Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
# To re-generate a bundle for another specific version without changing the standard setup, you can:
# - use the BUNDLE_VERSION as arg of the bundle target (e.g make bundle BUNDLE_VERSION=0.0.2)
# - use environment variables to overwrite this value (e.g export BUNDLE_VERSION=0.0.2)
BUNDLE_VERSION ?= 1.17.1
BUNDLE_VERSION ?= 1.17.2
CERT_MANAGER_VERSION ?= "v1.17.4"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There is a newer(1.17.4) z-stream of cert-manager 1.17 available, we should be updating to that.
The same isn't required for istio-csr, since it's TP in 1.17

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also is the downstream fork release branch release-1.17 synched with v1.17.4 of upstream?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. The CERT_MANAGER_VERSION is already at v1.17.4 (unchanged from the base branch). Are you asking us to bump BUNDLE_VERSION from 1.17.2 to 1.17.4 to match the cert-manager operand version?
  2. Yes, release-1.17 is synced with v1.17.4 and includes the additional CVE backports from [https://github.com/CM-1222: UPSTREAM: <carry>: Apply openshift-sustaining CVE backports for go 1.24 jetstack-cert-manager#45] (merge commit a9537101948b).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the confusion. I think got confused with the changes in Makefile and assumed operand was still at 1.17.2

ISTIO_CSR_VERSION ?= "v0.14.0"

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -250,7 +250,7 @@ metadata:
features.operators.openshift.io/token-auth-aws: "true"
features.operators.openshift.io/token-auth-azure: "true"
features.operators.openshift.io/token-auth-gcp: "true"
olm.skipRange: '>=1.17.0 <1.17.1'
olm.skipRange: '>=1.17.1 <1.17.2'
operator.openshift.io/uninstall-message: The cert-manager Operator for Red Hat
OpenShift will be removed from cert-manager-operator namespace. If your Operator
configured any off-cluster resources, these will continue to run and require
Expand All @@ -271,7 +271,7 @@ metadata:
operatorframework.io/arch.ppc64le: supported
operatorframework.io/arch.s390x: supported
operatorframework.io/os.linux: supported
name: cert-manager-operator.v1.17.1
name: cert-manager-operator.v1.17.2
namespace: cert-manager-operator
spec:
apiservicedefinitions: {}
Expand Down Expand Up @@ -670,7 +670,7 @@ spec:
- name: ISTIOCSR_OPERAND_IMAGE_VERSION
value: 0.14.0
- name: OPERATOR_IMAGE_VERSION
value: 1.17.1
value: 1.17.2
- name: OPERATOR_LOG_LEVEL
value: "2"
- name: TRUSTED_CA_CONFIGMAP_NAME
Expand Down Expand Up @@ -774,5 +774,5 @@ spec:
name: cert-manager-acmesolver
- image: quay.io/jetstack/cert-manager-istio-csr:v0.14.0
name: cert-manager-istiocsr
replaces: cert-manager-operator.v1.17.0
version: 1.17.1
replaces: cert-manager-operator.v1.17.1
version: 1.17.2
2 changes: 1 addition & 1 deletion config/manager/manager.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,7 @@ spec:
- name: ISTIOCSR_OPERAND_IMAGE_VERSION
value: 0.14.0
- name: OPERATOR_IMAGE_VERSION
value: 1.17.1
value: 1.17.2
- name: OPERATOR_LOG_LEVEL
value: '2'
- name: TRUSTED_CA_CONFIGMAP_NAME
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ metadata:
features.operators.openshift.io/token-auth-aws: "true"
features.operators.openshift.io/token-auth-azure: "true"
features.operators.openshift.io/token-auth-gcp: "true"
olm.skipRange: '>=1.17.0 <1.17.1'
olm.skipRange: '>=1.17.1 <1.17.2'
operator.openshift.io/uninstall-message: The cert-manager Operator for Red Hat
OpenShift will be removed from cert-manager-operator namespace. If your Operator
configured any off-cluster resources, these will continue to run and require
Expand All @@ -38,7 +38,7 @@ metadata:
operatorframework.io/arch.ppc64le: supported
operatorframework.io/arch.s390x: supported
operatorframework.io/os.linux: supported
name: cert-manager-operator.v1.17.1
name: cert-manager-operator.v1.17.2
namespace: cert-manager-operator
spec:
apiservicedefinitions: {}
Expand Down Expand Up @@ -104,5 +104,5 @@ spec:
minKubeVersion: 1.27.0
provider:
name: Red Hat
replaces: cert-manager-operator.v1.17.0
version: 1.17.1
replaces: cert-manager-operator.v1.17.1
version: 1.17.2
40 changes: 24 additions & 16 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ require (
github.com/spf13/cobra v1.8.1
github.com/spf13/pflag v1.0.5
github.com/stretchr/testify v1.11.1
golang.org/x/tools v0.28.0
golang.org/x/tools v0.41.0
k8s.io/api v0.32.13
k8s.io/apiextensions-apiserver v0.32.13
k8s.io/apimachinery v0.32.13
Expand All @@ -41,7 +41,7 @@ require (

require (
4d63.com/gochecknoglobals v0.1.0 // indirect
cel.dev/expr v0.19.1 // indirect
cel.dev/expr v0.24.0 // indirect
github.com/Abirdcfly/dupword v0.0.7 // indirect
github.com/Antonboom/errname v0.1.7 // indirect
github.com/Antonboom/nilnil v0.1.1 // indirect
Expand Down Expand Up @@ -212,7 +212,7 @@ require (
github.com/sivchari/tenv v1.7.0 // indirect
github.com/sonatard/noctx v0.0.1 // indirect
github.com/sourcegraph/go-diff v0.6.1 // indirect
github.com/spf13/afero v1.8.2 // indirect
github.com/spf13/afero v1.10.0 // indirect
github.com/spf13/cast v1.5.0 // indirect
github.com/spf13/jwalterweatherman v1.1.0 // indirect
github.com/spf13/viper v1.12.0 // indirect
Expand Down Expand Up @@ -251,22 +251,24 @@ require (
go.opentelemetry.io/proto/otlp v1.4.0 // indirect
go.uber.org/multierr v1.11.0 // indirect
go.uber.org/zap v1.27.0 // indirect
golang.org/x/crypto v0.36.0 // indirect
golang.org/x/crypto v0.48.0 // indirect
golang.org/x/exp v0.0.0-20241217172543-b2144cdd0a67 // indirect
golang.org/x/exp/typeparams v0.0.0-20220827204233-334a2380cb91 // indirect
golang.org/x/mod v0.22.0 // indirect
golang.org/x/net v0.38.0 // indirect
golang.org/x/oauth2 v0.28.0 // indirect
golang.org/x/sync v0.12.0 // indirect
golang.org/x/sys v0.40.0 // indirect
golang.org/x/term v0.30.0 // indirect
golang.org/x/text v0.23.0 // indirect
golang.org/x/mod v0.32.0 // indirect
golang.org/x/net v0.49.0 // indirect
golang.org/x/oauth2 v0.30.0 // indirect
golang.org/x/sync v0.19.0 // indirect
golang.org/x/sys v0.41.0 // indirect
golang.org/x/term v0.40.0 // indirect
golang.org/x/text v0.34.0 // indirect
golang.org/x/time v0.8.0 // indirect
golang.org/x/tools/go/expect v0.1.1-deprecated // indirect
golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated // indirect
gomodules.xyz/jsonpatch/v2 v2.4.0 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20241219192143-6b3ec007d9bb // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20241219192143-6b3ec007d9bb // indirect
google.golang.org/grpc v1.69.2 // indirect
google.golang.org/protobuf v1.36.0 // indirect
google.golang.org/genproto/googleapis/api v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20250707201910-8d1bb00bc6a7 // indirect
google.golang.org/grpc v1.71.0 // indirect
google.golang.org/protobuf v1.36.6 // indirect
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
gopkg.in/inf.v0 v0.9.1 // indirect
gopkg.in/ini.v1 v1.67.0 // indirect
Expand Down Expand Up @@ -296,6 +298,12 @@ require (
sigs.k8s.io/kustomize/kyaml v0.18.1 // indirect
)

replace github.com/cert-manager/cert-manager => github.com/openshift/jetstack-cert-manager v1.17.4
replace github.com/cert-manager/cert-manager => github.com/openshift/jetstack-cert-manager v1.17.5-0.20260924124801-70e2228def37

replace sigs.k8s.io/controller-tools => github.com/openshift/kubernetes-sigs-controller-tools v0.12.1-0.20250220141355-6d2c85031fbc

replace golang.org/x/net => github.com/openshift-sustaining/net v0.50.0-sec.4

replace google.golang.org/grpc => github.com/openshift-sustaining/grpc-go v1.75.1-sec.1

replace golang.org/x/crypto => github.com/openshift-sustaining/crypto v0.48.0-sec.3
Loading