Skip to content

build(deps): bump sigs.k8s.io/promo-tools/v3 from 3.4.4 to 3.4.9#232

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/sigs.k8s.io/promo-tools/v3-3.4.9
Closed

build(deps): bump sigs.k8s.io/promo-tools/v3 from 3.4.4 to 3.4.9#232
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/go_modules/sigs.k8s.io/promo-tools/v3-3.4.9

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Nov 10, 2022

Bumps sigs.k8s.io/promo-tools/v3 from 3.4.4 to 3.4.9.

Release notes

Sourced from sigs.k8s.io/promo-tools/v3's releases.

v3.4.9

Changes by Kind

Bug or Regression

  • Fixed bug to dedup images list before verifying their signatures. (#674, @​saschagrunert) [SIG Release]

Other (Cleanup or Flake)

Dependencies

Added

  • cloud.google.com/go/accessapproval: v1.4.0
  • cloud.google.com/go/accesscontextmanager: v1.3.0
  • cloud.google.com/go/apigateway: v1.3.0
  • cloud.google.com/go/apigeeconnect: v1.3.0
  • cloud.google.com/go/appengine: v1.4.0
  • cloud.google.com/go/baremetalsolution: v0.3.0
  • cloud.google.com/go/batch: v0.3.0
  • cloud.google.com/go/beyondcorp: v0.2.0
  • cloud.google.com/go/certificatemanager: v1.3.0
  • cloud.google.com/go/channel: v1.8.0
  • cloud.google.com/go/cloudbuild: v1.3.0
  • cloud.google.com/go/clouddms: v1.3.0
  • cloud.google.com/go/compute/metadata: v0.2.1
  • cloud.google.com/go/contactcenterinsights: v1.3.0
  • cloud.google.com/go/container: v1.6.0
  • cloud.google.com/go/datafusion: v1.4.0
  • cloud.google.com/go/dataplex: v1.3.0
  • cloud.google.com/go/dataproc: v1.7.0
  • cloud.google.com/go/deploy: v1.4.0
  • cloud.google.com/go/dlp: v1.6.0
  • cloud.google.com/go/essentialcontacts: v1.3.0
  • cloud.google.com/go/eventarc: v1.7.0
  • cloud.google.com/go/filestore: v1.3.0
  • cloud.google.com/go/gkebackup: v0.2.0
  • cloud.google.com/go/gkemulticloud: v0.3.0
  • cloud.google.com/go/gsuiteaddons: v1.3.0
  • cloud.google.com/go/iap: v1.4.0
  • cloud.google.com/go/ids: v1.1.0
  • cloud.google.com/go/iot: v1.3.0
  • cloud.google.com/go/longrunning: v0.1.1
  • cloud.google.com/go/managedidentities: v1.3.0
  • cloud.google.com/go/networkmanagement: v1.4.0
  • cloud.google.com/go/optimization: v1.1.0
  • cloud.google.com/go/orchestration: v1.3.0
  • cloud.google.com/go/orgpolicy: v1.4.0

... (truncated)

Changelog

Sourced from sigs.k8s.io/promo-tools/v3's changelog.

Releasing the artifact promoter tools

This is a draft document to describe the release process for artifact promotion tooling.

(If there are improvements you'd like to see, please comment on the tracking issue.)

Tracking

As the first task, a Release Manager should open a tracking issue for the release.

We don't currently have a template for releasing, but the following issue is a good example to draw inspiration from.

We're not striving for perfection with the template, but the tracking issue will serve as a reference point to aggregate feedback, so try your best to be as descriptive as possible.

Validation

TODO: Talk about canaries

Tagging

There are two tags that we care about:

  • git tags
  • image tags

We use with SemVer-compliant versions for git tags and GitHub releases, prefixed with v. SemVer is described in detail here.

Example:

v3.4.0

Image tags are derived from the git tag, with the addition of a revision.

... (truncated)

Commits
  • f3a08fe Merge pull request #676 from cpanato/bump
  • ff19400 releng: Bump promoter to v3.4.9
  • b8f665d Merge pull request #674 from saschagrunert/refs-dedup
  • 55e1bd8 Dedup images to verify for signed edges
  • 582c692 Merge pull request #673 from kubernetes-sigs/dependabot/go_modules/golang.org...
  • 472644f build(deps): bump golang.org/x/oauth2 from 0.1.0 to 0.2.0
  • 77f3f56 Merge pull request #670 from kubernetes-sigs/dependabot/go_modules/cloud.goog...
  • 62fd9ab build(deps): bump cloud.google.com/go/storage from 1.27.0 to 1.28.0
  • 98f10aa Merge pull request #671 from kubernetes-sigs/dependabot/go_modules/cloud.goog...
  • c165803 build(deps): bump cloud.google.com/go/iam from 0.6.0 to 0.7.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sigs.k8s.io/promo-tools/v3](https://github.com/kubernetes-sigs/promo-tools) from 3.4.4 to 3.4.9.
- [Release notes](https://github.com/kubernetes-sigs/promo-tools/releases)
- [Changelog](https://github.com/kubernetes-sigs/promo-tools/blob/main/RELEASE.md)
- [Commits](kubernetes-sigs/promo-tools@v3.4.4...v3.4.9)

---
updated-dependencies:
- dependency-name: sigs.k8s.io/promo-tools/v3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Nov 10, 2022

The following labels could not be found: area/dependency, release-note-none, ok-to-test.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Dec 1, 2022

Superseded by #243.

@dependabot dependabot bot closed this Dec 1, 2022
@dependabot dependabot bot deleted the dependabot/go_modules/sigs.k8s.io/promo-tools/v3-3.4.9 branch December 1, 2022 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants