Skip to content

NO-ISSUE: Synchronize From Upstream Repositories#1338

Open
openshift-bot wants to merge 48 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream
Open

NO-ISSUE: Synchronize From Upstream Repositories#1338
openshift-bot wants to merge 48 commits into
openshift:mainfrom
openshift-bot:synchronize-upstream

Conversation

@openshift-bot

@openshift-bot openshift-bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

The staging/ and vendor/ directories have been synchronized from the upstream repositories, pulling in the following commits:

Date Commit Author Message
2026-07-14 06:41:26 operator-framework/operator-lifecycle-manager@396954f dependabot[bot] 🌱 Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870)
2026-07-14 06:46:57 operator-framework/operator-lifecycle-manager@fdd5594 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869)
2026-07-14 10:46:25 operator-framework/operator-lifecycle-manager@a4f060a dependabot[bot] 🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868)
2026-07-15 10:15:40 operator-framework/operator-lifecycle-manager@174dccd Jordan Keister deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress (#3863)
2026-07-15 21:14:14 operator-framework/operator-lifecycle-manager@b0123be Chiman Jain Migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#3865)
2026-07-21 07:59:27 operator-framework/operator-lifecycle-manager@f59f6ec dependabot[bot] 🌱 Bump github.com/prometheus/client_golang (#3872)
2026-07-21 08:02:33 operator-framework/operator-lifecycle-manager@0a601aa dependabot[bot] Bump actions/setup-go from 6 to 7 (#3873)
2026-07-21 08:05:38 operator-framework/operator-lifecycle-manager@53c9aaa dependabot[bot] 🌱 Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3874)
2026-07-21 08:08:27 operator-framework/operator-lifecycle-manager@7d437b8 dependabot[bot] 🌱 Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#3875)
2026-07-23 20:28:05 operator-framework/operator-lifecycle-manager@0368a3f Jordan Keister chore: bump o-f deps (#3877)
2026-06-12 07:14:13 operator-framework/operator-registry@7d269bb dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#2009)
2026-06-15 07:45:11 operator-framework/operator-registry@98a7a1d dependabot[bot] Bump the k8s-dependencies group with 4 updates (#2010)
2026-06-15 07:47:40 operator-framework/operator-registry@8b4afca dependabot[bot] Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#2011)
2026-06-15 07:59:48 operator-framework/operator-registry@276ec06 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 (#2012)
2026-06-19 11:23:49 operator-framework/operator-registry@34f59d9 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.45 to 1.14.46 (#2013)
2026-06-19 11:26:38 operator-framework/operator-registry@c5ada4d dependabot[bot] Bump actions/checkout from 6 to 7 (#2014)
2026-06-19 11:29:19 operator-framework/operator-registry@84d62cf dependabot[bot] Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#2015)
2026-06-19 11:32:05 operator-framework/operator-registry@2219268 dependabot[bot] Bump github.com/docker/cli (#2016)
2026-06-22 07:13:46 operator-framework/operator-registry@1a822bd dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.47 (#2017)
2026-06-22 07:16:39 operator-framework/operator-registry@944d18b dependabot[bot] Bump go.etcd.io/bbolt from 1.4.3 to 1.5.0 (#2018)
2026-06-23 07:02:36 operator-framework/operator-registry@48f73d6 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 (#2019)
2026-06-24 12:25:16 operator-framework/operator-registry@55c06bd dependabot[bot] Bump github.com/joelanford/ignore from 0.1.1 to 0.1.2 (#2021)
2026-06-24 12:28:18 operator-framework/operator-registry@ab08265 dependabot[bot] Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#2022)
2026-06-25 16:13:02 operator-framework/operator-registry@13010cc Jordan Keister empty cred check failed to fall back (#2020)
2026-06-29 05:57:56 operator-framework/operator-registry@e79d272 dependabot[bot] Bump github.com/docker/cli (#2024)
2026-07-01 07:28:54 operator-framework/operator-registry@d2bf83f dependabot[bot] Bump google.golang.org/grpc from 1.81.1 to 1.82.0 (#2026)
2026-07-07 07:20:48 operator-framework/operator-registry@741b52e dependabot[bot] Bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-x-deps group (#2027)
2026-07-09 07:38:48 operator-framework/operator-registry@dbb3bd2 dependabot[bot] Bump the golang-x-deps group with 4 updates (#2028)
2026-07-09 07:44:25 operator-framework/operator-registry@eb78c9e dependabot[bot] Bump github.com/grpc-ecosystem/grpc-health-probe from 0.4.52 to 0.4.53 (#2030)
2026-07-09 09:08:40 operator-framework/operator-registry@f470500 dependabot[bot] Bump go.podman.io/common from 0.68.0 to 0.68.1 (#2029)
2026-07-10 03:48:01 operator-framework/operator-registry@8df27aa Chiman Jain Upgrade gopkg.in/yaml.v2 to go.yaml.in/yaml/v3 (#2023)
2026-07-10 07:32:11 operator-framework/operator-registry@fc2ca91 dependabot[bot] Bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#2031)
2026-07-13 07:17:48 operator-framework/operator-registry@798c576 dependabot[bot] Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#2032)
2026-07-14 06:41:25 operator-framework/operator-registry@6a6d882 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.47 to 1.14.48 (#2033)
2026-07-16 06:51:51 operator-framework/operator-registry@ce95ade dependabot[bot] Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#2035)
2026-07-17 08:12:20 operator-framework/operator-registry@ec5ca06 dependabot[bot] Bump github.com/docker/cli (#2036)
2026-07-17 08:15:10 operator-framework/operator-registry@37385d0 dependabot[bot] Bump actions/setup-go from 6 to 7 (#2037)
2026-07-23 16:26:18 operator-framework/operator-registry@f9556d7 Harald Klein Reject cyclic substitutesFor chains instead of looping until OOM (#2038)
2026-07-23 16:50:09 operator-framework/operator-registry@837bc5d Todd Short Bump github.com/moby/moby/client from v0.4.1 to v0.5.0 (#2039)
2026-07-23 19:28:03 operator-framework/operator-registry@19af4a3 Jordan Keister bump api to 0.45.0 (#2040)
2026-06-16 07:34:55 operator-framework/api@5adf634 dependabot[bot] Bump the k8s-dependencies group with 4 updates (#500)
2026-06-23 06:46:01 operator-framework/api@2b39c44 dependabot[bot] Bump actions/checkout from 6 to 7 (#501)
2026-06-26 13:57:32 operator-framework/api@492d6ba Lars Lehtonen pkg/manifests: fix dropped walk errors (#495)
2026-06-30 07:27:23 operator-framework/api@3c29466 dependabot[bot] Bump actions/cache from 5 to 6 (#502)
2026-07-06 07:30:57 operator-framework/api@23c932a dependabot[bot] Bump golang.org/x/net from 0.54.0 to 0.55.0 (#503)
2026-07-07 07:20:48 operator-framework/api@132f449 dependabot[bot] Bump github.com/google/cel-go from 0.28.1 to 0.29.1 (#504)
2026-07-14 06:41:25 operator-framework/api@c4902de dependabot[bot] Bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#505)
2026-07-21 07:56:33 operator-framework/api@72d46e1 dependabot[bot] Bump actions/setup-go from 6 to 7 (#506)

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

@openshift-bot openshift-bot added approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. labels Jul 15, 2026
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 15, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The staging/ and vendor/ directories have been synchronized from the upstream repositories, pulling in the following commits:

Date Commit Author Message
2026-07-14 06:41:26 operator-framework/operator-lifecycle-manager@396954f dependabot[bot] 🌱 Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870)
2026-07-14 06:46:57 operator-framework/operator-lifecycle-manager@fdd5594 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869)
2026-07-14 10:46:25 operator-framework/operator-lifecycle-manager@a4f060a dependabot[bot] 🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868)

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Jul 15, 2026

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Dependency versions and YAML module usage were updated, CI actions were upgraded, manifest loaders now propagate walk errors, registry credential handling and substitution cycle detection were added, and catalog/bundle network policies were introduced.

Changes

Core behavior and validation

Layer / File(s) Summary
Manifest walk error propagation
staging/api/pkg/manifests/*
Walk-time filesystem errors are returned by bundle and package loaders, with tests for invalid, missing, and inaccessible paths.
Registry and substitution safeguards
staging/operator-registry/pkg/image/..., staging/operator-registry/pkg/sqlite/...
Image pulls avoid shared context mutation and validate credentials; substitution traversal detects direct and indirect cycles.
Network policy coverage
manifests/..., microshift-manifests/..., staging/operator-lifecycle-manager/deploy/chart/templates/...
Catalog gRPC ingress and bundle-unpack egress policies are added to static and templated manifests.

Dependency, CI, and test maintenance

Layer / File(s) Summary
Dependency and YAML refresh
go.mod, staging/*/go.mod, staging/operator-registry/pkg/lib/..., staging/operator-lifecycle-manager/util/cpb/main.go
Go modules are upgraded, YAML imports move to go.yaml.in/yaml, and annotation generation uses the YAML v3 encoder.
CI and test maintenance
staging/*/.github/workflows/*, staging/operator-lifecycle-manager/pkg/controller/..., staging/operator-registry/pkg/...
GitHub Actions versions are updated and related tests receive formatting, assertion, and helper adjustments.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Possibly related issues

  • openshift/configure-goalert-operator#179 — Both changes update overlapping Go module dependencies, including Prometheus and golang.org/x/* modules.

Suggested reviewers: joelanford, tmshort

🚥 Pre-merge checks | ✅ 13 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 26.47% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Test Structure And Quality ⚠️ Warning FAIL: Several new tests use bare require assertions, two t.Cleanup chmod calls ignore errors, and path-failure tests only assert any error. Add concise assertion messages, handle cleanup chmod errors with t.Errorf, and assert the expected walk-cause for nonexistent/inaccessible path cases.
✅ Passed checks (13 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed No changed file adds Ginkgo titles; the new/modified tests use standard testing/t.Run with static names only.
Microshift Test Compatibility ✅ Passed No new Ginkgo e2e tests were added; touched test files use package testing with Test* functions and contain no It/Describe/Context/When blocks.
Single Node Openshift (Sno) Test Compatibility ✅ Passed PASS: The only new test file is a plain testing unit test (no Ginkgo Describe/It), and no test/e2e files were changed.
Topology-Aware Scheduling Compatibility ✅ Passed Touched manifests are NetworkPolicy-only; the new files contain no replicas, affinity, node selectors, or spread constraints.
Ote Binary Stdout Contract ✅ Passed No changed main/TestMain/BeforeSuite code adds stdout writes; the touched main.go change is import-only, and suite setup logs to GinkgoWriter/stderr.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed No new Ginkgo e2e tests were added; the new tests are plain Go unit tests and the manifest/workflow changes show no IPv4 or external-network assumptions.
No-Weak-Crypto ✅ Passed Scanned all changed lines and key implementation files; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret-comparison code was introduced.
Container-Privileges ✅ Passed The changed manifest files are NetworkPolicies only; no privileged/hostPID/hostNetwork/hostIPC/SYS_ADMIN/allowPrivilegeEscalation fields were added in the diffs.
No-Sensitive-Data-In-Logs ✅ Passed Touched files add deps/tests/manifests and error handling only; I found no new or modified logs that print passwords, tokens, PII, or hostnames.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main change: synchronizing staging and vendor code from upstream repositories.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from joelanford and tmshort July 15, 2026 00:08
@perdasilva

Copy link
Copy Markdown
Contributor

/retest

@openshift-bot
openshift-bot force-pushed the synchronize-upstream branch from 636c4d3 to 0711859 Compare July 16, 2026 00:08
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 16, 2026
@openshift-bot openshift-bot added the lgtm Indicates that a PR is ready to be merged. label Jul 17, 2026
@perdasilva

Copy link
Copy Markdown
Contributor

/retest

@openshift-bot
openshift-bot force-pushed the synchronize-upstream branch from 0711859 to ece9ee5 Compare July 22, 2026 00:11
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 22, 2026
@tmshort

tmshort commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

/retest

@openshift-bot
openshift-bot force-pushed the synchronize-upstream branch from ece9ee5 to eb08d90 Compare July 23, 2026 00:16
@openshift-bot openshift-bot added the lgtm Indicates that a PR is ready to be merged. label Jul 23, 2026
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 23, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In
`@staging/operator-lifecycle-manager/deploy/chart/templates/0000_50_olm_01-networkpolicies.yaml`:
- Around line 113-132: Replace the wildcard egress rule in the
bundle-unpack-egress NetworkPolicy with explicit rules reusing
.Values.networkPolicy.kubeAPIServer and .Values.networkPolicy.dns, plus only the
required registry and object-store destinations. Preserve the existing pod
selectors and policy type, and ensure no unrestricted destination or port
remains.
- Around line 89-111: The olm-catalog-grpc-ingress NetworkPolicy is rendered for
unsupported split-namespace deployments. Gate the manifest, including its
metadata and spec, on .Values.catalog_namespace equaling .Values.namespace so it
is omitted when the namespaces differ; preserve the existing policy unchanged
for matching namespaces.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 46a3c27d-2b80-473c-aa67-127bef63cebb

📥 Commits

Reviewing files that changed from the base of the PR and between ece9ee5 and eb08d90.

⛔ Files ignored due to path filters (129)
  • go.sum is excluded by !**/*.sum
  • staging/operator-lifecycle-manager/go.sum is excluded by !**/*.sum
  • vendor/github.com/go-logr/logr/context_noslog.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/context_slog.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/funcr/funcr.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/funcr/slogsink.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/sloghandler.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/slogr.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/slogr/slogr.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/slogsink.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/flate/dict_decoder.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/flate/inflate.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/huff0/build_table.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/internal/snapref/decode.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/dict.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_base.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_best.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_better.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_dfast.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_fast.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_jobs.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/encoder.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/encoder_options.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_amd64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_asm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_generic.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_amd64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_amd64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_arm64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_asm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_generic.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-lifecycle-manager/util/cpb/main.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header/header.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/counter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/desc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/expvar_collector.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/gauge.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/histogram.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/internal/difflib.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/labels.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/metric.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_darwin.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/option.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/registry.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/summary.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/timer.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/vec.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/wrap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/Makefile.common is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/SECURITY.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/crypto.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/mountinfo.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/net_wireless.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/proc_cgroup.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/armor/armor.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/errors/errors.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/packet/packet.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/read.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/s2k/s2k.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/net/http2/transport_wrap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/net/idna/idna.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sync/semaphore/semaphore.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/cpu/parse.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_386.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_amd64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_arm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_arm64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_loong64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_ppc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_s390x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zerrors_linux.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_386.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/windows/security_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/windows/syscall_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/windows/types_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/cases/context.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/cases/map.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/unicode/norm/forminfo.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/unicode/norm/iter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/unicode/norm/normalize.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/go/packages/packages.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/gcimporter/iexport.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/gcimporter/iimport.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/imports/fix.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/imports/imports.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/stdlib/deps.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/stdlib/manifest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/typesinternal/element.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/typesinternal/types.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/typesinternal/zerovalue.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/envconfig/envconfig.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/transport/controlbuf.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_server.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/version.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (11)
  • go.mod
  • manifests/0000_50_olm_01-networkpolicies.yaml
  • microshift-manifests/0000_50_olm_01-networkpolicies.yaml
  • staging/operator-lifecycle-manager/.github/workflows/e2e-tests.yml
  • staging/operator-lifecycle-manager/.github/workflows/goreleaser.yaml
  • staging/operator-lifecycle-manager/.github/workflows/sanity.yaml
  • staging/operator-lifecycle-manager/.github/workflows/unit.yml
  • staging/operator-lifecycle-manager/deploy/chart/templates/0000_50_olm_01-networkpolicies.yaml
  • staging/operator-lifecycle-manager/go.mod
  • staging/operator-lifecycle-manager/pkg/controller/operators/catalog/operator_test.go
  • staging/operator-lifecycle-manager/util/cpb/main.go
🚧 Files skipped from review as they are similar to previous changes (10)
  • staging/operator-lifecycle-manager/.github/workflows/sanity.yaml
  • staging/operator-lifecycle-manager/.github/workflows/unit.yml
  • staging/operator-lifecycle-manager/.github/workflows/goreleaser.yaml
  • staging/operator-lifecycle-manager/util/cpb/main.go
  • staging/operator-lifecycle-manager/.github/workflows/e2e-tests.yml
  • go.mod
  • microshift-manifests/0000_50_olm_01-networkpolicies.yaml
  • manifests/0000_50_olm_01-networkpolicies.yaml
  • staging/operator-lifecycle-manager/pkg/controller/operators/catalog/operator_test.go
  • staging/operator-lifecycle-manager/go.mod

Comment on lines +89 to +111
# Complements per-CatalogSource NPs from the controller; covers the bootstrapping window before reconciliation.
# Effective only when catalog_namespace == namespace (the default). When they differ, no OLM-managed
# deny-all exists in catalog_namespace, so this rule has no effect; adding one there is unsafe since
# OLM does not exclusively own that namespace.
# No 'from:' restriction is intentional, matching current dynamic NP behavior. If the controller ever
# restricts ingress sources, this Helm-owned NP (which the controller cannot delete) will silently
# override that — treat as a permanent design constraint.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: olm-catalog-grpc-ingress
namespace: {{ .Values.catalog_namespace }}
spec:
podSelector:
matchExpressions:
- key: olm.catalogSource
operator: Exists
policyTypes:
- Ingress
ingress:
- ports:
- protocol: TCP
port: {{ .Values.catalogGrpcPodPort }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Render this ingress policy only for the topology it supports.

Lines 90-92 claim this has no effect when catalog_namespace != namespace, but the manifest is rendered unconditionally. An ingress NetworkPolicy still selects matching pods and, absent another allow rule, denies ingress other than the listed TCP port. Split-namespace installations can therefore lose health, metrics, or service traffic. Gate this manifest on eq .Values.catalog_namespace .Values.namespace, or implement the correct split-namespace policy instead of documenting it as inert.

Proposed fix
+{{- if eq .Values.catalog_namespace .Values.namespace }}
 ---
 apiVersion: networking.k8s.io/v1
 kind: NetworkPolicy
 ...
   ingress:
     - ports:
       - protocol: TCP
         port: {{ .Values.catalogGrpcPodPort }}
+{{- end }}
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
# Complements per-CatalogSource NPs from the controller; covers the bootstrapping window before reconciliation.
# Effective only when catalog_namespace == namespace (the default). When they differ, no OLM-managed
# deny-all exists in catalog_namespace, so this rule has no effect; adding one there is unsafe since
# OLM does not exclusively own that namespace.
# No 'from:' restriction is intentional, matching current dynamic NP behavior. If the controller ever
# restricts ingress sources, this Helm-owned NP (which the controller cannot delete) will silently
# override that — treat as a permanent design constraint.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: olm-catalog-grpc-ingress
namespace: {{ .Values.catalog_namespace }}
spec:
podSelector:
matchExpressions:
- key: olm.catalogSource
operator: Exists
policyTypes:
- Ingress
ingress:
- ports:
- protocol: TCP
port: {{ .Values.catalogGrpcPodPort }}
{{- if eq .Values.catalog_namespace .Values.namespace }}
# Complements per-CatalogSource NPs from the controller; covers the bootstrapping window before reconciliation.
# Effective only when catalog_namespace == namespace (the default). When they differ, no OLM-managed
# deny-all exists in catalog_namespace, so this rule has no effect; adding one there is unsafe since
# OLM does not exclusively own that namespace.
# No 'from:' restriction is intentional, matching current dynamic NP behavior. If the controller ever
# restricts ingress sources, this Helm-owned NP (which the controller cannot delete) will silently
# override that — treat as a permanent design constraint.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: olm-catalog-grpc-ingress
namespace: {{ .Values.catalog_namespace }}
spec:
podSelector:
matchExpressions:
- key: olm.catalogSource
operator: Exists
policyTypes:
- Ingress
ingress:
- ports:
- protocol: TCP
port: {{ .Values.catalogGrpcPodPort }}
{{- end }}
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@staging/operator-lifecycle-manager/deploy/chart/templates/0000_50_olm_01-networkpolicies.yaml`
around lines 89 - 111, The olm-catalog-grpc-ingress NetworkPolicy is rendered
for unsupported split-namespace deployments. Gate the manifest, including its
metadata and spec, on .Values.catalog_namespace equaling .Values.namespace so it
is omitted when the namespaces differ; preserve the existing policy unchanged
for matching namespaces.

Comment on lines +113 to +132
# Wildcard egress; API server port omitted intentionally — it is implementation-defined and not statically knowable.
# Carries the same split-namespace limitation as olm-catalog-grpc-ingress above.
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: bundle-unpack-egress
namespace: {{ .Values.catalog_namespace }}
spec:
podSelector:
matchExpressions:
- key: operatorframework.io/bundle-unpack-ref
operator: Exists
- key: olm.managed
operator: In
values:
- "true"
policyTypes:
- Egress
egress:
- { }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift

Replace wildcard egress with an allowlist.

egress: - { } permits every destination and port for matching bundle-unpack pods. If the namespace is otherwise egress-isolated, this defeats the intended boundary and permits arbitrary cluster or external connections. Reuse the existing .Values.networkPolicy.kubeAPIServer and .Values.networkPolicy.dns configuration, then add only the required registry/object-store destinations.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In
`@staging/operator-lifecycle-manager/deploy/chart/templates/0000_50_olm_01-networkpolicies.yaml`
around lines 113 - 132, Replace the wildcard egress rule in the
bundle-unpack-egress NetworkPolicy with explicit rules reusing
.Values.networkPolicy.kubeAPIServer and .Values.networkPolicy.dns, plus only the
required registry and object-store destinations. Preserve the existing pod
selectors and policy type, and ensure no unrestricted destination or port
remains.

@perdasilva

Copy link
Copy Markdown
Contributor

/retest

@perdasilva

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 23, 2026
dependabot Bot and others added 7 commits July 24, 2026 00:05
Bumps [golang.org/x/sync](https://github.com/golang/sync) from 0.21.0 to 0.22.0.
- [Commits](golang/sync@v0.21.0...v0.22.0)

---
updated-dependencies:
- dependency-name: golang.org/x/sync
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: 396954f2ceb5cc5e68ee364fb161525c05390b9e
Bumps [github.com/prometheus/common](https://github.com/prometheus/common) from 0.69.0 to 0.70.0.
- [Release notes](https://github.com/prometheus/common/releases)
- [Changelog](https://github.com/prometheus/common/blob/main/CHANGELOG.md)
- [Commits](prometheus/common@v0.69.0...v0.70.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/common
  dependency-version: 0.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: fdd559459e09fce51148f8662f452018b55ea513
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.56.0 to 0.57.0.
- [Commits](golang/net@v0.56.0...v0.57.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.57.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: a4f060a9b8a125234a14099bb0f834219b5598eb
…ss and bundle unpack egress (#3863)

* deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress

The Helm chart's default-deny-all-traffic policy blocked two critical
traffic paths that are not covered by the existing static NetworkPolicies:

1. CatalogSource registry pods need to accept inbound gRPC connections on
   port 50051 from within the cluster. The catalog-operator reconciler
   already creates per-CatalogSource NetworkPolicies for this, but there
   is a bootstrapping gap between when default-deny-all-traffic is applied
   and when the controller first reconciles each CatalogSource.

2. Bundle-unpack Job pods need egress to reach the Kubernetes API server
   and container registries. The API server port is not statically
   specifiable because it varies across Kubernetes implementations, so a
   wildcard egress rule is used.

Adds two new NetworkPolicies to the chart:
- catalog-source-grpc-server: selects all pods carrying the
  olm.catalogSource label and allows ingress on the gRPC port.
- bundle-unpack-egress: selects all pods carrying both the
  olm.managed=true and operatorframework.io/bundle-unpack-ref labels and
  allows unrestricted egress.

Fixes: operator-framework/operator-lifecycle-manager#3676

Signed-off-by: grokspawn <jordan@nimblewidget.com>

* deploy/chart: use catalog_namespace for CatalogSource and bundle-unpack NPs

CatalogSource registry pods and bundle-unpack Jobs run in the namespace
determined by .Values.catalog_namespace, not .Values.namespace. When a
user overrides catalog_namespace to differ from namespace, the
NetworkPolicies must be created in catalog_namespace to actually apply
to those pods.

Fixes review feedback on #3863.

Signed-off-by: grokspawn <jordan@nimblewidget.com>

---------

Signed-off-by: grokspawn <jordan@nimblewidget.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: 174dccd0bd85f25fa9671839bbb21dc3a23cffc6
* chore: migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3

Signed-off-by: Chiman Jain <chimanjain15@gmail.com>

* chore: run go mod tidy

Signed-off-by: Chiman Jain <chimanjain15@gmail.com>

---------

Signed-off-by: Chiman Jain <chimanjain15@gmail.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: b0123beceac05a5d08b6d5734b1b7772a4fda921
Bumps [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) from 1.23.2 to 1.24.0.
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/v1.24.0/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.23.2...v1.24.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/client_golang
  dependency-version: 1.24.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: f59f6ece21efeef554981a5dedb44f3304e51e15
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: operator-lifecycle-manager
Upstream-commit: 0a601aa745fa4293402df4a761f74de17c474400
dependabot Bot added 3 commits July 24, 2026 00:20
Bumps [github.com/google/cel-go](https://github.com/google/cel-go) from 0.28.1 to 0.29.1.
- [Release notes](https://github.com/google/cel-go/releases)
- [Commits](cel-expr/cel-go@v0.28.1...v0.29.1)

---
updated-dependencies:
- dependency-name: github.com/google/cel-go
  dependency-version: 0.29.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: api
Upstream-commit: 132f4499f09433473b404d8da6594dd65aa89aba
Bumps [github.com/google/cel-go](https://github.com/google/cel-go) from 0.29.1 to 0.29.2.
- [Release notes](https://github.com/google/cel-go/releases)
- [Commits](cel-expr/cel-go@v0.29.1...v0.29.2)

---
updated-dependencies:
- dependency-name: github.com/google/cel-go
  dependency-version: 0.29.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: api
Upstream-commit: c4902decc528a59fb4efbcb33aef0c030978b845
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Upstream-repository: api
Upstream-commit: 72d46e1db6dffddc1c5747c885d845b39d3db1b2
@openshift-bot
openshift-bot force-pushed the synchronize-upstream branch from eb08d90 to c6c6b0c Compare July 24, 2026 00:21
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 24, 2026
@openshift-ci

openshift-ci Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

Approval requirements bypassed by manually added approval.

This pull-request has been approved by: openshift-bot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@staging/api/pkg/manifests/walkfunc_test.go`:
- Line 17: The assertions in walkfunc tests lack diagnostic context. Update the
affected require.ErrorIs, require.Len, require.Error, require.Contains, and
require.Mkdir calls to include concise, meaningful failure messages describing
the expected condition, while preserving their existing assertions and behavior.
- Line 81: Update both t.Cleanup callbacks around the permission restoration to
capture the os.Chmod error and report it through the test handle, such as
t.Errorf or t.Error. Ensure failures restoring each temporary directory’s
permissions are surfaced rather than discarded, while preserving the existing
cleanup behavior.
- Around line 58-72: Strengthen TestLoadBundle_NonexistentDirectory and
TestLoadPackage_NonexistentDirectory by asserting that each returned aggregate
error contains the expected filesystem walk failure from filepath.Walk, rather
than only checking that an error exists. Use the project’s existing
aggregate-error inspection and path-not-found cause symbols where available,
preserving the current nonexistent-directory setup.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 90ef4cd4-fd1e-4198-9a66-d133c660f646

📥 Commits

Reviewing files that changed from the base of the PR and between eb08d90 and c6c6b0c.

⛔ Files ignored due to path filters (220)
  • go.sum is excluded by !**/*.sum
  • staging/api/go.sum is excluded by !**/*.sum
  • staging/operator-lifecycle-manager/go.sum is excluded by !**/*.sum
  • staging/operator-registry/go.sum is excluded by !**/*.sum
  • vendor/github.com/containerd/containerd/version/version.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/docker/cli/AUTHORS is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/context_noslog.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/context_slog.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/funcr/funcr.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/funcr/slogsink.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/sloghandler.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/slogr.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/slogr/slogr.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/go-logr/logr/slogsink.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/cel/env.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/cel/folding.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/cel/library.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/cel/options.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/cel/program.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/cel/prompt.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/checker/cost.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/common/containers/container.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/common/functions/functions.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/common/runes/buffer.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/common/source.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/common/types/timestamp.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/common/types/unknown.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/BUILD.bazel is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/bindings.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/encoders.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/lists.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/network.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/ext/strings.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/BUILD.bazel is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/activation.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/attributes.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/decorators.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/frame.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/interpretable.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/interpreter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/planner.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/interpreter/runtimecost.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/google/cel-go/parser/unparser.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/grpc-ecosystem/grpc-health-probe/main.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/joelanford/ignore/.golangci.yml is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/joelanford/ignore/ignore.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/flate/dict_decoder.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/flate/inflate.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/huff0/build_table.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/internal/snapref/decode.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/dict.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_base.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_best.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_better.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_dfast.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_fast.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/enc_jobs.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/encoder.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/encoder_options.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_amd64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_asm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/fse_decoder_generic.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_amd64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_amd64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_arm64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_arm64.s is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_asm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/klauspost/compress/zstd/seqdec_generic.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/.coderabbit.yaml is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/callback.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3-binding.c is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3-binding.h is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3_load_extension.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3_opt_preupdate_hook.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3_opt_serialize.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/mattn/go-sqlite3/sqlite3_opt_vtable.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/api/pkg/manifests/bundleloader.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/api/pkg/manifests/packagemanifestloader.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-lifecycle-manager/util/cpb/main.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-registry/pkg/image/containersimageregistry/registry.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-registry/pkg/lib/bundle/chartutil.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-registry/pkg/lib/bundle/generate.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-registry/pkg/lib/indexer/indexer.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/operator-framework/operator-registry/pkg/sqlite/load.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/internal/github.com/golang/gddo/httputil/header/header.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/collectors/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/counter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/desc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/expvar_collector.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/gauge.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_go116.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/go_collector_latest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/histogram.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/internal/difflib.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/labels.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/metric.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_darwin.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/process_collector_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/http.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/instrument_server.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/promhttp/option.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/registry.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/summary.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/timer.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/vec.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/client_golang/prometheus/wrap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/Makefile.common is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/SECURITY.md is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/crypto.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/mountinfo.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/net_wireless.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/prometheus/procfs/proc_cgroup.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/bundle/jwtbundle/bundle.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/bundle/spiffebundle/bundle.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/bundle/spiffebundle/set.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/exp/bundle/witbundle/bundle.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/exp/bundle/witbundle/set.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/exp/bundle/witbundle/source.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/exp/svid/witsvid/source.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/exp/svid/witsvid/svid.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/proto/spiffe/workload/workload.pb.go is excluded by !**/*.pb.go, !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/proto/spiffe/workload/workload.proto is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/proto/spiffe/workload/workload_grpc.pb.go is excluded by !**/*.pb.go, !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/spiffetls/tlsconfig/config.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/svid/x509svid/svid.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/workloadapi/client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/workloadapi/convenience.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/workloadapi/option.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/workloadapi/watcher.go is excluded by !**/vendor/**, !vendor/**
  • vendor/github.com/spiffe/go-spiffe/v2/workloadapi/witsource.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/.gitattributes is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/.go-version is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/.golangci.yaml is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/Makefile is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/OWNERS is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/README.md is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/bucket.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/code-of-conduct.md is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/db.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/errors/errors.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/internal/common/page.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/internal/freelist/hashmap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/internal/freelist/shared.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/tx.go is excluded by !**/vendor/**, !vendor/**
  • vendor/go.etcd.io/bbolt/tx_check.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/armor/armor.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/errors/errors.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/packet/packet.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/read.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/crypto/openpgp/s2k/s2k.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/mod/modfile/read.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/mod/modfile/rule.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/net/http2/transport_wrap.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/net/idna/idna.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sync/semaphore/semaphore.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/cpu/parse.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_386.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_amd64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_arm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_arm64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_loong64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_mips64x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_mipsx.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_ppc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_ppc64x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_riscv64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_s390x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/syscall_linux_sparc64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zerrors_linux.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_386.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_amd64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_arm.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_arm64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_loong64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mips.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mips64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mips64le.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_mipsle.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_ppc.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_ppc64le.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_riscv64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_s390x.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/unix/zsyscall_linux_sparc64.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/windows/security_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/windows/syscall_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/sys/windows/types_windows.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/cases/context.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/cases/map.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/unicode/norm/forminfo.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/unicode/norm/iter.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/text/unicode/norm/normalize.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/go/packages/packages.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/gcimporter/iexport.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/gcimporter/iimport.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/imports/fix.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/imports/imports.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/stdlib/deps.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/stdlib/manifest.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/typesinternal/element.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/typesinternal/types.go is excluded by !**/vendor/**, !vendor/**
  • vendor/golang.org/x/tools/internal/typesinternal/zerovalue.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/envconfig/envconfig.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/transport/controlbuf.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_client.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/internal/transport/http2_server.go is excluded by !**/vendor/**, !vendor/**
  • vendor/google.golang.org/grpc/version.go is excluded by !**/vendor/**, !vendor/**
  • vendor/modules.txt is excluded by !**/vendor/**, !vendor/**
  • vendor/oras.land/oras-go/v2/content/reader.go is excluded by !**/vendor/**, !vendor/**
  • vendor/oras.land/oras-go/v2/errdef/errors.go is excluded by !**/vendor/**, !vendor/**
📒 Files selected for processing (38)
  • go.mod
  • manifests/0000_50_olm_01-networkpolicies.yaml
  • microshift-manifests/0000_50_olm_01-networkpolicies.yaml
  • staging/api/.github/workflows/go-verdiff.yaml
  • staging/api/.github/workflows/go.yaml
  • staging/api/.github/workflows/verify.yml
  • staging/api/go.mod
  • staging/api/pkg/manifests/bundleloader.go
  • staging/api/pkg/manifests/packagemanifestloader.go
  • staging/api/pkg/manifests/walkfunc_test.go
  • staging/operator-lifecycle-manager/.github/workflows/e2e-tests.yml
  • staging/operator-lifecycle-manager/.github/workflows/goreleaser.yaml
  • staging/operator-lifecycle-manager/.github/workflows/sanity.yaml
  • staging/operator-lifecycle-manager/.github/workflows/unit.yml
  • staging/operator-lifecycle-manager/deploy/chart/templates/0000_50_olm_01-networkpolicies.yaml
  • staging/operator-lifecycle-manager/go.mod
  • staging/operator-lifecycle-manager/pkg/controller/operators/catalog/operator_test.go
  • staging/operator-lifecycle-manager/util/cpb/main.go
  • staging/operator-registry/.github/workflows/build.yaml
  • staging/operator-registry/.github/workflows/go-apidiff.yaml
  • staging/operator-registry/.github/workflows/go-verdiff.yaml
  • staging/operator-registry/.github/workflows/goreleaser.yaml
  • staging/operator-registry/.github/workflows/sanity.yaml
  • staging/operator-registry/.github/workflows/test.yml
  • staging/operator-registry/.github/workflows/unit.yaml
  • staging/operator-registry/go.mod
  • staging/operator-registry/pkg/image/containersimageregistry/registry.go
  • staging/operator-registry/pkg/image/containersimageregistry/registry_test.go
  • staging/operator-registry/pkg/lib/bundle/chartutil.go
  • staging/operator-registry/pkg/lib/bundle/generate.go
  • staging/operator-registry/pkg/lib/bundle/generate_test.go
  • staging/operator-registry/pkg/lib/bundle/utils_test.go
  • staging/operator-registry/pkg/lib/bundle/validate_test.go
  • staging/operator-registry/pkg/lib/indexer/indexer.go
  • staging/operator-registry/pkg/prettyunmarshaler/prettyunmarshaler_test.go
  • staging/operator-registry/pkg/sqlite/directory_test.go
  • staging/operator-registry/pkg/sqlite/load.go
  • staging/operator-registry/pkg/sqlite/substitutesfor_cycle_test.go
🚧 Files skipped from review as they are similar to previous changes (9)
  • staging/operator-lifecycle-manager/.github/workflows/unit.yml
  • staging/operator-lifecycle-manager/.github/workflows/goreleaser.yaml
  • staging/operator-lifecycle-manager/.github/workflows/e2e-tests.yml
  • staging/operator-lifecycle-manager/.github/workflows/sanity.yaml
  • staging/operator-lifecycle-manager/util/cpb/main.go
  • microshift-manifests/0000_50_olm_01-networkpolicies.yaml
  • manifests/0000_50_olm_01-networkpolicies.yaml
  • staging/operator-lifecycle-manager/deploy/chart/templates/0000_50_olm_01-networkpolicies.yaml
  • staging/operator-lifecycle-manager/pkg/controller/operators/catalog/operator_test.go

walkErr := errors.New("permission denied")

err := loader.LoadBundleWalkFunc("some/path", nil, walkErr)
require.ErrorIs(t, err, walkErr)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add diagnostic messages to the assertions.

Several require calls omit failure messages, making failures in these new cases harder to diagnose. Add concise context to the ErrorIs, Len, Error, Contains, and Mkdir assertions.

As per coding guidelines, assertions should include meaningful failure messages.

Also applies to: 25-25, 33-33, 46-47, 54-55, 63-63, 71-71, 80-80, 85-85, 94-94, 99-99

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@staging/api/pkg/manifests/walkfunc_test.go` at line 17, The assertions in
walkfunc tests lack diagnostic context. Update the affected require.ErrorIs,
require.Len, require.Error, require.Contains, and require.Mkdir calls to include
concise, meaningful failure messages describing the expected condition, while
preserving their existing assertions and behavior.

Source: Coding guidelines

Comment on lines +58 to +72
func TestLoadBundle_NonexistentDirectory(t *testing.T) {
dir := filepath.Join(t.TempDir(), "nonexistent")

loader := NewBundleLoader(dir)
err := loader.LoadBundle()
require.Error(t, err)
}

func TestLoadPackage_NonexistentDirectory(t *testing.T) {
dir := filepath.Join(t.TempDir(), "nonexistent")

loader := NewPackageManifestLoader(dir)
err := loader.LoadPackage()
require.Error(t, err)
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Assert the specific walk failure, not just any error.

LoadBundle and LoadPackage can return unrelated validation errors, so require.Error alone does not prove that a nonexistent or inaccessible path error was propagated from filepath.Walk. Assert that the returned aggregate contains the expected walk-specific cause.

Also applies to: 74-100

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@staging/api/pkg/manifests/walkfunc_test.go` around lines 58 - 72, Strengthen
TestLoadBundle_NonexistentDirectory and TestLoadPackage_NonexistentDirectory by
asserting that each returned aggregate error contains the expected filesystem
walk failure from filepath.Walk, rather than only checking that an error exists.
Use the project’s existing aggregate-error inspection and path-not-found cause
symbols where available, preserving the current nonexistent-directory setup.

Comment thread staging/api/pkg/manifests/walkfunc_test.go
@grokspawn

Copy link
Copy Markdown
Contributor

/retest

  1. e2e-gcp-ovn — Infrastructure failure (not PR-related)
  • Cause: Pod scheduling timeout. — the CI pod sat in pending state for
    30 minutes and was never scheduled onto a build cluster node.
  • No test code ever ran. No artifacts or build logs were produced.
  • This is a transient CI infrastructure capacity issue.
  1. e2e-aws-upgrade-ovn-single-node — Unrelated test failures (not
    PR-related)
  • Overall result: 2121 pass, 8 blocking fail, 1 informing fail, 2161
    skip.
  • The 3 named failing tests are:
    • [sig-builds][Feature:Builds][timing] capture build stages and
      durations should record build stages and durations for docker
    • [sig-instrumentation][sig-builds][Feature:Builds]
      Prometheus...should start and expose a secured proxy and verify build
      metrics
    • [sig-network-edge][Conformance][Area:Networking][Feature:Router] The
      HAProxy router should pass the http2 tests

These are sig-builds and sig-network-edge (HAProxy router) tests — none
touch OLM, CatalogSource, operator-registry, or any code paths changed
by this PR.

@tmshort

tmshort commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

/test e2e-gcp-ovn

@tmshort

tmshort commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 24, 2026
@tmshort

tmshort commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

/retitle OCPBUGS-76752, OCPBUGS-96749: Synchronize From Upstream Repositories

The upstream moby updates fix these CVEs

@openshift-ci openshift-ci Bot changed the title NO-ISSUE: Synchronize From Upstream Repositories OCPBUGS-76752, OCPBUGS-96749: Synchronize From Upstream Repositories Jul 24, 2026
@openshift-ci-robot openshift-ci-robot added jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. labels Jul 24, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request references Jira Issue OCPBUGS-76752, which is invalid:

  • expected the bug to be open, but it isn't
  • expected the vulnerability to target either version "5.0." or "openshift-5.0.", but it targets "4.17.z" instead
  • expected the bug to be in one of the following states: NEW, ASSIGNED, POST, but it is Closed (Done-Errata) instead

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

This pull request references Jira Issue OCPBUGS-96749, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.0.0) matches configured target version for branch (5.0.0)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

The staging/ and vendor/ directories have been synchronized from the upstream repositories, pulling in the following commits:

Date Commit Author Message
2026-07-14 06:41:26 operator-framework/operator-lifecycle-manager@396954f dependabot[bot] 🌱 Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870)
2026-07-14 06:46:57 operator-framework/operator-lifecycle-manager@fdd5594 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869)
2026-07-14 10:46:25 operator-framework/operator-lifecycle-manager@a4f060a dependabot[bot] 🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868)
2026-07-15 10:15:40 operator-framework/operator-lifecycle-manager@174dccd Jordan Keister deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress (#3863)
2026-07-15 21:14:14 operator-framework/operator-lifecycle-manager@b0123be Chiman Jain Migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#3865)
2026-07-21 07:59:27 operator-framework/operator-lifecycle-manager@f59f6ec dependabot[bot] 🌱 Bump github.com/prometheus/client_golang (#3872)
2026-07-21 08:02:33 operator-framework/operator-lifecycle-manager@0a601aa dependabot[bot] Bump actions/setup-go from 6 to 7 (#3873)
2026-07-21 08:05:38 operator-framework/operator-lifecycle-manager@53c9aaa dependabot[bot] 🌱 Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3874)
2026-07-21 08:08:27 operator-framework/operator-lifecycle-manager@7d437b8 dependabot[bot] 🌱 Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#3875)
2026-07-23 20:28:05 operator-framework/operator-lifecycle-manager@0368a3f Jordan Keister chore: bump o-f deps (#3877)
2026-06-12 07:14:13 operator-framework/operator-registry@7d269bb dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#2009)
2026-06-15 07:45:11 operator-framework/operator-registry@98a7a1d dependabot[bot] Bump the k8s-dependencies group with 4 updates (#2010)
2026-06-15 07:47:40 operator-framework/operator-registry@8b4afca dependabot[bot] Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#2011)
2026-06-15 07:59:48 operator-framework/operator-registry@276ec06 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 (#2012)
2026-06-19 11:23:49 operator-framework/operator-registry@34f59d9 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.45 to 1.14.46 (#2013)
2026-06-19 11:26:38 operator-framework/operator-registry@c5ada4d dependabot[bot] Bump actions/checkout from 6 to 7 (#2014)
2026-06-19 11:29:19 operator-framework/operator-registry@84d62cf dependabot[bot] Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#2015)
2026-06-19 11:32:05 operator-framework/operator-registry@2219268 dependabot[bot] Bump github.com/docker/cli (#2016)
2026-06-22 07:13:46 operator-framework/operator-registry@1a822bd dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.47 (#2017)
2026-06-22 07:16:39 operator-framework/operator-registry@944d18b dependabot[bot] Bump go.etcd.io/bbolt from 1.4.3 to 1.5.0 (#2018)
2026-06-23 07:02:36 operator-framework/operator-registry@48f73d6 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 (#2019)
2026-06-24 12:25:16 operator-framework/operator-registry@55c06bd dependabot[bot] Bump github.com/joelanford/ignore from 0.1.1 to 0.1.2 (#2021)
2026-06-24 12:28:18 operator-framework/operator-registry@ab08265 dependabot[bot] Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#2022)
2026-06-25 16:13:02 operator-framework/operator-registry@13010cc Jordan Keister empty cred check failed to fall back (#2020)
2026-06-29 05:57:56 operator-framework/operator-registry@e79d272 dependabot[bot] Bump github.com/docker/cli (#2024)
2026-07-01 07:28:54 operator-framework/operator-registry@d2bf83f dependabot[bot] Bump google.golang.org/grpc from 1.81.1 to 1.82.0 (#2026)
2026-07-07 07:20:48 operator-framework/operator-registry@741b52e dependabot[bot] Bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-x-deps group (#2027)
2026-07-09 07:38:48 operator-framework/operator-registry@dbb3bd2 dependabot[bot] Bump the golang-x-deps group with 4 updates (#2028)
2026-07-09 07:44:25 operator-framework/operator-registry@eb78c9e dependabot[bot] Bump github.com/grpc-ecosystem/grpc-health-probe from 0.4.52 to 0.4.53 (#2030)
2026-07-09 09:08:40 operator-framework/operator-registry@f470500 dependabot[bot] Bump go.podman.io/common from 0.68.0 to 0.68.1 (#2029)
2026-07-10 03:48:01 operator-framework/operator-registry@8df27aa Chiman Jain Upgrade gopkg.in/yaml.v2 to go.yaml.in/yaml/v3 (#2023)
2026-07-10 07:32:11 operator-framework/operator-registry@fc2ca91 dependabot[bot] Bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#2031)
2026-07-13 07:17:48 operator-framework/operator-registry@798c576 dependabot[bot] Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#2032)
2026-07-14 06:41:25 operator-framework/operator-registry@6a6d882 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.47 to 1.14.48 (#2033)
2026-07-16 06:51:51 operator-framework/operator-registry@ce95ade dependabot[bot] Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#2035)
2026-07-17 08:12:20 operator-framework/operator-registry@ec5ca06 dependabot[bot] Bump github.com/docker/cli (#2036)
2026-07-17 08:15:10 operator-framework/operator-registry@37385d0 dependabot[bot] Bump actions/setup-go from 6 to 7 (#2037)
2026-07-23 16:26:18 operator-framework/operator-registry@f9556d7 Harald Klein Reject cyclic substitutesFor chains instead of looping until OOM (#2038)
2026-07-23 16:50:09 operator-framework/operator-registry@837bc5d Todd Short Bump github.com/moby/moby/client from v0.4.1 to v0.5.0 (#2039)
2026-07-23 19:28:03 operator-framework/operator-registry@19af4a3 Jordan Keister bump api to 0.45.0 (#2040)
2026-06-16 07:34:55 operator-framework/api@5adf634 dependabot[bot] Bump the k8s-dependencies group with 4 updates (#500)
2026-06-23 06:46:01 operator-framework/api@2b39c44 dependabot[bot] Bump actions/checkout from 6 to 7 (#501)
2026-06-26 13:57:32 operator-framework/api@492d6ba Lars Lehtonen pkg/manifests: fix dropped walk errors (#495)
2026-06-30 07:27:23 operator-framework/api@3c29466 dependabot[bot] Bump actions/cache from 5 to 6 (#502)
2026-07-06 07:30:57 operator-framework/api@23c932a dependabot[bot] Bump golang.org/x/net from 0.54.0 to 0.55.0 (#503)
2026-07-07 07:20:48 operator-framework/api@132f449 dependabot[bot] Bump github.com/google/cel-go from 0.28.1 to 0.29.1 (#504)
2026-07-14 06:41:25 operator-framework/api@c4902de dependabot[bot] Bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#505)
2026-07-21 07:56:33 operator-framework/api@72d46e1 dependabot[bot] Bump actions/setup-go from 6 to 7 (#506)

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Summary by CodeRabbit

  • New Features

  • Added network policies for catalog gRPC ingress and bundle unpacking egress.

  • Added validation to detect cyclic bundle substitution configurations.

  • Bug Fixes

  • Improved propagation of manifest traversal and filesystem errors.

  • Improved container registry authentication handling.

  • Prevented shared authentication context mutation during image pulls.

  • Maintenance

  • Updated dependencies, YAML processing, and CI workflow actions.

  • Added regression coverage for error handling, authentication, and substitution cycles.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@tmshort

tmshort commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

/retitle OCPBUGS-96752, OCPBUGS-96749: Synchronize From Upstream Repositories

Try again

@openshift-ci openshift-ci Bot changed the title OCPBUGS-76752, OCPBUGS-96749: Synchronize From Upstream Repositories OCPBUGS-96752, OCPBUGS-96749: Synchronize From Upstream Repositories Jul 24, 2026
@openshift-ci-robot openshift-ci-robot added jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. and removed jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. labels Jul 24, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request references Jira Issue OCPBUGS-96752, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.0.0) matches configured target version for branch (5.0.0)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)

The bug has been updated to refer to the pull request using the external bug tracker.

This pull request references Jira Issue OCPBUGS-96749, which is valid.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (5.0.0) matches configured target version for branch (5.0.0)
  • bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

The staging/ and vendor/ directories have been synchronized from the upstream repositories, pulling in the following commits:

Date Commit Author Message
2026-07-14 06:41:26 operator-framework/operator-lifecycle-manager@396954f dependabot[bot] 🌱 Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870)
2026-07-14 06:46:57 operator-framework/operator-lifecycle-manager@fdd5594 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869)
2026-07-14 10:46:25 operator-framework/operator-lifecycle-manager@a4f060a dependabot[bot] 🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868)
2026-07-15 10:15:40 operator-framework/operator-lifecycle-manager@174dccd Jordan Keister deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress (#3863)
2026-07-15 21:14:14 operator-framework/operator-lifecycle-manager@b0123be Chiman Jain Migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#3865)
2026-07-21 07:59:27 operator-framework/operator-lifecycle-manager@f59f6ec dependabot[bot] 🌱 Bump github.com/prometheus/client_golang (#3872)
2026-07-21 08:02:33 operator-framework/operator-lifecycle-manager@0a601aa dependabot[bot] Bump actions/setup-go from 6 to 7 (#3873)
2026-07-21 08:05:38 operator-framework/operator-lifecycle-manager@53c9aaa dependabot[bot] 🌱 Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3874)
2026-07-21 08:08:27 operator-framework/operator-lifecycle-manager@7d437b8 dependabot[bot] 🌱 Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#3875)
2026-07-23 20:28:05 operator-framework/operator-lifecycle-manager@0368a3f Jordan Keister chore: bump o-f deps (#3877)
2026-06-12 07:14:13 operator-framework/operator-registry@7d269bb dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#2009)
2026-06-15 07:45:11 operator-framework/operator-registry@98a7a1d dependabot[bot] Bump the k8s-dependencies group with 4 updates (#2010)
2026-06-15 07:47:40 operator-framework/operator-registry@8b4afca dependabot[bot] Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#2011)
2026-06-15 07:59:48 operator-framework/operator-registry@276ec06 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 (#2012)
2026-06-19 11:23:49 operator-framework/operator-registry@34f59d9 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.45 to 1.14.46 (#2013)
2026-06-19 11:26:38 operator-framework/operator-registry@c5ada4d dependabot[bot] Bump actions/checkout from 6 to 7 (#2014)
2026-06-19 11:29:19 operator-framework/operator-registry@84d62cf dependabot[bot] Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#2015)
2026-06-19 11:32:05 operator-framework/operator-registry@2219268 dependabot[bot] Bump github.com/docker/cli (#2016)
2026-06-22 07:13:46 operator-framework/operator-registry@1a822bd dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.47 (#2017)
2026-06-22 07:16:39 operator-framework/operator-registry@944d18b dependabot[bot] Bump go.etcd.io/bbolt from 1.4.3 to 1.5.0 (#2018)
2026-06-23 07:02:36 operator-framework/operator-registry@48f73d6 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 (#2019)
2026-06-24 12:25:16 operator-framework/operator-registry@55c06bd dependabot[bot] Bump github.com/joelanford/ignore from 0.1.1 to 0.1.2 (#2021)
2026-06-24 12:28:18 operator-framework/operator-registry@ab08265 dependabot[bot] Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#2022)
2026-06-25 16:13:02 operator-framework/operator-registry@13010cc Jordan Keister empty cred check failed to fall back (#2020)
2026-06-29 05:57:56 operator-framework/operator-registry@e79d272 dependabot[bot] Bump github.com/docker/cli (#2024)
2026-07-01 07:28:54 operator-framework/operator-registry@d2bf83f dependabot[bot] Bump google.golang.org/grpc from 1.81.1 to 1.82.0 (#2026)
2026-07-07 07:20:48 operator-framework/operator-registry@741b52e dependabot[bot] Bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-x-deps group (#2027)
2026-07-09 07:38:48 operator-framework/operator-registry@dbb3bd2 dependabot[bot] Bump the golang-x-deps group with 4 updates (#2028)
2026-07-09 07:44:25 operator-framework/operator-registry@eb78c9e dependabot[bot] Bump github.com/grpc-ecosystem/grpc-health-probe from 0.4.52 to 0.4.53 (#2030)
2026-07-09 09:08:40 operator-framework/operator-registry@f470500 dependabot[bot] Bump go.podman.io/common from 0.68.0 to 0.68.1 (#2029)
2026-07-10 03:48:01 operator-framework/operator-registry@8df27aa Chiman Jain Upgrade gopkg.in/yaml.v2 to go.yaml.in/yaml/v3 (#2023)
2026-07-10 07:32:11 operator-framework/operator-registry@fc2ca91 dependabot[bot] Bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#2031)
2026-07-13 07:17:48 operator-framework/operator-registry@798c576 dependabot[bot] Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#2032)
2026-07-14 06:41:25 operator-framework/operator-registry@6a6d882 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.47 to 1.14.48 (#2033)
2026-07-16 06:51:51 operator-framework/operator-registry@ce95ade dependabot[bot] Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#2035)
2026-07-17 08:12:20 operator-framework/operator-registry@ec5ca06 dependabot[bot] Bump github.com/docker/cli (#2036)
2026-07-17 08:15:10 operator-framework/operator-registry@37385d0 dependabot[bot] Bump actions/setup-go from 6 to 7 (#2037)
2026-07-23 16:26:18 operator-framework/operator-registry@f9556d7 Harald Klein Reject cyclic substitutesFor chains instead of looping until OOM (#2038)
2026-07-23 16:50:09 operator-framework/operator-registry@837bc5d Todd Short Bump github.com/moby/moby/client from v0.4.1 to v0.5.0 (#2039)
2026-07-23 19:28:03 operator-framework/operator-registry@19af4a3 Jordan Keister bump api to 0.45.0 (#2040)
2026-06-16 07:34:55 operator-framework/api@5adf634 dependabot[bot] Bump the k8s-dependencies group with 4 updates (#500)
2026-06-23 06:46:01 operator-framework/api@2b39c44 dependabot[bot] Bump actions/checkout from 6 to 7 (#501)
2026-06-26 13:57:32 operator-framework/api@492d6ba Lars Lehtonen pkg/manifests: fix dropped walk errors (#495)
2026-06-30 07:27:23 operator-framework/api@3c29466 dependabot[bot] Bump actions/cache from 5 to 6 (#502)
2026-07-06 07:30:57 operator-framework/api@23c932a dependabot[bot] Bump golang.org/x/net from 0.54.0 to 0.55.0 (#503)
2026-07-07 07:20:48 operator-framework/api@132f449 dependabot[bot] Bump github.com/google/cel-go from 0.28.1 to 0.29.1 (#504)
2026-07-14 06:41:25 operator-framework/api@c4902de dependabot[bot] Bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#505)
2026-07-21 07:56:33 operator-framework/api@72d46e1 dependabot[bot] Bump actions/setup-go from 6 to 7 (#506)

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Summary by CodeRabbit

  • New Features

  • Added network policies for catalog gRPC ingress and bundle unpacking egress.

  • Added validation to detect cyclic bundle substitution configurations.

  • Bug Fixes

  • Improved propagation of manifest traversal and filesystem errors.

  • Improved container registry authentication handling.

  • Prevented shared authentication context mutation during image pulls.

  • Maintenance

  • Updated dependencies, YAML processing, and CI workflow actions.

  • Added regression coverage for error handling, authentication, and substitution cycles.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@tmshort

tmshort commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

/test e2e-aws-upgrade-ovn-signle-node

@tmshort

tmshort commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

/test e2e-aws-upgrade-ovn-single-node

@openshift-bot openshift-bot changed the title OCPBUGS-96752, OCPBUGS-96749: Synchronize From Upstream Repositories NO-ISSUE: Synchronize From Upstream Repositories Jul 25, 2026
@openshift-ci-robot openshift-ci-robot removed jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-bug Indicates that a referenced Jira bug is valid for the branch this PR is targeting. labels Jul 25, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@openshift-bot: This pull request explicitly references no jira issue.

Details

In response to this:

The staging/ and vendor/ directories have been synchronized from the upstream repositories, pulling in the following commits:

Date Commit Author Message
2026-07-14 06:41:26 operator-framework/operator-lifecycle-manager@396954f dependabot[bot] 🌱 Bump golang.org/x/sync from 0.21.0 to 0.22.0 (#3870)
2026-07-14 06:46:57 operator-framework/operator-lifecycle-manager@fdd5594 dependabot[bot] 🌱 Bump github.com/prometheus/common from 0.69.0 to 0.70.0 (#3869)
2026-07-14 10:46:25 operator-framework/operator-lifecycle-manager@a4f060a dependabot[bot] 🌱 Bump golang.org/x/net from 0.56.0 to 0.57.0 (#3868)
2026-07-15 10:15:40 operator-framework/operator-lifecycle-manager@174dccd Jordan Keister deploy/chart: add static NetworkPolicies for CatalogSource gRPC ingress and bundle unpack egress (#3863)
2026-07-15 21:14:14 operator-framework/operator-lifecycle-manager@b0123be Chiman Jain Migrate deprecated gopkg.in/yaml.v3 to go.yaml.in/yaml/v3 (#3865)
2026-07-21 07:59:27 operator-framework/operator-lifecycle-manager@f59f6ec dependabot[bot] 🌱 Bump github.com/prometheus/client_golang (#3872)
2026-07-21 08:02:33 operator-framework/operator-lifecycle-manager@0a601aa dependabot[bot] Bump actions/setup-go from 6 to 7 (#3873)
2026-07-21 08:05:38 operator-framework/operator-lifecycle-manager@53c9aaa dependabot[bot] 🌱 Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 (#3874)
2026-07-21 08:08:27 operator-framework/operator-lifecycle-manager@7d437b8 dependabot[bot] 🌱 Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#3875)
2026-07-23 20:28:05 operator-framework/operator-lifecycle-manager@0368a3f Jordan Keister chore: bump o-f deps (#3877)
2026-06-12 07:14:13 operator-framework/operator-registry@7d269bb dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#2009)
2026-06-15 07:45:11 operator-framework/operator-registry@98a7a1d dependabot[bot] Bump the k8s-dependencies group with 4 updates (#2010)
2026-06-15 07:47:40 operator-framework/operator-registry@8b4afca dependabot[bot] Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#2011)
2026-06-15 07:59:48 operator-framework/operator-registry@276ec06 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.31.0 (#2012)
2026-06-19 11:23:49 operator-framework/operator-registry@34f59d9 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.45 to 1.14.46 (#2013)
2026-06-19 11:26:38 operator-framework/operator-registry@c5ada4d dependabot[bot] Bump actions/checkout from 6 to 7 (#2014)
2026-06-19 11:29:19 operator-framework/operator-registry@84d62cf dependabot[bot] Bump github.com/containerd/containerd from 1.7.32 to 1.7.33 (#2015)
2026-06-19 11:32:05 operator-framework/operator-registry@2219268 dependabot[bot] Bump github.com/docker/cli (#2016)
2026-06-22 07:13:46 operator-framework/operator-registry@1a822bd dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.46 to 1.14.47 (#2017)
2026-06-22 07:16:39 operator-framework/operator-registry@944d18b dependabot[bot] Bump go.etcd.io/bbolt from 1.4.3 to 1.5.0 (#2018)
2026-06-23 07:02:36 operator-framework/operator-registry@48f73d6 dependabot[bot] Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 (#2019)
2026-06-24 12:25:16 operator-framework/operator-registry@55c06bd dependabot[bot] Bump github.com/joelanford/ignore from 0.1.1 to 0.1.2 (#2021)
2026-06-24 12:28:18 operator-framework/operator-registry@ab08265 dependabot[bot] Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#2022)
2026-06-25 16:13:02 operator-framework/operator-registry@13010cc Jordan Keister empty cred check failed to fall back (#2020)
2026-06-29 05:57:56 operator-framework/operator-registry@e79d272 dependabot[bot] Bump github.com/docker/cli (#2024)
2026-07-01 07:28:54 operator-framework/operator-registry@d2bf83f dependabot[bot] Bump google.golang.org/grpc from 1.81.1 to 1.82.0 (#2026)
2026-07-07 07:20:48 operator-framework/operator-registry@741b52e dependabot[bot] Bump golang.org/x/text from 0.38.0 to 0.39.0 in the golang-x-deps group (#2027)
2026-07-09 07:38:48 operator-framework/operator-registry@dbb3bd2 dependabot[bot] Bump the golang-x-deps group with 4 updates (#2028)
2026-07-09 07:44:25 operator-framework/operator-registry@eb78c9e dependabot[bot] Bump github.com/grpc-ecosystem/grpc-health-probe from 0.4.52 to 0.4.53 (#2030)
2026-07-09 09:08:40 operator-framework/operator-registry@f470500 dependabot[bot] Bump go.podman.io/common from 0.68.0 to 0.68.1 (#2029)
2026-07-10 03:48:01 operator-framework/operator-registry@8df27aa Chiman Jain Upgrade gopkg.in/yaml.v2 to go.yaml.in/yaml/v3 (#2023)
2026-07-10 07:32:11 operator-framework/operator-registry@fc2ca91 dependabot[bot] Bump github.com/containerd/containerd from 1.7.33 to 1.7.34 (#2031)
2026-07-13 07:17:48 operator-framework/operator-registry@798c576 dependabot[bot] Bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#2032)
2026-07-14 06:41:25 operator-framework/operator-registry@6a6d882 dependabot[bot] Bump github.com/mattn/go-sqlite3 from 1.14.47 to 1.14.48 (#2033)
2026-07-16 06:51:51 operator-framework/operator-registry@ce95ade dependabot[bot] Bump google.golang.org/grpc from 1.82.0 to 1.82.1 (#2035)
2026-07-17 08:12:20 operator-framework/operator-registry@ec5ca06 dependabot[bot] Bump github.com/docker/cli (#2036)
2026-07-17 08:15:10 operator-framework/operator-registry@37385d0 dependabot[bot] Bump actions/setup-go from 6 to 7 (#2037)
2026-07-23 16:26:18 operator-framework/operator-registry@f9556d7 Harald Klein Reject cyclic substitutesFor chains instead of looping until OOM (#2038)
2026-07-23 16:50:09 operator-framework/operator-registry@837bc5d Todd Short Bump github.com/moby/moby/client from v0.4.1 to v0.5.0 (#2039)
2026-07-23 19:28:03 operator-framework/operator-registry@19af4a3 Jordan Keister bump api to 0.45.0 (#2040)
2026-06-16 07:34:55 operator-framework/api@5adf634 dependabot[bot] Bump the k8s-dependencies group with 4 updates (#500)
2026-06-23 06:46:01 operator-framework/api@2b39c44 dependabot[bot] Bump actions/checkout from 6 to 7 (#501)
2026-06-26 13:57:32 operator-framework/api@492d6ba Lars Lehtonen pkg/manifests: fix dropped walk errors (#495)
2026-06-30 07:27:23 operator-framework/api@3c29466 dependabot[bot] Bump actions/cache from 5 to 6 (#502)
2026-07-06 07:30:57 operator-framework/api@23c932a dependabot[bot] Bump golang.org/x/net from 0.54.0 to 0.55.0 (#503)
2026-07-07 07:20:48 operator-framework/api@132f449 dependabot[bot] Bump github.com/google/cel-go from 0.28.1 to 0.29.1 (#504)
2026-07-14 06:41:25 operator-framework/api@c4902de dependabot[bot] Bump github.com/google/cel-go from 0.29.1 to 0.29.2 (#505)
2026-07-21 07:56:33 operator-framework/api@72d46e1 dependabot[bot] Bump actions/setup-go from 6 to 7 (#506)

This pull request is expected to merge without any human intervention. If tests are failing here, changes must land upstream to fix any issues so that future downstreaming efforts succeed.

/assign @openshift/openshift-team-operator-runtime

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@dtfranz

dtfranz commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

/retest

@openshift-ci

openshift-ci Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

@openshift-bot: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-gcp-ovn c6c6b0c link true /test e2e-gcp-ovn

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants