Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
197 commits
Select commit Hold shift + click to select a range
3220f18
build(deps): bump github/codeql-action from 3.30.3 to 3.30.5 (#7232)
dependabot[bot] Oct 2, 2025
1d0b1cc
build(deps): bump actions/cache from 4.2.4 to 4.3.0 (#7233)
dependabot[bot] Oct 2, 2025
7d6a240
build(deps): bump google.golang.org/protobuf from 1.36.9 to 1.36.10 (…
dependabot[bot] Oct 6, 2025
2014178
build(deps): bump github.com/onsi/ginkgo/v2 from 2.25.3 to 2.26.0 (#7…
dependabot[bot] Oct 6, 2025
7f6308f
build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#7237)
dependabot[bot] Oct 6, 2025
4072ba1
build(deps): bump actions/stale from 10.0.0 to 10.1.0 (#7239)
dependabot[bot] Oct 6, 2025
50a93f8
build(deps): bump github/codeql-action from 3.30.5 to 3.30.6 (#7241)
dependabot[bot] Oct 6, 2025
27752f6
build(deps): bump docker/login-action from 3.5.0 to 3.6.0 (#7242)
dependabot[bot] Oct 6, 2025
e217872
build(deps): bump github.com/envoyproxy/go-control-plane/envoy (#7243)
dependabot[bot] Oct 13, 2025
6478a0f
build(deps): bump sigs.k8s.io/controller-runtime from 0.22.1 to 0.22.…
dependabot[bot] Oct 13, 2025
fe7cef0
build(deps): bump google.golang.org/grpc from 1.75.1 to 1.76.0 (#7254)
dependabot[bot] Oct 13, 2025
2e3cb7e
build(deps): bump github/codeql-action from 3.30.6 to 4.30.8 (#7255)
dependabot[bot] Oct 13, 2025
4823d2b
build(deps): bump golang.org/x/oauth2 from 0.31.0 to 0.32.0 (#7256)
dependabot[bot] Oct 13, 2025
c1241c3
Bump golang to 1.25.2 (#7260)
tsaarni Oct 14, 2025
31ba99f
build(deps): bump golang.org/x/net from 0.44.0 to 0.46.0 (#7263)
dependabot[bot] Oct 20, 2025
f417e61
build(deps): bump github/codeql-action from 4.30.8 to 4.30.9 (#7262)
dependabot[bot] Oct 22, 2025
0c2776a
build(deps): bump github.com/prometheus/common from 0.66.1 to 0.67.1 …
dependabot[bot] Oct 22, 2025
e91b8ed
build(deps): bump github.com/onsi/ginkgo/v2 from 2.26.0 to 2.27.1 (#7…
dependabot[bot] Oct 27, 2025
923f06f
build(deps): bump the artifact-actions group with 2 updates (#7273)
dependabot[bot] Oct 27, 2025
ea05075
build(deps): bump github/codeql-action from 4.30.9 to 4.31.0 (#7274)
dependabot[bot] Oct 27, 2025
2cf0e18
Fix docs build with Hugo v0.128+ by replacing deprecated resources.To…
shivamx64 Oct 29, 2025
65e3caa
build(deps): bump github.com/onsi/ginkgo/v2 from 2.27.1 to 2.27.2 (#7…
dependabot[bot] Nov 5, 2025
c9a17b2
build(deps): bump github.com/prometheus/common from 0.67.1 to 0.67.2 …
dependabot[bot] Nov 5, 2025
e6d1fb4
build(deps): bump github/codeql-action from 4.31.0 to 4.31.2 (#7286)
dependabot[bot] Nov 5, 2025
4519f55
build(deps): bump github.com/cert-manager/cert-manager (#7285)
dependabot[bot] Nov 5, 2025
d211a54
Remove deprecated preserveUnknownFields field from CRDs (#7283)
shivamx64 Nov 6, 2025
0c79cd1
Docs: fix helm installation (#7290)
amedinagar Nov 7, 2025
1de7aa9
Bump Envoy to v1.35.6 (#7279)
tsaarni Nov 13, 2025
8c20c44
build(deps): bump codespell-project/actions-codespell from 2.1 to 2.2…
dependabot[bot] Nov 13, 2025
3cfa2e7
build(deps): bump golangci/golangci-lint-action from 8.0.0 to 9.0.0 (…
dependabot[bot] Nov 13, 2025
10ca287
build(deps): bump sigs.k8s.io/kustomize/kyaml from 0.20.1 to 0.21.0 (…
dependabot[bot] Nov 13, 2025
c3b5c9a
Hack: semi-automate Go and Envoy updates (#7278)
tsaarni Nov 13, 2025
b0f4b32
build(deps): bump github/codeql-action from 4.31.2 to 4.31.3 (#7301)
dependabot[bot] Nov 17, 2025
4b82aa4
build(deps): bump golang.org/x/oauth2 from 0.32.0 to 0.33.0 (#7298)
dependabot[bot] Nov 17, 2025
30397f1
build(deps): bump sigs.k8s.io/controller-runtime from 0.22.3 to 0.22.…
dependabot[bot] Nov 17, 2025
266fa3f
build(deps): bump the k8s-dependencies group with 4 updates (#7302)
dependabot[bot] Nov 17, 2025
6821e9b
docs: add method matching example for HTTPProxy using Envoy pseudo-he…
shivamx64 Nov 24, 2025
24c6a57
build(deps): bump google.golang.org/grpc from 1.76.0 to 1.77.0 (#7313)
dependabot[bot] Nov 24, 2025
180ff16
docs: update outdated reference to bitnami (#7318)
consideRatio Nov 25, 2025
84e88d9
build(deps): bump golang.org/x/net (#7323)
dependabot[bot] Dec 1, 2025
114ef7c
Remove old blog post example yamls (#7320)
tsaarni Dec 3, 2025
e6133d6
build(deps): bump actions/stale from 10.1.0 to 10.1.1 (#7327)
dependabot[bot] Dec 8, 2025
506e160
build(deps): bump golang.org/x/crypto from 0.43.0 to 0.45.0 (#7308)
dependabot[bot] Dec 8, 2025
af997d4
build(deps): bump github.com/envoyproxy/go-control-plane/envoy (#7311)
dependabot[bot] Dec 8, 2025
f54d55b
build(deps): bump github/codeql-action from 4.31.3 to 4.31.7 (#7328)
dependabot[bot] Dec 8, 2025
d58b39c
build(deps): bump golangci/golangci-lint-action from 9.0.0 to 9.2.0 (…
dependabot[bot] Dec 8, 2025
b8f8f75
build(deps): bump actions/checkout from 5.0.0 to 6.0.1 (#7330)
dependabot[bot] Dec 8, 2025
443b452
build(deps): bump github.com/prometheus/common from 0.67.2 to 0.67.4 …
dependabot[bot] Dec 8, 2025
f43025c
build(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#7315)
dependabot[bot] Dec 8, 2025
26c45f3
build(deps): bump github.com/envoyproxy/go-control-plane (#7297)
dependabot[bot] Dec 8, 2025
b41c25b
build(deps): bump the artifact-actions group with 2 updates (#7335)
dependabot[bot] Dec 15, 2025
e647245
build(deps): bump the k8s-dependencies group with 4 updates (#7336)
dependabot[bot] Dec 15, 2025
94fe41e
build(deps): bump actions/cache from 4.3.0 to 5.0.1 (#7337)
dependabot[bot] Dec 16, 2025
cadfa9f
build(deps): bump codecov/codecov-action from 5.5.1 to 5.5.2 (#7338)
dependabot[bot] Dec 16, 2025
51db6b5
build(deps): bump golang.org/x/net from 0.47.0 to 0.48.0 (#7339)
dependabot[bot] Dec 16, 2025
add89fc
build(deps): bump google.golang.org/protobuf from 1.36.10 to 1.36.11 …
dependabot[bot] Dec 16, 2025
ddeeec3
build(deps): bump github.com/onsi/gomega from 1.38.2 to 1.38.3 (#7341)
dependabot[bot] Dec 16, 2025
bd2ec1d
build(deps): bump github/codeql-action from 4.31.7 to 4.31.8 (#7342)
dependabot[bot] Dec 17, 2025
92726bb
Bump Envoy to v1.35.8 (#7331)
tsaarni Dec 19, 2025
5f1ac18
Bump to go 1.25.5 (#7280)
tsaarni Dec 19, 2025
724ca5e
build(deps): bump github.com/onsi/ginkgo/v2 from 2.27.2 to 2.27.3 (#7…
dependabot[bot] Dec 22, 2025
c33f131
build(deps): bump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#…
dependabot[bot] Dec 22, 2025
86b8148
build(deps): bump github/codeql-action from 4.31.8 to 4.31.9 (#7354)
dependabot[bot] Dec 22, 2025
d6b8609
build(deps): bump github.com/cert-manager/cert-manager (#7355)
dependabot[bot] Dec 22, 2025
9477aaf
Doc updates for December 2025 patch releases: 1.33.1, 1.32.2, 1.31.3 …
sunjayBhatia Dec 22, 2025
9871b8f
build(deps): bump golang.org/x/oauth2 from 0.33.0 to 0.34.0 (#7363)
dependabot[bot] Dec 29, 2025
f8e96b6
build(deps): bump google.golang.org/grpc from 1.77.0 to 1.78.0 (#7364)
dependabot[bot] Dec 29, 2025
760fc07
build(deps): bump github.com/prometheus/common from 0.67.4 to 0.67.5 …
dependabot[bot] Jan 12, 2026
00812a4
build(deps): bump github.com/onsi/ginkgo/v2 from 2.27.3 to 2.27.4 (#7…
dependabot[bot] Jan 12, 2026
5078e1e
build(deps): bump actions/setup-go from 6.1.0 to 6.2.0 (#7381)
dependabot[bot] Jan 21, 2026
c3bf372
build(deps): bump github/codeql-action from 4.31.9 to 4.31.10 (#7380)
dependabot[bot] Jan 21, 2026
0b558cd
build(deps): bump actions/cache from 5.0.1 to 5.0.2 (#7378)
dependabot[bot] Jan 21, 2026
75df8ee
build(deps): bump golang.org/x/net from 0.48.0 to 0.49.0 (#7376)
dependabot[bot] Jan 21, 2026
07a2134
build(deps): bump github.com/onsi/gomega from 1.38.3 to 1.39.0 (#7379)
dependabot[bot] Jan 21, 2026
6886e3b
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (#7387)
dependabot[bot] Jan 27, 2026
9d9cb51
build(deps): bump github/codeql-action from 4.31.10 to 4.31.11 (#7390)
dependabot[bot] Jan 27, 2026
2083462
build(deps): bump github.com/onsi/ginkgo/v2 from 2.27.4 to 2.27.5 (#7…
dependabot[bot] Jan 27, 2026
8a51282
Add configurable client_sampling and random_sampling for tracing (#7373)
WUMUXIAN Jan 30, 2026
5aee9a7
build(deps): bump github.com/cert-manager/cert-manager (#7398)
dependabot[bot] Feb 3, 2026
045dd82
build(deps): bump actions/cache from 5.0.2 to 5.0.3 (#7397)
dependabot[bot] Feb 3, 2026
f9d03e7
build(deps): bump github/codeql-action from 4.31.11 to 4.32.0 (#7395)
dependabot[bot] Feb 3, 2026
dd59655
build(deps): bump github.com/onsi/ginkgo/v2 from 2.27.5 to 2.28.1 (#7…
dependabot[bot] Feb 3, 2026
d368385
build(deps): bump docker/login-action from 3.6.0 to 3.7.0 (#7393)
dependabot[bot] Feb 3, 2026
a826acd
provisioner: Increase CPU limit for shutdown-manager (#7382)
tsaarni Feb 4, 2026
3fcf197
Bump to go1.25.7 (#7400)
tsaarni Feb 6, 2026
c28b68e
Post-process HTTPProxy CRD schema to remove error as a required field…
tsaarni Feb 8, 2026
0eabcf8
build(deps): bump github.com/sirupsen/logrus from 1.9.3 to 1.9.4 (#7413)
dependabot[bot] Feb 9, 2026
1595fc4
build(deps): bump github/codeql-action from 4.32.0 to 4.32.2 (#7415)
dependabot[bot] Feb 9, 2026
86c8fdd
build(deps): bump github/codeql-action from 4.32.2 to 4.32.3 (#7422)
dependabot[bot] Feb 16, 2026
689efe2
build(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0 (#7…
dependabot[bot] Feb 17, 2026
4e5231c
build(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.1 (#7421)
dependabot[bot] Feb 17, 2026
7e63afa
Update Go code to new available syntax (#7426)
pims Feb 17, 2026
f55ae9b
Bump to go 1.26.0 (#7416)
tsaarni Feb 17, 2026
6aa394a
Doc updates for Feb 2026 patch releases: 1.33.2, 1.32.3, 1.31.4 (#7427)
tsaarni Feb 20, 2026
223001b
build(deps): bump github/codeql-action from 4.32.3 to 4.32.4 (#7430)
dependabot[bot] Feb 23, 2026
8794e11
build(deps): bump aquasecurity/trivy-action from 0.34.0 to 0.34.1 (#7…
dependabot[bot] Feb 23, 2026
a6e6acd
build(deps): bump actions/stale from 10.1.1 to 10.2.0 (#7428)
dependabot[bot] Feb 23, 2026
86667d2
Add codeql scan for github actions (#7445)
tsaarni Mar 2, 2026
f579288
build(deps): bump the artifact-actions group with 2 updates (#7436)
dependabot[bot] Mar 4, 2026
03e17e4
build(deps): bump actions/setup-go from 6.2.0 to 6.3.0 (#7437)
dependabot[bot] Mar 4, 2026
39a1a71
build(deps): bump aquasecurity/trivy-action from 0.34.1 to 0.35.0 (#7…
dependabot[bot] Mar 10, 2026
fdfeece
build(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0 (#7…
dependabot[bot] Mar 10, 2026
8de9ab6
build(deps): bump github/codeql-action from 4.32.4 to 4.32.6 (#7450)
dependabot[bot] Mar 11, 2026
3893011
Change CodeQL action name back to CodeQL-Build: (#7458)
tsaarni Mar 11, 2026
442cef0
build(deps): bump docker/login-action from 3.7.0 to 4.0.0 (#7448)
dependabot[bot] Mar 11, 2026
5bee8ea
main: Bump to Envoy v1.35.9 (#7454)
tsaarni Mar 12, 2026
2b6b176
build(deps): bump the k8s-dependencies group across 1 directory with …
dependabot[bot] Mar 12, 2026
eeae7fd
build(deps): bump github.com/envoyproxy/go-control-plane/envoy (#7429)
dependabot[bot] Mar 15, 2026
107bf83
Update Envoy from 1.35 to 1.37 release track (v1.37.1) (#7459)
tsaarni Mar 15, 2026
26d94aa
Update Kubernetes version for E2E tests to 1.35 (#7417)
tsaarni Mar 16, 2026
6d0b27e
build(deps): bump mheap/github-action-required-labels (#7466)
dependabot[bot] Mar 16, 2026
2722a69
build(deps): bump actions/download-artifact (#7461)
dependabot[bot] Mar 16, 2026
0dd7378
build(deps): bump google.golang.org/grpc from 1.79.1 to 1.79.2 (#7465)
dependabot[bot] Mar 16, 2026
180d62f
build(deps): bump golang.org/x/oauth2 from 0.34.0 to 0.36.0 (#7463)
dependabot[bot] Mar 16, 2026
626c7de
build(deps): bump google.golang.org/grpc from 1.79.2 to 1.79.3 (#7469)
dependabot[bot] Mar 19, 2026
23ba0a6
build(deps): bump sigs.k8s.io/controller-runtime from 0.22.4 to 0.23.…
dependabot[bot] Mar 19, 2026
f7cd812
Remove envoy stats hostport from example manifests (#7476)
tsaarni Mar 21, 2026
ebf407e
build(deps): bump the k8s-dependencies group with 4 updates (#7480)
dependabot[bot] Mar 23, 2026
5743f34
build(deps): bump github.com/onsi/gomega from 1.39.0 to 1.39.1 (#7486)
dependabot[bot] Mar 23, 2026
27fad0e
build(deps): bump github.com/vektra/mockery/v2 from 2.53.5 to 2.53.6 …
dependabot[bot] Mar 23, 2026
cb165bb
build(deps): bump github/codeql-action from 4.32.6 to 4.34.1 (#7479)
dependabot[bot] Mar 23, 2026
8f18e9f
Doc updates for Mar 2026 patch releases: 1.33.3, 1.32.4, 1.31.5 (#7491)
tsaarni Mar 23, 2026
f0bf184
build(deps): bump codecov/codecov-action from 5.5.2 to 5.5.3 (#7482)
dependabot[bot] Mar 24, 2026
76f6a3d
build(deps): bump actions/cache from 5.0.3 to 5.0.4 (#7483)
dependabot[bot] Mar 24, 2026
ac8eae1
build(deps): bump sigs.k8s.io/controller-tools from 0.19.0 to 0.20.1 …
dependabot[bot] Mar 24, 2026
762beec
build(deps): bump github.com/tsaarni/certyaml from 0.10.0 to 0.11.0 (…
dependabot[bot] Mar 24, 2026
41203bd
build(deps): bump sigs.k8s.io/kustomize/kyaml from 0.21.0 to 0.21.1 (…
dependabot[bot] Mar 24, 2026
1c13b68
build(deps): bump golang.org/x/net from 0.50.0 to 0.52.0 (#7495)
dependabot[bot] Mar 24, 2026
fb7cd75
Remove auto-request-review github action (#7493)
tsaarni Mar 24, 2026
3c7cb32
Remove welcome new contributor workflow (#7498)
sunjayBhatia Mar 25, 2026
7a834f4
build(deps): bump codecov/codecov-action from 5.5.3 to 6.0.0 (#7505)
dependabot[bot] Mar 30, 2026
23eb3de
build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 (#7504)
dependabot[bot] Mar 30, 2026
2b0b71b
build(deps): bump golang.org/x/image from 0.25.0 to 0.38.0 (#7506)
dependabot[bot] Apr 1, 2026
1009c6d
build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#7509)
dependabot[bot] Apr 6, 2026
e505630
build(deps): bump google.golang.org/grpc from 1.79.3 to 1.80.0 (#7510)
dependabot[bot] Apr 6, 2026
e168219
build(deps): bump actions/upload-artifact in the artifact-actions gro…
dependabot[bot] Apr 13, 2026
72a819d
build(deps): bump golang.org/x/net from 0.52.0 to 0.53.0 (#7513)
dependabot[bot] Apr 13, 2026
ba11857
build(deps): bump docker/login-action from 4.0.0 to 4.1.0 (#7508)
dependabot[bot] Apr 13, 2026
ee7ebc8
Doc updates for Apr 2026 patch releases: v1.33.4 v1.32.5 v1.31.6 (#7520)
tsaarni Apr 20, 2026
ff1974b
Cherry pick CVE-2026-41246 for main branch (#7521)
tsaarni Apr 21, 2026
bfeb9ab
main: Bump to Envoy v1.37.2 (#7522)
tsaarni Apr 21, 2026
a94de15
main: Bump to go 1.26.2 (#7523)
tsaarni Apr 21, 2026
f63cf95
build(deps): bump actions/cache from 5.0.4 to 5.0.5 (#7515)
dependabot[bot] Apr 22, 2026
c487f80
build(deps): bump the k8s-dependencies group with 4 updates (#7516)
dependabot[bot] Apr 22, 2026
aa535b5
Update website footer to align with CNCF guidelines (#7528)
tsaarni Apr 24, 2026
8630fe4
build(deps): bump aquasecurity/trivy-action from 0.35.0 to 0.36.0 (#7…
dependabot[bot] May 5, 2026
dae3914
build(deps): bump gonum.org/v1/plot from 0.16.0 to 0.17.0 (#7532)
dependabot[bot] May 5, 2026
5bc69e6
build(deps): bump github.com/onsi/gomega from 1.39.1 to 1.40.0 (#7534)
dependabot[bot] May 5, 2026
6e160b6
build(deps): bump github/codeql-action from 4.35.1 to 4.35.3 (#7536)
dependabot[bot] May 5, 2026
0ac7589
build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.1 to 2.28.3 (#7…
dependabot[bot] May 5, 2026
5d4d954
build(deps): bump google.golang.org/grpc from 1.80.0 to 1.81.0 (#7544)
dependabot[bot] May 15, 2026
34860d2
build(deps): bump github/codeql-action from 4.35.3 to 4.35.4 (#7539)
dependabot[bot] May 15, 2026
52113f4
build(deps): bump golang.org/x/net from 0.53.0 to 0.54.0 (#7542)
dependabot[bot] May 15, 2026
20d1f4a
build(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.…
dependabot[bot] May 15, 2026
cff107c
build(deps): bump github/codeql-action from 4.35.4 to 4.35.5 (#7547)
dependabot[bot] May 19, 2026
5bfb865
build(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1 (#7545)
dependabot[bot] May 19, 2026
502a2a1
build(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (…
dependabot[bot] May 25, 2026
a1c22f4
build(deps): bump actions/stale from 10.2.0 to 10.3.0 (#7554)
dependabot[bot] May 25, 2026
e7c2e54
build(deps): bump docker/login-action from 4.1.0 to 4.2.0 (#7555)
dependabot[bot] May 25, 2026
c704929
build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0 (#7557)
dependabot[bot] May 25, 2026
4feb0e9
build(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 (#7558)
dependabot[bot] May 25, 2026
5bf4cbb
build(deps): bump github.com/onsi/gomega from 1.40.0 to 1.41.0 (#7559)
dependabot[bot] May 25, 2026
ac372d9
build(deps): bump github/codeql-action from 4.35.5 to 4.36.0 (#7552)
dependabot[bot] May 25, 2026
895e3a2
build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.3 to 2.29.0 (#7…
dependabot[bot] May 26, 2026
b590174
Bumps k8s.io deps from v0.35.4 to v0.36.0 and sigs.k8s.io/controller-…
tsaarni May 27, 2026
d6f27be
release-main: Bump to go 1.26.3 (#7564)
tsaarni May 27, 2026
1769661
build(deps): bump sigs.k8s.io/controller-tools from 0.20.1 to 0.21.0 …
dependabot[bot] May 27, 2026
a50af0e
internal/envoy: always set NumRetries so numRetries=-1 actually disab…
SAY-5 May 27, 2026
c06f8e1
release-main: Bump to Envoy v1.38.0 (#7566)
tsaarni May 27, 2026
451aa91
HTTPProxy: reject fallback certificate combined with JWT verification
tsaarni May 27, 2026
883e92b
Doc updates for May 2026 patch release: v1.33.5 (#7569)
tsaarni May 28, 2026
b05d08f
Drop support for three release tracks (#7567)
tsaarni May 29, 2026
67f6e24
Enable TLS Fingerprinting configuration (JA3/JA4) (#7372)
WUMUXIAN May 30, 2026
baa6a93
build(deps): bump codecov/codecov-action from 6.0.0 to 6.0.1 (#7573)
dependabot[bot] Jun 1, 2026
0f2f23a
Update Kubernetes version for E2E tests to 1.36 (#7575)
tsaarni Jun 3, 2026
289dc15
release-main: Bump to go 1.26.4 (#7576)
tsaarni Jun 3, 2026
77c3f77
Add support for HTTP External Authorization Services (#7418)
therealak12 Jun 4, 2026
b91bd23
main: Bump to Envoy v1.38.1 (#7579)
tsaarni Jun 5, 2026
b39eba5
build(deps): bump github.com/prometheus/common from 0.67.5 to 0.68.1 …
dependabot[bot] Jun 5, 2026
b812dc9
build(deps): bump codecov/codecov-action from 6.0.1 to 7.0.0 (#7581)
dependabot[bot] Jun 8, 2026
c970a28
build(deps): bump github/codeql-action from 4.36.0 to 4.36.2 (#7582)
dependabot[bot] Jun 8, 2026
b656cfd
implement localJWKS documented in JWT verification design (#7502)
nissy-dev Jun 11, 2026
4f87115
release-main: Bump to Envoy v1.38.2 (#7583)
tsaarni Jun 11, 2026
ceac622
test(e2e): replace cert-manager with local certificate generation (#7…
shivamx64 Jun 12, 2026
4d027c5
Add e2e tests for JWT verification (#7586)
tsaarni Jun 12, 2026
3670db6
Use certyaml to issue certs in e2e suite (#7587)
tsaarni Jun 12, 2026
a172ab8
build(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#7580)
dependabot[bot] Jun 12, 2026
190faf0
Use go tool directive with separate tools/ module (#7589)
tsaarni Jun 12, 2026
26a3730
docs: clarify HTTPProxy match precedence and query-parameter case sen…
alliasgher Jun 12, 2026
5ee3645
build(deps): bump golang.org/x/net from 0.55.0 to 0.56.0 (#7593)
dependabot[bot] Jun 12, 2026
a13d379
build(deps): bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#7…
dependabot[bot] Jun 12, 2026
34d2ab1
Configure dependabot cooldown to delay updates (#7591)
tsaarni Jun 13, 2026
da87188
docs: fix wrong env var for --contour-cafile in configuration (#7600)
s3onghyun Jun 18, 2026
635b531
sync to da87188
Jun 22, 2026
4153673
fix gofumpt formatting
izturn Jun 22, 2026
9943b56
send image to release
izturn Jun 22, 2026
5dff037
revert to release-ci
izturn Jun 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
93 changes: 19 additions & 74 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,9 @@ updates:
schedule:
interval: "weekly"
day: "sunday"
cooldown:
default-days: 3
semver-major-days: 15
labels:
- area/dependency
- release-note/none-required
Expand All @@ -18,89 +21,25 @@ updates:
patterns:
- "k8s.io/*"
- target-branch: main
package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "sunday"
labels:
- area/tooling
- release-note/none-required
groups:
artifact-actions:
patterns:
- "actions/upload-artifact"
- "actions/download-artifact"

# release branch N targets
- target-branch: release-1.33
package-ecosystem: "gomod"
directory: "/"
schedule:
interval: "weekly"
day: "sunday"
ignore:
- dependency-name: "*"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
labels:
- area/dependency
- release-note/none-required
groups:
k8s-dependencies:
patterns:
- "k8s.io/*"
- target-branch: release-1.33
package-ecosystem: "github-actions"
directory: "/"
directory: "/tools"
schedule:
interval: "weekly"
day: "sunday"
ignore:
- dependency-name: "*"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
cooldown:
default-days: 3
semver-major-days: 15
labels:
- area/tooling
- release-note/none-required
groups:
artifact-actions:
patterns:
- "actions/upload-artifact"
- "actions/download-artifact"

# release branch N-1 targets
- target-branch: release-1.32
package-ecosystem: "gomod"
directory: "/"
schedule:
interval: "weekly"
day: "sunday"
ignore:
- dependency-name: "*"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
labels:
- area/dependency
- release-note/none-required
groups:
k8s-dependencies:
patterns:
- "k8s.io/*"
- target-branch: release-1.32
- target-branch: main
package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "sunday"
ignore:
- dependency-name: "*"
update-types:
- "version-update:semver-major"
- "version-update:semver-minor"
cooldown:
default-days: 3
labels:
- area/tooling
- release-note/none-required
Expand All @@ -110,13 +49,15 @@ updates:
- "actions/upload-artifact"
- "actions/download-artifact"

# release branch N-2 targets
- target-branch: release-1.31
# release branch targets
- target-branch: release-1.33
package-ecosystem: "gomod"
directory: "/"
schedule:
interval: "weekly"
day: "sunday"
cooldown:
default-days: 3
ignore:
- dependency-name: "*"
update-types:
Expand All @@ -129,12 +70,14 @@ updates:
k8s-dependencies:
patterns:
- "k8s.io/*"
- target-branch: release-1.31
- target-branch: release-1.33
package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "sunday"
cooldown:
default-days: 3
ignore:
- dependency-name: "*"
update-types:
Expand All @@ -148,3 +91,5 @@ updates:
patterns:
- "actions/upload-artifact"
- "actions/download-artifact"


7 changes: 0 additions & 7 deletions .github/reviewers.yaml

This file was deleted.

14 changes: 7 additions & 7 deletions .github/workflows/build_daily.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -12,16 +12,16 @@ permissions:

env:
GOPROXY: https://proxy.golang.org/
GO_VERSION: 1.25.1
GO_VERSION: 1.26.4

jobs:
e2e-envoy-deployment:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# * Module download cache
# * Build cache (Linux)
Expand All @@ -31,7 +31,7 @@ jobs:
key: ${{ runner.os }}-${{ github.job }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-${{ github.job }}-go-
- uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: false
Expand All @@ -48,10 +48,10 @@ jobs:
e2e-ipv6:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# * Module download cache
# * Build cache (Linux)
Expand All @@ -61,7 +61,7 @@ jobs:
key: ${{ runner.os }}-${{ github.job }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-${{ github.job }}-go-
- uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: false
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/build_main.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,15 +14,15 @@ jobs:
permissions:
packages: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
with:
version: latest
- name: Log in to GHCR
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand Down
16 changes: 8 additions & 8 deletions .github/workflows/build_tag.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -18,23 +18,23 @@ permissions:

env:
GOPROXY: https://proxy.golang.org/
GO_VERSION: 1.25.1
GO_VERSION: 1.26.4

jobs:
build:
runs-on: ubuntu-latest
permissions:
packages: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
with:
version: latest
- name: Log in to GHCR
uses: docker/login-action@184bdaa0721073962dff0199f1fb9940f07167d1 # v3.5.0
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: ghcr.io
username: ${{ github.actor }}
Expand All @@ -49,10 +49,10 @@ jobs:
runs-on: ubuntu-latest
needs: [build]
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# * Module download cache
# * Build cache (Linux)
Expand All @@ -62,7 +62,7 @@ jobs:
key: ${{ runner.os }}-${{ github.job }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-${{ github.job }}-go-
- uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: false
Expand All @@ -77,7 +77,7 @@ jobs:
export CONTOUR_E2E_IMAGE="ghcr.io/projectcontour/contour:$(git describe --tags)"
make setup-kind-cluster run-gateway-conformance cleanup-kind
- name: Upload gateway conformance report
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: gateway-conformance-report
path: gateway-conformance-report/projectcontour-contour-*.yaml
37 changes: 30 additions & 7 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,20 +12,24 @@ on:
permissions:
contents: read

concurrency:
group: codeql-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

env:
GOPROXY: https://proxy.golang.org/
GO_VERSION: 1.25.1
GO_VERSION: 1.26.4

jobs:
CodeQL-Build:
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# * Module download cache
# * Build cache (Linux)
Expand All @@ -35,17 +39,36 @@ jobs:
key: ${{ runner.os }}-${{ github.job }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-${{ github.job }}-go-
- uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ env.GO_VERSION }}
cache: false
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.29.5
with:
languages: go
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
- name: Autobuild
uses: github/codeql-action/autobuild@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
uses: github/codeql-action/autobuild@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.29.5
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@192325c86100d080feab897ff886c34abd4c83a3 # v3.29.5
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.29.5
with:
category: /language:go

CodeQL-for-Actions:
runs-on: ubuntu-latest
permissions:
security-events: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- name: Initialize CodeQL
uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.29.5
with:
languages: actions
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e # v3.29.5
with:
category: /language:actions
12 changes: 6 additions & 6 deletions .github/workflows/label_check.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,17 +23,17 @@ jobs:
name: Check release-note label set
runs-on: ubuntu-latest
steps:
- uses: mheap/github-action-required-labels@8afbe8ae6ab7647d0c9f0cfa7c2f939650d22509 # v5.5
- uses: mheap/github-action-required-labels@0ac283b4e65c1fb28ce6079dea5546ceca98ccbe # v5.5
with:
mode: minimum
count: 1
labels: "release-note/major, release-note/minor, release-note/small, release-note/docs, release-note/infra, release-note/deprecation, release-note/none-required"
- uses: mheap/github-action-required-labels@8afbe8ae6ab7647d0c9f0cfa7c2f939650d22509 # v5.5
- uses: mheap/github-action-required-labels@0ac283b4e65c1fb28ce6079dea5546ceca98ccbe # v5.5
with:
mode: maximum
count: 1
labels: "release-note/major, release-note/minor, release-note/small, release-note/docs, release-note/infra, release-note/none-required"
- uses: mheap/github-action-required-labels@8afbe8ae6ab7647d0c9f0cfa7c2f939650d22509 # v5.5
- uses: mheap/github-action-required-labels@0ac283b4e65c1fb28ce6079dea5546ceca98ccbe # v5.5
with:
mode: maximum
count: 1
Expand All @@ -43,10 +43,10 @@ jobs:
needs: [check-label]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
persist-credentials: false
- uses: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809 # v4.2.4
- uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5
with:
# * Module download cache
# * Build cache (Linux)
Expand All @@ -56,7 +56,7 @@ jobs:
key: ${{ runner.os }}-${{ github.job }}-go-${{ hashFiles('**/go.sum') }}
restore-keys: |
${{ runner.os }}-${{ github.job }}-go-
- uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: 'stable'
cache: false
Expand Down
Loading
Loading