chore(deps): update dependency alex1989hu/kubelet-serving-cert-approver to v0.12.0 - #3594
Conversation
Pull request was converted to draft
…o v0.12.0 The RGD static-scan gate fails a Kustomization resource that is not a local path or a reviewed remote, and the reviewed baseline still pinned v0.11.0, so the URL bump could not pass its own guard. Upstream diff between the two tags is a single line - the container image tag 0.11.0 -> 0.12.0. No RBAC, resource, webhook or label change. The PDB selector in this directory still matches the upstream Deployment matchLabels. The digest method is proven by control: re-fetching v0.11.0 reproduces the baseline digest 60b0f272... exactly. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Why this PR now carries a second commitThe URL bump could not pass its own guard. That is the control working as designed — a new upstream revision is not trusted until someone looks What actually changed upstreamThe whole diff between - image: ghcr.io/alex1989hu/kubelet-serving-cert-approver:0.11.0
+ image: ghcr.io/alex1989hu/kubelet-serving-cert-approver:0.12.0Both files are 260 lines. No RBAC rule, ClusterRole, RoleBinding, Service, webhook, namespace or The digest is proven by control, not assertedRe-fetching the old revision with the same method reproduces the reviewed baseline digest exactly:
A method that reproduces a known-good digest is what makes the new one trustworthy; without that The directory's own checklist item
Consequences
|
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
The render-remote-resource guard fails a row whose URL is no longer referenced, by design, so re-pinning only the static-scan baseline would have traded one red check for another. Both lists name the same URL and both have to move with the kustomization. Row semantics are unchanged: still a tracked exception owned by #3196, not an approval, and still the same manifest - only the tag it names moved. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A second list pins the same URL — re-pinning one would have traded one red check for another
Both lists now name The recorded maintainer gate on this package — flagging, not deciding
Both of those re-checks are done and evidenced above: the upstream diff is one image-tag line, and the So I am taking this PR to green-CI-plus-green-review and stopping there rather than merging it. That @devantler this is a one-click merge whenever you are happy with the upstream delta above. |
@coderabbitai full review |
|
✅ Action performedFull review finished. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Team Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
🧰 Additional context used📓 Path-based instructions (1)Never run a cluster Put a change in the layer that matches its scope📄 CodeRabbit inference engine (AGENTS.md) Files:
🔇 Additional comments (1)
📝 WalkthroughWalkthroughThe Kustomize configuration now references the Merge Risk: ⚪ Minimal · up to This updates the kubelet serving certificate approver HA manifest to v0.12.0. No current merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Readiness at
|
Maintainer-review gate: the two named checks are now done
1. Upstream manifest / privileged RBAC surface — no changeTwo independent signals agree:
The 2. Local PDB selector still matches upstream labels — verified liveRead from prod (read-only) rather than reasoned from the manifest:
Residual, stated honestlyI verified the selector against the currently deployed v0.11.0, not against Separately, nothing in CI asserts that a PDB's selector matches the workload it Pentad at |
@coderabbitai full review Please review current head 389a59b after the base refresh. |
|
✅ Action performedFull review finished. |
This PR contains the following updates:
0.11.0→0.12.0Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
alex1989hu/kubelet-serving-cert-approver (alex1989hu/kubelet-serving-cert-approver)
v0.12.0Compare Source
Chore
Ci
Fix
v0.11.1Compare Source
Chore
Ci
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.