Skip to content

chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.5.1 - #6845

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/siderolabs/image-factory-1.5.1
Open

chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.5.1#6845
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/go_modules/github.com/siderolabs/image-factory-1.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/siderolabs/image-factory from 1.3.3 to 1.5.1.

Release notes

Sourced from github.com/siderolabs/image-factory's releases.

v1.5.1

image-factory 1.5.1 (2026-08-25)

Welcome to the v1.5.1 release of image-factory!

Please try out the release binaries and report any issues at https://github.com/siderolabs/image-factory/issues.

Contributors

  • Andrey Smirnov
  • Noel Georgi
  • Mateusz Urbanek
  • Edward Sammut Alessi
  • Spencer Smith
  • Dmitrii Sharshakov
  • Maja Bojarska
  • Max Makarov
  • Dima Aratin
  • Evan Champion
  • Noel
  • Orzelius
  • Utku Ozdemir
  • dadbravo

Changes

  • 43adb19 release(v1.5.1): prepare release
  • 5f1f197 feat: update Talos to 1.14.0-rc.2
  • b7908c1 feat(enterprise): add Auth0 Management API client for node tokens
  • 36fedd7 feat: add WithBearerToken to include m2m token
  • e783a3d feat(frontend): preserve whitespace for vuln descriptions
  • 18f56f7 chore: make sure check-dirty also checks docs
  • 196a447 fix: enforce canonical image references
  • 26b95ca feat(enterprise): require auth0 clientID and clientSecret always
  • 25561f7 fix: retry put when joining a failed get flight
  • aab14ff feat: add spdx and vex reports to factory client
  • dc6a9f9 feat(enterprise): theme and translate Auth0 logout/login-error pages

Changes from siderolabs/pkgs

  • 13c7afc chore: update OpenZFS to 2.4.4

... (truncated)

Changelog

Sourced from github.com/siderolabs/image-factory's changelog.

image-factory 1.5.1 (2026-08-25)

Welcome to the v1.5.1 release of image-factory!

Please try out the release binaries and report any issues at https://github.com/siderolabs/image-factory/issues.

Contributors

  • Andrey Smirnov
  • Noel Georgi
  • Mateusz Urbanek
  • Edward Sammut Alessi
  • Spencer Smith
  • Dmitrii Sharshakov
  • Maja Bojarska
  • Max Makarov
  • Dima Aratin
  • Evan Champion
  • Noel
  • Orzelius
  • Utku Ozdemir
  • dadbravo

Changes

  • 5f1f197 feat: update Talos to 1.14.0-rc.2
  • b7908c1 feat(enterprise): add Auth0 Management API client for node tokens
  • 36fedd7 feat: add WithBearerToken to include m2m token
  • e783a3d feat(frontend): preserve whitespace for vuln descriptions
  • 18f56f7 chore: make sure check-dirty also checks docs
  • 196a447 fix: enforce canonical image references
  • 26b95ca feat(enterprise): require auth0 clientID and clientSecret always
  • 25561f7 fix: retry put when joining a failed get flight
  • aab14ff feat: add spdx and vex reports to factory client
  • dc6a9f9 feat(enterprise): theme and translate Auth0 logout/login-error pages

Changes from siderolabs/pkgs

  • 13c7afc chore: update OpenZFS to 2.4.4
  • 7cf25e7 feat: bump kernel to 6.18.46
  • 84c1b87 feat: backport aes256k support (Ceph)

... (truncated)

Commits
  • 43adb19 release(v1.5.1): prepare release
  • 5f1f197 feat: update Talos to 1.14.0-rc.2
  • b7908c1 feat(enterprise): add Auth0 Management API client for node tokens
  • 36fedd7 feat: add WithBearerToken to include m2m token
  • e783a3d feat(frontend): preserve whitespace for vuln descriptions
  • 18f56f7 chore: make sure check-dirty also checks docs
  • 196a447 fix: enforce canonical image references
  • 26b95ca feat(enterprise): require auth0 clientID and clientSecret always
  • 25561f7 fix: retry put when joining a failed get flight
  • aab14ff feat: add spdx and vex reports to factory client
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/siderolabs/image-factory](https://github.com/siderolabs/image-factory) from 1.3.3 to 1.5.1.
- [Release notes](https://github.com/siderolabs/image-factory/releases)
- [Changelog](https://github.com/siderolabs/image-factory/blob/main/CHANGELOG.md)
- [Commits](siderolabs/image-factory@v1.3.3...v1.5.1)

---
updated-dependencies:
- dependency-name: github.com/siderolabs/image-factory
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@ksail-bot
ksail-bot Bot enabled auto-merge (squash) September 2, 2026 19:28
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Success

✅ Linters with no issues

actionlint, bash-exec, git_diff, hadolint, jscpd, jsonlint, lychee, markdown-table-formatter, markdownlint, prettier, prettier, shellcheck, shfmt, stylelint, syft, trivy-sbom, trufflehog, v8r, v8r, yamllint

Notices

⚠️ Your configuration references items that have been removed from MegaLinter and are ignored: REPOSITORY_GITLEAKS. See Removed linters to find their replacements.

See detailed reports in MegaLinter artifacts

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Parked on a named blocker — recording it here, because this PR carried no blocker record.

Blocker: #6776 | last-verified 2026-09-02: still OPEN (blocked). Also
gated by #6728 (OPEN, blocked,dependencies).

Why this bump is affected even though it never mentions Talos. github.com/siderolabs/image-factory
depends transitively on siderolabs/talos/pkg/machinery, so bumping image-factory 1.3.3 → 1.5.1
pulls a machinery revision in which MachineConfig.Kubelet has been removed. That is exactly the
migration #6776 tracks.

Verified live on this PR's current head ffcc354f0c (run
33674595800, job 🔍 Dead Code Analysis):

  • pkg/fsutil/configmanager/talos/configs.go:615 and :619, and version.go:244
    cp.Machine().Kubelet undefined (… MachineConfig has no field or method Kubelet)Migrate off the removed Talos MachineConfig.Kubelet / ClusterConfig.CoreDNS accessors #6776, ours to migrate.
  • loft-sh/apiserver*DefaultStorageStrategy does not implement rest.RESTUpdateStrategy (wrong type for method AllowCreateOnUpdate) → external.
  • k8s.io/cri-client*remoteRuntimeService does not implement apis.RuntimeService (missing method CheckpointPod) → external.

Why it cannot self-progress. The branch is DIRTY, and Dependabot has forfeited rebase on it
(a ksail-bot sync commit landed, so it reports the branch as edited by someone other than
Dependabot — tracked in #6832). Auto-merge is armed (2026-09-02T19:28:48Z, SQUASH), but an armed
auto-merge can never fire on a conflicting branch, so the arming is not evidence of progress here.

Not actionable as a rebase or a recreate. @dependabot recreate would rebuild the bump onto
current main, but the three compile failures above are properties of the dependency graph rather
than of the merge state, so a clean rebuild would fail identically. Adding the blocked label so
future runs skip it on a re-verifiable record rather than re-deriving this each tick.

Unblocks when #6776 lands.

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Parked on a named, live-verified blocker: #6728 — same root cause as #6826, reached by a different route.

image-factory 1.5.1 constrains talos/pkg/machinery forward, so this PR lands in the same unsatisfiable corner the talos group bump does. Its build fails on both halves of #6728's ceiling:

  • First-party: pkg/fsutil/configmanager/talos/configs.go:615, :619 and version.go:244MachineConfig.Kubelet no longer exists in machinery v1.14.
  • vcluster stack: loft-sh/apiserver does not satisfy k8s.io/apiserver v0.37's rest.RESTUpdateStrategy (AllowCreateOnUpdate gained a context.Context parameter).

A rebase will not fix this one. Worth stating explicitly, because #6839 sitting alongside it is rebase-fixable — its only failing check is 🛡️ Vulnerability Scan against the old x/crypto pin, which main has since resolved. The two look similar in the PR list and are not the same problem: #6839 fails one check on a stale base, this fails ~40 because the dependency change itself does not compile.

Live-verified today (module proxy): loft-sh/apiserver latest is still the 2026-07-07 pseudo-version — the release this needs does not exist. talos/pkg/machinery stable is v1.13.9.

Control: 🏗️ Build (Linux) and 🏗️ Build + cask (macOS) pass on #6847 and #6839, so the desktop build is healthy on current main and these failures belong to this bump.

Left open and parked; it becomes mergeable once the vcluster stack supports k8s 0.37.

@devantler
devantler marked this pull request as draft September 3, 2026 07:13
auto-merge was automatically disabled September 3, 2026 07:13

Pull request was converted to draft

@devantler
devantler marked this pull request as ready for review September 3, 2026 07:18
@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Attempted a base-update rescue, aborted it, and re-confirmed the park on #6728

Sibling PR #6839 was rescued this tick by a plain branch update — its only red check was a
base-drift 🛡️ Vulnerability Scan, fixed once main's x/crypto v0.56.0 came across. I tried
the same here and it does not apply: this PR's failures are real, not drift.

What I did, so the state change is on the record: converted to draft (which also dropped the
auto-merge ksail-bot had armed — that arming could never have fired, since CI - Required Checks
was already failing), attempted update-branch, hit conflicts, resolved them the sanctioned way for
generated files — took main's side of go.mod/go.sum, re-applied this PR's own bump, re-ran
go mod tidy — then built the result and aborted the merge when it failed. Nothing was pushed;
the branch is untouched and back to ready for review. Auto-merge remains off.

Why it cannot be rescued mechanically. The local build failed with the same signature as this
PR's own CI, which is what makes this a dependency-graph problem rather than a merge artifact:

signature this PR's CI 🏗️ Build my local resolution
MachineConfig has no field or method Kubelet ×3 ×3
AllowCreateOnUpdate wrong signature ×6 ×6

Both hit pkg/fsutil/configmanager/talos/configs.go:615,619 and version.go:244, which call
Machine().Kubelet(). main pins talos/pkg/machinery v1.14.0-alpha.2; the bump pulls machinery
past the point where Kubelet was moved off MachineConfig. The second signature is the separate
loft-sh/apiserver vs k8s.io/apiserver mismatch.

That is exactly the chain already documented in #6728, which stays the named blocker. Re-verified
live today: #6728 is open, and both signatures still reproduce at this head. Correctly parked — no
further mechanical retry is worth a tick.

Also worth recording, since it cost time on #6839: @dependabot recreate is silently dropped on a
branch Dependabot has disowned. It was issued twice there (once bare, once fenced, ~8h apart) and
never answered, while @dependabot rebase drew a refusal in 4 seconds both times — so the command,
not the formatting, is the discriminator, and the refusal text advertising recreate as the remedy
is misleading. #6851 addresses the mechanism that disowns these branches in the first place.

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

This bump is still wanted — main is on image-factory v1.3.3 and this branch carries v1.5.1 — but the branch has been conflicting with main since 2026-09-03, which is why every required check is failing rather than anything about the dependency itself. It cannot reach merge without a refresh, so requesting the bot's own rebase as the least invasive repair.

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Following up on my own rebase request above, which was rejected — Dependabot replied that the branch "has been edited by someone other than Dependabot", so it cannot rebase this PR. That is a permanent property of the branch, not a transient failure: ksail-bot[bot] pushed a generated-file sync onto it, and Dependabot forfeits rebase for good once that happens. Re-requesting a rebase here cannot succeed — the only bot-side recovery is @dependabot recreate, which discards the branch and opens it fresh.

I should also have led with the blocker rather than the conflict. The conflict is a symptom; the reason this PR cannot land is #6728omni/client 1.10.4 is unsatisfiable while Talos beta.1 needs k8s 0.37 and the vcluster stack pins 0.36. Until that is resolved, a rebase would produce a clean branch that still cannot build, so it would not have moved this PR to merge even had it worked.

Leaving this parked on #6728, which is the correct terminal state. No action needed.

@dependabot @github

dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of github.com/siderolabs/image-factory exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Blocker: #6776 | last-verified 2026-09-04: still OPEN (blocked) — not shipped

Re-verified live this run rather than inherited from the 2026-09-02 record. #6776 ("Migrate off the
removed Talos MachineConfig.Kubelet / ClusterConfig.CoreDNS accessors") remains open and
blocked-labelled, so the accessor migration this bump depends on has not landed.

Terminal state unchanged: parked on a named, live-verified blocker. mergeStateStatus is DIRTY,
38 checks are failing, and Dependabot has forfeited the rebase on this branch, so the head cannot
self-heal — no action is available here until #6776 lands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: 🫴 Ready

Development

Successfully merging this pull request may close these issues.

1 participant