Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
128 commits
Select commit Hold shift + click to select a range
7ec6a0e
:seedling: Bump actions/setup-go from 6.5.0 to 7.0.0 (#2836)
dependabot[bot] Jul 29, 2026
7db5d14
:seedling: Bump actions/checkout from 7.0.0 to 7.0.1 (#2837)
dependabot[bot] Jul 31, 2026
0273129
:seedling: Bump actions/setup-python from 6.3.0 to 7.0.0 (#2839)
dependabot[bot] Aug 3, 2026
3240aa5
:seedling: Bump mkdocs-material from 9.7.6 to 9.7.7 (#2840)
dependabot[bot] Aug 3, 2026
689f632
:seedling: Bump platformdirs from 4.10.0 to 4.10.1 (#2841)
dependabot[bot] Aug 3, 2026
d298851
:seedling: Bump regex from 2026.7.10 to 2026.7.19 (#2842)
dependabot[bot] Aug 3, 2026
6145027
:seedling: Bump github.com/prometheus/client_golang (#2844)
dependabot[bot] Aug 3, 2026
fdaba96
:seedling: Bump github.com/klauspost/compress from 1.19.0 to 1.19.1 (…
dependabot[bot] Aug 3, 2026
0a6b0be
:seedling: Bump soupsieve from 2.8.4 to 2.9 (#2843)
dependabot[bot] Aug 3, 2026
255f5de
fix: make demo e2e catalog queries resilient to transient failures (#…
pedjak Aug 3, 2026
9c2ba82
:seedling: Bump platformdirs from 4.10.1 to 4.11.0 (#2846)
dependabot[bot] Aug 4, 2026
fee8cc2
fix: collect operator pod logs across restarts and rolling updates (#…
pedjak Aug 5, 2026
488a402
:seedling: Bump github.com/prometheus/common from 0.70.0 to 0.70.1 (#…
dependabot[bot] Aug 5, 2026
23256c7
:seedling: Bump certifi from 2026.6.17 to 2026.7.22 (#2850)
dependabot[bot] Aug 5, 2026
6603a82
:seedling: Bump soupsieve from 2.9 to 2.9.1 (#2851)
dependabot[bot] Aug 5, 2026
fb11d94
:seedling: Bump the k8s-dependencies group with 4 updates (#2853)
dependabot[bot] Aug 6, 2026
d854c6e
:seedling: Bump github.com/santhosh-tekuri/jsonschema/v6 (#2854)
dependabot[bot] Aug 6, 2026
be1115e
:seedling: Bump docker/login-action from 4.4.0 to 4.5.0 (#2855)
dependabot[bot] Aug 6, 2026
1e9e659
update repo owners (#2852)
pedjak Aug 7, 2026
4e5b855
Merge branch 'main' into synchronize
Aug 8, 2026
2fa52e9
UPSTREAM: <carry>: Add OpenShift specific files
dtfranz Oct 26, 2023
82f757e
UPSTREAM: <carry>: Add new tests for single/own namespaces install modes
camilamacedo86 Oct 6, 2025
b356f67
UPSTREAM: <carry>: Upgrade OCP image from 4.20 to 4.21
camilamacedo86 Oct 13, 2025
0285c05
UPSTREAM: <carry>: [Default Catalog Tests] - Change logic to get ocp …
camilamacedo86 Oct 13, 2025
706c8b9
UPSTREAM: <carry>: Update OCP catalogs to v4.21
tmshort Oct 13, 2025
7f40901
UPSTREAM: <carry>: support singleown cases in disconnected
kuiwang02 Oct 16, 2025
e7baed1
UPSTREAM: <carry>: fix cases 81696 and 74618 for product code changes
kuiwang02 Oct 17, 2025
df64145
UPSTREAM: <carry>: Define Default timeouts and apply their usage accr…
camilamacedo86 Oct 22, 2025
f5b2011
UPSTREAM: <carry>: Update to new feature-gate options in helm
tmshort Oct 22, 2025
d00a307
UPSTREAM: <carry>: Fix flake for single/own ns tests by ensuring uniq…
camilamacedo86 Oct 22, 2025
7e72a66
UPSTREAM: <carry>: [OTE]: Enhance single/own ns based on review comme…
camilamacedo86 Oct 24, 2025
28cb741
UPSTREAM: <carry>: Update OwnSingle template to use spec.config.inlin…
kuiwang02 Nov 3, 2025
df0f2ca
UPSTREAM: <carry>: [OTE]: Add webhook cleanup validation on extension…
camilamacedo86 Nov 4, 2025
5e08c18
UPSTREAM: <carry>: Add [OTP] to migrated cases
kuiwang02 Nov 7, 2025
14826b4
UPSTREAM: <carry>: [OTE]: Upgrade dependencies used
camilamacedo86 Nov 5, 2025
77a3cae
UPSTREAM: <carry>: fix(OTE): fix OpenShift Kubernetes replace version…
camilamacedo86 Nov 10, 2025
ca71034
UPSTREAM: <carry>: [Default Catalog Tests] Upgrade go 1.24.6 and depe…
camilamacedo86 Nov 11, 2025
2466f17
UPSTREAM: <carry>: add disconnected environment support with custom p…
kuiwang02 Nov 12, 2025
31d046a
UPSTREAM: <carry>: migrate jiazha test cases to OTE
jianzhangbjz Nov 14, 2025
ef12034
UPSTREAM: <carry>: migrate clustercatalog case to ote
Xia-Zhao-rh Oct 17, 2025
5e8637d
UPSTREAM: <carry>: migrate olmv1 QE stress cases
kuiwang02 Nov 20, 2025
7b37f5f
UPSTREAM: <carry>: Use busybox/httpd to simulate probes
tmshort Nov 25, 2025
3320db4
UPSTREAM: <carry>: migrate olmv1 QE cases
Xia-Zhao-rh Nov 25, 2025
88e173c
UPSTREAM: <carry>: add agent for olmv1 qe cases
kuiwang02 Oct 21, 2025
df87ac4
UPSTREAM: <carry>: Disable upstream PodDisruptionBudget
tmshort Dec 3, 2025
3cf214d
UPSTREAM: <carry>: Add AGENTS.md for AI code contributions
rashmigottipati Dec 11, 2025
cd0c90f
UPSTREAM: <carry>: address review comments through addl prompts
rashmigottipati Dec 11, 2025
1d77e43
UPSTREAM: <carry>: addressing some more review comments
rashmigottipati Dec 11, 2025
04d6ba2
UPSTREAM: <carry>: remove DCO line
rashmigottipati Dec 11, 2025
dffb947
UPSTREAM: <carry>: migrate bandrade test cases to OTE
bandrade Nov 18, 2025
e24eac3
UPSTREAM: <carry>: update metadata
bandrade Dec 3, 2025
172eb70
UPSTREAM: <carry>: remove originalName
bandrade Dec 3, 2025
a157471
UPSTREAM: <carry>: update 80458's timeout to 180s
jianzhangbjz Dec 8, 2025
b93c8ae
UPSTREAM: <carry>: update 83026 to specify the clustercatalog
jianzhangbjz Dec 15, 2025
e5d5af9
UPSTREAM: <carry>: Update to golang 1.25 and ocp 4.22
oceanc80 Dec 18, 2025
788e61e
UPSTREAM: <carry>: Use oc client for running e2e tests
pedjak Jan 13, 2026
c6b4892
UPSTREAM: <carry>: Run upstream e2e tests tagged with `@catalogd-update`
pedjak Jan 14, 2026
6416d4b
UPSTREAM: <carry>: enhance case to make it more stable
kuiwang02 Jan 6, 2026
b1537df
UPSTREAM: <carry>: add service account to curl job
ehearne-redhat Jan 7, 2026
34387f4
UPSTREAM: <carry>: move sa creation out of buildCurlJob()
ehearne-redhat Jan 8, 2026
63c4928
UPSTREAM: <carry>: comment out delete service account
ehearne-redhat Jan 9, 2026
e656cc2
UPSTREAM: <carry>: move defercleanup for sa for LIFO
ehearne-redhat Jan 9, 2026
317585e
UPSTREAM: <carry>: add polling so job fully deleted before proceed
ehearne-redhat Jan 12, 2026
e7f58f9
UPSTREAM: <carry>: Revert "Merge pull request #594 from ehearne-redha…
sosiouxme Jan 20, 2026
8562deb
UPSTREAM: <carry>: Remove openshift-redhat-marketplace catalog tests
camilamacedo86 Jan 8, 2026
3843be2
UPSTREAM: <carry>: config watchnamespace cases
kuiwang02 Jan 6, 2026
4238822
UPSTREAM: <carry>: enhance ocp-79770
Xia-Zhao-rh Jan 26, 2026
941ccb9
UPSTREAM: <carry>: upgrade version support case
kuiwang02 Jan 28, 2026
a18f83d
UPSTREAM: <carry>: Remove installed condition check from auth preflig…
Jan 30, 2026
018c2da
UPSTREAM: <carry>: Add openshift/api dependency
Jan 30, 2026
b1298e4
UPSTREAM: <carry>: Add boxcutter specific preflight auth test
Jan 30, 2026
9bc39f6
UPSTREAM: <carry>: adjust watchnamespace case based on change
kuiwang02 Feb 2, 2026
20068e2
UPSTREAM: <carry>: fix(ote): Use as operator-controller dep from root…
camilamacedo86 Feb 3, 2026
ccf2bb4
UPSTREAM: <carry>: add 83979 automation
bandrade Feb 2, 2026
2912c23
UPSTREAM: <carry>: add 85889 automation
bandrade Feb 2, 2026
135ec69
UPSTREAM: <carry>: Update test-operator startup script to fix pod pro…
Feb 4, 2026
09ad2b9
UPSTREAM: <carry>: Fix up own-namespace invalid configuration test
Feb 7, 2026
5a41f04
UPSTREAM: <carry>: Preflight tests use in-cluster catalog and bundles…
camilamacedo86 Feb 24, 2026
b3151f6
UPSTREAM: <carry>: adjust sa and permission test cases per new change…
kuiwang02 Feb 2, 2026
ccda67f
UPSTREAM: <carry>: Update OCP catalogs to v4.22
camilamacedo86 Feb 3, 2026
23db267
UPSTREAM: <carry>: chore(OTE and Default Catalog Tests) Update go and…
camilamacedo86 Feb 26, 2026
ee1ceeb
UPSTREAM: <carry>: fix 83026 for TP cluster
jianzhangbjz Feb 28, 2026
c203f53
UPSTREAM: <carry>: serviceAccount validation unified across all runtimes
kuiwang02 Mar 6, 2026
e690fef
UPSTREAM: <carry>: Fix OLMv1 test operator to listen on IPv6
stbenjam Mar 6, 2026
31fe57c
UPSTREAM: <carry>: Increase install timeout and add diagnostic loggin…
camilamacedo86 Mar 11, 2026
e81f8bd
UPSTREAM: <carry>: add service account to curl job
ehearne-redhat Mar 2, 2026
d392271
UPSTREAM: <carry>: update OCP-75441 to support multi-arch
jianzhangbjz Mar 19, 2026
1a2a897
UPSTREAM: <carry>: deployment config cases
kuiwang02 Feb 6, 2026
c0efac8
UPSTREAM: <carry>: Add OTE tests for OLMv1 DeploymentConfig support
tmshort Mar 11, 2026
ac99b9f
UPSTREAM: <carry>: Update openshift/api and client-go
tmshort Mar 19, 2026
0c7c129
UPSTREAM: <carry>: Add boxcutter tests
camilamacedo86 Mar 23, 2026
2c67bce
UPSTREAM: <carry>: enhance QE cases
Xia-Zhao-rh Mar 17, 2026
8f98a37
UPSTREAM: <carry>: Update quay-operator version to one containing arm…
dtfranz Mar 24, 2026
5a02c3b
UPSTREAM: <carry>: verify volume/volumeMount override
kuiwang02 Mar 25, 2026
9db019f
UPSTREAM: <carry>: Add long-duration test script and documents
jianzhangbjz Mar 11, 2026
741ecbe
UPSTREAM: <carry>: Update grpc in default-catalog-consistency tests
tmshort Mar 27, 2026
52113de
UPSTREAM: <carry>: Rename ClusterExtensionRevision to ClusterObjectSe…
camilamacedo86 Mar 31, 2026
9a4f15d
UPSTREAM: <carry>: Skip incompatible operator test when Boxcutter use…
camilamacedo86 Mar 31, 2026
2ab9e07
UPSTREAM: <carry>: add ocp-87557
bandrade Feb 8, 2026
a8b9739
UPSTREAM: <carry>: Add fgiudici as reviewer
fgiudici Mar 31, 2026
7d9af12
UPSTREAM: <carry>: Remove skip for incompatible operator check after …
camilamacedo86 Apr 1, 2026
b6dd5e1
UPSTREAM: <carry>: Test empty affinity erasure and cleanup
kuiwang02 Apr 1, 2026
0bc0877
UPSTREAM: <carry>: Fix boxcutter finalizer ResourceNames in prefligh…
camilamacedo86 Apr 9, 2026
751cc27
UPSTREAM: <carry>: Expand OTE docs with more comprehensive details
camilamacedo86 Apr 15, 2026
8959312
UPSTREAM: <carry>: Disable upstream TLSProfile tests
tmshort Apr 18, 2026
9d26eca
UPSTREAM: <carry>: OTE: Simplify by remove option to configure tests …
camilamacedo86 Apr 20, 2026
9c90add
UPSTREAM: <carry>: OTE - Make OTE local output easier to read
camilamacedo86 Apr 21, 2026
8efb30d
UPSTREAM: <carry>: remove dead e2e registry push job and related vari…
joelanford Apr 29, 2026
c827277
UPSTREAM: <carry>: OCPBUGS-62517: Set replicas=1, PDB, and pod anti-a…
tmshort Apr 23, 2026
ffa2886
UPSTREAM: <carry>: fix(test): drop blocking namespace-deletion wait b…
tmshort May 4, 2026
32040d6
UPSTREAM: <carry>: Fix downstream e2e test invocation
tmshort May 18, 2026
bd3b380
UPSTREAM: <carry>: Delete openshift/registry.Dockerfile
joelanford May 19, 2026
283b6a7
UPSTREAM: <carry>: Remove test-experimenal-e2e
tmshort May 20, 2026
2d4009a
UPSTREAM: <carry>: Update readme Default Catalog Tests
camilamacedo86 May 27, 2026
d942990
UPSTREAM: <carry>: add OLMv1 topology-based deployment scaling e2e test
tmshort May 26, 2026
f7062fd
UPSTREAM: <carry>: Update dockerfiles to use golang-1.26-release-4.23…
tmshort Jun 4, 2026
c171149
UPSTREAM: <carry>: Updating ose-olm-operator-controller-container ima…
Jun 6, 2026
320d794
UPSTREAM: <carry>: Updating ose-olm-catalogd-container image to be co…
Jun 6, 2026
92632d4
UPSTREAM: <carry>: Update catalogs for 4.23/5.0
tmshort May 21, 2026
64045c0
UPSTREAM: <carry>: Remove HelmChartSupport feature gate from experime…
Jul 15, 2026
48ab523
UPSTREAM: <carry>: test: add allow-case for operator maxOCPVersion > …
tmshort Jul 16, 2026
1ca60d0
UPSTREAM: <carry>: Add OLMv1 progress deadline QE tests
dtfranz Jun 23, 2026
1befe2f
UPSTREAM: <carry>: Remove stale reviewers/approvers, add trgeiger
tmshort Jul 21, 2026
821db12
UPSTREAM: <carry>: Remove openshift/ e2e related to deprecated Servic…
dtfranz Jun 22, 2026
6de00fa
UPSTREAM: <carry>: fix(test): update PolarionID:87224 for 4.23/5.0 up…
tmshort Jul 16, 2026
323dda5
UPSTREAM: <drop>: go mod vendor
Aug 8, 2026
cc7090e
UPSTREAM: <drop>: remove upstream GitHub configuration
Aug 8, 2026
501b500
UPSTREAM: <drop>: configure the commit-checker
Aug 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 15 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -383,6 +383,18 @@ wait-%: lint-deployed-%
KUBECONFIG=$(E2E_KUBECONFIG) kubectl wait --for=condition=Available --namespace=$(CATD_NAMESPACE) deployment/catalogd-controller-manager --timeout=60s
KUBECONFIG=$(E2E_KUBECONFIG) kubectl wait --for=condition=Ready --namespace=$(CATD_NAMESPACE) certificate/catalogd-service-cert

.PHONY: fluentbit-%
fluentbit-%: wait-% $(HELM)
ifeq ($(strip $(ARTIFACT_PATH)),)
@echo "ARTIFACT_PATH unset; skipping fluent-bit deployment"
else
KUBECONFIG=$(E2E_KUBECONFIG) $(HELM) upgrade --install fluent-bit oci://ghcr.io/fluent/helm-charts/fluent-bit \
--namespace $(FLUENTBIT_NAMESPACE) --create-namespace \
--version $(FLUENTBIT_CHART_VERSION) \
-f testdata/fluentbit/values.yaml \
--wait --timeout 2m
endif

.PHONY: prometheus-%
prometheus-%: wait-% $(HELM)
ifeq ($(strip $(E2E_SUMMARY_OUTPUT)),)
Expand All @@ -401,7 +413,7 @@ endif

.PHONY: e2e-run-%
e2e-run-%: GODOG_ARGS ?=
e2e-run-%: prometheus-%
e2e-run-%: prometheus-% fluentbit-%
ifeq ($(strip $(GODOG_ARGS)),)
E2E_PROMETHEUS_PORT=$$(grep -A1 'containerPort: 30900' $(KIND_CONFIG) | grep hostPort | awk '{print $$2}'); \
if [[ -z "$$E2E_PROMETHEUS_PORT" ]]; then echo "error: failed to extract prometheus hostPort from $(KIND_CONFIG)" >&2; exit 1; fi; \
Expand Down Expand Up @@ -631,6 +643,8 @@ run-experimental: wait-$(KIND_CLUSTER_NAME) #HELP Build the operator-controller
CATD_NAMESPACE := olmv1-system
PROMETHEUS_NAMESPACE := olmv1-system
PROMETHEUS_CHART_VERSION := 86.2.2
FLUENTBIT_NAMESPACE := fluent-bit
FLUENTBIT_CHART_VERSION := 0.57.9

.PHONY: docker-build
docker-build: build-linux #EXHELP Build docker image for operator-controller and catalog with GOOS=linux and local GOARCH.
Expand Down
6 changes: 1 addition & 5 deletions OWNERS_ALIASES
Original file line number Diff line number Diff line change
@@ -1,9 +1,8 @@
aliases:
olmv1-approvers:
- grokspawn
- joelanford
- kevinrizza
- oceanc80
- joelanford
- pedjak
- perdasilva
- tmshort
Expand All @@ -14,12 +13,9 @@ aliases:
- fgiudici
- grokspawn
- joelanford
- oceanc80
- OchiengEd
- perdasilva
- rashmigottipati
- tmshort
- trgeiger
- pedjak

api-approvers:
Expand Down
24 changes: 12 additions & 12 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -20,15 +20,15 @@ require (
github.com/google/renameio/v2 v2.0.2
github.com/gorilla/handlers v1.5.2
github.com/graphql-go/graphql v0.8.1
github.com/klauspost/compress v1.19.0
github.com/klauspost/compress v1.19.1
github.com/opencontainers/go-digest v1.0.0
github.com/opencontainers/image-spec v1.1.1
github.com/operator-framework/api v0.45.0
github.com/operator-framework/helm-operator-plugins v0.9.1
github.com/operator-framework/operator-registry v1.73.0
github.com/prometheus/client_golang v1.23.2
github.com/prometheus/common v0.70.0
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
github.com/prometheus/client_golang v1.24.0
github.com/prometheus/common v0.70.1
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3
Comment on lines +23 to +31

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

test -s go.sum
go mod verify
go list -m all >/tmp/go-modules.txt
osv-scanner scan source -r .

Repository: openshift/operator-framework-operator-controller

Length of output: 302


🏁 Script executed:

#!/usr/bin/env bash
set -u

printf '%s\n' '--- relevant files ---'
git ls-files | rg '(^|/)(go\.(mod|sum)|vendor/|\.github/workflows/|Dockerfile|Makefile|Taskfile|justfile|\.gitlab-ci\.yml|.*(sbom|provenance|cosign|sign).*)$' | head -300

printf '%s\n' '--- go.mod directives and dependency blocks ---'
cat -n go.mod | sed -n '1,280p'

printf '%s\n' '--- go.sum status ---'
test -s go.sum && echo 'go.sum is non-empty' || echo 'go.sum is missing or empty'
wc -l go.sum 2>/dev/null || true

printf '%s\n' '--- supply-chain references ---'
rg -n -i 'osv|sbom|cyclonedx|syft|spdx|provenance|attestation|slsa|cosign|sigstore|signing|artifact' \
  .github Makefile* Taskfile* justfile* Dockerfile* . 2>/dev/null | head -400 || true

Repository: openshift/operator-framework-operator-controller

Length of output: 50405


🏁 Script executed:

#!/usr/bin/env bash
set -u

printf '%s\n' '--- root module graph ---'
if command -v go >/dev/null 2>&1; then
  go list -m all -mod=readonly > /tmp/go-modules-readonly.txt
  status=$?
  echo "go list status: $status"
  if [ "$status" -eq 0 ]; then
    wc -l /tmp/go-modules-readonly.txt
    sed -n '1,12p' /tmp/go-modules-readonly.txt
    tail -12 /tmp/go-modules-readonly.txt
  fi
else
  echo 'go is unavailable'
fi

printf '%s\n' '--- OSV scan ---'
if command -v osv-scanner >/dev/null 2>&1; then
  osv-scanner scan source -r .
  echo "osv-scanner status: $?"
else
  echo 'osv-scanner is unavailable'
fi

printf '%s\n' '--- tracked CI and release metadata ---'
git ls-files | rg '(^|/)(\.github|\.tekton|ci|hack/ci|build|release|\.gitlab|\.circleci|\.travis|Makefile|Dockerfile|Containerfile|\.yaml$|\.yml$)' \
  | rg -v '(^|/)(vendor|testdata|docs|bundle)/' | head -300

printf '%s\n' '--- supply-chain terms outside vendored/generated trees ---'
rg -n -i --glob '!vendor/**' --glob '!**/vendor/**' --glob '!**/bundle/**' \
  'osv|sbom|cyclonedx|syft|spdx|provenance|attestation|slsa|cosign|sigstore|signing|artifact' \
  .github .tekton ci hack Makefile* Dockerfile* Containerfile* 2>/dev/null | head -300 || true

printf '%s\n' '--- vendor consistency metadata ---'
test -f vendor/modules.txt && { wc -l vendor/modules.txt; sed -n '1,8p' vendor/modules.txt; tail -8 vendor/modules.txt; } || echo 'vendor/modules.txt is missing'

Repository: openshift/operator-framework-operator-controller

Length of output: 26048


🏁 Script executed:

#!/usr/bin/env bash
set -u

printf '%s\n' '--- corrected root module graph ---'
go list -m -mod=readonly all > /tmp/go-modules-readonly.txt
status=$?
echo "go list status: $status"
if [ "$status" -eq 0 ]; then
  wc -l /tmp/go-modules-readonly.txt
  rg -n '^(github.com/containerd/containerd|golang.org/x/crypto) ' /tmp/go-modules-readonly.txt
fi

printf '%s\n' '--- root dependency declarations and hashes ---'
rg -n 'github.com/containerd/containerd|golang.org/x/crypto' go.mod go.sum vendor/modules.txt

printf '%s\n' '--- direct dependency hash coverage ---'
python3 - <<'PY'
from pathlib import Path
import re

mod = Path("go.mod").read_text()
sum_lines = Path("go.sum").read_text().splitlines()
hashed = {line.split()[0] for line in sum_lines if len(line.split()) >= 2}
declared = []
in_block = False
for line in mod.splitlines():
    if line.strip() == "require (":
        in_block = True
        continue
    if in_block and line.strip() == ")":
        in_block = False
        continue
    if in_block:
        m = re.match(r"\s*(\S+)\s+(\S+)", line)
        if m:
            declared.append(m.group(1))
missing = [name for name in declared if name not in hashed]
print(f"declared modules: {len(declared)}")
print(f"declared modules without a matching go.sum module entry: {len(missing)}")
for name in missing[:30]:
    print(name)
PY

printf '%s\n' '--- tracked workflow/config paths ---'
git ls-files | awk '
  /(^|\/)(\.github\/|\.tekton\/|\.gitlab-ci|\.circleci\/|\.travis|prow|release|build|ci\/)/ {print}
' | head -300

Repository: openshift/operator-framework-operator-controller

Length of output: 21442


🌐 Web query:

OSV.dev records GO-2026-5064, GO-2026-5338, GO-2026-5622, and GO-2026-5932 for the Go modules github.com/containerd/containerd v1.7.34 and golang.org/x/crypto v0.54.0

💡 Result:

The OSV.dev records you referenced pertain to specific security advisories concerning the listed Go modules [1][2][3][4]. For github.com/containerd/containerd, the following records apply to the CRI (Container Runtime Interface) checkpoint restore functionality [1][3][4]: GO-2026-5064: Concerns a CDI (Container Device Interface) annotation smuggling vulnerability during CRI checkpoint restore [1]. GO-2026-5338: Relates to a local image tag poisoning vulnerability allowed by CRI checkpoint import [3]. GO-2026-5622: Involves an arbitrary host CRI log file read vulnerability via symlink following during CRI checkpoint restore [4]. Note that containerd v1.7.34, released in 2026, includes various security and dependency updates [5], though these specific OSV records were marked as UNREVIEWED as of June 2026 [1][3][4]. For golang.org/x/crypto v0.54.0, the record is: GO-2026-5932: This is a reviewed advisory stating that the golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and contains known security issues [2]. Users are advised to avoid this package and instead utilize a maintained alternative, such as github.com/ProtonMail/go-crypto/openpgp, which serves as a drop-in replacement [2]. The Go ecosystem continues to support golang.org/x/crypto for other cryptographic needs [6][7], but this specific sub-package is deprecated due to its security posture [2].

Citations:


🏁 Script executed:

#!/usr/bin/env bash
set -u

printf '%s\n' '--- root module reachability ---'
go mod why -m github.com/containerd/containerd
go mod why -m golang.org/x/crypto

printf '%s\n' '--- root source imports outside vendor ---'
rg -n --glob '*.go' --glob '!vendor/**' --glob '!**/vendor/**' \
  'github\.com/containerd/containerd|golang\.org/x/crypto(/openpgp)?' . || true

printf '%s\n' '--- OSV records ---'
python3 - <<'PY'
import json
import urllib.request

for vuln in ("GO-2026-5064", "GO-2026-5338", "GO-2026-5622", "GO-2026-5932"):
    try:
        with urllib.request.urlopen(
            f"https://api.osv.dev/v1/vulns/{vuln}", timeout=15
        ) as response:
            data = json.load(response)
        print(vuln)
        print("summary:", data.get("summary"))
        for affected in data.get("affected", []):
            package = affected.get("package", {})
            ranges = affected.get("ranges", [])
            versions = affected.get("versions", [])
            print(" package:", package.get("name"))
            print(" versions:", versions[:10], "..." if len(versions) > 10 else "")
            print(" ranges:", [(r.get("type"), r.get("events")) for r in ranges])
    except Exception as exc:
        print(vuln, "ERROR", exc)
PY

Repository: openshift/operator-framework-operator-controller

Length of output: 6173


Remove the reachable golang.org/x/crypto/openpgp dependency before merging.

The root graph selects golang.org/x/crypto v0.54.0, which reaches go.podman.io/image/v5/signature through golang.org/x/crypto/openpgp. OSV reports GO-2026-5932 for this unsafe, unmaintained package. Replace the OpenPGP path or document an approved exception. Also assess the three containerd advisories reported for v1.7.34. The repository contains no tracked OSV, SBOM, provenance, or signing controls.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` around lines 23 - 31, Remove the reachable
golang.org/x/crypto/openpgp dependency from the module graph, replacing the
OpenPGP-based path used through go.podman.io/image/v5/signature or documenting
an approved exception. Also assess and address the three containerd advisories
associated with v1.7.34, adding the repository’s required security controls for
OSV, SBOM, provenance, or signing if needed.

Source: Path instructions

github.com/spf13/cobra v1.10.2
github.com/spf13/pflag v1.0.10
github.com/stretchr/testify v1.11.1
Expand All @@ -38,13 +38,13 @@ require (
golang.org/x/sync v0.22.0
golang.org/x/tools v0.48.0
helm.sh/helm/v3 v3.21.3
k8s.io/api v0.36.2
k8s.io/api v0.36.3
k8s.io/apiextensions-apiserver v0.36.2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- go.mod diff ---'
git diff -- go.mod

printf '%s\n' '--- go.mod Kubernetes block ---'
nl -ba go.mod | sed -n '35,52p'

printf '%s\n' '--- go.sum entries for changed Kubernetes modules ---'
for module in \
  k8s.io/api \
  k8s.io/apimachinery \
  k8s.io/apiextensions-apiserver \
  k8s.io/client-go \
  k8s.io/component-base \
  k8s.io/kube-aggregator \
  k8s.io/kube-openapi
do
  printf '%s\n' "[$module]"
  rg "^${module//\//\\/} v0\\.36\\.[23](/go\\.mod)? " go.sum || true
done

printf '%s\n' '--- repository supply-chain and dependency metadata files ---'
git ls-files | rg '(^|/)(go\\.sum|\\.github/|Dockerfile|Makefile|\\.goreleaser|.*sbom.*|.*provenance.*|.*cosign.*)' | head -200

Repository: openshift/operator-framework-operator-controller

Length of output: 7010


🌐 Web query:

Kubernetes apiextensions-apiserver v0.36.3 go.mod companion module versions

💡 Result:

The k8s.io/apiextensions-apiserver module at version v0.36.3 relies on the following key companion module versions in its go.mod file [1]: Dependency Module | Version --- | --- github.com/emicklei/go-restful/v3 | v3.13.0 github.com/fxamacker/cbor/v2 | v2.9.0 github.com/google/cel-go | v0.26.0 github.com/google/gnostic-models | v0.7.0 github.com/google/go-cmp | v0.7.0 github.com/google/uuid | v1.6.0 github.com/spf13/cobra | v1.10.2 github.com/spf13/pflag | v1.0.9 github.com/stretchr/testify | v1.11.1 go.etcd.io/etcd/client/pkg/v3 | v3.6.8 go.etcd.io/etcd/client/v3 | v3.6.8 go.opentelemetry.io/otel | v1.41.0 go.opentelemetry.io/otel/trace | v1.41.0 go.yaml.in/yaml/v2 | v2.4.3 golang.org/x/sync | v0.19.0 golang.org/x/text | v0.33.0 google.golang.org/grpc | v1.79.3 google.golang.org/protobuf | v1.36.12-0.20260120151049-f2248ac996af gopkg.in/evanphx/json-patch.v4 | v4.13.0 k8s.io/api | v0.36.3 k8s.io/apimachinery | v0.36.3 k8s.io/apiserver | v0.36.3 k8s.io/client-go | v0.36.3 k8s.io/code-generator | v0.36.3 k8s.io/component-base | v0.36.3 k8s.io/klog/v2 | v2.140.0 k8s.io/kube-openapi | v0.0.0-20260317180543-43fb72c5454a k8s.io/utils | v0.0.0-20260210185600-b8788abfbbc2 sigs.k8s.io/json | v0.0.0-20250730193827-2d320260d730 sigs.k8s.io/randfill | v1.0.0 sigs.k8s.io/structured-merge-diff/v6 | v6.3.3 sigs.k8s.io/yaml | v1.6.0 The module requires Go version 1.26.0 [1]. As part of the Kubernetes 1.36 release cycle, this module was updated to v0.36.3 alongside other core components [2][3]. This version specifically includes updates to dependencies such as sigs.k8s.io/structured-merge-diff/v6 to version v6.3.3 [2]. Note that many Kubernetes-internal modules are synced across the repository and share identical version numbers (v0.36.3) [1][4].

Citations:


🌐 Web query:

OSV k8s.io/apiextensions-apiserver v0.36.3 vulnerabilities

💡 Result:

As of August 7, 2026, there are no specific security vulnerabilities publicly associated with k8s.io/apiextensions-apiserver version v0.36.3 [1][2]. The k8s.io/apiextensions-apiserver repository is a staged component of the Kubernetes project [1][3]. Security advisories for Kubernetes are managed centrally via the Kubernetes Security Response Committee and are tracked in the official Kubernetes CVE feed [4][5]. While various Kubernetes-related vulnerabilities have been disclosed in 2026 (such as CVE-2026-3864 and CVE-2026-3865 affecting CSI drivers) [4][6][7], none of these reports identify version v0.36.3 of the apiextensions-apiserver as vulnerable [4][5]. Version v0.36.3 is a maintenance release [8][9] that synchronizes with the broader Kubernetes v1.36.x series (based on the versioning patterns observed in the ecosystem) [1][8]. Users should rely on the official Kubernetes security announcements and the Go vulnerability database for up-to-date information regarding any components [2][4].

Citations:


🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- go.mod Kubernetes block ---'
sed -n '35,52p' go.mod

printf '%s\n' '--- Kubernetes module references in go.mod and vendor metadata ---'
rg -n -C 1 'k8s\.io/(api|apimachinery|apiextensions-apiserver|apiserver|client-go|code-generator|component-base|kube-openapi)' go.mod vendor/modules.txt

printf '%s\n' '--- direct imports of apiextensions-apiserver ---'
rg -n 'k8s\.io/apiextensions-apiserver' --glob '!vendor/**' --glob '!**/go.sum' .

printf '%s\n' '--- upstream module manifests ---'
for version in v0.36.2 v0.36.3; do
  printf '%s\n' "--- $version ---"
  curl --fail --silent --show-error \
    "https://raw.githubusercontent.com/kubernetes/apiextensions-apiserver/$version/go.mod" |
    sed -n '1,90p'
done

Repository: openshift/operator-framework-operator-controller

Length of output: 50404


🏁 Script executed:

#!/bin/bash
set -eu

python3 - <<'PY'
from pathlib import Path
import re

text = Path("go.mod").read_text()
mods = {}
for line in text.splitlines():
    m = re.match(r"\s*(k8s\.io/\S+)\s+(v\S+)", line)
    if m:
        mods[m.group(1)] = m.group(2)

names = [
    "k8s.io/api",
    "k8s.io/apimachinery",
    "k8s.io/apiextensions-apiserver",
    "k8s.io/apiserver",
    "k8s.io/client-go",
    "k8s.io/code-generator",
    "k8s.io/component-base",
    "k8s.io/kube-openapi",
]
print("Root go.mod Kubernetes requirements:")
for name in names:
    print(f"{name}: {mods.get(name, '<not directly required>')}")
PY

Repository: openshift/operator-framework-operator-controller

Length of output: 498


🏁 Script executed:

#!/bin/bash
set -eu

printf '%s\n' '--- upstream Kubernetes requirements for apiextensions-apiserver ---'
for version in v0.36.2 v0.36.3; do
  printf '%s\n' "--- $version ---"
  curl --fail --silent --show-error \
    "https://raw.githubusercontent.com/kubernetes/apiextensions-apiserver/$version/go.mod" |
    grep -E '^(go |require \(|\s*k8s\.io/(api|apimachinery|apiserver|client-go|code-generator|component-base|kube-openapi))'
done

printf '%s\n' '--- root vendor module headers for Kubernetes modules ---'
grep -E '^# k8s\.io/(api|apimachinery|apiextensions-apiserver|apiserver|cli-runtime|client-go|component-base|klog/v2|kube-openapi|kubectl) ' vendor/modules.txt

printf '%s\n' '--- root dependency checksums for apiextensions-apiserver ---'
grep -E '^k8s\.io/apiextensions-apiserver ' go.sum || true

Repository: openshift/operator-framework-operator-controller

Length of output: 1401


🌐 Web query:

Kubernetes staging Go modules patch version skew policy apiextensions-apiserver apiserver

💡 Result:

There is no independent patch version skew policy for Kubernetes staging Go modules like apiextensions-apiserver or apiserver [1][2]. Instead, their versioning and dependency management are strictly tied to the main Kubernetes release cadence [1][3][4]. Key points regarding the management and skew of these modules include: Staging Repository Authoritative Source: All k8s.io/* staging modules (e.g., k8s.io/apiserver, k8s.io/apiextensions-apiserver) are managed within the main kubernetes/kubernetes repository under the staging/ directory [5][6]. This directory is considered the authoritative source; code changes made here are merged into the main repository and subsequently synced to the standalone k8s.io repositories [4][5]. Version Alignment: The modules k8s.io/apiserver and k8s.io/apiextensions-apiserver follow the Kubernetes release version (e.g., v0.36.2) [3]. They are designed to stay in sync with other core staging modules like k8s.io/apimachinery and k8s.io/client-go [3]. When a new Kubernetes minor release is cut, these modules are tagged with matching minor versions [1][3]. No Independent Patch Version Skew: Because these modules are developed, tested, and released as part of a monolithic Kubernetes release, there is no concept of "patch version skew" between them [1][5]. Consumers are expected to use matching versions of all k8s.io modules to ensure compatibility [1][7]. Mixing different patch versions of staging modules—or trying to use them independently of the Kubernetes release—is unsupported and will likely lead to dependency conflicts or runtime errors [7][8]. Version Skew Policy for Components: The official Kubernetes Version Skew Policy [2] applies to running cluster components (e.g., kube-apiserver, kubelet, kube-controller-manager), not the underlying Go module dependencies [2][7]. For example, the policy allows a maximum skew of ±1 minor version between the kube-apiserver and various controllers, and up to 2 minor versions for the kubelet [2]. This policy dictates operational cluster upgrades, not the Go module import constraints [2][7]. Developers building tools that consume these modules should depend on the tagged versions corresponding to the target Kubernetes minor release and ensure all imported k8s.io modules share the same version suffix to maintain consistency [1][7][3].

Citations:


Use matching Kubernetes v0.36.3 modules.

Update k8s.io/apiextensions-apiserver to v0.36.3. The current go.mod, go.sum, and vendor/modules.txt retain v0.36.2 while the companion modules use v0.36.3. Regenerate the module metadata and vendor tree.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` at line 42, Update the k8s.io/apiextensions-apiserver dependency from
v0.36.2 to v0.36.3 in go.mod, then regenerate go.sum and the vendor tree so
vendor/modules.txt and vendored contents consistently use v0.36.3 alongside the
companion Kubernetes modules.

k8s.io/apimachinery v0.36.2
k8s.io/apiserver v0.36.2
k8s.io/cli-runtime v0.36.2
k8s.io/client-go v0.36.2
k8s.io/component-base v0.36.2
k8s.io/apimachinery v0.36.3
k8s.io/apiserver v0.36.3
k8s.io/cli-runtime v0.36.3
k8s.io/client-go v0.36.3
k8s.io/component-base v0.36.3
k8s.io/klog/v2 v2.140.0
k8s.io/utils v0.0.0-20260626114624-be93311217bd
pkg.package-operator.run/boxcutter v0.14.0
Expand Down Expand Up @@ -187,7 +187,7 @@ require (
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
github.com/proglottis/gpgme v0.1.6 // indirect
github.com/prometheus/client_model v0.6.2 // indirect
github.com/prometheus/procfs v0.21.0 // indirect
github.com/prometheus/procfs v0.21.1 // indirect
github.com/rubenv/sql-migrate v1.8.1 // indirect
github.com/russross/blackfriday/v2 v2.1.0 // indirect
github.com/secure-systems-lab/go-securesystemslib v0.11.0 // indirect
Expand Down Expand Up @@ -245,7 +245,7 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
k8s.io/kube-openapi v0.0.0-20260520065146-aa012df4f4af // indirect
k8s.io/kubectl v0.36.2 // indirect
k8s.io/streaming v0.36.2 // indirect
k8s.io/streaming v0.36.3 // indirect
oras.land/oras-go/v2 v2.6.2 // indirect
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect
sigs.k8s.io/gateway-api v1.6.0 // indirect
Expand Down
48 changes: 24 additions & 24 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -328,8 +328,8 @@ github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnr
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8=
github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
github.com/klauspost/compress v1.19.0 h1:sXLILfc9jV2QYWkzFOPWStmcUVH2RHEB1JCdY2oVvCQ=
github.com/klauspost/compress v1.19.0/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk=
github.com/klauspost/compress v1.19.1/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
github.com/klauspost/pgzip v1.2.6 h1:8RXeL5crjEUFnR2/Sn6GJNWtSQ3Dk8pq4CL3jvdDyjU=
github.com/klauspost/pgzip v1.2.6/go.mod h1:Ch1tH69qFZu15pkjo5kYi6mth2Zzwzt50oCQKQE9RUs=
github.com/kr/pretty v0.2.1/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI=
Expand Down Expand Up @@ -438,17 +438,17 @@ github.com/poy/onpar v1.1.2 h1:QaNrNiZx0+Nar5dLgTVp5mXkyoVFIbepjyEoGSnhbAY=
github.com/poy/onpar v1.1.2/go.mod h1:6X8FLNoxyr9kkmnlqpK6LSoiOtrO6MICtWwEuWkLjzg=
github.com/proglottis/gpgme v0.1.6 h1:8WpQ8VWggLdxkuTnW+sZ1r1t92XBNd8GZNDhQ4Rz+98=
github.com/proglottis/gpgme v0.1.6/go.mod h1:5LoXMgpE4bttgwwdv9bLs/vwqv3qV7F4glEEZ7mRKrM=
github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg=
github.com/prometheus/client_golang v1.24.0 h1:5XStIklKuAtJSNpdD3s8XJj/Yv78IQmE1kbNk87JrAI=
github.com/prometheus/client_golang v1.24.0/go.mod h1:QcsNdotprC2nS4BTM2ucbcqxd2CeXTEa9jW7zHO9iDE=
github.com/prometheus/client_model v0.0.0-20190812154241-14fe0d1b01d4/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
github.com/prometheus/common v0.70.0 h1:bcpru3tWPVnxGnETLgOV5jbp/JRXgYEyv65CuBLAMMI=
github.com/prometheus/common v0.70.0/go.mod h1:S/SFasQmgGiYH6C81LKCtYa8QACgthGg5zxL2udV7SY=
github.com/prometheus/common v0.70.1 h1:1HvjP4D5oL3t8RsPlwxA9onvvStjtIHYE5XuuwOi/PY=
github.com/prometheus/common v0.70.1/go.mod h1:VdFUQDMZK3VLkurFUVhia6uys/0suUp86TJz5qbJRhc=
github.com/prometheus/otlptranslator v1.0.0 h1:s0LJW/iN9dkIH+EnhiD3BlkkP5QVIUVEoIwkU+A6qos=
github.com/prometheus/otlptranslator v1.0.0/go.mod h1:vRYWnXvI6aWGpsdY/mOT/cbeVRBlPWtBNDb7kGR3uKM=
github.com/prometheus/procfs v0.21.0 h1:Qh/e6TlBjZf+XLLqNCqFGmCU6Kj/2Bu7kj3oAc0UnXc=
github.com/prometheus/procfs v0.21.0/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
github.com/redis/go-redis/extra/rediscmd/v9 v9.17.3 h1:v9RNP5ynWkruvzscrIoDyyv20c9YeyVn12L9nYnaexw=
github.com/redis/go-redis/extra/rediscmd/v9 v9.17.3/go.mod h1:gdthSemCkR3WxTmzV2XxYIxClunkUJZAhL0zPHaB0Ww=
github.com/redis/go-redis/extra/redisotel/v9 v9.17.3 h1:bF0e3fV7PL0knd1UHDtMud8wA7CZt3RSWtyTMhpnWd8=
Expand All @@ -461,8 +461,8 @@ github.com/rubenv/sql-migrate v1.8.1 h1:EPNwCvjAowHI3TnZ+4fQu3a915OpnQoPAjTXCGOy
github.com/rubenv/sql-migrate v1.8.1/go.mod h1:BTIKBORjzyxZDS6dzoiw6eAFYJ1iNlGAtjn4LGeVjS8=
github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf35Ld67mk=
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ=
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28=
github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
github.com/secure-systems-lab/go-securesystemslib v0.11.0 h1:iuCR9kcMFD4QurdKrGvPLoKZLv9YvwPYVr0473BdtFs=
github.com/secure-systems-lab/go-securesystemslib v0.11.0/go.mod h1:+PMOTjUGwHj2vcZ+TFKlb1tXRbrdWE1LYDT5i9JC80Q=
github.com/sergi/go-diff v1.4.0 h1:n/SP9D5ad1fORl+llWyN+D6qoUETXNZARKjyY2/KVCw=
Expand Down Expand Up @@ -773,28 +773,28 @@ helm.sh/helm/v3 v3.21.3 h1:wkamdwI3liEkW6wI1l9aGqQZGxcTKyt8kx0qJLPcmCg=
helm.sh/helm/v3 v3.21.3/go.mod h1:iaJ0iNsPoTZl++7h6vzQFyT0VEVtLYJiyRBDkPOOBTs=
honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
k8s.io/api v0.36.2 h1:TF6YDLIzKfccK7cq9YpTcGX8TJmEkHVRv78DM51fRYY=
k8s.io/api v0.36.2/go.mod h1:F4LbMO4brjZYh7yFkXWhynSvtB7YauxV4c+HHkNRGNg=
k8s.io/api v0.36.3 h1:NxB+05W2UGqXWFXcLO0RB5cnqnUPP5v5sVlaOH0Iz4w=
k8s.io/api v0.36.3/go.mod h1:JzLQKqRHC5+I8RVj/lS3lCg0mg6nWI9Fo/Sk3ElxHzg=
k8s.io/apiextensions-apiserver v0.36.2 h1:3O5gqOj/dt2XWWbpMe+TXWpE9yU6pjM/tXxtHHJT/K4=
k8s.io/apiextensions-apiserver v0.36.2/go.mod h1:cL1tBWe8XSaP1H30iWKGo7hf6iAUUUJPEU70dskmAnA=
k8s.io/apimachinery v0.36.2 h1:0PE/W/WNy1UX61NLbXY5TMbJ6UwLL6E6lAPkYrKFxbQ=
k8s.io/apimachinery v0.36.2/go.mod h1:fvf/HOLXq9RId0rnDIbN1OEBvHXdQbLMM8nu0LcBUf4=
k8s.io/apiserver v0.36.2 h1:6vMnkmHZPeBloNkHUhmZYq7Ylv8WIB8xjyEl+eSt26E=
k8s.io/apiserver v0.36.2/go.mod h1:9PoQ2ikCytrZyZg11mGhLEF5m8Rgsb5FJmYJ4Wvnl1k=
k8s.io/cli-runtime v0.36.2 h1:CconTvEeV4DJs4ZX3HQKCFbFRGsm6OtuBM9yjmMP2VM=
k8s.io/cli-runtime v0.36.2/go.mod h1:LddcjiMf4YlnHO7c1Y7rEtDqL84FyiYVLco7V679GUU=
k8s.io/client-go v0.36.2 h1:bfgxmFKc9CgqsgX4xKLAAdmTQlWee7Ob/HlDOrJ5TBI=
k8s.io/client-go v0.36.2/go.mod h1:1vgO4OAlfPnoLcb+Rze2GF5rAr14w8qjrYMoyXJzQj0=
k8s.io/component-base v0.36.2 h1:Z0VH80O7Ng0HDZnZj3WRR3urEGa0kTwmO8CwEwjVK1w=
k8s.io/component-base v0.36.2/go.mod h1:mGfFOA7Gwpdm1VW2cwSQYbiDIlz8GD2WGwH88QSeCyA=
k8s.io/apimachinery v0.36.3 h1:PkzMRBRG8joFD8EhCuQAtNPvJlxb82FwplP26HIzvAM=
k8s.io/apimachinery v0.36.3/go.mod h1:cTSjBWgPe/6CQyBKzY/hDIRWCQQQeK0mfLbml0UYFHE=
k8s.io/apiserver v0.36.3 h1:MGSg2SkdfuytiDEcRylT5mQFmmSsbx90XFUO67Y4bsQ=
k8s.io/apiserver v0.36.3/go.mod h1:fVH7zv9EUNUA7Fl7LtDKh8aB9W7u1VQPSGtWV5SjUxg=
k8s.io/cli-runtime v0.36.3 h1:g+eJ+M1sYpnNYp/q5fzaw2KejIL0Q7DH+xFl6YVoL4U=
k8s.io/cli-runtime v0.36.3/go.mod h1:hZpAqK8nSFXvvLaVCbzUPVp8e9TRLSTCfpNzMt7s3tE=
k8s.io/client-go v0.36.3 h1:M4JdVzXxYcZk4fGpfDdYnxSwhLKWCFoQsHW6t+z8Hfg=
k8s.io/client-go v0.36.3/go.mod h1:gcPwr0c87vjjG6HB6pWEqOeuYVoXSsREjzux2j6GF30=
k8s.io/component-base v0.36.3 h1:vc/UFvPCkW0irPz84LAodAL1j3f4xktPM6dDJIEheAY=
k8s.io/component-base v0.36.3/go.mod h1:hZbNFG+gCMl9EbykDGEu73feKP9/Cq6JsV4pTo9GTO8=
k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc=
k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0=
k8s.io/kube-openapi v0.0.0-20260520065146-aa012df4f4af h1:zLXA2Irn14q2/06WMkxViyr7YCPUO2lJ0QYE9Juy5vA=
k8s.io/kube-openapi v0.0.0-20260520065146-aa012df4f4af/go.mod h1:V/QaCUYDa+0QpcHhVVc5l99Uz56wEMEXBSj9oCDkNDY=
k8s.io/kubectl v0.36.2 h1:rpUGGpeL09XVOLep2yle5jrtk//JA1L6ZHfkQQtVEwk=
k8s.io/kubectl v0.36.2/go.mod h1:gVbQ3B/yb4bSR2ggQ7rd0W6icUSWs7sduH4e16Vii+0=
k8s.io/streaming v0.36.2 h1:NSKthPPg9UFSKsRauVJUVGH2Dvn8fhKmY4qrMkw/p98=
k8s.io/streaming v0.36.2/go.mod h1:z6fV3D+NVkoeqRMtWwlUZK6U17SY/LqNzOxWL6GyR/s=
k8s.io/streaming v0.36.3 h1:9rAaqBk0C0Pc7+/fqGekj07NV+/Xrew58p647A0JT8w=
k8s.io/streaming v0.36.3/go.mod h1:z6fV3D+NVkoeqRMtWwlUZK6U17SY/LqNzOxWL6GyR/s=
k8s.io/utils v0.0.0-20260626114624-be93311217bd h1:Ea7fgQ5we8Y9T0OX5o0dAHzQOBRI07D/dEYRaB9ZZEs=
k8s.io/utils v0.0.0-20260626114624-be93311217bd/go.mod h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk=
oras.land/oras-go/v2 v2.6.2 h1:N04RXngAp1LJKTG6ifz3xHPipasEkWr+hFmInja5YKo=
Expand Down
16 changes: 8 additions & 8 deletions openshift/tests-extension/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -20,11 +20,11 @@ require (
github.com/tidwall/gjson v1.18.0
github.com/tidwall/pretty v1.2.1
gopkg.in/yaml.v3 v3.0.1
k8s.io/api v0.36.2
k8s.io/api v0.36.3
k8s.io/apiextensions-apiserver v0.36.2
k8s.io/apimachinery v0.36.2
k8s.io/apiserver v0.36.2
k8s.io/client-go v0.36.2
k8s.io/apimachinery v0.36.3
k8s.io/apiserver v0.36.3
k8s.io/client-go v0.36.3
k8s.io/kubernetes v1.34.1
k8s.io/utils v0.0.0-20260626114624-be93311217bd
sigs.k8s.io/controller-runtime v0.24.1
Expand Down Expand Up @@ -77,10 +77,10 @@ require (
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
github.com/prometheus/client_golang v1.23.2 // indirect
github.com/prometheus/client_golang v1.24.0 // indirect
github.com/prometheus/client_model v0.6.2 // indirect
github.com/prometheus/common v0.70.0 // indirect
github.com/prometheus/procfs v0.21.0 // indirect
github.com/prometheus/common v0.70.1 // indirect
github.com/prometheus/procfs v0.21.1 // indirect
github.com/sirupsen/logrus v1.9.4 // indirect
github.com/spf13/pflag v1.0.10 // indirect
github.com/tidwall/match v1.1.1 // indirect
Expand Down Expand Up @@ -113,7 +113,7 @@ require (
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
k8s.io/component-base v0.36.2 // indirect
k8s.io/component-base v0.36.3 // indirect
k8s.io/component-helpers v0.34.0 // indirect
k8s.io/controller-manager v0.33.2 // indirect
k8s.io/klog/v2 v2.140.0 // indirect
Expand Down
16 changes: 8 additions & 8 deletions openshift/tests-extension/go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -98,8 +98,8 @@ github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnr
github.com/json-iterator/go v1.1.12/go.mod h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8=
github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
github.com/klauspost/compress v1.19.0 h1:sXLILfc9jV2QYWkzFOPWStmcUVH2RHEB1JCdY2oVvCQ=
github.com/klauspost/compress v1.19.0/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk=
github.com/klauspost/compress v1.19.1/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
Expand Down Expand Up @@ -167,14 +167,14 @@ github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINE
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg=
github.com/prometheus/client_golang v1.24.0 h1:5XStIklKuAtJSNpdD3s8XJj/Yv78IQmE1kbNk87JrAI=
github.com/prometheus/client_golang v1.24.0/go.mod h1:QcsNdotprC2nS4BTM2ucbcqxd2CeXTEa9jW7zHO9iDE=
github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
github.com/prometheus/common v0.70.0 h1:bcpru3tWPVnxGnETLgOV5jbp/JRXgYEyv65CuBLAMMI=
github.com/prometheus/common v0.70.0/go.mod h1:S/SFasQmgGiYH6C81LKCtYa8QACgthGg5zxL2udV7SY=
github.com/prometheus/procfs v0.21.0 h1:Qh/e6TlBjZf+XLLqNCqFGmCU6Kj/2Bu7kj3oAc0UnXc=
github.com/prometheus/procfs v0.21.0/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
github.com/prometheus/common v0.70.1 h1:1HvjP4D5oL3t8RsPlwxA9onvvStjtIHYE5XuuwOi/PY=
github.com/prometheus/common v0.70.1/go.mod h1:VdFUQDMZK3VLkurFUVhia6uys/0suUp86TJz5qbJRhc=
github.com/prometheus/procfs v0.21.1 h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
github.com/prometheus/procfs v0.21.1/go.mod h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
Expand Down

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

This file was deleted.

Loading