Aleksei Sviridkin
24c2028a77
fix(registry): select the requested chart from an OCI Image Index
...
Pulling a reference that resolves to an Image Index collected every
descriptor matching a fixed media-type allow-list, then assigned the
config, chart and provenance descriptors with a switch that kept the
last match of each kind. That slice is filled from oras PreCopy
callbacks during a concurrent graph walk, so its order is neither the
order of the index nor defined by anything else, and each kind is
resolved independently of the others. For an index holding more than
one chart the delivered chart is arbitrary, and because the metadata
is read from the config blob while the bytes come from the chart
layer, the two can describe different charts. Nothing on the path
compares them, and the file name is taken from the reference rather
than from either.
Select the chart manifest before copying instead. An entry declaring
the chart artifactType is a candidate, whether or not it also carries
a platform, so that tooling stamping a platform on every index entry
cannot hide the chart. Entries declaring no type are matched on their
config mediaType, which keeps an index written before artifactType
existed resolvable. That second pass runs when the first found
nothing, and also when no single entry it found announces the whole
requested name and version, since narrowing the candidates before
that is checked is how a mixed index answers with the wrong chart.
Asking per attribute instead would let one entry supply the name and
another the version, and the pair they form belongs to neither.
Several candidates are then narrowed by the requested name and, if
that leaves more than one, by the requested version. Both are read
from the descriptor annotations, falling back to the candidate's own
config for whichever an index omits. Entries repeated in the index
are collapsed first, so one chart is never called ambiguous with
itself, and an answer that rests on nothing else matching is withheld
when the pass could not read every entry, because absence is a fact
about the index only while the whole index could be read. Reading a
candidate's identity can fail the same way and now says so, so a
chart whose name could not be fetched is no longer indistinguishable
from a chart that is not there. A choice that name and version cannot
settle is an error naming the candidates rather than an arbitrary
pick.
One consequence worth naming. Pulling an index reference reports the
digest of the selected chart manifest where it previously reported
the digest of the index. Selection runs inside the copy, on the root
oras has already resolved, so narrowing an index costs no request of
its own. The pass over the entries that declare no type is what costs
requests, one per entry, and only when it runs.
Signed-off-by: Aleksei Sviridkin <f@lex.la>
Assisted-By: Claude <noreply@anthropic.com>
4 weeks ago
dependabot[bot]
f3d68cdbea
chore(deps): bump the github-actions group with 4 updates ( #32523 )
...
Bumps the github-actions group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `github/codeql-action/init` from 4.37.5 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](d1ba80a13d...5595ccaf91 )
Updates `github/codeql-action/autobuild` from 4.37.5 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](d1ba80a13d...5595ccaf91 )
Updates `github/codeql-action/analyze` from 4.37.5 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](d1ba80a13d...5595ccaf91 )
Updates `github/codeql-action/upload-sarif` from 4.37.5 to 4.37.6
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](d1ba80a13d...5595ccaf91 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.37.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.6
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
Terry Howe
a0c2f6dade
fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158 ( #32521 )
...
* fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158
govulncheck on main flags GO-2026-5158 in go.opentelemetry.io/otel@v1.43.0
(fixed in v1.44.0). Bump the transitive otel dependency to clear the
vulnerability.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
* fix: bump otel/sdk and otel/sdk/metric to v1.44.0 for version parity
Keep the lockstep-versioned OpenTelemetry core and SDK modules aligned at
v1.44.0 to avoid version skew.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
---------
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 month ago
dependabot[bot]
f8a308cd47
chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6 ( #32514 )
...
Bumps [github.com/santhosh-tekuri/jsonschema/v6](https://github.com/santhosh-tekuri/jsonschema ) from 6.0.2 to 6.0.3.
- [Release notes](https://github.com/santhosh-tekuri/jsonschema/releases )
- [Commits](https://github.com/santhosh-tekuri/jsonschema/compare/v6.0.2...v6.0.3 )
---
updated-dependencies:
- dependency-name: github.com/santhosh-tekuri/jsonschema/v6
dependency-version: 6.0.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
George Jenkins
e8a24895d1
Merge pull request #31580 from biagiopietro/feature/rollback-description-flag
...
feat(rollback): add --description flag to provide rollback reason
1 month ago
George Jenkins
819e069eb9
Merge pull request #32516 from helm/dependabot/github_actions/main/github-actions-abda45ccb9
...
chore(deps): bump the github-actions group with 4 updates
1 month ago
dependabot[bot]
47eb219a71
chore(deps): bump the github-actions group with 4 updates
...
Bumps the github-actions group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `github/codeql-action/init` from 4.37.4 to 4.37.5
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](f205ea1c33...d1ba80a13d )
Updates `github/codeql-action/autobuild` from 4.37.4 to 4.37.5
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](f205ea1c33...d1ba80a13d )
Updates `github/codeql-action/analyze` from 4.37.4 to 4.37.5
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](f205ea1c33...d1ba80a13d )
Updates `github/codeql-action/upload-sarif` from 4.37.4 to 4.37.5
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](f205ea1c33...d1ba80a13d )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.37.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.5
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
1 month ago
MrJack
b44d98328b
Merge branch 'helm:main' into feature/rollback-description-flag
1 month ago
dependabot[bot]
ae877c8bfb
chore(deps): bump the github-actions group with 4 updates ( #32508 )
...
Bumps the github-actions group with 4 updates: [github/codeql-action/init](https://github.com/github/codeql-action ), [github/codeql-action/autobuild](https://github.com/github/codeql-action ), [github/codeql-action/analyze](https://github.com/github/codeql-action ) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ).
Updates `github/codeql-action/init` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e4fba868fa...f205ea1c33 )
Updates `github/codeql-action/autobuild` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e4fba868fa...f205ea1c33 )
Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e4fba868fa...f205ea1c33 )
Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](e4fba868fa...f205ea1c33 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.37.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
MrJack
2b239b84e4
Merge branch 'helm:main' into feature/rollback-description-flag
2 months ago
Nikolaus Schuetz
a8ab76e86f
test(action): poll for the interrupted install goroutine instead of a zero-margin sleep ( #32328 )
...
TestInstallRelease_Wait_Interrupted and
TestInstallRelease_RollbackOnFailure_Interrupted assert that the detached
installation goroutine has exited by sleeping a fixed 10s -- exactly the
FailingKubeClient WaitDuration the goroutine blocks on. Sleeping the same
duration the goroutine takes is a zero-margin race: if the goroutine
finishes a hair after the fixed sleep elapses (scheduler jitter under load),
getGoroutineCount() has not decremented yet and the assertion flakes.
Replace the fixed sleep + point-in-time assert with is.Eventually polling
getGoroutineCount() (30s ceiling, 10ms tick). It returns as soon as the
goroutine has actually finished and no longer races the exact wait
duration. Test-only; no change to install behavior.
Signed-off-by: Nikolaus Schuetz <nikolauspschuetz@gmail.com>
2 months ago
dependabot[bot]
ac1c68746f
chore(deps): bump actions/stale in the github-actions group ( #32487 )
...
Bumps the github-actions group with 1 update: [actions/stale](https://github.com/actions/stale ).
Updates `actions/stale` from 10.4.0 to 11.0.0
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](1e223db275...4391f3da66 )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 11.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 months ago
George Jenkins
9b1eb018a3
Merge pull request #32339 from 1solomonwakhungu/fix/get-helm-cache-busting
...
fix(scripts): add cache-busting to Helm version checks
2 months ago
Terry Howe
7e641d30a9
Merge pull request #32481 from mmorel-35/gofumpt
...
chore: fix gofumpt issues
2 months ago
Terry Howe
fda6e6043d
Merge pull request #32484 from helm/dependabot/go_modules/main/go.yaml.in/yaml/v3-3.0.5
...
chore(deps): bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5
2 months ago
dependabot[bot]
ce27485634
chore(deps): bump go.yaml.in/yaml/v3 from 3.0.4 to 3.0.5
...
Bumps [go.yaml.in/yaml/v3](https://github.com/yaml/go-yaml ) from 3.0.4 to 3.0.5.
- [Commits](https://github.com/yaml/go-yaml/compare/v3.0.4...v3.0.5 )
---
updated-dependencies:
- dependency-name: go.yaml.in/yaml/v3
dependency-version: 3.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
2 months ago
Solomon Wakhungu
bc0114c708
fix(scripts): clarify cache-busting behavior
...
Signed-off-by: Solomon Wakhungu <65043605+1solomonwakhungu@users.noreply.github.com>
2 months ago
Matthieu MOREL
24bbb46c62
chore: fix gofumpt issues
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Solomon Wakhungu
bbaf420a10
fix(scripts): address cache-busting review feedback
...
Signed-off-by: Solomon Wakhungu <65043605+1solomonwakhungu@users.noreply.github.com>
2 months ago
MrJack
f3edb83df4
Make golangci-lint happy
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
94a3315f4d
Added missing import
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
500f02d597
Readded "unicode/utf8"
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
f1ede7c9c1
Potential fix for pull request finding
...
If the CLI-side description validation is removed, the unicode/utf8 import becomes unused and should also be dropped.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
4fcc4e4b3d
Apply suggestions from code review
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
91520a7806
refactor(rollback): validate description length before cluster reachability check
...
Move description length validation to the beginning of Run(), before
IsReachable(), so programmatic callers get an immediate validation
error instead of a potentially misleading cluster reachability failure.
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
e73dfab5fb
refactor(test): reuse existing rollback.txt golden file
...
Remove duplicate rollback-with-description.txt fixture that had
identical content to rollback.txt.
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
b177a8e906
Removed extra space in rollback-with-description.txt
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
a92611c202
Enhance rune count in pkg/cmd/rollback.go and pkg/action/rollback.go
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
8a34f3b7b4
Use rune count to count properly multi-byte UTF-8 characters
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
cb91040c44
Enhanced rollback description length
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
e69e424ab1
Changed if construction
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
b606955f09
Set 256 as limit for maxDescriptionLength. 256 comes from MAX value for key and value
...
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
MrJack
f8180e6de4
feat(rollback): add --description flag to provide rollback reason
...
Add a new --description flag to the helm rollback command that allows
users to specify a custom description explaining why the rollback was
performed. This description is stored in the release metadata.
Changes:
- Add Description field to the Rollback action struct
- Add --description flag to the rollback CLI command
- Add 512 character limit validation for the description
- Default to 'Rollback to <version>' when no description is provided
The description flag is optional and follows the same pattern used by
the install and upgrade commands.
Closes #XXXX
Signed-off-by: MrJack <36191829+biagiopietro@users.noreply.github.com>
2 months ago
Terry Howe
8eb65528be
Merge pull request #32467 from mmorel-35/testify-assertions-pkg-3
...
chore(pkg): refactor: finer tests conversions to testify part 3
2 months ago
Matthieu MOREL
622f16b37f
Update resource_test.go
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
61d99a8bdb
Update labels_test.go
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
532eabf88a
Update chartrepo_test.go
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
bfca0688b1
Update show_test.go
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
b59dfd3901
Update rollback_test.go
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
a27f3a0620
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Terry Howe
e29e06e97d
Merge pull request #32466 from mmorel-35/testify-assertions-pkg-2
...
chore(pkg): refactor: finer tests conversions to testify part 2
2 months ago
Terry Howe
b152447a15
Merge pull request #32465 from mmorel-35/testify-assertions-internal-1
...
chore(internal): refactor: finer tests conversions to testify part 1
2 months ago
Terry Howe
c994f2a36a
Merge pull request #32464 from mmorel-35/testify-assertions-pkg-1
...
chore(pkg): refactor: finer tests conversions to testify part 1
2 months ago
Matthieu MOREL
828d01a878
chore(pkg): refactor: finer tests conversions to testify part 1
...
refactor: finer tests conversions to testify in pkg/strvals
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
9a2be11e6f
chore(pkg): refactor: finer tests conversions to testify part 3
...
refactor: finer tests conversions to testify in pkg/cmd
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
4d9c03f51c
chore(pkg): refactor: finer tests conversions to testify part 2
...
#### Description
refactor: finer tests conversions to testify in pkg/storage/driver
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
Matthieu MOREL
5142ca8ddc
chore(internal): refactor: finer tests conversions to testify part 1
...
#### Description
refactor: finer tests conversions to testify in internal/chart/v3/util
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
2 months ago
dependabot[bot]
8f74dce6ba
chore(deps): bump the k8s-io group across 1 directory with 7 updates ( #32459 )
...
Bumps the k8s-io group with 4 updates in the / directory: [k8s.io/api](https://github.com/kubernetes/api ), [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver ), [k8s.io/cli-runtime](https://github.com/kubernetes/cli-runtime ) and [k8s.io/kubectl](https://github.com/kubernetes/kubectl ).
Updates `k8s.io/api` from 0.36.2 to 0.36.3
- [Commits](https://github.com/kubernetes/api/compare/v0.36.2...v0.36.3 )
Updates `k8s.io/apiextensions-apiserver` from 0.36.2 to 0.36.3
- [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases )
- [Commits](https://github.com/kubernetes/apiextensions-apiserver/compare/v0.36.2...v0.36.3 )
Updates `k8s.io/apimachinery` from 0.36.2 to 0.36.3
- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.36.2...v0.36.3 )
Updates `k8s.io/apiserver` from 0.36.2 to 0.36.3
- [Commits](https://github.com/kubernetes/apiserver/compare/v0.36.2...v0.36.3 )
Updates `k8s.io/cli-runtime` from 0.36.2 to 0.36.3
- [Commits](https://github.com/kubernetes/cli-runtime/compare/v0.36.2...v0.36.3 )
Updates `k8s.io/client-go` from 0.36.2 to 0.36.3
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md )
- [Commits](https://github.com/kubernetes/client-go/compare/v0.36.2...v0.36.3 )
Updates `k8s.io/kubectl` from 0.36.2 to 0.36.3
- [Commits](https://github.com/kubernetes/kubectl/compare/v0.36.2...v0.36.3 )
---
updated-dependencies:
- dependency-name: k8s.io/api
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
- dependency-name: k8s.io/apiextensions-apiserver
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
- dependency-name: k8s.io/apimachinery
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
- dependency-name: k8s.io/apiserver
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
- dependency-name: k8s.io/cli-runtime
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
- dependency-name: k8s.io/client-go
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
- dependency-name: k8s.io/kubectl
dependency-version: 0.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: k8s-io
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 months ago
dependabot[bot]
050d3e99b9
chore(deps): bump ossf/scorecard-action in the github-actions group ( #32458 )
...
Bumps the github-actions group with 1 update: [ossf/scorecard-action](https://github.com/ossf/scorecard-action ).
Updates `ossf/scorecard-action` from 2.4.3 to 2.4.4
- [Release notes](https://github.com/ossf/scorecard-action/releases )
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md )
- [Commits](4eaacf0543...2d1146689b )
---
updated-dependencies:
- dependency-name: ossf/scorecard-action
dependency-version: 2.4.4
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2 months ago
Robert Sirchia
39231d01e1
Merge pull request #32435 from mmorel-35/testifylint-manual-assert-pkg-19
...
chore(pkg): refactor: convert tests to testify assert/require part 19
2 months ago