Skip to content

chore(deps): bump the k8s group across 1 directory with 3 updates - #263

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/k8s-3b809083d6
Closed

chore(deps): bump the k8s group across 1 directory with 3 updates#263
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/k8s-3b809083d6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the k8s group with 2 updates in the / directory: k8s.io/apimachinery and k8s.io/client-go.

Updates k8s.io/apimachinery from 0.32.13 to 0.36.3

Commits
  • 40bf4b2 Update dependencies to v0.36.3 tag
  • 34d46be Merge pull request #140296 from jpbetz/cherry-pick-smd-306-revert
  • 66a3724 Bump sigs.k8s.io/structured-merge-diff/v6 to v6.3.3
  • 2ec982d Merge pull request #139508lalitc375/automated-cherry-pick-of-#139480
  • 6a88102 Fix wrong marking of errors
  • efb7f26 Merge remote-tracking branch 'origin/master' into release-1.36
  • d966e56 Update github.com/moby/spdystream from v0.5.0 to v0.5.1
  • 79b3632 Merge pull request #137864 from yongruilin/dv-dra-mismatch
  • a8822f7 Add slice and map union member support with tests
  • 7dba2d0 Use IsZero instead of IsNil for union ratcheting check
  • Additional commits viewable in compare view

Updates k8s.io/client-go from 0.32.13 to 0.36.3

Commits
  • 44a8af2 Update dependencies to v0.36.3 tag
  • f501ada Merge pull request #140296 from jpbetz/cherry-pick-smd-306-revert
  • a43e1d7 Bump sigs.k8s.io/structured-merge-diff/v6 to v6.3.3
  • f22a53e Merge remote-tracking branch 'origin/master' into release-1.36
  • a948641 Update github.com/moby/spdystream from v0.5.0 to v0.5.1
  • 7e44ffc Add Workload-Aware Preemption fields to Workload and PodGroup APIs
  • df2d882 Merge pull request #136989 from nojnhuh/podgroup-resourceclaim
  • 4eece52 Workload API: PodGroup ResourceClaims (KEP-5729)
  • 3d35c51 Merge pull request #137190 from everpeace/KEP-5491-alpha
  • 0434117 Merge pull request #137028 from nmn3m/feature/dra-resource-pool-status
  • Additional commits viewable in compare view

Updates k8s.io/klog/v2 from 2.130.1 to 2.140.0

Release notes

Sourced from k8s.io/klog/v2's releases.

Prepare klog release for Kubernetes v1.36

What's Changed

New Contributors

Full Changelog: kubernetes/klog@v2.130.1...v2.140.0

Commits
  • ef4b370 Merge pull request #432 from pierluigilenoci/fix/stderr-threshold-issue-212
  • 39c4c76 refactor: address code review feedback from @​pohly
  • 764a9a3 Merge pull request #430 from pohly/textlogger-optional-header
  • 015c613 Update stderr_threshold_test.go
  • 2f517bd Update klog.go
  • 36bc4ff textlogger: optionally turn off header
  • 5f1f303 Merge pull request #433 from pohly/textlogger-hook-result
  • c469d41 Merge pull request #431 from pohly/ktesting-vmodule-fix
  • 8509d6a ktesting: support multi-line result from AnyToStringHook
  • 08e6e8b Fix stderrthreshold not honored when logtostderr is set
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Jun 2, 2026
@dependabot dependabot Bot changed the title chore(deps): bump the k8s group with 3 updates chore(deps): bump the k8s group across 1 directory with 3 updates Jun 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s-3b809083d6 branch from dd6e6f0 to d4281b2 Compare June 12, 2026 05:57
@cla-assistant

cla-assistant Bot commented Jun 12, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s-3b809083d6 branch from d4281b2 to 190d12e Compare June 12, 2026 06:03
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s-3b809083d6 branch from 190d12e to 96b904a Compare July 6, 2026 10:33
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s-3b809083d6 branch 2 times, most recently from c785635 to 6d5ff6d Compare July 20, 2026 10:33
@mayankpande88

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps the k8s group with 2 updates in the / directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) and [k8s.io/client-go](https://github.com/kubernetes/client-go).


Updates `k8s.io/apimachinery` from 0.32.13 to 0.36.3
- [Commits](kubernetes/apimachinery@v0.32.13...v0.36.3)

Updates `k8s.io/client-go` from 0.32.13 to 0.36.3
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.32.13...v0.36.3)

Updates `k8s.io/klog/v2` from 2.130.1 to 2.140.0
- [Release notes](https://github.com/kubernetes/klog/releases)
- [Changelog](https://github.com/kubernetes/klog/blob/main/RELEASE.md)
- [Commits](kubernetes/klog@v2.130.1...2.140.0)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s
- dependency-name: k8s.io/klog/v2
  dependency-version: 2.140.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/k8s-3b809083d6 branch from 6d5ff6d to 468fa18 Compare July 28, 2026 12:13
@mayankpande88

Copy link
Copy Markdown
Contributor

Rebased onto current main; CI still fails, and it is not a flake.

go: go.mod requires go >= 1.26.0 (running go 1.25.0; GOTOOLCHAIN=local)

k8s.io 0.36.x requires Go >= 1.26. This repo pins Go in two places, both below that:

  • .github/workflows/ci.ymlgo-version: '1.25.0' (with GOTOOLCHAIN=local, so no auto-upgrade)
  • DockerfileARG GO_VERSION=1.25.12 (the image the release actually ships)

So this PR is blocked on a deliberate Go 1.26 toolchain upgrade, not on anything in the bump itself. That upgrade should be its own PR covering both pins together. Leaving this open pending that decision.

@mayankpande88

Copy link
Copy Markdown
Contributor

Follow-up, correcting the earlier comment: the Go 1.26 toolchain is the first gate, not the only one.

#300 raises all three Go pins to 1.26.5 and clears the go >= 1.26.0 module-load failure. But once past that, this PR will hit the same wall #273 just demonstrated:

cilium@v1.17.16/pkg/k8s/informer/informer.go:103:3: unknown field RetryOnError in struct literal of type "k8s.io/client-go/tools/cache".Config

cache.Config.RetryOnError was removed in client-go 0.35; this PR targets 0.36.2, which is past that. cilium/cilium v1.17.16 still sets the field, so the build breaks regardless of the toolchain.

So this needs both:

  1. chore: move the Go toolchain to 1.26.5 #300 (Go 1.26.5) — open, CI green
  2. A cilium/cilium bump off 1.17.16 to a release built against client-go 0.35+ — upstream is at v1.19.6

Step 2 is the real work and touches the eBPF/datapath side, so it warrants its own PR and a dev-cluster validation.

mayankpande88 added a commit that referenced this pull request Jul 29, 2026
The repo pins Go in three places and they had drifted apart: CI on
1.25.0, the release image on 1.25.12, and the (unused) alpine build
file still on 1.23.8. Move all three to 1.26.5 together so the version
CI validates is the version the release actually ships.

This also unblocks #263: k8s.io 0.36.x declares `go >= 1.26.0`, and CI
runs with GOTOOLCHAIN=local, so a 1.25.x runner fails the module load
outright rather than fetching a newer toolchain.

Deliberately not touching the `go` directive in go.mod — 1.26.5
satisfies the current `go 1.25.0`, and raising it is the k8s bump's
business, not the toolchain's.
mayankpande88 added a commit that referenced this pull request Jul 29, 2026
The repo pins Go in three places and they had drifted apart: CI on
1.25.0, the release image on 1.25.12, and the (unused) alpine build
file still on 1.23.8. Move all three to 1.26.5 together so the version
CI validates is the version the release actually ships.

This also unblocks #263: k8s.io 0.36.x declares `go >= 1.26.0`, and CI
runs with GOTOOLCHAIN=local, so a 1.25.x runner fails the module load
outright rather than fetching a newer toolchain.

Deliberately not touching the `go` directive in go.mod — 1.26.5
satisfies the current `go 1.25.0`, and raising it is the k8s bump's
business, not the toolchain's.
@dependabot @github

dependabot Bot commented on behalf of github Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/go_modules/k8s-3b809083d6 branch July 29, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant