dependabot[bot] and GitHub
c2da96ecb8
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0
...
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action ) from 0.35.0 to 0.36.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases )
- [Commits](https://github.com/aquasecurity/trivy-action/compare/57a97c7e7821a5776cebc9bb87c984fa69cba8f1...ed142fd0673e97e23eac54620cfb913e5ce36c25 )
---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
dependency-version: 0.36.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-08 10:29:32 +00:00
Jean-Philippe Evrard and GitHub
5c24aba3bb
Merge pull request #1341 from evrardjp/bump-go
...
Bump go to fix CVE-2026-42504
2026-06-08 12:24:34 +02:00
Jean-Philippe Evrard
aabe5868d6
Bump go to fix CVE-2026-42504
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-06-08 12:13:46 +02:00
Jean-Philippe Evrard and GitHub
984d46844c
Merge pull request #1336 from kubereboot/dependabot/github_actions/step-security/harden-runner-2.19.4
...
build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4
2026-06-08 11:43:08 +02:00
Jean-Philippe Evrard and GitHub
a962b6eea9
Merge pull request #1339 from kubereboot/dependabot/go_modules/all-798ff1a463
2026-06-06 14:02:22 +02:00
dependabot[bot] and GitHub
c6e0ef61a6
build(deps): bump github.com/prometheus/common in the all group
...
Bumps the all group with 1 update: [github.com/prometheus/common](https://github.com/prometheus/common ).
Updates `github.com/prometheus/common` from 0.67.5 to 0.68.0
- [Release notes](https://github.com/prometheus/common/releases )
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md )
- [Commits](https://github.com/prometheus/common/compare/v0.67.5...v0.68.0 )
---
updated-dependencies:
- dependency-name: github.com/prometheus/common
dependency-version: 0.68.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: all
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-29 20:48:55 +00:00
Jean-Philippe Evrard and GitHub
1f37a84cad
Merge pull request #1337 from evrardjp/prepare-release-1.22.0
...
chore: update release
1.22.0
2026-05-26 15:40:53 +02:00
Jean-Philippe Evrard
bc10cd0445
chore: update release
...
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-05-26 15:37:42 +02:00
dependabot[bot] and GitHub
3b7c3241ad
build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4
...
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.19.0 to 2.19.4.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](https://github.com/step-security/harden-runner/compare/8d3c67de8e2fe68ef647c8db1e6a09f647780f40...9af89fc71515a100421586dfdb3dc9c984fbf411 )
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-version: 2.19.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-26 12:29:48 +00:00
Jean-Philippe Evrard and GitHub
1882041f7c
Merge pull request #1331 from evrardjp/update_dependabot_handling
...
Alter bumping work of dependabot
2026-05-26 14:10:43 +02:00
Jean-Philippe Evrard
7f2d941c5c
Alter bumping work of dependabot
...
Without this, dependabot would separate all the dependencies in
different PRs.
This is inefficient: The only group of PRs that need to be
separate, is kubernetes: We only want to bump them for a new
release.
On top of that, those kubernetes dependencies also need to be
bumped together.
This fixes the dependabot config to match that use case.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-05-26 14:06:19 +02:00
Jean-Philippe Evrard and GitHub
9a963b9124
Merge pull request #1329 from evrardjp/fix-remnant-broken-test
...
Remove "next" test
2026-05-26 13:19:56 +02:00
Jean-Philippe Evrard
4f19b4d5fe
Remove "next" test
...
During the policy change removing our "lagging behind", implemented
in 168fe81bb4 [1], we forgot to
remove one "next" test.
This should fix it.
[1]: https://github.com/kubereboot/kured/commit/168fe81bb40715b28a51e56ef10804e4275ff64c
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-05-26 13:14:01 +02:00
Jean-Philippe Evrard and GitHub
94b61bcaff
Merge pull request #1330 from evrardjp/bump_go
...
Bump go version
2026-05-26 13:12:07 +02:00
Jean-Philippe Evrard
d05bbcd107
Bump go version
...
Without this, our scanners will mark us as impacted by the CVEs:
- CVE-2026-32280
- CVE-2026-32281
- CVE-2026-32283
- CVE-2026-33811
- CVE-2026-33814
- CVE-2026-39820
- CVE-2026-39836
- CVE-2026-42499
None of those should have an impact on us, but it triggers the
scanner.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-05-26 11:58:41 +02:00
Jean-Philippe Evrard and GitHub
66d3ad3185
Merge pull request #1322 from kubereboot/dependabot/github_actions/actions/setup-go-6.4.0
...
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0
2026-05-26 10:35:03 +02:00
Jean-Philippe Evrard and GitHub
4bfa3363b7
Merge pull request #1321 from kubereboot/dependabot/github_actions/actions/upload-artifact-7.0.1
...
build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1
2026-05-26 10:34:28 +02:00
Jean-Philippe Evrard and GitHub
6f8c40f251
Merge pull request #1320 from kubereboot/dependabot/github_actions/step-security/harden-runner-2.19.0
...
build(deps): bump step-security/harden-runner from 2.13.2 to 2.19.0
2026-05-26 10:34:00 +02:00
Jean-Philippe Evrard and GitHub
afa59056b4
Merge pull request #1319 from kubereboot/dependabot/github_actions/docker/login-action-4.1.0
...
build(deps): bump docker/login-action from 4.0.0 to 4.1.0
2026-05-26 10:32:58 +02:00
Jean-Philippe Evrard and GitHub
086b3eee01
Merge pull request #1304 from kubereboot/dependabot/github_actions/actions/dependency-review-action-4.9.0
...
build(deps): bump actions/dependency-review-action from 4.8.1 to 4.9.0
2026-05-26 10:31:52 +02:00
dependabot[bot] and GitHub
8d4c431949
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 6.3.0 to 6.4.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...4a3601121dd01d1626a1e23e37211e3254c1c06c )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-version: 6.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-23 18:07:11 +00:00
dependabot[bot] and GitHub
fece55e37a
build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-23 18:07:06 +00:00
dependabot[bot] and GitHub
d062920e53
build(deps): bump step-security/harden-runner from 2.13.2 to 2.19.0
...
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner ) from 2.13.2 to 2.19.0.
- [Release notes](https://github.com/step-security/harden-runner/releases )
- [Commits](https://github.com/step-security/harden-runner/compare/95d9a5deda9de15063e7595e9719c11c38c90ae2...8d3c67de8e2fe68ef647c8db1e6a09f647780f40 )
---
updated-dependencies:
- dependency-name: step-security/harden-runner
dependency-version: 2.19.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-23 18:07:02 +00:00
dependabot[bot] and GitHub
cb06421abb
build(deps): bump docker/login-action from 4.0.0 to 4.1.0
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 4.0.0 to 4.1.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/b45d80f862d83dbcd57f89517bcf500b2ab88fb2...4907a6ddec9925e35a0a9e82d7399ccc52663121 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 4.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-23 18:06:54 +00:00
Jean-Philippe Evrard and GitHub
117dc5d185
Merge pull request #1310 from kubereboot/dependabot/docker/alpine-3.23.4
2026-04-23 05:46:37 +02:00
Jean-Philippe Evrard and GitHub
646c31f56e
Merge pull request #1311 from kubereboot/dependabot/go_modules/k8s.io/kubectl-0.35.4
2026-04-23 05:46:06 +02:00
Jean-Philippe Evrard and GitHub
5f33b41235
Merge pull request #1307 from kubereboot/dependabot/github_actions/actions/stale-10.2.0
2026-04-23 05:44:05 +02:00
Jean-Philippe Evrard and GitHub
da63cfe7d0
Merge pull request #1308 from kubereboot/dependabot/github_actions/github/codeql-action-4.35.1
2026-04-23 05:42:31 +02:00
Jean-Philippe Evrard and GitHub
a8576cbbbe
Merge pull request #1305 from kubereboot/dependabot/github_actions/docker/login-action-4.0.0
2026-04-23 05:39:31 +02:00
dependabot[bot] and GitHub
00898d8814
build(deps): bump k8s.io/kubectl from 0.35.3 to 0.35.4
...
Bumps [k8s.io/kubectl](https://github.com/kubernetes/kubectl ) from 0.35.3 to 0.35.4.
- [Commits](https://github.com/kubernetes/kubectl/compare/v0.35.3...v0.35.4 )
---
updated-dependencies:
- dependency-name: k8s.io/kubectl
dependency-version: 0.35.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-16 17:53:08 +00:00
dependabot[bot] and GitHub
68a0bcc376
build(deps): bump alpine from 3.23.3 to 3.23.4
...
Bumps alpine from 3.23.3 to 3.23.4.
---
updated-dependencies:
- dependency-name: alpine
dependency-version: 3.23.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-04-16 17:52:57 +00:00
dependabot[bot] and GitHub
fcaf85cff6
build(deps): bump github/codeql-action from 4.34.1 to 4.35.1
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 4.34.1 to 4.35.1.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/38697555549f1db7851b81482ff19f1fa5c4fedc...c10b8064de6f491fea524254123dbe5e09572f13 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-version: 4.35.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-27 17:54:16 +00:00
dependabot[bot] and GitHub
e2d4455cf0
build(deps): bump actions/stale from 10.1.0 to 10.2.0
...
Bumps [actions/stale](https://github.com/actions/stale ) from 10.1.0 to 10.2.0.
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/stale/compare/5f858e3efba33a5ca4407a664cc011ad407f2008...b5d41d4e1d5dceea10e7104786b73624c18a190f )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 10.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-26 17:53:27 +00:00
dependabot[bot] and GitHub
9bdb304231
build(deps): bump docker/login-action from 3.7.0 to 4.0.0
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 3.7.0 to 4.0.0.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...b45d80f862d83dbcd57f89517bcf500b2ab88fb2 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-26 17:53:04 +00:00
dependabot[bot] and GitHub
30c4ed0835
build(deps): bump actions/dependency-review-action from 4.8.1 to 4.9.0
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 4.8.1 to 4.9.0.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](https://github.com/actions/dependency-review-action/compare/40c09b7dc99638e5ddb0bfd91c1673effc064d8a...2031cfc080254a8a887f58cffee85186f0e49e48 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-version: 4.9.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-26 17:52:59 +00:00
Jean-Philippe Evrard and GitHub
08b436aeed
Merge pull request #1303 from evrardjp/update-comment
...
Update upload-artifact comment
2026-03-26 04:22:29 +01:00
Jean-Philippe Evrard
99ada00506
Update upload-artifact comment
...
Fixes dependabot incorrect comment update in PR#1299
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-03-26 03:59:14 +01:00
Jean-Philippe Evrard and GitHub
66cf0ccc5d
Merge pull request #1299 from kubereboot/dependabot/github_actions/actions/upload-artifact-7.0.0
...
build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0
2026-03-26 03:56:26 +01:00
Jean-Philippe Evrard and GitHub
b18f7398eb
Merge pull request #1298 from kubereboot/dependabot/github_actions/lycheeverse/lychee-action-2.8.0
...
build(deps): bump lycheeverse/lychee-action from 2.7.0 to 2.8.0
2026-03-26 03:53:50 +01:00
Jean-Philippe Evrard and GitHub
6bd56b8dc5
Merge pull request #1300 from kubereboot/dependabot/github_actions/jdx/mise-action-4.0.1
...
build(deps): bump jdx/mise-action from 3.6.1 to 4.0.1
2026-03-26 03:52:49 +01:00
Jean-Philippe Evrard and GitHub
157d027d6c
Merge pull request #1301 from kubereboot/dependabot/github_actions/docker/setup-qemu-action-4.0.0
...
build(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0
2026-03-26 03:51:40 +01:00
Jean-Philippe Evrard and GitHub
ebbca87f4e
Merge pull request #1302 from kubereboot/dependabot/github_actions/docker/metadata-action-6.0.0
...
build(deps): bump docker/metadata-action from 5.10.0 to 6.0.0
2026-03-26 03:51:14 +01:00
dependabot[bot] and GitHub
1ac5bd69bf
build(deps): bump docker/metadata-action from 5.10.0 to 6.0.0
...
Bumps [docker/metadata-action](https://github.com/docker/metadata-action ) from 5.10.0 to 6.0.0.
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](https://github.com/docker/metadata-action/compare/c299e40c65443455700f0fdfc63efafe5b349051...030e881283bb7a6894de51c315a6bfe6a94e05cf )
---
updated-dependencies:
- dependency-name: docker/metadata-action
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-24 17:53:25 +00:00
dependabot[bot] and GitHub
20168b53cc
build(deps): bump docker/setup-qemu-action from 3.7.0 to 4.0.0
...
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action ) from 3.7.0 to 4.0.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases )
- [Commits](https://github.com/docker/setup-qemu-action/compare/c7c53464625b32c7a7e944ae62b3e17d2b600130...ce360397dd3f832beb865e1373c09c0e9f86d70a )
---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
dependency-version: 4.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-24 17:53:20 +00:00
dependabot[bot] and GitHub
da72996abe
build(deps): bump jdx/mise-action from 3.6.1 to 4.0.1
...
Bumps [jdx/mise-action](https://github.com/jdx/mise-action ) from 3.6.1 to 4.0.1.
- [Release notes](https://github.com/jdx/mise-action/releases )
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/jdx/mise-action/compare/6d1e696aa24c1aa1bcc1adea0212707c71ab78a8...1648a7812b9aeae629881980618f079932869151 )
---
updated-dependencies:
- dependency-name: jdx/mise-action
dependency-version: 4.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-24 17:53:13 +00:00
dependabot[bot] and GitHub
757cb25fe8
build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0
...
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact ) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases )
- [Commits](https://github.com/actions/upload-artifact/compare/b7c566a772e6b6bfb58ed0dc250532a479d7789f...bbbca2ddaa5d8feaa63e36b76fdaad77386f024f )
---
updated-dependencies:
- dependency-name: actions/upload-artifact
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-24 17:53:01 +00:00
dependabot[bot] and GitHub
72b55a5ed4
build(deps): bump lycheeverse/lychee-action from 2.7.0 to 2.8.0
...
Bumps [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action ) from 2.7.0 to 2.8.0.
- [Release notes](https://github.com/lycheeverse/lychee-action/releases )
- [Commits](https://github.com/lycheeverse/lychee-action/compare/a8c4c7cb88f0c7386610c35eb25108e448569cb0...8646ba30535128ac92d33dfc9133794bfdd9b411 )
---
updated-dependencies:
- dependency-name: lycheeverse/lychee-action
dependency-version: 2.8.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-03-24 17:52:57 +00:00
Jean-Philippe Evrard and GitHub
334fb5f99c
Merge pull request #1289 from evrardjp/include-comment-for-dependabot
...
Fix dependabot bumping
2026-03-24 09:58:48 +01:00
Jean-Philippe Evrard
ee13c5c40a
Unpin actions to fix dependabot bumping
...
Since September 2025, dependabot does not update some actions
anymore. Putting in a comment the _version tag_ (next to the
sha) make it clear that the intent is not to pin and should
allow further bumping by dependabot.
This was not necessary in the past and seem required now.
Signed-off-by: Jean-Philippe Evrard <open-source@a.spamming.party >
2026-03-24 09:50:55 +01:00
Jean-Philippe Evrard and GitHub
01317d3e0a
Merge pull request #1293 from kubereboot/dependabot/github_actions/github/codeql-action-4.34.1
2026-03-23 22:20:50 +01:00