Skip to content

chore(deps): update module go.yaml.in/yaml/v2 to v3 - #571

Open
red-hat-konflux[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x
Open

red-hat-konflux[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
go.yaml.in/yaml/v2 v2.4.4v3.0.5 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

yaml/go-yaml (go.yaml.in/yaml/v2)

v3.0.5

Compare Source

v3.0.4

Compare Source

v3.0.3

Compare Source

v3.0.2

Compare Source

v3.0.1

Compare Source

v3.0.0

Compare Source


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 02:00 AM and 04:59 AM, Monday through Friday (* 2-4 * * 1-5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot added area/dependency Issues or PRs related to dependency changes ok-to-test Indicates a non-member PR verified by an org member that is safe to test. major-update manual-review-required labels Jun 16, 2026
@coderabbitai

coderabbitai Bot commented Jun 16, 2026

Copy link
Copy Markdown

Walkthrough

The PR updates the indirect go.yaml.in/yaml/v3 module requirement in go.mod from v3.0.4 to v3.0.5. The go.yaml.in/yaml/v2 requirement remains unchanged.

Changes

YAML dependency update

Layer / File(s) Summary
Dependency version update
go.mod
The indirect go.yaml.in/yaml/v3 requirement changes from v3.0.4 to v3.0.5.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: typeid, anispate

🚥 Pre-merge checks | ✅ 14 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title claims that go.yaml.in/yaml/v2 changes to v3, but the diff updates go.yaml.in/yaml/v3 from v3.0.4 to v3.0.5. Rename the title to describe the actual update, such as "chore(deps): update go.yaml.in/yaml/v3 from v3.0.4 to v3.0.5".
✅ Passed checks (14 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed PR only changes go.mod/go.sum dependency versions; no test files or Ginkgo titles were modified.
Test Structure And Quality ✅ Passed PR only updates go.mod/go.sum; no Ginkgo test code changed, so the test-structure checklist is not applicable.
Microshift Test Compatibility ✅ Passed Only go.mod/go.sum changed; no Ginkgo e2e tests or test files were added or modified, so the check is not applicable.
Single Node Openshift (Sno) Test Compatibility ✅ Passed Only go.mod/go.sum changed; no new or modified Ginkgo e2e tests to review for SNO assumptions.
Topology-Aware Scheduling Compatibility ✅ Passed Commit only updates go.mod/go.sum for a yaml dependency; no manifests, operators, or controllers changed, so topology-aware scheduling isn’t implicated.
Ote Binary Stdout Contract ✅ Passed PR only updates go.mod/go.sum; no process-level stdout code was changed, so it doesn't affect the binary stdout contract.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed The PR only updates go.mod/go.sum; no new Ginkgo e2e tests were added, so IPv6/disconnected compatibility isn’t implicated.
No-Weak-Crypto ✅ Passed Diff only bumps go.yaml.in/yaml/v3 in go.mod/go.sum; no MD5/SHA1/DES/RC4/3DES/ECB, custom crypto, or secret comparisons added.
Container-Privileges ✅ Passed PR only changes go.mod/go.sum; no container/K8s manifests or privilege-related fields were modified.
No-Sensitive-Data-In-Logs ✅ Passed Only go.mod/go.sum dependency bumps changed; no logging code or sensitive fields were added.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from anispate and typeid June 16, 2026 04:31
@bergmannf

Copy link
Copy Markdown
Contributor

/retest

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x branch from 55ba64d to b56ffd7 Compare June 26, 2026 04:18
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module go.yaml.in/yaml/v2 to v3 chore(deps): update module go.yaml.in/yaml/v2 to v3 - autoclosed Jul 2, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jul 2, 2026
@red-hat-konflux
red-hat-konflux Bot deleted the konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x branch July 2, 2026 00:13
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module go.yaml.in/yaml/v2 to v3 - autoclosed chore(deps): update module go.yaml.in/yaml/v2 to v3 Jul 2, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jul 2, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x branch 2 times, most recently from b56ffd7 to 70d668e Compare July 2, 2026 04:17
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module go.yaml.in/yaml/v2 to v3 chore(deps): update module go.yaml.in/yaml/v2 to v3 - autoclosed Jul 3, 2026
@red-hat-konflux red-hat-konflux Bot closed this Jul 3, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module go.yaml.in/yaml/v2 to v3 - autoclosed chore(deps): update module go.yaml.in/yaml/v2 to v3 Jul 7, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Jul 7, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x branch 2 times, most recently from 70d668e to 19cdaa7 Compare July 7, 2026 04:19
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x branch from 19cdaa7 to 8404bc2 Compare July 30, 2026 04:11

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@go.mod`:
- Line 133: Update the google.golang.org/grpc dependency in go.mod to v1.82.1 or
later, then refresh go.sum so the dependency checksums match the new version.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 61245d22-2e09-441e-8d30-c0f665b495e0

📥 Commits

Reviewing files that changed from the base of the PR and between 19cdaa7 and 8404bc2.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (1)
  • go.mod

Comment thread go.mod
go.uber.org/zap v1.28.0 // indirect
go.yaml.in/yaml/v2 v2.4.4 // indirect
go.yaml.in/yaml/v3 v3.0.4 // indirect
go.yaml.in/yaml/v3 v3.0.5 // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Show the relevant section of go.mod with line numbers
cat -n go.mod | sed -n '120,170p'

# Search for grpc references in the module files
rg -n "google\.golang\.org/grpc|v1\.82\.0|v1\.82\.1" go.mod go.sum

Repository: openshift/configure-alertmanager-operator

Length of output: 2828


🌐 Web query:

GO-2026-6061 google.golang.org/grpc v1.82.1 xDS RBAC authorization bypass HTTP/2 denial of service OSV

💡 Result:

GO-2026-6061 is a security advisory for the google.golang.org/grpc package, which addresses three distinct vulnerabilities fixed in version v1.82.1 [1][2][3]. These vulnerabilities involve the xDS RBAC authorization engine and the HTTP/2 transport implementation [1][4]. The vulnerabilities are as follows: 1. xDS RBAC Authorization Bypass (Fail-Open): When building RBAC policies from xDS configurations, the engine previously ignored unsupported rule types, specifically Metadata and RequestedServerName [5][4]. If an authorization policy relied on these matchers, they were treated as no-ops, effectively removing the intended security restrictions [5][6]. 2. xDS RBAC Denial of Service (Panic): The system was vulnerable to a server panic when parsing specifically crafted xDS RBAC policies that contained NOT rules wrapping unsupported field types [5][4]. A recursive call for the inner rule could return a nil matcher, leading to a pointer dereference error and server crash upon processing incoming requests [5][7]. 3. HTTP/2 Denial of Service (Mitigation Bypass): An HTTP/2 Rapid Reset mitigation bypass allowed for denial of service [3][4]. Attackers could initiate a rapid flood of HEADERS frames followed immediately by RST_STREAM frames [4]. Because these items were queued in the control buffer without correctly counting against the transport's response frame threshold, they could bypass reader blocking and cause high CPU consumption [4][7]. The resolution, released in v1.82.1, includes explicit handling for the missing xDS rule types to prevent silent authorization bypasses, fixes to the recursive matcher logic to avoid null pointer dereferences, and a new mechanism to throttle incoming HTTP/2 frames [5][4]. Users can adjust this new HTTP/2 throttling behavior using the GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT environment variable [4][6]. Updates should be applied by upgrading the google.golang.org/grpc module to v1.82.1 or later [5][3].

Citations:


Upgrade the gRPC pin in go.mod:147.

google.golang.org/grpc v1.82.0 is still pinned here; GO-2026-6061 affects versions before v1.82.1. Bump to v1.82.1 or later and refresh go.sum.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` at line 133, Update the google.golang.org/grpc dependency in go.mod
to v1.82.1 or later, then refresh go.sum so the dependency checksums match the
new version.

Sources: Path instructions, Linters/SAST tools

@openshift-ci

openshift-ci Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux[bot]
Once this PR has been reviewed and has the lgtm label, please assign bpresnel-rh for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module go.yaml.in/yaml/v2 to v3 chore(deps): update module go.yaml.in/yaml/v2 to v3 - autoclosed Aug 7, 2026
@red-hat-konflux red-hat-konflux Bot closed this Aug 7, 2026
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update module go.yaml.in/yaml/v2 to v3 - autoclosed chore(deps): update module go.yaml.in/yaml/v2 to v3 Aug 10, 2026
@red-hat-konflux red-hat-konflux Bot reopened this Aug 10, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/master/go.yaml.in-yaml-v2-3.x branch 2 times, most recently from 8404bc2 to 17b6a17 Compare August 10, 2026 04:15
@nephomaniac

Copy link
Copy Markdown
Contributor

/retest

@codecov

codecov Bot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 67.61%. Comparing base (ac8e304) to head (17b6a17).
⚠️ Report is 2 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #571   +/-   ##
=======================================
  Coverage   67.61%   67.61%           
=======================================
  Files           8        8           
  Lines        1124     1124           
=======================================
  Hits          760      760           
  Misses        330      330           
  Partials       34       34           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@openshift-ci

openshift-ci Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

@red-hat-konflux[bot]: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/lint 17b6a17 link true /test lint
ci/prow/validate 17b6a17 link true /test validate

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@nephomaniac

Copy link
Copy Markdown
Contributor

Indirect dep patch bump (go.yaml.in/yaml/v3). Requires rebase — 19 commits behind master, stale Konflux checks from removed tenant.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Issues or PRs related to dependency changes major-update manual-review-required ok-to-test Indicates a non-member PR verified by an org member that is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants