chore(deps): dependabot merge train 2026-09-01 - #768
Merged
ArangoGutierrez merged 6 commits intoSep 1, 2026
Merged
Conversation
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.8 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.24.0 to 0.24.2. - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@e22c389...3ad7283) --- updated-dependencies: - dependency-name: anchore/sbom-action dependency-version: 0.24.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.8 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.8 to 4.37.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@db488dd...cdf488f) --- updated-dependencies: - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Bumps the k8sio group with 4 updates: [k8s.io/apiextensions-apiserver](https://github.com/kubernetes/apiextensions-apiserver), [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery), [k8s.io/client-go](https://github.com/kubernetes/client-go) and [k8s.io/kubelet](https://github.com/kubernetes/kubelet). Updates `k8s.io/apiextensions-apiserver` from 0.36.3 to 0.37.0 - [Release notes](https://github.com/kubernetes/apiextensions-apiserver/releases) - [Commits](kubernetes/apiextensions-apiserver@v0.36.3...v0.37.0) Updates `k8s.io/apimachinery` from 0.36.3 to 0.37.0 - [Commits](kubernetes/apimachinery@v0.36.3...v0.37.0) Updates `k8s.io/client-go` from 0.36.3 to 0.37.0 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.36.3...v0.37.0) Updates `k8s.io/kubelet` from 0.36.3 to 0.37.0 - [Commits](kubernetes/kubelet@v0.36.3...v0.37.0) --- updated-dependencies: - dependency-name: k8s.io/apiextensions-apiserver dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: k8sio - dependency-name: k8s.io/apimachinery dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: k8sio - dependency-name: k8s.io/client-go dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: k8sio - dependency-name: k8s.io/kubelet dependency-version: 0.37.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: k8sio ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.83.1 to 1.83.2. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](grpc/grpc-go@v1.83.1...v1.83.2) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.83.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
ArangoGutierrez
marked this pull request as ready for review
September 1, 2026 11:08
|
Too many files changed for review (985 files, 100 file limit). |
ArangoGutierrez
enabled auto-merge (squash)
September 1, 2026 12:25
ArangoGutierrez
disabled auto-merge
September 1, 2026 13:17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Six Dependabot PRs were open against
main. Merging them individually costs afull CI matrix each and a rebase round every time they collide.
Two of them could not go green on their own. Dependabot split one atomic change
into separate PRs for
github/codeql-action/init(#766) andgithub/codeql-action/analyze(#764), but both steps run in the same job and theaction refuses to run mismatched versions:
That is why #764 shows a red
code-scanningcheck. Bumping both together, asthis PR does, is the only way either one passes.
Approach
Cherry-picked all six commits onto
upstream/main(b6fefaf3), preservingdependabot[bot]authorship, the original messages, and theupdated-dependenciestrailers. Every commit is GPG-signed and carries bothDependabot's and my DCO sign-off. No merge commits.
Superseded: #764, #765, #766, #767, #754, #755.
Dependency changes
github/codeql-action(init, analyze, upload-sarif)anchore/sbom-actionk8s.io/{api,apiextensions-apiserver,apimachinery,client-go,kubelet}google.golang.org/grpcThe grpc bump is a security fix: it rejects requests missing both
:authorityand
Hostheaders (grpc/grpc-go#9365).Conflict resolution
#755 (k8sio group) and #754 (grpc) were both cut from an older
mainand bothmove the same four indirect modules to different versions. Resolved as a union,
keeping the newest of each:
golang.org/x/modgolang.org/x/netgolang.org/x/textgolang.org/x/toolsBecause both PRs vendor those four modules, git's line-level merge produced
files mixing source from two different upstream releases (
manifest.go,deps.go,transport_wrap.goall auto-merged). Rather than trust that, thevendored trees for
x/mod,x/net,x/textandx/toolswere taken wholefrom #754 and confirmed byte-identical to it. The vendored package sets are the
same on both sides, so nothing k8s 0.37.0 needs was dropped.
k8s.io/*stays at 0.37.0 from #755;grpctakes 1.83.2 from #754.Testing done
Run against the final tree, Go 1.26.6 on darwin/arm64:
go build ./...cleango vet ./...cleango test -race -covermode=atomic $(go list ./... | grep -v vendor)40 packages ok, 0 failuresgolangci-lint run ./...0 issuesgo test -tags integration ./internal/ib/sysfs/... ./internal/pcisysfs/... ./shims/libpcisysfs/...okgovulncheck ./...no vulnerabilitiesgo.mod and vendor/modules.txt agree on all ten bumped modules. That consistency
is enforced by
go builditself: reverting a single version line invendor/modules.txt turns the build red with
inconsistent vendoring, which wasconfirmed before relying on it.
make modules-checkcould not be validated locally. It fails the same way onpristine
upstream/main(module cache resolution errors on packages that doexist), so it is a local environment limitation, not a property of this branch.
CI covers it on Linux.
Breaking changes
None. No first-party source changed; the diff is workflow pins, go.mod/go.sum,
and vendored dependencies.