Update External dependencies (release-1.3) (patch)

This MR contains the following updates:

Package Type Update Change
ClusterSecretStore patch external-secrets.io/v1beta1 -> external-secrets.io/v1
ExternalSecret patch external-secrets.io/v1beta1 -> external-secrets.io/v1
cert-manager (source) patch v1.15.4 -> v1.15.5
core (source) patch 2.8.3 -> 2.8.9
external-secrets patch 0.10.4 -> 0.10.7
ghcr.io/kube-vip/kube-vip patch v0.8.7 -> v0.8.10
https://github.com/bank-vaults/vault-operator.git patch v1.22.3 -> v1.22.6
https://github.com/grafana/loki.git patch v3.3.2 -> v3.3.4
https://github.com/minio/operator.git patch v5.0.16 -> v5.0.18
https://github.com/rancher/local-path-provisioner.git patch v0.0.31 -> v0.0.32
kepler (source) patch 0.5.12 -> 0.5.19
kubernetes-sigs/cluster-api-provider-openstack patch v0.11.6 -> v0.11.8
kubernetes-sigs/cluster-api-provider-vsphere patch v1.12.0 -> v1.12.1
kyverno (source) patch 3.3.4 -> 3.3.9
openshift/assisted-service patch v2.33.0 -> v2.33.1
openshift/assisted-service Kustomization patch v2.33.0 -> v2.33.1
openstack-cinder-csi patch 2.31.2 -> 2.31.7
python image patch 3.13.3-slim -> 3.13.9-slim
rancher-cis-benchmark patch 105.0.0+up7.0.0 -> 105.0.1+up7.0.1
to-be-continuous/gitleaks repository patch 2.7.1 -> 2.7.3
vault-config-operator patch v0.8.29 -> v0.8.36

Release Notes

cert-manager/cert-manager (cert-manager)

v1.15.5

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager v1.15.5 contains simple dependency bumps to address reported CVEs (CVE-2024-45337 and CVE-2024-45338).

We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners.

Changes

Bug or Regression
  • Bump golang.org/x/net to address CVE-2024-45337 and CVE-2024-45338 (#​7496, @​wallrj)
Other (Cleanup or Flake)
neuvector/neuvector-helm (core)

v2.8.9: Release 2.8.9

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/neuvector/neuvector-helm/compare/v2.8.8...v2.8.9

v2.8.8: Release 2.8.8

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/neuvector/neuvector-helm/compare/v2.8.7...v2.8.8

v2.8.7: Release 2.8.7

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/neuvector/neuvector-helm/compare/v2.8.6...v2.8.7

v2.8.6: Release 2.8.6

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/neuvector/neuvector-helm/compare/v2.8.5...v2.8.6

v2.8.5: Release 2.8.5

Compare Source

What's Changed

Full Changelog: https://github.com/neuvector/neuvector-helm/compare/v2.8.4...v2.8.5

v2.8.4: Release 2.8.4

Compare Source

What's Changed

Full Changelog: https://github.com/neuvector/neuvector-helm/compare/v2.8.3...v2.8.4

external-secrets/external-secrets (external-secrets)

v0.10.7

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.7 Image: ghcr.io/external-secrets/external-secrets:v0.10.7-ubi Image: ghcr.io/external-secrets/external-secrets:v0.10.7-ubi-boringssl

What's Changed

New Contributors

Full Changelog: https://github.com/external-secrets/external-secrets/compare/v0.10.6...v0.10.7

v0.10.6

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.6 Image: ghcr.io/external-secrets/external-secrets:v0.10.6-ubi Image: ghcr.io/external-secrets/external-secrets:v0.10.6-ubi-boringssl

What's Changed

New Contributors

Full Changelog: https://github.com/external-secrets/external-secrets/compare/v0.10.5...v0.10.6

v0.10.5

Compare Source

Image: ghcr.io/external-secrets/external-secrets:v0.10.5 Image: ghcr.io/external-secrets/external-secrets:v0.10.5-ubi Image: ghcr.io/external-secrets/external-secrets:v0.10.5-ubi-boringssl

What's Changed

New Contributors

Full Changelog: https://github.com/external-secrets/external-secrets/compare/v0.10.4...v0.10.5

kube-vip/kube-vip (ghcr.io/kube-vip/kube-vip)

v0.8.10

Compare Source

Bugfix Release

What's Changed

Full Changelog: https://github.com/kube-vip/kube-vip/compare/v0.8.9...v0.8.10

v0.8.9

Compare Source

Quick and hopefully the final 0.8.x version

Fixes a blocking issue where an etcd timeout or network "blip" would stop load balancer services from restarting.

What's Changed

Full Changelog: https://github.com/kube-vip/kube-vip/compare/v0.8.8...v0.8.9

v0.8.8

Compare Source

Recreation of v0.8.8

Unfortunately a bug was introduced from fixing a linting issue that broke one of the watchers for services being created, this has been fixed and tested. Thanks @​jjschwarz 🙏

What's Changed

New Contributors

Full Changelog: https://github.com/kube-vip/kube-vip/compare/v0.8.7...v0.8.8

bank-vaults/vault-operator (https://github.com/bank-vaults/vault-operator.git)

v1.22.6

Compare Source

What's Changed

Features 🚀
Maintenance 🚧
Dependency Updates ⬆️
View all dependency changes

New Contributors

Full Changelog: https://github.com/bank-vaults/vault-operator/compare/v1.22.5...v1.22.6

v1.22.5

Compare Source

What's Changed

Maintenance 🚧
Dependency Updates ⬆️
View all dependency changes

New Contributors

Full Changelog: https://github.com/bank-vaults/vault-operator/compare/v1.22.4...v1.22.5

v1.22.4

Compare Source

What's Changed

Maintenance 🚧
Documentation 📄
Dependency Updates ⬆️
View all dependency changes

New Contributors

Full Changelog: https://github.com/bank-vaults/vault-operator/compare/v1.22.3...v1.22.4

grafana/loki (https://github.com/grafana/loki.git)

v3.3.4

Compare Source

Bug Fixes
  • deps: Move to Go 1.23.7 (#​16681) (f6c6474)
  • deps: update jwt and oauth2 dependencies for 3.3.x (#​17021) (241f5aa)
  • deps: update module golang.org/x/crypto to v0.35.0 [security] (release-3.3.x) (#​16590) (454cad2)
  • deps: update module golang.org/x/oauth2 to v0.27.0 [security] (release-3.3.x) (#​16591) (7b35a41)
  • docs: add a note on docker configuration.md doc to explain accep… (#​16746) (0102107)

v3.3.3

Compare Source

Bug Fixes
minio/operator (https://github.com/minio/operator.git)

v5.0.18: Version 5.0.18

Compare Source

Changelog

v5.0.17

Compare Source

rancher/local-path-provisioner (https://github.com/rancher/local-path-provisioner.git)

v0.0.32: Local Path Provisioner v0.0.32

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/rancher/local-path-provisioner/compare/v0.0.31...v0.0.32

sustainable-computing-io/kepler-helm-chart (kepler)

v0.5.19

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

v0.5.18

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

v0.5.17

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

v0.5.16

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

v0.5.15

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

v0.5.14

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

v0.5.13

Compare Source

A Helm chart for kepler (Kubernetes-based Efficient Power Level Exporter)

kubernetes-sigs/cluster-api-provider-openstack (kubernetes-sigs/cluster-api-provider-openstack)

v0.11.8

Compare Source

Changes since v0.11.7

🐛 Bug Fixes

  • Fixes out-of-range bug when multiple ports are passed to getSGControlPlaneAdditionalPorts (#​2690)

🌱 Others

  • Uplift go 1.23.12 to address security issue in release-0.12 (#​2712)
  • (deps): Bump github.com/spf13/pflag to 1.0.10 (#​2700)
  • (deps): Bump the all-github-actions group with 2 updates (#​2698)
  • (deps): Bump github.com/spf13/pflag and github.com/ulikunitz/xz (#​2678)
  • (deps): Bump gophercloud to v2.8.0 and ulikunitz/xz to 0.5.13 (#​2670)
  • (deps): Bump k8s.io dependencies to 0.31.12 (#​2661)
  • (deps): Bump sigs.k8s.io/kustomize/kustomize/v5 and sigs.k8s.io/yaml (#​2655)
  • (deps): Bump the all-github-actions group with 2 updates (#​2648)
  • E2E: Update Calico to v3.30.2 (#​2643)
  • (deps): Bump the all-go-mod-patch-and-minor group across 3 directories with 9 updates (#​2625)
  • Ignore irrelevant CVE-2025-22868 (#​2632)

Thanks to all our contributors! 😊

v0.11.7

Compare Source

Changes since v0.11.6

🐛 Bug Fixes

  • Add FlavorID to be set by openStackMachineSpecToOpenStackServerSpec (#​2586)
  • allow switching from filter.name to id of network and subnets in OSC spec (#​2541)

🌱 Others

  • Update templates (#​2606)
  • (deps): Bump the all-go-mod-patch-and-minor group across 3 directories with 6 updates (#​2603)
  • Bump go to 1.23.10 (#​2599)
  • (deps): Bump softprops/action-gh-release from 2.2.2 to 2.3.2 in the all-github-actions group (#​2597)
  • (deps): Bump the all-go-mod-patch-and-minor group across 3 directories with 1 update (#​2580)
  • (deps): Bump actions/setup-go from 5.4.0 to 5.5.0 in the all-github-actions group (#​2572)
  • Build with go1.23.8 (#​2559)
  • Make security scanners happy release-0.11 (#​2557)
  • (deps): Bump the all-go-mod-patch-and-minor group across 3 directories with 6 updates (#​2556)
  • Add weekly security scan using govulncheck and trivy (#​2553)
  • (deps): Bump actions/setup-go from 5.4.0 to 5.5.0 in the all-github-actions group (#​2545)
  • (deps): Bump the all-go-mod-patch-and-minor group across 3 directories with 8 updates (#​2529)

Thanks to all our contributors! 😊

kubernetes-sigs/cluster-api-provider-vsphere (kubernetes-sigs/cluster-api-provider-vsphere)

v1.12.1

Compare Source

Changes since v1.12.0

📈 Overview

  • 22 new commits merged
  • 2 bugs fixed 🐛

🐛 Bug Fixes

  • StoragePolicy should ignore datastores in maintenance mode (#​3502)
  • Vspheremachinetemplate: don't reconcile if className is not set (#​3381)

🌱 Others

  • Able to export webhooks for external utilization (#​3455)
  • Bump envtest to v1.32.0 (#​3317)
  • Bump golang.org/x/net to v0.33.0 (#​3315)
  • Bump govulncheck to v1.1.4 (#​3464)
  • Bump to controller-runtime v0.19.4 (#​3319)
  • Bump to Go 1.22.11 (#​3338)
  • Bump to Go 1.22.12 (#​3346)
  • Bump to Go 1.23.8 to fix CVEs + ignore CVE CVE-2025-22872 via trivy (#​3458)
  • Bump to Go v1.23.10, github.com/cloudflare/circl v1.6.1 (#​3511)
  • Cherry-Pick: Changes for community owned Prow CI (#​3487)
  • E2e: also collect pod logs (#​3497)
  • E2e: fixup flake while claiming VIPs and and IPAM MTU (#​3506)
  • E2e: wait for vsphere api and set mtu for calico (#​3515)
  • Fix web-hook structure names and descriptions (#​3467)
  • Hack: debug vsphere connectivity (#​3521)
  • Log version directly on controller startup (#​3390)
  • Makefile: drop test file to ignore ssh vulnerability in test code (#​3368)
  • Security: whitelist CVE-2025-22870 for trivy because of being not affected according to govulncheck (#​3397)
  • Templates: remove cloud-provider flag for kube-apiserver due to removal in v1.33 (#​3366)
  • Vcsim: wait for powered on VM and use mac address reference to set IP (#​3355)

Dependencies

Added

Nothing has changed.

Changed
  • golang.org/x/net: v0.32.0 → v0.33.0
  • sigs.k8s.io/controller-runtime: v0.19.3 → v0.19.4
Removed

Nothing has changed.

Thanks to all our contributors! 😊

openshift/assisted-service (openshift/assisted-service)

v2.33.1

Compare Source

kubernetes/cloud-provider-openstack (openstack-cinder-csi)

v2.31.7

Compare Source

Cinder CSI Chart for OpenStack

to-be-continuous/gitleaks (to-be-continuous/gitleaks)

v2.7.3

Compare Source

Features

2.7.3 (2025-07-05)

Bug Fixes

2.7.2 (2025-06-13)

Bug Fixes
  • replace deprecated Docker Hub registry FQDN (7a0f26e)

2.7.1 (2025-04-02)

Bug Fixes
  • analyse branch or MR commits only (0ed44f1)

v2.7.2

Compare Source

Features

2.7.3 (2025-07-05)

Bug Fixes

2.7.2 (2025-06-13)

Bug Fixes
  • replace deprecated Docker Hub registry FQDN (7a0f26e)

2.7.1 (2025-04-02)

Bug Fixes
  • analyse branch or MR commits only (0ed44f1)
redhat-cop/vault-config-operator (vault-config-operator)

v0.8.36

Compare Source

What's Changed

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.35...v0.8.36

v0.8.35

Compare Source

What's Changed

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.34...v0.8.35

v0.8.34

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.33...v0.8.34

v0.8.33

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.32...v0.8.33

v0.8.32

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.29...v0.8.32

v0.8.31

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.29...v0.8.31

v0.8.30

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/redhat-cop/vault-config-operator/compare/v0.8.29...v0.8.30


Configuration

📅 Schedule: Branch creation - On day 11 and 26 of the month ( * * 11,26 * * ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This MR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot Sylva instance.

CI configuration couldn't be handle by MR description. A dedicated comment has been posted to control it.

If no checkbox is checked, a default pipeline will be enabled (capm3, or capo if capo label is set)

Edited by Sylva Renovate bot

Merge request reports

Loading