Commit Graph

874 Commits

Author SHA1 Message Date
cert-manager-prow[bot]
e930ea76fb
Merge pull request #7877 from erikgb/bump-depnendencies
Bump most direct dependencies to their latest release
2025-07-26 10:43:47 +00:00
Erik Godding Boye
069f38faa9
Bump most direct dependencies to their latest release
Signed-off-by: Erik Godding Boye <egboye@gmail.com>
2025-07-23 21:17:07 +02:00
hjoshi123
021a9a49e1
added cert collector and moved unit test
Signed-off-by: hjoshi123 <mail@hjoshi.me>
2025-07-20 15:28:52 -06:00
Tim Ramlot
2032911ed8
refactor ACME registry (part 1)
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-07-09 00:21:39 +02:00
hjoshi123
2558e46a3b
added collector for cert challenge and unit, integrationt test
Signed-off-by: hjoshi123 <hemant.joshi@vizio.com>
2025-07-07 15:15:12 -06:00
Tim Ramlot
ba367e5baa
use licenses makefile module to generate LICENSES files
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-07-04 15:38:36 +02:00
Tim Ramlot
25bd23091d
use sigs.k8s.io/randfill instead of github.com/google/gofuzz
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-06-06 16:11:48 +02:00
Tim Ramlot
ad3b6fbcef
upgrade go dependencies
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-06-06 16:11:48 +02:00
Tim Ramlot
d72df08425
bump go 1.24.0 and fix 'usetesting' linter
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-06-05 03:16:46 +02:00
Richard Wall
a42312a8f5 go get golang.org/x/crypto@v0.38.0
I ran the following commands:

 go get golang.org/x/crypto@v0.38.0
 make go-tidy generate-licenses

Signed-off-by: Richard Wall <richard.wall@cyberark.com>
2025-06-03 20:33:17 +01:00
Richard Wall
d7090f55e7 Fork the golang.org/x/crypto/acme package into cert-manager third_party
Using klone

Signed-off-by: Richard Wall <richard.wall@venafi.com>
2025-06-03 20:21:20 +01:00
Josh Soref
5ad454a65d spelling: e.g.
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2025-05-07 22:05:43 -04:00
cert-manager-bot
73cefcea26 BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
2025-05-05 13:36:01 +00:00
cert-manager-bot
715d42bd02 BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
2025-05-02 00:27:36 +00:00
Richard Wall
d9c69a6d9e make generate-licenses
Signed-off-by: Richard Wall <richard.wall@venafi.com>
2025-04-17 11:49:58 +01:00
dependabot[bot]
257a41dbe4
build(deps): bump the go_modules group across 8 directories with 1 update
Bumps the go_modules group with 1 update in the / directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/acmesolver directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/cainjector directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/controller directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/startupapicheck directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/webhook directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /test/e2e directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /test/integration directory: [golang.org/x/net](https://github.com/golang/net).


Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

Updates `golang.org/x/net` from 0.36.0 to 0.38.0
- [Commits](https://github.com/golang/net/compare/v0.36.0...v0.38.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-version: 0.38.0
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-04-16 23:23:15 +00:00
Tero Saarni
11baa07851 Allow disabling experimental CSR controllers
Signed-off-by: Tero Saarni <tero.saarni@est.tech>
2025-04-14 18:11:23 +03:00
cert-manager-prow[bot]
dae91eee5b
Merge pull request #7678 from Nordix/namespaced-fix
Fix behavior when running with --namespace=<namespace>
2025-04-14 11:53:46 +00:00
cert-manager-prow[bot]
380c8ae706
Merge pull request #7638 from NicholasBlaskey/patch_cves
Patch CVE CVE-2025-30204 and CVE-2025-22868
2025-04-12 23:34:44 +00:00
Erik Godding Boye
b90118f1ab
Make DynamicAuthority CN and secret labels configurable
Signed-off-by: Erik Godding Boye <egboye@gmail.com>
2025-04-12 17:49:59 +02:00
Tero Saarni
105d90d5eb Fix behavior when running with --namespace=<namespace>
- Disable controllers that require cluster-scoped RBAC permissions by design.
- In the self-signed issuer, skip listing ClusterIssuer resources to respect
  the --namespace parameter and prevent the need for unnecessary cluster-wide
  RBAC permissions.

Signed-off-by: Tero Saarni <tero.saarni@est.tech>
2025-04-11 20:56:36 +03:00
Tim Ramlot
e2c81c9708
run 'make generate-licenses'
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-04-11 08:26:17 +00:00
Nick Blaskey
d469a779ad
Bump crypto library to patch CVE-2025-22869
Signed-off-by: Nick Blaskey <nblaskey@amazon.com>
2025-04-11 08:25:31 +00:00
Nick Blaskey
de468abb47
Bump oauth library to patch CVE-2025-22868
Signed-off-by: Nick Blaskey <nblaskey@amazon.com>
2025-04-11 08:23:03 +00:00
Nick Blaskey
5d63628504
Bump jwt library to patch CVE-2025-30204
Signed-off-by: Nick Blaskey <nblaskey@amazon.com>
2025-04-11 08:20:25 +00:00
cert-manager-prow[bot]
c19d4696c3
Merge pull request #7619 from cert-manager/dependabot/go_modules/go_modules-6560020d2a
build(deps): bump the go_modules group across 8 directories with 1 update
2025-04-11 08:18:43 +00:00
Tim Ramlot
077352f2a7
run 'make generate-licenses'
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-04-11 07:51:14 +00:00
Dinar Valeev
e644d20222
ingress-shim: optionally copy specific annotation
This commit introduces an ingress-shim option:
--extra-certificate-annotations which sets list of annotation keys to be copied
from IngLike to resulting Certificate object

Co-authored-by: Ashley Davis <SgtCoDFish@users.noreply.github.com>
Signed-off-by: Dinar Valeev <k0da@opensuse.org>
2025-03-21 10:08:35 +01:00
dependabot[bot]
99ed5c2121
build(deps): bump the go_modules group across 8 directories with 1 update
Bumps the go_modules group with 1 update in the / directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/acmesolver directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/cainjector directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/controller directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/startupapicheck directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /cmd/webhook directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /test/e2e directory: [golang.org/x/net](https://github.com/golang/net).
Bumps the go_modules group with 1 update in the /test/integration directory: [golang.org/x/net](https://github.com/golang/net).


Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

Updates `golang.org/x/net` from 0.33.0 to 0.36.0
- [Commits](https://github.com/golang/net/compare/v0.33.0...v0.36.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/net
  dependency-type: indirect
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-03-13 01:33:22 +00:00
Ashley Davis
a161067f0f
bump go-jose to address CVE-2025-27144
Signed-off-by: Ashley Davis <ashley.davis@cyberark.com>
2025-03-05 14:47:33 +00:00
cert-manager-prow[bot]
f754d975cd
Merge pull request #7554 from jsoref/spelling
Spelling
2025-02-19 09:58:36 +00:00
Josh Soref
efc380a480 spelling: kubernetes
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2025-02-18 13:20:13 -05:00
Josh Soref
daf7e33252 spelling: cainjector
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2025-02-18 13:17:02 -05:00
cert-manager-prow[bot]
5a7dba91a2
Merge pull request #7553 from SgtCoDFish/remote-validate-caa
Remove ValidateCAA code, leaving a warning
2025-02-10 10:57:27 +00:00
cert-manager-prow[bot]
a0ea1915b1
Merge pull request #7284 from AdamKorcz/add-validation-fuzzers
cr approval: add fuzz test
2025-02-06 13:38:43 +00:00
cert-manager-prow[bot]
f21438aa60
Merge pull request #7405 from AdamKorcz/process-item-fuzzer
add fuzz tests for ProcessItem APIs
2025-02-06 12:16:43 +00:00
Ashley Davis
07ab66c75d
remove ValidateCAA code, leaving a warning
Signed-off-by: Ashley Davis <ashley.davis@cyberark.com>
2025-02-05 15:52:56 +00:00
cert-manager-prow[bot]
c94079cf65
Merge pull request #7500 from minus7/acmeresolver-exit
acmesolver: Fix error message on successful exit
2025-01-30 09:58:27 +00:00
cert-manager-prow[bot]
c003da2560
Merge pull request #7428 from jsoref/shorten-skipping-controller-messages
Simplify skipping controller messages
2025-01-28 10:27:29 +00:00
cert-manager-prow[bot]
b96e0af16d
Merge pull request #7491 from jsoref/deprecate-ValidateCAA
Deprecate ValidateCAA
2025-01-08 14:26:38 +00:00
Josh Soref
5bfa94c871 Deprecate ValidateCAA
Plan to remove it in 1.18

Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2025-01-07 08:32:52 -05:00
Thomas Renoth
92f8c1e2b4 acmesolver: Fix error message on successful exit
Signed-off-by: Thomas Renoth <thomas.renoth@authenticvision.com>
2025-01-07 14:30:04 +01:00
Tim Ramlot
c24fe6f9fd
upgrade vcert to v5.8.0
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2025-01-07 09:34:34 +00:00
Adam Korczynski
8ac1c7835e add fuzz tests for ProcessItem APIs
Signed-off-by: Adam Korczynski <adam@adalogics.com>
2025-01-03 13:26:52 +00:00
Adam Korczynski
d5e1ba3640 fix lint issues
Signed-off-by: Adam Korczynski <adam@adalogics.com>
2025-01-03 13:23:32 +00:00
Alex Ellwein
4bcac4a77b
chore: regenerate LICENSES
Signed-off-by: Alex Ellwein <alex.ellwein@gmail.com>
2025-01-02 15:32:50 +01:00
Alex Ellwein
228d5c4968
chore(deps): bump k8s.io/api and client-go to 0.32.0
Some adjustments were needed because the pkg/util/version was
[moved](4bece4d457 (diff-33ef32bf6c23acb95f5902d7097b7a1d5128ca061167ec0716715b0b9eeaa5f6L55))
to k8s.io/component-base.

Signed-off-by: Alex Ellwein <alex.ellwein@gmail.com>
2024-12-22 14:33:28 +01:00
Tim Ramlot
bba49fac51
Bump the go_modules group across 7 directories with 1 update
Bumps the go_modules group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go_modules group with 1 update in the /cmd/cainjector directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go_modules group with 1 update in the /cmd/controller directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go_modules group with 1 update in the /cmd/startupapicheck directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go_modules group with 1 update in the /cmd/webhook directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go_modules group with 1 update in the /test/e2e directory: [golang.org/x/crypto](https://github.com/golang/crypto).
Bumps the go_modules group with 1 update in the /test/integration directory: [golang.org/x/crypto](https://github.com/golang/crypto).

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

Updates `golang.org/x/crypto` from 0.27.0 to 0.31.0
- [Commits](https://github.com/golang/crypto/compare/v0.27.0...v0.31.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: indirect
  dependency-group: go_modules
- dependency-name: golang.org/x/crypto
  dependency-type: direct:production
  dependency-group: go_modules
...

Signed-off-by: dependabot[bot] <support@github.com>
2024-12-13 14:15:19 +00:00
Tim Ramlot
f958e8c88f
Add Shutdown function to KubeInformerFactory interface and call Shutdown on shutdown
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
2024-12-04 10:46:37 +00:00
Josh Soref
4d3afe0764 Simplify skipping controller messages
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
2024-11-19 10:23:06 -05:00