chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.7.0 - #6845
dependabot[bot] wants to merge 2 commits into
Conversation
✅MegaLinter analysis: Success✅ Linters with no issuesactionlint, bash-exec, git_diff, hadolint, jscpd, jsonlint, lychee, markdown-table-formatter, markdownlint, prettier, prettier, shellcheck, shfmt, stylelint, syft, trivy-sbom, trufflehog, v8r, v8r, yamllint Notices
See detailed reports in MegaLinter artifacts
|
Parked on a named blocker — recording it here, because this PR carried no blocker record. Blocker: #6776 | last-verified 2026-09-02: still OPEN ( Why this bump is affected even though it never mentions Talos. Verified live on this PR's current head
Why it cannot self-progress. The branch is Not actionable as a rebase or a recreate. Unblocks when #6776 lands. |
Parked on a named, live-verified blocker: #6728 — same root cause as #6826, reached by a different route.
A rebase will not fix this one. Worth stating explicitly, because #6839 sitting alongside it is rebase-fixable — its only failing check is Live-verified today (module proxy): Control: Left open and parked; it becomes mergeable once the vcluster stack supports k8s 0.37. |
Pull request was converted to draft
Attempted a base-update rescue, aborted it, and re-confirmed the park on #6728Sibling PR #6839 was rescued this tick by a plain branch update — its only red check was a What I did, so the state change is on the record: converted to draft (which also dropped the Why it cannot be rescued mechanically. The local build failed with the same signature as this
Both hit That is exactly the chain already documented in #6728, which stays the named blocker. Re-verified Also worth recording, since it cost time on #6839: |
This bump is still wanted — @dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
Following up on my own rebase request above, which was rejected — Dependabot replied that the branch "has been edited by someone other than Dependabot", so it cannot rebase this PR. That is a permanent property of the branch, not a transient failure: I should also have led with the blocker rather than the conflict. The conflict is a symptom; the reason this PR cannot land is #6728 — Leaving this parked on #6728, which is the correct terminal state. No action needed. |
|
A newer version of github.com/siderolabs/image-factory exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Blocker: #6776 | last-verified 2026-09-04: still OPEN ( Re-verified live this run rather than inherited from the 2026-09-02 record. #6776 ("Migrate off the Terminal state unchanged: parked on a named, live-verified blocker. |
Blocker: #6776 | last-verified 2026-09-06: still OPEN ( Re-read live this run: #6776 ("Migrate off the removed Talos MachineConfig.Kubelet / ClusterConfig.CoreDNS accessors") remains open and Terminal state unchanged: parked on a named, live-verified blocker. The head is DIRTY and Dependabot has forfeited the rebase, so it cannot self-heal. |
ffcc354 to
a18b4da
Compare
|
Parked: this cannot go green until #6776 lands — stop asking Dependabot to recreate itThe recreate/re-lock loop above was chasing the wrong thing. Even a perfectly rebased branch fails, and it fails at compile, which is why all ~40 checks go red rather than a couple of system tests: Talos v1.14 removed the Blocker: #6776 | upstream | last-verified 2026-09-17: not shipped — #6776 is itself parked on Nothing to do on this PR until then. It is left open deliberately: it is the correct bump, arriving before the code that has to receive it. |
Conflicting with @dependabot recreate |
Bumps [github.com/siderolabs/image-factory](https://github.com/siderolabs/image-factory) from 1.3.3 to 1.7.0. - [Release notes](https://github.com/siderolabs/image-factory/releases) - [Changelog](https://github.com/siderolabs/image-factory/blob/main/CHANGELOG.md) - [Commits](siderolabs/image-factory@v1.3.3...v1.7.0) --- updated-dependencies: - dependency-name: github.com/siderolabs/image-factory dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
ee494e0 to
178a73a
Compare
Parked on #6776 and #6728. Recreated onto current |
Blocker: #6776 | upstream | last-verified 2026-09-19: OPEN ( Blocker: #6728 | upstream | last-verified 2026-09-19: OPEN ( Auto-merge is disabled while these current-head compile failures remain. |
Parked on a named upstream blocker, not abandoned. This PR's build failure is not its own: it raises kyverno's latest release (v1.19.1, 2026-09-10) still requires k8s 0.36.3, so there is nothing to adapt to on our side yet. Tracked in #7143 with the evidence and the re-check condition. Leaving this PR open so it rebuilds once kyverno ships a k8s-0.37 release; no adaptation commit, because any adaptation now would be a downgrade of the bump this PR exists to make. |
Parked on a named upstream blocker: this bump raises the Kubernetes libraries to v0.37, which vcluster does not support yet (its newest release still builds against v0.36), so the build cannot compile. Tracked in #7167; it will be revisited when vcluster ships support. |

Bumps github.com/siderolabs/image-factory from 1.3.3 to 1.7.0.
Release notes
Sourced from github.com/siderolabs/image-factory's releases.
... (truncated)
Changelog
Sourced from github.com/siderolabs/image-factory's changelog.
... (truncated)
Commits
5da8c30release(v1.7.0): prepare release513036cfix: cache unauthenticated iPXE scripts, dedupe cache signing5fec48btest: characterize HTTP frontend behavior4520b38fix(enterprise): evaluate VEX against Talos kernela27dfe6feat: enforce public API with OpenAPI773ba3cfix(ui): gate token create modal on the in-flight POST2e149c8fix(auth0): drop Bearer challenge from 401 response9f82ddefix: rename registryClientRefreshInterval to refreshIntervalf4f79dbfeat(enterprise): repo-per-org token storage, url-safe stored tokensf4e4d01feat(enterprise): expose actor profiles for token creation UI