Skip to content

fix(deps): update gomod dependencies - #3259

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/gomod-dependencies
Open

fix(deps): update gomod dependencies#3259
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/gomod-dependencies

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update Pending
cloud.google.com/go/kms v1.21.1v1.33.0 age confidence require minor
github.com/Masterminds/semver/v3 v3.4.0v3.5.0 age confidence require minor
github.com/PuerkitoBio/goquery v1.10.2v1.13.0 age confidence require minor
github.com/aws/aws-sdk-go-v2 v1.42.0v1.45.1 age confidence require minor
github.com/aws/aws-sdk-go-v2/config v1.32.25v1.33.1 age confidence require minor v1.33.2
github.com/aws/aws-sdk-go-v2/credentials v1.19.24v1.20.1 age confidence require minor v1.20.2
github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.2.11v0.4.1 age confidence require minor v0.4.2
github.com/aws/aws-sdk-go-v2/service/cloudformation v1.71.4v1.78.1 age confidence require minor v1.79.0
github.com/aws/aws-sdk-go-v2/service/ec2 v1.294.1v1.325.1 age confidence require minor v1.326.0
github.com/aws/aws-sdk-go-v2/service/iam v1.54.5v1.61.1 age confidence require minor v1.62.0
github.com/aws/aws-sdk-go-v2/service/s3 v1.104.0v1.109.1 age confidence require minor v1.110.0
github.com/aws/smithy-go v1.27.1v1.28.1 age confidence require minor
github.com/fsnotify/fsnotify v1.9.0v1.10.1 age confidence require minor
github.com/go-logr/logr v1.4.3v1.4.4 age confidence require patch
github.com/gomarkdown/markdown 37c66b813c5cf4 age confidence require digest
github.com/hashicorp/go-version v1.7.0v1.9.0 age confidence require minor
github.com/hashicorp/hc-install v0.9.2v0.9.5 age confidence require patch
github.com/hashicorp/terraform-exec v0.23.0v0.25.3 age confidence require minor
github.com/onsi/ginkgo/v2 v2.28.1v2.32.1 age confidence require minor
github.com/onsi/gomega v1.39.1v1.43.0 age confidence require minor
github.com/operator-framework/api v0.30.0v0.45.0 age confidence require minor
github.com/operator-framework/operator-lifecycle-manager v0.22.0v0.46.0 age confidence require minor
github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring v0.74.0v0.93.1 age confidence require minor
github.com/prometheus-operator/prometheus-operator/pkg/client v0.74.0v0.93.1 age confidence require minor
github.com/prometheus/client_golang v1.23.2v1.24.1 age confidence require minor
github.com/spf13/afero v1.12.0v1.15.0 age confidence require minor
github.com/spf13/cobra v1.10.0v1.10.2 age confidence require patch
github.com/spf13/pflag v1.0.9v1.0.10 age confidence require patch
github.com/spf13/viper v1.19.0v1.21.0 age confidence require minor
github.com/stretchr/testify v1.11.1v1.12.1 age confidence require minor
github.com/vmware-tanzu/velero v1.10.2v1.18.2 age confidence require minor
google.golang.org/api v0.227.0v0.295.0 age confidence require minor v0.296.0
google.golang.org/genai v1.51.0v1.70.0 age confidence require minor v1.71.0
sigs.k8s.io/controller-runtime v0.21.0v0.24.1 age confidence require minor
sigs.k8s.io/e2e-framework v0.6.0v0.7.0 age confidence require minor

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

Masterminds/semver (github.com/Masterminds/semver/v3)

v3.5.0

Compare Source

What's Changed

New Contributors

Full Changelog: Masterminds/semver@v3.4.0...v3.5.0

PuerkitoBio/goquery (github.com/PuerkitoBio/goquery)

v1.13.0

Compare Source

Performance improvements and new top-level goquery.Text function to extract text from a selection with more control than the sel.Text jquery-like method.

v1.12.0

Compare Source

Note that Go1.25 is now required (use goquery < 1.12.0 if you can't use go1.25+, see README for version details).

v1.11.0

Compare Source

Note that Go1.24 is now required (use goquery < 1.11.0 if you can't use go1.24+).

v1.10.3

Compare Source

Update dependencies and a small memory optimization.

aws/aws-sdk-go-v2 (github.com/aws/aws-sdk-go-v2)

v1.45.1

Compare Source

General Highlights

  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/aws-sdk-go-v2: v1.45.1
    • Bug Fix: Fix internal timeout gate to not depend on env opt-in.
  • github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager: v0.4.1
    • Bug Fix: Fix DownloadObject bug so parts can be read to correct offset regardless of parts sizes change
    • Bug Fix: Fix GetObject bug so object parts can be read to correct offset regardless of parts sizes change

v1.45.0

Compare Source

Module Highlights

  • github.com/aws/aws-sdk-go-v2/service/acm: v1.47.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/agentregistry: v1.3.0
    • Feature: AWS Agent Registry becomes Generally Available
  • github.com/aws/aws-sdk-go-v2/service/agentregistrycontrol: v1.3.0
    • Feature: AWS Agent Registry becomes Generally Available
  • github.com/aws/aws-sdk-go-v2/service/amp: v1.51.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/amplify: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/appflow: v1.57.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/apprunner: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/appstream: v1.67.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/athena: v1.63.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cleanrooms: v1.54.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudsearchdomain: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudtrail: v1.61.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codedeploy: v1.41.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cognitoidentity: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cognitoidentityprovider: v1.71.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/comprehend: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/configservice: v1.71.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/connect: v1.193.0
    • Feature: Added support for global routing on Amazon Connect Global Resiliency instances. New APIs GetCrossRegionRouting and UpdateCrossRegionRouting allow you to view and control cross-region contact routing between linked instances, so both Regions are active at all times.
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/connectcontactlens: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/connectparticipant: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/controltower: v1.34.2
    • Documentation: Updated the descriptions for the AWS Control Tower ListEnabledControls API parameters to make them more accurate and intuitive.
  • github.com/aws/aws-sdk-go-v2/service/customerprofiles: v1.68.0
    • Feature: This release introduces new APIs for segment membership events allowing segment definition membership events to be exported to a kinesis stream for downstream processing. Additionally, includes new calculated attribute statistic and 2 new segment dimension types.
  • github.com/aws/aws-sdk-go-v2/service/datasync: v1.64.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/devopsagent: v1.14.0
    • Feature: Adds support for Slack bidirectional communication configuration in AWS DevOps Agent agent spaces.
  • github.com/aws/aws-sdk-go-v2/service/dsql: v1.19.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ecrpublic: v1.44.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/emr: v1.67.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/glacier: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/grafana: v1.41.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/greengrass: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/greengrassv2: v1.48.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/internetmonitor: v1.32.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iot: v1.81.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/kafkaconnect: v1.36.0
    • Feature: Amazon MSK Connect now supports restarting newly created connectors via the asynchronous RestartConnector API. Restart all tasks or only failed tasks, while preserving configuration and committed offsets. This returns a connector operation ARN that you can track with DescribeConnectorOperation.
  • github.com/aws/aws-sdk-go-v2/service/kinesis: v1.50.0
    • Feature: Adds support for data delivery to Amazon S3 Tables (Apache Iceberg) and general purpose Amazon S3 buckets with new CreateChannel, UpdateChannel, DeleteChannel, DescribeChannel, and ListChannels APIs for Amazon Kinesis Data Streams.
  • github.com/aws/aws-sdk-go-v2/service/lexmodelsv2: v1.67.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/lightsail: v1.61.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/m2: v1.32.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/mailmanager: v1.24.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/managedblockchain: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/neptunegraph: v1.27.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/opensearchserverless: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/organizations: v1.57.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/partnercentralselling: v1.27.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/paymentcryptographydata: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/personalize: v1.53.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/pinpoint: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/pinpointsmsvoicev2: v1.36.0
    • Feature: AWS End User Messaging SMS now returns ConditionalBehavior on DescribeRegistrationFieldDefinitions, allowing you to programmatically discover which registration fields are required, optional, or disallowed based on the values of other fields in the same form.
  • github.com/aws/aws-sdk-go-v2/service/pipes: v1.29.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/quicksight: v1.127.0
    • Feature: This release adds support for managing apps in Amazon QuickSight with ListApps, SearchApps, DescribeApp, DescribeAppPermissions, UpdateAppPermissions, and DeleteApp
  • github.com/aws/aws-sdk-go-v2/service/route53resolver: v1.51.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/sagemaker: v1.271.0
    • Feature: Amazon SageMaker Batch Transform now supports G6e instances, powered by NVIDIA L40S Tensor Core GPUs. G6e instances are the most cost-efficient GPU instances for deploying generative AI models and the highest-performance GPU instances for spatial computing workloads.
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/schemas: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/serverlessapplicationrepository: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/servicequotas: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/sqs: v1.49.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/support: v1.37.0
    • Feature: AWS Support now allows up to 10 attachments (150 MB each) per case correspondence, up from 3 at 5 MB. Customers can share large diagnostic logs, heap dumps, and packet captures directly in cases to reduce back-and-forth and speed up resolution. Available in US East, US West, and Europe (Ireland).
  • github.com/aws/aws-sdk-go-v2/service/transcribe: v1.61.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/wellarchitected: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/workspaces: v1.77.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/workspacesinstances: v1.12.0
    • Feature: Amazon WorkSpaces Core managed instances now support nested virtualization. Customers can enable nested virtualization with supported instance types at launch via CpuOptions.NestedVirtualization in CreateWorkspaceInstance to run hypervisors and virtual machines inside their WorkSpaces Instance.

v1.44.0

Compare Source

Module Highlights

  • github.com/aws/aws-sdk-go-v2/service/acm: v1.47.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/agentregistry: v1.3.0
    • Feature: AWS Agent Registry becomes Generally Available
  • github.com/aws/aws-sdk-go-v2/service/agentregistrycontrol: v1.3.0
    • Feature: AWS Agent Registry becomes Generally Available
  • github.com/aws/aws-sdk-go-v2/service/amp: v1.51.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/amplify: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/appflow: v1.57.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/apprunner: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/appstream: v1.67.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/athena: v1.63.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cleanrooms: v1.54.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudsearchdomain: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudtrail: v1.61.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codedeploy: v1.41.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cognitoidentity: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cognitoidentityprovider: v1.71.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/comprehend: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/configservice: v1.71.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/connect: v1.193.0
    • Feature: Added support for global routing on Amazon Connect Global Resiliency instances. New APIs GetCrossRegionRouting and UpdateCrossRegionRouting allow you to view and control cross-region contact routing between linked instances, so both Regions are active at all times.
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/connectcontactlens: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/connectparticipant: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/controltower: v1.34.2
    • Documentation: Updated the descriptions for the AWS Control Tower ListEnabledControls API parameters to make them more accurate and intuitive.
  • github.com/aws/aws-sdk-go-v2/service/customerprofiles: v1.68.0
    • Feature: This release introduces new APIs for segment membership events allowing segment definition membership events to be exported to a kinesis stream for downstream processing. Additionally, includes new calculated attribute statistic and 2 new segment dimension types.
  • github.com/aws/aws-sdk-go-v2/service/datasync: v1.64.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/devopsagent: v1.14.0
    • Feature: Adds support for Slack bidirectional communication configuration in AWS DevOps Agent agent spaces.
  • github.com/aws/aws-sdk-go-v2/service/dsql: v1.19.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ecrpublic: v1.44.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/emr: v1.67.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/glacier: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/grafana: v1.41.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/greengrass: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/greengrassv2: v1.48.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/internetmonitor: v1.32.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iot: v1.81.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/kafkaconnect: v1.36.0
    • Feature: Amazon MSK Connect now supports restarting newly created connectors via the asynchronous RestartConnector API. Restart all tasks or only failed tasks, while preserving configuration and committed offsets. This returns a connector operation ARN that you can track with DescribeConnectorOperation.
  • github.com/aws/aws-sdk-go-v2/service/kinesis: v1.50.0
    • Feature: Adds support for data delivery to Amazon S3 Tables (Apache Iceberg) and general purpose Amazon S3 buckets with new CreateChannel, UpdateChannel, DeleteChannel, DescribeChannel, and ListChannels APIs for Amazon Kinesis Data Streams.
  • github.com/aws/aws-sdk-go-v2/service/lexmodelsv2: v1.67.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/lightsail: v1.61.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/m2: v1.32.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/mailmanager: v1.24.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/managedblockchain: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/neptunegraph: v1.27.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/opensearchserverless: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/organizations: v1.57.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/partnercentralselling: v1.27.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/paymentcryptographydata: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/personalize: v1.53.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/pinpoint: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/pinpointsmsvoicev2: v1.36.0
    • Feature: AWS End User Messaging SMS now returns ConditionalBehavior on DescribeRegistrationFieldDefinitions, allowing you to programmatically discover which registration fields are required, optional, or disallowed based on the values of other fields in the same form.
  • github.com/aws/aws-sdk-go-v2/service/pipes: v1.29.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/quicksight: v1.127.0
    • Feature: This release adds support for managing apps in Amazon QuickSight with ListApps, SearchApps, DescribeApp, DescribeAppPermissions, UpdateAppPermissions, and DeleteApp
  • github.com/aws/aws-sdk-go-v2/service/route53resolver: v1.51.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/sagemaker: v1.271.0
    • Feature: Amazon SageMaker Batch Transform now supports G6e instances, powered by NVIDIA L40S Tensor Core GPUs. G6e instances are the most cost-efficient GPU instances for deploying generative AI models and the highest-performance GPU instances for spatial computing workloads.
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/schemas: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/serverlessapplicationrepository: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/servicequotas: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/sqs: v1.49.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/support: v1.37.0
    • Feature: AWS Support now allows up to 10 attachments (150 MB each) per case correspondence, up from 3 at 5 MB. Customers can share large diagnostic logs, heap dumps, and packet captures directly in cases to reduce back-and-forth and speed up resolution. Available in US East, US West, and Europe (Ireland).
  • github.com/aws/aws-sdk-go-v2/service/transcribe: v1.61.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/wellarchitected: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/workspaces: v1.77.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/workspacesinstances: v1.12.0
    • Feature: Amazon WorkSpaces Core managed instances now support nested virtualization. Customers can enable nested virtualization with supported instance types at launch via CpuOptions.NestedVirtualization in CreateWorkspaceInstance to run hypervisors and virtual machines inside their WorkSpaces Instance.

v1.43.8

Compare Source

General Highlights

  • Dependency Update: Update to smithy-go v1.27.10.
  • Dependency Update: Updated to the latest SDK module versions

Module Highlights

  • github.com/aws/aws-sdk-go-v2: v1.43.8
    • Bug Fix: Make X-Amz-Checksum-Mode appear on query parameters on presigned URLs
  • github.com/aws/aws-sdk-go-v2/service/account: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/acmpca: v1.51.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/autoscaling: v1.73.0
    • Feature: Adds support for Distribution Segments in mixed instances policies, providing ordered prioritization across On-Demand Capacity Reservations, Capacity Blocks, interruptible Capacity Reservations, and On-Demand capacity.
  • github.com/aws/aws-sdk-go-v2/service/billingconductor: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudcontrol: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudhsmv2: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/cloudwatchevents: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codebuild: v1.73.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codegurureviewer: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/codepipeline: v1.50.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/dataexchange: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/deadline: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/detective: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/devopsagent: v1.11.0
    • Feature: Adds the UpdateApprovalAction API for resolving agent action approvals in AWS DevOps Agent agent spaces.
  • github.com/aws/aws-sdk-go-v2/service/directoryservice: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/drs: v1.44.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ec2: v1.323.0
    • Feature: Fleet feature to support Capacity Reservation Resource Groups with Amazon EC2 Capacity Blocks and interruptible Capacity Reservations
  • github.com/aws/aws-sdk-go-v2/service/eks: v1.93.0
    • Feature: This feature would give customers the ability to tune TerminatedPodGcThreshold configuration in an Amazon EKS cluster.
  • github.com/aws/aws-sdk-go-v2/service/emrcontainers: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/eventbridge: v1.49.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/evs: v1.14.0
    • Feature: EVS now supports i7i.metal-48xl EC2 bare metal instance type, delivering high random IOPS performance with real-time latency, ideal for IO intensive and latency-sensitive workloads such as transactional databases, real-time analytics, and AI ML pre-processing.
  • github.com/aws/aws-sdk-go-v2/service/frauddetector: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/fsx: v1.69.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/globalaccelerator: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iamtoolbox: v1.0.0
    • Release: New AWS service client module
    • Feature: AWS Identity and Access Management (IAM) announces access troubleshooter, helping you debug access denied errors faster. Supported error messages now include an identifier you can use to retrieve detailed evaluations of the policies considered and their results. Preview in US East (N. Virginia).
  • github.com/aws/aws-sdk-go-v2/service/inspector: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iot: v1.78.0
    • Feature: As part of this release, we are extending capability of AWS IoT Rules Engine to support IoT InfluxDB Action. The IoT InfluxDB action lets customers send messages from IoT sensors and applications to InfluxDB.
  • github.com/aws/aws-sdk-go-v2/service/iotsecuretunneling: v1.37.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/iottwinmaker: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ivs: v1.56.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/ivsrealtime: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/licensemanager: v1.42.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/marketplacecatalog: v1.46.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/marketplacemetering: v1.40.3
    • Documentation: Updated documentation to clarify duplicate-billing prevention and BatchMeterUsage retry guidance
  • github.com/aws/aws-sdk-go-v2/service/mediapackage: v1.43.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/mediapackagevod: v1.43.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/mediastore: v1.33.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/networkmanager: v1.45.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/outposts: v1.68.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/paymentcryptography: v1.34.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/pi: v1.40.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/qconnect: v1.35.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/resourceexplorer2: v1.28.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/servicecatalogappregistry: v1.39.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/servicediscovery: v1.44.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/shield: v1.38.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/signer: v1.36.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/storagegateway: v1.47.0
    • Feature: Enable schema-based (de)serialization for this service.
  • github.com/aws/aws-sdk-go-v2/service/swf: [v1.38.0](se

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 02:00 AM and 04:59 AM, Monday through Friday (* 2-4 * * 1-5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux red-hat-konflux Bot added approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. labels Jun 17, 2026
@red-hat-konflux

red-hat-konflux Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: downloading github.com/stretchr/testify v1.12.1
go: downloading google.golang.org/genai v1.70.0
go: downloading github.com/openshift/client-go v0.0.0-20260320040014-4b5fc2cdad98
go: downloading k8s.io/api v0.36.3
go: downloading github.com/aws/aws-sdk-go-v2 v1.45.1
go: downloading k8s.io/apimachinery v0.36.3
go: downloading github.com/aws/aws-sdk-go-v2/config v1.33.1
go: downloading github.com/aws/aws-sdk-go-v2/credentials v1.20.1
go: downloading k8s.io/client-go v0.36.3
go: downloading github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.4.1
go: downloading github.com/aws/aws-sdk-go-v2/service/cloudformation v1.78.1
go: downloading github.com/aws/aws-sdk-go-v2/service/ec2 v1.325.1
go: downloading github.com/aws/aws-sdk-go-v2/service/iam v1.61.1
go: downloading github.com/onsi/ginkgo/v2 v2.32.1
go: downloading github.com/aws/aws-sdk-go-v2/service/s3 v1.109.1
go: downloading github.com/openshift/api v0.0.0-20260318185450-1f2fa3f09f4e
go: downloading github.com/aws/smithy-go v1.28.1
go: downloading github.com/openshift/osde2e-common v0.0.0-20260514215146-b07512784467
go: downloading github.com/fsnotify/fsnotify v1.10.1
go: downloading github.com/spf13/afero v1.15.0
go: downloading github.com/spf13/viper v1.21.0
go: downloading golang.org/x/tools v0.48.0
go: downloading github.com/onsi/gomega v1.43.0
go: downloading k8s.io/utils v0.0.0-20260507154919-ff6756f316d2
go: downloading sigs.k8s.io/e2e-framework v0.7.0
go: downloading github.com/operator-framework/api v0.45.0
go: downloading github.com/operator-framework/operator-lifecycle-manager v0.46.0
go: downloading github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring v0.93.1
go: downloading github.com/prometheus-operator/prometheus-operator/pkg/client v0.93.1
go: downloading github.com/vmware-tanzu/velero v1.18.2
go: downloading k8s.io/apiextensions-apiserver v0.36.3
go: downloading github.com/prometheus/client_golang v1.24.1
go: downloading github.com/openshift-online/ocm-sdk-go v0.1.499
go: downloading golang.org/x/net v0.58.0
go: downloading github.com/hashicorp/hc-install v0.9.5
go: downloading github.com/hashicorp/terraform-exec v0.25.3
go: downloading github.com/PuerkitoBio/goquery v1.13.0
go: downloading sigs.k8s.io/controller-runtime v0.24.1
go: downloading cloud.google.com/go/kms v1.33.0
go: downloading github.com/openshift/cloud-credential-operator v0.0.0-20250326174647-d66761c09842
go: downloading google.golang.org/api v0.295.0
go: downloading github.com/gomarkdown/markdown v0.0.0-20260824154242-13c5cf49db8d
go: downloading github.com/hashicorp/go-version v1.9.0
go: downloading cloud.google.com/go/auth v0.23.2
go: downloading github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.19.1
go: downloading github.com/aws/aws-sdk-go-v2/service/signin v1.7.1
go: downloading github.com/aws/aws-sdk-go-v2/service/sso v1.35.1
go: downloading github.com/aws/aws-sdk-go-v2/service/ssooidc v1.40.1
go: downloading github.com/aws/aws-sdk-go-v2/service/sts v1.47.1
go: downloading github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.1
go: downloading github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19
go: downloading github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.1
go: downloading github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20
go: downloading github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.1
go: downloading github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.11.1
go: downloading github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.20.1
go: downloading k8s.io/kube-openapi v0.0.0-20260603220949-865597e52e25
go: downloading sigs.k8s.io/structured-merge-diff/v6 v6.4.0
go: downloading golang.org/x/text v0.41.0
go: downloading github.com/go-viper/mapstructure/v2 v2.5.0
go: downloading github.com/sagikazarmark/locafero v0.11.0
go: downloading github.com/spf13/cast v1.10.0
go: downloading k8s.io/streaming v0.36.3
go: downloading github.com/openshift-online/ocm-api-model/clientapi v0.0.453
go: downloading github.com/openshift-online/ocm-api-model/model v0.0.453
go: downloading github.com/hashicorp/terraform-json v0.28.0
go: downloading github.com/andybalholm/cascadia v1.3.4
go: downloading github.com/openshift/library-go v0.0.0-20260311094140-ac826d10cb40
go: downloading cloud.google.com/go/iam v1.12.0
go: downloading cloud.google.com/go/longrunning v1.2.0
go: downloading github.com/googleapis/gax-go/v2 v2.24.0
go: downloading google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d
go: downloading google.golang.org/grpc v1.83.2
go: downloading google.golang.org/protobuf v1.36.12
go: downloading google.golang.org/genproto/googleapis/api v0.0.0-20260715232425-e75dac1f907d
go: downloading go.yaml.in/yaml/v3 v3.0.5
go: downloading go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0
go: downloading github.com/google/gnostic-models v0.7.1
go: downloading github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.1
go: downloading github.com/fxamacker/cbor/v2 v2.9.2
go: downloading github.com/sourcegraph/conc v0.3.1-0.20240121214520-5f936abd7ae8
go: downloading github.com/pelletier/go-toml/v2 v2.2.4
go: downloading golang.org/x/mod v0.38.0
go: downloading github.com/ProtonMail/go-crypto v1.4.1
go: downloading github.com/zclconf/go-cty v1.18.1
go: downloading google.golang.org/genproto/googleapis/rpc v0.0.0-20260819154853-08b0e4226688
go: downloading github.com/googleapis/enterprise-certificate-proxy v0.3.20
go: downloading github.com/go-openapi/jsonreference v0.21.6
go: downloading github.com/go-openapi/swag v0.26.1
go: downloading golang.org/x/crypto v0.55.0
go: downloading k8s.io/component-base v0.36.3
go: downloading github.com/go-openapi/jsonpointer v0.23.1
go: downloading github.com/go-openapi/swag/cmdutils v0.26.1
go: downloading github.com/go-openapi/swag/conv v0.26.1
go: downloading github.com/go-openapi/swag/fileutils v0.26.1
go: downloading github.com/go-openapi/swag/jsonname v0.26.1
go: downloading github.com/go-openapi/swag/jsonutils v0.26.1
go: downloading github.com/go-openapi/swag/loading v0.26.1
go: downloading github.com/go-openapi/swag/mangling v0.26.1
go: downloading github.com/go-openapi/swag/netutils v0.26.1
go: downloading github.com/go-openapi/swag/stringutils v0.26.1
go: downloading github.com/go-openapi/swag/typeutils v0.26.1
go: downloading github.com/go-openapi/swag/yamlutils v0.26.1
go: downloading k8s.io/api v0.37.0
go: github.com/openshift/osde2e/pkg/common/helper imports
	github.com/vmware-tanzu/velero/pkg/generated/clientset/versioned: cannot find module providing package github.com/vmware-tanzu/velero/pkg/generated/clientset/versioned
go: github.com/openshift/osde2e/pkg/common/cluster/healthchecks imports
	github.com/openshift/osde2e-common/pkg/clients/openshift imports
	github.com/openshift/api imports
	k8s.io/api/autoscaling/v2beta1: cannot find module providing package k8s.io/api/autoscaling/v2beta1
go: github.com/openshift/osde2e/pkg/common/cluster/healthchecks imports
	github.com/openshift/osde2e-common/pkg/clients/openshift imports
	github.com/openshift/api imports
	k8s.io/api/autoscaling/v2beta2: cannot find module providing package k8s.io/api/autoscaling/v2beta2
go: github.com/openshift/osde2e/pkg/common/cluster/healthchecks imports
	github.com/openshift/osde2e-common/pkg/clients/openshift imports
	github.com/openshift/api imports
	k8s.io/api/scheduling/v1alpha1: cannot find module providing package k8s.io/api/scheduling/v1alpha1

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

There are test jobs defined for this repository which are not configured to run automatically. Comment /test ? to see a list of all defined jobs. Review these jobs and use /test <job> to manually trigger jobs most likely to be impacted by the proposed changes.Comment /pipeline required to trigger all required & necessary jobs.

@coderabbitai

coderabbitai Bot commented Jun 17, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: b4fb4f78-df54-49c0-a9cf-df20e969f002

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch konflux/mintmaker/main/gomod-dependencies

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from YiqinZhang and minlei98 June 17, 2026 02:05
@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 1d7f2d4 and 2 for PR HEAD b8569c5 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD 5487ab5 and 1 for PR HEAD b8569c5 in total

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@go.mod`:
- Line 59: The github.com/gomarkdown/markdown dependency is pinned to a
vulnerable version (v0.0.0-20260217112301-37c66b85d6ab) that is susceptible to
CVE-2026-40890 with a CVSS score of 7.5 due to an out-of-bounds read in
SmartypantsRenderer. Update the version of github.com/gomarkdown/markdown in the
go.mod file to a patched version such as v0.0.0-20260614204949-e08cff860f76 or
any later version that includes the fix committed on April 10, 2026.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: a0d29158-e7c8-45e3-826f-3322c44b02f7

📥 Commits

Reviewing files that changed from the base of the PR and between 1d7f2d4 and b8569c5.

📒 Files selected for processing (1)
  • go.mod

Comment thread go.mod Outdated

require (
github.com/golang-jwt/jwt/v4 v4.5.2
github.com/gomarkdown/markdown v0.0.0-20260217112301-37c66b85d6ab

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🌐 Web query:

GHSA-77fj-vx54-gvh7 gomarkdown markdown out-of-bounds read vulnerability details

💡 Result:

GHSA-77fj-vx54-gvh7, also tracked as CVE-2026-40890, is a security vulnerability in the gomarkdown/markdown Go library that causes an out-of-bounds read or a panic [1][2]. The vulnerability occurs specifically within the SmartypantsRenderer component [1][3]. When the library processes malformed input containing a '<' character that is not followed by a '>' character anywhere in the remaining text, the smartLeftAngle function performs an out-of-bounds slice operation [1]. This behavior can lead to a denial-of-service (DoS) condition if the application panics [1][4]. Technical details: - Affected Component: SmartypantsRenderer [1] - Vulnerability Type: Out-of-bounds Read (CWE-125) [1] - Impact: Denial of Service / Panic [1][4] - Fix: The issue was addressed in commit 759bbc3e32073c3bc4e25969c132fc520eda2778 [1][2]. Users of the library are advised to update their dependency to a version containing this patch to mitigate the risk [2].

Citations:


🏁 Script executed:

# Check if we can fetch information about the gomarkdown/markdown commit
# The pseudo-version indicates commit 37c66b85d6ab from Feb 17, 2026
# We need to verify if this includes the fix commit 759bbc3e32073c3bc4e25969c132fc520eda2778

# First, let's try to check if there's any git history or refs available
cd /tmp && git clone --depth 100 https://github.com/gomarkdown/markdown.git 2>&1 | head -20 || true

Repository: openshift/osde2e

Length of output: 149


🌐 Web query:

gomarkdown/markdown commit 759bbc3e32073c3bc4e25969c132fc520eda2778 GHSA-77fj-vx54-gvh7 fix merged when

💡 Result:

The commit 759bbc3e32073c3bc4e25969c132fc520eda2778 in the gomarkdown/markdown repository, which addresses the vulnerability identified as GHSA-77fj-vx54-gvh7 (CVE-2026-40890), was authored on April 10, 2026 [1]. This patch corrects an out-of-bounds read vulnerability in the SmartypantsRenderer [1][2]. Although the commit itself is dated April 10, 2026 [1], the associated security advisory (GHSA-77fj-vx54-gvh7) was published on April 13, 2026 [2]. The fix ensures that the library correctly handles malformed input containing a '<' character not followed by a '>' character, preventing potential service panics or out-of-bounds reads [3][2].

Citations:


🌐 Web query:

gomarkdown/markdown v0.0.0-20260217112301 release date vulnerability status

💡 Result:

The Go package github.com/gomarkdown/markdown version v0.0.0-20260217112301-37c66b85d6ab was released on February 17, 2026 [1][2]. Regarding its vulnerability status, this version is affected by CVE-2026-40890 (GHSA-77fj-vx54-gvh7) [3][4]. This vulnerability involves an out-of-bounds read or potential panic when using a SmartypantsRenderer to process malformed input containing a '<' character that is not followed by a '>' character [3][4]. The issue was officially documented and assigned a CVSS v3.1 base score of 7.5 (High) [3][4]. Users of this package are advised to upgrade to a version containing the fix, which is commit 759bbc3e32073c3bc4e25969c132fc520eda2778 [4]. Current registry data indicates that later versions, such as v0.0.0-20260614204949-e08cff860f76, are available [5].

Citations:


Update gomarkdown/markdown to patched version before merge.

The version v0.0.0-20260217112301-37c66b85d6ab (February 17, 2026) is vulnerable to CVE-2026-40890 / GHSA-77fj-vx54-gvh7 (out-of-bounds read in SmartypantsRenderer, CVSS 7.5). The fix was committed April 10, 2026. Upgrade to a patched version such as v0.0.0-20260614204949-e08cff860f76 or later.

🧰 Tools
🪛 OSV Scanner (2.3.8)

[HIGH] 59-59: github.com/gomarkdown/markdown 0.0.0-20260217112301-37c66b85d6ab: Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

(GHSA-77fj-vx54-gvh7)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` at line 59, The github.com/gomarkdown/markdown dependency is pinned
to a vulnerable version (v0.0.0-20260217112301-37c66b85d6ab) that is susceptible
to CVE-2026-40890 with a CVSS score of 7.5 due to an out-of-bounds read in
SmartypantsRenderer. Update the version of github.com/gomarkdown/markdown in the
go.mod file to a patched version such as v0.0.0-20260614204949-e08cff860f76 or
any later version that includes the fix committed on April 10, 2026.

Source: Linters/SAST tools

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/retest-required

Remaining retests: 0 against base HEAD c7ae4e9 and 0 for PR HEAD b8569c5 in total

@openshift-merge-bot

Copy link
Copy Markdown
Contributor

/hold

Revision b8569c5 was retested 3 times: holding

@openshift-ci openshift-ci Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Jun 18, 2026
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch from b8569c5 to bd3263d Compare June 25, 2026 02:29
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jun 25, 2026
@openshift-ci

openshift-ci Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

New changes are detected. LGTM label has been removed.

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch 2 times, most recently from e392220 to bd81291 Compare July 20, 2026 03:03
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch from bd81291 to 9b5cbc0 Compare July 28, 2026 04:41
@openshift-ci

openshift-ci Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: red-hat-konflux[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch 2 times, most recently from 21dd467 to ad982d3 Compare August 18, 2026 02:07
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch 3 times, most recently from 71b5306 to 37b8851 Compare August 26, 2026 02:45
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch from 37b8851 to 2062c2a Compare August 28, 2026 02:33
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/gomod-dependencies branch from 2062c2a to 390ad5f Compare September 1, 2026 02:34
@openshift-ci

openshift-ci Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

@red-hat-konflux[bot]: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/code-quality-checks 390ad5f link true /test code-quality-checks

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants