Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 4, 2025

Bumps the security group with 3 updates: github.com/vmware-tanzu/velero, sigs.k8s.io/kustomize/api and sigs.k8s.io/kustomize/kyaml.

Updates github.com/vmware-tanzu/velero from 1.16.1 to 1.16.2

Release notes

Sourced from github.com/vmware-tanzu/velero's releases.

v1.16.2

Download

https://github.com/vmware-tanzu/velero/releases/tag/v1.16.2

Container Image

velero/velero:v1.16.2

Documentation

https://velero.io/docs/v1.16/

Upgrading

https://velero.io/docs/v1.16/upgrade-to-1.16/

All Changes

v1.16.2-rc.1

v1.16.2

Download

https://github.com/vmware-tanzu/velero/releases/tag/v1.16.2-rc.1

Container Image

velero/velero:v1.16.2-rc.1

Documentation

https://velero.io/docs/v1.16/

Upgrading

https://velero.io/docs/v1.16/upgrade-to-1.16/

All Changes

Commits
  • a608082 Merge pull request #9108 from blackpiglet/bump_e2e_upgrade_versions
  • befd9d4 Bump the Velero and plugin image versions for the upgrade and migration tests.
  • 5ae1cae Merge pull request #9107 from Lyndon-Li/release-1.16
  • cc2dc02 1.16.2 changelog
  • 189a5b2 Bump Golang, Ubuntu, and golang.org/x/oauth2 to fix CVEs. (#9104)
  • 0fc7e2f Add imagePullSecrets inheritance for VGDP pod and maintenance job. (#9102)
  • 8adfd8d Merge pull request #9103 from shubham-pampattiwar/fix-backup-desc-cp
  • 78fd58f Update Backup describe string for DefaultVolumesToFSBackup flag (#9105)
  • 8f51c1c Fix missing defaultVolumesToFsBackup flag output in Velero describe backup cm...
  • fd9f3fe issue 9077: don't block backup deletion on list VS error (#9101)
  • Additional commits viewable in compare view

Updates sigs.k8s.io/kustomize/api from 0.20.0 to 0.20.1

Release notes

Sourced from sigs.k8s.io/kustomize/api's releases.

api/v0.20.1

#5943: drop shlex dependency #5948: Update kyaml to v0.20.1

cmd/config/v0.20.1

#5948: Update kyaml to v0.20.1

kyaml/v0.20.1

No release notes provided.

Commits
  • 8b42cd9 Merge pull request #5949 from koba1t/pinToCmdConfig
  • 5b313f5 Update cmd/config to v0.20.1
  • 792b241 Merge pull request #5948 from koba1t/pinToKyaml
  • 8192ab3 Update kyaml to v0.20.1
  • 87f462a Merge pull request #5943 from koba1t/chore/drop_shlex_dependency
  • 3866a30 introduce one const value that indicate to no quote in ShlexSplit()
  • 5cb1b4e remove shlex dependencies
  • b612895 add ShlexSplit() as an alternative to shlex.Split()
  • 042a2cf add testcases for shlexsplit
  • f9ab532 Merge pull request #5937 from koba1t/unpinEverything
  • Additional commits viewable in compare view

Updates sigs.k8s.io/kustomize/kyaml from 0.20.0 to 0.20.1

Release notes

Sourced from sigs.k8s.io/kustomize/kyaml's releases.

api/v0.20.1

#5943: drop shlex dependency #5948: Update kyaml to v0.20.1

cmd/config/v0.20.1

#5948: Update kyaml to v0.20.1

kyaml/v0.20.1

No release notes provided.

Commits
  • 8b42cd9 Merge pull request #5949 from koba1t/pinToCmdConfig
  • 5b313f5 Update cmd/config to v0.20.1
  • 792b241 Merge pull request #5948 from koba1t/pinToKyaml
  • 8192ab3 Update kyaml to v0.20.1
  • 87f462a Merge pull request #5943 from koba1t/chore/drop_shlex_dependency
  • 3866a30 introduce one const value that indicate to no quote in ShlexSplit()
  • 5cb1b4e remove shlex dependencies
  • b612895 add ShlexSplit() as an alternative to shlex.Split()
  • 042a2cf add testcases for shlexsplit
  • f9ab532 Merge pull request #5937 from koba1t/unpinEverything
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the security group with 3 updates: [github.com/vmware-tanzu/velero](https://github.com/vmware-tanzu/velero), [sigs.k8s.io/kustomize/api](https://github.com/kubernetes-sigs/kustomize) and [sigs.k8s.io/kustomize/kyaml](https://github.com/kubernetes-sigs/kustomize).


Updates `github.com/vmware-tanzu/velero` from 1.16.1 to 1.16.2
- [Release notes](https://github.com/vmware-tanzu/velero/releases)
- [Changelog](https://github.com/vmware-tanzu/velero/blob/main/CHANGELOG.md)
- [Commits](vmware-tanzu/velero@v1.16.1...v1.16.2)

Updates `sigs.k8s.io/kustomize/api` from 0.20.0 to 0.20.1
- [Release notes](https://github.com/kubernetes-sigs/kustomize/releases)
- [Commits](kubernetes-sigs/kustomize@api/v0.20.0...api/v0.20.1)

Updates `sigs.k8s.io/kustomize/kyaml` from 0.20.0 to 0.20.1
- [Release notes](https://github.com/kubernetes-sigs/kustomize/releases)
- [Commits](kubernetes-sigs/kustomize@api/v0.20.0...api/v0.20.1)

---
updated-dependencies:
- dependency-name: github.com/vmware-tanzu/velero
  dependency-version: 1.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security
- dependency-name: sigs.k8s.io/kustomize/api
  dependency-version: 0.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security
- dependency-name: sigs.k8s.io/kustomize/kyaml
  dependency-version: 0.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: security
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code type::chore labels Aug 4, 2025
@dependabot dependabot bot requested a review from a team as a code owner August 4, 2025 14:45
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code type::chore labels Aug 4, 2025
Copy link
Contributor Author

dependabot bot commented on behalf of github Aug 18, 2025

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot bot closed this Aug 18, 2025
@dependabot dependabot bot deleted the dependabot/go_modules/security-94c55a4022 branch August 18, 2025 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code type::chore
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants