Skip to content

OAPE-843: 5.0(4.23) chore: Rebase openshift/ocp-release-operator-sdk to upstream operator-framework/operator-sdk v1.42.3#457

Open
PillaiManish wants to merge 28 commits into
openshift:mainfrom
PillaiManish:v1.42.3-rebase-main
Open

OAPE-843: 5.0(4.23) chore: Rebase openshift/ocp-release-operator-sdk to upstream operator-framework/operator-sdk v1.42.3#457
PillaiManish wants to merge 28 commits into
openshift:mainfrom
PillaiManish:v1.42.3-rebase-main

Conversation

@PillaiManish

@PillaiManish PillaiManish commented Jul 8, 2026

Copy link
Copy Markdown
Member

Rebase to upstream v1.42.3

Ran the following script to create the rebase branch:
./UPSTREAM-MERGE.sh v1.42.3

Made with Cursor

Summary by CodeRabbit

  • New Features

    • Updated release references to v1.42.3 across build, test, and documentation assets.
  • Bug Fixes

    • Refreshed bundled tooling and test images so scorecard, operator SDK, and helm/operator workflows stay aligned with v1.42.3.
  • Documentation

    • Updated installation and CLI docs to use v1.42.3 assets (including the default decompression image to UBI9 9.8).
    • Added upgrade note for v1.42.3 (no migrations).
  • Chores

    • Bumped build environments to Go 1.26 and UBI9 9.8 across supported images and CI.

acornett21 and others added 27 commits March 12, 2026 09:53
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.78.0 to 1.79.3.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.78.0...v1.79.3)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.79.3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) from 4.1.3 to 4.1.4.
- [Release notes](https://github.com/go-jose/go-jose/releases)
- [Commits](go-jose/go-jose@v4.1.3...v4.1.4)

---
updated-dependencies:
- dependency-name: github.com/go-jose/go-jose/v4
  dependency-version: 4.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.40.0 to 1.43.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.40.0...v1.43.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/otel/sdk
  dependency-version: 1.43.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.16.5 to 5.17.1.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Commits](go-git/go-git@v5.16.5...v5.17.1)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.17.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/distribution/distribution/v3](https://github.com/distribution/distribution) from 3.0.0 to 3.1.0.
- [Release notes](https://github.com/distribution/distribution/releases)
- [Commits](distribution/distribution@v3.0.0...v3.1.0)

---
updated-dependencies:
- dependency-name: github.com/distribution/distribution/v3
  dependency-version: 3.1.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…(#7082)

Bumps [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp](https://github.com/open-telemetry/opentelemetry-go) from 1.36.0 to 1.43.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.36.0...v1.43.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp
  dependency-version: 1.43.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…p (#7081)

Bumps [go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp](https://github.com/open-telemetry/opentelemetry-go) from 1.36.0 to 1.43.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@v1.36.0...v1.43.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp
  dependency-version: 1.43.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp](https://github.com/open-telemetry/opentelemetry-go) from 0.12.2 to 0.19.0.
- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-go@log/v0.12.2...v0.19.0)

---
updated-dependencies:
- dependency-name: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
  dependency-version: 0.19.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/moby/spdystream](https://github.com/moby/spdystream) from 0.5.0 to 0.5.1.
- [Release notes](https://github.com/moby/spdystream/releases)
- [Commits](moby/spdystream@v0.5.0...v0.5.1)

---
updated-dependencies:
- dependency-name: github.com/moby/spdystream
  dependency-version: 0.5.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/distribution/distribution/v3](https://github.com/distribution/distribution) from 3.1.0 to 3.1.1.
- [Release notes](https://github.com/distribution/distribution/releases)
- [Commits](distribution/distribution@v3.1.0...v3.1.1)

---
updated-dependencies:
- dependency-name: github.com/distribution/distribution/v3
  dependency-version: 3.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.1 to 5.19.0.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.17.1...v5.19.0)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.19.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.19.0 to 5.19.1.
- [Release notes](https://github.com/go-git/go-git/releases)
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)
- [Commits](go-git/go-git@v5.19.0...v5.19.1)

---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
  dependency-version: 5.19.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.29 to 1.7.32.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v1.7.29...v1.7.32)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.32
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…cies (#7106)

Signed-off-by: Adam D. Cornett <adc@redhat.com>
Bumps ubi9/ubi-minimal from 9.7 to 9.8.

---
updated-dependencies:
- dependency-name: ubi9/ubi-minimal
  dependency-version: '9.8'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps ubi9/ubi-minimal from 9.7 to 9.8.

---
updated-dependencies:
- dependency-name: ubi9/ubi-minimal
  dependency-version: '9.8'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps ubi9/ubi-minimal from 9.7 to 9.8.

---
updated-dependencies:
- dependency-name: ubi9/ubi-minimal
  dependency-version: '9.8'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…ts (#7095)

Bumps ubi9/ubi-minimal from 9.7 to 9.8.

---
updated-dependencies:
- dependency-name: ubi9/ubi-minimal
  dependency-version: '9.8'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.32 to 1.7.33.
- [Release notes](https://github.com/containerd/containerd/releases)
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)
- [Commits](containerd/containerd@v1.7.32...v1.7.33)

---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
  dependency-version: 1.7.33
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Signed-off-by: Adam D. Cornett <adc@redhat.com>
Operator SDK v1.42.3

Merge executed via ./UPSTREAM-MERGE.sh v1.42.3 upstream main

Overwritten conflicts:
<NONE>
@openshift-ci-robot

openshift-ci-robot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

@PillaiManish: This pull request references OAPE-843 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target either version "5.0." or "openshift-5.0.", but it targets "openshift-4.22" instead.

Details

In response to this:

Rebase to upstream v1.42.3

Ran the following script to create the rebase branch:
./UPSTREAM-MERGE.sh v1.42.3

Made with Cursor

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Jul 8, 2026
@openshift-ci
openshift-ci Bot requested a review from grokspawn July 8, 2026 11:42
@openshift-ci
openshift-ci Bot requested a review from oceanc80 July 8, 2026 11:42
@coderabbitai

coderabbitai Bot commented Jul 8, 2026

Copy link
Copy Markdown

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: openshift/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: a91cc677-efa2-4df5-8950-cb51fe46e777

📥 Commits

Reviewing files that changed from the base of the PR and between 828a041 and 045fa0f.

📒 Files selected for processing (2)
  • .ci-operator.yaml
  • release/helm/Dockerfile
🚧 Files skipped from review as they are similar to previous changes (2)
  • .ci-operator.yaml
  • release/helm/Dockerfile

Walkthrough

This PR updates v1.42.3 release references, refreshes Go 1.26.3 and dependency pins, bumps builder and runtime images, aligns operator testdata, and adds or updates release documentation.

Changes

Release and image refresh

Layer / File(s) Summary
Release metadata and toolchain updates
Makefile, UPSTREAM-VERSION, patches/03-setversion.patch, go.mod, .ci-operator.yaml, release/helm/Dockerfile
Release constants, version derivation, lint tooling, Go toolchain and dependency versions, CI images, and release build images are updated.
Runtime and builder image updates
images/*/Dockerfile, internal/olm/fbcutil/util.go
Go builder images, UBI runtime images, and the default initialization image are updated to newer tags.
Operator testdata version alignment
testdata/go/v4/..., testdata/helm/memcached-operator/...
Operator SDK, helm-operator, and scorecard-test references are updated across Go and Helm testdata.
Release documentation updates
website/content/en/docs/...
CLI and installation references are updated, and v1.42.2 and v1.42.3 upgrade pages are added.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: oceanc80, grokspawn

🚥 Pre-merge checks | ✅ 15
✅ Passed checks (15 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the rebase to operator-framework/operator-sdk v1.42.3 and matches the main change in the PR.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stable And Deterministic Test Names ✅ Passed The visible diff only changes CI/Dockerfile base images; no Ginkgo test declarations or titles were added or edited.
Test Structure And Quality ✅ Passed The PR only changes .ci-operator.yaml and release/helm/Dockerfile; no Ginkgo test files or test logic were modified, so this check is not applicable.
Microshift Test Compatibility ✅ Passed The commit only changes build/deploy files; no new Ginkgo e2e tests or MicroShift-unsupported APIs were added.
Single Node Openshift (Sno) Test Compatibility ✅ Passed No new Ginkgo e2e tests were added; the non-vendor diff is utility code plus docs/configs, with no multi-node/HA test code present.
Topology-Aware Scheduling Compatibility ✅ Passed No topology-sensitive scheduling fields were added; the PR only bumps image/version tags in Dockerfiles, Makefiles, docs, and a util constant.
Ote Binary Stdout Contract ✅ Passed No new stdout writes were added in main/TestMain/RunSpecs/setup paths; added prints are confined to vendored Ginkgo CLI commands, outside the OTE binary contract.
Ipv6 And Disconnected Network Test Compatibility ✅ Passed No new Ginkgo e2e test files were added; recent commits changed docs, Dockerfiles, vendored deps, and scorecard YAMLs, with no *_test.go paths.
No-Weak-Crypto ✅ Passed Changed files are version/image bumps only; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret comparisons were added.
Container-Privileges ✅ Passed Touched YAML/manifests contain no privileged/host settings or allowPrivilegeEscalation=true; the Dockerfiles only bump base images and mostly use non-root users.
No-Sensitive-Data-In-Logs ✅ Passed Reviewed touched files; no new logging of passwords/tokens/PII found. The only log in fbcutil is an unchanged generic cleanup warning with no sensitive fields.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@go.mod`:
- Line 93: The build still depends on the vulnerable Docker module, so update
the dependency chain to remove github.com/docker/docker or replace it with a
patched github.com/moby/moby release. Adjust the module requirement in go.mod
and any related imports or transitive constraints so the legacy
github.com/docker/docker path is no longer pulled in.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

Comment thread go.mod
github.com/distribution/reference v0.6.0 // indirect
github.com/docker/cli v29.2.0+incompatible // indirect
github.com/docker/distribution v2.8.3+incompatible // indirect
github.com/docker/docker v28.5.2+incompatible // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail
go mod why -m github.com/docker/docker
go list -deps ./... | rg 'github.com/docker/docker'

Repository: openshift/ocp-release-operator-sdk

Length of output: 4979


🌐 Web query:

github.com/docker/docker v28.5.2+incompatible osv advisory CVE

💡 Result:

The version v28.5.2+incompatible of the github.com/docker/docker module is affected by multiple security vulnerabilities [1]. As of July 8, 2026, this module path is considered a legacy path for Docker/Moby, and patches for these vulnerabilities are only available in newer versions (v29.x and later) which have migrated to the github.com/moby/moby module path [1]. Notable CVEs affecting version v28.5.2 and earlier include: - CVE-2026-41567 (GHSA-x86f-5xw2-fm2r): A high-severity vulnerability where the PUT /containers/{id}/archive API can execute a container binary on the host with daemon (root) privileges when handling compressed archives [2][3][1]. - CVE-2026-41568 (GHSA-vp62-88p7-qqf5): A medium-severity race condition during docker cp mount setup that allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem [4][5][1]. - CVE-2026-42306 (GHSA-rg2x-37c3-w2rh): A high-severity issue involving a docker cp race condition that allows bind-mount redirection to a host path [1]. Because the github.com/docker/docker module no longer receives security updates on this path, users are advised to migrate their dependencies to the current github.com/moby/moby module (v29.x or later) to receive these fixes [1]. Users who cannot migrate immediately are advised to follow the mitigation strategies provided in the individual security advisories, such as running only trusted container images and limiting access to sensitive API endpoints [3][4].

Citations:


Remove or upgrade the vulnerable Docker module
github.com/docker/docker v28.5.2+incompatible is still pulled into the build graph and is covered by multiple high-severity OSV advisories. Update the dependency chain or move off the legacy github.com/docker/docker path to a patched github.com/moby/moby release.

🧰 Tools
🪛 OSV Scanner (2.4.0)

[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Moby has an Off-by-one error in its plugin privilege validation in github.com/docker/docker

(GO-2026-4883)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker

(GO-2026-4887)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Docker: Race condition in docker cp allows bind mount redirection to host path in github.com/docker/docker

(GO-2026-5617)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap in github.com/docker/docker

(GO-2026-5668)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Docker: PUT /containers/{id}/archive executes container binary on the host in github.com/docker/docker

(GO-2026-5746)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Moby has an Off-by-one error in its plugin privilege validation

(GHSA-pxq6-2prw-chj9)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Docker: Race condition in docker cp allows bind mount redirection to host path

(GHSA-rg2x-37c3-w2rh)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

(GHSA-vp62-88p7-qqf5)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Moby has AuthZ plugin bypass when provided oversized request bodies

(GHSA-x744-4wpc-v9h2)


[HIGH] 93-93: github.com/docker/docker 28.5.2+incompatible: Docker: PUT /containers/{id}/archive executes container binary on the host

(GHSA-x86f-5xw2-fm2r)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` at line 93, The build still depends on the vulnerable Docker module,
so update the dependency chain to remove github.com/docker/docker or replace it
with a patched github.com/moby/moby release. Adjust the module requirement in
go.mod and any related imports or transitive constraints so the legacy
github.com/docker/docker path is no longer pulled in.

Sources: Path instructions, Linters/SAST tools

@PillaiManish
PillaiManish force-pushed the v1.42.3-rebase-main branch 2 times, most recently from a197f50 to 828a041 Compare July 9, 2026 05:10
@mytreya-rh

Copy link
Copy Markdown

/lgtm
cc: @chiragkyal

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 9, 2026
@chiragkyal

chiragkyal commented Jul 21, 2026

Copy link
Copy Markdown
Member

/retitle OAPE-843: 5.0(4.23) chore: Rebase openshift/ocp-release-operator-sdk to upstream operator-framework/operator-sdk v1.42.3

@openshift-ci openshift-ci Bot changed the title OAPE-843: 4.22 chore: Rebase openshift/ocp-release-operator-sdk to upstream operator-framework/operator-sdk v1.42.3 OAPE-843: 5.0(4.23) chore: Rebase openshift/ocp-release-operator-sdk to upstream operator-framework/operator-sdk v1.42.3 Jul 21, 2026

@chiragkyal chiragkyal left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Please prefix the last commit with <carry>

/lgtm
/approve

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 21, 2026
The upstream v1.42.3 merge updated go.mod to require Go 1.26.3.
The Go 1.26 builder images are available under the openshift-5.0
stream (not 4.22). Update CI and release builder images accordingly.

Co-authored-by: Cursor <cursoragent@cursor.com>
@PillaiManish
PillaiManish force-pushed the v1.42.3-rebase-main branch from 828a041 to 045fa0f Compare July 21, 2026 06:06
@openshift-ci openshift-ci Bot removed the lgtm Indicates that a PR is ready to be merged. label Jul 21, 2026
@openshift-ci

openshift-ci Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

@PillaiManish: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@chiragkyal chiragkyal left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Jul 21, 2026
@openshift-ci

openshift-ci Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: chiragkyal, PillaiManish

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@Senthamilarasu-STA

Copy link
Copy Markdown

/label px-approved

@openshift-ci openshift-ci Bot added the px-approved Signifies that Product Support has signed off on this PR label Jul 23, 2026
@michaelryanpeter

Copy link
Copy Markdown
Contributor

/label docs-approved

@openshift-ci openshift-ci Bot added the docs-approved Signifies that Docs has signed off on this PR label Jul 23, 2026
@grokspawn

Copy link
Copy Markdown
Contributor

/unassign

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. docs-approved Signifies that Docs has signed off on this PR jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. px-approved Signifies that Product Support has signed off on this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants