chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.5.1 - #6845
chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.5.1#6845dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [github.com/siderolabs/image-factory](https://github.com/siderolabs/image-factory) from 1.3.3 to 1.5.1. - [Release notes](https://github.com/siderolabs/image-factory/releases) - [Changelog](https://github.com/siderolabs/image-factory/blob/main/CHANGELOG.md) - [Commits](siderolabs/image-factory@v1.3.3...v1.5.1) --- updated-dependencies: - dependency-name: github.com/siderolabs/image-factory dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
✅MegaLinter analysis: Success✅ Linters with no issuesactionlint, bash-exec, git_diff, hadolint, jscpd, jsonlint, lychee, markdown-table-formatter, markdownlint, prettier, prettier, shellcheck, shfmt, stylelint, syft, trivy-sbom, trufflehog, v8r, v8r, yamllint Notices
See detailed reports in MegaLinter artifacts
|
Parked on a named blocker — recording it here, because this PR carried no blocker record. Blocker: #6776 | last-verified 2026-09-02: still OPEN ( Why this bump is affected even though it never mentions Talos. Verified live on this PR's current head
Why it cannot self-progress. The branch is Not actionable as a rebase or a recreate. Unblocks when #6776 lands. |
Parked on a named, live-verified blocker: #6728 — same root cause as #6826, reached by a different route.
A rebase will not fix this one. Worth stating explicitly, because #6839 sitting alongside it is rebase-fixable — its only failing check is Live-verified today (module proxy): Control: Left open and parked; it becomes mergeable once the vcluster stack supports k8s 0.37. |
Pull request was converted to draft
Attempted a base-update rescue, aborted it, and re-confirmed the park on #6728Sibling PR #6839 was rescued this tick by a plain branch update — its only red check was a What I did, so the state change is on the record: converted to draft (which also dropped the Why it cannot be rescued mechanically. The local build failed with the same signature as this
Both hit That is exactly the chain already documented in #6728, which stays the named blocker. Re-verified Also worth recording, since it cost time on #6839: |
This bump is still wanted — @dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
Following up on my own rebase request above, which was rejected — Dependabot replied that the branch "has been edited by someone other than Dependabot", so it cannot rebase this PR. That is a permanent property of the branch, not a transient failure: I should also have led with the blocker rather than the conflict. The conflict is a symptom; the reason this PR cannot land is #6728 — Leaving this parked on #6728, which is the correct terminal state. No action needed. |
|
A newer version of github.com/siderolabs/image-factory exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Blocker: #6776 | last-verified 2026-09-04: still OPEN ( Re-verified live this run rather than inherited from the 2026-09-02 record. #6776 ("Migrate off the Terminal state unchanged: parked on a named, live-verified blocker. |

Bumps github.com/siderolabs/image-factory from 1.3.3 to 1.5.1.
Release notes
Sourced from github.com/siderolabs/image-factory's releases.
... (truncated)
Changelog
Sourced from github.com/siderolabs/image-factory's changelog.
... (truncated)
Commits
43adb19release(v1.5.1): prepare release5f1f197feat: update Talos to 1.14.0-rc.2b7908c1feat(enterprise): add Auth0 Management API client for node tokens36fedd7feat: add WithBearerToken to include m2m tokene783a3dfeat(frontend): preserve whitespace for vuln descriptions18f56f7chore: make sure check-dirty also checks docs196a447fix: enforce canonical image references26b95cafeat(enterprise): require auth0 clientID and clientSecret always25561f7fix: retry put when joining a failed get flightaab14fffeat: add spdx and vex reports to factory clientDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)