Skip to content

[v2.12] Prerelease dependency bumps for v2.12.13 - #651

Merged
pmatseykanets merged 5 commits into
rancher:v2.12from
pmatseykanets:bump-deps-pre-v2.12.13
Aug 26, 2026
Merged

[v2.12] Prerelease dependency bumps for v2.12.13#651
pmatseykanets merged 5 commits into
rancher:v2.12from
pmatseykanets:bump-deps-pre-v2.12.13

Conversation

@pmatseykanets

Copy link
Copy Markdown
Contributor
  • Go toolchain: go1.25.14
  • Kubernetes: synced to rancher/rancher 1.33.13 (5 replace directive(s) updated)
  • Compatibility replace directives synced with rancher/rancher
  • Rancher: v2.12.13-rc1

Rancher commit:

05536d1125ef59ae8f0d47f2a3c61e5687d4f0d9

@pmatseykanets
pmatseykanets marked this pull request as ready for review August 25, 2026 20:52
@pmatseykanets
pmatseykanets requested a review from a team as a code owner August 25, 2026 20:52
@pmatseykanets pmatseykanets self-assigned this Aug 25, 2026
@pmatseykanets
pmatseykanets force-pushed the bump-deps-pre-v2.12.13 branch from e4a473f to 3fb316c Compare August 25, 2026 22:54
go.opentelemetry.io/otel and otel/trace were bumped to v1.44.0 to clear
trivy findings. rancher/rancher pins both at v1.43.0, so the dependency
sync treated them as drift and pulled them back down, silently
reintroducing the CVEs on the next prerelease bump.

Recording them as explicit replace directives states the intent: the
sync leaves a module alone when cli pins it above rancher/rancher.
Modules that merely resolve higher without a pin are still synced --
github.com/google/gnostic-models has to come down to v0.6.9 to match
the held-back kube-openapi.
@pmatseykanets
pmatseykanets merged commit 043a5d7 into rancher:v2.12 Aug 26, 2026
1 check passed
@pmatseykanets
pmatseykanets deleted the bump-deps-pre-v2.12.13 branch August 26, 2026 09:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants