Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/cert-manager/cert-manager

Automatically provision and manage TLS certificates in Kubernetes
https://github.com/cert-manager/cert-manager

Move critical from NameConstraintItem to NameConstraint and remove validateNameConstraints

Signed-off-by: tanujd11 <[email protected]>

d1b3e5ca83d56f4c950a5e94f758cc2e28abba5e authored about 1 year ago by tanujd11 <[email protected]>
validate name constraint before signing CSR

Signed-off-by: tanujd11 <[email protected]>

adb9311f56f7459c6aff60f4fbd3cb6947679030 authored about 1 year ago by tanujd11 <[email protected]>
nits: added new line at EOF and comment fix

Signed-off-by: tanujd11 <[email protected]>

50d84c1bbc832bf211b72adb2fdd12a64b7bc82a authored about 1 year ago by tanujd11 <[email protected]>
feature: added name constraints

Signed-off-by: tanujd11 <[email protected]>

589030dec1bbe4a8da82d03aecc8d5d6a1f3b43f authored about 1 year ago by tanujd11 <[email protected]>
Merge pull request #6534 from wallrj/server-timeout

Mitigate potential Slowloris attacks by setting ReadHeaderTimeout in all http.Server instances

e7e3e5f4de14e5309c068337e848d93b7a2f07be authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6535 from inteon/cleanup_generate_csr

Refactor GenerateCSR and deprecate the helper functions

5484a92df8d84ca9c905f5a467b1ba60733908d8 authored about 1 year ago by jetstack-bot <[email protected]>
Add ReadHeaderTimeout to all http.Server where that setting is missing

Signed-off-by: Richard Wall <[email protected]>

8bed16685845428af3989753bf16780f43e5829c authored about 1 year ago by Richard Wall <[email protected]>
refactor GenerateCSR and deprecated the helper functions

Signed-off-by: Tim Ramlot <[email protected]>

767764d598128ccd2f4835c0f4225ca2b77abb1e authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6533 from inteon/cleanup_literal_subject_validation

BUGFIX: LiteralCertificateSubject webhook logic

4209de23716562f44f3f7295b1f162bbb69f6ccd authored about 1 year ago by jetstack-bot <[email protected]>
LiteralCertificateSubject: improve webhook logic

Signed-off-by: Tim Ramlot <[email protected]>

c5d7f15aa17a242af88364c23e4d822528515ec7 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6531 from inteon/rename_fields_internal_api

Rename internal API fields to match the field names in the public API

40951826ab7062a98a92a400d4a1fb19624bbd13 authored about 1 year ago by jetstack-bot <[email protected]>
rename internal API fields to match the fieldnames in the public API

Signed-off-by: Tim Ramlot <[email protected]>

25eec9514a6e10fa4bde8a7b2e37703368671ec9 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6519 from JoeNorth/master

Update AWS SDK for Go to 1.48.7

202a80e2184b1b479dbb5d03f32aafc4b2c811b9 authored about 1 year ago by jetstack-bot <[email protected]>
run 'make tidy' and 'make update-licenses'

Signed-off-by: Tim Ramlot <[email protected]>

63c1636a839eea58ddd27ce6aa2b809425386ba6 authored about 1 year ago by Tim Ramlot <[email protected]>
Update AWS SDK for Go version

Signed-off-by: Joe North <[email protected]>

4e03eb12831550ddf25fbe4faab61acdcf5db620 authored about 1 year ago by Joe North <[email protected]>
Merge pull request #6491 from inteon/pprof_non_leaders

BUGFIX: run pprof server on non-leaderelected replicas

e47444db80039a310069d4c05cf1a54cd9684b4d authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6517 from inteon/use_pkcs12_legacyrc2

Replace deprecated pkcs12 function call with pkcs12.LegacyRC2

554ceac1c8b7f7ca739a3038f1e530f4a18ac0d7 authored about 1 year ago by jetstack-bot <[email protected]>
replace deprecated pkcs12 function call with pkcs12.LegacyRC2

Signed-off-by: Tim Ramlot <[email protected]>

6f7ebbed7b7b566e506640eccb145d50005b9df6 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6512 from inteon/bump_jose

Bump the go-jose dependency

cc40c405d6cd49784f74a4fc844b0e305429b300 authored about 1 year ago by jetstack-bot <[email protected]>
bump the go-jose dependency

Signed-off-by: Tim Ramlot <[email protected]>

99d473bbf1e27bdec47a5981001a76d1fe0a8085 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6498 from inteon/fix_webhook_bug

BUGFIX: Limit webhook admission input

630dba760af27b38daa778694bf3f958a1e5ad23 authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6499 from avi-08/fix-helm-controller-featuregates

Fix controller feature gates config in helm

0e5f9c679d418d98b785e35889ca1b06a0f8f119 authored about 1 year ago by jetstack-bot <[email protected]>
Fix controller feautregates config in helm

Signed-off-by: Avi Sharma <[email protected]>

c72fc2877304dd091f707fdf8551df0c9ec46154 authored about 1 year ago by Avi Sharma <[email protected]>
Merge pull request #6347 from lauraseidler/fix/gateway-warning-http

Do not process Gateway listeners that do not support TLS

c9e028f3dbc8be3e3036e88b0e31cc97e6cc3c0d authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6497 from SgtCoDFish/bestpractices

Add Core Infrastructure Initiative Best Practices badge

30205eab8541346863a141c6359741739ddece48 authored about 1 year ago by jetstack-bot <[email protected]>
limit webhook admission input

Signed-off-by: Tim Ramlot <[email protected]>

073d90611e7f6d5c1f916c1c5e0cb25ed28f66ae authored about 1 year ago by Tim Ramlot <[email protected]>
Add Core Infrastructure Initiative Best Practices badge

I filled out the form on the CII site and they gave us a badge!

This is part of the work toward...

d25471e58d7555c6e64bbdefe3685cc4a792d74d authored about 1 year ago by Ashley Davis <[email protected]>
Merge pull request #6495 from wallrj/6482-startupapicheck-verbose-logging

Enable verbose logging in startupapicheck by default

7dca7210e799f84446aac168e5ff2a0f02734435 authored about 1 year ago by jetstack-bot <[email protected]>
Enable verbose logging in startupapicheck by default

So that if it fails, users can know exactly what caused the failure.

Signed-off-by: Richard Wal...

a2ca3c714f5490beebe231c8e4af4784fa5c71de authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6486 from jeremycampbell-okta/caissuers-extension

Add x509 v3 CA Issuers Extension

c4aa1ec50b0938a8a025e6a8f625c23a39bece2b authored about 1 year ago by jetstack-bot <[email protected]>
Add x509 v3 CA Issuers Extension

Signed-off-by: Jeremy Campbell <[email protected]>

dc876fef16bc44ca783fe12fedb2220cb753660a authored about 1 year ago by Jeremy Campbell <[email protected]>
Merge pull request #6459 from shlomitubul/master

feat(helm) Add support for PodMonitor

b0ed33341340f4248f926fb7984a3949c982e194 authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6488 from wallrj/increase-default-webhook-timeout

Increase the default webhook timeout to its maximum value of 30 seconds

b4c3b313d43fe4c0b6f72187ae42bc52cc3703ee authored about 1 year ago by jetstack-bot <[email protected]>
BUGFIX: run pprof server on non-leaderelected replicas

Signed-off-by: Tim Ramlot <[email protected]>

05de99458770996f9c88b9765e7dbcb489d70949 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6490 from inteon/fix_cve_alert

Bump docker to fix cve alert

8c7615f89695e5a8a12d21683ae3144906c4240d authored about 1 year ago by jetstack-bot <[email protected]>
bump docker to fix cve alert

Signed-off-by: Tim Ramlot <[email protected]>

aa23a7e97327af5b34cd4e68372889c3895e3edc authored about 1 year ago by Tim Ramlot <[email protected]>
Increase the webhook timeout to its maximum value

Users sometimes report that the connection between the K8S API server and the
cert-manager webho...

a0e5afc0f45cabf9561830e6858ba6512acd2b45 authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6487 from inteon/fix_cve_alert

Fix CVE alert

3938a8c2c192aec07339680384ddc1f52141c36c authored about 1 year ago by jetstack-bot <[email protected]>
fix CVE alert

Signed-off-by: Tim Ramlot <[email protected]>

c953e48b7eed8da321d12d4ebae1580d842fd9be authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6433 from vinny-sabatini/issue-5782

fix error message when setting up vault issuer

6fddbe538fb94b9164d2371ef8925592b0a65adf authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6479 from SgtCoDFish/distroless

Use explicit debian version for base images

ac88b3e3308d715e18fbd73a79370a05fe112a75 authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6477 from SgtCoDFish/bumpcerts

Regenerate hardcoded certs

943cbfdfda21f6808cde1b407218abc47f78d6de authored about 1 year ago by jetstack-bot <[email protected]>
Use explicit debian version for base images

Fixes #6478

Signed-off-by: Ashley Davis <[email protected]>

f7937c7372f8f0c54b67e501b7df29928c5025fa authored about 1 year ago by Ashley Davis <[email protected]>
regenerate hardcoded certs

fixes #6476

Signed-off-by: Ashley Davis <[email protected]>

96e081fbd36846fc3a6e53938e201c9d4e8b3302 authored about 1 year ago by Ashley Davis <[email protected]>
Merge pull request #6028 from inteon/fix_scheme_errors

Stop using global runtime.Scheme variables

d2f6bbe579fd9d5f88b82f9a4bfe9241709e9eb8 authored about 1 year ago by jetstack-bot <[email protected]>
create ad-hoc schemes instead of sharing global ones

Signed-off-by: Tim Ramlot <[email protected]>

4c94f3ef10f532d737933718c6b3b08726e1fb1b authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6467 from inteon/cainjector_cleanup

cainjector: Use controller-runtime manager to manage goroutine instead of errorgroup.

7373e1f386ddb69b490d5864402cbc4982ca1b95 authored about 1 year ago by jetstack-bot <[email protected]>
Use controller-runtime manager instead of errorgroup.

Signed-off-by: Tim Ramlot <[email protected]>

80e3960f9157a4e52e62ef0bda51c3aeae8a065c authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6462 from wallrj/policy-compliant-acme-solver-pod

Ensure ACME solver Pod complies with Pod Security Standards

5141dddf2c0c5e10c5d4452c99a2e260c6eb2983 authored about 1 year ago by jetstack-bot <[email protected]>
Update documentation of the Kyverno policies Kustomization file

Signed-off-by: Richard Wall <[email protected]>

80896bce367f694ce7d59cc365344f6c29d4a76c authored about 1 year ago by Richard Wall <[email protected]>
Configure HTTP01 solver Pod with readOnlyRootFilesystem

Signed-off-by: Richard Wall <[email protected]>

9b5dd86084e7f379bde8c9787c20ecce123a7647 authored about 1 year ago by Richard Wall <[email protected]>
Apply Kyverno policies to E2E test namespaces too

By using ClusterPolicy with exlusion rules for the namespaces of non-compliant E2E test tools.

...

c8640908e7534e3409331be9ca94ee63d79f7f8c authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6461 from wallrj/run-as-non-root

Remove redundant / misleading runAsNonRoot examples from values.yaml

2f6e9f484b934c5a0f8f75cdbb2ec2ccbf06ba7b authored about 1 year ago by jetstack-bot <[email protected]>
Remove redundant / misleading runAsNonRoot examples from values.yaml

`runAsNonRoot` is already set to true in the *Pod*SecurityContext,
so there isn't really any rea...

8eb547d9cbe4eba58f4623764034950eac0ef455 authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6460 from erikgb/helm-ca-injector-feature-gates

feat(helm): allow configuration of cainjector feature gates

32418051c3595de90e36ac1ed0413158d275f62a authored about 1 year ago by jetstack-bot <[email protected]>
Merge pull request #6453 from wallrj/read-only-root-filesystem

Enable readOnlyRootFilesystem by default

dd3fe1fe0222a309fdf117747ba8566a58c07a74 authored about 1 year ago by jetstack-bot <[email protected]>
Enable readOnlyRootFilesystem by default

Signed-off-by: Richard Wall <[email protected]>

6d206795c70efc70395147493b296582807c4a21 authored about 1 year ago by Richard Wall <[email protected]>
feat(helm): allow configuration of cainjector feature gates

Signed-off-by: Erik Godding Boye <[email protected]>

af3e88c6dab4e2a1b2138bf30a07cf5b5a0a428d authored about 1 year ago by Erik Godding Boye <[email protected]>
feat(helm) Add support for PodMonitor

Signed-off-by: ShlomiTubul <[email protected]>

0a16c4ecd28836b93f3042272fb7c8080687b768 authored about 1 year ago by ShlomiTubul <[email protected]>
Merge pull request #6452 from wallrj/upgrade-bestpractice-values-url

Use latest version of the best-practice Helm values

a8813c5f43730e312ae5ba1601b3dadd3f23e835 authored about 1 year ago by jetstack-bot <[email protected]>
Enable readOnlyRootFilesystem policy in Kyverno

Signed-off-by: Richard Wall <[email protected]>

9dfb7c3ecf578aac02373d1ec24616b2c58211de authored about 1 year ago by Richard Wall <[email protected]>
Update the Kyverno policy file

Signed-off-by: Richard Wall <[email protected]>

c3a8144da86266cad36213638fd19867355a664a authored about 1 year ago by Richard Wall <[email protected]>
Use latest version of the bestpractice Helm values

Signed-off-by: Richard Wall <[email protected]>

2264de13f30d447b1b7bb5ebcbfdb4200aa9ac8a authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6449 from inteon/bump_grpc

Bump gRPC library version to fix CVE alert

16e70c57cde3a924aa1987ab3c1c7fedf4f36970 authored about 1 year ago by Ashley Davis <[email protected]>
bump grpc library version to fix CVE alert

Signed-off-by: Tim Ramlot <[email protected]>

d756311b2e10534e0f76178031250c319867dfeb authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6447 from wallrj/fix-kindest-image-digests

Fix kindest image digests

655481546961dc425d0b6db950f25df8d051ea7f authored about 1 year ago by jetstack-bot <[email protected]>
Add a dedicated rule for kindest node

And explain why

Signed-off-by: Richard Wall <[email protected]>

1329c71f27451d65cd2fb0285c56d67f9bb05581 authored about 1 year ago by Richard Wall <[email protected]>
./hack/latest-kind-images.sh

Signed-off-by: Richard Wall <[email protected]>

c08e34cab1e5d7c3b888fa3e6a286ebc9d38f271 authored about 1 year ago by Richard Wall <[email protected]>
Use the official multi-arch digest for K8S 1.28 on Kind 0.20.0

https://github.com/kubernetes-sigs/kind/releases/tag/v0.20.0

Signed-off-by: Richard Wall <richa...

c8801e997a9cebb7d4c5f843436007deb72e482d authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6440 from wallrj/fix-image-digest-check

Fix image checksum validation and upgrade ingress NGINX to demonstrate the problem

446f133690bd4cc4baafc9887390b859952bac7a authored about 1 year ago by jetstack-bot <[email protected]>
Update pkg/issuer/vault/setup.go

Co-authored-by: Tim Ramlot <[email protected]>
Signed-off-by: Vinny Sabat...

d15e55a16cc2bdf0f6189ffff4222773be439686 authored about 1 year ago by Vinny Sabatini <[email protected]>
Remove the multi-arch variant

Because it was also broken and was being supplied with digests of
single-architecture images rat...

4d2a2277941d45c9b9fc5af4b72f0ac943074d12 authored about 1 year ago by Richard Wall <[email protected]>
Update ingress-nginx image checksums

Signed-off-by: Richard Wall <[email protected]>

c34bddace771c327a6170d88ea7d5be098d653c6 authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6439 from wallrj/sample-external-issuer-0.4.0

Use sample-external-issuer v0.4.0

d660f5b20cccf2f9b63a914d431612e08bdd23a4 authored about 1 year ago by jetstack-bot <[email protected]>
Fix the digest check for single-arch images

Signed-off-by: Richard Wall <[email protected]>

5db745b1038a0778bc41d7590b673e8a577d82dc authored about 1 year ago by Richard Wall <[email protected]>
Upgrade ingress NGINX

Signed-off-by: Richard Wall <[email protected]>

ecada9c30f8612614793fa81e3f27b1546bb3bbb authored about 1 year ago by Richard Wall <[email protected]>
Use sample-external-issuer v0.4.0

Signed-off-by: Richard Wall <[email protected]>

a1164b9c4f7cfd75976e79201cb437db756c76b7 authored about 1 year ago by Richard Wall <[email protected]>
Merge pull request #6435 from ABWassim/fix/templating-config-controllers

fix(helm): templating of required value in controller and webhook configmaps

04056f7bf6d889d5128bd529ac5670cce4658306 authored about 1 year ago by jetstack-bot <[email protected]>
fix(helm): templating of required value in controller and webhook configmaps

Signed-off-by: ABWassim <[email protected]>

5ab8a6b71cfc04d4efafa02e192833e3f8b27e0a authored about 1 year ago by ABWassim <[email protected]>
additional improvements to vault issuer error messages

When initializing a Vault issuer:

* Create different error messages depending on if Vault is se...

ef6ef1f0dbe96d8695e3f4b3b6737133a54d87de authored about 1 year ago by Vinny Sabatini <[email protected]>
fix error message when setting up vault issuer

* Ensure Vault URL can be parsed
* Separate generic http errors from vault specific errors when ...

298ceb3b2a72706097f03271ec0998d496610ca5 authored about 1 year ago by Vincent Sabatini <[email protected]>
Merge pull request #6427 from SgtCoDFish/bumpnet

Bump golang.org/x/net v0.15.0 => v0.17.0

2e51b258da73ba28b04007b191c14c347a1a5b0f authored about 1 year ago by jetstack-bot <[email protected]>
bump golang.org/x/net v0.15.0 => v0.17.0

part of addressing CVE-2023-44487 / CVE-2023-39325
(which, again, we're not super concerned abou...

e514b1acf8ba94fca982898600ff023a349b6403 authored about 1 year ago by Ashley Davis <[email protected]>
Merge pull request #6428 from inteon/fix_go_licenses_on_darwin

Fix the 'make update-licenses' command on macos

69f3e5304fc46162ffcd3bec59de6c44094b0bfc authored about 1 year ago by jetstack-bot <[email protected]>
fix the 'make update-licenses' command on macos

Signed-off-by: Tim Ramlot <[email protected]>

aab50ac20d09a0287891d3377da9ae3b894d5e92 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6426 from mamachanko/topic/mamachanko/master/improve-config-file-tests

Rename `webhookConfig` to `controllerConfig`

a51d7607edd3a94a1569af3fcc507f7e3d2c8fae authored about 1 year ago by jetstack-bot <[email protected]>
Rename webhookConfig to controllerConfig

Signed-off-by: Max Brauer <[email protected]>

432430b311bc37c529706f15f1077db464ecd265 authored about 1 year ago by Max Brauer <[email protected]>
Merge pull request #6406 from inteon/duplicate_secret_name

Fix DuplicateSecretName issue

3b0a5cec4140e92ba12f3eace362a4bd65fbb30e authored about 1 year ago by jetstack-bot <[email protected]>
update the Condition Message for IncorrectCertificate

Signed-off-by: Tim Ramlot <[email protected]>

c51b23497df40af17dcbbdbc2327b32c779d0395 authored about 1 year ago by Tim Ramlot <[email protected]>
add test for SecretCertificateNameAnnotationsMismatch

Signed-off-by: Tim Ramlot <[email protected]>

b6ba4ded868c32c20d33e89de18b2b0757be4102 authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6414 from zoispag/patch-1

Fix typo in values.yml

9fd770a011815d8499a7fb35a6387982ec909762 authored about 1 year ago by jetstack-bot <[email protected]>
Fix typo in values.yml

Affinty -> Affinity

Signed-off-by: Zois Pagoulatos <[email protected]>

c4986a93c83b330bf998b17480e4dada57828c02 authored about 1 year ago by Zois Pagoulatos <[email protected]>
make changes based on feedback

Signed-off-by: Tim Ramlot <[email protected]>

15bc387da65327ead63766af15fbab5b4a856c4a authored about 1 year ago by Tim Ramlot <[email protected]>
Merge pull request #6410 from SgtCoDFish/bumpgo

Bump go to latest to address CVE-2023-39325

b53527eb787c508a2dc0a27853cd4eb4b138faf6 authored about 1 year ago by jetstack-bot <[email protected]>
bump base images to latest

Signed-off-by: Ashley Davis <[email protected]>

45545ec39fea98fe541ffd24f0ffbcd37273f081 authored about 1 year ago by Ashley Davis <[email protected]>
bump go to latest version to address CVE-2023-39325

Signed-off-by: Ashley Davis <[email protected]>

ad3bc2c66ad8f854b2394279770a3d979cfdc2b3 authored about 1 year ago by Ashley Davis <[email protected]>
only sort the duplicates

Signed-off-by: Tim Ramlot <[email protected]>

61bdecf68a9b549d8d9faf6a4fe4fa7f53357ed0 authored about 1 year ago by Tim Ramlot <[email protected]>
add tests

Signed-off-by: Tim Ramlot <[email protected]>

e63d0612699641b31debaf70bb8d5b4a677af1d9 authored about 1 year ago by Tim Ramlot <[email protected]>
Fix DuplicateSecretName issue

Signed-off-by: Tim Ramlot <[email protected]>

d40dae9d6719610fc53ecf7803ee4ad0b61209ec authored about 1 year ago by Tim Ramlot <[email protected]>
Do not process Gateway listeners that do not support TLS

Otherwise, these will raise warnings in the next steps (e.g. about empty
TLS blocks, which are n...

6ac88fd6b9f7655a65f7a793d1778c3658caa2f6 authored about 1 year ago by Laura Seidler <[email protected]>