Skip to content

build(deps): bump the go-dependencies group across 1 directory with 28 updates#11828

Open
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/go_modules/go-dependencies-3d78d6c61d
Open

build(deps): bump the go-dependencies group across 1 directory with 28 updates#11828
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/go_modules/go-dependencies-3d78d6c61d

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 7, 2026

Bumps the go-dependencies group with 20 updates in the / directory:

Package From To
github.com/Azure/secrets-store-csi-driver-provider-azure 1.7.2 1.8.1
github.com/Masterminds/semver/v3 3.4.0 3.5.0
github.com/aws/aws-sdk-go-v2 1.41.6 1.41.7
github.com/aws/aws-sdk-go-v2/config 1.32.16 1.32.17
github.com/aws/aws-sdk-go-v2/service/cloudcontrol 1.29.14 1.29.15
github.com/aws/aws-sdk-go-v2/service/cloudformation 1.71.10 1.71.11
github.com/aws/aws-sdk-go-v2/service/ec2 1.299.0 1.300.0
github.com/aws/aws-sdk-go-v2/service/ecr 1.57.1 1.57.2
github.com/getkin/kin-openapi 0.135.0 0.137.0
github.com/go-git/go-git/v5 5.18.0 5.19.0
github.com/go-openapi/runtime 0.29.4 0.29.5
github.com/hashicorp/hc-install 0.9.4 0.9.5
github.com/hashicorp/terraform-exec 0.25.1 0.25.2
github.com/mattn/go-isatty 0.0.21 0.0.22
github.com/stern/stern 1.33.1 1.34.0
go.uber.org/zap 1.27.1 1.28.0
k8s.io/apiextensions-apiserver 0.35.4 0.36.0
k8s.io/kubectl 0.35.4 0.36.0
sigs.k8s.io/controller-runtime 0.23.3 0.24.0
sigs.k8s.io/secrets-store-csi-driver 1.5.6 1.6.0

Updates github.com/Azure/secrets-store-csi-driver-provider-azure from 1.7.2 to 1.8.1

Release notes

Sourced from github.com/Azure/secrets-store-csi-driver-provider-azure's releases.

v1.8.1 - 2026-04-28

Changelog

Bug Fixes 🐞

Code Refactoring 💎

Continuous Integration 💜

Documentation 📘

Features 🌈

Maintenance 🔧

Commits
  • c07d0d6 release: update manifest and helm charts for v1.8.1 (#2027)
  • 7dc89ab fix: set ErrorStream and InfoStream for JSON logger to avoid (#2024)
  • 94750e0 fix: only set managed identity client ID when non-empty (#2022)
  • 8a59ecd release: update manifest and helm charts for v1.8.0 (#2019)
  • 87c87fa chore: update to go 1.25.9 and otel/sdk v1.43.0 (#2014)
  • e007db9 ci: remove unused labels from dependabot config (#2013)
  • ef3d4c2 feat: identity binding support (#1984)
  • 2f419ea chore: update to go 1.25.8, grpc v1.79.3 and fix workflow action comments (#2...
  • 3f2347e chore: update to go 1.25.7 and otel/sdk to v1.40.0 (#1988)
  • 694b16c fix: validate pod context and secure socket perm with umask (#1981)
  • Additional commits viewable in compare view

Updates github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0

Release notes

Sourced from github.com/Masterminds/semver/v3's releases.

v3.5.0

What's Changed

New Contributors

Full Changelog: Masterminds/semver@v3.4.0...v3.5.0

Changelog

Sourced from github.com/Masterminds/semver/v3's changelog.

Changelog

Commits
  • 8b89c86 Merge pull request #287 from mattfarina/fix-da-issues
  • 29d51d0 Fixing some quality issues
  • 87f651d Merge pull request #286 from mattfarina/update-devcontainer
  • 158a685 Updating gitignore for devcontainers
  • 7e83c08 Merge pull request #284 from Masterminds/dependabot/github_actions/golangci/g...
  • 697e27f Merge pull request #283 from Masterminds/dependabot/github_actions/actions/ca...
  • 1591f8e Merge pull request #282 from Masterminds/dependabot/github_actions/github/cod...
  • 3f5ff17 Bump golangci/golangci-lint-action from 7.0.1 to 9.2.0
  • 04baa33 Bump actions/cache from 4.2.3 to 5.0.5
  • 45939fe Bump github/codeql-action from 4.35.1 to 4.35.2
  • Additional commits viewable in compare view

Updates github.com/aws/aws-sdk-go-v2 from 1.41.6 to 1.41.7

Commits

Updates github.com/aws/aws-sdk-go-v2/config from 1.32.16 to 1.32.17

Commits

Updates github.com/aws/aws-sdk-go-v2/credentials from 1.19.15 to 1.19.16

Commits

Updates github.com/aws/aws-sdk-go-v2/service/cloudcontrol from 1.29.14 to 1.29.15

Commits

Updates github.com/aws/aws-sdk-go-v2/service/cloudformation from 1.71.10 to 1.71.11

Commits

Updates github.com/aws/aws-sdk-go-v2/service/ec2 from 1.299.0 to 1.300.0

Commits

Updates github.com/aws/aws-sdk-go-v2/service/ecr from 1.57.1 to 1.57.2

Commits

Updates github.com/aws/aws-sdk-go-v2/service/sts from 1.42.0 to 1.42.1

Commits

Updates github.com/getkin/kin-openapi from 0.135.0 to 0.137.0

Release notes

Sourced from github.com/getkin/kin-openapi's releases.

v0.137.0

What's Changed

Full Changelog: getkin/kin-openapi@v0.136.0...v0.137.0

v0.136.0

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.135.0...v0.136.0

Commits
  • b641244 revert to go 1.25 and revert cc4f8d99
  • ff4bce7 fix and upgrade goimports-reviser
  • 028df2a refacto(tests): use t.Context instead of context.Background
  • cc4f8d9 refacto: replace openapi3.*Ptr(..) funcs with new(..)
  • df95b87 address various lint errors
  • 3556929 openapi2conv: nil-guard components lookup in FromV3SchemaRef (#1156)
  • 5a0a337 openapi3: remove map-iteration order leaks causing flaky tests (#1158)
  • 3489553 openapi3: skip v3.1 load/validation flaky tests
  • 3aa08cd openapi3: record v3.1 load/validation test failures
  • 3179775 openapi3: enable testing for 3.1 documents
  • Additional commits viewable in compare view

Updates github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0

Release notes

Sourced from github.com/go-git/go-git/v5's releases.

v5.19.0

What's Changed

Full Changelog: go-git/go-git@v5.18.0...v5.19.0

Commits
  • bc930f4 Merge pull request #2065 from go-git/commit-v5
  • d315264 plumbing: object, Reset object before decode
  • 6e1d348 plumbing: object, Align Tree handling with upstream
  • e134ba3 tests: Skip double checks in Git v2.11
  • 1971422 tests: Add git conformance tests for signing verification
  • a387aa8 plumbing: object, Add ErrMalformedTag
  • f415670 plumbing: object, Decode Tag headers via a state machine
  • 5b0cd38 plumbing: object, Reject multi-signature commits at Verify
  • fe8ed62 plumbing: object, Align Tag.EncodeWithoutSignature with Commit
  • 98e337d plumbing: object, Add support for Tag.SignatureSHA256
  • Additional commits viewable in compare view

Updates github.com/go-openapi/runtime from 0.29.4 to 0.29.5

Release notes

Sourced from github.com/go-openapi/runtime's releases.

v0.29.5

0.29.5 - 2026-05-04

Full Changelog: go-openapi/runtime@v0.29.4...v0.29.5

10 commits in this release.


Implemented enhancements

  • feat(client): prefer multipart and support url-encoded file uploads by @​fredbi in #428 ...

Fixed bugs

Documentation

Miscellaneous tasks

Updates


People who contributed to this release


New Contributors

... (truncated)

Commits
  • 316127b chore: prepare release v0.29.5
  • d7fb83c feat(client): prefer multipart and support url-encoded file uploads (#428)
  • 1114423 fix(statuses): align http status text with current standard (#427)
  • c69b34d fix(validation): match content-type with MIME parameters (#426)
  • dd5f9c7 fix(auth): detect nil interface vs nil interface (#425)
  • 8b594b4 doc: aligned docs with org-level docs (#424)
  • 32bf6a0 doc: updated contributors file
  • 8fe7420 fix: handle literal colons in URL paths for denco router (#422)
  • 5b8c120 build(deps): bump the go-openapi-dependencies group across 2 directories with...
  • 57116dd doc: updated contributors file
  • See full diff in compare view

Updates github.com/go-openapi/strfmt from 0.26.1 to 0.26.2

Release notes

Sourced from github.com/go-openapi/strfmt's releases.

v0.26.2

0.26.2 - 2026-04-29

Full Changelog: go-openapi/strfmt@v0.26.1...v0.26.2

13 commits in this release.


Documentation

Performance

Miscellaneous tasks

Updates

  • build(deps): bump the other-dependencies group across 2 directories with 2 updates by @​dependabot[bot] in #245 ...
  • build(deps): bump the development-dependencies group with 8 updates by @​dependabot[bot] in #242 ...
  • build(deps): bump golang.org/x/net from 0.52.0 to 0.53.0 in the golang-org-dependencies group across 1 directory by @​dependabot[bot] in #241 ...
  • build(deps): bump github.com/jackc/pgx/v5 from 5.8.0 to 5.9.1 in /internal/testintegration in the other-dependencies group across 1 directory by @​dependabot[bot] in #240 ...
  • build(deps): bump the go-openapi-dependencies group across 2 directories with 1 update by @​dependabot[bot] in #238 ...
  • build(deps): bump golang.org/x/net from 0.50.0 to 0.52.0 in the golang-org-dependencies group across 1 directory by @​dependabot[bot] in #228 ...

People who contributed to this release


strfmt license terms

[![License][license-badge]][license-url]

... (truncated)

Commits
  • fb29dd2 chore: prepare release v0.26.2
  • c8c1e4e doc: aligned docs with org-wide documentation. (#247)
  • ebb2f2f perf(duration): faster and stricter ParseDuration. (#246)
  • c09c1cd build(deps): bump the other-dependencies group across 2 directories with 2 up...
  • 1dfdf84 build(deps): bump the development-dependencies group with 8 updates
  • 290bce4 build(deps): bump golang.org/x/net
  • 49afd07 build(deps): bump github.com/jackc/pgx/v5 (#240)
  • b04e233 doc: updated contributors file
  • 9cdd252 build(deps): bump the go-openapi-dependencies group across 2 directories with...
  • 5b911b6 build(deps): bump golang.org/x/net
  • Additional commits viewable in compare view

Updates github.com/hashicorp/hc-install from 0.9.4 to 0.9.5

Release notes

Sourced from github.com/hashicorp/hc-install's releases.

v0.9.5

  • go.mod: Lower compatibility constraint from 1.25.8 to 1.25.0 (#376)
Commits

Updates github.com/hashicorp/terraform-exec from 0.25.1 to 0.25.2

Release notes

Sourced from github.com/hashicorp/terraform-exec's releases.

v0.25.2

NOTES:

  • go.mod: Lower compatibility constraint from 1.25.8 to 1.25.0 (#581)

DEPENDENCIES:

  • build(deps): bump github.com/hashicorp/hc-install from 0.9.4 to 0.9.5 (#585)
Changelog

Sourced from github.com/hashicorp/terraform-exec's changelog.

0.25.2 (April 29, 2026)

NOTES:

  • go.mod: Lower compatibility constraint from 1.25.8 to 1.25.0 (#581)

DEPENDENCIES:

  • build(deps): bump github.com/hashicorp/hc-install from 0.9.4 to 0.9.5 (#585)
Commits
  • 56a0d8b v0.25.2 [skip ci]
  • 94a3afe Update Changelog in preparation for 0.25.2 (#586)
  • ac26db5 go.mod: Keep compatibility constraint separate from build (#581)
  • e856bad build(deps): bump github.com/hashicorp/hc-install from 0.9.4 to 0.9.5 (#585)
  • See full diff in compare view

Updates github.com/mattn/go-isatty from 0.0.21 to 0.0.22

Commits

Updates github.com/stern/stern from 1.33.1 to 1.34.0

Release notes

Sourced from github.com/stern/stern's releases.

v1.34.0

⚡ Notable Changes

New --qps and --burst flags for client-side throttling

You can now control the rate of requests to the Kubernetes API server with --qps and --burst flags. This is useful when you are tailing many pods and want to avoid overwhelming the API server.

stern . --qps 10 --burst 20

Changes

  • Add --qps and --burst flags to control client-side throttling (#363) 7e59e4e (Abhishek Pareek)
  • fix: honor klog -stderrthreshold even when -logtostderr is true (#364) 8e4ece3 (Pierluigi Lenoci)
  • Update dependencies for Kubernetes 1.36 (#365) 6761a78 (Takashi Kusumi)
Changelog

Sourced from github.com/stern/stern's changelog.

v1.34.0

⚡ Notable Changes

New --qps and --burst flags for client-side throttling

You can now control the rate of requests to the Kubernetes API server with --qps and --burst flags. This is useful when you are tailing many pods and want to avoid overwhelming the API server.

stern . --qps 10 --burst 20

Changes

  • Add --qps and --burst flags to control client-side throttling (#363) 7e59e4e (Abhishek Pareek)
  • fix: honor klog -stderrthreshold even when -logtostderr is true (#364) 8e4ece3 (Pierluigi Lenoci)
  • Update dependencies for Kubernetes 1.36 (#365) 6761a78 (Takashi Kusumi)
Commits
  • b6f1226 Update CHANGELOG for v1.34.0 (#366)
  • 6761a78 Update dependencies for Kubernetes 1.36 (#365)
  • 8e4ece3 fix: honor klog -stderrthreshold even when -logtostderr is true (#364)
  • 7e59e4e Add --qps and --burst flags to contorl client-side throttling (#363)
  • See full diff in compare view

Updates go.uber.org/zap from 1.27.1 to 1.28.0

Release notes

Sourced from go.uber.org/zap's releases.

v1.28.0

Enhancements:

  • #1534[]: Add zapcore.CheckPreWriteHook and CheckedEntry.Before method for transforming entries before they are written to any Cores.

#1534: uber-go/zap#1534

Changelog

Sourced from

…8 updates

Bumps the go-dependencies group with 20 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github.com/Azure/secrets-store-csi-driver-provider-azure](https://github.com/Azure/secrets-store-csi-driver-provider-azure) | `1.7.2` | `1.8.1` |
| [github.com/Masterminds/semver/v3](https://github.com/Masterminds/semver) | `3.4.0` | `3.5.0` |
| [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) | `1.41.6` | `1.41.7` |
| [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2) | `1.32.16` | `1.32.17` |
| [github.com/aws/aws-sdk-go-v2/service/cloudcontrol](https://github.com/aws/aws-sdk-go-v2) | `1.29.14` | `1.29.15` |
| [github.com/aws/aws-sdk-go-v2/service/cloudformation](https://github.com/aws/aws-sdk-go-v2) | `1.71.10` | `1.71.11` |
| [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) | `1.299.0` | `1.300.0` |
| [github.com/aws/aws-sdk-go-v2/service/ecr](https://github.com/aws/aws-sdk-go-v2) | `1.57.1` | `1.57.2` |
| [github.com/getkin/kin-openapi](https://github.com/getkin/kin-openapi) | `0.135.0` | `0.137.0` |
| [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) | `5.18.0` | `5.19.0` |
| [github.com/go-openapi/runtime](https://github.com/go-openapi/runtime) | `0.29.4` | `0.29.5` |
| [github.com/hashicorp/hc-install](https://github.com/hashicorp/hc-install) | `0.9.4` | `0.9.5` |
| [github.com/hashicorp/terraform-exec](https://github.com/hashicorp/terraform-exec) | `0.25.1` | `0.25.2` |
| [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty) | `0.0.21` | `0.0.22` |
| [github.com/stern/stern](https://github.com/stern/stern) | `1.33.1` | `1.34.0` |
| [go.uber.org/zap](https://github.com/uber-go/zap) | `1.27.1` | `1.28.0` |
| [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver) | `0.35.4` | `0.36.0` |
| [k8s.io/kubectl](https://github.com/kubernetes/kubectl) | `0.35.4` | `0.36.0` |
| [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) | `0.23.3` | `0.24.0` |
| [sigs.k8s.io/secrets-store-csi-driver](https://github.com/kubernetes-sigs/secrets-store-csi-driver) | `1.5.6` | `1.6.0` |



Updates `github.com/Azure/secrets-store-csi-driver-provider-azure` from 1.7.2 to 1.8.1
- [Release notes](https://github.com/Azure/secrets-store-csi-driver-provider-azure/releases)
- [Changelog](https://github.com/Azure/secrets-store-csi-driver-provider-azure/blob/master/docs/Release_Management.md)
- [Commits](Azure/secrets-store-csi-driver-provider-azure@v1.7.2...v1.8.1)

Updates `github.com/Masterminds/semver/v3` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/Masterminds/semver/releases)
- [Changelog](https://github.com/Masterminds/semver/blob/master/CHANGELOG.md)
- [Commits](Masterminds/semver@v3.4.0...v3.5.0)

Updates `github.com/aws/aws-sdk-go-v2` from 1.41.6 to 1.41.7
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@v1.41.6...v1.41.7)

Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.16 to 1.32.17
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.32.16...config/v1.32.17)

Updates `github.com/aws/aws-sdk-go-v2/credentials` from 1.19.15 to 1.19.16
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@credentials/v1.19.15...credentials/v1.19.16)

Updates `github.com/aws/aws-sdk-go-v2/service/cloudcontrol` from 1.29.14 to 1.29.15
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@config/v1.29.14...config/v1.29.15)

Updates `github.com/aws/aws-sdk-go-v2/service/cloudformation` from 1.71.10 to 1.71.11
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/cloudformation/v1.71.10...service/cloudformation/v1.71.11)

Updates `github.com/aws/aws-sdk-go-v2/service/ec2` from 1.299.0 to 1.300.0
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/ec2/v1.299.0...service/ec2/v1.300.0)

Updates `github.com/aws/aws-sdk-go-v2/service/ecr` from 1.57.1 to 1.57.2
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.57.1...service/ssm/v1.57.2)

Updates `github.com/aws/aws-sdk-go-v2/service/sts` from 1.42.0 to 1.42.1
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](aws/aws-sdk-go-v2@service/s3/v1.42.0...service/s3/v1.42.1)

Updates `github.com/getkin/kin-openapi` from 0.135.0 to 0.137.0
- [Release notes](https://github.com/getkin/kin-openapi/releases)
- [Commits](getkin/kin-openapi@v0.135.0...v0.137.0)

Updates `github.com/go-git/go-git/v5` from 5.18.0 to 5.19.0
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.18.0...v5.19.0)

Updates `github.com/go-openapi/runtime` from 0.29.4 to 0.29.5
- [Release notes](https://github.com/go-openapi/runtime/releases)
- [Commits](go-openapi/runtime@v0.29.4...v0.29.5)

Updates `github.com/go-openapi/strfmt` from 0.26.1 to 0.26.2
- [Release notes](https://github.com/go-openapi/strfmt/releases)
- [Commits](go-openapi/strfmt@v0.26.1...v0.26.2)

Updates `github.com/hashicorp/hc-install` from 0.9.4 to 0.9.5
- [Release notes](https://github.com/hashicorp/hc-install/releases)
- [Commits](hashicorp/hc-install@v0.9.4...v0.9.5)

Updates `github.com/hashicorp/terraform-exec` from 0.25.1 to 0.25.2
- [Release notes](https://github.com/hashicorp/terraform-exec/releases)
- [Changelog](https://github.com/hashicorp/terraform-exec/blob/main/CHANGELOG.md)
- [Commits](hashicorp/terraform-exec@v0.25.1...v0.25.2)

Updates `github.com/mattn/go-isatty` from 0.0.21 to 0.0.22
- [Commits](mattn/go-isatty@v0.0.21...v0.0.22)

Updates `github.com/stern/stern` from 1.33.1 to 1.34.0
- [Release notes](https://github.com/stern/stern/releases)
- [Changelog](https://github.com/stern/stern/blob/master/CHANGELOG.md)
- [Commits](stern/stern@v1.33.1...v1.34.0)

Updates `go.uber.org/zap` from 1.27.1 to 1.28.0
- [Release notes](https://github.com/uber-go/zap/releases)
- [Changelog](https://github.com/uber-go/zap/blob/master/CHANGELOG.md)
- [Commits](uber-go/zap@v1.27.1...v1.28.0)

Updates `golang.org/x/exp` from 0.0.0-20240909161429-701f63a606c0 to 0.0.0-20260410095643-746e56fc9e2f
- [Commits](https://github.com/golang/exp/commits)

Updates `k8s.io/api` from 0.35.4 to 0.36.0
- [Commits](kubernetes/api@v0.35.4...v0.36.0)

Updates `k8s.io/apiextensions-apiserver` from 0.35.4 to 0.36.0
- [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases)
- [Commits](kubernetes/apiextensions-apiserver@v0.35.4...v0.36.0)

Updates `k8s.io/apimachinery` from 0.35.4 to 0.36.0
- [Commits](kubernetes/apimachinery@v0.35.4...v0.36.0)

Updates `k8s.io/cli-runtime` from 0.35.4 to 0.36.0
- [Commits](kubernetes/cli-runtime@v0.35.4...v0.36.0)

Updates `k8s.io/client-go` from 0.35.4 to 0.36.0
- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)
- [Commits](kubernetes/client-go@v0.35.4...v0.36.0)

Updates `k8s.io/kubectl` from 0.35.4 to 0.36.0
- [Commits](kubernetes/kubectl@v0.35.4...v0.36.0)

Updates `sigs.k8s.io/controller-runtime` from 0.23.3 to 0.24.0
- [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases)
- [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/controller-runtime@v0.23.3...v0.24.0)

Updates `sigs.k8s.io/secrets-store-csi-driver` from 1.5.6 to 1.6.0
- [Release notes](https://github.com/kubernetes-sigs/secrets-store-csi-driver/releases)
- [Changelog](https://github.com/kubernetes-sigs/secrets-store-csi-driver/blob/main/docs/RELEASE.md)
- [Commits](kubernetes-sigs/secrets-store-csi-driver@v1.5.6...v1.6.0)

---
updated-dependencies:
- dependency-name: github.com/Azure/secrets-store-csi-driver-provider-azure
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/Masterminds/semver/v3
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2
  dependency-version: 1.41.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/credentials
  dependency-version: 1.19.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/cloudcontrol
  dependency-version: 1.29.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/cloudformation
  dependency-version: 1.71.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2
  dependency-version: 1.300.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/ecr
  dependency-version: 1.57.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
  dependency-version: 1.42.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/getkin/kin-openapi
  dependency-version: 0.137.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: github.com/go-openapi/runtime
  dependency-version: 0.29.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/go-openapi/strfmt
  dependency-version: 0.26.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/hashicorp/hc-install
  dependency-version: 0.9.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/hashicorp/terraform-exec
  dependency-version: 0.25.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/mattn/go-isatty
  dependency-version: 0.0.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: github.com/stern/stern
  dependency-version: 1.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: go.uber.org/zap
  dependency-version: 1.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/exp
  dependency-version: 0.0.0-20260410095643-746e56fc9e2f
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
- dependency-name: k8s.io/api
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: k8s.io/apiextensions-apiserver
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: k8s.io/apimachinery
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: k8s.io/cli-runtime
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: k8s.io/client-go
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: k8s.io/kubectl
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: sigs.k8s.io/controller-runtime
  dependency-version: 0.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: sigs.k8s.io/secrets-store-csi-driver
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels May 7, 2026
Copilot AI review requested due to automatic review settings May 7, 2026 03:27
@dependabot dependabot Bot requested review from a team as code owners May 7, 2026 03:27
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels May 7, 2026
@dependabot dependabot Bot review requested due to automatic review settings May 7, 2026 03:27
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 7, 2026

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 37 package(s) with unknown licenses.
  • ⚠️ 1 packages with OpenSSF Scorecard issues.
See the Details below.

License Issues

go.mod

PackageVersionLicenseIssue Type
github.com/Azure/secrets-store-csi-driver-provider-azure1.8.1NullUnknown License
github.com/Masterminds/semver/v33.5.0NullUnknown License
github.com/aws/aws-sdk-go-v21.41.7NullUnknown License
github.com/aws/aws-sdk-go-v2/config1.32.17NullUnknown License
github.com/aws/aws-sdk-go-v2/credentials1.19.16NullUnknown License
github.com/aws/aws-sdk-go-v2/feature/ec2/imds1.18.23NullUnknown License
github.com/aws/aws-sdk-go-v2/internal/configsources1.4.23NullUnknown License
github.com/aws/aws-sdk-go-v2/internal/endpoints/v22.7.23NullUnknown License
github.com/aws/aws-sdk-go-v2/service/cloudformation1.71.11NullUnknown License
github.com/aws/aws-sdk-go-v2/service/ec21.300.0NullUnknown License
github.com/aws/aws-sdk-go-v2/service/ecr1.57.2NullUnknown License
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding1.13.9NullUnknown License
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url1.13.23NullUnknown License
github.com/aws/aws-sdk-go-v2/service/sso1.30.17NullUnknown License
github.com/aws/aws-sdk-go-v2/service/ssooidc1.35.21NullUnknown License
github.com/aws/aws-sdk-go-v2/service/sts1.42.1NullUnknown License
github.com/fxamacker/cbor/v22.9.1NullUnknown License
github.com/getkin/kin-openapi0.137.0NullUnknown License
github.com/go-git/go-git/v55.19.0NullUnknown License
github.com/go-openapi/swag0.26.0NullUnknown License
github.com/klauspost/cpuid/v22.3.0NullUnknown License
github.com/mattn/go-isatty0.0.22NullUnknown License
github.com/stern/stern1.34.0NullUnknown License
golang.org/x/exp0.0.0-20260410095643-746e56fc9e2fNullUnknown License
google.golang.org/protobuf1.36.12-0.20260120151049-f2248ac996afNullUnknown License
k8s.io/api0.36.0NullUnknown License
k8s.io/apiextensions-apiserver0.36.0NullUnknown License
k8s.io/apimachinery0.36.0NullUnknown License
k8s.io/apiserver0.36.0NullUnknown License
k8s.io/client-go0.36.0NullUnknown License
k8s.io/component-base0.36.0NullUnknown License
k8s.io/klog/v22.140.0NullUnknown License
k8s.io/kube-openapi0.0.0-20260502001324-b7f5293f4787NullUnknown License
k8s.io/kubectl0.36.0NullUnknown License
sigs.k8s.io/controller-runtime0.24.0NullUnknown License
sigs.k8s.io/kustomize/kyaml0.21.1NullUnknown License
github.com/oasdiff/yaml30.0.12NullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
gomod/github.com/Azure/azure-sdk-for-go/sdk/azidentity 1.14.0-beta.2.0.20260124023332-4c5175309ebb 🟢 7.3
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy🟢 10security policy file detected
License🟢 10license file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Fuzzing⚠️ 0project is not fuzzed
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 5dependency not pinned by hash detected -- score normalized to 5
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
gomod/github.com/Azure/secrets-store-csi-driver-provider-azure 1.8.1 UnknownUnknown
gomod/github.com/Masterminds/semver/v3 3.5.0 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2 1.41.7 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/config 1.32.17 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/credentials 1.19.16 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/feature/ec2/imds 1.18.23 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/internal/configsources 1.4.23 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 2.7.23 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/internal/v4a 1.4.24 🟢 6.4
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 1Found 3/30 approved changesets -- score normalized to 1
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
License🟢 10license file detected
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 6SAST tool is not run on all commits -- score normalized to 6
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
gomod/github.com/aws/aws-sdk-go-v2/service/cloudcontrol 1.29.15 🟢 6.4
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 1Found 3/30 approved changesets -- score normalized to 1
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
License🟢 10license file detected
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 6SAST tool is not run on all commits -- score normalized to 6
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
gomod/github.com/aws/aws-sdk-go-v2/service/cloudformation 1.71.11 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/ec2 1.300.0 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/ecr 1.57.2 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding 1.13.9 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/internal/presigned-url 1.13.23 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/signin 1.0.11 🟢 6.4
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 1Found 3/30 approved changesets -- score normalized to 1
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
License🟢 10license file detected
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
SAST🟢 6SAST tool is not run on all commits -- score normalized to 6
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
gomod/github.com/aws/aws-sdk-go-v2/service/sso 1.30.17 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/ssooidc 1.35.21 UnknownUnknown
gomod/github.com/aws/aws-sdk-go-v2/service/sts 1.42.1 UnknownUnknown
gomod/github.com/fxamacker/cbor/v2 2.9.1 UnknownUnknown
gomod/github.com/getkin/kin-openapi 0.137.0 UnknownUnknown
gomod/github.com/go-git/go-billy/v5 5.9.0 🟢 8.6
Details
CheckScoreReason
Code-Review🟢 5Found 2/4 approved changesets -- score normalized to 5
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Dependency-Update-Tool🟢 10update tool detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Vulnerabilities🟢 100 existing vulnerabilities detected
Signed-Releases⚠️ -1no releases found
Fuzzing⚠️ 0project is not fuzzed
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 8branch protection is not maximal on development and all release branches
SAST🟢 10SAST tool is run on all commits
CI-Tests🟢 107 out of 7 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 26 contributing companies or organizations
gomod/github.com/go-git/go-git/v5 5.19.0 UnknownUnknown
gomod/github.com/go-openapi/runtime 0.29.5 🟢 7.5
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Code-Review⚠️ 0Found 1/13 approved changesets -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 7SAST tool is not run on all commits -- score normalized to 7
gomod/github.com/go-openapi/strfmt 0.26.2 🟢 7.5
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/14 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Pinned-Dependencies🟢 9dependency not pinned by hash detected -- score normalized to 9
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 8SAST tool is not run on all commits -- score normalized to 8
gomod/github.com/go-openapi/swag 0.26.0 UnknownUnknown
gomod/github.com/go-openapi/swag/cmdutils 0.26.0 🟢 8.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/12 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1026 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 8SAST tool is not run on all commits -- score normalized to 8
gomod/github.com/go-openapi/swag/mangling 0.26.0 🟢 8.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/12 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1026 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 8SAST tool is not run on all commits -- score normalized to 8
gomod/github.com/go-openapi/swag/netutils 0.26.0 🟢 8.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/12 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1026 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST🟢 8SAST tool is not run on all commits -- score normalized to 8
gomod/github.com/hashicorp/hc-install 0.9.5 🟢 6.7
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
gomod/github.com/hashicorp/terraform-exec 0.25.2 🟢 6.2
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 8Found 12/15 approved changesets -- score normalized to 8
Maintained🟢 1020 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 6dependency not pinned by hash detected -- score normalized to 6
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
gomod/github.com/klauspost/cpuid/v2 2.3.0 UnknownUnknown
gomod/github.com/mattn/go-isatty 0.0.22 UnknownUnknown
gomod/github.com/oasdiff/yaml3 0.0.12 UnknownUnknown
gomod/github.com/pjbgf/sha1cd 0.6.0 🟢 6.7
Details
CheckScoreReason
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 56 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/7 approved changesets -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 3branch protection is not maximal on development and all release branches
Security-Policy⚠️ 0security policy file not detected
SAST🟢 10SAST tool is run on all commits
gomod/github.com/sergi/go-diff 1.4.0 ⚠️ 2.9
Details
CheckScoreReason
Code-Review🟢 6Found 8/12 approved changesets -- score normalized to 6
Dangerous-Workflow⚠️ -1no workflows found
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Token-Permissions⚠️ -1No tokens found
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Pinned-Dependencies⚠️ -1no dependencies found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
gomod/github.com/stern/stern 1.34.0 UnknownUnknown
gomod/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc 0.65.0 🟢 8.8
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Dependency-Update-Tool🟢 10update tool detected
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1030 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Signed-Releases🟢 84 out of the last 4 releases have a total of 4 signed artifacts.
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies🟢 4dependency not pinned by hash detected -- score normalized to 4
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 4branch protection is not maximal on development and all release branches
Security-Policy🟢 10security policy file detected
Vulnerabilities🟢 100 existing vulnerabilities detected
CI-Tests🟢 1030 out of 30 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 40 contributing companies or organizations
gomod/go.uber.org/zap 1.28.0 🟢 6.4
Details
CheckScoreReason
Maintained⚠️ 23 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 10all changesets reviewed
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Security-Policy⚠️ 0security policy file not detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
gomod/golang.org/x/exp 0.0.0-20260410095643-746e56fc9e2f UnknownUnknown
gomod/golang.org/x/tools 0.44.0 UnknownUnknown
gomod/google.golang.org/protobuf 1.36.12-0.20260120151049-f2248ac996af UnknownUnknown
gomod/k8s.io/api 0.36.0 UnknownUnknown
gomod/k8s.io/apiextensions-apiserver 0.36.0 UnknownUnknown
gomod/k8s.io/apimachinery 0.36.0 UnknownUnknown
gomod/k8s.io/apiserver 0.36.0 UnknownUnknown
gomod/k8s.io/cli-runtime 0.36.0 🟢 5.3
Details
CheckScoreReason
Token-Permissions⚠️ -1No tokens found
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow⚠️ -1no workflows found
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/30 approved changesets -- score normalized to 0
SAST⚠️ 0no SAST tool detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ -1no dependencies found
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
gomod/k8s.io/client-go 0.36.0 UnknownUnknown
gomod/k8s.io/component-base 0.36.0 UnknownUnknown
gomod/k8s.io/klog/v2 2.140.0 UnknownUnknown
gomod/k8s.io/kube-openapi 0.0.0-20260502001324-b7f5293f4787 UnknownUnknown
gomod/k8s.io/kubectl 0.36.0 UnknownUnknown
gomod/k8s.io/streaming 0.36.0 UnknownUnknown
gomod/k8s.io/utils 0.0.0-20260319190234-28399d86e0b5 🟢 5.3
Details
CheckScoreReason
Maintained⚠️ 34 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 10all changesets reviewed
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
gomod/sigs.k8s.io/controller-runtime 0.24.0 UnknownUnknown
gomod/sigs.k8s.io/kustomize/api 0.21.1 🟢 5.7
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1030 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Binary-Artifacts🟢 10no binaries found in the repo
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies⚠️ 2dependency not pinned by hash detected -- score normalized to 2
gomod/sigs.k8s.io/kustomize/kyaml 0.21.1 UnknownUnknown
gomod/sigs.k8s.io/secrets-store-csi-driver 1.6.0 🟢 6.9
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Dependency-Update-Tool🟢 10update tool detected
Binary-Artifacts🟢 10no binaries found in the repo
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Vulnerabilities🟢 55 existing vulnerabilities detected
Branch-Protection⚠️ 3branch protection is not maximal on development and all release branches
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
SAST🟢 10SAST tool is run on all commits
License🟢 10license file detected
Packaging🟢 10packaging workflow detected
Security-Policy🟢 10security policy file detected
Fuzzing⚠️ 0project is not fuzzed
CI-Tests🟢 1015 out of 15 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 10 contributing companies or organizations
gomod/sigs.k8s.io/structured-merge-diff/v6 6.4.0 🟢 6.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow⚠️ -1no workflows found
Maintained🟢 1012 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 10all changesets reviewed
Token-Permissions⚠️ -1No tokens found
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • go.mod

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 7, 2026

Unit Tests

    2 files  ±0    420 suites  ±0   6m 50s ⏱️ +7s
5 022 tests ±0  5 020 ✅ ±0  2 💤 ±0  0 ❌ ±0 
6 049 runs  ±0  6 047 ✅ ±0  2 💤 ±0  0 ❌ ±0 

Results for commit 2bc094a. ± Comparison against base commit 073b796.

♻️ This comment has been updated with latest results.

Copilot AI review requested due to automatic review settings May 8, 2026 16:18
@radius-functional-tests
Copy link
Copy Markdown

radius-functional-tests Bot commented May 8, 2026

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref 2bc094a
Unique ID func5d5e6f7b96
Image tag pr-func5d5e6f7b96
  • gotestsum 1.13.0
  • KinD: v0.29.0
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-func5d5e6f7b96
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-func5d5e6f7b96
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-func5d5e6f7b96
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-func5d5e6f7b96
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-func5d5e6f7b96
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repository’s Go module dependencies (including Kubernetes, controller-runtime, AWS SDK v2, and multiple HashiCorp/Azure/OpenAPI libraries) and bumps the Go toolchain version declared in go.mod to align builds with the refreshed dependency set.

Changes:

  • Bump go directive from 1.26.1 to 1.26.2.
  • Update a broad set of Go dependencies (Kubernetes to v0.36.0, controller-runtime to v0.24.0, etc.).
  • Refresh go.sum to match the updated module graph.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
go.mod Updates Go version and direct/indirect dependency versions; introduces a standalone require line for github.com/hashicorp/go-version.
go.sum Updates module checksums to reflect the dependency bumps and transitive graph changes.

Comment thread go.mod
Comment on lines 118 to +121
)

require github.com/hashicorp/go-version v1.9.0

@codecov
Copy link
Copy Markdown

codecov Bot commented May 8, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 51.21%. Comparing base (073b796) to head (2bc094a).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #11828      +/-   ##
==========================================
+ Coverage   51.20%   51.21%   +0.01%     
==========================================
  Files         715      715              
  Lines       45074    45074              
==========================================
+ Hits        23079    23085       +6     
+ Misses      19798    19795       -3     
+ Partials     2197     2194       -3     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants