REPLACE-WITH-JIRA-KEY: Bump Kubernetes dependencies to v1.36.2#3062
REPLACE-WITH-JIRA-KEY: Bump Kubernetes dependencies to v1.36.2#3062dfarrell07 wants to merge 4 commits into
Conversation
go get k8s.io/api@v0.36.2 go get k8s.io/apiextensions-apiserver@v0.36.2 go get k8s.io/apiserver@v0.36.2 go get k8s.io/client-go@v0.36.2 go get k8s.io/code-generator@v0.36.2 go get k8s.io/component-base@v0.36.2 go get k8s.io/kms@v0.36.2 go get k8s.io/kube-aggregator@v0.36.2 go get k8s.io/kube-proxy@v0.36.2 go get sigs.k8s.io/controller-runtime@v0.24.1 go get github.com/openshift/api go get github.com/openshift/build-machinery-go go get github.com/openshift/client-go go get github.com/openshift/library-go go get k8s.io/apimachinery go get k8s.io/gengo/v2 go get k8s.io/klog/v2 go get k8s.io/kube-openapi go get k8s.io/utils go get sigs.k8s.io/apiserver-network-proxy/konnectivity-client go get sigs.k8s.io/controller-tools go get sigs.k8s.io/json go get sigs.k8s.io/kube-storage-version-migrator go get sigs.k8s.io/randfill go get sigs.k8s.io/structured-merge-diff/v6 go get sigs.k8s.io/yaml go mod tidy Signed-off-by: Daniel Farrell <dfarrell@redhat.com> Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Daniel Farrell <dfarrell@redhat.com> Assisted-by: Claude Code <noreply@anthropic.com>
./.ci-operator.yaml ./Dockerfile Signed-off-by: Daniel Farrell <dfarrell@redhat.com> Assisted-by: Claude Code <noreply@anthropic.com>
WatchListClient (default-true since k8s 1.35) changes the initial list mechanism to streaming lists. Fake clientsets don't implement this protocol, causing informer hangs in unit tests. Signed-off-by: Daniel Farrell <dfarrell@redhat.com> Assisted-by: Claude Code <noreply@anthropic.com>
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
|
Skipping CI for Draft Pull Request. |
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dfarrell07 The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Summary
k8s.io/*dependencies from v0.35.2 to v0.36.2sigs.k8s.io/controller-runtimefrom v0.23.3 to v0.24.1sigs.k8s.io/controller-toolsfrom v0.20.1 to v0.21.0What changed
Details
No Go source files were modified outside of
vendor/. The k8s 1.36 API surface is fully compatible with CNO's existing code.The only non-mechanical change disables the
WatchListClientfeature gate (default-true since k8s 1.35) inhack/test-go.sh. This prevents unit test hangs caused by fake clientsets not implementing the streaming list protocol.Security improvement: This rebase fixes 37 known CVEs in transitive dependencies, including a critical gRPC auth bypass (GHSA-p77j-4mvh-x3m3, CVSS 9.1) in google.golang.org/grpc.
Verification
Locally verified:
go build ./...-- PASSgo vet ./...-- PASSgolangci-lint run-- PASSpkg/controller/proxyconfigfails due to missing/etc/pki/ca-trust/in container env, pre-existing)All commits carry
Assisted-by: Claude Codetrailers.CI Notes
golang-1.26-openshift-4.22-- verify ART has published these..snykusesvendor/**glob exclusion (safe for vendor changes).