Skip to content

chore(deps): bump the go group with 9 updates#860

Merged
matthiasbruns merged 1 commit intomainfrom
dependabot/go_modules/go-4c5ad1da79
Mar 16, 2026
Merged

chore(deps): bump the go group with 9 updates#860
matthiasbruns merged 1 commit intomainfrom
dependabot/go_modules/go-4c5ad1da79

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 15, 2026

Bumps the go group with 9 updates:

Package From To
github.com/fluxcd/helm-controller/api 1.5.1 1.5.2
github.com/fluxcd/kustomize-controller/api 1.8.1 1.8.2
github.com/fluxcd/pkg/apis/event 0.24.0 0.25.0
github.com/fluxcd/pkg/apis/meta 1.25.0 1.25.1
github.com/fluxcd/pkg/kustomize 1.27.0 1.28.0
github.com/fluxcd/pkg/runtime 0.102.0 0.103.0
github.com/fluxcd/source-controller/api 1.8.0 1.8.1
helm.sh/helm/v3 3.20.0 3.20.1
ocm.software/ocm 0.36.0 0.37.0

Updates github.com/fluxcd/helm-controller/api from 1.5.1 to 1.5.2

Release notes

Sourced from github.com/fluxcd/helm-controller/api's releases.

v1.5.2

Changelog

v1.5.2 changelog

Container images

  • docker.io/fluxcd/helm-controller:v1.5.2
  • ghcr.io/fluxcd/helm-controller:v1.5.2

Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.

The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC. To verify the images and their provenance (SLSA level 3), please see the security documentation.

Changelog

Sourced from github.com/fluxcd/helm-controller/api's changelog.

1.5.2

Release date: 2026-03-12

This patch release fixes reconciliation queue behavior for source watch events while a HelmRelease is already reconciling the watched revision. It also comes with Helm 4.1.3, which fixes a Go templates bug where the YAML document separator --- could be concatenated to apiVersion as ---apiVersion, and introduces the DefaultToRetryOnFailure feature gate to improve the experience when CancelHealthCheckOnNewRevision is enabled by ensuring canceled HelmReleases do not get stuck when no retry strategy is configured.

Fixes:

  • Fix enqueing the same revision while reconciling #1430

Improvements:

  • Introduce DefaultToRetryOnFailure feature gate #1431
  • Update fluxcd/pkg dependencies #1436
Commits
  • 942324a Merge pull request #1439 from fluxcd/release-v1.5.2
  • d679396 Release v1.5.2
  • 4e20b44 Add changelog entry for v1.5.2
  • 440a3a6 Merge pull request #1436 from fluxcd/update-pkg-deps/release/v1.5.x
  • 1f0eae9 Update fluxcd/pkg dependencies
  • f27c7a7 Merge pull request #1435 from fluxcd/backport-1430-to-release/v1.5.x
  • 1986afd Fix enqueing the same revision while reconciling
  • 9f1a820 Merge pull request #1434 from fluxcd/backport-1431-to-release/v1.5.x
  • 096694f Introduce DefaultToRetryOnFailure feature gate
  • See full diff in compare view

Updates github.com/fluxcd/kustomize-controller/api from 1.8.1 to 1.8.2

Release notes

Sourced from github.com/fluxcd/kustomize-controller/api's releases.

v1.8.2

Changelog

v1.8.2 changelog

Container images

  • docker.io/fluxcd/kustomize-controller:v1.8.2
  • ghcr.io/fluxcd/kustomize-controller:v1.8.2

Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.

The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC. To verify the images and their provenance (SLSA level 3), please see the security documentation.

Changelog

Sourced from github.com/fluxcd/kustomize-controller/api's changelog.

1.8.2

Release date: 2026-03-12

This patch release fixes reconciliation queue behavior for source watch events while a Kustomization is already reconciling the watched revision.

Fixes:

  • Fix enqueing the same revision while reconciling #1614

Improvements:

  • Fix docs typo #1609
  • Update fluxcd/pkg dependencies #1616
Commits
  • 42b9656 Merge pull request #1619 from fluxcd/release-v1.8.2
  • f3b4e7f Release v1.8.2
  • 19b22d0 Add changelog entry for v1.8.2
  • 5d6a259 Merge pull request #1616 from fluxcd/update-pkg-deps/release/v1.8.x
  • d77f236 Update fluxcd/pkg dependencies
  • 22ec318 Merge pull request #1615 from fluxcd/backport-1614-to-release/v1.8.x
  • bd08fde Fix enqueing the same revision while reconciling
  • 4fff2fd Merge pull request #1610 from fluxcd/backport-1609-to-release/v1.8.x
  • c235d26 fix: docs typo
  • See full diff in compare view

Updates github.com/fluxcd/pkg/apis/event from 0.24.0 to 0.25.0

Commits
  • 090c3ce Merge pull request #886 from dipti-pai/move-github-provider
  • 84883b4 Move auth/github to git/github
  • 0d627fb Merge pull request #885 from fluxcd/gh-app-cache-key
  • 4380ea7 Take the hash of all the parts in the GitHub App token cache key
  • 84d0d45 Merge pull request #882 from kathleenfrench/kfrench/cel-eval-string
  • 567773d support string evaluation in CEL expressions
  • 8b1f852 Merge pull request #881 from fluxcd/token-cache-flags
  • 4b34b01 Add CLI flags for the token cache and method to delete all events
  • c05eb67 Merge pull request #880 from fluxcd/cache-custom-metric-labels
  • 4d91aae Add option for custom event namespace label in cache metrics
  • Additional commits viewable in compare view

Updates github.com/fluxcd/pkg/apis/meta from 1.25.0 to 1.25.1

Commits
  • 021a21b Merge pull request #1149 from fluxcd/release-flux/v2.8.x
  • 7bc8b6d Prepare for release
  • 62e3263 Merge pull request #1147 from fluxcd/backport-1146-to-flux/v2.8.x
  • f6a623b Upgrade to Kubernetes 1.35.2
  • 3e50452 Merge pull request #1138 from fluxcd/release-flux/v2.8.x
  • 6d1513a Prepare for release
  • 72ab2be Merge pull request #1139 from fluxcd/backport-1130-to-flux/v2.8.x
  • 5b08e23 Use ACR-scoped token for registry authentication
  • e8be077 Merge pull request #1136 from fluxcd/backport-1135-to-flux/v2.8.x
  • de936cb Update fluxcd/cli-utils to v0.37.2-flux.1
  • Additional commits viewable in compare view

Updates github.com/fluxcd/pkg/kustomize from 1.27.0 to 1.28.0

Commits
  • 357bbcc Merge pull request #1148 from fluxcd/release-main
  • cb33487 Prepare for release
  • 2513374 Merge pull request #1146 from fluxcd/upgrade-deps
  • b30a6ab Upgrade to Kubernetes 1.35.2
  • 70c1447 Merge pull request #1145 from fluxcd/dependabot/github_actions/ci-fe7542dce4
  • cf1d606 build(deps): bump the ci group across 1 directory with 11 updates
  • 07d627d Merge pull request #1137 from fluxcd/release-main
  • 2f6ee78 Prepare for release
  • 0dd5550 Merge pull request #1130 from kukacz/fix-acr-scope-auth
  • 68b8866 Use ACR-scoped token for registry authentication
  • Additional commits viewable in compare view

Updates github.com/fluxcd/pkg/runtime from 0.102.0 to 0.103.0

Commits
  • 357bbcc Merge pull request #1148 from fluxcd/release-main
  • cb33487 Prepare for release
  • 2513374 Merge pull request #1146 from fluxcd/upgrade-deps
  • b30a6ab Upgrade to Kubernetes 1.35.2
  • 70c1447 Merge pull request #1145 from fluxcd/dependabot/github_actions/ci-fe7542dce4
  • cf1d606 build(deps): bump the ci group across 1 directory with 11 updates
  • 07d627d Merge pull request #1137 from fluxcd/release-main
  • 2f6ee78 Prepare for release
  • 0dd5550 Merge pull request #1130 from kukacz/fix-acr-scope-auth
  • 68b8866 Use ACR-scoped token for registry authentication
  • Additional commits viewable in compare view

Updates github.com/fluxcd/source-controller/api from 1.8.0 to 1.8.1

Release notes

Sourced from github.com/fluxcd/source-controller/api's releases.

v1.8.1

Changelog

v1.8.1 changelog

Container images

  • docker.io/fluxcd/source-controller:v1.8.1
  • ghcr.io/fluxcd/source-controller:v1.8.1

Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.

The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC. To verify the images and their provenance (SLSA level 3), please see the security documentation.

Changelog

Sourced from github.com/fluxcd/source-controller/api's changelog.

1.8.1

Release date: 2026-03-12

This patch release fixes Azure Container Registry authentication by using the ACR-specific auth scope instead of the generic registry scope.

Improvements:

  • Remove no longer needed workaround for Flux 2.8 #1993
  • Update fluxcd/pkg dependencies #2001 #2005
Commits
  • d091e4a Merge pull request #2007 from fluxcd/release-v1.8.1
  • 664a42c Release v1.8.1
  • b900dcc Add changelog entry for v1.8.1
  • bc004b8 Merge pull request #2005 from fluxcd/update-pkg-deps/release/v1.8.x
  • 9ea8b2b Update fluxcd/pkg dependencies
  • 071151e Merge pull request #2001 from fluxcd/update-pkg-deps/release/v1.8.x
  • 5d8a9d2 Update fluxcd/pkg dependencies
  • 7ec3dd0 Merge pull request #1994 from fluxcd/backport-1993-to-release/v1.8.x
  • 902eac9 Remove no longer needed workaround for Flux 2.8
  • See full diff in compare view

Updates helm.sh/helm/v3 from 3.20.0 to 3.20.1

Release notes

Sourced from helm.sh/helm/v3's releases.

Helm v3.20.1 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Notable Changes

  • Backport of #31644: Fixed a bug where user-provided nil value was not preserved when chart has an empty map or no default for a key
  • Backport of #31601: Fixed a bug where OCI references with tag+digest failed with "invalid byte" error

Installation and Upgrading

Download Helm v3.20.1. The common platform binaries are here:

This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @​scottrigby keybase account. Please use the attached signatures for verifying this release using gpg.

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.2.0 and 3.21.0 are the next minor releases and will be on May 13, 2026
  • 4.1.4 and 3.20.2 are the next patch releases and will be on April 8, 2026

Changelog

  • chore(deps): bump the k8s-io group with 7 updates a2369ca71c0ef633bf6e4fccd66d634eb379b371 (dependabot[bot])
  • add image index test 90e10564f7ae746a153f3a03006e7061a54ad490 (Pedro Tôrres)
  • fix pulling charts from OCI indices 911f2e908ae40b01ca95b857e94b8894043f64fd (Pedro Tôrres)
  • Remove refactorring changes from coalesce_test.go 76dad33fb1a2b6451920429b4f5f2dd575ea71bb (Evans Mungai)
  • Fix import 45c12f71407b6054a37d3e425d5293ee79a1ab37 (Evans Mungai)
  • Update pkg/chart/common/util/coalesce_test.go 26c6f19f967941dbe53bfb5e52d419b3b3e46075 (Evans Mungai)
  • Fix lint warning 09f5129d49a14c9336cea6f33adf5f52889915ef (Evans Mungai)
  • Preserve nil values in chart already 417deb2b6b7504357b0f580b76f5eed1bb8a5270 (Evans Mungai)

... (truncated)

Commits
  • a2369ca chore(deps): bump the k8s-io group with 7 updates
  • 90e1056 add image index test
  • 911f2e9 fix pulling charts from OCI indices
  • 76dad33 Remove refactorring changes from coalesce_test.go
  • 45c12f7 Fix import
  • 26c6f19 Update pkg/chart/common/util/coalesce_test.go
  • 09f5129 Fix lint warning
  • 417deb2 Preserve nil values in chart already
  • 5417bfa fix(values): preserve nil values when chart default is empty map
  • See full diff in compare view

Updates ocm.software/ocm from 0.36.0 to 0.37.0

Release notes

Sourced from ocm.software/ocm's releases.

v0.37.0

What's Changed

🚀 Features

🐛 Bug Fixes

⬆️ Dependencies

🧰 Maintenance

Full Changelog: open-component-model/ocm@v0.36...v0.37.0

v0.37.0-rc.1

What's Changed

🚀 Features

🐛 Bug Fixes

⬆️ Dependencies

... (truncated)

Commits
  • 81d0787 chore: Revert "chore: bump VERSION to 0.38.0-dev (#1819)" (#1836)
  • d15beb2 fix: increase token scope to create PRs or sent events in other repositories ...
  • 7c0adfc fix: revert feat: add registry client timeout attribute (#1823) (#1835)
  • 567e941 chore(deps): bump the ci group with 2 updates (#1832)
  • 44e518e chore(deps): bump the go group with 7 updates (#1831)
  • 2a53f2d chore(deps): bump shimataro/ssh-key-action from 2.7.0 to 2.8.0 in the ci grou...
  • 001ac9f chore: update to use create-github-app-token action instead of deprecated tib...
  • c3ea1f7 fix: the version comment on codeql is incorrect (#1828)
  • 60e3711 feat: add registry client timeout attribute (#1823)
  • ac1c9a6 chore: update mongodb for security compliance fixes (#1827)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels Mar 15, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 15, 2026 15:04
@dependabot dependabot bot added kind/chore chore, maintenance, etc. kind/dependency dependency update, etc. labels Mar 15, 2026
@matthiasbruns
Copy link
Contributor

@dependabot rebase

Bumps the go group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [github.com/fluxcd/helm-controller/api](https://github.com/fluxcd/helm-controller) | `1.5.1` | `1.5.2` |
| [github.com/fluxcd/kustomize-controller/api](https://github.com/fluxcd/kustomize-controller) | `1.8.1` | `1.8.2` |
| [github.com/fluxcd/pkg/apis/event](https://github.com/fluxcd/pkg) | `0.24.0` | `0.25.0` |
| [github.com/fluxcd/pkg/apis/meta](https://github.com/fluxcd/pkg) | `1.25.0` | `1.25.1` |
| [github.com/fluxcd/pkg/kustomize](https://github.com/fluxcd/pkg) | `1.27.0` | `1.28.0` |
| [github.com/fluxcd/pkg/runtime](https://github.com/fluxcd/pkg) | `0.102.0` | `0.103.0` |
| [github.com/fluxcd/source-controller/api](https://github.com/fluxcd/source-controller) | `1.8.0` | `1.8.1` |
| [helm.sh/helm/v3](https://github.com/helm/helm) | `3.20.0` | `3.20.1` |
| [ocm.software/ocm](https://github.com/open-component-model/ocm) | `0.36.0` | `0.37.0` |


Updates `github.com/fluxcd/helm-controller/api` from 1.5.1 to 1.5.2
- [Release notes](https://github.com/fluxcd/helm-controller/releases)
- [Changelog](https://github.com/fluxcd/helm-controller/blob/main/CHANGELOG.md)
- [Commits](fluxcd/helm-controller@v1.5.1...v1.5.2)

Updates `github.com/fluxcd/kustomize-controller/api` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/fluxcd/kustomize-controller/releases)
- [Changelog](https://github.com/fluxcd/kustomize-controller/blob/main/CHANGELOG.md)
- [Commits](fluxcd/kustomize-controller@v1.8.1...v1.8.2)

Updates `github.com/fluxcd/pkg/apis/event` from 0.24.0 to 0.25.0
- [Commits](fluxcd/pkg@git/v0.24.0...git/v0.25.0)

Updates `github.com/fluxcd/pkg/apis/meta` from 1.25.0 to 1.25.1
- [Commits](fluxcd/pkg@apis/meta/v1.25.0...apis/meta/v1.25.1)

Updates `github.com/fluxcd/pkg/kustomize` from 1.27.0 to 1.28.0
- [Commits](fluxcd/pkg@kustomize/v1.27.0...kustomize/v1.28.0)

Updates `github.com/fluxcd/pkg/runtime` from 0.102.0 to 0.103.0
- [Commits](fluxcd/pkg@runtime/v0.102.0...runtime/v0.103.0)

Updates `github.com/fluxcd/source-controller/api` from 1.8.0 to 1.8.1
- [Release notes](https://github.com/fluxcd/source-controller/releases)
- [Changelog](https://github.com/fluxcd/source-controller/blob/main/CHANGELOG.md)
- [Commits](fluxcd/source-controller@v1.8.0...v1.8.1)

Updates `helm.sh/helm/v3` from 3.20.0 to 3.20.1
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/helm@v3.20.0...v3.20.1)

Updates `ocm.software/ocm` from 0.36.0 to 0.37.0
- [Release notes](https://github.com/open-component-model/ocm/releases)
- [Changelog](https://github.com/open-component-model/ocm/blob/main/RELEASE_PROCESS.md)
- [Commits](open-component-model/ocm@v0.36...v0.37)

---
updated-dependencies:
- dependency-name: github.com/fluxcd/helm-controller/api
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/fluxcd/kustomize-controller/api
  dependency-version: 1.8.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/fluxcd/pkg/apis/event
  dependency-version: 0.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/fluxcd/pkg/apis/meta
  dependency-version: 1.25.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: github.com/fluxcd/pkg/kustomize
  dependency-version: 1.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/fluxcd/pkg/runtime
  dependency-version: 0.103.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
- dependency-name: github.com/fluxcd/source-controller/api
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go
- dependency-name: ocm.software/ocm
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/go-4c5ad1da79 branch from bff03cf to c308d91 Compare March 16, 2026 09:05
@matthiasbruns matthiasbruns merged commit 7d57e7c into main Mar 16, 2026
9 checks passed
@matthiasbruns matthiasbruns deleted the dependabot/go_modules/go-4c5ad1da79 branch March 16, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/chore chore, maintenance, etc. kind/dependency dependency update, etc.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant