Skip to content

chore(deps): update module sigs.k8s.io/controller-runtime to v0.25.1 - #39

Open
scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/sigs.k8s.io-controller-runtime-0.x
Open

scality-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/sigs.k8s.io-controller-runtime-0.x

Conversation

@scality-renovate

@scality-renovate scality-renovate Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
sigs.k8s.io/controller-runtime v0.24.1 → v0.25.1 age confidence

Release Notes

kubernetes-sigs/controller-runtime (sigs.k8s.io/controller-runtime)

v0.25.1

Compare Source

What's Changed

Full Changelog: kubernetes-sigs/controller-runtime@v0.25.0...v0.25.1

v0.25.0

Compare Source

Highlights

This version of controller-runtime introduces a new experimental ReadYourWritesConsistency feature,
which ensures that all writes are reflected in subsequent reads from the default cache-backed client.
Stale client reads are arguably the biggest source of friction and sometimes bugs for controller
authors, providing this functionality at the library level eliminates that class of problems entirely.

Try it out by setting Client.EnableReadYourWritesConsistency: new(true) in your manager
and leave any feedback you may have on the tracking issue.

⚠️ Breaking Changes

✨ New Features

  • Client: Add a read-your-own-writes client (#​3472)
  • Fakeclient: Add WithGlobalResourceVersionCounter (#​3581)
  • Fakeclient: Add scale subresource support for Apply (#​3569)
  • Metrics: Allow opt-in for client-go REST client metrics (#​3510)
  • Metrics: Allow overriding client-go REST client metrics latency histogram buckets (#​3573)
  • Source: Add TypedInformer source (#​3520)
  • Webhooks: Allow to disable the webhook server by setting the port to -1 (#​3481)

🐛 Bug Fixes

  • Cache: Fix goroutine leaks in cache Start() methods (#​3565)
  • Client: Fix regression in Apply typed error handling (#​3515)
  • Controller: Unlock when Controller.Start() returns with error (#​3545)
  • Envtest: Fix envtest process stop on Windows (#​3519)
  • Fakeclient: Allow updating managedFields through Update (#​3585)
  • Fakeclient: Fix AddIndex panic when wrapped with an interceptor (#​3583)
  • Fakeclient: Fix PartialObjectMeta handling (#​3571)
  • Fakeclient: Support scale subresource get/update for unstructured objects (#​3546)
  • Fakeclient: Update object on subresource apply (#​3570)
  • PriorityQueue: Fix PriorityQueue deadlock on shutdown (#​3540)
  • Testing/Process: Fix process Stop timeout error handling (#​3523)

🌱 Others

  • LeaderElection: Pass Managers Logger to Leader Elector via Context (#​3576)

🌱 CI & linters

  • Add copyright header validation & fix findings (#​3544)
  • Bump to golangci-lint v2.12.1 (#​3514)
  • Bump to golangci-lint v2.12.2 (#​3532)
  • Bump to golangci-lint v2.13.1 (#​3580)
  • Declare contents: read permissions for pr-verify action (#​3517)
  • Revert "Migrate away from custom GitHub action approval workflow" (#​3528)

📖 Additionally, there have been 7 contributions to our documentation and book. (#​3513, #​3521, #​3531, #​3551, #​3562, #​3563, #​3566)

Dependencies

Added
  • github.com/go-openapi/swag/cmdutils: v0.27.1
  • github.com/go-openapi/swag/conv: v0.27.1
  • github.com/go-openapi/swag/fileutils: v0.27.1
  • github.com/go-openapi/swag/jsonutils/fixtures_test: v0.27.1
  • github.com/go-openapi/swag/jsonutils: v0.27.1
  • github.com/go-openapi/swag/loading: v0.27.1
  • github.com/go-openapi/swag/mangling: v0.27.1
  • github.com/go-openapi/swag/netutils: v0.27.1
  • github.com/go-openapi/swag/pools: v0.27.1
  • github.com/go-openapi/swag/stringutils: v0.27.1
  • github.com/go-openapi/swag/typeutils: v0.27.1
  • github.com/go-openapi/swag/yamlutils: v0.27.1
  • github.com/go-openapi/testify/enable/yaml/v2: v2.6.0
  • github.com/go-openapi/testify/v2: v2.6.0
Changed
  • github.com/Azure/go-ansiterm: 306776e → faa5f7b
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp: v1.30.0 → v1.32.0
  • github.com/antlr4-go/antlr/v4: v4.13.0 → v4.13.1
  • github.com/cncf/xds/go: ee656c7 → dba9d58
  • github.com/envoyproxy/go-control-plane/envoy: v1.36.0 → v1.37.0
  • github.com/envoyproxy/protoc-gen-validate: v1.3.0 → v1.3.3
  • github.com/fxamacker/cbor/v2: v2.9.0 → v2.9.1
  • github.com/go-jose/go-jose/v4: v4.1.3 → v4.1.4
  • github.com/go-openapi/jsonpointer: v0.21.0 → v1.0.0
  • github.com/go-openapi/jsonreference: v0.20.2 → v1.0.0
  • github.com/go-openapi/swag: v0.23.0 → v0.27.1
  • github.com/golang-jwt/jwt/v5: v5.3.0 → v5.3.1
  • github.com/google/cel-go: v0.26.0 → v0.29.2
  • github.com/grpc-ecosystem/grpc-gateway/v2: v2.27.7 → v2.29.0
  • github.com/klauspost/compress: v1.18.0 → v1.19.0
  • github.com/moby/term: v0.5.0 → v0.5.2
  • github.com/prometheus/client_golang: v1.23.2 → v1.24.0
  • github.com/prometheus/common: v0.67.5 → v0.70.0
  • github.com/prometheus/procfs: v0.19.2 → v0.21.1
  • github.com/sirupsen/logrus: v1.9.3 → v1.9.4
  • github.com/spf13/pflag: v1.0.9 → v1.0.10
  • github.com/stretchr/objx: v0.5.2 → v0.5.3
  • go.etcd.io/bbolt: v1.4.3 → v1.5.0
  • go.etcd.io/etcd/api/v3: v3.6.8 → v3.7.0
  • go.etcd.io/etcd/client/pkg/v3: v3.6.8 → v3.7.0
  • go.etcd.io/etcd/client/v3: v3.6.8 → v3.7.0
  • go.etcd.io/etcd/pkg/v3: v3.6.8 → v3.7.0
  • go.etcd.io/etcd/server/v3: v3.6.8 → v3.7.0
  • go.etcd.io/raft/v3: v3.6.0 → v3.7.0
  • go.opentelemetry.io/contrib/detectors/gcp: v1.39.0 → v1.43.0
  • go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc: v0.65.0 → v0.68.0
  • go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp: v0.65.0 → v0.69.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc: v1.40.0 → v1.44.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace: v1.40.0 → v1.44.0
  • go.opentelemetry.io/otel/metric: v1.41.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk/metric: v1.40.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk: v1.40.0 → v1.44.0
  • go.opentelemetry.io/otel/trace: v1.41.0 → v1.44.0
  • go.opentelemetry.io/otel: v1.41.0 → v1.44.0
  • go.opentelemetry.io/proto/otlp: v1.9.0 → v1.10.0
  • go.yaml.in/yaml/v2: v2.4.3 → v2.4.4
  • golang.org/x/crypto: v0.47.0 → v0.54.0
  • golang.org/x/exp: 944ab1f → 746e56f
  • golang.org/x/mod: v0.32.0 → v0.37.0
  • golang.org/x/net: v0.49.0 → v0.57.0
  • golang.org/x/oauth2: v0.34.0 → v0.36.0
  • golang.org/x/sync: v0.19.0 → v0.22.0
  • golang.org/x/sys: v0.40.0 → v0.47.0
  • golang.org/x/telemetry: bd525da → 59b4966
  • golang.org/x/term: v0.39.0 → v0.45.0
  • golang.org/x/text: v0.33.0 → v0.40.0
  • golang.org/x/time: v0.14.0 → v0.15.0
  • golang.org/x/tools: v0.41.0 → v0.47.0
  • gonum.org/v1/gonum: v0.16.0 → v0.17.0
  • google.golang.org/genproto/googleapis/api: 8636f87 → 3dc84a4
  • google.golang.org/genproto/googleapis/rpc: 8636f87 → 3dc84a4
  • google.golang.org/grpc: v1.79.3 → v1.82.1
  • k8s.io/api: v0.36.0 → v0.37.0
  • k8s.io/apiextensions-apiserver: v0.36.0 → v0.37.0
  • k8s.io/apimachinery: v0.36.0 → v0.37.0
  • k8s.io/apiserver: v0.36.0 → v0.37.0
  • k8s.io/client-go: v0.36.0 → v0.37.0
  • k8s.io/code-generator: v0.36.0 → v0.37.0
  • k8s.io/component-base: v0.36.0 → v0.37.0
  • k8s.io/gengo/v2: ec3ebc5 → 25e2208
  • k8s.io/kms: v0.36.0 → v0.37.0
  • k8s.io/kube-openapi: 43fb72c → d427ff9
  • k8s.io/streaming: v0.36.0 → v0.37.0
  • k8s.io/utils: b8788ab → be93311
  • sigs.k8s.io/apiserver-network-proxy/konnectivity-client: v0.34.0 → v0.36.0
  • sigs.k8s.io/structured-merge-diff/v6: v6.3.2 → v6.4.2
Removed
  • github.com/creack/pty: v1.1.9
  • github.com/gogo/protobuf: v1.3.2
  • github.com/josharian/intern: v1.0.0
  • github.com/kr/pty: v1.1.1
  • github.com/mailru/easyjson: v0.7.7
  • github.com/matttproud/golang_protobuf_extensions: v1.0.1
  • github.com/stoewer/go-strcase: v1.3.0

Thanks to all our contributors! 😊


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 9am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@scality-renovate
scality-renovate Bot requested a review from a team as a code owner September 14, 2026 04:19
@scality-renovate scality-renovate Bot added dependencies Pull requests that update a dependency file go-deps minor labels Sep 14, 2026
@scality-renovate

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 43 additional dependencies were updated

Due to Go's usage of Minimal Version Selection (MVS), these packages have been updated to the minimum version available, so will still abide by minimumReleaseAge=7 days

Details:

Package Change
k8s.io/api v0.36.3 -> v0.37.0
k8s.io/apimachinery v0.36.3 -> v0.37.0
k8s.io/client-go v0.36.3 -> v0.37.0
github.com/antlr4-go/antlr/v4 v4.13.0 -> v4.13.1
github.com/fxamacker/cbor/v2 v2.9.0 -> v2.9.1
github.com/go-openapi/jsonpointer v0.21.0 -> v1.0.0
github.com/go-openapi/jsonreference v0.20.2 -> v1.0.0
github.com/go-openapi/swag v0.23.0 -> v0.27.1
github.com/google/cel-go v0.26.0 -> v0.29.2
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.7 -> v2.29.0
github.com/prometheus/client_golang v1.23.2 -> v1.24.0
github.com/prometheus/common v0.67.5 -> v0.70.0
github.com/prometheus/procfs v0.19.2 -> v0.21.1
github.com/spf13/pflag v1.0.9 -> v1.0.10
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0 -> v0.69.0
go.opentelemetry.io/otel v1.41.0 -> v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/metric v1.41.0 -> v1.44.0
go.opentelemetry.io/otel/sdk v1.40.0 -> v1.44.0
go.opentelemetry.io/otel/trace v1.41.0 -> v1.44.0
go.opentelemetry.io/proto/otlp v1.9.0 -> v1.10.0
go.yaml.in/yaml/v2 v2.4.3 -> v2.4.4
golang.org/x/exp v0.0.0-20251219203646-944ab1f22d93 -> v0.0.0-20260410095643-746e56fc9e2f
golang.org/x/mod v0.35.0 -> v0.37.0
golang.org/x/net v0.53.0 -> v0.57.0
golang.org/x/oauth2 v0.34.0 -> v0.36.0
golang.org/x/sync v0.20.0 -> v0.22.0
golang.org/x/sys v0.43.0 -> v0.47.0
golang.org/x/term v0.42.0 -> v0.45.0
golang.org/x/text v0.36.0 -> v0.40.0
golang.org/x/time v0.14.0 -> v0.15.0
golang.org/x/tools v0.44.0 -> v0.47.0
google.golang.org/genproto/googleapis/api v0.0.0-20260128011058-8636f8732409 -> v0.0.0-20260526163538-3dc84a4a5aaa
google.golang.org/genproto/googleapis/rpc v0.0.0-20260128011058-8636f8732409 -> v0.0.0-20260526163538-3dc84a4a5aaa
google.golang.org/grpc v1.79.3 -> v1.82.1
k8s.io/apiextensions-apiserver v0.36.1 -> v0.37.0
k8s.io/apiserver v0.36.1 -> v0.37.0
k8s.io/component-base v0.36.1 -> v0.37.0
k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a -> v0.0.0-20260721132016-d427ff9ee9ad
k8s.io/streaming v0.36.3 -> v0.37.0
sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 -> v0.36.0
sigs.k8s.io/structured-merge-diff/v6 v6.3.3 -> v6.4.2

@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Dependency Bump Evaluation

Version change: sigs.k8s.io/controller-runtime v0.24.1 → v0.25.1 (minor + patch)

Changes:

  • New experimental ReadYourWritesConsistency feature (opt-in)
  • GetEventRecorder() return type widened from events.EventRecorder to recorder.EventRecorder (embeds the former)
  • Transitive bump to k8s.io/* v0.37.0 (Kubernetes 1.37)
  • Multiple bug fixes (cache goroutine leaks, PriorityQueue deadlock, fake client fixes)
  • v0.25.1 patch: fix data race on []*item in PriorityQueue logState, fix subresource create RV parse error under read-your-writes consistency
  • Security-relevant patch bumps: golang-jwt v5.3.1, go-jose v4.1.4, golang.org/x/crypto v0.54.0
  • Removed transitive deps: gogo/protobuf, mailru/easyjson, stoewer/go-strcase, josharian/intern

Breaking changes:

  • EventRecorder interface (#3509): mgr.GetEventRecorder() now returns recorder.EventRecorder instead of events.EventRecorder. Verified this project stores it as events.EventRecorder (internal/controller/noderemediationpolicy_controller.go:58). Since recorder.EventRecorder embeds events.EventRecorder, Go structural typing makes this assignment-compatible — no code changes needed. The Eventf() call signature is unchanged.
  • k8s.io/ v1.37*: Transitive dependency. Project uses standard APIs (core/v1, apimachinery, client-go) with no deprecated patterns.

Security concerns: None — includes routine security patches for JWT, JOSE, and crypto libraries.

Impact on codebase:

  • No direct imports of any removed packages (gogo/protobuf, mailru/easyjson, stoewer/go-strcase, josharian/intern)
  • cel-go v0.26.0 → v0.29.2 is indirect only (used by apiextensions-apiserver for CRD validation, not imported directly)
  • EventRecorder field type (events.EventRecorder) remains compatible with the new return type
  • Only go.mod and go.sum are modified — no source code changes needed

Recommendation: SAFE TO MERGE (once CI is green)

Notes: CI checks (build, lint, test, test-e2e) are still in progress at time of evaluation. The listed breaking changes do not affect this project's usage patterns. Merge after all checks pass.

— Claude Code

@scality-renovate
scality-renovate Bot force-pushed the renovate/sigs.k8s.io-controller-runtime-0.x branch from 7ecd297 to 14ce40b Compare September 21, 2026 04:20
@scality-renovate scality-renovate Bot changed the title chore(deps): update module sigs.k8s.io/controller-runtime to v0.25.0 chore(deps): update module sigs.k8s.io/controller-runtime to v0.25.1 Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go-deps minor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants