Skip to content

fix(deps): update all dependencies - #142

Open
bootc-bot[bot] wants to merge 1 commit into
mainfrom
bootc-renovate/all
Open

bootc-bot[bot] wants to merge 1 commit into
mainfrom
bootc-renovate/all

Conversation

@bootc-bot

@bootc-bot bootc-bot Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/onsi/ginkgo/v2 v2.32.2 → v2.33.0 age confidence
github.com/onsi/gomega v1.43.0 → v1.44.0 age confidence
go.podman.io/common v0.69.1 → v0.69.2 age confidence
go.podman.io/podman/v6 v6.1.1 → v6.1.3 age confidence
k8s.io/api v0.37.0 → v0.37.1 age confidence
k8s.io/apimachinery v0.37.0 → v0.37.1 age confidence
k8s.io/client-go v0.37.0 → v0.37.1 age confidence

Release Notes

onsi/ginkgo (github.com/onsi/ginkgo/v2)

v2.33.0

Compare Source

Features
  • The JUnit reporter now records each spec's ReportEntrys as <properties> on its <testcase> element, with the entry's name and its JSON-encoded value. Thanks @​pohly! [23db51a]
Maintenance
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. See RELEASING.md. [8616ecb]
onsi/gomega (github.com/onsi/gomega)

v1.44.0

Compare Source

Fixes
  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#​925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#​928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#​927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#​929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#​926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#​930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#​931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#​934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#​933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#​932) [c0dbd89, 2565350]

v1.43.1

Compare Source

Maintenance
  • Update go.yaml.in/yaml/v3 to v3.0.5 [d547015]
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. Releases still ship the stripped-down tree on master-lite - tests removed and Ginkgo dropped from go.mod - and the workflow now builds it and checks it on every push. See RELEASING.md. [e9dc84d]
podman-container-tools/container-libs (go.podman.io/common)

v0.69.2

What's Changed

Full Changelog: podman-container-tools/container-libs@common/v0.69.0...common/v0.69.2

podman-container-tools/podman (go.podman.io/podman/v6)

v6.1.3

Compare Source

Security
  • This release addresses CVE-2026-94603, where a podman run on a checkpoint image (any image with the io.podman.annotations.checkpoint.runtime.name annotation) could disable all sandboxing, including sandboxing specified by the user, when the container was created.
Breaking Changes
  • Removed support for checkpoint images in podman run due to serious security concerns with the different security models of running images and running checkpoints. Checkpoints ignore user-specified security configuration and are very difficult to run safely.

v6.1.2

Compare Source

Security
  • This release addresses (CVE-2025-11395), where importing images containing crafted layer tarballs with the podman load command, or importing volumes containing crafted symlinks with podman volume import, allows overwriting files on the host.
  • This release also addresses CVE-2026-79699 and CVE-2026-79705, though we do not believe these CVEs are exploitable through the Podman command line.
Misc
  • Updated Buildah to v1.45.1
  • Updated Common to v0.69.2
  • Updated Image to v5.41.2
  • Updated Storage to v1.64.1
kubernetes/api (k8s.io/api)

v0.37.1

Compare Source

kubernetes/apimachinery (k8s.io/apimachinery)

v0.37.1

Compare Source

kubernetes/client-go (k8s.io/client-go)

v0.37.1

Compare Source


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "on sunday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@bootc-bot

bootc-bot Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 4 additional dependencies were updated

Details:

Package Change
go.podman.io/buildah v1.45.0 -> v1.45.1
go.podman.io/image/v5 v5.41.1 -> v5.41.2
go.podman.io/storage v1.64.0 -> v1.64.1
k8s.io/streaming v0.37.0 -> v0.37.1

Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
Signed-off-by: bootc-bot[bot] <225049296+bootc-bot[bot]@users.noreply.github.com>
@bootc-bot
bootc-bot Bot force-pushed the bootc-renovate/all branch from 1483c73 to e74f08c Compare October 4, 2026 00:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants