v0.9.0) Updates `golang.org/x/crypto` from 0.31.0 to 0.46.0 - [Commits](golang/crypto@v0.31.0...v0.46.0) Updates `golang.org/x/text` from 0.21.0 to 0.32.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.21.0...v0.32.0) Updates `k8s.io/api` from 0.31.3 to 0.34.1 - [Commits](kubernetes/api@v0.31.3...v0.34.1) Updates `k8s.io/apiextensions-apiserver` from 0.31.3 to 0.34.0 - [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases) - [Commits](kubernetes/apiextensions-apiserver@v0.31.3...v0.34.0) Updates `k8s.io/apimachinery` from 0.31.3 to 0.34.1 - [Commits](kubernetes/apimachinery@v0.31.3...v0.34.1) Updates `k8s.io/apiserver` from 0.31.3 to 0.34.0 - [Commits](kubernetes/apiserver@v0.31.3...v0.34.0) Updates `k8s.io/cli-runtime` from 0.31.3 to 0.34.1 - [Commits](kubernetes/cli-runtime@v0.31.3...v0.34.1) Updates `k8s.io/client-go` from 0.31.3 to 0.34.1 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.31.3...v0.34.1) Updates `k8s.io/component-base` from 0.31.3 to 0.34.0 - [Commits](kubernetes/component-base@v0.31.3...v0.34.0) Updates `k8s.io/kubectl` from 0.31.3 to 0.33.3 - [Commits](kubernetes/kubectl@v0.31.3...v0.33.3) Updates `k8s.io/utils` from 0.0.0-20240711033017-18e509b52bc8 to 0.0.0-20250604170112-4c0f3b243397 - [Commits](https://github.com/kubernetes/utils/commits) Updates `sigs.k8s.io/aws-iam-authenticator` from 0.6.13 to 0.7.10 - [Release notes](https://github.com/kubernetes-sigs/aws-iam-authenticator/releases) - [Changelog](https://github.com/kubernetes-sigs/aws-iam-authenticator/blob/master/docs/RELEASE.md) - [Commits](kubernetes-sigs/aws-iam-authenticator@v0.6.13...v0.7.10) Updates `sigs.k8s.io/cluster-api` from 1.9.4 to 1.9.11 - [Release notes](https://github.com/kubernetes-sigs/cluster-api/releases) - [Commits](kubernetes-sigs/cluster-api@v1.9.4...v1.9.11) Updates `sigs.k8s.io/cluster-api/test` from 1.9.4 to 1.9.11 - [Release notes](https://github.com/kubernetes-sigs/cluster-api/releases) - [Commits](kubernetes-sigs/cluster-api@v1.9.4...v1.9.11) Updates `sigs.k8s.io/controller-runtime` from 0.19.4 to 0.22.1 - [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases) - [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/controller-runtime@v0.19.4...v0.22.1) Updates `sigs.k8s.io/yaml` from 1.4.0 to 1.6.0 - [Release notes](https://github.com/kubernetes-sigs/yaml/releases) - [Changelog](https://github.com/kubernetes-sigs/yaml/blob/master/RELEASE.md) - [Commits](kubernetes-sigs/yaml@v1.4.0...v1.6.0) --- updated-dependencies: - dependency-name: github.com/aws/amazon-vpc-cni-k8s dependency-version: 1.21.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/aws/aws-lambda-go dependency-version: 1.52.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/aws/aws-sdk-go dependency-version: 1.55.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/aws/aws-sdk-go-v2/service/sts dependency-version: 1.38.6 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/coreos/ignition/v2 dependency-version: 2.25.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/go-logr/logr dependency-version: 1.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/gofrs/flock dependency-version: 0.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/google/go-cmp dependency-version: 0.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/onsi/ginkgo/v2 dependency-version: 2.23.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/onsi/gomega dependency-version: 1.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/openshift/rosa dependency-version: 1.2.48 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/prometheus/client_golang dependency-version: 1.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/sergi/go-diff dependency-version: 1.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/sirupsen/logrus dependency-version: 1.9.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/spf13/cobra dependency-version: 1.9.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: github.com/spf13/pflag dependency-version: 1.0.10 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: github.com/zgalor/weberr dependency-version: 0.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: golang.org/x/crypto dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: golang.org/x/text dependency-version: 0.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/api dependency-version: 0.34.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/apiextensions-apiserver dependency-version: 0.34.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/apimachinery dependency-version: 0.34.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/apiserver dependency-version: 0.34.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/cli-runtime dependency-version: 0.34.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/client-go dependency-version: 0.34.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/component-base dependency-version: 0.34.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/kubectl dependency-version: 0.33.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: k8s.io/utils dependency-version: 0.0.0-20250604170112-4c0f3b243397 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: sigs.k8s.io/aws-iam-authenticator dependency-version: 0.7.10 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: sigs.k8s.io/cluster-api dependency-version: 1.9.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: sigs.k8s.io/cluster-api/test dependency-version: 1.9.11 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: sigs.k8s.io/controller-runtime dependency-version: 0.22.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: sigs.k8s.io/yaml dependency-version: 1.6.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a spectrocloud member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
There was a problem hiding this comment.
- G401: Use of weak cryptographic primitive, Severity: MEDIUM
-
- File: /home/runner/work/bulwark/bulwark/target-repo/pkg/cloud/services/eks/iam/iam.go:499:13
-
- G505: Blocklisted import crypto/sha1: weak cryptographic primitive, Severity: MEDIUM
-
- File: /home/runner/work/bulwark/bulwark/target-repo/pkg/cloud/services/eks/iam/iam.go:22:2
-
Please review these findings and fix the issues before merging.
Bumps the dependencies group with 12 updates in the / directory:
1.15.51.21.11.41.01.52.01.55.51.55.82.16.22.25.10.8.10.13.01.2.48-rc11.2.481.3.11.4.01.9.31.9.40.8.20.9.00.6.130.7.101.9.41.9.111.9.41.9.11Updates
github.com/aws/amazon-vpc-cni-k8sfrom 1.15.5 to 1.21.1Release notes
Sourced from github.com/aws/amazon-vpc-cni-k8s's releases.
... (truncated)
Changelog
Sourced from github.com/aws/amazon-vpc-cni-k8s's changelog.
... (truncated)
Commits
e082baeMerge pull request #3552 from aws/mastercdfc4c5Merge branch 'release-1.21' into master2379e32Adding CNI v1.21.1 release (#3550)457feb3Release 1.21 (#3545)b58ebdbMerge branch 'master' into release-1.21f3a6226Release notes for v1.21.0 (#3547)a1fa583Merge pull request #3522 from aws/master (#3540)06343adMerge branch 'master' into release-1.2132fbbc2update golang version (#3536)401cbc6update tags in chart file(#3535)Updates
github.com/aws/aws-lambda-gofrom 1.41.0 to 1.52.0Release notes
Sourced from github.com/aws/aws-lambda-go's releases.
... (truncated)
Commits
9dac8a5Add structured logging helper (#614)6252f73fix: always return PhysicalResourceID for CFn CustomResources (#613)d4fbc0bAdd CODECOV_TOKEN to tests.yml (#609)a28c6f0Update lambda/sigterm_test to use RIE via public.ecr.aws/lambda/provided rath...56a0f54documentation rework (#608)bbde148Bump GitHub actions (#605)e2b5656fix flaky test TestRuntimeAPILoopWithConcurrency (#606)1fe9d1bAdd TenantID to LambdaContext (#604)7dfe2bbAdd APIGatewayProxyStreamingResponse45c22d5Remove _X_AMZN_TRACE_ID environment variable mutations when handling concurre...Updates
github.com/aws/aws-sdk-gofrom 1.55.5 to 1.55.8Release notes
Sourced from github.com/aws/aws-sdk-go's releases.
Commits
070853erelease v1.55.8 (2025-07-31)bb0168eAdd deprecation warnings everywhere and remove some README content7ce44f3aws6d9a26dremove doc issue tmpl239002fdeprecate service packages and HLLs70c4177deprecate main runtime packagesbbdd4e9deprecate163aadarelease v1.55.7 (2025-04-22) (#5346)9eb2bfdAbort multi part download if the object is modified during download8d203ccUpdate bug-report.ymlUpdates
github.com/aws/aws-sdk-go-v2/service/stsfrom 1.28.6 to 1.38.6Commits
67db690Release 2025-09-2632ee1b5Regenerated Clients0b43122Update endpoints model44786d9Update API modelc98edb7update internal endpts comment that was wrong (#3194)88da3c8Release 2025-09-2574a74fcRegenerated Clients5e6f7aeUpdate endpoints model0e722abUpdate API model41a7d00Release 2025-09-24Updates
github.com/coreos/ignition/v2from 2.16.2 to 2.25.1Release notes
Sourced from github.com/coreos/ignition/v2's releases.
... (truncated)
Changelog
Sourced from github.com/coreos/ignition/v2's changelog.
... (truncated)
Commits
ef86d61Merge pull request #2181 from prestist/new-release-2.25.187e5dd1docs/release-notes: update for 2.25.1b97b22cMerge pull request #2177 from yasminvalim/bugfix-openstack-support4248e7bMerge pull request #2179 from coreosbot-releng/repo-templates478adc4Sync repo templates ⚙67a4c91Merge pull request #2174 from coreos/dependabot/go_modules/build-4a2c2cba6ae7e9ce1Merge pull request #2176 from coreos/add-owners34be53drelease-notes: add release notes for the bugfixd0c5d54openstack.go: fix fetchConfigFromMetadataService bug removing encoding/json21f3aaabuild(deps): bump the build group with 7 updatesUpdates
github.com/go-logr/logrfrom 1.4.2 to 1.4.3Release notes
Sourced from github.com/go-logr/logr's releases.
Commits
38a1c47build(deps): bump github/codeql-action from 3.28.17 to 3.28.18f08beddbuild(deps): bump actions/setup-go from 5.4.0 to 5.5.06295e99build(deps): bump golangci/golangci-lint-action from 7.0.0 to 8.0.0028840dbuild(deps): bump github/codeql-action from 3.28.15 to 3.28.17511e5faMerge pull request #367 from go-logr/dependabot/github_actions/github/codeql-...d806463build(deps): bump github/codeql-action from 3.28.13 to 3.28.15158c311Merge pull request #366 from thockin/masterc79ddb3Update to support golangci-lint v220a64babuild(deps): bump github/codeql-action from 3.28.12 to 3.28.130385e14Add comments around slog exceptionsUpdates
github.com/gofrs/flockfrom 0.8.1 to 0.13.0Release notes
Sourced from github.com/gofrs/flock's releases.
... (truncated)
Commits
bfec60bchore(deps): bump golang.org/x/sys from 0.36.0 to 0.37.0 in the gomod group (...7094284chore: update linter8111aecfeat: add Stat method (#127)6f0f0edchore(deps): bump the github-actions group with 4 updates (#126)fe44231chore(deps): bump golang.org/x/sys from 0.35.0 to 0.36.0 in the gomod group (...f74f0fbchore(deps): bump github.com/stretchr/testify from 1.10.0 to 1.11.1 in the go...c1f6d16chore(deps): bump golang.org/x/sys from 0.34.0 to 0.35.0 in the gomod group (...c542c57chore(deps): bump github/codeql-action from 3.29.2 to 3.29.5 in the github-ac...425570bchore(deps): bump golang.org/x/sys from 0.33.0 to 0.34.0 in the gomod group (...12753eachore(deps): bump github/codeql-action from 3.28.18 to 3.29.2 in the github-a...Updates
github.com/google/go-cmpfrom 0.6.0 to 0.7.0Release notes
Sourced from github.com/google/go-cmp's releases.
Commits
9b12f36Detect proto.Message types when failing to export a field (#370)4dd3d63fix: type 'aribica' => 'arabica' (#368)391980cSupport compare functions with SortSlices and SortMaps (#367)Updates
github.com/onsi/ginkgo/v2from 2.22.0 to 2.23.4Release notes
Sourced from github.com/onsi/ginkgo/v2's releases.
... (truncated)
Changelog
Sourced from github.com/onsi/ginkgo/v2's changelog.
... (truncated)
Commits
229c981v2.23.42d134d5bump dependencies2b9c428Add automaxprocs for using CPUQuota31137deRevert "Add automaxprocs to automatically match the linux container CPU Quota"91b11b8Add automaxprocs to automatically match the linux container CPU Quotacdfddb6maybe escape quotes when you put them in a quoted string.1f59d07clarify gotchas about -vet flag7ab7d10bump all the things04a9a74v2.23.3cfcc1a5allow-as a standalone argumentUpdates
github.com/onsi/gomegafrom 1.36.0 to 1.37.0Release notes
Sourced from github.com/onsi/gomega's releases.
Changelog
Sourced from github.com/onsi/gomega's changelog.
Commits
272fca3v1.37.05666f98add To/ToNot/NotTo aliases for AsyncAssertion2251143v1.36.3adb8b49bump all the things7613216chore: replaceinterface{}withany9fe5259Bump google.golang.org/protobuf from 1.36.1 to 1.36.5 (#822)a0e85b9remove spurious "toolchain" from go.mod (#819)604a8b1Bump golang.org/x/net from 0.33.0 to 0.35.0 (#823)36fbc84Bump activesupport from 6.0.6.1 to 6.1.7.5 in /docs (#772)ced70d7Bump github-pages from 231 to 232 in /docs (#778)Updates
github.com/openshift/rosafrom 1.2.48-rc1 to 1.2.48Release notes
Sourced from github.com/openshift/rosa's releases.
... (truncated)
Commits
cae7dfdOCM-12316 | chore: Set release version to 1.2.48