Skip to content

chore(deps): update all dependencies - #227

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/onsi/ginkgo/v2 v2.32.2 → v2.33.1 age confidence require minor
github.com/onsi/gomega v1.43.0 → v1.44.0 age confidence require minor
github.com/open-telemetry/opentelemetry-operator/apis v0.159.0 → v0.160.0 age confidence require minor
github.com/prometheus/client_golang v1.24.1 → v1.25.0 age confidence require minor
go.opentelemetry.io/collector/component v1.67.0 → v1.68.0 age confidence require minor
go.opentelemetry.io/collector/config/configauth v1.67.0 → v1.68.0 age confidence require minor
go.opentelemetry.io/collector/config/configcompression v1.67.0 → v1.68.0 age confidence require minor
go.opentelemetry.io/collector/config/configopaque v1.67.0 → v1.68.0 age confidence require minor
go.opentelemetry.io/collector/config/configtelemetry v0.161.0 → v0.162.0 age confidence require minor
go.opentelemetry.io/collector/otelcol v0.161.0 → v0.162.0 age confidence require minor
go.opentelemetry.io/collector/pipeline v1.67.0 → v1.68.0 age confidence require minor
go.opentelemetry.io/collector/service v0.161.0 → v0.162.0 age confidence require minor
golang (source) 1.27.1-alpine3.23 → 1.27.2-alpine3.23 age confidence stage patch
golangci/golangci-lint 2.13.2 → 2.14.0 age confidence minor
k8s.io/api v0.37.0 → v0.37.1 age confidence require patch
k8s.io/apimachinery v0.37.0 → v0.37.1 age confidence require patch
k8s.io/client-go v0.37.0 → v0.37.1 age confidence require patch
open-telemetry/opentelemetry-operator 0.159.0 → 0.160.0 age confidence minor
opentelemetry-operator (source) 0.123.0 → 0.124.1 age confidence minor
sigs.k8s.io/controller-runtime v0.25.1 → v0.25.2 age confidence require patch

Release Notes

onsi/ginkgo (github.com/onsi/ginkgo/v2)

v2.33.1

Compare Source

Fixes
  • Add several missing fields to spec report JSON output.

v2.33.0

Compare Source

Features
  • The JUnit reporter now records each spec's ReportEntrys as <properties> on its <testcase> element, with the entry's name and its JSON-encoded value. Thanks @​pohly! [23db51a]
Maintenance
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. See RELEASING.md. [8616ecb]
onsi/gomega (github.com/onsi/gomega)

v1.44.0

Compare Source

Fixes
  • BeNumerically compares signed and unsigned integers by value: -1 no longer equals uint64(math.MaxUint64) and uint(5) is now greater than -3 (#​925) [26e3c6b]
  • BeNumerically("~") no longer overflows when computing the distance between extreme integers (#​928) [1955764]
  • BeNumerically("==", x, threshold) now honors the threshold for floats, as it already did for integers (#​927) [10e2aca]
  • HaveKeyWithValue succeeds if any key accepted by the key matcher has a matching value, rather than depending on map iteration order (#​929) [ffc577a]
  • HaveKey and HaveKeyWithValue treat key and value matcher errors like ContainElement does: a match wins, and an error is only reported when nothing matches (#​926) [dc91598]
  • MatchJSON no longer treats numbers too large for a float64 as equal to one another (#​930) [9d619a5]
  • MatchJSON compares integers beyond ±2^53 exactly, so neighboring large integers (e.g. IDs) no longer match; all other numbers are still compared as float64s (#​931) [8ef1aa7, 630fe12]
  • HaveExactElements reports missing or extra elements that start at index 0, and reports the first extra element's index rather than the last (#​934) [af1b777]
  • MatchYAML compares every document in a multi-document stream rather than only the first; empty documents (e.g. a leading or trailing ---) are ignored (#​933) [2773796]
  • MatchXML ignores namespace prefixes: elements and attributes are compared by namespace URI, and the URIs declared on each element must match whatever prefix they are bound to (#​932) [c0dbd89, 2565350]

v1.43.1

Compare Source

Maintenance
  • Update go.yaml.in/yaml/v3 to v3.0.5 [d547015]
  • Releases are now cut by a GitHub Actions workflow (Actions -> Release -> Run workflow) rather than by hand, with changelog entries collected under ## Unreleased as the work happens. Releases still ship the stripped-down tree on master-lite - tests removed and Ginkgo dropped from go.mod - and the workflow now builds it and checks it on every push. See RELEASING.md. [e9dc84d]
open-telemetry/opentelemetry-operator (github.com/open-telemetry/opentelemetry-operator/apis)

v0.160.0

Compare Source

0.160.0

🛑 Breaking changes 🛑
  • operator, collector, target allocator: Disable operator, collector, and target allocator network policies by default. (#​5551, #​5558, #​5621, #​5624, #​5654)
    The operator.networkpolicy and operand.networkpolicy feature gates are moved back to alpha and are disabled by default.
    The generated network policies can block API server access on some clusters.
    To keep creating network policies, enable them with --feature-gates=+operator.networkpolicy,+operand.networkpolicy,
    or set spec.networkPolicy.enabled: true on individual collectors and target allocators.
🚩 Deprecations 🚩
  • auto-instrumentation: Remove autoinstrumentation-php image definition from the repository (#​932)
    The PHP autoinstrumentation image will be hosted by the packaging SIG.
    The one released image (v0.1.0) of the image in the operator registry will
    eventually be deleted. This image was never used for any functionality shipped by the operator.
💡 Enhancements 💡
  • collector: Add RBAC support for extracting labels and annotations from CronJobs (and Jobs) via the k8sattributes processor. (#​5527)
    The operator's own ServiceAccount must itself hold get/list/watch on batch/jobs and
    batch/cronjobs for this to take effect, since Kubernetes RBAC only lets a ServiceAccount
    grant permissions it already has. This PR also extends the operator's own ClusterRole
    accordingly (config/rbac/role.yaml).

  • collector, target allocator: Add enableServiceLinks to the OpenTelemetryCollector and TargetAllocator CRs, passed through to the pod spec of the generated workloads. It defaults to true, matching the Kubernetes Pod field. (#​5569)

  • operator: Add support for Kubernetes 1.37 (#​5650)

🧰 Bug fixes 🧰
  • auto-instrumentation: Honor Instrumentation CRD/API json tags when loading --config-file (no-CRD webhook configs). (#​5618)
    Operator Config fields still load with gopkg.in/yaml.v3 (yaml tags). The
    instrumentations block is re-parsed with sigs.k8s.io/yaml so embedded API
    types keep their json tags (for example apacheHttpd, imagePullPolicy,
    resourceAttributes, valueFrom, volumeLimitSize, configPath).

  • collector: Preserve TCP and UDP protocols when generating NetworkPolicy ports. (#​5611)

  • target allocator: Use the .svc FQDN for the TargetAllocator endpoint injected into the collector's Prometheus receiver so it works on clusters behind an HTTP proxy. (#​5586)
    The bare service name (http://-targetallocator:80) does not match the standard NO_PROXY
    entries (.svc, .cluster.local), so Go routes the request through the proxy. Using
    -targetallocator..svc matches NO_PROXY=.svc while staying compatible with
    custom cluster domains (unlike the full .svc.cluster.local endpoint reverted in #​3248).

  • target allocator: Restore promhttp_metric_handler_requests_total and promhttp_metric_handler_requests_in_flight on the /metrics endpoint when a custom gatherer is configured. (#​5622)
    #5294 switched the /metrics handler to promhttp.HandlerFor when a custom gatherer
    is set, but omitted the InstrumentMetricHandler wrapper that registers these two metrics.
    The handler is now built once in NewServer (after options are applied) using
    InstrumentMetricHandler, restoring the missing metrics for both code paths.

  • target allocator: Watch and prune all the resources the TargetAllocator controller creates. (#​5657)
    The controller now watches the resources it creates, so manual changes to them are reverted.
    It also deletes the resources it no longer needs, for example the NetworkPolicy after
    spec.networkPolicy.enabled is set to false, or the ServiceMonitor after
    spec.observability.metrics.enableMetrics is set to false.

  • collector: Fix string values that look like numbers, booleans, timestamps or special floats (e.g. "0e12", ".inf") being written unquoted to the collector ConfigMap, which made the collector read them as a different type and fail to start. (#​4314)
    The ConfigMap is now rendered with the same YAML library the collector parses it with (go.yaml.in/yaml/v3),
    and the rendered document is checked to decode back to the values held by the CR before it is written.
    The target allocator rewrite of the Prometheus receiver no longer re-parses the rendered config, and the
    resulting ConfigMap uses the same formatting as configs without a target allocator (2-space indentation).

  • collector: Detect Gateway API availability by the HTTPRoute kind served in gateway.networking.k8s.io/v1 instead of the API group alone, so the operator no longer crash-loops on clusters with a partial Gateway API bundle (for example only GatewayClass). (#​5571)

  • target allocator: Stop assigning targets to collector pods that are being deleted. A terminating pod keeps reporting Ready until the kubelet confirms the deletion, which never happens while its node is unreachable, so its targets were never reassigned. (#​5576)

  • webhook: Configure the standalone OpenShift webhook with the environment variables required for cert-manager autodetection. (#​5660)
    This allows TargetAllocator mTLS admission to discover cert-manager when the webhook is
    installed through the OpenShift/OLM deployment path.

  • opamp: Only require workload patch permissions when the AcceptsRestartCommand capability is enabled, and reject restart commands when it is not. (#​5573)

Components
prometheus/client_golang (github.com/prometheus/client_golang)

v1.25.0

Compare Source

⚠️ This release raises the minimum required Go version to 1.26 and includes breaking API changes in api/prometheus/v1 (see the [CHANGE] entries below). ⚠️

1.25.0 / 2026-10-07

  • [CHANGE] Minimum required Go version is now 1.26, only the two latest Go versions (1.26 and 1.27) are supported from now on. #​2138
  • [CHANGE] api/prometheus/v1: Query, QueryRange, Series, LabelNames, and LabelValues now return Infos annotations in addition to Warnings, matching the Prometheus server's info annotations. This changes the signatures of these methods and of api.Client's Do/DoGetFallback; custom API client implementations must be updated. #​1963
  • [CHANGE] api/prometheus/v1: Rework TSDBBlocks result types to align with the Prometheus server's tsdb.BlockMeta: TSDBBlocksResult now contains Blocks []TSDBBlockMeta directly instead of mirroring the full API envelope, nested types are renamed (TSDBBlockMeta, TSDBBlockStats, TSDBBlockMetaCompaction), stat fields are uint64 with omitempty tags, and the optional compaction parents field is included. #​1928
  • [FEATURE] testutil: Add GatherAndFormat to encode a subset of metrics from a Gatherer. #​2091
  • [FEATURE] promhttp: Add HandlerOpts.AcceptedFormats to customize the formats negotiated from the incoming Accept header, enabling opt-in to experimental formats such as OpenMetrics 2.0 without changing default negotiation. #​2146
  • [ENHANCEMENT] promhttp: Negotiated metrics responses now include a Vary header. #​2142
  • [ENHANCEMENT] prometheus: Regenerate the default runtime collector metrics for Go 1.25 and Go 1.26. #​2090, #​2095
  • [ENHANCEMENT] testutil: Finalize OpenMetrics output in GatherAndFormat and CollectAndFormat (terminating # EOF). #​2125
  • [BUGFIX] api: Match complete URL path placeholders only; a :foo argument no longer substitutes inside :foobar. #​2136
  • [BUGFIX] exp/api/remote: Reset the pooled buffer before generic proto marshaling, preventing corrupted remote-write payloads. #​2139
  • [BUGFIX] testutil/promlint: Fix "mibi" unit prefix to "mebi". #​2135
What's changed

What's Changed

New Contributors

Full Changelog: prometheus/client_golang@v1.24.1...v1.25.0

open-telemetry/opentelemetry-collector (go.opentelemetry.io/collector/component)

v1.68.0

🛑 Breaking changes 🛑
  • cmd/mdatagen: Generated processor lifecycle tests now assert that the processor propagates the incoming context unchanged to the next consumer by default. (#​15994)
    Disable with skip_context_propagation: true

  • processor/queue_batch: Rename queuebatch processor to queue_batch processor. (#​14396)

💡 Enhancements 💡
  • extension/memory_limiter: Add otelcol_memorylimiter_refused_requests metric to record network request refusals in extension mode. (#​15561)

  • pkg/confighttp: Enable keepalive configuration by default. (#​16026)
    Introduces the feature gate pkg.confighttp.PrioritizeNewKeepalive. When disabled, this flag
    restores the old behaviour of removing the keepalive configuration in favour
    of the deprecated fields IdleConnTimeout, MaxIdleConns, MaxIdleConnsPerHost,
    DisableKeepAlives when the flag is disabled.

  • pkg/exporterhelper: Make the partition idle timeout configurable via batch::partition::idle_timeout and raise the default to 90s. (#​15894)

  • pkg/exporterhelper: Make the multi-batcher partition LRU cache size configurable and export cache size metrics. (#​14526)
    Adds sending_queue::batch::partition::cache_size (default 10000) to cap the
    number of active partition batchers. The value
    must be positive. Current size and configured capacity are exported as
    otelcol_exporter_queue_batch_partition_cache_size
    and otelcol_exporter_queue_batch_partition_cache_capacity.

  • pkg/pprofile: Speed up profiles dictionary merging during exporter-queue batching by replacing the linear-scan dedup in switchDictionary with an indexed lookup, reducing per-merge cost from O(N*L^2) to O(N+L). (#​15544)
    No behavior change: merged dictionary contents and remapped indices are identical to before.

  • pkg/receiverhelper: Stop allocating a span link that is always discarded when a long-lived-context receiver starts an operation without a parent span context. (#​15998)
    Receivers created with LongLivedCtx: true no longer build a trace.Link when the
    long-lived context carries no valid span context. The SDK already discarded such a link,
    so behaviour is unchanged. This removes 3 of 7 allocations per receive operation.

  • pkg/xpdata: Reduce the time xhash.MapHash takes for maps with many entries. (#​15990)

🧰 Bug fixes 🧰
  • exporter/debug: Support known sync error handling on AIX (#​15924)
    Enable the debug exporter to handle known synchronous errors on AIX.

  • pkg/exporterhelper: Drop only the oversized item when splitting a batch, instead of discarding every item queued behind it (#​15936)
    Applied to logs only for now

  • pkg/exporterhelper: Add exporter and data_type attributes to exporter/enqueue spans. (#​16022)

  • receiver/otlp: Error handler preserves the HTTP status code when the request Content-Type is not one a Status can be encoded in (#​15995)
    Extends the fix in #​13414, which handled a missing Content-Type. A Content-Type that was
    present but unsupported, or malformed, still fell through to
    500 {"code": 13, "message": "failed to marshal error message"}, reporting client errors
    such as 401 from a server auth extension or 400 from an unsupported Content-Encoding as
    server faults.

golangci/golangci-lint (golangci/golangci-lint)

v2.14.0

Compare Source

Released on 2026-09-24

  1. Bug fixes
    • fix: cache of facts reloading
  2. Linters new features or changes
    • bodyclose: from 73d1f95 to 857993a (new directive handled)
    • exhaustive: from 0.12.0 to 0.13.0
    • exhaustruct_v5: from 5.0.3 to 5.2.0 (new option: allow-empty-blank-assignments)
    • go-check-sumtype: from 0.3.1 to ae6904d
    • gocritic: from 0.14.4 to 0.15.0
    • gofumpt: from 0.11.0 to 0.12.0
    • gomoddirectives: from 0.9.0 to 0.10.0
    • gosec: from 2.28.0 to 2.29.0 (re-enable G407)
    • govet-modernize: from 0.49.0 to 0.50.0
    • loggercheck: from 0.11.0 to 0.12.0
    • revive: from 1.15.0 to 1.17.0 (new rules: marshal-receiver, multiline-if-init, use-slices-concat)
    • tagliatelle: from 0.7.2 to 0.8.0
  3. Linters bug fixes
    • fatcontext: from 0.10.0 to 0.10.1
    • flock: from 0.13.0 to 0.13.1
    • godoclint: from 0.11.2 to 0.11.4
    • protogetter: from 0.3.21 to 1.0.1
    • recvcheck: from 0.3.0 to 0.3.1
    • tagalign: from 1.4.3 to 1.4.4
kubernetes/api (k8s.io/api)

v0.37.1

Compare Source

kubernetes/apimachinery (k8s.io/apimachinery)

v0.37.1

Compare Source

kubernetes/client-go (k8s.io/client-go)

v0.37.1

Compare Source

open-telemetry/opentelemetry-helm-charts (opentelemetry-operator)

v0.124.1

Compare Source

OpenTelemetry Operator Helm chart for Kubernetes

What's Changed

New Contributors

Full Changelog: open-telemetry/opentelemetry-helm-charts@opentelemetry-ebpf-instrumentation-0.14.1...opentelemetry-operator-0.124.1

v0.124.0

Compare Source

OpenTelemetry Collector Helm chart for Kubernetes

What's Changed

Full Changelog: open-telemetry/opentelemetry-helm-charts@opentelemetry-collector-0.123.0...opentelemetry-collector-0.124.0

v0.123.1

Compare Source

OpenTelemetry Operator Helm chart for Kubernetes

What's Changed

Full Changelog: open-telemetry/opentelemetry-helm-charts@opentelemetry-ebpf-instrumentation-0.14.0...opentelemetry-operator-0.123.1

kubernetes-sigs/controller-runtime (sigs.k8s.io/controller-runtime)

v0.25.2

Compare Source

What's Changed

Full Changelog: kubernetes-sigs/controller-runtime@v0.25.1...v0.25.2


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM (* 0-3 * * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/all branch 4 times, most recently from 4daa517 to 5e7c84c Compare September 24, 2026 21:47
@renovate

renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 43 additional dependencies were updated

Details:

Package Change
github.com/prometheus/common v0.71.0 -> v0.72.0
github.com/prometheus/procfs v0.21.1 -> v0.22.0
go.opentelemetry.io/collector/component/componentstatus v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/component/componenttest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/confmap v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/confmap/xconfmap v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/connector v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/connector/connectortest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/connector/xconnector v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/consumer v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/consumer/consumererror v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/consumer/consumertest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/consumer/xconsumer v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/exporter v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/exporter/exportertest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/exporter/xexporter v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/extension v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/extension/extensionauth v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/extension/extensioncapabilities v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/extension/extensiontest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/featuregate v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/internal/componentalias v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/internal/fanoutconsumer v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/internal/telemetry v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/pdata v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/pdata/pprofile v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/pdata/testdata v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/pdata/xpdata v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/pipeline/xpipeline v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/processor v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/processor/processortest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/processor/xprocessor v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/receiver v1.67.0 -> v1.68.0
go.opentelemetry.io/collector/receiver/receivertest v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/receiver/xreceiver v0.161.0 -> v0.162.0
go.opentelemetry.io/collector/service/hostcapabilities v0.161.0 -> v0.162.0
golang.org/x/mod v0.40.0 -> v0.41.0
golang.org/x/net v0.58.0 -> v0.59.0
golang.org/x/oauth2 v0.36.0 -> v0.37.0
golang.org/x/sync v0.22.0 -> v0.23.0
golang.org/x/term v0.45.0 -> v0.46.0
golang.org/x/text v0.41.0 -> v0.42.0
k8s.io/streaming v0.37.0 -> v0.37.1

@renovate
renovate Bot force-pushed the renovate/all branch 6 times, most recently from 3957605 to 8e3e40a Compare October 5, 2026 19:10
@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 9fb0b81 to cdb6efe Compare October 10, 2026 00:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants