Skip to content

chore(deps): bump the go group with 4 updates - #1000

Merged
jneisener merged 1 commit into
mainfrom
dependabot/go_modules/go-fbbd6feb56
Sep 14, 2026
Merged

jneisener merged 1 commit into
mainfrom
dependabot/go_modules/go-fbbd6feb56

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor

Bumps the go group with 4 updates: github.com/google/go-containerregistry, helm.sh/helm/v3, ocm.software/ocm and sigs.k8s.io/controller-runtime.

Updates github.com/google/go-containerregistry from 0.22.0 to 0.22.1

Release notes

Sourced from github.com/google/go-containerregistry's releases.

v0.22.1

What's Changed

New Contributors

Full Changelog: google/go-containerregistry@v0.22.0...v0.22.1

Commits
  • 8a72a42 remote: copy manifest annotations to referrers fallback tag descriptors (#2441)
  • 5765c35 build(deps): bump the go-deps group across 2 directories with 3 updates (#2439)
  • 969402f fix(mutate): make Time layer updates lazy (#2429)
  • 25c682e flatten: preserve config and layer media types when flattening (#2438)
  • 79af990 remote: add SSRF redirect protection to writer-side HTTP clients (#2432)
  • 4b9b3c7 fix(release): honor declared Go toolchain (#2435)
  • e033b9c fix(build): install binaries to /ko-app and add to PATH (#2424) (#2436)
  • 8bd7902 name: return a helpful error when a reference contains a URL scheme (#2431)
  • 163134d validate: support index attestation manifests and empty configs (#2414)
  • 44f7ea3 fix(build): Use dependencies.gitSource in cloudbuild_v2.yaml (#2434)
  • Additional commits viewable in compare view

Updates helm.sh/helm/v3 from 3.21.4 to 3.22.0

Release notes

Sourced from helm.sh/helm/v3's releases.

Helm v3.22.0 is a feature release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Notable Changes

  • primarily dependency updates and k8s-io group to 0.37.0

Installation and Upgrading

Download Helm v3.22.0. The common platform binaries are here:

This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @​scottrigby keybase account. Please use the attached signatures for verifying this release using gpg.

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.3.1 and 3.22.1 are the next patch releases scheduled for October 14, 2026
  • 4.4.0 is the next minor release scheduled for January 13, 2027. There will be no further Helm 3 minor releases (see https://helm.sh/blog/helm-v3-end-of-life)

Changelog

  • chore(deps): bump the k8s-io group across 1 directory with 6 updates 144ca65f8501953fa8b41cd1d37c7223051c85b7 (dependabot[bot])
  • bump version to 3.22 (#32606) b5de8bbe62975c8f9d4801fd7dfafacff462209f (Scott Rigby)
  • fix: set [pull,push] scope when helm push to a registry(use token auth) (backport) (#32362) 9dbcb9f1edb4cdf2b055870dc9a07e0c0f4b05d1 (kimsungmin1)
  • chore(deps): bump the github-actions group across 1 directory with 4 updates (#32575) 665ab55b05ce3d8c5a9d40e22b14f920d84fa68a (dependabot[bot])
  • chore(deps): bump the k8s-io group with 7 updates (#32573) 0841093658d96f4787cc9599cd2a891a3c590971 (dependabot[bot])
  • chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32563) d0569c7d625151ee8c7b858d87218dd06087d613 (dependabot[bot])

... (truncated)

Commits
  • 144ca65 chore(deps): bump the k8s-io group across 1 directory with 6 updates
  • b5de8bb bump version to 3.22 (#32606)
  • 9dbcb9f fix: set [pull,push] scope when helm push to a registry(use token auth) (back...
  • 665ab55 chore(deps): bump the github-actions group across 1 directory with 4 updates ...
  • 0841093 chore(deps): bump the k8s-io group with 7 updates (#32573)
  • d0569c7 chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 (#32563)
  • bcbdb1e chore(deps): bump the github-actions group across 1 directory with 4 updates ...
  • 6cdcc8f chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#32554)
  • 158719f chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32542)
  • a442b8c [dev-v3 backport] deps: bump google.golang.org/grpc@v1.82.1 for GO-2026-6061 ...
  • Additional commits viewable in compare view

Updates ocm.software/ocm from 0.48.0 to 0.50.0

Release notes

Sourced from ocm.software/ocm's releases.

v0.50.0

What's Changed

🐛 Bug Fixes

⬆️ Dependencies

🧰 Maintenance

Full Changelog: open-component-model/ocm@v0.49...v0.50.0

v0.50.0-rc.1

What's Changed

🐛 Bug Fixes

⬆️ Dependencies

🧰 Maintenance

Full Changelog: open-component-model/ocm@v0.49...v0.50.0

v0.49.0

What's Changed

🐛 Bug Fixes

⬆️ Dependencies

🧰 Maintenance

... (truncated)

Commits
  • 1af92bc chore(deps): bump the ci group with 2 updates (#2091)
  • 4e14bc5 chore(deps): bump the go group with 10 updates (#2089)
  • 0e26b7f chore: update 'flake.nix' (#2088)
  • c183e32 chore(deps): bump github.com/moby/go-archive from 0.2.0 to 0.3.0 (#2086)
  • 7aa8c74 chore(deps): bump docker/setup-buildx-action from 4.2.0 to 4.3.0 in the ci gr...
  • 80ed9d3 chore: update 'flake.nix' (#2084)
  • 63e9c85 chore(deps): bump the go group across 1 directory with 20 updates (#2085)
  • 035afbe fix: fork cosign files that were deleted because they were unused (#2082)
  • 9ff08ce chore(deps): bump the ci group with 2 updates (#2083)
  • 11bb9b4 chore(deps): bump rojopolis/spellcheck-github-actions from 0.65.0 to 0.66.0 i...
  • Additional commits viewable in compare view

Updates sigs.k8s.io/controller-runtime from 0.24.1 to 0.25.0

Release notes

Sourced from sigs.k8s.io/controller-runtime's releases.

v0.25.0

Highlights

This version of controller-runtime introduces a new experimental ReadYourWritesConsistency feature, which ensures that all writes are reflected in subsequent reads from the default cache-backed client. Stale client reads are arguably the biggest source of friction and sometimes bugs for controller authors, providing this functionality at the library level eliminates that class of problems entirely.

Try it out by setting Client.EnableReadYourWritesConsistency: new(true) in your manager and leave any feedback you may have on the tracking issue.

⚠️ Breaking Changes

✨ New Features

  • Client: Add a read-your-own-writes client (#3472)
  • Fakeclient: Add WithGlobalResourceVersionCounter (#3581)
  • Fakeclient: Add scale subresource support for Apply (#3569)
  • Metrics: Allow opt-in for client-go REST client metrics (#3510)
  • Metrics: Allow overriding client-go REST client metrics latency histogram buckets (#3573)
  • Source: Add TypedInformer source (#3520)
  • Webhooks: Allow to disable the webhook server by setting the port to -1 (#3481)

🐛 Bug Fixes

  • Cache: Fix goroutine leaks in cache Start() methods (#3565)
  • Client: Fix regression in Apply typed error handling (#3515)
  • Controller: Unlock when Controller.Start() returns with error (#3545)
  • Envtest: Fix envtest process stop on Windows (#3519)
  • Fakeclient: Allow updating managedFields through Update (#3585)
  • Fakeclient: Fix AddIndex panic when wrapped with an interceptor (#3583)
  • Fakeclient: Fix PartialObjectMeta handling (#3571)
  • Fakeclient: Support scale subresource get/update for unstructured objects (#3546)
  • Fakeclient: Update object on subresource apply (#3570)
  • PriorityQueue: Fix PriorityQueue deadlock on shutdown (#3540)
  • Testing/Process: Fix process Stop timeout error handling (#3523)

🌱 Others

  • LeaderElection: Pass Managers Logger to Leader Elector via Context (#3576)

🌱 CI & linters

  • Add copyright header validation & fix findings (#3544)
  • Bump to golangci-lint v2.12.1 (#3514)
  • Bump to golangci-lint v2.12.2 (#3532)
  • Bump to golangci-lint v2.13.1 (#3580)

... (truncated)

Commits
  • e8f9455 🐛 fakeclient: Allow updating managedFields through Update (#3585)
  • 0cc1315 Merge pull request #3565 from dongjiang1989/fix-leak
  • fa96780 🐛 Fix goroutine leaks in cache Start() methods
  • 1f5514b ✨ Add a read-your-own-write client (#3472)
  • df386c7 🌱 Bump to golangci-lint v2.13.1 (#3580)
  • dc7618f Merge pull request #3583 from pujitha24/auto/issue-3582
  • 37fe235 🐛 fake: fix AddIndex panic when client is wrapped with an interceptor
  • 01c7782 ✨ Allow overriding REST client latency histogram buckets (#3573)
  • 857be80 Merge pull request #3576 from demirdilek/fix-leaderelection-contextual-logging
  • b1387be Merge pull request #3581 from alvaroaleman/fake-consistent
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the go group with 4 updates: [github.com/google/go-containerregistry](https://github.com/google/go-containerregistry), [helm.sh/helm/v3](https://github.com/helm/helm), [ocm.software/ocm](https://github.com/open-component-model/ocm) and [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime).


Updates `github.com/google/go-containerregistry` from 0.22.0 to 0.22.1
- [Release notes](https://github.com/google/go-containerregistry/releases)
- [Commits](google/go-containerregistry@v0.22.0...v0.22.1)

Updates `helm.sh/helm/v3` from 3.21.4 to 3.22.0
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/helm@v3.21.4...v3.22.0)

Updates `ocm.software/ocm` from 0.48.0 to 0.50.0
- [Release notes](https://github.com/open-component-model/ocm/releases)
- [Changelog](https://github.com/open-component-model/ocm/blob/main/RELEASE_PROCESS.md)
- [Commits](open-component-model/ocm@v0.48...v0.50)

Updates `sigs.k8s.io/controller-runtime` from 0.24.1 to 0.25.0
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/controller-runtime@v0.24.1...v0.25.0)

---
updated-dependencies:
- dependency-name: github.com/google/go-containerregistry
  dependency-version: 0.22.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: ocm.software/ocm
  dependency-version: 0.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels Sep 13, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 13, 2026 15:03
@dependabot dependabot Bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels Sep 13, 2026

@jneisener jneisener left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Breaking Changes

Dependencies: Bump to k8s.io/* v1.37 (#3579 #3575 #3567 #3561 #3547 #3529 #3524)
Events: Add new EventRecorder interface (#3509)

  1. Non-issue, several k8s dependencies are already on .37
    k8s.io/component-base v0.37.0 // indirect
  2. Code already uses EventRecorder from
    kuberecorder "k8s.io/client-go/tools/record"

@jneisener
jneisener merged commit 65c0b25 into main Sep 14, 2026
9 checks passed
@jneisener
jneisener deleted the dependabot/go_modules/go-fbbd6feb56 branch September 14, 2026 05:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant