Skip to content

build(deps): bump the misc-dependencies group across 1 directory with 4 updates - #9312

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/misc-dependencies-e2c7f69965
Open

build(deps): bump the misc-dependencies group across 1 directory with 4 updates#9312
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/misc-dependencies-e2c7f69965

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the misc-dependencies group with 3 updates in the / directory: google.golang.org/api, kubevirt.io/api and kubevirt.io/containerized-data-importer-api.

Updates google.golang.org/api from 0.290.0 to 0.292.0

Release notes

Sourced from google.golang.org/api's releases.

v0.292.0

0.292.0 (2026-08-04)

Features

v0.291.0

0.291.0 (2026-07-28)

Features

Bug Fixes

  • transport: Use ds.GetUniverseDomain() instead of raw ds.UniverseDomain field (#3660) (6bad358)
Changelog

Sourced from google.golang.org/api's changelog.

0.292.0 (2026-08-04)

Features

0.291.0 (2026-07-28)

Features

Bug Fixes

  • transport: Use ds.GetUniverseDomain() instead of raw ds.UniverseDomain field (#3660) (6bad358)
Commits

Updates google.golang.org/grpc from 1.82.1 to 1.83.0

Release notes

Sourced from google.golang.org/grpc's releases.

Release 1.83.0

Security

  • server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT.
  • xds/rbac: Support Metadata and RequestedServerName permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open.
  • xds/rbac: Fix panic when parsing unsupported fields in NotRule/NotId permissions.
  • xds/rbac: Support the deprecated source_ip principal identifier by treating it as equivalent to direct_remote_ip.
  • xds: Fix panic when parsing route header matchers configured with empty exact_match, prefix_match, or suffix_match strings. (#9223)

New Features

  • xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the force-xds target URI query parameter. (#9133)
  • xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. (#9145)
  • authz: Add OnPolicyUpdate callback to FileWatcherOptions to notify when an authz policy is loaded or updated. (#9142)
  • xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs.
    • This feature can be enabled by setting environment variable GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true. (#9119)
  • xds: Add support for xDS-based HTTP CONNECT proxies.
    • This feature can be enabled by setting environment variable GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true. (#9151)
  • xds: Add support for contains_match in route header matchers. (#9223)

Bug Fixes

  • credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. (#9197)
  • grpc: Fix compilation on Plan 9 targets (GOOS=plan9), broken since v1.81.0. (#9255)
Commits
  • 4c226da Change version to 1.83.0 (#9228)
  • c198988 Cherrypick 9223 into v1.83.x (#9279)
  • 8ce3ebf Cherrypick PR 9255 into v1.83.x (#9263)
  • e393849 Cherry-pick recent changes from master (#9240)
  • 2a112a8 authz: add onPolicyUpdate callback to authz file watcher (#9142)
  • 1a80fca vet: adds a check to disallow usage of regex.Compile in xDS code (#9216)
  • 26ffdb3 [tls] Add safety check in custom cert verification that peer cert chain is no...
  • 5013974 internal/grpcsync: add ScheduleAndWait to CallbackSerializer (#9162)
  • bd58bc0 internal/transport: increase test timeout locally in TestAccountCheckWindowSi...
  • 484f150 httpfilter/extproc: add check to ensure that response trailer mode must be SE...
  • Additional commits viewable in compare view

Updates kubevirt.io/api from 1.8.4 to 1.9.0

Commits
  • 83a8fc3 api update by KubeVirt Prow build 2082808337480552448
  • 8fb6035 api update by KubeVirt Prow build 2081408016631992320
  • 8a71446 api update by KubeVirt Prow build 2081183370464727040
  • 8fe9ba3 api update by KubeVirt Prow build 2081187560167575552
  • dcfb224 api update by KubeVirt Prow build 2080820979432427520
  • 76b5c67 api update by KubeVirt Prow build 2080733071321075712
  • 4ef2507 api update by KubeVirt Prow build 2080733108688130048
  • 27cbe21 api update by KubeVirt Prow build 2078161080135192576
  • 1b04bb1 api update by KubeVirt Prow build 2077088456936263680
  • 3e76ac1 api update by KubeVirt Prow build 2076983216459223040
  • Additional commits viewable in compare view

Updates kubevirt.io/containerized-data-importer-api from 1.65.0 to 1.66.0

Commits
  • 39144c3 containerized-data-importer-api update by KubeVirt Prow build 208506990475870...
  • a7b0542 containerized-data-importer-api update by KubeVirt Prow build 207745580380298...
  • 4b97fe6 containerized-data-importer-api update by KubeVirt Prow build 206907729846364...
  • 50fe031 containerized-data-importer-api update by KubeVirt Prow build 205163622804174...
  • 595620c containerized-data-importer-api update by KubeVirt Prow build 204663201925274...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated several underlying service and platform dependencies to newer versions.
    • Improved compatibility and maintenance without changing the user-facing functionality.

@dependabot dependabot Bot added area/ci-tooling Indicates the PR includes changes for CI or tooling ok-to-test Indicates a non-member PR verified by an org member that is safe to test. labels Aug 14, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 1afbec88-93d4-435e-b7b3-04bb0687b14a

📥 Commits

Reviewing files that changed from the base of the PR and between f7e85cc and 277c3fa.

⛔ Files ignored due to path filters (46)
  • go.sum is excluded by !**/*.sum
  • vendor/cloud.google.com/go/auth/CHANGES.md is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/credentials/detect.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/credentials/filetypes.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/httptransport/transport.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/internal.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/regionalaccessboundary/external_accounts_config_providers.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/regionalaccessboundary/regional_access_boundary.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/retry/retry.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/retry/retry_linux.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/transport/headers/headers.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/trustboundary/trust_boundary.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute-api.json is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute2-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute3-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/dns/v1/dns-api.json is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/dns/v1/dns-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/iam/v1/iam-api.json is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/iam/v1/iam-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/internal/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/transport/http/dial.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/clientconn.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/clientconn_disconnect_reason_noplan9.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/clientconn_disconnect_reason_plan9.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/envconfig/xds.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/grpcsync/callback_serializer.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/resolver/config_selector.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/transport/client_stream.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_client.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/transport/transport.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/stream.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/deepcopy_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/types.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/types_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/deepcopy_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/schema.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/schema_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/types.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/types_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/containerized-data-importer-api/pkg/apis/core/v1beta1/types.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/containerized-data-importer-api/pkg/apis/core/v1beta1/types_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/containerized-data-importer-api/pkg/apis/core/v1beta1/zz_generated.deepcopy.go is excluded by !vendor/**, !**/vendor/**, !**/zz_generated*.go, !**/zz_generated*
  • vendor/modules.txt is excluded by !vendor/**, !**/vendor/**
📒 Files selected for processing (1)
  • go.mod

📝 Walkthrough

Walkthrough

Updated dependency versions in go.mod. The changes update Google API, gRPC, KubeVirt API, CDI API, CEL expression, Google Cloud auth, enterprise certificate proxy, and Genproto RPC modules. No exported or public declarations changed.

Suggested reviewers: bryan-cox, joelspeed

Mergeability Score: 🔵 Low · up to 277c3

This PR updates several direct Go dependencies and regenerated vendored APIs, so compatibility with the declared Go toolchain and affected callers should be confirmed before merge. It is otherwise mergeable with owner awareness; the bounded risk is a compatibility regression if those checks are skipped.


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error, 2 warnings)

Check name Status Explanation Resolution
No-Sensitive-Data-In-Logs ❌ Error The update adds debug logging after setting Authorization to the access token; internallog.HTTPRequest serializes every header without redaction. Redact Authorization and other credential headers before logging. Do not log raw request or response bodies, including bodies embedded in warning errors.
Linked Issues check ⚠️ Warning The changes update go.mod dependencies but provide no Pipelines as Code configuration described in issue #9197. Add the required Pipelines as Code configuration for issue #9197, or link an issue that covers the dependency updates.
Out of Scope Changes check ⚠️ Warning The dependency updates are unrelated to the Pipelines as Code configuration objective in issue #9197. Remove the unrelated dependency updates or update the linked issue to define dependency version upgrades as the objective.
✅ Passed checks (8 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the dependency version updates in the root directory.
Stable And Deterministic Test Names ✅ Passed The PR changes go.mod/go.sum and vendored dependency code only; no *_test.go files or Ginkgo title declarations were added or modified.
Test Structure And Quality ✅ Passed The PR changes go.mod, go.sum, and vendored dependency sources only; the diff contains no Ginkgo test files or added test constructs, so this check is inapplicable.
Topology-Aware Scheduling Compatibility ✅ Passed The PR changes only go.mod/go.sum and vendored dependency files; it adds no deployment manifests, operator/controller code, or scheduling constraints.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The pull request changes dependency manifests and vendored code only; the diff adds no *_test.go files or Ginkgo e2e tests.
No-Weak-Crypto ✅ Passed The diff only updates dependency manifests and vendored code; added-line scanning found no MD5/SHA1/DES/RC4/Blowfish/ECB usage, crypto imports, weak constructors, or timing APIs.
Container-Privileges ✅ Passed The diff changes go.mod/go.sum and vendored Go/JSON files only; no container or Kubernetes manifest is changed, and no forbidden privilege setting is added.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/go_modules/misc-dependencies-e2c7f69965

Comment @coderabbitai help to get the list of available commands.

@openshift-ci

openshift-ci Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci
openshift-ci Bot requested review from devguyio and ironcladlou August 14, 2026 01:05
@openshift-ci

openshift-ci Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: dependabot[bot]
Once this PR has been reviewed and has the lgtm label, please assign sjenning for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

… 4 updates

- api: 0.290.0 => 0.292.0
- grpc: 1.82.1 => 1.83.0
- api: 1.8.4 => 1.9.0
- containerized-data-importer-api: 1.65.0 => 1.66.0

Signed-off-by: dependabot[bot] <support@github.com>
@openshift-ci

openshift-ci Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

@dependabot[bot]: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/verify 2b76832 link true /test verify

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci-tooling Indicates the PR includes changes for CI or tooling ok-to-test Indicates a non-member PR verified by an org member that is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants