Skip to content

Bump the k8s-deps group with 6 updates#62

Merged
mneverov merged 6 commits intomainfrom
dependabot/go_modules/k8s-deps-3d45f62826
Jan 21, 2026
Merged

Bump the k8s-deps group with 6 updates#62
mneverov merged 6 commits intomainfrom
dependabot/go_modules/k8s-deps-3d45f62826

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 19, 2026

Bumps the k8s-deps group with 6 updates:

Package From To
k8s.io/apimachinery 0.33.3 0.35.0
k8s.io/client-go 0.33.3 0.35.0
k8s.io/component-base 0.33.3 0.35.0
k8s.io/component-helpers 0.33.3 0.35.0
k8s.io/utils 0.0.0-20250604170112-4c0f3b243397 0.0.0-20251002143259-bc988d571ff4
sigs.k8s.io/controller-runtime 0.21.0 0.23.0

Updates k8s.io/apimachinery from 0.33.3 to 0.35.0

Commits
  • 72d71ea Merge remote-tracking branch 'origin/master' into release-1.35
  • e2a2dbc Bump golang.org/x/crypto to v0.45.0
  • 2e9c228 Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix
  • f274aac vendor: update vendor and license metadata after replacing BeTrue usage in cs...
  • 9445443 Resolve lint restriction on BeTrue by introducing Succeed() with contextual e...
  • 52154f7 Update vendored dependencies
  • 5a348c5 KEP-5471: Extend tolerations operators (#134665)
  • 6f89492 Merge pull request #133648 from richabanker/merged-discovery
  • c77dde2 util/sort: Add MergePreservingRelativeOrder for topological sorting
  • 729c13d Merge pull request #134624 from yt2985/podcertificates-beta
  • Additional commits viewable in compare view

Updates k8s.io/client-go from 0.33.3 to 0.35.0

Commits
  • 9bcb694 Update dependencies to v0.35.0 tag
  • 2d83546 Merge remote-tracking branch 'origin/master' into release-1.35
  • 56b4af2 Merge pull request #135591 from p0lyn0mial/upstream-watchlist-reflector-log-f...
  • 891f94c Merge remote-tracking branch 'origin/master' into release-1.35
  • 65ffe04 Merge pull request #135580 from serathius/client-go-transformer
  • 2fe4ac2 downgrade reflector watchlist fallback log to V(4)
  • 97256a6 Bump golang.org/x/crypto to v0.45.0
  • 46360b5 Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix
  • 171ef8c Use transformer in consistency checker
  • 3878a64 vendor: update vendor and license metadata after replacing BeTrue usage in cs...
  • Additional commits viewable in compare view

Updates k8s.io/component-base from 0.33.3 to 0.35.0

Commits
  • 4e6b4eb Update dependencies to v0.35.0 tag
  • 5e09e27 Merge remote-tracking branch 'origin/master' into release-1.35
  • 518a1d0 Bump golang.org/x/crypto to v0.45.0
  • dffb9df Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix
  • 622fcbc vendor: update vendor and license metadata after replacing BeTrue usage in cs...
  • 4461559 Resolve lint restriction on BeTrue by introducing Succeed() with contextual e...
  • 43140e8 Update vendored dependencies
  • c1ad413 Merge pull request #134870 from pmengelbert/pmengelbert/kuberc/4
  • 8209f50 Add client-go credential plugin to kuberc
  • 09c454e Merge pull request #134995 from yongruilin/flagz-kk-structure
  • Additional commits viewable in compare view

Updates k8s.io/component-helpers from 0.33.3 to 0.35.0

Commits
  • 71c97d7 Update dependencies to v0.35.0 tag
  • 8313d23 Merge remote-tracking branch 'origin/master' into release-1.35
  • 8aa03b8 Bump golang.org/x/crypto to v0.45.0
  • 165c29d Merge pull request #135131 from Dev1622/sig-storage/mock-expand-flake-fix
  • b6e62f7 vendor: update vendor and license metadata after replacing BeTrue usage in cs...
  • be0fff2 Resolve lint restriction on BeTrue by introducing Succeed() with contextual e...
  • 0907aec Merge pull request #132919 from ndixita/pod-level-in-place-pod-resize
  • d433219 Update vendored dependencies
  • 723ce89 Add InPlacePodLevelResourcesVerticalScaling declared feature.
  • 8ee2417 Scheduler changes to support pod level resources in place resize
  • Additional commits viewable in compare view

Updates k8s.io/utils from 0.0.0-20250604170112-4c0f3b243397 to 0.0.0-20251002143259-bc988d571ff4

Commits

Updates sigs.k8s.io/controller-runtime from 0.21.0 to 0.23.0

Release notes

Sourced from sigs.k8s.io/controller-runtime's releases.

v0.23.0

🔆 Highlights

⚠️ Breaking changes

✨ Features

🐛 Bugfixes

... (truncated)

Commits
  • 129853d Merge pull request #3419 from alvaroaleman/limit-cardinality
  • 00b8b07 🐛 Limit depthWithPriorityMetric cardinality to 25
  • 43b0e35 ✨ Delay reconciliation until handlers sync (#3406)
  • 137b9c0 Merge pull request #3415 from zach593/pq-buffer
  • c47f9cb Use a buffer to optimize priority queue AddWithOpts performance
  • 5de4c4f Merge pull request #3416 from alvaroaleman/twotrees
  • 9de69a7 🌱 Priorityqueue: Use separate b-trees for ready and non-ready items
  • 0c3a910 Merge pull request #3408 from zach593/pq-fifo
  • 31d30b6 fix priority queue ordering when item priority changes
  • a085590 Merge pull request #3411 from brito-rafa/issue-3410-expbucket-webhook
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added area/dependency Issues or PRs related to dependency changes ok-to-test Indicates a non-member PR verified by an org member that is safe to test. labels Jan 19, 2026
@k8s-ci-robot k8s-ci-robot requested review from aojea and thockin January 19, 2026 18:04
@k8s-ci-robot k8s-ci-robot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Jan 19, 2026
@dependabot dependabot bot force-pushed the dependabot/go_modules/k8s-deps-3d45f62826 branch 3 times, most recently from 2913733 to c3c4153 Compare January 20, 2026 02:30
@mneverov mneverov marked this pull request as draft January 20, 2026 06:46
@k8s-ci-robot k8s-ci-robot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jan 20, 2026
@aojea
Copy link
Contributor

aojea commented Jan 20, 2026

on this I agree with you, the dependency on golangci-lint with the golang version is a source of friction on developer experience

Failed executing command with error: can't load config: the Go language version (go1.24) used to build golangci-lint is lower than the targeted Go version (1.25.0)

@mneverov
Copy link
Member

@dependabot rebase

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 20, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

dependabot bot and others added 3 commits January 20, 2026 12:32
Bumps the k8s-deps group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) | `0.33.3` | `0.35.0` |
| [k8s.io/client-go](https://github.com/kubernetes/client-go) | `0.33.3` | `0.35.0` |
| [k8s.io/component-base](https://github.com/kubernetes/component-base) | `0.33.3` | `0.35.0` |
| [k8s.io/component-helpers](https://github.com/kubernetes/component-helpers) | `0.33.3` | `0.35.0` |
| [k8s.io/utils](https://github.com/kubernetes/utils) | `0.0.0-20250604170112-4c0f3b243397` | `0.0.0-20251002143259-bc988d571ff4` |
| [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.21.0` | `0.23.0` |


Updates `k8s.io/apimachinery` from 0.33.3 to 0.35.0
- [Commits](kubernetes/apimachinery@v0.33.3...v0.35.0)

Updates `k8s.io/client-go` from 0.33.3 to 0.35.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.33.3...v0.35.0)

Updates `k8s.io/component-base` from 0.33.3 to 0.35.0
- [Commits](kubernetes/component-base@v0.33.3...v0.35.0)

Updates `k8s.io/component-helpers` from 0.33.3 to 0.35.0
- [Commits](kubernetes/component-helpers@v0.33.3...v0.35.0)

Updates `k8s.io/utils` from 0.0.0-20250604170112-4c0f3b243397 to 0.0.0-20251002143259-bc988d571ff4
- [Commits](https://github.com/kubernetes/utils/commits)

Updates `sigs.k8s.io/controller-runtime` from 0.21.0 to 0.23.0
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/controller-runtime@v0.21.0...v0.23.0)

---
updated-dependencies:
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-deps
- dependency-name: k8s.io/client-go
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-deps
- dependency-name: k8s.io/component-base
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-deps
- dependency-name: k8s.io/component-helpers
  dependency-version: 0.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-deps
- dependency-name: k8s.io/utils
  dependency-version: 0.0.0-20251002143259-bc988d571ff4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: k8s-deps
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: k8s-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@mneverov mneverov force-pushed the dependabot/go_modules/k8s-deps-3d45f62826 branch 2 times, most recently from 820a5c9 to 29643c2 Compare January 20, 2026 13:06
@mneverov mneverov force-pushed the dependabot/go_modules/k8s-deps-3d45f62826 branch from 29643c2 to 25f7833 Compare January 20, 2026 13:27
@mneverov
Copy link
Member

See kubernetes/kubernetes#126850
fake.NewSimpleClientset() is deprecated, but fake.NewClientset() does not work with CRDs. Proposed solution requires generating openapi models, SSA models and seems hacky. I chose to linter ignore the use of deprecated methods since it is only used in tests.

@mneverov mneverov marked this pull request as ready for review January 20, 2026 17:33
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Jan 20, 2026
@aojea
Copy link
Contributor

aojea commented Jan 20, 2026

See kubernetes/kubernetes#126850
fake.NewSimpleClientset() is deprecated, but fake.NewClientset() does not work with CRDs

yep, this is an area that lacks contributors, there is no people working on CRD support, as I said in the other comment in the other thread, a lot of people consume core libraries in the kubebuilder / controller runtime ecosystem but they do not maintain it and core developers do not have time ... those fake clientset work for the core functionality, it just need contributors to work on the missing ones for CRDs ... in this case I do not know why we marked something deprecated when it is not fully working though

@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dependabot[bot], mneverov

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jan 21, 2026
@mneverov mneverov merged commit 4e4cb9e into main Jan 21, 2026
8 of 9 checks passed
@dependabot dependabot bot deleted the dependabot/go_modules/k8s-deps-3d45f62826 branch January 21, 2026 05:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/dependency Issues or PRs related to dependency changes cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants