Skip to content

chore(deps): bump go.pinniped.dev from 0.23.0 to 0.42.0 - #592

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go.pinniped.dev-0.42.0
Closed

chore(deps): bump go.pinniped.dev from 0.23.0 to 0.42.0#592
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/go.pinniped.dev-0.42.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Nov 17, 2025

Copy link
Copy Markdown
Contributor

Bumps go.pinniped.dev from 0.23.0 to 0.42.0.

Release notes

Sourced from go.pinniped.dev's releases.

v0.42.0

Release v0.42.0

Release Image

Image Registry
ghcr.io/vmware/pinniped/pinniped-server:v0.42.0 GitHub Container Registry
docker.io/getpinniped/pinniped-server:v0.42.0 DockerHub

These images can also be referenced by their digest: sha256:7f901305b659e9ed3c5b32ab273141430202f2b5fa697616574753a96c845537.

Changes

This release adds some more advanced configuration options for the Concierge's kube cert agent Deployment.

Minor Changes

  • Adds a new configuration option which can be used in the Concierge's ConfigMap to change the kube cert agent Deployment's strategy type. See PR description for details. (#2690)
  • Adds a new configuration option which can be used in the Concierge's ConfigMap to change the kube cert agent Deployment's pod template runAsUser and runAsGroup. See PR description for details. (#2683)
  • Updates the Kubernetes libraries to v0.33.5, Golang to v1.25.3, and updates all other project dependencies. (#2676, #2590)

Diffs

A complete list of changes (15 commits, 32 changed files with 648 additions and 205 deletions) can be found here.

v0.41.0

Release v0.41.0

Release Image

Image Registry
ghcr.io/vmware/pinniped/pinniped-server:v0.41.0 GitHub Container Registry
docker.io/getpinniped/pinniped-server:v0.41.0 DockerHub

These images can also be referenced by their digest: sha256:7f8f5822e762396fe964ec4737bb02c3370be1eb7edd087079c80f9b3caaa061.

Changes

This release enables the use of ADFS with the Pinniped Supervisor and upgrades dependencies.

Major Changes

  • The Pinniped Supervisor supports OIDC-compliant providers, along with several other identity provider types. However, ADFS does not correctly implement the OIDC specification, so it was not previously supported. This release provides a workaround so that the Pinniped Supervisor can be configured to use ADFS as an OIDCIdentityProvider. See PR #2580's description for more documentation.

Minor Changes

  • Updates the Kubernetes libraries to v0.33.4, Golang to v1.25.0, and updates all other project dependencies. (#2588, #2577, #2573, #2536, #2531, #2529)

... (truncated)

Commits
  • 2cfa610 Merge pull request #2690 from vmware/configurable_kube_cert_agent_strategy_type
  • fa5f754 upgrade dep github.com/google/go-github to v75
  • 718b970 update direct deps
  • 9be6bb0 allow the kube cert agent deployment's strategy type to be configured
  • 6e87caa Merge pull request #2683 from vmware/jtc/configurable-kubecertagent-usergroup
  • 270594c Allow users to specify the RunAsUser and RunAsGroup for the kube-cert-agent c...
  • b1b4bba Merge pull request #2676 from vmware/jtc/bump-libs-to-v0.33.5
  • 9aa3f74 Update CEL errors for k8s 1.35+
  • 7f14ac7 Run codegen with new k8s lib versions
  • f001df3 Bump go versions in Dockerfiles
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [go.pinniped.dev](https://github.com/vmware/pinniped) from 0.23.0 to 0.42.0.
- [Release notes](https://github.com/vmware/pinniped/releases)
- [Commits](vmware/pinniped@v0.23.0...v0.42.0)

---
updated-dependencies:
- dependency-name: go.pinniped.dev
  dependency-version: 0.42.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependencies go Pull requests that update go code labels Nov 17, 2025
@github-actions github-actions Bot added chore Chore provider Provider needs-review Needs Review labels Nov 17, 2025
@tenthirtyam

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Nov 17, 2025

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@tenthirtyam

Copy link
Copy Markdown
Contributor

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Nov 17, 2025

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@tenthirtyam

Copy link
Copy Markdown
Contributor

@dependabot close

@dependabot @github

dependabot Bot commented on behalf of github Nov 17, 2025

Copy link
Copy Markdown
Contributor Author

Beginning January 27, 2026, Dependabot will no longer support the @dependabot close command. Please use GitHub's native pull request controls instead. Please see the changelog announcement for additional details.

@dependabot dependabot Bot closed this Nov 17, 2025
@dependabot @github

dependabot Bot commented on behalf of github Nov 17, 2025

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/go_modules/go.pinniped.dev-0.42.0 branch November 17, 2025 18:30
@tenthirtyam tenthirtyam removed the needs-review Needs Review label Dec 1, 2025
@github-actions

github-actions Bot commented Jan 1, 2026

Copy link
Copy Markdown

I'm going to lock this pull request because it has been closed for 30 days. This helps our maintainers find and focus on the active issues.

If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Jan 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

chore Chore dependencies Dependencies go Pull requests that update go code provider Provider

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant