Bump github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring from 0.55.1 to 0.93.0 - #609
Conversation
WalkthroughThe Prometheus Operator monitoring API dependency in ChangesMonitoring API dependency update
Estimated code review effort: 1 (Trivial) | ~2 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 15✅ Passed checks (15 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: dependabot[bot] The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @dependabot[bot]. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
…toring Bumps [github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring](https://github.com/prometheus-operator/prometheus-operator) from 0.55.1 to 0.93.0. - [Release notes](https://github.com/prometheus-operator/prometheus-operator/releases) - [Changelog](https://github.com/prometheus-operator/prometheus-operator/blob/main/CHANGELOG.md) - [Commits](prometheus-operator/prometheus-operator@v0.55.1...v0.93.0) --- updated-dependencies: - dependency-name: github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring dependency-version: 0.93.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
15b8f31 to
34a9f91
Compare
There was a problem hiding this comment.
🧹 Nitpick comments (1)
go.mod (1)
16-16: 🔒 Security & Privacy | 🔵 TrivialAdd SBOM/provenance and signing checks for dependency bumps. The module is pinned and
go.sumalready has matching hashes, but I don't see repo-side CI for SBOM generation, provenance attestations, or Sigstore/cosign-signed artifacts.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@go.mod` at line 16, Add repository CI checks for dependency updates such as github.com/prometheus-operator/prometheus-operator: generate and validate an SBOM, verify provenance attestations, and check Sigstore/cosign signatures for the resulting artifacts. Integrate these checks into the existing dependency or release workflow, using the repository’s established CI tooling and failing when verification does not pass.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@go.mod`:
- Line 16: Add repository CI checks for dependency updates such as
github.com/prometheus-operator/prometheus-operator: generate and validate an
SBOM, verify provenance attestations, and check Sigstore/cosign signatures for
the resulting artifacts. Integrate these checks into the existing dependency or
release workflow, using the repository’s established CI tooling and failing when
verification does not pass.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 3116dd40-0887-46ab-bcf9-cc20ca0c0e52
⛔ Files ignored due to path filters (1)
go.sumis excluded by!**/*.sum
📒 Files selected for processing (1)
go.mod
|
@dependabot[bot]: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Bumps github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring from 0.55.1 to 0.93.0.
Release notes
Sourced from github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring's releases.
... (truncated)
Changelog
Sourced from github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring's changelog.
... (truncated)
Commits
f8fafd4build(deps): bump the github-actions-deps group with 2 updates (#8726)387684bchore: cut v0.93.0 (#8725)263387cbuild(deps): bump the github-actions-deps group with 2 updatesfadceb3chore: cut v0.93.06eea70dMerge pull request #8714 from prometheus-operator/dependabot/go_modules/k8s.i...3a40dd9feat: add chunkEncoding field to TSDBSpec for runtime float encoding selectio...12fb55dRegenerate docs + bump in other go.mod files7b97bc9fix: create IPv6 EndpointSlice for kubelet Service on dual-stack clusters (#8...2e55a51Merge pull request #8694 from Poil/feat/thanos-delayed-compaction-8266716c885Merge pull request #8717 from prometheus-operator/dependabot/go_modules/githu...Summary by CodeRabbit