Bump the go_modules group across 2 directories with 13 updates - #1482
Bump the go_modules group across 2 directories with 13 updates#1482dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the go_modules group with 10 updates in the /tests/e2e directory: | Package | From | To | | --- | --- | --- | | [github.com/cloudflare/circl](https://github.com/cloudflare/circl) | `1.6.0` | `1.6.3` | | [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) | `4.1.1` | `4.1.4` | | [github.com/google/cel-go](https://github.com/google/cel-go) | `0.26.1` | `0.29.0` | | [github.com/microsoft/kiota-http-go](https://github.com/microsoft/kiota-http-go) | `1.5.2` | `1.5.5` | | [github.com/moby/spdystream](https://github.com/moby/spdystream) | `0.5.0` | `0.5.1` | | [go.mongodb.org/mongo-driver](https://github.com/mongodb/mongo-go-driver) | `1.17.3` | `1.17.7` | | [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) | `1.37.0` | `1.41.0` | | [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.37.0` | `1.43.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.47.0` | `0.52.0` | | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.75.1` | `1.82.1` | Bumps the go_modules group with 6 updates in the /tests/integration directory: | Package | From | To | | --- | --- | --- | | [github.com/google/cel-go](https://github.com/google/cel-go) | `0.22.1` | `0.29.0` | | [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) | `1.42.0` | `1.43.0` | | [golang.org/x/crypto](https://github.com/golang/crypto) | `0.48.0` | `0.52.0` | | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.79.3` | `1.82.1` | | [github.com/go-git/go-billy/v5](https://github.com/go-git/go-billy) | `5.6.1` | `5.9.0` | | [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.13.1` | `5.19.1` | Updates `github.com/cloudflare/circl` from 1.6.0 to 1.6.3 - [Release notes](https://github.com/cloudflare/circl/releases) - [Commits](cloudflare/circl@v1.6.0...v1.6.3) Updates `github.com/go-jose/go-jose/v4` from 4.1.1 to 4.1.4 - [Release notes](https://github.com/go-jose/go-jose/releases) - [Commits](go-jose/go-jose@v4.1.1...v4.1.4) Updates `github.com/google/cel-go` from 0.26.1 to 0.29.0 - [Release notes](https://github.com/google/cel-go/releases) - [Commits](cel-expr/cel-go@v0.26.1...v0.29.0) Updates `github.com/microsoft/kiota-http-go` from 1.5.2 to 1.5.5 - [Release notes](https://github.com/microsoft/kiota-http-go/releases) - [Changelog](https://github.com/microsoft/kiota-http-go/blob/main/CHANGELOG.md) - [Commits](microsoft/kiota-http-go@v1.5.2...v1.5.5) Updates `github.com/moby/spdystream` from 0.5.0 to 0.5.1 - [Release notes](https://github.com/moby/spdystream/releases) - [Commits](moby/spdystream@v0.5.0...v0.5.1) Updates `go.mongodb.org/mongo-driver` from 1.17.3 to 1.17.7 - [Release notes](https://github.com/mongodb/mongo-go-driver/releases) - [Commits](mongodb/mongo-go-driver@v1.17.3...v1.17.7) Updates `go.opentelemetry.io/otel` from 1.37.0 to 1.41.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.37.0...v1.41.0) Updates `go.opentelemetry.io/otel/sdk` from 1.37.0 to 1.43.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.37.0...v1.43.0) Updates `golang.org/x/crypto` from 0.47.0 to 0.52.0 - [Commits](golang/crypto@v0.47.0...v0.52.0) Updates `golang.org/x/net` from 0.49.0 to 0.54.0 - [Commits](golang/net@v0.49.0...v0.54.0) Updates `google.golang.org/grpc` from 1.75.1 to 1.82.1 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.75.1...v1.82.1) Updates `github.com/google/cel-go` from 0.22.1 to 0.29.0 - [Release notes](https://github.com/google/cel-go/releases) - [Commits](cel-expr/cel-go@v0.26.1...v0.29.0) Updates `go.opentelemetry.io/otel/sdk` from 1.42.0 to 1.43.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-go@v1.37.0...v1.43.0) Updates `golang.org/x/crypto` from 0.48.0 to 0.52.0 - [Commits](golang/crypto@v0.47.0...v0.52.0) Updates `golang.org/x/net` from 0.51.0 to 0.54.0 - [Commits](golang/net@v0.49.0...v0.54.0) Updates `google.golang.org/grpc` from 1.79.3 to 1.82.1 - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.75.1...v1.82.1) Updates `github.com/go-git/go-billy/v5` from 5.6.1 to 5.9.0 - [Release notes](https://github.com/go-git/go-billy/releases) - [Commits](go-git/go-billy@v5.6.1...v5.9.0) Updates `github.com/go-git/go-git/v5` from 5.13.1 to 5.19.1 - [Release notes](https://github.com/go-git/go-git/releases) - [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md) - [Commits](go-git/go-git@v5.13.1...v5.19.1) --- updated-dependencies: - dependency-name: github.com/cloudflare/circl dependency-version: 1.6.3 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/go-jose/go-jose/v4 dependency-version: 4.1.4 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/google/cel-go dependency-version: 0.29.0 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/microsoft/kiota-http-go dependency-version: 1.5.5 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/moby/spdystream dependency-version: 0.5.1 dependency-type: indirect dependency-group: go_modules - dependency-name: go.mongodb.org/mongo-driver dependency-version: 1.17.7 dependency-type: indirect dependency-group: go_modules - dependency-name: go.opentelemetry.io/otel dependency-version: 1.41.0 dependency-type: indirect dependency-group: go_modules - dependency-name: go.opentelemetry.io/otel/sdk dependency-version: 1.43.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.54.0 dependency-type: indirect dependency-group: go_modules - dependency-name: google.golang.org/grpc dependency-version: 1.82.1 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/google/cel-go dependency-version: 0.29.0 dependency-type: indirect dependency-group: go_modules - dependency-name: go.opentelemetry.io/otel/sdk dependency-version: 1.43.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/crypto dependency-version: 0.52.0 dependency-type: indirect dependency-group: go_modules - dependency-name: golang.org/x/net dependency-version: 0.54.0 dependency-type: indirect dependency-group: go_modules - dependency-name: google.golang.org/grpc dependency-version: 1.82.1 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/go-git/go-billy/v5 dependency-version: 5.9.0 dependency-type: indirect dependency-group: go_modules - dependency-name: github.com/go-git/go-git/v5 dependency-version: 5.19.1 dependency-type: indirect dependency-group: go_modules ... Signed-off-by: dependabot[bot] <support@github.com>
|
Pipeline controller notification For optional jobs, comment This repository is configured in: LGTM mode |
WalkthroughThis pull request updates dependency declarations in two go.mod files under the tests directory. It bumps the Go version requirement in tests/e2e/go.mod, refreshes numerous indirect dependency versions in both modules, adds go-git and gotest.tools/v3 dependencies, and removes several obsolete indirect dependencies. ChangesGo module dependency updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/ok-to-test |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
tests/e2e/go.mod (1)
3-3: 🔒 Security & Privacy | 🔵 TrivialUse a patched Go 1.25.x or newer toolchain in CI.
Dockerfile.tests-extensionuses Go 1.24 withGOTOOLCHAIN=auto;go 1.25.0can therefore select the unpatchedgo1.25.0toolchain. Use Go 1.25.12 or newer in the builder image. Keepgo 1.25.0as the module minimum if required.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@tests/e2e/go.mod` at line 3, Update the Go toolchain used by Dockerfile.tests-extension to Go 1.25.12 or newer so CI never selects the unpatched Go 1.25.0 toolchain; keep the go 1.25.0 directive in tests/e2e/go.mod unchanged as the module minimum.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/e2e/go.mod`:
- Around line 17-21: The tests/e2e go.mod has a broken dependency chain where
k8s.io/kubernetes v1.34.1 requires the unpublished k8s.io/externaljwt v0.0.0,
which prevents graph download. Additionally, there are unaddressed OSV findings
across Kubernetes, AWS SDK, Docker, runc, golang.org/x modules, and
OpenTelemetry. Update k8s.io/kubernetes to a consumable version without this
broken transitive dependency, then systematically address each OSV finding by
upgrading to patched versions, removing unused modules, or documenting
acceptance. Record license compatibility for all dependencies, run go mod verify
on the complete graph, and run OSV scanning. If build artifacts are produced,
emit a signed SBOM and provenance attestation and verify artifact signatures.
In `@tests/integration/go.mod`:
- Line 88: Align the OpenTelemetry dependencies declared in
tests/integration/go.mod to one consistent release line, preferably v1.44.0.
Update the SDK, SDK metric, and SDK log modules alongside the core, metric, and
trace modules so all OpenTelemetry components use matching compatible versions.
---
Nitpick comments:
In `@tests/e2e/go.mod`:
- Line 3: Update the Go toolchain used by Dockerfile.tests-extension to Go
1.25.12 or newer so CI never selects the unpatched Go 1.25.0 toolchain; keep the
go 1.25.0 directive in tests/e2e/go.mod unchanged as the module minimum.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 6d8674a2-061b-4ba9-a80f-adfcafade26b
⛔ Files ignored due to path filters (2)
tests/e2e/go.sumis excluded by!**/*.sumtests/integration/go.sumis excluded by!**/*.sum
📒 Files selected for processing (2)
tests/e2e/go.modtests/integration/go.mod
| cel.dev/expr v0.25.1 // indirect | ||
| cloud.google.com/go v0.121.6 // indirect | ||
| cloud.google.com/go/auth v0.16.5 // indirect | ||
| cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect | ||
| cloud.google.com/go/compute/metadata v0.8.0 // indirect | ||
| cloud.google.com/go/compute/metadata v0.9.0 // indirect |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
for dir in tests/e2e tests/integration; do
tmp="$(mktemp -d)"
cp -a "$dir"/. "$tmp"/
(
cd "$tmp"
go mod tidy
go mod download all
go mod verify
)
diff -u "$dir/go.mod" "$tmp/go.mod"
diff -u "$dir/go.sum" "$tmp/go.sum"
doneRepository: openshift/oc-mirror
Length of output: 378
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- module files ---'
for f in tests/e2e/go.mod tests/integration/go.mod tests/e2e/go.sum tests/integration/go.sum; do
if [ -f "$f" ]; then
printf '\n[%s]\n' "$f"
wc -l "$f"
sed -n '1,280p' "$f"
fi
done
printf '%s\n' '--- repository changes ---'
git diff --stat
git status --short
printf '%s\n' '--- build, SBOM, provenance, and signing references ---'
rg -n -i --glob '!vendor/**' \
'syft|sbom|cyclonedx|spdx|provenance|attest|cosign|sigstore|slsa|go mod verify|osv|govulncheck' \
.github .tekton Makefile* Dockerfile* tests 2>/dev/null || true
printf '%s\n' '--- dependency and license metadata ---'
find . -maxdepth 3 -type f \( -iname 'LICENSE*' -o -iname 'NOTICE*' -o -iname 'THIRD_PARTY*' -o -iname 'bom*' \) -printRepository: openshift/oc-mirror
Length of output: 50376
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- invalid module references ---'
rg -n -C 3 'k8s\.io/externaljwt|v0\.0\.0' --glob 'go.mod' --glob 'go.sum' .
printf '%s\n' '--- relevant diffs ---'
git diff -- tests/e2e/go.mod tests/e2e/go.sum tests/integration/go.mod tests/integration/go.sum | \
rg -n -C 4 '^(\+|-)($|[^+-])|^@@' | head -n 500 || true
printf '%s\n' '--- workflow and build files ---'
git ls-files '.github/**' '.tekton/**' 'Makefile*' 'Dockerfile*' 'hack/**' | head -n 300
printf '%s\n' '--- supply-chain controls ---'
rg -n -i --glob '!**/go.sum' --glob '!vendor/**' \
'osv|govulncheck|license|sbom|cyclonedx|spdx|syft|provenance|attestation|cosign|sigstore|slsa|rekor|go mod verify' \
.github .tekton Makefile* Dockerfile* hack tests 2>/dev/null | head -n 500 || trueRepository: openshift/oc-mirror
Length of output: 50376
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- exact externaljwt references ---'
rg -n -F 'k8s.io/externaljwt' . || true
printf '%s\n' '--- exact zero-version references in module manifests ---'
rg -n -F 'k8s.io/externaljwt v0.0.0' --glob 'go.mod' --glob 'go.sum' . || true
printf '%s\n' '--- changed files and changed module lines ---'
git diff --name-status
git diff --numstat
git diff --unified=0 -- tests/e2e/go.mod tests/e2e/go.sum tests/integration/go.mod tests/integration/go.sum | \
sed -n '1,500p'
printf '%s\n' '--- control-file paths ---'
git ls-files | rg '(^|/)(\.github|\.tekton|Makefile|Dockerfile|hack)(/|$)' | head -n 300
printf '%s\n' '--- supply-chain control matches outside dependency lockfiles ---'
rg -n -i \
--glob '!**/go.sum' \
--glob '!**/vendor/**' \
--glob '!**/node_modules/**' \
'osv|govulncheck|license|sbom|cyclonedx|spdx|syft|provenance|attestation|cosign|sigstore|slsa|rekor|go mod verify' \
.github .tekton Makefile* Dockerfile* hack tests 2>/dev/null | head -n 300 || trueRepository: openshift/oc-mirror
Length of output: 50375
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- transitive module metadata ---'
for spec in \
'k8s.io/kubernetes v1.34.1' \
'k8s.io/apimachinery v0.34.1' \
'k8s.io/component-base v0.34.1' \
'github.com/openshift/origin v1.5.2' \
'github.com/openshift-eng/openshift-tests-extension v0.0.0-20260127124016-0fed2b824818'
do
module="${spec% *}"
version="${spec##* }"
url="https://proxy.golang.org/${module}/@v/${version}.mod"
printf '\n[%s]\n' "$url"
curl -fsSL "$url" | rg -n -C 2 'externaljwt|require \(' || true
done
printf '%s\n' '--- OSV results for declared test-module requirements ---'
python3 - <<'PY'
import json
import re
import urllib.request
mods = []
for path in ("tests/e2e/go.mod", "tests/integration/go.mod"):
text = open(path, encoding="utf-8").read()
for module, version in re.findall(r"^\s*([^\s]+)\s+([^\s]+)(?:\s+//.*)?$", text, re.M):
if module == "module" or module == "go" or version.startswith("("):
continue
mods.append({"package": {"name": module, "ecosystem": "Go"}, "version": version})
# Remove duplicate module/version queries.
queries = []
seen = set()
for item in mods:
key = (item["package"]["name"], item["version"])
if key not in seen:
seen.add(key)
queries.append(item)
payload = json.dumps({"queries": queries}).encode()
request = urllib.request.Request(
"https://api.osv.dev/v1/querybatch",
data=payload,
headers={"Content-Type": "application/json"},
)
with urllib.request.urlopen(request, timeout=60) as response:
result = json.load(response)
findings = []
for query, result_item in zip(queries, result.get("results", [])):
vulns = result_item.get("vulns") or []
if vulns:
findings.append({
"module": query["package"]["name"],
"version": query["version"],
"ids": [v.get("id") for v in vulns],
})
print(json.dumps({
"queried": len(queries),
"vulnerable_requirements": findings,
}, indent=2, sort_keys=True))
PYRepository: openshift/oc-mirror
Length of output: 5729
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
printf '%s\n' '--- transitive module metadata ---'
for spec in \
'k8s.io/kubernetes v1.34.1' \
'k8s.io/apimachinery v0.34.1' \
'k8s.io/component-base v0.34.1' \
'github.com/openshift/origin v1.5.2' \
'github.com/openshift-eng/openshift-tests-extension v0.0.0-20260127124016-0fed2b824818'
do
module="${spec% *}"
version="${spec##* }"
url="https://proxy.golang.org/${module}/@v/${version}.mod"
printf '\n[%s]\n' "$url"
curl -fsSL "$url" | rg -n -C 2 'externaljwt|require \(' || true
done
printf '%s\n' '--- OSV results for declared test-module requirements ---'
python3 - <<'PY'
import json
import re
import urllib.request
mods = []
for path in ("tests/e2e/go.mod", "tests/integration/go.mod"):
text = open(path, encoding="utf-8").read()
for module, version in re.findall(r"^\s*([^\s]+)\s+([^\s]+)(?:\s+//.*)?$", text, re.M):
if module == "module" or module == "go" or version.startswith("("):
continue
mods.append({"package": {"name": module, "ecosystem": "Go"}, "version": version})
queries = []
seen = set()
for item in mods:
key = (item["package"]["name"], item["version"])
if key not in seen:
seen.add(key)
queries.append(item)
payload = json.dumps({"queries": queries}).encode()
request = urllib.request.Request(
"https://api.osv.dev/v1/querybatch",
data=payload,
headers={"Content-Type": "application/json"},
)
with urllib.request.urlopen(request, timeout=60) as response:
result = json.load(response)
findings = []
for query, result_item in zip(queries, result.get("results", [])):
vulns = result_item.get("vulns") or []
if vulns:
findings.append({
"module": query["package"]["name"],
"version": query["version"],
"ids": [v.get("id") for v in vulns],
})
print(json.dumps({
"queried": len(queries),
"vulnerable_requirements": findings,
}, indent=2, sort_keys=True))
PYRepository: openshift/oc-mirror
Length of output: 5729
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
for dir in tests/e2e tests/integration; do
printf '\n--- %s: go mod download ---\n' "$dir"
(
cd "$dir"
go mod download all
) 2>&1 || true
printf '%s\n' "--- $dir: go mod verify ---"
(
cd "$dir"
go mod verify
) 2>&1 || true
done
printf '%s\n' '--- OSV results for declared requirements ---'
python3 - <<'PY' >/tmp/osv-queries.json
import json
import re
queries = []
seen = set()
for path in ("tests/e2e/go.mod", "tests/integration/go.mod"):
text = open(path, encoding="utf-8").read()
for line in text.splitlines():
match = re.match(r"^\s*([^\s()]+)\s+([^\s]+)(?:\s+//.*)?$", line)
if not match:
continue
module, version = match.groups()
if module in {"module", "go"}:
continue
key = (module, version)
if key not in seen:
seen.add(key)
queries.append({
"package": {"name": module, "ecosystem": "Go"},
"version": version,
})
json.dump({"queries": queries}, __import__("sys").stdout)
PY
curl -ksSf \
-H 'Content-Type: application/json' \
--data-binary `@/tmp/osv-queries.json` \
https://api.osv.dev/v1/querybatch |
python3 -c '
import json, sys
data=json.load(sys.stdin)
findings=[]
for query, result in zip(json.load(open("/tmp/osv-queries.json"))["queries"], data.get("results", [])):
vulns=result.get("vulns") or []
if vulns:
findings.append({
"module": query["package"]["name"],
"version": query["version"],
"ids": [v["id"] for v in vulns],
})
print(json.dumps({"queried": len(json.load(open("/tmp/osv-queries.json"))["queries"]), "findings": findings}, indent=2))
'Repository: openshift/oc-mirror
Length of output: 3482
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
for dir in tests/e2e tests/integration; do
printf '\n--- %s: go mod download ---\n' "$dir"
(
cd "$dir"
go mod download all
) 2>&1 || true
printf '%s\n' "--- $dir: go mod verify ---"
(
cd "$dir"
go mod verify
) 2>&1 || true
done
printf '%s\n' '--- OSV results for declared requirements ---'
python3 - <<'PY' >/tmp/osv-queries.json
import json
import re
queries = []
seen = set()
for path in ("tests/e2e/go.mod", "tests/integration/go.mod"):
text = open(path, encoding="utf-8").read()
for line in text.splitlines():
match = re.match(r"^\s*([^\s()]+)\s+([^\s]+)(?:\s+//.*)?$", line)
if not match:
continue
module, version = match.groups()
if module in {"module", "go"}:
continue
key = (module, version)
if key not in seen:
seen.add(key)
queries.append({
"package": {"name": module, "ecosystem": "Go"},
"version": version,
})
json.dump({"queries": queries}, __import__("sys").stdout)
PY
curl -ksSf \
-H 'Content-Type: application/json' \
--data-binary `@/tmp/osv-queries.json` \
https://api.osv.dev/v1/querybatch |
python3 -c '
import json, sys
data=json.load(sys.stdin)
queries=json.load(open("/tmp/osv-queries.json"))["queries"]
findings=[]
for query, result in zip(queries, data.get("results", [])):
vulns=result.get("vulns") or []
if vulns:
findings.append({
"module": query["package"]["name"],
"version": query["version"],
"ids": [v["id"] for v in vulns],
})
print(json.dumps({"queried": len(queries), "findings": findings}, indent=2))
'Repository: openshift/oc-mirror
Length of output: 3482
Fix the dependency graph and triage OSV findings before merge.
tests/e2e cannot download its graph because k8s.io/kubernetes v1.34.1 requires k8s.io/externaljwt v0.0.0, which has no published revision. Use a consumable module version. The passing go mod verify result does not cover the failed download.
The declared graph contains OSV findings for Kubernetes, AWS SDK, Docker, runc, golang.org/x/{crypto,net,text}, and OpenTelemetry modules. Upgrade, remove, or document each finding. Record license compatibility. Then run go mod verify and OSV against the complete graph. If this build produces artifacts, emit a signed SBOM and provenance attestation, and verify artifact signatures with Sigstore/cosign.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@tests/e2e/go.mod` around lines 17 - 21, The tests/e2e go.mod has a broken
dependency chain where k8s.io/kubernetes v1.34.1 requires the unpublished
k8s.io/externaljwt v0.0.0, which prevents graph download. Additionally, there
are unaddressed OSV findings across Kubernetes, AWS SDK, Docker, runc,
golang.org/x modules, and OpenTelemetry. Update k8s.io/kubernetes to a
consumable version without this broken transitive dependency, then
systematically address each OSV finding by upgrading to patched versions,
removing unused modules, or documenting acceptance. Record license compatibility
for all dependencies, run go mod verify on the complete graph, and run OSV
scanning. If build artifacts are produced, emit a signed SBOM and provenance
attestation and verify artifact signatures.
Source: Path instructions
| go.opentelemetry.io/contrib/exporters/autoexport v0.67.0 // indirect | ||
| go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.67.0 // indirect | ||
| go.opentelemetry.io/otel v1.42.0 // indirect | ||
| go.opentelemetry.io/otel v1.44.0 // indirect |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/usr/bin/env bash
set -euo pipefail
cd tests/integration
main_go="$(awk '$1 == "go" { print $2; exit }' go.mod)"
printf 'module Go requirement: %s\n' "$main_go"
for module in \
go.opentelemetry.io/otel \
go.opentelemetry.io/otel/metric \
go.opentelemetry.io/otel/trace \
go.opentelemetry.io/otel/sdk \
go.opentelemetry.io/otel/sdk/metric \
go.opentelemetry.io/otel/sdk/log
do
go list -m -json "$module" | jq '{Path, Version, GoVersion}'
done
test "$(printf '%s\n' "$main_go" '1.25.0' | sort -V | tail -n1)" = "$main_go"Repository: openshift/oc-mirror
Length of output: 763
Align OpenTelemetry dependency versions across the release train.
The module declares three different OpenTelemetry release lines: core (go.opentelemetry.io/otel), metric, and trace at v1.44.0; SDK and SDK metric at v1.43.0; and SDK log at v0.18.0. The SDK log version v0.18.0 corresponds to the v1.42.0 release line, creating version skew across the dependency graph. Align all OpenTelemetry modules to a single release line—typically the newest—to ensure API and SDK compatibility. The module already requires Go 1.25.0, which satisfies all component minimum Go requirements.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@tests/integration/go.mod` at line 88, Align the OpenTelemetry dependencies
declared in tests/integration/go.mod to one consistent release line, preferably
v1.44.0. Update the SDK, SDK metric, and SDK log modules alongside the core,
metric, and trace modules so all OpenTelemetry components use matching
compatible versions.
|
@dependabot[bot]: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
rebase DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps the go_modules group with 10 updates in the /tests/e2e directory:
1.6.01.6.34.1.14.1.40.26.10.29.01.5.21.5.50.5.00.5.11.17.31.17.71.37.01.41.01.37.01.43.00.47.00.52.01.75.11.82.1Bumps the go_modules group with 6 updates in the /tests/integration directory:
0.22.10.29.01.42.01.43.00.48.00.52.01.79.31.82.15.6.15.9.05.13.15.19.1Updates
github.com/cloudflare/circlfrom 1.6.0 to 1.6.3Release notes
Sourced from github.com/cloudflare/circl's releases.
... (truncated)
Commits
24ae53cRelease CIRCL v1.6.3581020bRename method to oddMultiplesProjective.12209a4Removing unused cmov for jacobian points.fcba359ecc/p384: use of complete projective formulas for scalar multiplication.5e1bae8ecc/p384: handle point doubling in point addition with Jacobian coordinates.3416046Check opts for nil value.a763d47Release CIRCL v1.6.23c70bf9Bump x/crypto x/sys dependencies.3f0f15bRevert to using package-declared HPKE errors for shortkem instead of standard...23491bdAdding generic Power2Round method.Updates
github.com/go-jose/go-jose/v4from 4.1.1 to 4.1.4Release notes
Sourced from github.com/go-jose/go-jose/v4's releases.
Commits
0e59876Merge commit from forkddffdbcBump actions/checkout from 5 to 6 (#213)5348b9aReject JWS with an unprotected critical b64 header (#210)9153a5eBump actions/setup-python from 5 to 6 (#208)2126e17Bump actions/setup-go from 5 to 6 (#209)9860c65Bump actions/checkout from 4 to 5 (#206)14239fdRemove Go 1.23 support (#205)a16e158Update CI to run on Go 1.24 and 1.25 (#204)a1565a4testutils/assert: remove True, Nil, NotNil (#202)3a80e13jwe: accept non-pointer JSONWebKey in Recipient (#200)Updates
github.com/google/cel-gofrom 0.26.1 to 0.29.0Release notes
Sourced from github.com/google/cel-go's releases.
... (truncated)
Commits
fa16799avoid repeated construction of cost tracker (#1357)ea3d5c0feat(ext): add json encoder (#1340)a4d0d64startsWith / endsWith runtime cost agreement with checked cost (#1351)d4efa77Ensure receiver and global matches cost estimates agree (#1350)13cff33ext/lists: add max size check to genRange() to prevent OOM (#1310)f0ffa7eExecution frame integration with updated IntepretableV2 (#1344)f1ec2f6guard int32/uint32 map key narrowing in qualifyInternal (#1337)258e7c8Managed execution frame with async call foundations (#1316)14f6746validate offset on empty-string path in indexOf and lastIndexOf (#1335)783267dreject out-of-range minutes in timezone offset parsing (#1336)Updates
github.com/microsoft/kiota-http-gofrom 1.5.2 to 1.5.5Release notes
Sourced from github.com/microsoft/kiota-http-go's releases.
Changelog
Sourced from github.com/microsoft/kiota-http-go's changelog.
Commits
c6133feMerge pull request #223 from microsoft/release-please--branches--main--compon...cb68231chore(main): release 1.5.5fba6ba4Merge pull request #221 from microsoft/cobando/fix-redirect-vulnerability39fa46cupdating scrub func to use 2 instead of 3 paramsce4f0dcadding port conditione68b9e1adding senstive headers scrub functionf950250Merge pull request #220 from microsoft/ci/release-please-dispatch849a4eeci: adds workflow dispatch to release please7bdff1cMerge pull request #218 from microsoft/dependabot/github_actions/dependabot/f...85d1657chore(deps): bump dependabot/fetch-metadata from 2.4.0 to 2.5.0Updates
github.com/moby/spdystreamfrom 0.5.0 to 0.5.1Release notes
Sourced from github.com/moby/spdystream's releases.
Commits
c59e5d7Merge pull request #109 from thaJeztah/use_ioutil2fd0155use ioutil.Discard for go1.13 compatibilityef6121fMerge commit from fork241cec9compare with signed Int for 32-bit Arm21c3864Add options to customize limitsacf9b45spdy: update godoc for MaxDataLengtheb63605spdy: limit header-size and header-count2f21da4spdy: fix header block byte accounting5976b66spdy: enforce 24-bit frame length limitscf0ec5dGuard against oversized SPDY framesUpdates
go.mongodb.org/mongo-driverfrom 1.17.3 to 1.17.7Release notes
Sourced from go.mongodb.org/mongo-driver's releases.
... (truncated)
Commits
eb01e7eBUMP v1.17.73c55093GODRIVER-3766 Remove deprecation notice forMergeClientOptions(#2294)f6163bfGODRIVER-3770 Remove libasan from gssapi tests in CI (#2293)6798963GODRIVER-3770 Fix buffer handling in GSSAPI error description and username fu...c1e9575Add more visible deprecation banner to the 1.17 readme (#2233)d2fa0abBUMP v1.17.6f1d540bBUMP v1.17.5b879028GODRIVER-3654 Don't test v1 branches against latest server. (#2188)21f47d4Allow ignore-for-release label to satisfy label checker (#2203)8708ca8Disable merge-up from release/1.17 (#2202)Updates
go.opentelemetry.io/otelfrom 1.37.0 to 1.41.0Changelog
Sourced from go.opentelemetry.io/otel's changelog.
... (truncated)
Commits
4575a97Release 1.41.0/0.63.0/0.17.0/0.0.15 (#7977)66fc10dfix: add error handling for insecure HTTP endpoints with TLS client configura...76e6eecchore(deps): update github/codeql-action action to v4.32.5 (#7980)0d50f90Revert "Generate semconv/v1.40.0" (#7978)c38a4a5Generate semconv/v1.40.0 (#7929)0f1a224chore(deps): update module github.com/securego/gosec/v2 to v2.23.0 (#7899)c79ebf4chore(deps): update module github.com/daixiang0/gci to v0.14.0 (#7973)f758157chore(deps): update module github.com/sonatard/noctx to v0.5.0 (#7968)92a1164fix(deps): update github.com/opentracing-contrib/go-grpc/test digest to d566b...3cd7c27chore(deps): update module github.com/protonmail/go-crypto to v1.4.0 (#7969)Updates
go.opentelemetry.io/otel/sdkfrom 1.37.0 to 1.43.0Changelog
Sourced from go.opentelemetry.io/otel/sdk's changelog.
... (truncated)
Commits
9276201Release v1.43.0 / v0.65.0 / v0.19.0 (#8128)61b8c94chore(deps): update module github.com/mattn/go-runewidth to v0.0.22 (#8131)97a086echore(deps): update github.com/golangci/dupl digest to c99c5cf (#8122)5e363delimit response body size for OTLP HTTP exporters (#8108)35214b6Use an absolute path when calling bsd kenv (#8113)290024cfix(deps): update module google.golang.org/grpc to v1.80.0 (#8121)