Skip to content

chore(deps): update go indirect dependencies - #75

Closed
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/go-indirect-dependencies
Closed

chore(deps): update go indirect dependencies#75
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/go-indirect-dependencies

Conversation

@red-hat-konflux

@red-hat-konflux red-hat-konflux Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
github.com/Azure/go-ansiterm indirect digest d185dfcfaa5f7b age confidence
github.com/Masterminds/squirrel indirect minor v1.1.0v1.5.4 age confidence
github.com/bxcodec/faker/v3 indirect minor v3.2.0v3.8.1 age confidence
github.com/cenkalti/backoff/v4 indirect minor v4.2.1v4.3.0 age confidence
github.com/docker/distribution indirect patch v2.8.1+incompatiblev2.8.3+incompatible age confidence
github.com/docker/go-connections indirect minor v0.6.0v0.8.1 age confidence
github.com/fatih/color indirect minor v1.18.0v1.19.0 age confidence
github.com/felixge/httpsnoop indirect minor v1.0.4v1.1.0 age confidence
github.com/getkin/kin-openapi indirect minor v0.135.0v0.146.0 v0.147.0 age confidence
github.com/go-logr/logr indirect patch v1.4.3v1.4.4 age confidence
github.com/go-ole/go-ole indirect minor v1.2.6v1.3.0 age confidence
github.com/go-openapi/jsonpointer indirect minor v0.21.0v0.24.0 age confidence
github.com/go-openapi/jsonpointer indirect minor v0.23.1v0.24.0 age confidence
github.com/go-openapi/jsonreference indirect patch v0.21.5v0.21.6 age confidence
github.com/go-openapi/swag indirect minor v0.23.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/cmdutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/conv indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/fileutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/jsonname indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/jsonutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/loading indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/mangling indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/netutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/stringutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/typeutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/go-openapi/swag/yamlutils indirect minor v0.26.0v0.28.0 v0.29.1 (+1) age confidence
github.com/gorilla/handlers indirect minor v1.4.2v1.5.2 age confidence
github.com/grpc-ecosystem/grpc-gateway/v2 indirect minor v2.29.0v2.30.0 age confidence
github.com/inconshreveable/mousetrap indirect minor v1.0.0v1.1.0 age confidence
github.com/jackc/pgx/v5 indirect minor v5.6.0v5.10.0 age confidence
github.com/kaptinlin/jsonpointer indirect patch v0.4.27v0.4.28 age confidence
github.com/kaptinlin/jsonschema indirect patch v0.9.3v0.9.8 age confidence
github.com/klauspost/compress indirect minor v1.18.0v1.19.2 age confidence
github.com/knadh/koanf/maps indirect patch v0.1.2v0.1.3 age confidence
github.com/knadh/koanf/parsers/json indirect patch v1.0.0v1.0.1 age confidence
github.com/knadh/koanf/parsers/toml/v2 indirect patch v2.2.1v2.2.2 age confidence
github.com/knadh/koanf/parsers/yaml indirect patch v1.1.0v1.1.1 age confidence
github.com/knadh/koanf/providers/fs indirect patch v1.0.0v1.0.1 age confidence
github.com/knadh/koanf/providers/rawbytes indirect patch v1.0.0v1.0.1 age confidence
github.com/knadh/koanf/v2 indirect patch v2.3.5v2.3.6 age confidence
github.com/lib/pq indirect minor v1.10.9v1.12.3 age confidence
github.com/lucasb-eyer/go-colorful indirect patch v1.4.0v1.4.1 age confidence
github.com/lufia/plan9stats indirect digest 39d0f17341c2f0 age confidence
github.com/magiconair/properties indirect minor v1.8.10v1.18.11 age confidence
github.com/mailru/easyjson indirect minor v0.7.7v0.9.2 age confidence
github.com/mattn/go-colorable indirect patch v0.1.13v0.1.15 age confidence
github.com/mattn/go-colorable indirect patch v0.1.14v0.1.15 age confidence
github.com/mattn/go-isatty indirect patch v0.0.22v0.0.24 age confidence
github.com/mattn/go-isatty indirect patch v0.0.20v0.0.24 age confidence
github.com/mattn/go-runewidth indirect patch v0.0.24v0.0.27 v0.0.28 age confidence
github.com/moby/go-archive indirect minor v0.1.0v0.3.3 age confidence
github.com/moby/patternmatcher indirect patch v0.6.0v0.6.1 age confidence
github.com/moby/sys/sequential indirect minor v0.6.0v0.7.0 age confidence
github.com/moby/sys/user indirect patch v0.4.0v0.4.1 age confidence
github.com/moby/term indirect patch v0.5.0v0.5.2 age confidence
github.com/morikuni/aec indirect minor v1.0.0v1.1.0 age confidence
github.com/oasdiff/yaml indirect minor v0.0.9v0.1.1 age confidence
github.com/oasdiff/yaml3 indirect patch v0.0.9v0.0.14 age confidence
github.com/power-devops/perfstat indirect digest 5aafc228845660 age confidence
github.com/prometheus/client_golang indirect minor v1.16.0v1.24.1 age confidence
github.com/prometheus/client_model indirect minor v0.3.0v0.6.2 age confidence
github.com/prometheus/common indirect minor v0.42.0v0.70.1 age confidence
github.com/prometheus/procfs indirect minor v0.10.1v0.21.1 age confidence
github.com/shirou/gopsutil/v3 indirect minor v3.23.12v3.24.5 age confidence
github.com/shoenig/go-m1cpu indirect minor v0.1.6v0.2.2 age confidence
github.com/sirupsen/logrus indirect patch v1.9.3v1.9.4 v1.10.1 (+1) age confidence
github.com/spf13/cobra indirect patch v0.0.5v0.0.7 age confidence
github.com/testcontainers/testcontainers-go indirect minor v0.33.0v0.44.0 age confidence
github.com/testcontainers/testcontainers-go/modules/postgres indirect minor v0.33.0v0.44.0 age confidence
github.com/tklauser/go-sysconf indirect minor v0.3.12v0.4.0 age confidence
github.com/tklauser/numcpus indirect minor v0.6.1v0.12.0 age confidence
github.com/woodsbury/decimal128 indirect minor v1.3.0v1.4.0 v1.4.1 age confidence
go.opentelemetry.io/otel/exporters/otlp/otlptrace indirect minor v1.44.0v1.45.0 age confidence
go.yaml.in/yaml/v3 indirect patch v3.0.4v3.0.5 age confidence
golang.org/x/mod indirect minor v0.37.0v0.38.0 v0.40.0 (+1) age confidence
golang.org/x/sync indirect minor v0.21.0v0.22.0 age confidence
golang.org/x/sys indirect minor v0.46.0v0.47.0 age confidence
golang.org/x/sys indirect minor v0.29.0v0.47.0 age confidence
golang.org/x/term indirect minor v0.44.0v0.45.0 age confidence
golang.org/x/text indirect minor v0.38.0v0.40.0 v0.41.0 age confidence
gorm.io/driver/postgres indirect patch v1.6.0v1.6.2 age confidence
k8s.io/utils indirect digest 28399d8cf1189d age confidence
sigs.k8s.io/structured-merge-diff/v6 indirect patch v6.4.0v6.4.2 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

Masterminds/squirrel (github.com/Masterminds/squirrel)

v1.5.4

Compare Source

What's Changed

New Contributors

Full Changelog: Masterminds/squirrel@v1.5.3...v1.5.4

v1.5.3

Compare Source

v1.5.2: Fix placeholder generation for And/Or

Compare Source

What's Changed

v1.5.1

Compare Source

What's Changed

New Contributors

Full Changelog: Masterminds/squirrel@v1.5.0...v1.5.1

v1.5.0

Compare Source

  • Add InnerJoin and CrossJoin methods
  • Fix nested select statements in Update.Set values

v1.4.0

Compare Source

Test fix and StatementBuilder.Where

v1.3.0

Compare Source

v1.2.0

Compare Source

bxcodec/faker (github.com/bxcodec/faker/v3)

v3.8.1: Deprecating v3 module

Compare Source

Full Changelog: bxcodec/faker@v3.8.0...v3.8.1

v3.8.0

Compare Source

What's Changed

New Contributors

Full Changelog: bxcodec/faker@v3.7.0...v3.8.0

v3.7.0

Compare Source

What's Changed

New Contributors

Full Changelog: bxcodec/faker@v3.6.0...v3.7.0

v3.6.0

Compare Source

Features
Chores

v3.5.0

Compare Source

Features
Fixes

v3.4.0

Compare Source

Features
Fixes

v3.3.1

Compare Source

Fixes
Chores

v3.3.0

Compare Source

Features
Chores
cenkalti/backoff (github.com/cenkalti/backoff/v4)

v4.3.0

Compare Source

docker/distribution (github.com/docker/distribution)

v2.8.3+incompatible

Compare Source

v2.8.2+incompatible

Compare Source

docker/go-connections (github.com/docker/go-connections)

v0.8.1

Compare Source

v0.8.0

Compare Source

v0.7.0

Compare Source

fatih/color (github.com/fatih/color)

v1.19.0

Compare Source

What's Changed

New Contributors

Full Changelog: fatih/color@v1.18.0...v1.19.0

felixge/httpsnoop (github.com/felixge/httpsnoop)

v1.1.0

Compare Source

getkin/kin-openapi (github.com/getkin/kin-openapi)

v0.146.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.145.0...v0.146.0

v0.145.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.144.0...v0.145.0

v0.144.0

Compare Source

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.143.0...v0.144.0

v0.143.0

Compare Source

What's Changed

New Contributors

Full Changelog: getkin/kin-openapi@v0.142.0...v0.143.0

v0.142.0

Compare Source

What's Changed

Full Changelog: getkin/kin-openapi@v0.141.0...v0.142.0

v0.141.0

[Compare Source]

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • Between 12:00 AM and 07:59 AM, only on Monday (* 0-7 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux

red-hat-konflux Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: components/api-server/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 10 additional dependencies were updated

Details:

Package Change
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.49.0 -> v0.70.0
go.opentelemetry.io/otel v1.44.0 -> v1.45.0
go.opentelemetry.io/otel/metric v1.44.0 -> v1.45.0
go.opentelemetry.io/otel/sdk v1.44.0 -> v1.45.0
go.opentelemetry.io/otel/sdk/metric v1.44.0 -> v1.45.0
go.opentelemetry.io/otel/trace v1.44.0 -> v1.45.0
google.golang.org/grpc v1.82.1 -> v1.83.0
gorm.io/gorm v1.31.1 -> v1.31.2
google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a -> v0.0.0-20260803160001-6ac0973c030d
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a -> v0.0.0-20260803160001-6ac0973c030d
File name: components/control-plane/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated

Details:

Package Change
google.golang.org/grpc v1.82.1 -> v1.83.0
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a -> v0.0.0-20260803160001-6ac0973c030d
File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.26.4 -> 1.26.5
File name: scripts/cli-generator/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.24.0 -> 1.25.0
File name: scripts/openapi-ir/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.24.0 -> 1.25.0
File name: scripts/sdk-generator/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.24.0 -> 1.25.0

@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/go-indirect-dependencies branch from 3928b0f to 94a47cc Compare August 17, 2026 05:28
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux
red-hat-konflux Bot force-pushed the konflux/mintmaker/main/go-indirect-dependencies branch from 94a47cc to 2ff746e Compare August 24, 2026 05:11
@coderabbitai

coderabbitai Bot commented Aug 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: fda8c0b4-be3c-4781-8088-568e33d50187

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@jsell-rh

jsell-rh commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Amber review

Status: Complete

Verdict

COMMENT — low-risk automated dependency bump, no HyperShell convention violations found. This PR only touches go.mod/go.sum across the Go modules; the changes are internally consistent (each new version has matching h1:/go.mod go.sum entries) and the one indirect→direct reclassification is legitimate. A couple of minor cross-module/version-hygiene items are worth confirming, and it must not merge until CI (build, vet, test, test-integration, lint) is green, since no Go toolchain is available to validate locally.

Hi, Amber here. This is a Konflux/mintmaker chore(deps) PR bumping Go module dependencies across api-server, control-plane, cli, and the scripts/* generator modules. I reviewed it as a dependency change: correctness of the module graph, direct/indirect classification, version consistency across modules, and supply-chain sanity. All bumped packages are well-known upstream deps; nothing suspicious was introduced.

What I verified

  • go.sum integrity: spot-checked the new pins (prometheus/client_golang v1.24.1, go.opentelemetry.io/otel v1.45.0, the protobuf pseudo-version) — each has both h1: and /go.mod hash lines. Consistent.
  • indirect→direct reclassification is correct: github.com/prometheus/client_golang moved into the direct require block in components/api-server/go.mod. That matches the real direct import in components/api-server/plugins/gateways/metrics.go:7, so go mod tidy did the right thing. Not a concern.
  • No go/toolchain directive changes, no code changes, no manifest/image changes.

Findings (all Minor)

  1. [Minor] PR title says "indirect" but the change also bumps direct deps. Besides indirect deps, this bumps direct requires (google.golang.org/grpc 1.82.1→1.83.0, gorm.io/gorm 1.31.1→1.31.2, OTel core 1.44.0→1.45.0) and promotes prometheus/client_golang and (in control-plane) google.golang.org/protobuf to direct. The title is slightly inaccurate; harmless but worth noting so reviewers don't assume it's indirect-only.

  2. [Minor] Mixed OpenTelemetry module versions in components/api-server/go.mod. Core/metric/trace/sdk are at v1.45.0 and otelhttp at v0.70.0, but the OTLP gRPC exporters (otlpmetricgrpc, otlptracegrpc) remain at v1.44.0. OTel exporters generally track the core release; MVS will resolve upward, but please confirm CI actually compiles the exporter code paths against otel v1.45.0 before merge. Confidence: Medium.

  3. [Minor] control-plane pins google.golang.org/protobuf to an unreleased pseudo-version (v1.36.12-0.20260120151049-f2248ac996af) while api-server stays on the released v1.36.11. Depending on an untagged commit is unusual for a mintmaker bump and creates cross-module drift. Prefer a released tag for reproducibility unless a specific fix requires the pseudo-version. Confidence: Medium.

Cross-PR coordination

I listed and compared all other open PRs in openshift-online/hypershell. Only two touch the same dependency files:

No material conflict. These overlaps are ordinary go.mod/go.sum edits with distinct goals; they do not represent competing designs, duplicate solutions, or incompatible assumptions with #75. The only coordination need is routine: whichever of #75/#182/#194 merges second on a shared module will need a go mod tidy/go mod verify re-run to reconcile go.sum. That is normal maintenance, not a design decision. #207 (feat: reconcile-to-request trace correlation) uses OTel APIs but does not modify any go.mod, so it inherits whatever OTel version lands and does not compete with the bump here. All other open PRs (UI, docs/specs, e2e, kind/dev, container-image bump #73) touch disjoint files.

Full open PR list reviewed: #216, #214, #212, #211, #210, #209, #208, #207, #206, #201, #200, #194, #189, #188, #185, #182, #179, #151, #150, #148, #135, #109, #73.

Findings Summary (ordered by severity, highest first)

  1. [Minor] PR title says "indirect" but direct deps are also bumped/reclassified — Commit/PR hygiene (go.mod L12, L18, L25)
  2. [Minor] Mixed OTel versions: core/metric at v1.45.0, OTLP exporters left at v1.44.0 — Dependency consistency (components/api-server/go.mod L19–L21)
  3. [Minor] control-plane pins protobuf to an unreleased pseudo-version while api-server uses a release — Dependency consistency/reproducibility (components/control-plane/go.mod L8)

Convention Checklist

Convention Result
Conventional commit message Pass
go.sum hashes present & consistent for new pins Pass
indirect/direct classification matches actual imports Pass
Image references consistent across stack N/A (no image/manifest changes)
Build/tests validated Deferred to CI (no Go toolchain available locally)

Rollback: this is a self-contained dependency bump — reverting the merge commit fully restores the prior module graph.

@jsell-rh jsell-rh left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

COMMENT — low-risk automated dependency bump, no HyperShell convention violations found. This PR only touches go.mod/go.sum across the Go modules; the changes are internally consistent (each new version has matching h1:/go.mod go.sum entries) and the one indirect→direct reclassification is legitimate. A couple of minor cross-module/version-hygiene items are worth confirming, and it must not merge until CI (build, vet, test, test-integration, lint) is green, since no Go toolchain is available to validate locally.

Hi, Amber here. This is a Konflux/mintmaker chore(deps) PR bumping Go module dependencies across api-server, control-plane, cli, and the scripts/* generator modules. I reviewed it as a dependency change: correctness of the module graph, direct/indirect classification, version consistency across modules, and supply-chain sanity. All bumped packages are well-known upstream deps; nothing suspicious was introduced.

What I verified

  • go.sum integrity: spot-checked the new pins (prometheus/client_golang v1.24.1, go.opentelemetry.io/otel v1.45.0, the protobuf pseudo-version) — each has both h1: and /go.mod hash lines. Consistent.
  • indirect→direct reclassification is correct: github.com/prometheus/client_golang moved into the direct require block in components/api-server/go.mod. That matches the real direct import in components/api-server/plugins/gateways/metrics.go:7, so go mod tidy did the right thing. Not a concern.
  • No go/toolchain directive changes, no code changes, no manifest/image changes.

Findings (all Minor)

  1. [Minor] PR title says "indirect" but the change also bumps direct deps. Besides indirect deps, this bumps direct requires (google.golang.org/grpc 1.82.1→1.83.0, gorm.io/gorm 1.31.1→1.31.2, OTel core 1.44.0→1.45.0) and promotes prometheus/client_golang and (in control-plane) google.golang.org/protobuf to direct. The title is slightly inaccurate; harmless but worth noting so reviewers don't assume it's indirect-only.

  2. [Minor] Mixed OpenTelemetry module versions in components/api-server/go.mod. Core/metric/trace/sdk are at v1.45.0 and otelhttp at v0.70.0, but the OTLP gRPC exporters (otlpmetricgrpc, otlptracegrpc) remain at v1.44.0. OTel exporters generally track the core release; MVS will resolve upward, but please confirm CI actually compiles the exporter code paths against otel v1.45.0 before merge. Confidence: Medium.

  3. [Minor] control-plane pins google.golang.org/protobuf to an unreleased pseudo-version (v1.36.12-0.20260120151049-f2248ac996af) while api-server stays on the released v1.36.11. Depending on an untagged commit is unusual for a mintmaker bump and creates cross-module drift. Prefer a released tag for reproducibility unless a specific fix requires the pseudo-version. Confidence: Medium.

Cross-PR coordination

I listed and compared all other open PRs in openshift-online/hypershell. Only two touch the same dependency files:

  • #182 fix(auth): enforce management API JWT audience — edits components/api-server/go.mod/go.sum (bumps rh-trex-ai and adds charmbracelet/* deps).
  • #194 feat(control-plane): adopt upstream OpenShell Helm chart — edits components/control-plane/go.mod (promotes sigs.k8s.io/yaml to direct).

No material conflict. These overlaps are ordinary go.mod/go.sum edits with distinct goals; they do not represent competing designs, duplicate solutions, or incompatible assumptions with #75. The only coordination need is routine: whichever of #75/#182/#194 merges second on a shared module will need a go mod tidy/go mod verify re-run to reconcile go.sum. That is normal maintenance, not a design decision. #207 (feat: reconcile-to-request trace correlation) uses OTel APIs but does not modify any go.mod, so it inherits whatever OTel version lands and does not compete with the bump here. All other open PRs (UI, docs/specs, e2e, kind/dev, container-image bump #73) touch disjoint files.

Full open PR list reviewed: #216, #214, #212, #211, #210, #209, #208, #207, #206, #201, #200, #194, #189, #188, #185, #182, #179, #151, #150, #148, #135, #109, #73.

Findings Summary (ordered by severity, highest first)

  1. [Minor] PR title says "indirect" but direct deps are also bumped/reclassified — Commit/PR hygiene (go.mod L12, L18, L25)
  2. [Minor] Mixed OTel versions: core/metric at v1.45.0, OTLP exporters left at v1.44.0 — Dependency consistency (components/api-server/go.mod L19–L21)
  3. [Minor] control-plane pins protobuf to an unreleased pseudo-version while api-server uses a release — Dependency consistency/reproducibility (components/control-plane/go.mod L8)

Convention Checklist

Convention Result
Conventional commit message Pass
go.sum hashes present & consistent for new pins Pass
indirect/direct classification matches actual imports Pass
Image references consistent across stack N/A (no image/manifest changes)
Build/tests validated Deferred to CI (no Go toolchain available locally)

Rollback: this is a self-contained dependency bump — reverting the merge commit fully restores the prior module graph.

github.com/gorilla/mux v1.7.3
github.com/onsi/gomega v1.27.1
github.com/openshift-online/rh-trex-ai v0.0.32-0.20260819203335-5798cb607fcb
github.com/prometheus/client_golang v1.24.1

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

prometheus/client_golang is (correctly) promoted from indirect to a direct require here — it's directly imported at components/api-server/plugins/gateways/metrics.go:7, so go mod tidy did the right thing. Just noting the PR title ("indirect dependencies") understates that this touches direct requires too.

go.opentelemetry.io/otel v1.44.0
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.70.0
go.opentelemetry.io/otel v1.45.0
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.44.0

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OTel version skew: core/metric/trace/sdk are bumped to v1.45.0 (and otelhttp to v0.70.0) but these OTLP gRPC exporters stay at v1.44.0. Exporters normally track the core release; MVS will resolve upward, but please confirm CI compiles the exporter paths against otel v1.45.0 before merge. (Minor, Confidence: Medium)

github.com/openshift-online/hypershell/components/api-server v0.0.0-00010101000000-000000000000
google.golang.org/grpc v1.82.1
google.golang.org/grpc v1.83.0
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

google.golang.org/protobuf is pinned to an unreleased pseudo-version (v1.36.12-0.2026...) here, while components/api-server/go.mod stays on the released v1.36.11. Depending on an untagged commit is unusual for a mintmaker bump and creates cross-module drift — prefer a released tag for reproducibility unless a specific fix requires it. (Minor, Confidence: Medium)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant