Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package kubectl-cnpg for openSUSE:Factory 
checked in at 2026-09-24 22:57:54
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/kubectl-cnpg (Old)
 and      /work/SRC/openSUSE:Factory/.kubectl-cnpg.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "kubectl-cnpg"

Thu Sep 24 22:57:54 2026 rev:17 rq:1380079 version:1.30.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/kubectl-cnpg/kubectl-cnpg.changes        
2026-07-01 16:50:28.209894211 +0200
+++ /work/SRC/openSUSE:Factory/.kubectl-cnpg.new.383539/kubectl-cnpg.changes    
2026-09-24 23:00:13.707175573 +0200
@@ -1,0 +2,263 @@
+Thu Sep 24 05:04:25 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 1.30.1:
+  * cnpg plugin:
+    - Added a --dry-run option to the backup command that prints
+      the Backup resource that would be created, without creating
+      it. (#11233)
+    - Used UTC time zone for the default backup name. (#11329)
+    - Deleted PVCs before Pods in cnpg destroy, avoiding a race
+      that could leave dangling PVCs needing a second invocation to
+      clean up. (#10847)
+    - fix(plugin): report the Postgres capabilities of a plugin
+      (#11447)
+    - docs(plugin): added note about verbose mode requirement
+      (#11339)
+    - fix(plugin): replace finalizer with in-memory cleanup on
+      service deletion (#10940)
+  * Dependencies
+    - Updated google.golang.org/grpc to v1.83.1, fixing
+      CVE-2026-84304 / GHSA-vp52-pcj8-j9qc (gRPC-Go heap memory
+      exhaustion via HTTP/2 DATA frame fragmentation). (#11394)
+    - chore(deps): update dependency onsi/ginkgo to v2.33.0
+      (#11529)
+    - fix(deps): update module
+      github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring
+      to v0.94.0 (#11530)
+    - fix(deps): update module sigs.k8s.io/controller-runtime to
+      v0.25.1 (#11528)
+    - chore(deps): update dependency ubuntu to v26 (#11531)
+    - fix(deps): update all non-major go dependencies (#11439)
+    - chore(deps): update dependency cert-manager/cert-manager to
+      v1.21.2 (#11527)
+    - chore(deps): update backup test tools (#11524)
+    - chore(deps): update
+      
https://github.com/redhat-openshift-ecosystem/community-operators-pipeline.git
+      digest to 8ed9daf (#11525)
+    - chore(deps): update ghcr.io/cloudnative-pg/pgbouncer docker
+      tag to v1.25.2 (#11535)
+    - chore(deps): update container distroless digests (#11523)
+    - chore(deps): update objectstore test images (#11435)
+    - chore(deps): update
+      registry.access.redhat.com/ubi9/ubi-micro:latest docker
+      digest to 7a0454c (#11526)
+    - chore(deps): update dependency
+      kubernetes-csi/external-attacher to v4.13.0 (#11428)
+    - chore(deps): update dependency onsi/ginkgo to v2.32.1
+      (#11417)
+    - chore(deps): update
+      
https://github.com/redhat-openshift-ecosystem/community-operators-pipeline.git
+      digest to 80f1f4f (#11416)
+    - chore(deps): update dependency cert-manager/cert-manager to
+      v1.21.1 (#11412)
+    - chore(deps): update kindest/node docker tag to v1.37.0
+      (#11420)
+    - chore(deps): update curlimages/curl docker tag to v8.22.0
+      (#11418)
+    - chore(deps): update operator framework (#11421)
+    - fix(deps): update module sigs.k8s.io/controller-runtime to
+      v0.25.0 (#11423)
+    - fix(deps): update module
+      github.com/prometheus-operator/prometheus-operator/pkg/apis/monitoring
+      to v0.93.1 (#11422)
+    - chore(deps): pin go toolchain to 1.27.1 (#11425)
+    - fix(deps): update cnpg to v0.6.0 (#11399)
+    - fix(deps): update kubernetes monorepo to v0.37.0 (#11400)
+    - fix(deps): update all non-major go dependencies (#11404)
+    - chore(deps): update kubernetes csi (#11209)
+    - chore(deps): update
+      registry.access.redhat.com/ubi9/ubi-micro:latest docker
+      digest to f332c99 (#11398)
+    - chore(deps): update dependency golangci/golangci-lint to
+      v2.13.2 (#11402)
+    - chore(deps): update cuelang/cue docker tag to v0.17.1
+      (#11226)
+    - chore(deps): update module sigs.k8s.io/controller-tools to
+      v0.22.0 (#11403)
+    - chore(deps): update dependency boto3 to v1.43.87 (#11162)
+    - fix(deps): bump go toolchain to 1.26.6 (#11323)
+    - fix(deps): update module golang.org/x/text to v0.39.0
+      (#11240)
+    - fix(deps): update module github.com/cloudnative-pg/cnpg-i to
+      v0.6.0 (#11235)
+    - fix(deps): update all non-major go dependencies (#11160)
+    - fix(deps): update kubernetes patches (#11104)
+    - chore(deps): update kubernetes csi (#11158)
+    - chore(deps): update cuelang/cue docker tag to v0.17.0
+      (#11124)
+    - chore(deps): update docker.io/amazon/aws-cli docker tag to
+      v2.35.19 (#11101)
+    - chore(deps): update
+      registry.access.redhat.com/ubi9/ubi-micro:latest docker
+      digest to 35de56a (#11117)
+    - chore(deps): update dependency cert-manager/cert-manager to
+      v1.21.0 (#11156)
+    - chore(deps): update dependency boto3 to v1.43.44 (#11100)
+    - chore(deps): update container distroless digests (#11154)
+    - fix(deps): bump go toolchain to 1.26.5 (#11155)
+
+
+
+
+-------------------------------------------------------------------
+Wed Jul 01 11:54:03 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 1.30.0:
+  * Important changes
+    - Updated the deprecation notice for native (in-tree) Barman
+      Cloud support to reflect that it will now be removed in
+      CloudNativePG 1.31.0, rather than 1.30.0. Users are still
+      encouraged to migrate to the Barman Cloud Plugin. (#11083)
+    - The cluster reference is now immutable on the Database,
+      Pooler, Publication, Subscription, and ScheduledBackup
+      resources. Pointing one of these objects at a different
+      cluster has no well-defined semantics and previously left the
+      controllers in an inconsistent state; the update is now
+      rejected at the API server via a CEL validation rule.
+      (#10743)
+  * Features
+    - Primary Lease for safe primary election: introduced a
+      Kubernetes Lease object (named after the cluster) that acts
+      as a mutex serializing primary promotion: the instance
+      manager must hold the lease before acting as primary and
+      releases it on clean shutdown so replicas can promote without
+      waiting for the full TTL. Timings are configurable via the
+      new .spec.primaryLease stanza. The lease is a promotion gate,
+      not a fence. Primary isolation remains responsible for
+      fencing. (#10627)
+    - DatabaseRole CRD for declarative role management: introduced
+      a DatabaseRole custom resource that manages a PostgreSQL role
+      as a standalone Kubernetes object, instead of declaring it
+      inline in the Cluster's .spec.managed.roles stanza. Each role
+      gets its own lifecycle, status, and RBAC, which suits GitOps
+      workflows and lets role definitions live next to the
+      applications that own them. The spec reuses the same
+      RoleConfiguration structure as the inline method, so
+      migrating a role is a matter of moving the stanza into its
+      own manifest. A databaseRoleReclaimPolicy field (retain, the
+      default, or delete) controls what happens to the role when
+      the resource is deleted, mirroring persistent volumes.
+      (#6155)
+    - TLS client certificates for declarative roles: a DatabaseRole
+      can now include a clientCertificate block to have the
+      operator automatically generate and renew a TLS client
+      certificate, signed by the cluster's client CA and stored in
+      a <databaserole-name>-client-cert Secret. This enables
+      password-free PostgreSQL cert authentication; the Secret is
+      cleaned up when the feature is disabled or the DatabaseRole
+      is deleted. (#10896)
+    - PgBouncer image management via image catalogs: the Pooler
+      resource can now reference an entry in an ImageCatalog or
+      ClusterImageCatalog through the new
+      spec.pgbouncer.imageCatalogRef field, centralizing PgBouncer
+      image management. When a catalog entry is updated, all
+      referencing Poolers are automatically reconciled and roll out
+      the new image without any change to their spec. The resolved
+      image is reported in status.image, and a new status.phase
+      (active, paused, inactive, or failed), also surfaced as a
+      Phase column in kubectl get pooler, summarizes the lifecycle.
+      (#10568)
+  * Enhancements
+    - Enabled pg_upgrade in-place major upgrades to PostgreSQL 19
+      or later for clusters that use Image Volume extensions,
+      building on the extension-path support added to pg_upgrade in
+      PostgreSQL 19. During the upgrade Job, the source- and
+      target-version extension images are mounted side by side, so
+      the old server keeps its libraries and a failed upgrade
+      reverts cleanly. (#10366)
+    - Added TLS support for the Pooler metrics endpoint via
+      .spec.monitoring.tls.enabled. When enabled, the metrics
+      server is served over HTTPS, reusing the certificate and key
+      from .spec.pgbouncer.clientTLSSecret and reloading it on
+      every handshake to support rotation without a restart; the
+      generated PodMonitor scrapes over https accordingly. (#10466)
+    - Added a label selector to the Cluster scale subresource
+      (status.selector), making a Cluster a valid targetRef for the
+      Vertical Pod Autoscaler (VPA) and Horizontal Pod Autoscaler
+      (HPA), which can now map a Cluster to its instance pods.
+      Contributed by @sebv004. (#8996)
+    - The operator now emits a Warning PrimaryStatusCheckFailed
+      event on the Cluster when the primary pod is Ready from the
+      kubelet perspective but the operator's /pg/status check fails
+      and failover is deferred, giving users visibility into the
+      deferral via kubectl describe cluster. (#10509)
+    - Added the ENABLE_WEBHOOK_NAMESPACE_SUFFIX flag, which
+      suffixes the operator's webhook configuration names with
+      -<OPERATOR_NAMESPACE> so that multiple operator instances can
+      coexist on the same cluster. The operator only looks up these
+      configurations; users must create and maintain them.
+      Contributed by @maxlengdell. (#10420)
+    - The operator now reloads a CNPG-i plugin automatically when
+      its pods are rolled: it watches the EndpointSlices backing
+      plugin Services and re-enqueues every cluster using the
+      plugin once the new pods become Ready, so an upgraded plugin
+      is picked up without waiting for the next resync. (#10836)
+    - Instance serial numbers are now assigned by reusing the
+      lowest free slot among existing instance names, instead of
+      always incrementing a global counter. Pod and PVC names stay
+      stable across instance recreation (for example, an instance
+      recreated after a node drain comes back with the same name),
+      and serials freed by deleted instances are reclaimed. A new
+      Initialized cluster condition reports whether the cluster has
+      completed its first bootstrap, and status.latestGeneratedNode
+      is deprecated: it is no longer written, but is preserved on
+      the CRD for backward compatibility. (#10548)
+    - Defaulting and validation now run during reconciliation as a
+      fallback when admission webhooks are unavailable, or
+      configured to ignore failures, so the operator no longer
+      reconciles invalid or incomplete specs. Missing defaults are
+      applied directly, and validation failures are surfaced in the
+      resource status instead of failing silently later. (#10874)
+  * Security
+    - CVE-2026-55769 / GHSA-x8c2-3p4r-v9r6: search_path pinning on
+      operator-issued connections: a database owner could plant
+      overloaded built-in operators in the public schema and alter
+      the search_path so that operator introspection probes,
+      running as the cluster superuser, resolved those overloads
+      before pg_catalog, a CWE-426 privilege-escalation chain (same
+      class as CVE-2018-1058) that could lead to in-pod RCE via
+      COPY ... FROM PROGRAM. The operator now pins search_path =
+      pg_catalog, public, pg_temp on every pooled connection so it
+      ships in the startup message and takes precedence over
+      tenant-controlled defaults. (#10774, GHSA-x8c2-3p4r-v9r6)
+    - GHSA-7qwx-x8ff-3px9: authenticated
+      operator-to-instance-manager calls: the instance manager's
+      remote webserver relied on network isolation rather than
+      authentication for its operator-only control endpoints, so
+      any party able to reach the pod's status port could invoke
+      them, disrupting backup orchestration and WAL archival and
+      reading operational metadata. (The upgrade endpoint is
+      SHA-256-pinned, so this did not permit arbitrary code
+      execution.) The operator now generates an in-memory ECDSA
+      P-256 client certificate at startup and reconciles its
+      SHA-256 fingerprint into the cluster status; the instance
+      manager rejects requests to sensitive endpoints that do not
+      present a matching certificate. This hardening is not
+      backported; earlier releases should continue to restrict the
+      status port with a NetworkPolicy. (#10579,
+      GHSA-7qwx-x8ff-3px9)
+    - CVE-2026-55765 / GHSA-w3gf-xc94-wvmj: operator-side
+      SCRAM-SHA-256 password encoding: the operator now
+      SCRAM-SHA-256 encodes cleartext role passwords before issuing
+      CREATE/ALTER ROLE ... PASSWORD, so the literal PostgreSQL
+      parses (and that extensions such as pg_stat_statements or
+      pgaudit may capture) is the SCRAM verifier rather than the
+      cleartext secret. Pre-hashed (MD5 or SCRAM) values are
+      forwarded unchanged, and the per-Secret annotation
+      cnpg.io/passwordPassthrough: "enabled" opts out. (#10724,
+      GHSA-w3gf-xc94-wvmj)
+  * Changes
+    - Added support for Kubernetes 1.36. (#10900)
+    - Updated the default PostgreSQL version to 18.4. (#10719)
+    - Updated the Kubernetes versions used to test the operator on
+      public cloud providers. (#10720, #10563, #11033)
+  * Fixes - cnpg plugin:
+    - Fixed kubectl cnpg psql on Windows, where execution relied on
+      a Unix-only system call and failed with "not supported by
+      windows"; Windows now launches kubectl exec as a child
+      process. Contributed by @Utkarsh-sharma47. (#10972)
+    - Fixed an unbounded memory leak in kubectl cnpg logs -f on
+      busy clusters, where a per-log-group timer was never
+      released; timers are now reused across iterations.
+
+-------------------------------------------------------------------

Old:
----
  kubectl-cnpg-1.29.2.obscpio

New:
----
  kubectl-cnpg-1.30.1.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ kubectl-cnpg.spec ++++++
--- /var/tmp/diff_new_pack.PASqBi/_old  2026-09-24 23:00:15.548252561 +0200
+++ /var/tmp/diff_new_pack.PASqBi/_new  2026-09-24 23:00:15.549252603 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           kubectl-cnpg
-Version:        1.29.2
+Version:        1.30.1
 Release:        0
 Summary:        Manage PostgreSQL clusters built using CloudNativePG
 License:        Apache-2.0
@@ -26,7 +26,7 @@
 Source1:        vendor.tar.gz
 BuildRequires:  bash-completion
 BuildRequires:  fish
-BuildRequires:  go1.26 >= 1.26.3
+BuildRequires:  go1.27 >= 1.27.1
 BuildRequires:  zsh
 
 %description

++++++ _service ++++++
--- /var/tmp/diff_new_pack.PASqBi/_old  2026-09-24 23:00:15.585254108 +0200
+++ /var/tmp/diff_new_pack.PASqBi/_new  2026-09-24 23:00:15.588254234 +0200
@@ -3,7 +3,7 @@
     <param 
name="url">https://github.com/cloudnative-pg/cloudnative-pg.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/v1.29.2</param>
+    <param name="revision">refs/tags/v1.30.1</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.PASqBi/_old  2026-09-24 23:00:15.615255363 +0200
+++ /var/tmp/diff_new_pack.PASqBi/_new  2026-09-24 23:00:15.618255488 +0200
@@ -3,6 +3,6 @@
                 <param 
name="url">https://github.com/cloudnative-pg/cloudnative-pg</param>
               <param 
name="changesrevision">a4060c152630c9e8958e17d3d23f26b4eb30b69f</param></service><service
 name="tar_scm">
                 <param 
name="url">https://github.com/cloudnative-pg/cloudnative-pg.git</param>
-              <param 
name="changesrevision">94ee3117858765c77d0dbfde381a037944a48a64</param></service></servicedata>
+              <param 
name="changesrevision">2a35abb4628f209d149825ef3c38011e0701ff2f</param></service></servicedata>
 (No newline at EOF)
 

++++++ kubectl-cnpg-1.29.2.obscpio -> kubectl-cnpg-1.30.1.obscpio ++++++
++++ 128067 lines of diff (skipped)

++++++ kubectl-cnpg.obsinfo ++++++
--- /var/tmp/diff_new_pack.PASqBi/_old  2026-09-24 23:00:17.300325827 +0200
+++ /var/tmp/diff_new_pack.PASqBi/_new  2026-09-24 23:00:17.305326036 +0200
@@ -1,5 +1,5 @@
 name: kubectl-cnpg
-version: 1.29.2
-mtime: 1782749117
-commit: 94ee3117858765c77d0dbfde381a037944a48a64
+version: 1.30.1
+mtime: 1790170481
+commit: 2a35abb4628f209d149825ef3c38011e0701ff2f
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/kubectl-cnpg/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.kubectl-cnpg.new.383539/vendor.tar.gz differ: char 
31, line 1

Reply via email to