Skip to content

build(deps): consolidate dependency updates on Go 1.27 - #154

Merged
Matt Tucker (matucker-msft) merged 3 commits into
mainfrom
consolidate-dependabot-updates
Sep 15, 2026
Merged

Matt Tucker (matucker-msft) merged 3 commits into
mainfrom
consolidate-dependabot-updates

Conversation

@matucker-msft

@matucker-msft Matt Tucker (matucker-msft) commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

Summary

Consolidates all five open Dependabot Go-module updates and the x/crypto update into one PR.

Dependency Version Superseded PR
github.com/Azure/azure-workload-identity v1.6.3 #151
sigs.k8s.io/controller-runtime v0.25.1 (newer than the proposed v0.24.1) #150
k8s.io/apimachinery v0.37.0 #149
github.com/go-logr/logr v1.4.4 #147
k8s.io/client-go v0.37.0 #146
golang.org/x/crypto v0.57.0 #153

Also updates Azure Identity to v1.14.1, Kubernetes utilities to the latest available revision, and the associated transitive dependencies. Kubernetes API modules are aligned at v0.37.0.

Toolchain and Compatibility

  • Select Go 1.27.1, required by workload identity v1.6.3, and have E2E CI read the version from go.mod.
  • Use the Microsoft Go 1.27 builder with CGO_ENABLED=0 and retain -tags=requirefips; remove the obsolete ms_nocgo_opensslcrypto experiment.
  • Pin the final runtime image to mcr.microsoft.com/azurelinux/base/core:3.0.20260909. Verified that the published amd64 image contains openssl-libs-3.3.7-6.azl3. The provider-backed ML-KEM fix landed in 3.3.7-5 via fix(openssl): backport EVP_PKEY_Q_keygen support microsoft/azurelinux#18630 and was confirmed shipped in this Azure Linux release in systemcrypto: TLS client fails with ML-KEM on Azure Linux 3 and SymCrypt-OpenSSL microsoft/go#2472. This avoids relying on a stale cached core:3.0 image.
  • Update golangci-lint to v2.13.2 for Go 1.27 support; update controller-gen to v0.22.0, mockgen to v0.6.0, and setup-envtest to v0.25.1 through Bingo. Regenerate their output.
  • Replace the deprecated controller-runtime scheme helper with Kubernetes runtime scheme registration to satisfy lint with the updated controller-runtime.
  • No new tests. The existing credential-provisioning E2E test retries both scope updates with client-go RetryOnConflict, re-fetching the current resource version on each attempt, to handle concurrent controller status writes. Helm and Kustomize upgrades are left separate.

Validation

  • GOTOOLCHAIN=go1.27.1 make lint all test: passed using existing tests.
  • Production Docker image build with Go 1.27 and the pinned runtime image: passed.
  • go mod verify and go mod tidy -diff: passed for the consolidated dependency graph.
  • govulncheck v1.8.0: no vulnerabilities in reachable code or imported packages. One module-only advisory, GO-2026-5932, concerns the unimported golang.org/x/crypto/openpgp package and has no fixed version.
  • Azure E2E validation is left to PR CI. The local image build does not establish end-to-end TLS/FIPS behavior.

E2E Conflict Fix

The initial E2E run failed on a resource-version conflict while restoring the valid registry scope, not on a crypto or image-pull failure. Both scope updates now retry conflicts.

Validation: go test -tags=e2e -run '^$' ./test passed; Full E2E-tagged lint passes with zero issues after removing the unused bindingGetter declaration. Azure E2E validation will run again on the updated commit.

@matucker-msft
Matt Tucker (matucker-msft) merged commit f70e530 into main Sep 15, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants