Skip to content

Dependabot/go modules/golang.org/x/crypto 0.45.0#371

Open
hlipsig wants to merge 21 commits intorelease-4.19from
dependabot/go_modules/golang.org/x/crypto-0.45.0
Open

Dependabot/go modules/golang.org/x/crypto 0.45.0#371
hlipsig wants to merge 21 commits intorelease-4.19from
dependabot/go_modules/golang.org/x/crypto-0.45.0

Conversation

@hlipsig
Copy link
Copy Markdown
Contributor

@hlipsig hlipsig commented Nov 26, 2025

Dependency bumps should be double checked against the active release branch before merge to main.

rhamitarora and others added 21 commits July 14, 2025 16:00
[ARO-20321] Don't check for availability zones in bad regions (like centraluseuap)
ARO-14269 Fluentbit update to latest support version 4.0.4
Add red-hat-managed: true tag to install-config
  - GHSA-qxp5-gwg8-xv66
  - GHSA-vvgc-356p-c3xw (CVE-2025-22872)
- Updated related dependencies (x/crypto, x/sync, x/sys, x/term, x/text)

System library vulnerabilities (glibc, krb5, libxml2) will be fixed on image rebuild.
ARO-21088: Installer vulnerabilities September 2025
Revert "Add red-hat-managed: true tag to install-config"
Signed-off-by: Daniel J. Holmes (jaitaiwan) <daholmes@redhat.com>
Signed-off-by: Daniel J. Holmes (jaitaiwan) <daholmes@redhat.com>
Signed-off-by: Daniel J. Holmes (jaitaiwan) <daholmes@redhat.com>
Signed-off-by: Daniel J. Holmes (jaitaiwan) <daholmes@redhat.com>
Signed-off-by: Daniel J. Holmes (jaitaiwan) <daholmes@redhat.com>
Remove pkg/api in favour of ARO-RP/pkg/api
Split image configuration into granular build args for better flexibility:

Builder image args:
- BUILDER_REGISTRY (default: registry.ci.openshift.org)
- BUILDER_REPOSITORY (default: ocp/builder)
- BUILDER_TAG (default: rhel-9-golang-1.24-openshift-4.20)

Base image args:
- REGISTRY (default: registry.access.redhat.com)
- REPOSITORY (default: ubi9/ubi-minimal)
- TAG (default: latest)

This allows customizing individual components (registry, repository, or tag)
without modifying the Dockerfile, making it more flexible for different
environments (e.g., using MCR images for OneBranch pipelines).

Defaults maintain existing behavior.
…d-images

Make builder and base images configurable via build args
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.36.0 to 0.45.0.
- [Commits](golang/crypto@v0.36.0...v0.45.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.45.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@openshift-merge-robot
Copy link
Copy Markdown
Contributor

PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-merge-robot openshift-merge-robot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Nov 26, 2025
@openshift-ci openshift-ci Bot requested a review from kimorris27 November 26, 2025 21:46
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Nov 26, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hlipsig

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot requested a review from petrkotas November 26, 2025 21:46
@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 26, 2025
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Dec 3, 2025

@hlipsig: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/vendor d0c0410 link true /test vendor
ci/prow/images d0c0410 link true /test images
ci/prow/lint d0c0410 link true /test lint
ci/prow/unit d0c0410 link true /test unit
ci/prow/validate d0c0410 link true /test validate

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-bot
Copy link
Copy Markdown

Issues go stale after 90d of inactivity.

Mark the issue as fresh by commenting /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.
Exclude this issue from closing by commenting /lifecycle frozen.

If this issue is safe to close now please do so with /close.

/lifecycle stale

@openshift-ci openshift-ci Bot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Mar 3, 2026
@openshift-bot
Copy link
Copy Markdown

Stale issues rot after 30d of inactivity.

Mark the issue as fresh by commenting /remove-lifecycle rotten.
Rotten issues close after an additional 30d of inactivity.
Exclude this issue from closing by commenting /lifecycle frozen.

If this issue is safe to close now please do so with /close.

/lifecycle rotten
/remove-lifecycle stale

@openshift-ci openshift-ci Bot added lifecycle/rotten Denotes an issue or PR that has aged beyond stale and will be auto-closed. and removed lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. labels Apr 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lifecycle/rotten Denotes an issue or PR that has aged beyond stale and will be auto-closed. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD.

Projects

None yet

Development

Successfully merging this pull request may close these issues.