Skip to content

chore(deps): update github actions - #267

Open
ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

ferrlabs-renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@ferrlabs-renovate

@ferrlabs-renovate ferrlabs-renovate Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker/setup-buildx-action (changelog) action digest 37fe631 → f87e599
docker/setup-qemu-action (changelog) action digest 1f40c72 → 9901266
github/codeql-action (changelog) action digest b96794f → 2892aa5
kindest/node uses-with minor v1.32.2 → v1.37.0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@ferrlabs-renovate
ferrlabs-renovate Bot enabled auto-merge (squash) September 21, 2026 00:06

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three changes: digest bumps for docker/setup-qemu-action and docker/setup-buildx-action (both stay on v4, no tag change), and kindest/node v1.32.2 → v1.37.0 in .github/workflows/e2e.yml.

The node image bump is worth calling out as a positive: go.mod pins k8s.io/api, k8s.io/client-go, k8s.io/apimachinery all at v0.37.0, so the e2e cluster was previously running 5 minors behind the client library version skew the operator is built against. This bump actually removes an existing version mismatch rather than introducing one.

No API usage in this repo is affected by either docker action's digest-only update. CI is still finishing at review time (kind smoke test, CI/Test, CI/Lint, opengrep in progress), but everything that has completed so far is green and nothing points at these three lines.

Nothing blocking.

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/github-actions branch from 6751cf3 to 32f258f Compare September 21, 2026 14:00
@github-actions

Copy link
Copy Markdown

SonarQube — aucune nouvelle issue

Comparaison entre le projet bac à sable de cette PR et la branche par défaut : SonarQube Community n'analyse pas les PR, ce delta est calculé côté CI. Détail

@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/github-actions branch from 32f258f to d8f6383 Compare September 24, 2026 12:01
@ferrlabs-renovate
ferrlabs-renovate Bot force-pushed the renovate/github-actions branch from d8f6383 to ad6cd14 Compare September 27, 2026 12:14

@ferrfleet ferrfleet Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Follow-up on my earlier approval at d8f6383. Two things changed since then.

CI has now finished, and kind smoke test fails on ad6cd14. The cause is the kindest/node bump, detail inline. That reverses the "nothing blocking" I gave when the job was still running: the version-skew argument for the bump still holds, it just needs the kind version bumped alongside it.

The branch also gained a third digest bump, github/codeql-action/upload-sarif b96794f → 2892aa5, which was not in what I reviewed. That digest is the v4.38.2 release commit on the v4 line, the # v4 comment stays accurate, and scorecard.yml passes no inputs that changed. No concern there. The two docker digests resolve to v4.4.0 (qemu) and v4.4.1 (buildx), both still under the v4 tag.

Automerge is on for this PR, so the failing required check is the only thing holding it.

Comment thread .github/workflows/e2e.yml
cluster_name: ferrvault-e2e
# Keep the node image pinned so a kind release doesn't break us.
node_image: kindest/node:v1.32.2
node_image: kindest/node:v1.37.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: this is what breaks kind smoke test on the current head. The job failed at step 5, the helm/kind-action step itself, with everything after it skipped.

The pinned action (ef37e7f) defaults to version: v0.31.0, and kind v0.31.0 only ships node images up to kindest/node:v1.35.0. v1.37.0 first appears in kind v0.33.0. The image tag does exist on Docker Hub, so the failure is the kind binary refusing the image, not a bad tag.

The action's default kubectl_version at this pin is also v1.35.0, two minors behind a 1.37 control plane and outside the supported ±1 kubectl skew, so pin both explicitly rather than relying on the action's defaults. That also fits the intent of the comment on the line above.

Suggested change
node_image: kindest/node:v1.37.0
node_image: kindest/node:v1.37.0
# kind v0.31.0 (this action pin's default) tops out at node image
# v1.35.0; v1.37.0 needs kind v0.33.0. Pin kubectl too, so it stays
# within one minor of the control plane.
version: v0.33.0
kubectl_version: v1.37.0

Alternative if you prefer fewer explicit inputs: bump the helm/kind-action digest to its latest release, whose defaults are already kind v0.33.0 and kubectl v1.37.0. I'd still take the explicit pins, since they fail loudly on the next node image bump instead of depending on whatever the action happens to default to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants