Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
3224 commits
Select commit Hold shift + click to select a range
4d75e48
fix(deps): update cloud go deps
octo-sts[bot] Dec 2, 2025
0ea59f6
Merge pull request #8281 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 2, 2025
6bb9c74
Merge pull request #8276 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 2, 2025
71014c3
Graduate DefaultPrivateKeyRotationPolicyAlways to GA and remove gating
wallrj-cyberark Dec 2, 2025
44f5769
Merge pull request #8287 from wallrj-cyberark/remove-private-key-rota…
cert-manager-prow[bot] Dec 2, 2025
96cd769
Sort missing field list
jsoref Dec 2, 2025
6043501
spelling: invalid oid syntax
jsoref Dec 2, 2025
cdfce67
spelling: parsecertificaterequest
jsoref Dec 2, 2025
13f5f25
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 3, 2025
931f516
spelling: fall back
jsoref Dec 2, 2025
f2da642
spelling: , or
jsoref Dec 2, 2025
8408940
spelling: , or
jsoref Dec 2, 2025
6763632
chore(deps): update actions/checkout action to v6.0.1
octo-sts[bot] Dec 3, 2025
86461e7
fix(deps): update cloud go deps
octo-sts[bot] Dec 3, 2025
2d613f7
Promote OtherNames to Beta and enable by default
wallrj-cyberark Dec 2, 2025
d4dd566
Merge pull request #8288 from wallrj-cyberark/graduate-othernames-fea…
cert-manager-prow[bot] Dec 3, 2025
071a208
Merge pull request #8292 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 3, 2025
f425691
Merge pull request #8293 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 3, 2025
7008892
Merge pull request #8290 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 3, 2025
46dfcb9
chore: Improve vault error message for missing credentials
jsoref Dec 3, 2025
f85d2c7
drop unused DiscoveryClient from context struct
inteon Dec 3, 2025
06fc942
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 4, 2025
7d7e9c8
Merge pull request #8298 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 4, 2025
22e2a8e
fix(deps): update module github.com/spf13/cobra to v1.10.2
octo-sts[bot] Dec 4, 2025
4d0951c
Merge pull request #8297 from jsoref/vault-missing-credentials
cert-manager-prow[bot] Dec 4, 2025
a677cd5
Use constructors to create event handlers
inteon Dec 4, 2025
3979caa
make vendor-go generate
wallrj-cyberark Dec 4, 2025
2899810
Merge pull request #8299 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 4, 2025
49f218c
Merge pull request #8291 from jsoref/minor-tweaks
cert-manager-prow[bot] Dec 4, 2025
bce7706
Event handler: add support for predicate based filtering
inteon Dec 8, 2025
5f3f76b
Merge pull request #8302 from inteon/remove_unused_discovery_client
cert-manager-prow[bot] Dec 4, 2025
fdc7e41
add tests for event handlers
inteon Dec 4, 2025
b210ded
chore(deps): update base images
octo-sts[bot] Dec 5, 2025
5bb8690
Use resource version instead of deepequal when possible
inteon Dec 8, 2025
f625b7d
venafi: Process custom fields annotations on Issuer
k0da Dec 4, 2025
02d1e19
Merge pull request #8303 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Dec 5, 2025
1be74b4
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 6, 2025
7a2fdab
Merge pull request #8306 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 6, 2025
13ca575
chore(deps): update github/codeql-action action to v4.31.7
octo-sts[bot] Dec 6, 2025
69f1e69
fix(deps): update module sigs.k8s.io/gateway-api to v1.4.1
octo-sts[bot] Dec 6, 2025
f756a9c
fix(deps): update module github.com/cloudflare/cloudflare-go/v6 to v6…
octo-sts[bot] Dec 6, 2025
5a02b6c
Merge pull request #8307 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 6, 2025
0c9a62e
Merge pull request #8305 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 6, 2025
af592c3
Merge pull request #8304 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Dec 6, 2025
cdf0921
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 6, 2025
2225f2f
Merge pull request #8308 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 6, 2025
af55546
fix(deps): update k8s.io/kube-openapi digest to 4e65d59
renovate[bot] Dec 6, 2025
c87b897
Merge pull request #8310 from cert-manager/renovate/master-k8s.io-kub…
cert-manager-prow[bot] Dec 6, 2025
83cb932
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 7, 2025
c2c23e2
Merge pull request #8311 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 7, 2025
89d0a9c
fix(deps): update k8s.io/utils digest to bc988d5
renovate[bot] Dec 8, 2025
efccfbc
Merge pull request #8315 from cert-manager/renovate/master-k8s.io-uti…
cert-manager-prow[bot] Dec 8, 2025
a238c83
fix typos found by copilot
inteon Dec 8, 2025
8318aff
Merge pull request #8314 from inteon/construct_event_handlers
cert-manager-prow[bot] Dec 8, 2025
4c89b11
Merge pull request #8139 from hjoshi123/feat/cert-renewal-drafts
cert-manager-prow[bot] Dec 8, 2025
e484b2c
fix(deps): update github.com/onsi deps
renovate[bot] Dec 8, 2025
ac1f70f
fix(deps): update cloud go deps
renovate[bot] Dec 8, 2025
70a69bc
fix(deps): update golang.org/x deps
renovate[bot] Dec 8, 2025
c0eb769
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 9, 2025
f530e85
fix(deps): update module github.com/go-openapi/jsonreference to v0.21.4
renovate[bot] Dec 9, 2025
227989f
Merge pull request #8322 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 9, 2025
ffd8de8
Merge pull request #8316 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Dec 9, 2025
df59e32
Merge pull request #8321 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 9, 2025
6059764
Merge pull request #8323 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 9, 2025
f545630
Merge pull request #8320 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Dec 9, 2025
33fc9b5
Merge pull request #8261 from inteon/refactor_event_handler
cert-manager-prow[bot] Dec 9, 2025
9098658
Extend makefile-modules Renovate preset
erikgb Dec 9, 2025
ab22b7f
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 10, 2025
26165a4
Merge pull request #8333 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 10, 2025
02d3ae3
Merge pull request #8332 from cert-manager/renovate/reconfigure
cert-manager-prow[bot] Dec 10, 2025
406e2c5
fix(deps): update kubernetes go patches to v0.34.3
renovate[bot] Dec 10, 2025
4414c84
Merge pull request #8335 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Dec 10, 2025
577d52a
fix(deps): update cloud go deps
renovate[bot] Dec 10, 2025
9858f56
Merge pull request #8329 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 10, 2025
e574fa9
add TestOnlyUpdateWhenResourceChanged
inteon Dec 10, 2025
fd8417e
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 11, 2025
8670ec8
Merge pull request #8337 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 11, 2025
ab036af
chore: fix some struct comments
changgesi Dec 11, 2025
014d580
run 'make generate'
inteon Dec 10, 2025
23629d5
Merge pull request #7839 from cert-manager/proposal-gatewayapi-listen…
cert-manager-prow[bot] Dec 11, 2025
352de00
fix(deps): update module github.com/miekg/dns to v1.1.69
renovate[bot] Dec 11, 2025
c9d425c
Merge pull request #8341 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 11, 2025
174fde5
Merge pull request #8338 from changgesi/master
cert-manager-prow[bot] Dec 12, 2025
2976330
chore(deps): update github/codeql-action action to v4.31.8
renovate[bot] Dec 12, 2025
c130e53
Merge pull request #8342 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 12, 2025
2fec07d
add extra comments
inteon Dec 12, 2025
c468d13
chore(deps): update actions/upload-artifact action to v6
renovate[bot] Dec 12, 2025
35b1995
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 14, 2025
4c44989
Merge pull request #8344 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 14, 2025
c3cb959
fix(deps): update module github.com/venafi/vcert/v5 to v5.12.3
renovate[bot] Dec 14, 2025
9fcf05d
Merge pull request #8345 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 15, 2025
3faec85
Merge pull request #8343 from cert-manager/renovate/master-major-misc…
cert-manager-prow[bot] Dec 15, 2025
c35aa1a
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 16, 2025
27e1261
Merge pull request #8346 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 16, 2025
54b588e
chore(deps): update github/codeql-action action to v4.31.9
renovate[bot] Dec 16, 2025
166f378
fix(deps): update cloud go deps
renovate[bot] Dec 17, 2025
93b7863
Merge pull request #8347 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Dec 17, 2025
f7f75c3
Merge pull request #8348 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 17, 2025
80e0a3b
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 18, 2025
d84ef8d
Merge pull request #8349 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 18, 2025
bee9a6d
chore(deps): update dependency kubernetes-sigs/kind to v0.31.0
renovate[bot] Dec 18, 2025
1a6633e
fix: update helm install NOTES to include GWAPI instructions
jaxels10 Dec 18, 2025
15481ea
fix(deps): update cloud go deps
renovate[bot] Dec 19, 2025
49a0425
Merge pull request #8351 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Dec 19, 2025
2e365c8
Merge pull request #8356 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Dec 20, 2025
9def8f7
Add checks for Duration and RenewBefore changes when determining if a…
eleanor-merry Dec 12, 2025
a66597e
Fix pointer refs for Duration/RenewBefore/RevisionHistoryLimit
eleanor-merry Dec 12, 2025
f4346c0
Move to ptr.Equal
eleanor-merry Dec 22, 2025
874c925
feat: Allow extra containers in deployment
dancmeyers Dec 18, 2025
f0d2d82
fix(deps): update module software.sslmate.com/src/go-pkcs12 to v0.7.0
renovate[bot] Dec 23, 2025
ff466ee
Merge pull request #8301 from AbsaOSS/venafi_issuer_custom_field
cert-manager-prow[bot] Dec 23, 2025
cac4f59
feat(trigger): adding certificate request backoff duration to trigger…
hjoshi123 Dec 23, 2025
a48898b
Upgrade K8s dependencies to 1.35 (#8358)
erikgb Dec 23, 2025
399a243
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 24, 2025
25fa183
Merge pull request #8365 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 24, 2025
c825445
Merge pull request #8232 from eleanor-merry/notice-duration-changes-o…
cert-manager-prow[bot] Dec 24, 2025
d1a0ad3
Merge pull request #8362 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Dec 25, 2025
3d29a83
Add unhealthyPodEvictionPolicy to supported PDB options
jcpunk Nov 6, 2025
536e74e
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Dec 27, 2025
8fa9f88
Merge pull request #8366 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Dec 27, 2025
886e4b4
Merge pull request #8353 from jaxels10/master
cert-manager-prow[bot] Dec 28, 2025
09600a6
adding 1.35 kind version
hjoshi123 Dec 28, 2025
bde5356
Merge pull request #8371 from hjoshi123/fix/kind-1-35
cert-manager-prow[bot] Dec 28, 2025
e41d1b7
feat(controller): adding labels to lease (#8043)
hjoshi123 Dec 28, 2025
f129792
feat(vault): add server as default audience
terinjokes Nov 4, 2025
c084079
Merge pull request #8228 from terinjokes/vault-default-audiences
cert-manager-prow[bot] Dec 29, 2025
140000a
Merge pull request #7728 from jcpunk/pdb-smarter
cert-manager-prow[bot] Jan 1, 2026
640eafd
fix: improve error message when Certificate secret conflicts with CA …
majiayu000 Jan 1, 2026
3156023
Replace custom Challenge SSA with upstream
inteon Jan 6, 2026
97c2870
Merge pull request #8377 from erikgb/ssa-apply
cert-manager-prow[bot] Jan 6, 2026
c94a6fc
fix(deps): update module google.golang.org/api to v0.259.0
renovate[bot] Jan 6, 2026
56dfa60
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 7, 2026
8e8448c
Merge pull request #8382 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 7, 2026
fa7ce9b
Merge pull request #8381 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 7, 2026
9bf98b2
fix(deps): update github.com/onsi deps
renovate[bot] Jan 8, 2026
8d4e60d
Merge pull request #8384 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Jan 8, 2026
d51b461
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 9, 2026
1e6ac3f
Merge pull request #8385 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 9, 2026
a0c521d
feat(deploy/chart): optional networkPolicy for more containers
jcpunk Jan 2, 2026
6643991
fix(deps): update module github.com/miekg/dns to v1.1.70
renovate[bot] Jan 9, 2026
dd8ca4d
Bump kyverno images to v1.16.2 and chart to 3.6.2
wallrj-cyberark Jan 9, 2026
9aa17d3
Merge pull request #8389 from wallrj-cyberark/upgrade-kyverno
cert-manager-prow[bot] Jan 9, 2026
0a5d834
Merge pull request #8388 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Jan 9, 2026
27fce07
fix(deps): update cloud go deps
renovate[bot] Jan 9, 2026
8a42f70
Merge pull request #8390 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 9, 2026
02b4661
fix(deps): update module github.com/aws/aws-sdk-go-v2/config to v1.32.7
renovate[bot] Jan 9, 2026
0d19b9b
fix(deps): update module github.com/hashicorp/vault/sdk to v0.21.0
renovate[bot] Jan 9, 2026
e528577
Merge pull request #8392 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Jan 9, 2026
38727ba
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 10, 2026
b09530f
Merge pull request #8393 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 10, 2026
365a621
Merge pull request #8391 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 10, 2026
04b3d75
chore(deps): update base images
renovate[bot] Jan 12, 2026
f5e3a04
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 12, 2026
2aebd06
Merge pull request #8396 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 12, 2026
c340480
Merge pull request #8398 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Jan 12, 2026
35c4b88
fix code review
inteon Jan 12, 2026
aa9c35a
docs: clarify PKCS1 encoding behavior for EC and Ed25519 keys
WinterCabbage Dec 22, 2025
7f81d24
Merge pull request #8330 from inteon/filter_using_resource_version
cert-manager-prow[bot] Jan 12, 2026
b188c22
chore(deps): update github/codeql-action action to v4.31.10
renovate[bot] Jan 12, 2026
a5baee9
fix(deps): update module golang.org/x/crypto to v0.47.0
renovate[bot] Jan 12, 2026
8caf65c
Merge pull request #8400 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Jan 12, 2026
da748e7
fix(deps): update module github.com/onsi/ginkgo/v2 to v2.27.5
renovate[bot] Jan 13, 2026
17957cd
Merge pull request #8401 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Jan 13, 2026
2108dbb
Merge pull request #8360 from WinterCabbage/docs/fix-pkcs1-ec-key-doc…
cert-manager-prow[bot] Jan 13, 2026
8d8cf46
Fail issuance when certificate public key doesn't match CSR (#8380)
calm329 Jan 9, 2026
59eec54
fix(deps): update cloud go deps
renovate[bot] Jan 13, 2026
1fdd203
Merge pull request #8404 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 14, 2026
5db1769
Make event handlers correctly typed, using generics
inteon Dec 10, 2025
dfdc725
Merge pull request #8399 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Jan 14, 2026
82e2fb8
remove G601 linter exceptions
inteon Jan 14, 2026
af6739a
Merge pull request #8405 from inteon/remove_G601_exceptions
cert-manager-prow[bot] Jan 14, 2026
dec929d
add code comment explaining origin isNil
inteon Jan 14, 2026
1a2a29a
Merge pull request #8317 from inteon/typed_handlers
cert-manager-prow[bot] Jan 15, 2026
3d247fc
Use nonroot base image tags in latest-base-images script
wallrj-cyberark Jan 15, 2026
15527f9
./hack/latest-base-images.sh
wallrj-cyberark Jan 15, 2026
36ec644
Remove USER from containerfile
wallrj-cyberark Jan 15, 2026
3a7761c
Merge pull request #8408 from wallrj-cyberark/use-nonroot-base-images
cert-manager-prow[bot] Jan 15, 2026
ac557ba
Update pkg/controller/certificaterequests/sync.go
majiayu000 Jan 15, 2026
0d4e762
Fail issuance when certificate public key doesn't match CSR
calm329 Jan 15, 2026
29e1890
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 16, 2026
b97d836
Merge pull request #8413 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 16, 2026
c23cd0c
fix(deps): update cloud go deps
renovate[bot] Jan 16, 2026
59a1347
Use nonroot tag for latest base images in Renovate
wallrj-cyberark Jan 16, 2026
03ccc6a
Merge pull request #8411 from wallrj-cyberark/use-nonroot-base-images-2
cert-manager-prow[bot] Jan 16, 2026
4287874
Merge pull request #8370 from jcpunk/networkPolicies
cert-manager-prow[bot] Jan 16, 2026
9668922
Merge pull request #8403 from calm329/fix/prevent-reissuance-loop-on-…
cert-manager-prow[bot] Jan 16, 2026
5000883
Merge pull request #8406 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 18, 2026
198e4fa
[VC-48226] Use the latest best-practices Helm chart values in the E2E…
wallrj-cyberark Jan 9, 2026
88b5ce9
fix(deps): update module github.com/akamai/akamaiopen-edgegrid-golang…
renovate[bot] Jan 19, 2026
5e532cc
Merge pull request #8374 from majiayu000/fix-7002-confusing-messaging…
cert-manager-prow[bot] Jan 19, 2026
fe7f935
fix(deps): update module sigs.k8s.io/controller-runtime to v0.23.0
renovate[bot] Jan 19, 2026
4fd571f
Merge pull request #8419 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Jan 19, 2026
71c693f
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 20, 2026
2374849
Merge pull request #8420 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 20, 2026
00c743d
Merge pull request #8387 from wallrj-cyberark/networkpolicies-enabled…
cert-manager-prow[bot] Jan 20, 2026
0c6d0d7
fix(HTTP-01): handling of IPv6 address literals
SlashNephy Jan 20, 2026
c2c23a2
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 21, 2026
4064750
Merge pull request #8427 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 21, 2026
11a9c0a
Merge pull request #8417 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 21, 2026
5a355ff
Introduction of 3 additional Helm Values
Jan 21, 2026
7650afe
Ammended -fips and added brief explanation of "name" field.
Jan 21, 2026
635387c
fix(e2e): replacing contour with kgateway (#8426)
hjoshi123 Jan 21, 2026
28399d4
Enable the modernize any linter
erikgb Jan 21, 2026
9ab2184
fix(deps): update module google.golang.org/api to v0.261.0
renovate[bot] Jan 22, 2026
d53e967
Merge pull request #8429 from erikgb/lint-modernize-any
cert-manager-prow[bot] Jan 22, 2026
7ea34c8
Enable the modernize-omitzero linter rule
erikgb Jan 21, 2026
6db4ffe
Merge pull request #8430 from erikgb/enable-modernize-omitzero
cert-manager-prow[bot] Jan 22, 2026
9f2bb03
Improve golangci-lint configuration
erikgb Jan 21, 2026
335a9ba
fix(deps): update module github.com/miekg/dns to v1.1.72
renovate[bot] Jan 22, 2026
d60fdfb
Merge pull request #8432 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Jan 22, 2026
9c35793
Merge pull request #8428 from erikgb/improve-golangci-lint-config
cert-manager-prow[bot] Jan 22, 2026
ffa5fc5
Merge pull request #8431 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 22, 2026
81c657d
Merge pull request #8425 from FelixPhipps/master
cert-manager-prow[bot] Jan 22, 2026
12be2ba
Merge pull request #8424 from SlashNephy/fix/http-01-challenge-contai…
cert-manager-prow[bot] Jan 22, 2026
d355d5a
fix(deps): update cloud go deps
renovate[bot] Jan 22, 2026
6b418d3
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 23, 2026
27beedf
Merge pull request #8439 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 23, 2026
620c53c
Merge pull request #8433 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 23, 2026
43f8c24
Merge pull request #8355 from dancmeyers/infra-990/allow-extra-contai…
cert-manager-prow[bot] Jan 23, 2026
31ab699
chore(deps): update misc github actions
renovate[bot] Jan 23, 2026
183fc53
Merge pull request #8435 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Jan 23, 2026
f33f483
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 24, 2026
3b69897
Merge pull request #8444 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 24, 2026
a03eadb
fix: Avoid setting HTTPRoute.spec.hostnames when the challenge DNSNam…
alviss7 Jan 23, 2026
507b2e5
fix(deps): update module sigs.k8s.io/controller-runtime to v0.23.1
renovate[bot] Jan 26, 2026
0f67a60
chore(deps): update github/codeql-action action to v4.32.0
renovate[bot] Jan 26, 2026
6c4506c
Merge pull request #8445 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Jan 26, 2026
d1d501a
Merge pull request #8446 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Jan 27, 2026
5449cdc
Merge pull request #8443 from alviss7/fix/Avoid-setting-HTTPRoute.spe…
cert-manager-prow[bot] Jan 27, 2026
8159dce
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 28, 2026
0403682
Merge pull request #8449 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 28, 2026
75caaf4
chore(deps): update base images
renovate[bot] Jan 29, 2026
f0eec7d
Merge pull request #8452 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Jan 29, 2026
21a5e16
feat(certificate-shim): implementing XListenerSet (#8394)
hjoshi123 Jan 29, 2026
1ed5592
fix(deps): update module google.golang.org/api to v0.264.0
renovate[bot] Jan 29, 2026
d2b0e6d
fix(deps): update module github.com/onsi/ginkgo/v2 to v2.28.0
renovate[bot] Jan 30, 2026
cf69052
Merge pull request #8454 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Jan 30, 2026
ba46c0e
fix(deps): update github.com/onsi deps
renovate[bot] Jan 30, 2026
65f3663
Merge pull request #8455 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Jan 30, 2026
54f5a10
Merge pull request #8448 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Jan 30, 2026
16e1172
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Jan 31, 2026
14255f6
Merge pull request #8461 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Jan 31, 2026
e29c624
adding hjoshi123 as approver
hjoshi123 Jan 31, 2026
7d89aee
Merge pull request #8462 from hjoshi123/add-hjoshi123-approver
cert-manager-prow[bot] Jan 31, 2026
29d8b99
Bump gateway-api to enable watch-list in tests
erikgb Feb 1, 2026
15a0f4d
Merge pull request #8465 from erikgb/list-watch-enable
cert-manager-prow[bot] Feb 2, 2026
2cc95a0
security: address GHSA-gx3x-vq4p-mhhv
SgtCoDFish Feb 2, 2026
409fc24
Merge pull request #8469 from SgtCoDFish/fqdn-patch
cert-manager-prow[bot] Feb 2, 2026
7032dc7
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Feb 3, 2026
bf94b0f
Merge pull request #8473 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Feb 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 0 additions & 2 deletions .bazelignore

This file was deleted.

7 changes: 0 additions & 7 deletions .bazelrc

This file was deleted.

9 changes: 9 additions & 0 deletions .clomonitor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# License scanning information
licenseScanning:
# URL with the repository's license scanning results
#
# CLOMonitor can extract license scanning results from FOSSA and Snyk badges
# in the repository README.md file automatically. If your repository uses a
# different scanning solution, this url can be set to pass the corresponding
# check.
url: https://github.com/cert-manager/cert-manager/blob/master/LICENSES
6 changes: 3 additions & 3 deletions .github/ISSUE_TEMPLATE/bug.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ about: Report a bug to help us improve cert-manager
<!--
Bugs should be filed for issues encountered whilst operating cert-manager.
You should first attempt to resolve your issues through the community support
channels, e.g. Slack, in order to rule out individual configuration errors.
channels, e.g., Slack, in order to rule out individual configuration errors.
Please provide as much detail as possible.
-->

Expand All @@ -30,10 +30,10 @@ gain an understanding of the problem.-->

**Anything else we need to know?**:

**Environment details:**:
**Environment details**:
- Kubernetes version:
- Cloud-provider/provisioner:
- cert-manager version:
- Install method: e.g. helm/static manifests
- Install method: e.g., helm/static manifests

/kind bug
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/feature-request.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ about: Suggest an idea to improve cert-manager
- Kubernetes version:
- Cloud-provider/provisioner:
- cert-manager version:
- Install method: e.g. helm/static manifests
- Install method: e.g., helm/static manifests


/kind feature
7 changes: 6 additions & 1 deletion .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,14 @@ Thanks for opening a pull request! Here are some tips to get everything merged s

### Kind

<!--
The kind(s) listed after "kind" after this comment will be used by a bot to add labels when the PR is opened.
If omitted at PR creation, someone will need to make a new comment with them later (editing the description after the fact will not trigger the bot).
-->
/kind
<!--

Pick a kind which best describes your PR from the following list:
Pick the kind(s) which best describe your PR from the following list:

<cleanup | bug | feature | documentation | design | flake>

Expand Down
10 changes: 10 additions & 0 deletions .github/chainguard/make-self-upgrade.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/repository-base/base/.github/chainguard/make-self-upgrade.sts.yaml instead.

issuer: https://token.actions.githubusercontent.com
subject_pattern: ^repo:cert-manager/cert-manager:ref:refs/heads/(main|master)$

permissions:
contents: write
pull_requests: write
workflows: write
80 changes: 80 additions & 0 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
{
$schema: 'https://docs.renovatebot.com/renovate-schema.json',
extends: [
'github>cert-manager/makefile-modules:renovate-config.json5'
],
baseBranchPatterns: [
'master',
'release-1.19',
'release-1.18',
],
addLabels: [
'kind/cleanup',
'release-note-none',
],
customManagers: [
{
customType: 'regex',
managerFilePatterns: [
'make/base_images.mk',
],
matchStrings: [
'(?<depName>gcr\\.io\/[^@]+)@(?<currentDigest>sha256:[a-f0-9]{64})',
],
datasourceTemplate: 'docker',
// this tag must match the tag used in hack/latest-base-images.sh
currentValueTemplate: 'nonroot'
},
{
customType: 'regex',
managerFilePatterns: [
'hack/latest-kind-images.sh',
],
matchStrings: [
'kind_version=(?<currentValue>.*)',
],
datasourceTemplate: 'github-releases',
depNameTemplate: 'kubernetes-sigs/kind',
},
],
packageRules: [
{
groupName: 'Base Images',
matchManagers: [
'custom.regex',
],
},
{
groupName: null,
matchManagers: [
'custom.regex',
],
matchPackageNames: [
'kubernetes-sigs/kind',
],
postUpgradeTasks: {
commands: [
'hack/latest-kind-images.sh',
],
},
},
{
matchBaseBranches: [
'/^release-.*/',
],
enabled: false,
},
{
matchBaseBranches: [
'/^release-.*/',
],
matchUpdateTypes: [
'patch',
'pin',
'pinDigest',
'digest',
],
enabled: true,
},
],
}
37 changes: 37 additions & 0 deletions .github/workflows/govulncheck.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/go/base/.github/workflows/govulncheck.yaml instead.

# Run govulncheck at midnight every night on the main branch,
# to alert us to recent vulnerabilities which affect the Go code in this
# project.
name: govulncheck
on:
workflow_dispatch: {}
schedule:
- cron: '0 0 * * *'

permissions:
contents: read

jobs:
govulncheck:
runs-on: ubuntu-latest

if: github.repository == 'cert-manager/cert-manager'

steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Adding `fetch-depth: 0` makes sure tags are also fetched. We need
# the tags so `git describe` returns a valid version.
# see https://github.com/actions/checkout/issues/701 for extra info about this option
with: { fetch-depth: 0 }

- id: go-version
run: |
make print-go-version >> "$GITHUB_OUTPUT"

- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
with:
go-version: ${{ steps.go-version.outputs.result }}

- run: make verify-govulncheck
114 changes: 114 additions & 0 deletions .github/workflows/make-self-upgrade.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/repository-base/base/.github/workflows/make-self-upgrade.yaml instead.

name: make-self-upgrade
concurrency: make-self-upgrade
on:
workflow_dispatch: {}
schedule:
- cron: '0 0 * * *'

permissions:
contents: read

jobs:
self_upgrade:
runs-on: ubuntu-latest

if: github.repository == 'cert-manager/cert-manager'

permissions:
id-token: write

env:
SOURCE_BRANCH: "${{ github.ref_name }}"
SELF_UPGRADE_BRANCH: "self-upgrade-${{ github.ref_name }}"

steps:
- name: Fail if branch is not head of branch.
if: ${{ !startsWith(github.ref, 'refs/heads/') && env.SOURCE_BRANCH != '' && env.SELF_UPGRADE_BRANCH != '' }}
run: |
echo "This workflow should not be run on a non-branch-head."
exit 1

- name: Octo STS Token Exchange
uses: octo-sts/action@f603d3be9d8dd9871a265776e625a27b00effe05 # v1.1.1
id: octo-sts
with:
scope: 'cert-manager/cert-manager'
identity: make-self-upgrade

- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Adding `fetch-depth: 0` makes sure tags are also fetched. We need
# the tags so `git describe` returns a valid version.
# see https://github.com/actions/checkout/issues/701 for extra info about this option
with:
fetch-depth: 0
token: ${{ steps.octo-sts.outputs.token }}

- id: go-version
run: |
make print-go-version >> "$GITHUB_OUTPUT"

- uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
with:
go-version: ${{ steps.go-version.outputs.result }}

- run: |
git checkout -B "$SELF_UPGRADE_BRANCH"

- run: |
make -j upgrade-klone
make -j generate

- id: is-up-to-date
shell: bash
run: |
git_status=$(git status -s)
is_up_to_date="true"
if [ -n "$git_status" ]; then
is_up_to_date="false"
echo "The following changes will be committed:"
echo "$git_status"
fi
echo "result=$is_up_to_date" >> "$GITHUB_OUTPUT"

- if: ${{ steps.is-up-to-date.outputs.result != 'true' }}
run: |
git config --global user.name "cert-manager-bot"
git config --global user.email "[email protected]"
git add -A && git commit -m "BOT: run 'make upgrade-klone' and 'make generate'" --signoff
git push -f origin "$SELF_UPGRADE_BRANCH"

- if: ${{ steps.is-up-to-date.outputs.result != 'true' }}
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
with:
github-token: ${{ steps.octo-sts.outputs.token }}
script: |
const { repo, owner } = context.repo;
const pulls = await github.rest.pulls.list({
owner: owner,
repo: repo,
head: owner + ':' + process.env.SELF_UPGRADE_BRANCH,
base: process.env.SOURCE_BRANCH,
state: 'open',
});

if (pulls.data.length < 1) {
const result = await github.rest.pulls.create({
title: '[CI] Merge ' + process.env.SELF_UPGRADE_BRANCH + ' into ' + process.env.SOURCE_BRANCH,
owner: owner,
repo: repo,
head: process.env.SELF_UPGRADE_BRANCH,
base: process.env.SOURCE_BRANCH,
body: [
'This PR is auto-generated to bump the Makefile modules.',
].join('\n'),
});
await github.rest.issues.addLabels({
owner,
repo,
issue_number: result.data.number,
labels: ['ok-to-test', 'skip-review', 'release-note-none', 'kind/cleanup']
});
}
55 changes: 55 additions & 0 deletions .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: Scorecards supply-chain security
on:
# Only the default branch is supported.
branch_protection_rule:
schedule:
- cron: '43 13 * * 6'
push:
branches: [ "master" ]

# Declare default permissions as read only.
permissions: read-all

jobs:
analysis:
name: Scorecards analysis
runs-on: ubuntu-latest
if: github.ref_name == github.event.repository.default_branch
permissions:
# Needed to upload the results to code-scanning dashboard.
security-events: write
# Used to receive a badge.
id-token: write

steps:
- name: "Checkout code"
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- name: "Run analysis"
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif

# Publish the results for public repositories to enable scorecard badges. For more details, see
# https://github.com/ossf/scorecard-action#publishing-results.
# For private repositories, `publish_results` will automatically be set to `false`, regardless
# of the value entered here.
publish_results: true

# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0
with:
name: SARIF file
path: results.sarif
retention-days: 5

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4.32.0
with:
sarif_file: results.sarif
4 changes: 2 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,13 @@
/hack/build/dockerfiles/cert-manager-*_*_*
.vscode
.venv
bazel-*
/.settings/
/.project
_artifacts/
/vendor/
bin/
_bin/
.bin/
user.bazelrc
*.bak
/go.work.sum
**/go.work
Loading