b303fae0 chore: update debian-base to bookworm-v1.0.1
v1.4.1 - 2024-01-16
Changelog
Continuous Integration 💜
10b07c1c ci: remove low quota regions for aks windows job
d4e169bf ci: remove aks-engine job templates
80637cac ci: add script for aks windows cluster
Maintenance 🔧
2884c1d2 chore: bump version to v1.4.1 in release-1.4
b9101a72 chore: update to go 1.21.6 in docker
Security Fix 🛡️
eb644a30 security: bump golang.org/x/crypto to v0.17.0 to fix CVE-2023-48795
v1.4.0 - 2023-11-20
Breaking Changes ⚠️
total_ prefix in the metrics name has been dropped as part of the latest otel bump in the driver. For Prometheus counters, by default the otel library appends total suffix.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the k8s-go-deps group with 4 updates in the / directory: k8s.io/api, k8s.io/apiextensions-apiserver, sigs.k8s.io/controller-runtime and sigs.k8s.io/secrets-store-csi-driver.
Updates
k8s.io/api
from 0.29.5 to 0.30.2Commits
118f81c
Update dependencies to v0.30.2 tag0fd470c
Merge pull request #124702aojea/automated-cherry-pick-of-#124572
a669f18
Merge pull request #124694 from pmalek/backport-124553-to-release-1.3015001b5
fix(api): make LocalObjectReference.Name and HostAlias.IP required (#124553)d9a08c5
tag service.spec.TrafficDistribution field as alphad014286
Merge remote-tracking branch 'origin/master' into release-1.30581c1b8
Update x/net for CVE-2023-4528835ca1f4
Merge pull request #123932 from pohly/dra-api-resource-model-renameb048bd8
Merge pull request #123909 from AkihiroSuda/fix-123906f06d24a
dra api: NodeResourceModel -> ResourceModelUpdates
k8s.io/apiextensions-apiserver
from 0.29.5 to 0.30.2Commits
2d2addc
Update dependencies to v0.30.2 tag803669d
Merge pull request #124676cici37/automated-cherry-pick-of-#124675
5e9c693
Adding the feature gates to fix cost for VAP and webhook matchConditions.cb47ad4
Merge remote-tracking branch 'origin/master' into release-1.306ce7f38
Update x/net for CVE-2023-45288a2f312c
Merge remote-tracking branch 'origin/master' into release-1.30d3649bc
fix test flake caused by not waiting for CRD schema update9624e52
Merge pull request #123732 from serathius/parallel-featureflags24438a9
Merge pull request #123758 from liggitt/protobump916521e
Bump github.com/golang/protobuf v1.5.4, google.golang.org/protobuf v1.33.0Updates
k8s.io/apimachinery
from 0.29.5 to 0.30.2Commits
37988e5
Merge remote-tracking branch 'origin/master' into release-1.30c857a38
Update x/net for CVE-2023-452880407311
followup to allow special characters25164f7
Merge pull request #123435 from tallclair/apparmor-gacbfe0a1
Merge pull request #123758 from liggitt/protobump21d26b6
Bump github.com/golang/protobuf v1.5.4, google.golang.org/protobuf v1.33.00c29f84
Merge pull request #123385 from HirazawaUi/allow-special-characters60d24f2
Merge pull request #123708 from p0lyn0mial/upstream-const-watchlist-bookmark-...513d23a
apimachinery/meta/types.go: define InitialEventsAnnotationKey const67cb3a8
Merge pull request #123413 from seans3/tunneling-spdy-websocketsUpdates
k8s.io/client-go
from 0.29.5 to 0.30.2Commits
592d891
Update dependencies to v0.30.2 tag4e1652b
Merge pull request #124694 from pmalek/backport-124553-to-release-1.302daa31e
fix(api): make LocalObjectReference.Name and HostAlias.IP required (#124553)2df4de1
Merge remote-tracking branch 'origin/master' into release-1.30ade2ae2
Update x/net for CVE-2023-45288b4632b7
Merge pull request #123932 from pohly/dra-api-resource-model-rename4467b1e
Merge pull request #123909 from AkihiroSuda/fix-123906650f392
dra api: NodeResourceModel -> ResourceModel00e4609
api: NodeStatus: rename RuntimeClasses to RuntimeHandlers7ebe0ea
Merge pull request #123180 from AkihiroSuda/rroUpdates
sigs.k8s.io/controller-runtime
from 0.17.5 to 0.18.4Release notes
Sourced from sigs.k8s.io/controller-runtime's releases.
... (truncated)
Commits
12cc8d5
Merge pull request #2848 from k8s-infra-cherrypick-robot/cherry-pick-2847-to-...c0c229e
controllerutil: allow configuring BlockOwnerDeletion when setting OwnerRefere...be2f383
Merge pull request #2840 from sbueringer/pr-bump-k8s4720d17
Bump k8s.io/* to v0.30.1aa9ed14
Merge pull request #2837 from sbueringer/pr-setup-envtest-ct-rel-0.1835d7bbd
default --use-deprecated-gcs to truece4e4f5
some more deprecations56dcc14
setup-envtest: allow downloading envtest binaries from controller-tools834905b
Merge pull request #2817 from k8s-infra-cherrypick-robot/cherry-pick-2813-to-...6396a49
Reintroduce AddMetricsExtraHandler on managerUpdates
sigs.k8s.io/secrets-store-csi-driver
from 1.3.4 to 1.4.3Release notes
Sourced from sigs.k8s.io/secrets-store-csi-driver's releases.
... (truncated)
Commits
e6c80ff
Merge pull request #1501aramase/automated-cherry-pick-of-#1500
c7e0f0b
release: update manifest and helm charts for v1.4.32ee8013
Merge pull request #1499 from aramase/aramase/c/bump_release_1.4_v1.4.3aa75fe5
chore: bump version to v1.4.3 in release-1.464df848
Merge pull request #1497aramase/automated-cherry-pick-of-#1496
412c477
security: bump golang.org/x/net to v0.23.0+ to fix GO-2024-268703dd391
ci: add govulncheck4ab55c1
Merge pull request #1492aramase/automated-cherry-pick-of-#1491
3c3889a
chore: update debian-base to bookworm-v1.0.298559e0
Merge pull request #1474aramase/automated-cherry-pick-of-#1467
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show