Skip to content

NO-JIRA: chore(deps): weekly dependabot consolidation - #8410

Merged
openshift-merge-bot[bot] merged 6 commits into
openshift:mainfrom
hypershift-community:fix/weekly-dependabot-consolidation
May 5, 2026
Merged

openshift-merge-bot[bot] merged 6 commits into
openshift:mainfrom
hypershift-community:fix/weekly-dependabot-consolidation

Conversation

@hypershift-jira-solve-ci

@hypershift-jira-solve-ci hypershift-jira-solve-ci Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

Summary

Weekly consolidation of dependabot dependency updates.

Consolidated PRs

Commits

  1. chore(deps): update root module dependencies
  2. chore(deps): update vendored dependencies
  3. chore(deps): update API module dependencies
  4. chore(deps): update API vendored dependencies
  5. chore: regenerate CRD assets

Assisted-by: Claude (via Claude Code)


Note: This PR was auto-generated by the dependabot-triage periodic CI job. See the full report for token usage, cost breakdown, and detailed output.

Summary by CodeRabbit

Release Notes

  • Chores
    • Updated Go module dependencies to latest patch and minor versions for security improvements and bug fixes across logging, cryptography, networking, and cloud infrastructure libraries.

OpenShift CI Bot added 5 commits May 4, 2026 14:45
Weekly dependabot dependency consolidation.
Vendor updates for root module dependency changes.
Weekly dependabot dependency consolidation for api/ module.
Vendor updates for api/ module dependency changes.
Regenerated CRD manifests after dependency updates.
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Pipeline controller notification
This repo is configured to use the pipeline controller. Second-stage tests will be triggered either automatically or after lgtm label is added, depending on the repository configuration. The pipeline controller will automatically detect which contexts are required and will utilize /test Prow commands to trigger the second stage.

For optional jobs, comment /test ? to see a list of all defined jobs. To trigger manually all jobs from second stage use /pipeline required command.

This repository is configured in: LGTM mode

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label May 4, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@hypershift-jira-solve-ci[bot]: This pull request explicitly references no jira issue.

Details

In response to this:

Summary

Weekly consolidation of dependabot dependency updates.

Consolidated PRs

Commits

  1. chore(deps): update root module dependencies
  2. chore(deps): update vendored dependencies
  3. chore(deps): update API module dependencies
  4. chore(deps): update API vendored dependencies
  5. chore: regenerate CRD assets

Assisted-by: Claude (via Claude Code)

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented May 4, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 5b702ba4-df94-410b-b293-241c05490f23

📥 Commits

Reviewing files that changed from the base of the PR and between 68106f0 and 4c0df66.

⛔ Files ignored due to path filters (142)
  • api/go.sum is excluded by !**/*.sum
  • api/vendor/golang.org/x/net/http2/hpack/tables.go is excluded by !**/vendor/**
  • api/vendor/golang.org/x/net/http2/http2.go is excluded by !**/vendor/**
  • api/vendor/golang.org/x/net/http2/server.go is excluded by !**/vendor/**
  • api/vendor/golang.org/x/net/http2/transport.go is excluded by !**/vendor/**
  • api/vendor/golang.org/x/net/http2/writesched.go is excluded by !**/vendor/**
  • api/vendor/golang.org/x/net/http2/writesched_priority_rfc7540.go is excluded by !**/vendor/**
  • api/vendor/golang.org/x/net/http2/writesched_random.go is excluded by !**/vendor/**
  • api/vendor/modules.txt is excluded by !**/vendor/**
  • cmd/install/assets/crds/cluster-api-provider-kubevirt/infrastructure.cluster.x-k8s.io_kubevirtmachines.yaml is excluded by !cmd/install/assets/**/*.yaml
  • cmd/install/assets/crds/cluster-api-provider-kubevirt/infrastructure.cluster.x-k8s.io_kubevirtmachinetemplates.yaml is excluded by !cmd/install/assets/**/*.yaml
  • go.sum is excluded by !**/*.sum
  • vendor/cloud.google.com/go/auth/CHANGES.md is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/httptransport/transport.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/transport/transport.go is excluded by !vendor/**, !**/vendor/**
  • vendor/cloud.google.com/go/auth/internal/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/CHANGES.md is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/apierror/apierror.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/apierror/internal/proto/custom_error.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/github.com/googleapis/gax-go/v2/apierror/internal/proto/error.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/github.com/googleapis/gax-go/v2/call_option.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/callctx/callctx.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/content_type.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/feature.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/internal/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/invoke.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/googleapis/gax-go/v2/telemetry.go is excluded by !vendor/**, !**/vendor/**
  • vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml is excluded by !vendor/**, !**/vendor/**, !**/zz_generated*
  • vendor/go.etcd.io/etcd/api/v3/version/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc/config.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc/interceptor.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc/internal/parse.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc/metadata_supplier.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc/stats_handler.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/LICENSE is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/client.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/common.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/config.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/doc.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/handler.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/request/resp_writer_wrapper.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/client.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/env.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/httpconv.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/server.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/util.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconv/v1.20.0.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil/gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil/httpconv.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/internal/semconvutil/netconv.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/transport.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/README.md is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/attribute_group.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/doc.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/event.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/exception.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/http.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/resource.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/schema.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.20.0/trace.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.26.0/README.md is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.26.0/attribute_group.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.26.0/doc.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.26.0/exception.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.26.0/metric.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.26.0/schema.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.37.0/rpcconv/metric.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.40.0/httpconv/metric.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.opentelemetry.io/otel/semconv/v1.40.0/rpcconv/metric.go is excluded by !vendor/**, !**/vendor/**
  • vendor/go.uber.org/zap/CHANGELOG.md is excluded by !vendor/**, !**/vendor/**
  • vendor/go.uber.org/zap/zapcore/entry.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/crypto/ssh/cipher.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/crypto/ssh/client_auth.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http/httpproxy/proxy.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/hpack/tables.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/http2.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/server.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/transport.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/writesched.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/writesched_priority_rfc7540.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/net/http2/writesched_random.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/sys/cpu/cpu_darwin_arm64_other.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/sys/cpu/cpu_other_arm64.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/sys/cpu/cpu_windows_arm64.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/sys/windows/dll_windows.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/sys/windows/security_windows.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/tools/go/packages/golist.go is excluded by !vendor/**, !**/vendor/**
  • vendor/golang.org/x/tools/go/packages/packages.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute-api.json is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute2-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/compute/v1/compute3-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/dns/v1/dns-api.json is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/dns/v1/dns-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/iam/v1/iam-api.json is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/iam/v1/iam-gen.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/internal/gensupport/send.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/internal/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/api/option/internaloption/unsaferesolver.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/genproto/googleapis/rpc/code/code.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/google.golang.org/genproto/googleapis/rpc/errdetails/error_details.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/google.golang.org/genproto/googleapis/rpc/status/status.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/google.golang.org/grpc/attributes/attributes.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/balancer/balancer.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/balancer/base/balancer.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/balancer/endpointsharding/endpointsharding.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/balancer/pickfirst/pickfirst.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/binarylog/grpc_binarylog_v1/binarylog.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/google.golang.org/grpc/credentials/tls.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/dialoptions.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/health/grpc_health_v1/health.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/google.golang.org/grpc/health/grpc_health_v1/health_grpc.pb.go is excluded by !**/*.pb.go, !vendor/**, !**/vendor/**, !**/*.pb.go
  • vendor/google.golang.org/grpc/internal/envconfig/envconfig.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/mem/buffer_pool.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/transport/defaults.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_client.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_server.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/mem/buffer_pool.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/picker_wrapper.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/resolver/map.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/rpc_util.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/server.go is excluded by !vendor/**, !**/vendor/**
  • vendor/google.golang.org/grpc/version.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/register.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/deepcopy_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/doc.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/register.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/types.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/backup/v1alpha1/types_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/deepcopy_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/schema.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/schema_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/types.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/types_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/api/core/v1/zz_generated.defaults.go is excluded by !vendor/**, !**/vendor/**, !**/zz_generated*.go, !**/zz_generated*
  • vendor/kubevirt.io/containerized-data-importer-api/pkg/apis/core/v1beta1/types.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/containerized-data-importer-api/pkg/apis/core/v1beta1/types_swagger_generated.go is excluded by !vendor/**, !**/vendor/**
  • vendor/kubevirt.io/containerized-data-importer-api/pkg/apis/core/v1beta1/zz_generated.deepcopy.go is excluded by !vendor/**, !**/vendor/**, !**/zz_generated*.go, !**/zz_generated*
  • vendor/modules.txt is excluded by !vendor/**, !**/vendor/**
📒 Files selected for processing (2)
  • api/go.mod
  • go.mod

📝 Walkthrough

Walkthrough

This pull request updates Go module dependencies across two go.mod files. In api/go.mod, indirect dependencies golang.org/x/net and golang.org/x/text receive minor version bumps. The root go.mod file sees more extensive updates, including direct dependency bumps for go.etcd.io/etcd, go.uber.org/zap, multiple golang.org/x/* packages, google.golang.org/api, google.golang.org/grpc, and KubeVirt-related packages. Several indirect dependencies are also advanced, including OpenTelemetry instrumentation libraries and cloud.google.com/go/auth. A replace directive for kubevirt.io/controller-lifecycle-operator-sdk/api is updated from a pseudo-version to v0.2.4.

🚥 Pre-merge checks | ✅ 12
✅ Passed checks (12 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: a weekly consolidation of dependabot dependency updates across multiple Go modules.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The PR only modifies Go module dependencies in go.mod and api/go.mod files with no changes to test files, so the check for stable Ginkgo test names does not apply.
Test Structure And Quality ✅ Passed This PR exclusively updates Go module dependencies and vendored files without modifying any test code, making the Ginkgo test quality check not applicable.
Microshift Test Compatibility ✅ Passed PR adds Ginkgo e2e tests using only standard Kubernetes and HyperShift APIs without unavailable OpenShift APIs or MicroShift-incompatible assumptions.
Single Node Openshift (Sno) Test Compatibility ✅ Passed This PR modifies only go.mod and api/go.mod files for dependency updates with no new Ginkgo e2e tests added.
Topology-Aware Scheduling Compatibility ✅ Passed PR only modifies Go module dependencies in go.mod and api/go.mod files. No deployment manifests, operator code, controllers, or scheduling constraints have been added or modified.
Ote Binary Stdout Contract ✅ Passed This PR exclusively contains Go module dependency version updates and regenerated CRD assets with no modifications to application source code that could introduce stdout contract violations.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed PR contains only dependency updates and CRD asset regeneration with no new Ginkgo e2e tests added.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Review rate limit: 9/10 reviews remaining, refill in 6 minutes.

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci
openshift-ci Bot requested review from bryan-cox and clebs May 4, 2026 14:54
@openshift-ci openshift-ci Bot added area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/platform/kubevirt PR/issue for KubeVirt (KubevirtPlatform) platform and removed do-not-merge/needs-area labels May 4, 2026
@bryan-cox

Copy link
Copy Markdown
Member

/approve

@hypershift-jira-solve-ci

Copy link
Copy Markdown
Contributor Author

The file zz_generated.featuregated-crd-manifests.yaml exists on main in vendor. The PR incorrectly deleted it. Now I have all the evidence for the report.

Test Failure Analysis Complete

Job Information

  • Prow Job: verify / Verify (GitHub Actions)
  • Build ID: 25326046528 / Job 74247019246
  • Repository: openshift/hypershift
  • PR: NO-JIRA: chore(deps): weekly dependabot consolidation #8410 — NO-JIRA: chore(deps): weekly dependabot consolidation
  • Failed Step: Run git update-index --refresh (dirty-tree check)

Test Failure Analysis

Error

untracked files detected:
?? vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml
Process completed with exit code 1.

Summary

The verify workflow detected an untracked file after running make generate update. The PR's "update vendored dependencies" commit incorrectly deleted vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml (368 lines removed) from the vendor directory, but the source file in api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml was not deleted. When CI runs make updatedepsgo mod vendor, the vendor step copies the local ./api/ module (via replace directive) back into vendor/github.com/openshift/hypershift/api/, which recreates the deleted file. Git then detects it as a new untracked file, failing the dirty-tree check.

Root Cause

The root module's go.mod contains replace github.com/openshift/hypershift/api => ./api, meaning go mod vendor copies the entire ./api/ directory tree into vendor/github.com/openshift/hypershift/api/. The source file api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml is a code-generated artifact that is always present in the api/ source directory.

The PR's dependabot consolidation workflow deleted this .yaml file from the vendor/ copy (commit 8113d9bc — "update vendored dependencies") but left the source file in api/ intact. This created an inconsistency:

  1. PR state: vendor/.../zz_generated.featuregated-crd-manifests.yaml is deleted (git tracks the deletion)
  2. CI runs make update: The deps target executes go mod vendor, which copies ./api/vendor/github.com/openshift/hypershift/api/
  3. File recreated: Since api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml still exists in the source, it gets copied back to vendor/
  4. Dirty tree: Git sees this previously-deleted-and-now-recreated file as an untracked file (??), failing the git status -s check

This is a vendor consistency issue in the dependabot consolidation script — it should not have deleted this file from vendor/ without also deleting it from api/ (or, more correctly, it should not have deleted it at all since it's a legitimate vendored artifact).

Recommendations
  1. Immediate fix: Re-run go mod vendor in the root module to restore vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml and commit the result. This ensures vendor consistency with the ./api/ source.

  2. Root cause fix in consolidation script: The dependabot consolidation workflow that produced the "update vendored dependencies" commit should not remove files that go mod vendor would regenerate. If the script runs go mod vendor itself, verify it is using the same Go toolchain version as CI and that no additional cleanup step is inadvertently deleting .yaml files from vendor/.

  3. Validation step: Add a go mod vendor && git diff --exit-code check to the consolidation script before committing, to catch vendor inconsistencies before the PR is pushed.

Evidence
Evidence Detail
Failed step Run git update-index --refresh — dirty-tree check after make generate update
Untracked file vendor/github.com/openshift/hypershift/api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml
PR diff status File was removed (368 deletions) in the PR, but only from vendor/ — not from source api/
Source file present api/hypershift/v1beta1/zz_generated.featuregated-crd-manifests.yaml exists on main and was not modified by the PR
File exists on main vendor/.../zz_generated.featuregated-crd-manifests.yaml is tracked on main — confirming it's a legitimate vendored artifact
go.mod replace directive replace github.com/openshift/hypershift/api => ./api — causes go mod vendor to copy ./api/ into vendor/
Makefile deps target Runs go mod vendor which copies ./api/vendor/github.com/openshift/hypershift/api/
Makefile update target api-deps workspace-sync deps api api-docs clients docs-aggregatedeps runs vendor step
Responsible commit 8113d9bc — "chore(deps): update vendored dependencies" — incorrectly deleted the file

The file was incorrectly removed during vendoring. It must be
present in vendor/ since go mod vendor copies it from the api/
module source.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@codecov

codecov Bot commented May 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 37.23%. Comparing base (68106f0) to head (f571f57).
⚠️ Report is 15 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #8410   +/-   ##
=======================================
  Coverage   37.22%   37.23%           
=======================================
  Files         750      752    +2     
  Lines       91789    91829   +40     
=======================================
+ Hits        34172    34195   +23     
- Misses      54978    54993   +15     
- Partials     2639     2641    +2     

see 6 files with indirect coverage changes

Flag Coverage Δ
cmd-support 32.06% <ø> (ø)
cpo-hostedcontrolplane 36.50% <ø> (+0.05%) ⬆️
cpo-other 37.73% <ø> (ø)
hypershift-operator 47.85% <ø> (ø)
other 27.77% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@bryan-cox bryan-cox left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/approve

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label May 4, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Scheduling tests matching the pipeline_run_if_changed or not excluded by pipeline_skip_if_only_changed parameters:
/test e2e-aks
/test e2e-aws
/test e2e-aws-upgrade-hypershift-operator
/test e2e-azure-self-managed
/test e2e-kubevirt-aws-ovn-reduced
/test e2e-v2-aws

@bryan-cox

Copy link
Copy Markdown
Member

/lgtm cancel

@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label May 4, 2026
@cwbotbot

cwbotbot commented May 4, 2026

Copy link
Copy Markdown

Test Results

e2e-aws

e2e-aks

@bryan-cox

Copy link
Copy Markdown
Member

/verified by e2e

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label May 4, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@bryan-cox: This PR has been marked as verified by e2e.

Details

In response to this:

/verified by e2e

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@JoelSpeed

Copy link
Copy Markdown
Contributor

/approve

For API

@openshift-ci

openshift-ci Bot commented May 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: bryan-cox, hypershift-jira-solve-ci[bot], JoelSpeed

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label May 5, 2026
@bryan-cox

Copy link
Copy Markdown
Member

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label May 5, 2026
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

Tests from second stage were triggered manually. Pipeline can be controlled only manually, until HEAD changes. Use command to trigger second stage.

@openshift-ci

openshift-ci Bot commented May 5, 2026

Copy link
Copy Markdown
Contributor

@hypershift-jira-solve-ci: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 6b39d47 into openshift:main May 5, 2026
40 checks passed
@bryan-cox
bryan-cox deleted the fix/weekly-dependabot-consolidation branch May 5, 2026 11:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/api Indicates the PR includes changes for the API area/cli Indicates the PR includes changes for CLI area/platform/kubevirt PR/issue for KubeVirt (KubevirtPlatform) platform jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants