Skip to content

build(deps): Bump the k8s-sigs group across 1 directory with 2 updates#325

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/k8s-sigs-e8ba5e8270
Open

build(deps): Bump the k8s-sigs group across 1 directory with 2 updates#325
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/k8s-sigs-e8ba5e8270

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 10, 2025

Bumps the k8s-sigs group with 1 update in the / directory: sigs.k8s.io/release-sdk.

Updates sigs.k8s.io/release-sdk from 0.10.4 to 0.12.2

Release notes

Sourced from sigs.k8s.io/release-sdk's releases.

v0.12.2

Changes by Kind

API Change

  • Add a flag draft to the function call CreatePullRequest(...) (#422, @​hectorj2f) [SIG Release]

Feature

Bug or Regression

Dependencies

Added

  • cel.dev/expr: v0.19.0
  • chainguard.dev/sdk: v0.1.23
  • cloud.google.com/go/auth/oauth2adapt: v0.2.7
  • cloud.google.com/go/auth: v0.14.0
  • cloud.google.com/go/translate: v1.10.3
  • github.com/AliyunContainerService/ack-ram-tool/pkg/credentials/provider: v0.14.0
  • github.com/DataDog/go-libddwaf/v3: v3.3.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: v1.25.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric: v0.48.1
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping: v0.48.1
  • github.com/avast/retry-go/v4: v4.6.0
  • github.com/chainguard-dev/slogctx: v1.2.2
  • github.com/containerd/errdefs: v0.1.0
  • github.com/containerd/platforms: v0.2.1
  • github.com/distribution/reference: v0.6.0
  • github.com/go-piv/piv-go/v2: v2.3.0
  • github.com/go-task/slim-sprig/v3: v3.0.0
  • github.com/hashicorp/golang-lru/v2: v2.0.7
  • github.com/in-toto/attestation: v1.1.0
  • github.com/moby/docker-image-spec: v1.3.1
  • github.com/planetscale/vtprotobuf: 0393e58
  • github.com/sigstore/sigstore-go: v0.6.1
  • github.com/theupdateframework/go-tuf/v2: v2.0.1
  • github.com/tink-crypto/tink-go-awskms/v2: v2.1.0
  • github.com/tink-crypto/tink-go-gcpkms/v2: v2.2.0
  • github.com/tink-crypto/tink-go/v2: v2.3.0
  • go.opentelemetry.io/auto/sdk: v1.1.0
  • go.opentelemetry.io/contrib/detectors/gcp: v1.32.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: v1.33.0
  • go.opentelemetry.io/otel/sdk/metric: v1.32.0
  • go.uber.org/mock: v0.5.0
  • gopkg.in/evanphx/json-patch.v4: v4.12.0

... (truncated)

Commits
  • c6bcf8a Merge pull request #422 from hectorj2f/add_draft_flag
  • 6766ba8 CreatePullRequest: add Draft flag to func args
  • a714ea2 Merge pull request #421 from kubernetes-sigs/dependabot/go_modules/golang.org...
  • c03754b build(deps): bump golang.org/x/oauth2 from 0.25.0 to 0.26.0
  • 3cdba3d Merge pull request #419 from kubernetes-sigs/dependabot/go_modules/sigs.k8s.i...
  • d56bfb2 build(deps): bump sigs.k8s.io/release-utils from 0.10.0 to 0.11.0
  • 815767c Merge pull request #418 from saschagrunert/lint
  • e6dd5f8 Update golangci-lint config and fix reports
  • 7a5fc6d Merge pull request #417 from kubernetes-sigs/dependabot/go_modules/all-6bddf0...
  • 414df5b build(deps): bump github.com/sigstore/rekor in the all group
  • Additional commits viewable in compare view

Updates sigs.k8s.io/release-utils from 0.7.7 to 0.11.0

Release notes

Sourced from sigs.k8s.io/release-utils's releases.

v0.11.0

No release notes provided.

v0.10.0

Dependencies

Added

Nothing has changed.

Changed

Removed

Nothing has changed.

v0.9.0

No release notes provided.

v0.8.5

No release notes provided.

v0.8.4

Changes by Kind

Feature

  • K-sigs/release-utils now has an automated release workflow and publishes an SBOM (#110, @​puerco) [SIG Release]
  • Release-utils now has a new throttle package forked from nozzle/throttle (#108, @​puerco) [SIG Release]
  • The http.Agent now has *Group variants of its functions to support parallel fetching o lists of URLs. (#107, @​puerco) [SIG Release]
  • The util package has a new convenience function util.IsDir() to detect if a path is a directory. (#109, @​puerco) [SIG Release]

Other (Cleanup or Flake)

Dependencies

Added

  • github.com/nozzle/throttler: 2ea9822

Changed

Nothing has changed.

Removed

Nothing has changed.

... (truncated)

Commits
  • ff25b35 Merge pull request #127 from saschagrunert/simplify
  • d608579 Simplify retry logic
  • 196ffaa Merge pull request #126 from saschagrunert/retry-api
  • 6676419 Use go-retry for HTTP retry
  • de44574 Merge pull request #125 from saschagrunert/lint
  • f6fed87 Update golangci-lint config and fix reports
  • 3122958 Merge pull request #124 from kubernetes-sigs/dependabot/github_actions/action...
  • 70d8b64 Update release.yaml
  • fd239ba build(deps): bump actions/setup-go in the actions group
  • beb5169 Merge pull request #123 from cpanato/update-golangci
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the k8s-sigs group with 1 update in the / directory: [sigs.k8s.io/release-sdk](https://github.com/kubernetes-sigs/release-sdk).


Updates `sigs.k8s.io/release-sdk` from 0.10.4 to 0.12.2
- [Release notes](https://github.com/kubernetes-sigs/release-sdk/releases)
- [Commits](kubernetes-sigs/release-sdk@v0.10.4...v0.12.2)

Updates `sigs.k8s.io/release-utils` from 0.7.7 to 0.11.0
- [Release notes](https://github.com/kubernetes-sigs/release-utils/releases)
- [Commits](kubernetes-sigs/release-utils@v0.7.7...v0.11.0)

---
updated-dependencies:
- dependency-name: sigs.k8s.io/release-sdk
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-sigs
- dependency-name: sigs.k8s.io/release-utils
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-sigs
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot requested a review from a team as a code owner February 10, 2025 23:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Feb 10, 2025
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Sep 15, 2025

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants