# 4.13.69 Created: 2026-07-15 16:56:56 +0000 UTC Image Digest: `sha256:6ff433fc5d4e0a3e7a0496e41af47da5c9349afeaad949e6d3bb49764618e1b9` ## Changes from 4.14.70 ### Components * Kubernetes upgraded from 1.27.16 to 1.26.15 * Red Hat Enterprise Linux CoreOS upgraded from 414.92.202607210313-0 to 413.92.202607141229-0 ### New images * [ovirt-csi-driver](https://github.com/openshift/ovirt-csi-driver) git [54958deb](https://github.com/openshift/ovirt-csi-driver/commit/54958deb4998e08696af0abe3585486a6b5b6800) `sha256:4386f012274aa99a2d1152cacfd88cbd9a03b2e131142bd706eae0797bda895c` * [ovirt-csi-driver-operator](https://github.com/openshift/ovirt-csi-driver-operator) git [6011d655](https://github.com/openshift/ovirt-csi-driver-operator/commit/6011d6557a4e689124da6776a0cbd716edbc238a) `sha256:640a0dc76979e1c2338000fc7c10051470532c866aaeb97f540e28097ec94571` * [ovn-kubernetes-microshift-rhel-9](https://github.com/openshift/ovn-kubernetes) git [ad660789](https://github.com/openshift/ovn-kubernetes/commit/ad6607895c2b51c7bd8f7ddd1cb5e3fc50bd7c54) `sha256:f58ad0443f06d359b17c31d02f945c0185fa020bf2fdc17daf74aefe830da943` * [ovn-kubernetes-rhel-9](https://github.com/openshift/ovn-kubernetes) git [ad660789](https://github.com/openshift/ovn-kubernetes/commit/ad6607895c2b51c7bd8f7ddd1cb5e3fc50bd7c54) `sha256:eb7493b04867c5838cc22d464cc4e9415a62b8df9b9848b7fc28f7f5862465ad` ### Removed images * agent-installer-utils * azure-workload-identity-webhook * cluster-olm-operator * monitoring-plugin * olm-catalogd * olm-operator-controller * ovn-kubernetes * ovn-kubernetes-microshift ### Rebuilt images without code change * [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [f56c606a](https://github.com/openshift/apiserver-network-proxy/commit/f56c606ae15041b0c981e654ab577d2b0a3a0a8f) `sha256:b361332ed0b89c5a6157b2c144a8b3e9864fe16dba81a6f80ac17da0cd49fe9a` * machine-os-content `sha256:9f1c27abb122351de98f3d8baa9df6d25d37005dd8f5bd154d7b63b45e7b7d49` * rhel-coreos `sha256:142888d77c065de0855da6e9e9d42532e0963011c69ed4c78723bd3b14b123a4` * rhel-coreos-extensions `sha256:ace3dd1d3f7eb09ca49b1e7c3199969e8dbfb93bf62e747e26d2a486e39f1e34` ### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/c8c68cac0611ba7df7b34e900a666f64c2dec887) * [MGMT-23439](https://issues.redhat.com/browse/MGMT-23439): Bump Go 1.18 to 1.20 and regenerate code [#10043](https://github.com/openshift/assisted-service/pull/10043) * [MGMT-23439](https://issues.redhat.com/browse/MGMT-23439): Use archived dnf repositories for CentOS Stream 8 [#10017](https://github.com/openshift/assisted-service/pull/10017) * And 12 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/assisted-service/compare/f09936a257b0f83cc808ad6e70cfaa8e1632e7eb...c8c68cac0611ba7df7b34e900a666f64c2dec887) ### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/46c4e76ac9a7af1002a06f8bc8302c956e6893e2) * [OCPBUGS-59114](https://issues.redhat.com/browse/OCPBUGS-59114): CVE-2024-45339: Bump glog pkg to version 1.2.4 (#1195) [#1195](https://github.com/openshift/assisted-installer/pull/1195) * [OCPBUGS-53717](https://issues.redhat.com/browse/OCPBUGS-53717): Bump jwt to 4.5.2 in release-4.13 (#1094) [#1094](https://github.com/openshift/assisted-installer/pull/1094) * Bump golang.org/x/net to 0.33.0 (#1015) [#1015](https://github.com/openshift/assisted-installer/pull/1015) * [OCPBUGS-13612](https://issues.redhat.com/browse/OCPBUGS-13612): Update version go-http-metrics/gin (#935) [#935](https://github.com/openshift/assisted-installer/pull/935) * [MGMT-17595](https://issues.redhat.com/browse/MGMT-17595): Bump x/net to at least v0.24.0 to mitigate CVE-2023-45288 (#835) [#835](https://github.com/openshift/assisted-installer/pull/835) * [MGMT-17588](https://issues.redhat.com/browse/MGMT-17588): Bump runc to v1.1.12 to mitigate CVE-2024-21626 (#829) [#829](https://github.com/openshift/assisted-installer/pull/829) * [MGMT-17541](https://issues.redhat.com/browse/MGMT-17541): Replace broken golangci reference (#826) [#826](https://github.com/openshift/assisted-installer/pull/826) * [MGMT-13586](https://issues.redhat.com/browse/MGMT-13586): Wait for ETCD Bootstrap to complete (#670) (#717) [#670](https://github.com/openshift/assisted-installer/pull/670) * Updating ose-agent-installer-csr-approver images to be consistent with ART (#587) [#587](https://github.com/openshift/assisted-installer/pull/587) * [Full changelog](https://github.com/openshift/assisted-installer/compare/54aa57eb81d052a36ae8b78f2905d870ee0718ad...46c4e76ac9a7af1002a06f8bc8302c956e6893e2) ### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/b2417a540ef11f4739395745f0d41d7630093aa4) * [OCPBUGS-67568](https://issues.redhat.com/browse/OCPBUGS-67568): Bump logrus v1.9.0 to v1.9.3 [#1280](https://github.com/openshift/assisted-installer-agent/pull/1280) * And 17 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/91a728121bc65eae12af93ae003695d879a8f019...b2417a540ef11f4739395745f0d41d7630093aa4) ### [alibaba-cloud-controller-manager](https://github.com/openshift/cloud-provider-alibaba-cloud/tree/e41e11ccf25fa74e4cfb4ace124f35cffc0191a7) * [OCPBUGS-21238](https://issues.redhat.com/browse/OCPBUGS-21238): Bump golang.org/x/net to v0.19.0 [#43](https://github.com/openshift/cloud-provider-alibaba-cloud/pull/43) * [Full changelog](https://github.com/openshift/cloud-provider-alibaba-cloud/compare/8ba0b37a45510404a842d6dbd84d40a18008e81d...e41e11ccf25fa74e4cfb4ace124f35cffc0191a7) ### [alibaba-cloud-csi-driver](https://github.com/openshift/alibaba-cloud-csi-driver/tree/6384f904d041b761670532ac183271b8110707f2) * [OCPBUGS-21329](https://issues.redhat.com/browse/OCPBUGS-21329): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#37](https://github.com/openshift/alibaba-cloud-csi-driver/pull/37) * [OCPBUGS-16377](https://issues.redhat.com/browse/OCPBUGS-16377): [release-4.13] UPSTREAM: 763: Bump (golang.org/x/net): to address CVE-2022-41723 [#31](https://github.com/openshift/alibaba-cloud-csi-driver/pull/31) * [Full changelog](https://github.com/openshift/alibaba-cloud-csi-driver/compare/3dc363d364c43c1fb03e223147e25d9057273428...6384f904d041b761670532ac183271b8110707f2) ### [alibaba-disk-csi-driver-operator](https://github.com/openshift/alibaba-disk-csi-driver-operator/tree/7e415973dda671d82ae58d0107af274ff053db5c) * [OCPBUGS-21428](https://issues.redhat.com/browse/OCPBUGS-21428): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#65](https://github.com/openshift/alibaba-disk-csi-driver-operator/pull/65) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#55](https://github.com/openshift/alibaba-disk-csi-driver-operator/pull/55) * [Full changelog](https://github.com/openshift/alibaba-disk-csi-driver-operator/compare/8853e6ef4966018b96f9d8bfbf99df3a984bb454...7e415973dda671d82ae58d0107af274ff053db5c) ### [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws/tree/95c03b7b838f7c78efe8957b50c50a22cd625be7) * [OCPBUGS-32073](https://issues.redhat.com/browse/OCPBUGS-32073): update for CVE-2023-45288 [release-4.13] [#84](https://github.com/openshift/cloud-provider-aws/pull/84) * [OCPBUGS-27964](https://issues.redhat.com/browse/OCPBUGS-27964): bump go.opentelemetry.io [#72](https://github.com/openshift/cloud-provider-aws/pull/72) * [OCPBUGS-20738](https://issues.redhat.com/browse/OCPBUGS-20738): Update golang.org/x/net to v0.17.0 [#54](https://github.com/openshift/cloud-provider-aws/pull/54) * [Full changelog](https://github.com/openshift/cloud-provider-aws/compare/9a7820e81baa6ba8885b47a71416026036d53d79...95c03b7b838f7c78efe8957b50c50a22cd625be7) ### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/85a6abbea5b82b750fe12e6089588ed4c1243082) * [OCPBUGS-78230](https://issues.redhat.com/browse/OCPBUGS-78230): [release-4.13] hermetic 4.13 [#594](https://github.com/openshift/cluster-api-provider-aws/pull/594) * [OCPBUGS-32470](https://issues.redhat.com/browse/OCPBUGS-32470): UPSTREAM: 4670:Update awsmachine providerID and instanceID immediately after ec2:RunInstances is called [#509](https://github.com/openshift/cluster-api-provider-aws/pull/509) * [OCPBUGS-20836](https://issues.redhat.com/browse/OCPBUGS-20836): bump golang.org/x/net to v0.17.0 [#482](https://github.com/openshift/cluster-api-provider-aws/pull/482) * [OCPBUGS-15512](https://issues.redhat.com/browse/OCPBUGS-15512): Pass right SGs for IsExternallyManaged on creation [#468](https://github.com/openshift/cluster-api-provider-aws/pull/468) * [OCPBUGS-8481](https://issues.redhat.com/browse/OCPBUGS-8481): [release-4.13] Merge https://github.com/kubernetes-sigs/cluster-api-provider-aws:release-2.0 (28bc9b8) into release-4.13 [#458](https://github.com/openshift/cluster-api-provider-aws/pull/458) * [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/01508fcd4a006ce6bd5bcc63de6d9fc4e4d41f4e...85a6abbea5b82b750fe12e6089588ed4c1243082) ### [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver/tree/8205d51c798f8fea91eb6c1702fb63e7d6c17005) * [OCPBUGS-33363](https://issues.redhat.com/browse/OCPBUGS-33363): [release-4.13] UPSTREAM: 1919: Add reserved-volume-attachments [#266](https://github.com/openshift/aws-ebs-csi-driver/pull/266) * [OCPBUGS-20939](https://issues.redhat.com/browse/OCPBUGS-20939): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#240](https://github.com/openshift/aws-ebs-csi-driver/pull/240) * [OCPBUGS-13811](https://issues.redhat.com/browse/OCPBUGS-13811): Volume unmount repeats after successful unmount, preventing pod delete [#225](https://github.com/openshift/aws-ebs-csi-driver/pull/225) * [Full changelog](https://github.com/openshift/aws-ebs-csi-driver/compare/4622deecace538b375edc782a19cb5da977ae458...8205d51c798f8fea91eb6c1702fb63e7d6c17005) ### [aws-ebs-csi-driver-operator](https://github.com/openshift/aws-ebs-csi-driver-operator/tree/cc2d716073f4e9df06326c1a343b5ee189a56c4b) * [OCPBUGS-67575](https://issues.redhat.com/browse/OCPBUGS-67575): Updated logrus to v1.8.3 [#314](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/314) * [OCPBUGS-33363](https://issues.redhat.com/browse/OCPBUGS-33363): Explicitly reserve 1 attachment for the root disk [#307](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/307) * [OCPBUGS-21034](https://issues.redhat.com/browse/OCPBUGS-21034): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#281](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/281) * [OCPBUGS-13036](https://issues.redhat.com/browse/OCPBUGS-13036): 4.13: Bump (golang.org/x/net): to address CVE-2022-41723 [#220](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/220) * [OCPBUGS-13828](https://issues.redhat.com/browse/OCPBUGS-13828): assets/hypershift/controller_sa: Set controller ServiceAccount imagePullSecrets [#224](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/224) * [OCPBUGS-10645](https://issues.redhat.com/browse/OCPBUGS-10645): Hypershift: set control plane operand properties [#206](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/206) * [OCPBUGS-10405](https://issues.redhat.com/browse/OCPBUGS-10405): feat: add workload annotation to deployment and daemonset [#199](https://github.com/openshift/aws-ebs-csi-driver-operator/pull/199) * [Full changelog](https://github.com/openshift/aws-ebs-csi-driver-operator/compare/082e5ff33782f19c39a665967929faf6f1b76c3e...cc2d716073f4e9df06326c1a343b5ee189a56c4b) ### [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws/tree/e1a57b5e4ce731e8f90cd2c0d4ded81e40fa7a37) * [OCPBUGS-24563](https://issues.redhat.com/browse/OCPBUGS-24563): Reduce metrics cardinality [#96](https://github.com/openshift/machine-api-provider-aws/pull/96) * [OCPBUGS-21568](https://issues.redhat.com/browse/OCPBUGS-21568): Update golang.org/x/net to v0.17.0 [#89](https://github.com/openshift/machine-api-provider-aws/pull/89) * [OCPBUGS-13092](https://issues.redhat.com/browse/OCPBUGS-13092): Bump x/net package to v0.9.0 [#70](https://github.com/openshift/machine-api-provider-aws/pull/70) * [Full changelog](https://github.com/openshift/machine-api-provider-aws/compare/e2bb8297ff39438a8adae059a652e0687f56700a...e1a57b5e4ce731e8f90cd2c0d4ded81e40fa7a37) ### [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook/tree/ae01a272aff73b1390ee4c3934cc2382370a1660) * [OCPBUGS-32882](https://issues.redhat.com/browse/OCPBUGS-32882): Upgrade go-jose module to 2.6.3 [#190](https://github.com/openshift/aws-pod-identity-webhook/pull/190) * [OCPBUGS-21331](https://issues.redhat.com/browse/OCPBUGS-21331): Upgrade golang/x/net for CVE-2023-39325 [#184](https://github.com/openshift/aws-pod-identity-webhook/pull/184) * NO-ISSUE: Sync OWNERS with team members [#177](https://github.com/openshift/aws-pod-identity-webhook/pull/177) * snyk: exclude vendor/ [#172](https://github.com/openshift/aws-pod-identity-webhook/pull/172) * [OCPBUGS-12555](https://issues.redhat.com/browse/OCPBUGS-12555): Update builder to OCP4.13/go1.19 [#164](https://github.com/openshift/aws-pod-identity-webhook/pull/164) * [Full changelog](https://github.com/openshift/aws-pod-identity-webhook/compare/2c864ca0f09e038c4b0c82215ef1a6f60fb54e63...ae01a272aff73b1390ee4c3934cc2382370a1660) ### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/bf9bd02236e13c426d58c9828685dd6c598ff15f) * [OCPBUGS-21419](https://issues.redhat.com/browse/OCPBUGS-21419): Bump golang.org/x/net to v0.18.0 [#94](https://github.com/openshift/cloud-provider-azure/pull/94) * [OCPBUGS-17145](https://issues.redhat.com/browse/OCPBUGS-17145): Increase service idle max timeout to 100 minutes [#81](https://github.com/openshift/cloud-provider-azure/pull/81) * [OCPBUGS-13952](https://issues.redhat.com/browse/OCPBUGS-13952): Update x/net package to v0.8.0 [#68](https://github.com/openshift/cloud-provider-azure/pull/68) * [OCPBUGS-13011](https://issues.redhat.com/browse/OCPBUGS-13011): Allow deprecated beta topology labels to be applied for those not ready to migrate [#66](https://github.com/openshift/cloud-provider-azure/pull/66) * [OCPBUGS-8326](https://issues.redhat.com/browse/OCPBUGS-8326): update kubernetes dependencies to 1.26 [#56](https://github.com/openshift/cloud-provider-azure/pull/56) * [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/9ee3b74412f076928e05388af38b0372f484f3a9...bf9bd02236e13c426d58c9828685dd6c598ff15f) ### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/913fbb0f9a5d8c09737f4deb2a8445629403e2d0) * [OCPBUGS-78179](https://issues.redhat.com/browse/OCPBUGS-78179): [release-4.13] Hermetic 4.13 [#367](https://github.com/openshift/cluster-api-provider-azure/pull/367) * [OCPBUGS-36022](https://issues.redhat.com/browse/OCPBUGS-36022): Update go-retryablehttp to v0.7.7 [#314](https://github.com/openshift/cluster-api-provider-azure/pull/314) * [OCPBUGS-21503](https://issues.redhat.com/browse/OCPBUGS-21503): bump golang.org/x/net to v0.17.0 [#288](https://github.com/openshift/cluster-api-provider-azure/pull/288) * [OCPBUGS-12557](https://issues.redhat.com/browse/OCPBUGS-12557): Bump x/net package to v0.10.0 [#278](https://github.com/openshift/cluster-api-provider-azure/pull/278) * [OCPBUGS-8481](https://issues.redhat.com/browse/OCPBUGS-8481): [release-4.13] Merge https://github.com/kubernetes-sigs/cluster-api-provider-azure:release-1.7 (741a29d) into release-4.13 [#270](https://github.com/openshift/cluster-api-provider-azure/pull/270) * [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/728723125921ca6f44f38b3d90318cb98f74bd72...913fbb0f9a5d8c09737f4deb2a8445629403e2d0) ### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/b6d3fbcbf312f03247092323a88a43873b693f22) * [OCPBUGS-23216](https://issues.redhat.com/browse/OCPBUGS-23216): Update to v1.26.7 [#63](https://github.com/openshift/azure-disk-csi-driver/pull/63) * [OCPBUGS-20688](https://issues.redhat.com/browse/OCPBUGS-20688): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#55](https://github.com/openshift/azure-disk-csi-driver/pull/55) * [OCPBUGS-16318](https://issues.redhat.com/browse/OCPBUGS-16318): 4.13: UPSTREAM: 1744: fix: CVE-2022-41723 [#44](https://github.com/openshift/azure-disk-csi-driver/pull/44) * [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/6d3558a3b5ae9d383988495cc64dc05b4bba0382...b6d3fbcbf312f03247092323a88a43873b693f22) ### [azure-disk-csi-driver-operator](https://github.com/openshift/azure-disk-csi-driver-operator/tree/8534d7563e209e12eec38a2027cd1d9efd530071) * [OCPBUGS-20766](https://issues.redhat.com/browse/OCPBUGS-20766): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#102](https://github.com/openshift/azure-disk-csi-driver-operator/pull/102) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#86](https://github.com/openshift/azure-disk-csi-driver-operator/pull/86) * [Full changelog](https://github.com/openshift/azure-disk-csi-driver-operator/compare/918935767350f9f330b9d6a9c3ee03e9869e7828...8534d7563e209e12eec38a2027cd1d9efd530071) ### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/15e6f80ec4be826cd5d03ef4126be0dd171b506e) * [OCPBUGS-41678](https://issues.redhat.com/browse/OCPBUGS-41678): bump mount-utils to treat ENODEV error as corrupted mount [#81](https://github.com/openshift/azure-file-csi-driver/pull/81) * [OCPBUGS-20862](https://issues.redhat.com/browse/OCPBUGS-20862): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#38](https://github.com/openshift/azure-file-csi-driver/pull/38) * [OCPBUGS-16321](https://issues.redhat.com/browse/OCPBUGS-16321): 4.13: UPSTREAM: 1211: fix: CVE-2022-41723 [#30](https://github.com/openshift/azure-file-csi-driver/pull/30) * [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/71fa09b11075da73a8934127a181ee03abd738f8...15e6f80ec4be826cd5d03ef4126be0dd171b506e) ### [azure-file-csi-driver-operator](https://github.com/openshift/azure-file-csi-driver-operator/tree/247aeae8c7fc836d6b7173dc8d07859df5c2ba38) * [OCPBUGS-67580](https://issues.redhat.com/browse/OCPBUGS-67580): Bump github.com/sirupsen/logrus to v1.8.3 [#115](https://github.com/openshift/azure-file-csi-driver-operator/pull/115) * [OCPBUGS-20964](https://issues.redhat.com/browse/OCPBUGS-20964): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#77](https://github.com/openshift/azure-file-csi-driver-operator/pull/77) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#67](https://github.com/openshift/azure-file-csi-driver-operator/pull/67) * [Full changelog](https://github.com/openshift/azure-file-csi-driver-operator/compare/9a5a5a6950401d6587e128e2c149fd05cf7201a3...247aeae8c7fc836d6b7173dc8d07859df5c2ba38) ### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/dcdd193c28b1ae9d124a639bf7e806b70275b416) * [OCPBUGS-78265](https://issues.redhat.com/browse/OCPBUGS-78265): hermetic 4.13 [#187](https://github.com/openshift/machine-api-provider-azure/pull/187) * [OCPBUGS-29906](https://issues.redhat.com/browse/OCPBUGS-29906): Don't create availability set when using spot instances [#104](https://github.com/openshift/machine-api-provider-azure/pull/104) * [OCPBUGS-24563](https://issues.redhat.com/browse/OCPBUGS-24563): Reduce metrics cardinality [#89](https://github.com/openshift/machine-api-provider-azure/pull/89) * [OCPBUGS-20758](https://issues.redhat.com/browse/OCPBUGS-20758): Bump x/net package to v0.18.0 [#83](https://github.com/openshift/machine-api-provider-azure/pull/83) * [OCPBUGS-13053](https://issues.redhat.com/browse/OCPBUGS-13053): Bump x/net to v.0.7.0 [#61](https://github.com/openshift/machine-api-provider-azure/pull/61) * [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/d526284e26f37f36f9d5297faa801ea117d81f48...dcdd193c28b1ae9d124a639bf7e806b70275b416) ### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/b3d2f7b8834666c220b88f7aee46ec9160274bcc) * [OCPBUGS-81578](https://issues.redhat.com/browse/OCPBUGS-81578): Azure UPI ARM template: use storageAccountId [#10454](https://github.com/openshift/installer/pull/10454) * [OCPBUGS-76931](https://issues.redhat.com/browse/OCPBUGS-76931): terraform/provider/google: Fixing inconsistencies with the service account creation [#10384](https://github.com/openshift/installer/pull/10384) * [OCPBUGS-66232](https://issues.redhat.com/browse/OCPBUGS-66232): Replace terraform-provider-google with Openshift fork [#10141](https://github.com/openshift/installer/pull/10141) * [OCPBUGS-62848](https://issues.redhat.com/browse/OCPBUGS-62848): Release 4.13 bump terraform provider azurerm [#10006](https://github.com/openshift/installer/pull/10006) * [OCPBUGS-55034](https://issues.redhat.com/browse/OCPBUGS-55034): IBMCloud: Move to IBM TF openshift fork [#9668](https://github.com/openshift/installer/pull/9668) * [OCPBUGS-39217](https://issues.redhat.com/browse/OCPBUGS-39217): Add yq v4 to ci image [#8922](https://github.com/openshift/installer/pull/8922) * [OCPBUGS-36088](https://issues.redhat.com/browse/OCPBUGS-36088): [release-4.13]: bump go-retryablehttp for CVE fix [#8659](https://github.com/openshift/installer/pull/8659) * [OCPBUGS-29124](https://issues.redhat.com/browse/OCPBUGS-29124): IBMCloud: Handle disk delete errors [#7989](https://github.com/openshift/installer/pull/7989) * [OCPBUGS-37168](https://issues.redhat.com/browse/OCPBUGS-37168): Add yq-v4 to the upi-installer image for CI [#8743](https://github.com/openshift/installer/pull/8743) * [OCPBUGS-35976](https://issues.redhat.com/browse/OCPBUGS-35976): [release-4.13] bump github.com/containers/image for CVE fix [#8651](https://github.com/openshift/installer/pull/8651) * [OCPBUGS-33732](https://issues.redhat.com/browse/OCPBUGS-33732): preserve category name when trying to find tag category [#8419](https://github.com/openshift/installer/pull/8419) * [OCPBUGS-33062](https://issues.redhat.com/browse/OCPBUGS-33062): openstack: Honour worker server group policy [#8323](https://github.com/openshift/installer/pull/8323) * [OCPBUGS-32359](https://issues.redhat.com/browse/OCPBUGS-32359): Updated libvirt installer to include multi-arch yq and symlink for backwards compatibility [#8284](https://github.com/openshift/installer/pull/8284) * [OCPBUGS-22979](https://issues.redhat.com/browse/OCPBUGS-22979): IBMCloud: Add eu-es region [#7685](https://github.com/openshift/installer/pull/7685) * [OCPBUGS-30629](https://issues.redhat.com/browse/OCPBUGS-30629): baremetal: populate customDeploy in advance [#8129](https://github.com/openshift/installer/pull/8129) * [OCPBUGS-29627](https://issues.redhat.com/browse/OCPBUGS-29627): update RHCOS 4.13 bootimage metadata to 413.92.202402131523-0 [#8038](https://github.com/openshift/installer/pull/8038) * [OCPBUGS-30000](https://issues.redhat.com/browse/OCPBUGS-30000): [release-4.13] Bump containerd for vulnerability fix [#8073](https://github.com/openshift/installer/pull/8073) * [OCPBUGS-28654](https://issues.redhat.com/browse/OCPBUGS-28654): Fix depreciated typo [#7963](https://github.com/openshift/installer/pull/7963) * [OCPBUGS-27453](https://issues.redhat.com/browse/OCPBUGS-27453): baremetal: correct external_http_url for v6-only BMCs [#7934](https://github.com/openshift/installer/pull/7934) * [OCPBUGS-23499](https://issues.redhat.com/browse/OCPBUGS-23499): update RHCOS 4.13 bootimage metadata to 413.92.202401100947-0 [#7920](https://github.com/openshift/installer/pull/7920) * [OCPBUGS-25420](https://issues.redhat.com/browse/OCPBUGS-25420): destroy: gcp: fix destroying regional disks [#7840](https://github.com/openshift/installer/pull/7840) * [OCPBUGS-23464](https://issues.redhat.com/browse/OCPBUGS-23464): Add KMS encryption keys if provided [#7746](https://github.com/openshift/installer/pull/7746) * [OCPBUGS-23141](https://issues.redhat.com/browse/OCPBUGS-23141): Specify google cloud CLI to version 447.0.0 [#7706](https://github.com/openshift/installer/pull/7706) * [OCPBUGS-22939](https://issues.redhat.com/browse/OCPBUGS-22939): azure: validation: validate defaultMachinePlatform [#7679](https://github.com/openshift/installer/pull/7679) * [OCPBUGS-14551](https://issues.redhat.com/browse/OCPBUGS-14551): [vSphere] Upi installation failed due to VMs for master and worker node creation failed [#7229](https://github.com/openshift/installer/pull/7229) * [OCPBUGS-19307](https://issues.redhat.com/browse/OCPBUGS-19307): Implement workaround to allow SNO installations for OKD/FCOS [#7480](https://github.com/openshift/installer/pull/7480) * [OCPBUGS-18787](https://issues.redhat.com/browse/OCPBUGS-18787): vSphere set bootstrap/master efi [#7481](https://github.com/openshift/installer/pull/7481) * [OCPBUGS-19320](https://issues.redhat.com/browse/OCPBUGS-19320): [release-4.13] for vsphere ipi add cluster domain to the uploaded vm configs so that… [#7498](https://github.com/openshift/installer/pull/7498) * [OCPBUGS-20141](https://issues.redhat.com/browse/OCPBUGS-20141): [release-4.13] Use updated ansible-core for Openstack image [#7559](https://github.com/openshift/installer/pull/7559) * [OCPBUGS-19670](https://issues.redhat.com/browse/OCPBUGS-19670): [release-4.13] Allow different service account for xpn installs in gcp [#7524](https://github.com/openshift/installer/pull/7524) * [OCPBUGS-19773](https://issues.redhat.com/browse/OCPBUGS-19773): Increase bootstrap timeout for vSphere platform by 30 mins [#7530](https://github.com/openshift/installer/pull/7530) * [OCPBUGS-16383](https://issues.redhat.com/browse/OCPBUGS-16383): [release-4.13] Default dataStore is returned the name instead the inventoryPath [#7343](https://github.com/openshift/installer/pull/7343) * [OCPBUGS-13681](https://issues.redhat.com/browse/OCPBUGS-13681): FCOS: bump to latest stable version [#7188](https://github.com/openshift/installer/pull/7188) * [OCPBUGS-11093](https://issues.redhat.com/browse/OCPBUGS-11093): Azure: don't set default subscriptionID for disk encryption sets [#7432](https://github.com/openshift/installer/pull/7432) * [OCPBUGS-17809](https://issues.redhat.com/browse/OCPBUGS-17809): Allow destroy for C2S isolated (us-iso and us-isob) partitions [#7427](https://github.com/openshift/installer/pull/7427) * [OCPBUGS-15231](https://issues.redhat.com/browse/OCPBUGS-15231): new Aws secret regions support [#7264](https://github.com/openshift/installer/pull/7264) * [OCPBUGS-15222](https://issues.redhat.com/browse/OCPBUGS-15222): terraform: aws: secret regions now support ALIAS record [#7262](https://github.com/openshift/installer/pull/7262) * [OCPBUGS-17823](https://issues.redhat.com/browse/OCPBUGS-17823): CORS-2445: GCP: Add osImage to the install config [#7431](https://github.com/openshift/installer/pull/7431) * [OCPBUGS-14432](https://issues.redhat.com/browse/OCPBUGS-14432): Replica validations [#7423](https://github.com/openshift/installer/pull/7423) * [OCPBUGS-13865](https://issues.redhat.com/browse/OCPBUGS-13865): vSphere Add ova sha query; additional debugging [#7198](https://github.com/openshift/installer/pull/7198) * [OCPBUGS-16640](https://issues.redhat.com/browse/OCPBUGS-16640): [release-4.13] Update azure cli version to 2.49.0 [#7357](https://github.com/openshift/installer/pull/7357) * [OCPBUGS-16777](https://issues.redhat.com/browse/OCPBUGS-16777): update RHCOS 4.13 bootimage metadata to 413.92.202307260246-0 [#7410](https://github.com/openshift/installer/pull/7410) * [CORS-2764](https://issues.redhat.com/browse/CORS-2764): AWS Shared VPC Backport [release-4.13] [#7362](https://github.com/openshift/installer/pull/7362) * [OCPBUGS-17104](https://issues.redhat.com/browse/OCPBUGS-17104): [release-4.13] vsphere terraform bump [#7383](https://github.com/openshift/installer/pull/7383) * [OCPBUGS-17397](https://issues.redhat.com/browse/OCPBUGS-17397): backport openstack UPI for ansible 2.10 [#7385](https://github.com/openshift/installer/pull/7385) * [OCPBUGS-15290](https://issues.redhat.com/browse/OCPBUGS-15290): GCP: ic: improve project validation [#7361](https://github.com/openshift/installer/pull/7361) * [OCPBUGS-16390](https://issues.redhat.com/browse/OCPBUGS-16390): Allow override of networkType [#7344](https://github.com/openshift/installer/pull/7344) * [OCPBUGS-16673](https://issues.redhat.com/browse/OCPBUGS-16673): Fix timing issue between network services [#7358](https://github.com/openshift/installer/pull/7358) * [OCPBUGS-14711](https://issues.redhat.com/browse/OCPBUGS-14711): Convert Rendezvous IPv6 address to canonical format [#7237](https://github.com/openshift/installer/pull/7237) * [OCPBUGS-16066](https://issues.redhat.com/browse/OCPBUGS-16066): Use correct SELinux label. Make rename atomic. [#7315](https://github.com/openshift/installer/pull/7315) * [OCPBUGS-14599](https://issues.redhat.com/browse/OCPBUGS-14599): Log additional host info at warning level [#7233](https://github.com/openshift/installer/pull/7233) * [OCPBUGS-15866](https://issues.redhat.com/browse/OCPBUGS-15866): Use the same names for public LB in IPI and UPI Azure [#7302](https://github.com/openshift/installer/pull/7302) * [OCPBUGS-16124](https://issues.redhat.com/browse/OCPBUGS-16124): azure: skip LB creation when not needed [#7322](https://github.com/openshift/installer/pull/7322) * [OCPBUGS-13812](https://issues.redhat.com/browse/OCPBUGS-13812): ic: azure: validate diskTypes in AzureStack [#7195](https://github.com/openshift/installer/pull/7195) * [OCPBUGS-15230](https://issues.redhat.com/browse/OCPBUGS-15230): azure: skip NSG creation when BYO vnet [#7263](https://github.com/openshift/installer/pull/7263) * [OCPBUGS-15591](https://issues.redhat.com/browse/OCPBUGS-15591): [release-4.13] gcp: add confidential compute support for boostrap TF [#7298](https://github.com/openshift/installer/pull/7298) * [OCPBUGS-15187](https://issues.redhat.com/browse/OCPBUGS-15187): images: installer: add xz to the container [#7260](https://github.com/openshift/installer/pull/7260) * [OCPBUGS-14867](https://issues.redhat.com/browse/OCPBUGS-14867): Shorten SNO installation duration by releasing CPC lease [#7241](https://github.com/openshift/installer/pull/7241) * [OCPBUGS-13752](https://issues.redhat.com/browse/OCPBUGS-13752): Set AdditionalTrustBundle in override when mirroring not enabled [#7191](https://github.com/openshift/installer/pull/7191) * [OCPBUGS-15289](https://issues.redhat.com/browse/OCPBUGS-15289): gcp use preconfigured private zone for installation [#7271](https://github.com/openshift/installer/pull/7271) * [OCPBUGS-14916](https://issues.redhat.com/browse/OCPBUGS-14916): Replace with govc docker image and fix ibmcli folder permission issue [#7245](https://github.com/openshift/installer/pull/7245) * [OCPBUGS-13323](https://issues.redhat.com/browse/OCPBUGS-13323): update RHCOS 4.13 bootimage metadata to 413.92.202306140611-0 [#7248](https://github.com/openshift/installer/pull/7248) * [OCPBUGS-14860](https://issues.redhat.com/browse/OCPBUGS-14860): GCP XPN Private Cluster Fails with no Public Zone [#7240](https://github.com/openshift/installer/pull/7240) * [OCPBUGS-13765](https://issues.redhat.com/browse/OCPBUGS-13765): Support /dev/disk/by-path root device hints [#7193](https://github.com/openshift/installer/pull/7193) * [OCPBUGS-14171](https://issues.redhat.com/browse/OCPBUGS-14171): Ignore IAM Roles that the Installer is not authorized to access [#7210](https://github.com/openshift/installer/pull/7210) * [OCPBUGS-11530](https://issues.redhat.com/browse/OCPBUGS-11530): [release-4.13] add project filter to gcp usage api requests [#7045](https://github.com/openshift/installer/pull/7045) * [OCPBUGS-10493](https://issues.redhat.com/browse/OCPBUGS-10493): Nutanix Hostname of the VM is not set when using DHCP network config [#7016](https://github.com/openshift/installer/pull/7016) * [OCPBUGS-14027](https://issues.redhat.com/browse/OCPBUGS-14027): GCP XPN: Pass instance service acct in manual mode [#7204](https://github.com/openshift/installer/pull/7204) * [OCPBUGS-11775](https://issues.redhat.com/browse/OCPBUGS-11775): Log additional info when status is pending-user-action [#7090](https://github.com/openshift/installer/pull/7090) * [OCPBUGS-13086](https://issues.redhat.com/browse/OCPBUGS-13086): Bootstrap on aws should have same metadata service type as on other nodes [#7162](https://github.com/openshift/installer/pull/7162) * [OCPBUGS-12886](https://issues.redhat.com/browse/OCPBUGS-12886): use python3 for cloud sdk [#7140](https://github.com/openshift/installer/pull/7140) * [OCPBUGS-11799](https://issues.redhat.com/browse/OCPBUGS-11799): update RHCOS 4.13 bootimage metadata to 413.92.202305021736-0 [#7156](https://github.com/openshift/installer/pull/7156) * [OCPBUGS-12910](https://issues.redhat.com/browse/OCPBUGS-12910): openstack: Add netcat to the Installer image [#7144](https://github.com/openshift/installer/pull/7144) * [OCPBUGS-11845](https://issues.redhat.com/browse/OCPBUGS-11845), [OCPBUGS-11846](https://issues.redhat.com/browse/OCPBUGS-11846), [OCPBUGS-11847](https://issues.redhat.com/browse/OCPBUGS-11847): CVE: bump hashicorp/vault version [#7097](https://github.com/openshift/installer/pull/7097) * [OCPBUGS-5140](https://issues.redhat.com/browse/OCPBUGS-5140): [Alibaba] update the bandwidth value of EIP [#7010](https://github.com/openshift/installer/pull/7010) * [OCPBUGS-11261](https://issues.redhat.com/browse/OCPBUGS-11261): Fix and improve locking session and AWS Metadata access [#7129](https://github.com/openshift/installer/pull/7129) * [OCPBUGS-12179](https://issues.redhat.com/browse/OCPBUGS-12179): agent: copy also symbolic link when storing agent-tui related files into the agent ISO [#7113](https://github.com/openshift/installer/pull/7113) * [OCPBUGS-11950](https://issues.redhat.com/browse/OCPBUGS-11950): vsphere, nutanix survey: relax vip in machine cidr [#7107](https://github.com/openshift/installer/pull/7107) * [OCPBUGS-11529](https://issues.redhat.com/browse/OCPBUGS-11529): [release-4.13] gather: azure: fix collecting VM serial logs [#7077](https://github.com/openshift/installer/pull/7077) * [OCPBUGS-10658](https://issues.redhat.com/browse/OCPBUGS-10658): openstack: No master primarySubnet control-plane if portTarget is set [#7008](https://github.com/openshift/installer/pull/7008) * [OCPBUGS-11789](https://issues.redhat.com/browse/OCPBUGS-11789): update RHCOS 4.13 bootimage metadata to 413.92.202304131328-0 [#7093](https://github.com/openshift/installer/pull/7093) * [OCPBUGS-11659](https://issues.redhat.com/browse/OCPBUGS-11659): Upgrade libnmstate version used [#7082](https://github.com/openshift/installer/pull/7082) * [OCPBUGS-11661](https://issues.redhat.com/browse/OCPBUGS-11661): AWS - Remove ACLs from s3 ign [#7083](https://github.com/openshift/installer/pull/7083) * [OCPBUGS-11010](https://issues.redhat.com/browse/OCPBUGS-11010): vSphere - finding networks use full path cluster [#7043](https://github.com/openshift/installer/pull/7043) * [OCPBUGS-10892](https://issues.redhat.com/browse/OCPBUGS-10892): Don't log password values [#7024](https://github.com/openshift/installer/pull/7024) * [OCPBUGS-11093](https://issues.redhat.com/browse/OCPBUGS-11093): pkg/asset/installconfig: set subscriptionID [#7049](https://github.com/openshift/installer/pull/7049) * [OCPBUGS-11188](https://issues.redhat.com/browse/OCPBUGS-11188): Use 100 GB as minimum disk size in validations [#7053](https://github.com/openshift/installer/pull/7053) * [OCPBUGS-10989](https://issues.redhat.com/browse/OCPBUGS-10989): Properly handle invalid agent command [#7034](https://github.com/openshift/installer/pull/7034) * [OCPBUGS-10903](https://issues.redhat.com/browse/OCPBUGS-10903): IBMCloud: Fix SSH Private bootstrap [#7027](https://github.com/openshift/installer/pull/7027) * [OCPBUGS-11011](https://issues.redhat.com/browse/OCPBUGS-11011): Do not remove host default configuration unless network configuration is provided for it [#7044](https://github.com/openshift/installer/pull/7044) * [OCPBUGS-11040](https://issues.redhat.com/browse/OCPBUGS-11040): remove container-runtime flag from kubelet config [#7048](https://github.com/openshift/installer/pull/7048) * [OCPBUGS-11054](https://issues.redhat.com/browse/OCPBUGS-11054): GCP: add europe-west12 region to the survey as supported region [#7046](https://github.com/openshift/installer/pull/7046) * [OCPBUGS-11004](https://issues.redhat.com/browse/OCPBUGS-11004): Kubelet Client Cert should include system:serviceaccounts group [#7039](https://github.com/openshift/installer/pull/7039) * [OCPBUGS-10902](https://issues.redhat.com/browse/OCPBUGS-10902): IBMCloud set dnsrecords offset [#7026](https://github.com/openshift/installer/pull/7026) * rhcos: Bump to 413.92.202303281804-0 [#7041](https://github.com/openshift/installer/pull/7041) * [OCPBUGS-10657](https://issues.redhat.com/browse/OCPBUGS-10657): Do not always output warning msg when releaseImage is digest [#7007](https://github.com/openshift/installer/pull/7007) * [OCPBUGS-10656](https://issues.redhat.com/browse/OCPBUGS-10656): Verify output file exists when `oc image extract` is run [#7006](https://github.com/openshift/installer/pull/7006) * [OCPBUGS-10813](https://issues.redhat.com/browse/OCPBUGS-10813): bootstrap-pivot: skip pivot in SCOS Live ISO [#7020](https://github.com/openshift/installer/pull/7020) * [OCPBUGS-8511](https://issues.redhat.com/browse/OCPBUGS-8511): baremetal: do not use port 80 for httpd [#7022](https://github.com/openshift/installer/pull/7022) * [OCPBUGS-10214](https://issues.redhat.com/browse/OCPBUGS-10214): CVE-2023-25173: bump containerd [#7013](https://github.com/openshift/installer/pull/7013) * [OCPBUGS-10597](https://issues.redhat.com/browse/OCPBUGS-10597): fix agent tui showing up multiple times [#6989](https://github.com/openshift/installer/pull/6989) * [OCPBUGS-6265](https://issues.redhat.com/browse/OCPBUGS-6265): Shorten SNO installation duration by releasing CVO lease [#6979](https://github.com/openshift/installer/pull/6979) * [OCPBUGS-10585](https://issues.redhat.com/browse/OCPBUGS-10585): rhcos: Update to 413.92.202303190222-0 [#6997](https://github.com/openshift/installer/pull/6997) * [OCPBUGS-10499](https://issues.redhat.com/browse/OCPBUGS-10499): [release-4.13] CVE: bump mongo-go-driver for fix [#6986](https://github.com/openshift/installer/pull/6986) * [OCPBUGS-10436](https://issues.redhat.com/browse/OCPBUGS-10436): Sort userTags in Machine and Machineset manifests [#6983](https://github.com/openshift/installer/pull/6983) * [OCPBUGS-10213](https://issues.redhat.com/browse/OCPBUGS-10213): aws: bump aws-sdk-go version [#6969](https://github.com/openshift/installer/pull/6969) * update RHCOS 4.13 bootimage metadata [#6955](https://github.com/openshift/installer/pull/6955) * [OCPBUGS-8463](https://issues.redhat.com/browse/OCPBUGS-8463): [release-4.13] OpenStack Failure domains [#6948](https://github.com/openshift/installer/pull/6948) * [OCPBUGS-8312](https://issues.redhat.com/browse/OCPBUGS-8312): Power VS: Add resourceGroup to infrastructure manifest [#6930](https://github.com/openshift/installer/pull/6930) * [OCPBUGS-8353](https://issues.redhat.com/browse/OCPBUGS-8353): Disable 'create pxe-files' command [#6939](https://github.com/openshift/installer/pull/6939) * [OCPBUGS-8463](https://issues.redhat.com/browse/OCPBUGS-8463): [release-4.13] openstack: consistent TechPreview-only feature validation [#6934](https://github.com/openshift/installer/pull/6934) * [OCPBUGS-8341](https://issues.redhat.com/browse/OCPBUGS-8341): Pass Capabilites from install-config to cluster [#6936](https://github.com/openshift/installer/pull/6936) * [OCPBUGS-8343](https://issues.redhat.com/browse/OCPBUGS-8343): Disable systemd status while TUI showing [#6938](https://github.com/openshift/installer/pull/6938) * [OCPBUGS-8342](https://issues.redhat.com/browse/OCPBUGS-8342): Specify filename for default registries.conf [#6937](https://github.com/openshift/installer/pull/6937) * [SPLAT-636](https://issues.redhat.com/browse/SPLAT-636): Create edge compute pool to support AWS Local Zones [#6931](https://github.com/openshift/installer/pull/6931) * And 1 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/installer/compare/4dd5abdf12a97ef0f32f6774ab79fa8dc6482f34...b3d2f7b8834666c220b88f7aee46ec9160274bcc) ### [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal/tree/ec65cd2e98d30b9449d45eccdb2b17d030d83bdc) * [OCPBUGS-78102](https://issues.redhat.com/browse/OCPBUGS-78102): [release-4.13] fix vendor/ for hermetic migration [#246](https://github.com/openshift/cluster-api-provider-baremetal/pull/246) * [OCPBUGS-46640](https://issues.redhat.com/browse/OCPBUGS-46640): Bump x/net 0.33.0 [#229](https://github.com/openshift/cluster-api-provider-baremetal/pull/229) * [OCPBUGS-29822](https://issues.redhat.com/browse/OCPBUGS-29822): Extend metal3remediation aggregation role [#212](https://github.com/openshift/cluster-api-provider-baremetal/pull/212) * [OCPBUGS-21701](https://issues.redhat.com/browse/OCPBUGS-21701): Uplift x/net to v0.17.0 [#199](https://github.com/openshift/cluster-api-provider-baremetal/pull/199) * [OCPBUGS-16084](https://issues.redhat.com/browse/OCPBUGS-16084): Fix Metal3Remediation CRD install order [#194](https://github.com/openshift/cluster-api-provider-baremetal/pull/194) * [OCPBUGS-12692](https://issues.redhat.com/browse/OCPBUGS-12692): Use go 1.19 and uplift x/net to 0.7.0 [#192](https://github.com/openshift/cluster-api-provider-baremetal/pull/192) * [Full changelog](https://github.com/openshift/cluster-api-provider-baremetal/compare/0c1c23f3a63168ec2deb171dc66149fe7ec558ac...ec65cd2e98d30b9449d45eccdb2b17d030d83bdc) ### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/3f56e498ce77b472070c804fca0522eb234ed99f) * [OCPBUGS-53334](https://issues.redhat.com/browse/OCPBUGS-53334): BMO can expose any secret via BMCEventSubscription CRD 4.13 [#411](https://github.com/openshift/baremetal-operator/pull/411) * [OCPBUGS-30629](https://issues.redhat.com/browse/OCPBUGS-30629): Do not update instance_info and deploy_interface for active nodes [#337](https://github.com/openshift/baremetal-operator/pull/337) * [OCPBUGS-23504](https://issues.redhat.com/browse/OCPBUGS-23504): hack for deploying V6-only clusters from dualstack hubs [#321](https://github.com/openshift/baremetal-operator/pull/321) * [OCPBUGS-21167](https://issues.redhat.com/browse/OCPBUGS-21167): Uplift x/net to v0.17.0 [#309](https://github.com/openshift/baremetal-operator/pull/309) * [OCPBUGS-17365](https://issues.redhat.com/browse/OCPBUGS-17365): Trigger reconcile on Secret change [#295](https://github.com/openshift/baremetal-operator/pull/295) * [OCPBUGS-16013](https://issues.redhat.com/browse/OCPBUGS-16013): Bump go.etcd.io/etcd/client/pkg/v3 from 3.5.6 to 3.5.9 [#292](https://github.com/openshift/baremetal-operator/pull/292) * [OCPBUGS-17229](https://issues.redhat.com/browse/OCPBUGS-17229): Set minimum TLS version for webhook to 1.2 [#294](https://github.com/openshift/baremetal-operator/pull/294) * [OCPBUGS-13374](https://issues.redhat.com/browse/OCPBUGS-13374): Do not try to update images for nodes in transient states [#282](https://github.com/openshift/baremetal-operator/pull/282) * [OCPBUGS-13927](https://issues.redhat.com/browse/OCPBUGS-13927): Deleting unmanaged BMH get stuck fix [#281](https://github.com/openshift/baremetal-operator/pull/281) * [OCPBUGS-12363](https://issues.redhat.com/browse/OCPBUGS-12363): release-4.13: Use same settings for provisioner and controller logs [#275](https://github.com/openshift/baremetal-operator/pull/275) * [OCPBUGS-13082](https://issues.redhat.com/browse/OCPBUGS-13082): Allow by-path devices in root device hints [#277](https://github.com/openshift/baremetal-operator/pull/277) * [OCPBUGS-12708](https://issues.redhat.com/browse/OCPBUGS-12708): Supported forced reboot of preprovisioning images [#272](https://github.com/openshift/baremetal-operator/pull/272) * [OCPBUGS-12828](https://issues.redhat.com/browse/OCPBUGS-12828): [release 4.13] Store htpasswd files in Secrets instead of ConfigMaps [#273](https://github.com/openshift/baremetal-operator/pull/273) * [OCPBUGS-11870](https://issues.redhat.com/browse/OCPBUGS-11870): Create nodes with namespace already prepended [#265](https://github.com/openshift/baremetal-operator/pull/265) * [OCPBUGS-11983](https://issues.redhat.com/browse/OCPBUGS-11983): Revert live-iso validation [#268](https://github.com/openshift/baremetal-operator/pull/268) * [OCPBUGS-11213](https://issues.redhat.com/browse/OCPBUGS-11213): backport: Delay delete of detached hosts [#261](https://github.com/openshift/baremetal-operator/pull/261) * [Full changelog](https://github.com/openshift/baremetal-operator/compare/483d019146b8495b9299c08c57461747e727f3f7...3f56e498ce77b472070c804fca0522eb234ed99f) ### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/1280cf541c220af73b9886379dad2dfa4921f73b) * [OCPBUGS-26929](https://issues.redhat.com/browse/OCPBUGS-26929): Add .snyk file to ignore vendor and test files [#295](https://github.com/openshift/baremetal-runtimecfg/pull/295) * [OCPBUGS-22207](https://issues.redhat.com/browse/OCPBUGS-22207): deps: upgrade x/sys [#282](https://github.com/openshift/baremetal-runtimecfg/pull/282) * [OCPBUGS-20081](https://issues.redhat.com/browse/OCPBUGS-20081): Increase timeout for bootstrap kubeapi [#278](https://github.com/openshift/baremetal-runtimecfg/pull/278) * [OCPBUGS-18582](https://issues.redhat.com/browse/OCPBUGS-18582): Move haproxy firewall rule check earlier in loop [#271](https://github.com/openshift/baremetal-runtimecfg/pull/271) * [OCPBUGS-17423](https://issues.redhat.com/browse/OCPBUGS-17423): Don't render config with incomplete unicast peer list [#267](https://github.com/openshift/baremetal-runtimecfg/pull/267) * [OCPBUGS-14487](https://issues.redhat.com/browse/OCPBUGS-14487): Support IPv6 VIP for setup with multipe IPv6 addresses [#259](https://github.com/openshift/baremetal-runtimecfg/pull/259) * [OCPBUGS-15101](https://issues.redhat.com/browse/OCPBUGS-15101): Use machine-config state instead of comparing roles [#261](https://github.com/openshift/baremetal-runtimecfg/pull/261) * [OCPBUGS-13066](https://issues.redhat.com/browse/OCPBUGS-13066): Update x/net and parent dependencies [#246](https://github.com/openshift/baremetal-runtimecfg/pull/246) * [OCPBUGS-13230](https://issues.redhat.com/browse/OCPBUGS-13230): Verify kubelet version in upgrade check [#248](https://github.com/openshift/baremetal-runtimecfg/pull/248) * [OCPBUGS-12862](https://issues.redhat.com/browse/OCPBUGS-12862): In keepalived config print structs instead of pointers [#242](https://github.com/openshift/baremetal-runtimecfg/pull/242) * [OCPBUGS-12804](https://issues.redhat.com/browse/OCPBUGS-12804): Make nested dual stack VIP configs respect EnableUnicast [#239](https://github.com/openshift/baremetal-runtimecfg/pull/239) * [OCPBUGS-11138](https://issues.redhat.com/browse/OCPBUGS-11138): fix isUpgradeStillRunning() [#231](https://github.com/openshift/baremetal-runtimecfg/pull/231) * [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/0ba9e555eeb173d42e5adf6f65e982e17acfdb9d...1280cf541c220af73b9886379dad2dfa4921f73b) ### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/d192e901ece237d9ae1580d73e78f423ec2ef322) * [OCPBUGS-30288](https://issues.redhat.com/browse/OCPBUGS-30288): oc adm catalog mirror: use ToSlash and FromSlash to unify the path separators [#1700](https://github.com/openshift/oc/pull/1700) * [OCPBUGS-25418](https://issues.redhat.com/browse/OCPBUGS-25418): Add client version in must-gather summary [#1635](https://github.com/openshift/oc/pull/1635) * [OCPBUGS-24461](https://issues.redhat.com/browse/OCPBUGS-24461): Overwrite template's namespace with the explicit one [#1617](https://github.com/openshift/oc/pull/1617) * [AUTH-443](https://issues.redhat.com/browse/AUTH-443): Add OAuth2 Authorization Code Grant Flow for login [#1599](https://github.com/openshift/oc/pull/1599) * [OCPBUGS-22815](https://issues.redhat.com/browse/OCPBUGS-22815): regeneratemco: explicitly check for PlatformStatus field [#1593](https://github.com/openshift/oc/pull/1593) * [OCPBUGS-20298](https://issues.redhat.com/browse/OCPBUGS-20298): Use quay redis image instead docker mysql [#1566](https://github.com/openshift/oc/pull/1566) * [OCPBUGS-19942](https://issues.redhat.com/browse/OCPBUGS-19942): Truncate existing files when writing from inspect [#1553](https://github.com/openshift/oc/pull/1553) * [OCPBUGS-13527](https://issues.redhat.com/browse/OCPBUGS-13527): Bump x org deps 4.13 [#1422](https://github.com/openshift/oc/pull/1422) * [OCPBUGS-16055](https://issues.redhat.com/browse/OCPBUGS-16055): mcs cert: account for environments that use IP directly [#1500](https://github.com/openshift/oc/pull/1500) * [OCPBUGS-16193](https://issues.redhat.com/browse/OCPBUGS-16193): reboot: set ignition version to 3.1 [#1508](https://github.com/openshift/oc/pull/1508) * [OCPBUGS-16172](https://issues.redhat.com/browse/OCPBUGS-16172): Add tls-server-name when property exists in kubeconfig [#1506](https://github.com/openshift/oc/pull/1506) * handle the error case of node retrieval while waiting for reboot [#1484](https://github.com/openshift/oc/pull/1484) * bring some cert rotation helpers back into 4.13 [#1474](https://github.com/openshift/oc/pull/1474) * [OCPBUGS-14249](https://issues.redhat.com/browse/OCPBUGS-14249): preserve explicit release image in ClusterVersion [#1435](https://github.com/openshift/oc/pull/1435) * [OCPBUGS-14180](https://issues.redhat.com/browse/OCPBUGS-14180): Remove closed centos7 registry from newapp unit tests [#1432](https://github.com/openshift/oc/pull/1432) * [OCPBUGS-10773](https://issues.redhat.com/browse/OCPBUGS-10773): bump repo sclorg/s2i-ruby-container location for newapp test [#1381](https://github.com/openshift/oc/pull/1381) * [OCPBUGS-10378](https://issues.redhat.com/browse/OCPBUGS-10378): Add microshift into generate-docs [#1372](https://github.com/openshift/oc/pull/1372) * [Full changelog](https://github.com/openshift/oc/compare/44b3ac26e654777e0283759d45a2b3351823fc5e...d192e901ece237d9ae1580d73e78f423ec2ef322) ### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/134ade41c3293d81d0966e4d4644d18f0e7368e6) * [OCPBUGS-53419](https://issues.redhat.com/browse/OCPBUGS-53419): github.com/golang/glog v1.2.4 [#846](https://github.com/openshift/cloud-credential-operator/pull/846) * [OCPBUGS-51546](https://issues.redhat.com/browse/OCPBUGS-51546): Ignore SNYK-GOLANG-GOLANGORGXOAUTH2JWS-8749594 due to not being affected [#831](https://github.com/openshift/cloud-credential-operator/pull/831) * [OCPBUGS-43340](https://issues.redhat.com/browse/OCPBUGS-43340): Update github.com/sirupsen/logrus v1.8.3 [#770](https://github.com/openshift/cloud-credential-operator/pull/770) * [OCPBUGS-37834](https://issues.redhat.com/browse/OCPBUGS-37834): Resolve SNYK errors in security job. [#743](https://github.com/openshift/cloud-credential-operator/pull/743) * [OCPBUGS-37421](https://issues.redhat.com/browse/OCPBUGS-37421): SNYK ignore go-client misreporting [#740](https://github.com/openshift/cloud-credential-operator/pull/740) * [OCPBUGS-36028](https://issues.redhat.com/browse/OCPBUGS-36028): IBM/go-sdk-core update to v5.17.4 [#722](https://github.com/openshift/cloud-credential-operator/pull/722) * [OCPBUGS-32898](https://issues.redhat.com/browse/OCPBUGS-32898): Upgrade go-jose module to 2.6.3 [#698](https://github.com/openshift/cloud-credential-operator/pull/698) * [OCPBUGS-27912](https://issues.redhat.com/browse/OCPBUGS-27912): Resolve all outstanding snyk vulnerabilities [#651](https://github.com/openshift/cloud-credential-operator/pull/651) * NO-JIRA: Removing andrew from OWNERS [#644](https://github.com/openshift/cloud-credential-operator/pull/644) * [OCPBUGS-25369](https://issues.redhat.com/browse/OCPBUGS-25369): Discover AWS dns suffix from partition and region. [#640](https://github.com/openshift/cloud-credential-operator/pull/640) * [OCPBUGS-21367](https://issues.redhat.com/browse/OCPBUGS-21367): Upgrade golang/x/net for CVE-2023-39325 [#623](https://github.com/openshift/cloud-credential-operator/pull/623) * snyk: exclude vendor/ [#616](https://github.com/openshift/cloud-credential-operator/pull/616) * [OCPBUGS-12565](https://issues.redhat.com/browse/OCPBUGS-12565): CVE-2022-41723 ose-cloud-credential-operator-container: net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding [openshift-4] [#543](https://github.com/openshift/cloud-credential-operator/pull/543) * [OCPBUGS-13692](https://issues.redhat.com/browse/OCPBUGS-13692): Determine AWS partition based on region for readOnlyAnonUserPolicyTemplate bucket ARN. [#538](https://github.com/openshift/cloud-credential-operator/pull/538) * [OCPBUGS-11706](https://issues.redhat.com/browse/OCPBUGS-11706): ccoctl: Enable public anon read access to default OIDC S3 bucket [#528](https://github.com/openshift/cloud-credential-operator/pull/528) * [OCPBUGS-10822](https://issues.redhat.com/browse/OCPBUGS-10822): Adding missing workload annotations [#524](https://github.com/openshift/cloud-credential-operator/pull/524) * [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/b491a81980f16adba3dcdb95356302d8a00d5454...134ade41c3293d81d0966e4d4644d18f0e7368e6) ### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/d377281c10ab68ea3faf4775f015c1651004b0ff) * [OCPBUGS-32180](https://issues.redhat.com/browse/OCPBUGS-32180): Avoid nil pointer panic while assigning private IP on Azure [#139](https://github.com/openshift/cloud-network-config-controller/pull/139) * [OCPBUGS-22299](https://issues.redhat.com/browse/OCPBUGS-22299): Azure: skip backend pool if attached to an outbound rule [#126](https://github.com/openshift/cloud-network-config-controller/pull/126) * [OCPBUGS-15856](https://issues.redhat.com/browse/OCPBUGS-15856): Azure: Handle already existing IP configurations [#116](https://github.com/openshift/cloud-network-config-controller/pull/116) * [OCPBUGS-14635](https://issues.redhat.com/browse/OCPBUGS-14635): increase GCP egress ip capacity to 100 from 10 [#113](https://github.com/openshift/cloud-network-config-controller/pull/113) * [OCPBUGS-13127](https://issues.redhat.com/browse/OCPBUGS-13127): sync CloudPrivateIpConfig when node is missing [#106](https://github.com/openshift/cloud-network-config-controller/pull/106) * [OCPBUGS-10990](https://issues.redhat.com/browse/OCPBUGS-10990): pull project name from subnet uri [#101](https://github.com/openshift/cloud-network-config-controller/pull/101) * [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/1bd04641f210d19370f782086949f827bfb7a264...d377281c10ab68ea3faf4775f015c1651004b0ff) ### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/1801056c175da7d1e8d5507fa4558564740c7f4d) * [OCPBUGS-28760](https://issues.redhat.com/browse/OCPBUGS-28760): Fix http2 [4.13] [#654](https://github.com/openshift/cluster-authentication-operator/pull/654) * [AUTH-443](https://issues.redhat.com/browse/AUTH-443): Add openshift-cli-client OAuth Client [#641](https://github.com/openshift/cluster-authentication-operator/pull/641) * [OCPBUGS-22210](https://issues.redhat.com/browse/OCPBUGS-22210): increase timeout for probes [#638](https://github.com/openshift/cluster-authentication-operator/pull/638) * [OCPBUGS-15258](https://issues.redhat.com/browse/OCPBUGS-15258): Correctly link oauth apiserver ServiceMonitor with its Service [#617](https://github.com/openshift/cluster-authentication-operator/pull/617) * [OCPBUGS-13763](https://issues.redhat.com/browse/OCPBUGS-13763): dont log tokens [#618](https://github.com/openshift/cluster-authentication-operator/pull/618) * [OCPBUGS-4343](https://issues.redhat.com/browse/OCPBUGS-4343): update apf configuration to use v1beta3 [#604](https://github.com/openshift/cluster-authentication-operator/pull/604) * [OCPBUGS-10044](https://issues.redhat.com/browse/OCPBUGS-10044): update openshift/api to get new apiserver schema [#605](https://github.com/openshift/cluster-authentication-operator/pull/605) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#602](https://github.com/openshift/cluster-authentication-operator/pull/602) * [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/9203d4d5a83c86d4c51050a2c58e5ffe6e8d137e...1801056c175da7d1e8d5507fa4558564740c7f4d) ### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/3ce55c7137713427df9f9fe163b1cb9c775290b6) * [OCPBUGS-45151](https://issues.redhat.com/browse/OCPBUGS-45151): [release-4.13] VPA: Update OWNERS file [#328](https://github.com/openshift/kubernetes-autoscaler/pull/328) * [OCPBUGS-40929](https://issues.redhat.com/browse/OCPBUGS-40929): update VPA golang.org/x/net for http rapid reset for CVE-2024-8421 [#317](https://github.com/openshift/kubernetes-autoscaler/pull/317) * [OCPBUGS-31702](https://issues.redhat.com/browse/OCPBUGS-31702): add check for taint.value == nil [#295](https://github.com/openshift/kubernetes-autoscaler/pull/295) * [OCPBUGS-30874](https://issues.redhat.com/browse/OCPBUGS-30874): Fix unstructured taint parsing in Cluster API provider [#289](https://github.com/openshift/kubernetes-autoscaler/pull/289) * [OCPBUGS-23272](https://issues.redhat.com/browse/OCPBUGS-23272): Rebase 4.13 branch onto cluster autoscaler 1.26.4 [#268](https://github.com/openshift/kubernetes-autoscaler/pull/268) * [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/d030dbaade38e116d27d5039a3597f694f73ea2b...3ce55c7137713427df9f9fe163b1cb9c775290b6) ### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/0007e9081f1d7aecd652c0843815be4844f67453) * [OCPBUGS-31992](https://issues.redhat.com/browse/OCPBUGS-31992): Update x/net to v0.25.0 [#324](https://github.com/openshift/cluster-autoscaler-operator/pull/324) * [OCPBUGS-20770](https://issues.redhat.com/browse/OCPBUGS-20770): Bump x/net package to v0.18.0 [#299](https://github.com/openshift/cluster-autoscaler-operator/pull/299) * [OCPBUGS-17056](https://issues.redhat.com/browse/OCPBUGS-17056): Address long acquire times during update [#289](https://github.com/openshift/cluster-autoscaler-operator/pull/289) * [OCPBUGS-17098](https://issues.redhat.com/browse/OCPBUGS-17098): update x/net dependency to 0.7.0 [#280](https://github.com/openshift/cluster-autoscaler-operator/pull/280) * [OCPBUGS-16768](https://issues.redhat.com/browse/OCPBUGS-16768): add nutanix labels that should be ignored [#278](https://github.com/openshift/cluster-autoscaler-operator/pull/278) * [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/32854baae386c4d6854d7fd8658fdff75588e919...0007e9081f1d7aecd652c0843815be4844f67453) ### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/e62fbc906e9ebe245c220e912415d3dbbe2322cd) * [OCPBUGS-77450](https://issues.redhat.com/browse/OCPBUGS-77450): Bump github.com/go-errors/errors to v1.5.1 [#565](https://github.com/openshift/cluster-baremetal-operator/pull/565) * [OCPBUGS-31993](https://issues.redhat.com/browse/OCPBUGS-31993): bump x/net to 0.23.0 [#439](https://github.com/openshift/cluster-baremetal-operator/pull/439) * [OCPBUGS-23504](https://issues.redhat.com/browse/OCPBUGS-23504): hack for deploying V6-only clusters from dualstack hubs [#391](https://github.com/openshift/cluster-baremetal-operator/pull/391) * [OCPBUGS-23444](https://issues.redhat.com/browse/OCPBUGS-23444): Update the deprecated field APIServerInternalIP to APIServerInternalIPs [#385](https://github.com/openshift/cluster-baremetal-operator/pull/385) * [OCPBUGS-20867](https://issues.redhat.com/browse/OCPBUGS-20867): Uplift x/net to v0.17.0 [#370](https://github.com/openshift/cluster-baremetal-operator/pull/370) * [OCPBUGS-19369](https://issues.redhat.com/browse/OCPBUGS-19369): Guard against nil PlatformStatus [#363](https://github.com/openshift/cluster-baremetal-operator/pull/363) * [OCPBUGS-15472](https://issues.redhat.com/browse/OCPBUGS-15472): Limit role binding to openshift-machine-api namespace [#346](https://github.com/openshift/cluster-baremetal-operator/pull/346) * [OCPBUGS-12685](https://issues.redhat.com/browse/OCPBUGS-12685): Uplift x/net to 0.7.0 [#340](https://github.com/openshift/cluster-baremetal-operator/pull/340) * [OCPBUGS-11985](https://issues.redhat.com/browse/OCPBUGS-11985): use proxying for inspector in addition to ironic [#338](https://github.com/openshift/cluster-baremetal-operator/pull/338) * [OCPBUGS-10689](https://issues.redhat.com/browse/OCPBUGS-10689): Add ironic IP to no_proxy [#332](https://github.com/openshift/cluster-baremetal-operator/pull/332) * [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/a23843eff0e827107921a13ab9ef871c2ee34ffd...e62fbc906e9ebe245c220e912415d3dbbe2322cd) ### [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap/tree/ee908b6bb91dee3e61aface46d53a00b4e9288a2) * [OCPBUGS-10923](https://issues.redhat.com/browse/OCPBUGS-10923): Waiting for 2 masters in HA mode case [#83](https://github.com/openshift/cluster-bootstrap/pull/83) * [Full changelog](https://github.com/openshift/cluster-bootstrap/compare/93fba13f576831ba0953190663ab26aaf5766984...ee908b6bb91dee3e61aface46d53a00b4e9288a2) ### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/15159b38390ee3911f2c01c1903dff2d10cdf9ba) * [OCPBUGS-77975](https://issues.redhat.com/browse/OCPBUGS-77975): fix vendor for hermetic [#266](https://github.com/openshift/cluster-api/pull/266) * [OCPBUGS-21531](https://issues.redhat.com/browse/OCPBUGS-21531): bump golang.org/x/net to v0.17.0 [#185](https://github.com/openshift/cluster-api/pull/185) * [OCPBUGS-12567](https://issues.redhat.com/browse/OCPBUGS-12567): Bump x/net package to v0.10.0 [#176](https://github.com/openshift/cluster-api/pull/176) * [OCPBUGS-8481](https://issues.redhat.com/browse/OCPBUGS-8481): [release-4.13] Merge https://github.com/kubernetes-sigs/cluster-api:release-1.3 (eb18352) into release-4.13 [#169](https://github.com/openshift/cluster-api/pull/169) * [Full changelog](https://github.com/openshift/cluster-api/compare/eb617d0f25600eacf3b5971fce8c2fdb60642118...15159b38390ee3911f2c01c1903dff2d10cdf9ba) ### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/35f47274e9ed0a2a7332c2b95aa50c33fb182300) * NO-JIRA: Allow sustaining engineering to self serve dependency updates [#563](https://github.com/openshift/cluster-capi-operator/pull/563) * [OCPBUGS-21082](https://issues.redhat.com/browse/OCPBUGS-21082): bump golang.org/x/net to v0.17.0 [#137](https://github.com/openshift/cluster-capi-operator/pull/137) * [OCPBUGS-10967](https://issues.redhat.com/browse/OCPBUGS-10967): feat: add workload annotations [#108](https://github.com/openshift/cluster-capi-operator/pull/108) * [OCPBUGS-8481](https://issues.redhat.com/browse/OCPBUGS-8481): [release-4.13] Bump CAPI, CAPI providers, go 1.19 [#103](https://github.com/openshift/cluster-capi-operator/pull/103) * [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/0d033265ffd31be8061ee53f4940b4dd71192bbd...35f47274e9ed0a2a7332c2b95aa50c33fb182300) ### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/38f638f020ff1e34d33fd44c42b0351912a74486) * [OCPBUGS-35562](https://issues.redhat.com/browse/OCPBUGS-35562): update azure and ash tolerations on node manager [#353](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/353) * [OCPBUGS-35562](https://issues.redhat.com/browse/OCPBUGS-35562): update unit tests [release-4.13] [#354](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/354) * [OCPBUGS-21169](https://issues.redhat.com/browse/OCPBUGS-21169): Bump golang.org/x/net to v0.18.0 [#296](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/296) * [OCPBUGS-17101](https://issues.redhat.com/browse/OCPBUGS-17101): update x/net dependency to 0.7.0 [#269](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/269) * [OCPBUGS-15746](https://issues.redhat.com/browse/OCPBUGS-15746): Alibaba platforms should not be upgradeable [#260](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/260) * [OCPBUGS-13011](https://issues.redhat.com/browse/OCPBUGS-13011): Add beta topology labels flag to Azure cloud node manager [#250](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/250) * [OCPBUGS-10334](https://issues.redhat.com/browse/OCPBUGS-10334): add rbac permission for Nutanix CCM manager [#237](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/237) * [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/54dce160186799ac2d6e21f9609f8f8b1e493003...38f638f020ff1e34d33fd44c42b0351912a74486) ### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/a6d56530c7156bef726005d640c3ded3565104ec) * [OCPBUGS-28802](https://issues.redhat.com/browse/OCPBUGS-28802): Add required PSa labels [#404](https://github.com/openshift/cluster-config-operator/pull/404) * : OCPBUGS-21269: bump library-go to include switch to HTTP/1.1 [#372](https://github.com/openshift/cluster-config-operator/pull/372) * [CORS-2766](https://issues.redhat.com/browse/CORS-2766): AWS Shared VPC API Bump [release-4.13] [#337](https://github.com/openshift/cluster-config-operator/pull/337) * [OCPBUGS-16164](https://issues.redhat.com/browse/OCPBUGS-16164): retire LatencySensitive featureset [#329](https://github.com/openshift/cluster-config-operator/pull/329) * [OCPBUGS-10038](https://issues.redhat.com/browse/OCPBUGS-10038): update openshift/api to get new apiserver schema [#291](https://github.com/openshift/cluster-config-operator/pull/291) * [OCPBUGS-8710](https://issues.redhat.com/browse/OCPBUGS-8710): bump o/api for the updated featureflags [#290](https://github.com/openshift/cluster-config-operator/pull/290) * [Full changelog](https://github.com/openshift/cluster-config-operator/compare/2378670aee1858db6b1ff425a1d208eb7d73afec...a6d56530c7156bef726005d640c3ded3565104ec) ### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/c5fb62818751e8372d1febd631d9671d83f62962) * [OCPBUGS-48259](https://issues.redhat.com/browse/OCPBUGS-48259): Add unreadyNodeGracePeriod for allowing brief node hiccups [#342](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/342) * [OCPBUGS-35380](https://issues.redhat.com/browse/OCPBUGS-35380): Improved debugging of API listing errors [#304](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/304) * [OCPBUGS-30156](https://issues.redhat.com/browse/OCPBUGS-30156): Never delete a Machine when there's a single Machine in an index [#286](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/286) * [OCPBUGS-21364](https://issues.redhat.com/browse/OCPBUGS-21364): Bump golang.org/x/net to v0.17.0 [#259](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/259) * [OCPBUGS-20482](https://issues.redhat.com/browse/OCPBUGS-20482): fix: e2e: add gcp custom type to test framework [#249](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/249) * [OCPBUGS-17055](https://issues.redhat.com/browse/OCPBUGS-17055): Address long acquire times during update [#240](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/240) * [OCPBUGS-15330](https://issues.redhat.com/browse/OCPBUGS-15330): Fix lint issue [#222](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/222) * [OCPBUGS-15161](https://issues.redhat.com/browse/OCPBUGS-15161): Surface cpms vs machine diff [#218](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/218) * [OCPBUGS-14024](https://issues.redhat.com/browse/OCPBUGS-14024): Check ProviderSpec before generating MachineInfo [#211](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/211) * [OCPBUGS-13888](https://issues.redhat.com/browse/OCPBUGS-13888): fix double machine creation on stale cache [#208](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/208) * [OCPBUGS-11968](https://issues.redhat.com/browse/OCPBUGS-11968): Prioritise machine mapping over alphabetical mapping [#198](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/198) * [OCPBUGS-11506](https://issues.redhat.com/browse/OCPBUGS-11506): E2E periodics test timeout failures improvement [#187](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/187) * [OCPBUGS-11460](https://issues.redhat.com/browse/OCPBUGS-11460): Use PlatformStatus instead of PlatformSpec to determine platform [#186](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/186) * [OCPBUGS-11354](https://issues.redhat.com/browse/OCPBUGS-11354): controlplanemachineset: start watching control plane nodes [#184](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/184) * [OCPBUGS-10771](https://issues.redhat.com/browse/OCPBUGS-10771): updates: manually requeue when waiting for replicas being ready [#181](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/181) * [OCPBUGS-8424](https://issues.redhat.com/browse/OCPBUGS-8424): machine's node must be ready for CPMS machine to be ready [#173](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/173) * [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/783d9dd134451c12f0c1abf7e53c30b61ddd74bf...c5fb62818751e8372d1febd631d9671d83f62962) ### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/c068540d9976ba0fd272e2848de9b0d31a2b7a17) * [OCPBUGS-32334](https://issues.redhat.com/browse/OCPBUGS-32334): create suitable role and roleBinding for csi-snapshot-webhook [#206](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/206) * [OCPBUGS-21461](https://issues.redhat.com/browse/OCPBUGS-21461): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#168](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/168) * [OCPBUGS-10645](https://issues.redhat.com/browse/OCPBUGS-10645): Hypershift: set Deployment properties [#147](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/147) * [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/d4a1162514ecbf248b04e6e8625d17bc2b775ccd...c068540d9976ba0fd272e2848de9b0d31a2b7a17) ### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/65a8fdac5800978f535260997def3e58245f814b) * [OCPBUGS-52501](https://issues.redhat.com/browse/OCPBUGS-52501): [release-4.13] Add runbook_url for CoreDNSErrorsHigh [#434](https://github.com/openshift/cluster-dns-operator/pull/434) * [OCPBUGS-11449](https://issues.redhat.com/browse/OCPBUGS-11449): Enable topology-aware hints iff nodes in >=2 zones [#418](https://github.com/openshift/cluster-dns-operator/pull/418) * [OCPBUGS-11449](https://issues.redhat.com/browse/OCPBUGS-11449): Ignore max unavailable for status [#417](https://github.com/openshift/cluster-dns-operator/pull/417) * [OCPBUGS-11449](https://issues.redhat.com/browse/OCPBUGS-11449): Set DNS DaemonSet's maxSurge value to 10% [#366](https://github.com/openshift/cluster-dns-operator/pull/366) * [OCPBUGS-21534](https://issues.redhat.com/browse/OCPBUGS-21534): Bump golang.org/x/net/http2 to v0.17.0 for CVE-2023-39325 in cluster-dns-operator [#390](https://github.com/openshift/cluster-dns-operator/pull/390) * [OCPBUGS-11449](https://issues.redhat.com/browse/OCPBUGS-11449): Enable topology-aware hints if, and only if, nodes have zones [#367](https://github.com/openshift/cluster-dns-operator/pull/367) * [OCPBUGS-15225](https://issues.redhat.com/browse/OCPBUGS-15225): Add support for protocolStrategy API field to enable force_tcp configuration [#372](https://github.com/openshift/cluster-dns-operator/pull/372) * [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/0164e3c4464f03d5ddbbba5d426f4bf02822753d...65a8fdac5800978f535260997def3e58245f814b) ### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/19e43e8d9e904076f69dc2cd71220fee69f502ac) * [OCPBUGS-67597](https://issues.redhat.com/browse/OCPBUGS-67597): Update logrus to 1.9.3 to address CVE-2025-65637 [#1549](https://github.com/openshift/cluster-etcd-operator/pull/1549) * [OCPBUGS-53509](https://issues.redhat.com/browse/OCPBUGS-53509): fix CVE-2025-30204 [#1415](https://github.com/openshift/cluster-etcd-operator/pull/1415) * [OCPBUGS-35077](https://issues.redhat.com/browse/OCPBUGS-35077): return errors in wait-for-ceo [#1273](https://github.com/openshift/cluster-etcd-operator/pull/1273) * [OCPBUGS-31988](https://issues.redhat.com/browse/OCPBUGS-31988): update golang x net [#1255](https://github.com/openshift/cluster-etcd-operator/pull/1255) * [OCPBUGS-30248](https://issues.redhat.com/browse/OCPBUGS-30248): fix panic in health check timeouts [#1217](https://github.com/openshift/cluster-etcd-operator/pull/1217) * [OCPBUGS-30245](https://issues.redhat.com/browse/OCPBUGS-30245): [4.13] Replace nodelister with master nodelister everywhere [#1216](https://github.com/openshift/cluster-etcd-operator/pull/1216) * [OCPBUGS-23572](https://issues.redhat.com/browse/OCPBUGS-23572): Add annotation in the etcd-guard static pod for worklo… [#1163](https://github.com/openshift/cluster-etcd-operator/pull/1163) * [OCPBUGS-23106](https://issues.redhat.com/browse/OCPBUGS-23106): [4.13] Remove z-upgrades from UpgradeBackupController [#1154](https://github.com/openshift/cluster-etcd-operator/pull/1154) * Revert "[release-4.13] OCPBUGS-23044: remove revision stability check from bootstrap complet…" [#1166](https://github.com/openshift/cluster-etcd-operator/pull/1166) * [OCPBUGS-22783](https://issues.redhat.com/browse/OCPBUGS-22783): relax readiness to local serializable requests [#1144](https://github.com/openshift/cluster-etcd-operator/pull/1144) * [OCPBUGS-23044](https://issues.redhat.com/browse/OCPBUGS-23044): remove revision stability check from bootstrap complet… [#1151](https://github.com/openshift/cluster-etcd-operator/pull/1151) * [OCPBUGS-21155](https://issues.redhat.com/browse/OCPBUGS-21155): fixing CVE-2023-39325 by updating dependencies [#1143](https://github.com/openshift/cluster-etcd-operator/pull/1143) * [OCPBUGS-20488](https://issues.redhat.com/browse/OCPBUGS-20488): prioritize podman pull in etcdctl dl [#1136](https://github.com/openshift/cluster-etcd-operator/pull/1136) * [OCPBUGS-19378](https://issues.redhat.com/browse/OCPBUGS-19378): [4.13] Backports of backup/restore fixes [#1117](https://github.com/openshift/cluster-etcd-operator/pull/1117) * [OCPBUGS-19825](https://issues.redhat.com/browse/OCPBUGS-19825): Update staticpod file permissions to conform with CIS benchmarks [#1125](https://github.com/openshift/cluster-etcd-operator/pull/1125) * [OCPBUGS-16804](https://issues.redhat.com/browse/OCPBUGS-16804): reset snapshot default counts to avoid file already lo… [#1080](https://github.com/openshift/cluster-etcd-operator/pull/1080) * [OCPBUGS-12487](https://issues.redhat.com/browse/OCPBUGS-12487): update golang.org/x/net/http2 [#1075](https://github.com/openshift/cluster-etcd-operator/pull/1075) * [OCPBUGS-11683](https://issues.redhat.com/browse/OCPBUGS-11683): Revert Add Controller health to CEO liveness probe [#1050](https://github.com/openshift/cluster-etcd-operator/pull/1050) * [OCPBUGS-12450](https://issues.redhat.com/browse/OCPBUGS-12450): Fix Flake TestAttemptToScaleDown/scale_down_only_by_one_machine_at_a_time [#1032](https://github.com/openshift/cluster-etcd-operator/pull/1032) * [OCPBUGS-11683](https://issues.redhat.com/browse/OCPBUGS-11683): Add Controller health to CEO liveness probe [#1039](https://github.com/openshift/cluster-etcd-operator/pull/1039) * [OCPBUGS-10960](https://issues.redhat.com/browse/OCPBUGS-10960): skip machine deletion during boostrap [#1036](https://github.com/openshift/cluster-etcd-operator/pull/1036) * [OCPBUGS-9957](https://issues.redhat.com/browse/OCPBUGS-9957): Garbage collect grafana-dashboard-etcd [#1023](https://github.com/openshift/cluster-etcd-operator/pull/1023) * And 1 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/8892946e2c4748e38971c69b370f2db79cdb8a4d...19e43e8d9e904076f69dc2cd71220fee69f502ac) ### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/c3ad421ea822cb625321ea3a2a8e589f0d053fe2) * [OCPBUGS-67598](https://issues.redhat.com/browse/OCPBUGS-67598): Bump logrus to 1.8.3 [#1291](https://github.com/openshift/cluster-image-registry-operator/pull/1291) * [OCPBUGS-53869](https://issues.redhat.com/browse/OCPBUGS-53869): Bump github.com/golang-jwt/jwt [#1235](https://github.com/openshift/cluster-image-registry-operator/pull/1235) * [OCPBUGS-51602](https://issues.redhat.com/browse/OCPBUGS-51602): bump golang.org/x/oauth2 [#1222](https://github.com/openshift/cluster-image-registry-operator/pull/1222) * [OCPBUGS-36034](https://issues.redhat.com/browse/OCPBUGS-36034): go.*,vendor: bump go-retryablehttp [#1070](https://github.com/openshift/cluster-image-registry-operator/pull/1070) * [OCPBUGS-29935](https://issues.redhat.com/browse/OCPBUGS-29935): pkg/storage/s3: enable bucket key on encryption settings [#1007](https://github.com/openshift/cluster-image-registry-operator/pull/1007) * [OCPBUGS-22126](https://issues.redhat.com/browse/OCPBUGS-22126): increase storage account key cache expiration [#940](https://github.com/openshift/cluster-image-registry-operator/pull/940) * [OCPBUGS-20698](https://issues.redhat.com/browse/OCPBUGS-20698): mitigate effects of rapid reset [#946](https://github.com/openshift/cluster-image-registry-operator/pull/946) * [OCPBUGS-10716](https://issues.redhat.com/browse/OCPBUGS-10716): fix storage selection on IBM cloud [#851](https://github.com/openshift/cluster-image-registry-operator/pull/851) * [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/c9f6afc6a929632395ded838792a9f1289eaaa1f...c3ad421ea822cb625321ea3a2a8e589f0d053fe2) ### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/ad1fa40619711f4730c9d6f7c60aa942c1d0632a) * [OCPBUGS-86710](https://issues.redhat.com/browse/OCPBUGS-86710): Add configuration override for X-SSL strip [#1493](https://github.com/openshift/cluster-ingress-operator/pull/1493) * [OCPBUGS-43095](https://issues.redhat.com/browse/OCPBUGS-43095): Add alert for RFC 7230 violation in Transfer-Encoding headers [#1161](https://github.com/openshift/cluster-ingress-operator/pull/1161) * [OCPBUGS-43095](https://issues.redhat.com/browse/OCPBUGS-43095): Add e2e test for duplicate Transfer-Encoding headers [#1150](https://github.com/openshift/cluster-ingress-operator/pull/1150) * [OCPBUGS-36551](https://issues.redhat.com/browse/OCPBUGS-36551): Add Regexp Anchor to TestAll [#1104](https://github.com/openshift/cluster-ingress-operator/pull/1104) * [OCPBUGS-35453](https://issues.redhat.com/browse/OCPBUGS-35453): [release-4.13] internal service changed fix target port logic [#1089](https://github.com/openshift/cluster-ingress-operator/pull/1089) * [OCPBUGS-35094](https://issues.redhat.com/browse/OCPBUGS-35094): TestHostNetworkPortBinding: Delete t.Parallel() [#1082](https://github.com/openshift/cluster-ingress-operator/pull/1082) * [OCPBUGS-34765](https://issues.redhat.com/browse/OCPBUGS-34765): Don't add clientca-configmap finalizer if deleting [#1073](https://github.com/openshift/cluster-ingress-operator/pull/1073) * [OCPBUGS-34409](https://issues.redhat.com/browse/OCPBUGS-34409): desiredRouterDeployment: Set HostPort if needed [#1062](https://github.com/openshift/cluster-ingress-operator/pull/1062) * [OCPBUGS-33990](https://issues.redhat.com/browse/OCPBUGS-33990): Avoid spurious updates for internalTrafficPolicy [Backport to 4.13] [#1055](https://github.com/openshift/cluster-ingress-operator/pull/1055) * [OCPBUGS-34476](https://issues.redhat.com/browse/OCPBUGS-34476): Use centos7 tag for quay.io/centos7/httpd-24-centos7 image [#1065](https://github.com/openshift/cluster-ingress-operator/pull/1065) * [OCPBUGS-20781](https://issues.redhat.com/browse/OCPBUGS-20781): Bump golang.org/x/net for CVE-2023-44487 [#987](https://github.com/openshift/cluster-ingress-operator/pull/987) * [OCPBUGS-22402](https://issues.redhat.com/browse/OCPBUGS-22402): test/e2e: Don't use openshift/origin-node [#991](https://github.com/openshift/cluster-ingress-operator/pull/991) * [OCPBUGS-17733](https://issues.redhat.com/browse/OCPBUGS-17733): [release-4.13] remove shared VPC cred request [#972](https://github.com/openshift/cluster-ingress-operator/pull/972) * [NE-1341](https://issues.redhat.com/browse/NE-1341): Add support for AWS shared VPC in another account [#966](https://github.com/openshift/cluster-ingress-operator/pull/966) * [OCPBUGS-15434](https://issues.redhat.com/browse/OCPBUGS-15434): [release-4.13] Fix invalid DNS name formatting for GCP [#958](https://github.com/openshift/cluster-ingress-operator/pull/958) * [OCPBUGS-15515](https://issues.redhat.com/browse/OCPBUGS-15515): Update TestAWSELBConnectionIdleTimeout to not use wildcard DNS record [#955](https://github.com/openshift/cluster-ingress-operator/pull/955) * [OCPBUGS-12743](https://issues.redhat.com/browse/OCPBUGS-12743): bump controller-runtime to fix the multi namespace cache indexing [#921](https://github.com/openshift/cluster-ingress-operator/pull/921) * [OCPBUGS-13964](https://issues.redhat.com/browse/OCPBUGS-13964), [OCPBUGS-13967](https://issues.redhat.com/browse/OCPBUGS-13967): Handle mTLS CRLs, and fix accidental CRL duplication [#935](https://github.com/openshift/cluster-ingress-operator/pull/935) * [OCPBUGS-12918](https://issues.redhat.com/browse/OCPBUGS-12918): gatewayclass: Update for OSSM 2.4 API change [#917](https://github.com/openshift/cluster-ingress-operator/pull/917) * [OCPBUGS-13157](https://issues.redhat.com/browse/OCPBUGS-13157): Deflake TestRouterCompressionOperation [#926](https://github.com/openshift/cluster-ingress-operator/pull/926) * [OCPBUGS-13071](https://issues.redhat.com/browse/OCPBUGS-13071): Fix TestClientTLS flakes [#923](https://github.com/openshift/cluster-ingress-operator/pull/923) * [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/5fcaab01bd320a9d35bcbe1a7474891c3a51786a...ad1fa40619711f4730c9d6f7c60aa942c1d0632a) ### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/c0d6807816ddb7adcda71e8b1fbe72ee12e7a97a) * [OCPBUGS-67602](https://issues.redhat.com/browse/OCPBUGS-67602): CVE-2025-65637 openshift4/ose-cluster-kube-apiserver-operator: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.13.z] [#2047](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2047) * [OCPBUGS-50850](https://issues.redhat.com/browse/OCPBUGS-50850): Increase waitForFallbackDegradedConditionTimeout [#1809](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1809) * [OCPBUGS-34062](https://issues.redhat.com/browse/OCPBUGS-34062): [4.13] add a controller that reconciles SCCs' volumes [#1677](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1677) * [OCPBUGS-25922](https://issues.redhat.com/browse/OCPBUGS-25922): [release-4.13] dashboard: use recording rules for most metrics [#1611](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1611) * : OCPBUGS-24023: Add workload partitioning annotation [#1591](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1591) * : OCPBUGS-20880: bump library-go to include switch to HTTP/1.1 [#1573](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1573) * [OCPBUGS-19825](https://issues.redhat.com/browse/OCPBUGS-19825): Update staticpod file permissions to conform with CIS benchmarks [#1558](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1558) * [OCPBUGS-15853](https://issues.redhat.com/browse/OCPBUGS-15853): pkg/operator/configobserver: check that the serving certificate refer… [#1522](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1522) * [OCPBUGS-17081](https://issues.redhat.com/browse/OCPBUGS-17081): make webhook connection failure a warning in log [#1532](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1532) * [OCPBUGS-13763](https://issues.redhat.com/browse/OCPBUGS-13763): dont log jwt tokens [#1499](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1499) * [OCPBUGS-4343](https://issues.redhat.com/browse/OCPBUGS-4343): update apf configuration to use v1beta3 [#1470](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1470) * [OCPBUGS-10712](https://issues.redhat.com/browse/OCPBUGS-10712): PSA Violation alert: add ocp_namespace label [#1473](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1473) * [OCPBUGS-10042](https://issues.redhat.com/browse/OCPBUGS-10042): update openshift/api to get new apiserver schema [#1472](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1472) * [OCPBUGS-8710](https://issues.redhat.com/browse/OCPBUGS-8710): turn PSa to logging mode by default again [#1463](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1463) * [OCPBUGS-5939](https://issues.redhat.com/browse/OCPBUGS-5939): revert dev cert rotation for 4.13 [#1465](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1465) * [OCPBUGS-8712](https://issues.redhat.com/browse/OCPBUGS-8712): API-1509: Enable AES-GCM encryption [#1458](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1458) * [OCPBUGS-8475](https://issues.redhat.com/browse/OCPBUGS-8475): Disable TestBoundTokenSignerController [#1457](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1457) * [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/67e982f05404a1ec1e08eaaa66cc408199181a68...c0d6807816ddb7adcda71e8b1fbe72ee12e7a97a) ### [cluster-kube-cluster-api-operator](https://github.com/openshift/cluster-api-operator/tree/18c076b1b56e06086fc3e4ea89d6922cca2d6b4a) * [OCPBUGS-20981](https://issues.redhat.com/browse/OCPBUGS-20981): bump golang.org/x/net to v0.17.0 [#28](https://github.com/openshift/cluster-api-operator/pull/28) * [OCPBUGS-13093](https://issues.redhat.com/browse/OCPBUGS-13093): Bump golang.org/x/net [#20](https://github.com/openshift/cluster-api-operator/pull/20) * [Full changelog](https://github.com/openshift/cluster-api-operator/compare/b287d08b3dabe6b3b67b87a8a284f19ed12a165e...18c076b1b56e06086fc3e4ea89d6922cca2d6b4a) ### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/dac7113696160d1170d9b3773afa4a4b7cb2099b) * [OCPBUGS-27066](https://issues.redhat.com/browse/OCPBUGS-27066): bump(library-go)=release-4.13 [#788](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/788) * [OCPBUGS-21103](https://issues.redhat.com/browse/OCPBUGS-21103): Drop flags removed in k8s 1.26 [4.13] [#766](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/766) * [OCPBUGS-21078](https://issues.redhat.com/browse/OCPBUGS-21078): Bump deps to address CVE-2023-44487 [4.13] [#758](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/758) * [OCPBUGS-19825](https://issues.redhat.com/browse/OCPBUGS-19825): Update staticpod file permissions to conform with CIS benchmarks [#752](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/752) * [OCPBUGS-11353](https://issues.redhat.com/browse/OCPBUGS-11353): AWS should not use external-cloud-volume-plugin post CSI migration [#734](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/734) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): KCMO and MCO must set env var for CSI migration [#718](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/718) * [OCPBUGS-11222](https://issues.redhat.com/browse/OCPBUGS-11222): do not degrade KCM when when monitoring stack rollout is in progress [#717](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/717) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#716](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/716) * [OCPBUGS-8710](https://issues.redhat.com/browse/OCPBUGS-8710): Move PSa back to logging [#711](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/711) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#712](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/712) * [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/4e059638c2cbf003551ee699106dc024760eece3...dac7113696160d1170d9b3773afa4a4b7cb2099b) ### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/74c941a79efaf8a9401adde2174f3bdd9260ca94) * [CNTRLPLANE-2843](https://issues.redhat.com/browse/CNTRLPLANE-2843): chore: update OWNERS [#627](https://github.com/openshift/cluster-kube-scheduler-operator/pull/627) * [OCPBUGS-27065](https://issues.redhat.com/browse/OCPBUGS-27065): bump(library-go)=release-4.13 [#528](https://github.com/openshift/cluster-kube-scheduler-operator/pull/528) * [OCPBUGS-21811](https://issues.redhat.com/browse/OCPBUGS-21811): Bump deps to address CVE-2023-44487 [#502](https://github.com/openshift/cluster-kube-scheduler-operator/pull/502) * [OCPBUGS-19825](https://issues.redhat.com/browse/OCPBUGS-19825): Update staticpod file permissions to conform with CIS benchmarks [#497](https://github.com/openshift/cluster-kube-scheduler-operator/pull/497) * [OCPBUGS-14651](https://issues.redhat.com/browse/OCPBUGS-14651): disable debug pporf with unauthenticated port for 4.13 [#480](https://github.com/openshift/cluster-kube-scheduler-operator/pull/480) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#477](https://github.com/openshift/cluster-kube-scheduler-operator/pull/477) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#470](https://github.com/openshift/cluster-kube-scheduler-operator/pull/470) * [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/0ae603324e89e65037136d7623e4dd2fd223faf9...74c941a79efaf8a9401adde2174f3bdd9260ca94) ### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/a580054caf85de76e8d764d1c989f4ca9464e919) * [OCPBUGS-67607](https://issues.redhat.com/browse/OCPBUGS-67607): Bump github.com/sirupsen/logrus to v1.8.3 [#142](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/142) * : OCPBUGS-21355: bump library-go to include switch to HTTP/1.1 [#97](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/97) * [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/55a86078bfc7ee57757532598bcb21495994202a...a580054caf85de76e8d764d1c989f4ca9464e919) ### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/25fe7b4bd96baba2eef8c0c22521fdc8c08f981d) * [OCPBUGS-21447](https://issues.redhat.com/browse/OCPBUGS-21447): Bump x/net package to v0.18.0 [#213](https://github.com/openshift/cluster-machine-approver/pull/213) * [OCPBUGS-23368](https://issues.redhat.com/browse/OCPBUGS-23368): Filter non node CSRs in metrics [#210](https://github.com/openshift/cluster-machine-approver/pull/210) * [OCPBUGS-11227](https://issues.redhat.com/browse/OCPBUGS-11227): Update node client allowed usages [#190](https://github.com/openshift/cluster-machine-approver/pull/190) * [OCPBUGS-11227](https://issues.redhat.com/browse/OCPBUGS-11227): Update isNodeClientCert to allow for new key usages [#187](https://github.com/openshift/cluster-machine-approver/pull/187) * [OCPBUGS-11227](https://issues.redhat.com/browse/OCPBUGS-11227): approver: fix ECDSA approvals in 1.27 [#185](https://github.com/openshift/cluster-machine-approver/pull/185) * [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/38a758d0026346b751774b2459520174b46e39bf...25fe7b4bd96baba2eef8c0c22521fdc8c08f981d) ### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/314cde5b6949090062c318894b22ed2eb96acd65) * [OCPBUGS-76488](https://issues.redhat.com/browse/OCPBUGS-76488): test: remove image registry e2e tests [#2813](https://github.com/openshift/cluster-monitoring-operator/pull/2813) * [OCPBUGS-33581](https://issues.redhat.com/browse/OCPBUGS-33581): label for infra nodes for metric cluster:capacity_cpu_cores:sum [#2344](https://github.com/openshift/cluster-monitoring-operator/pull/2344) * [OCPBUGS-28767](https://issues.redhat.com/browse/OCPBUGS-28767): fix generation of telemeter token hash [#2305](https://github.com/openshift/cluster-monitoring-operator/pull/2305) * [OCPBUGS-25388](https://issues.redhat.com/browse/OCPBUGS-25388): Add RHACM telemetry metric for 4.13 [#2203](https://github.com/openshift/cluster-monitoring-operator/pull/2203) * [OCPBUGS-21457](https://issues.redhat.com/browse/OCPBUGS-21457): Set the new --disable-http2 flag for prometheus-adapter to disable HTTP2 [#2146](https://github.com/openshift/cluster-monitoring-operator/pull/2146) * [OCPBUGS-22920](https://issues.redhat.com/browse/OCPBUGS-22920): jsonnet: pin commits [#2144](https://github.com/openshift/cluster-monitoring-operator/pull/2144) * [OCPBUGS-22842](https://issues.redhat.com/browse/OCPBUGS-22842): [release-4.13] add RHACS telemetry metrics [#2139](https://github.com/openshift/cluster-monitoring-operator/pull/2139) * [OCPBUGS-22308](https://issues.redhat.com/browse/OCPBUGS-22308): fix: force HTTP/1.1 connections [#2134](https://github.com/openshift/cluster-monitoring-operator/pull/2134) * [OCPBUGS-21250](https://issues.redhat.com/browse/OCPBUGS-21250): upgrade golang.org/x/net to v0.17.0 [#2122](https://github.com/openshift/cluster-monitoring-operator/pull/2122) * [OCPBUGS-22099](https://issues.redhat.com/browse/OCPBUGS-22099): Extend remote write test timeout [#2127](https://github.com/openshift/cluster-monitoring-operator/pull/2127) * [OCPBUGS-11016](https://issues.redhat.com/browse/OCPBUGS-11016): Node Exporter ignores network interface under name "cali[a-f0-9]*" [#1927](https://github.com/openshift/cluster-monitoring-operator/pull/1927) * [OCPBUGS-16023](https://issues.redhat.com/browse/OCPBUGS-16023): Add the trusted CA bundle in UWM Prometheus pods [#2041](https://github.com/openshift/cluster-monitoring-operator/pull/2041) * [OCPBUGS-15469](https://issues.redhat.com/browse/OCPBUGS-15469): Limit the value of GOMAXPROCS on node-exporter to 4. [#2021](https://github.com/openshift/cluster-monitoring-operator/pull/2021) * [OCPBUGS-14251](https://issues.redhat.com/browse/OCPBUGS-14251): Add new web console usage metrics [#1976](https://github.com/openshift/cluster-monitoring-operator/pull/1976) * [OCPBUGS-12488](https://issues.redhat.com/browse/OCPBUGS-12488): go.mod: update golang.org/x/net to v0.7.0 [#1957](https://github.com/openshift/cluster-monitoring-operator/pull/1957) * [OCPBUGS-13007](https://issues.redhat.com/browse/OCPBUGS-13007): Add build number to rules [#1964](https://github.com/openshift/cluster-monitoring-operator/pull/1964) * [OCPBUGS-13397](https://issues.redhat.com/browse/OCPBUGS-13397): Uncomment cluster:vsphere_infrastructure_failure_domains:max [#1962](https://github.com/openshift/cluster-monitoring-operator/pull/1962) * 4.13: OCPBUGS-11294: Add vSphere CSI migration to telemetry [#1929](https://github.com/openshift/cluster-monitoring-operator/pull/1929) * [OCPBUGS-11536](https://issues.redhat.com/browse/OCPBUGS-11536): node-exporter: disable btrfs collector [#1941](https://github.com/openshift/cluster-monitoring-operator/pull/1941) * [OCPBUGS-10895](https://issues.redhat.com/browse/OCPBUGS-10895): add startup probe for prometheus-adapter [#1923](https://github.com/openshift/cluster-monitoring-operator/pull/1923) * [OCPBUGS-11333](https://issues.redhat.com/browse/OCPBUGS-11333): jsonnet: Add prometheus container in UWM [#1934](https://github.com/openshift/cluster-monitoring-operator/pull/1934) * [OCPBUGS-10793](https://issues.redhat.com/browse/OCPBUGS-10793): bugfix in Node Exporter argument setting [#1922](https://github.com/openshift/cluster-monitoring-operator/pull/1922) * [OCPBUGS-10476](https://issues.redhat.com/browse/OCPBUGS-10476): turn off netlink mode of netclass collector in Node Exporter. [#1919](https://github.com/openshift/cluster-monitoring-operator/pull/1919) * [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/c58a1bda8cd18c79f15a0ff39cbc9fc06f10569c...314cde5b6949090062c318894b22ed2eb96acd65) ### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/bc45a4d1dad2656dbf44f5143679f8795ebf3986) * [OCPBUGS-78106](https://issues.redhat.com/browse/OCPBUGS-78106): fix vendor for hermetic 4.13 [#2914](https://github.com/openshift/cluster-network-operator/pull/2914) * [OCPBUGS-43856](https://issues.redhat.com/browse/OCPBUGS-43856): manifests/02-cncc-credentials: Set skipServiceCheck for GCP [#2547](https://github.com/openshift/cluster-network-operator/pull/2547) * [OCPBUGS-38403](https://issues.redhat.com/browse/OCPBUGS-38403): Add missing runbook for OVNKubernetesNorthdInactive [#2471](https://github.com/openshift/cluster-network-operator/pull/2471) * [OCPBUGS-37941](https://issues.redhat.com/browse/OCPBUGS-37941): update whereabouts crd [#2458](https://github.com/openshift/cluster-network-operator/pull/2458) * [OCPBUGS-30150](https://issues.redhat.com/browse/OCPBUGS-30150): ipsec: fix openssl typo [#2290](https://github.com/openshift/cluster-network-operator/pull/2290) * [OCPBUGS-29674](https://issues.redhat.com/browse/OCPBUGS-29674): add env var in whereabouts-reconciler daemonset [#2279](https://github.com/openshift/cluster-network-operator/pull/2279) * [OCPBUGS-29301](https://issues.redhat.com/browse/OCPBUGS-29301): Update ingressconfig_controller to use field Manager [#2267](https://github.com/openshift/cluster-network-operator/pull/2267) * [OCPBUGS-28208](https://issues.redhat.com/browse/OCPBUGS-28208): ipsec: fix oopsy from 2e3fc8e (cherry-pick of 980c08318e) [#2222](https://github.com/openshift/cluster-network-operator/pull/2222) * [OCPBUGS-28777](https://issues.redhat.com/browse/OCPBUGS-28777): fix whereabouts conformance test failures [#2241](https://github.com/openshift/cluster-network-operator/pull/2241) * [OCPBUGS-27958](https://issues.redhat.com/browse/OCPBUGS-27958): Add ConfigMap mount to the whereabouts-reconciler DaemonSet [#2220](https://github.com/openshift/cluster-network-operator/pull/2220) * NO-JIRA: add kyrtapz as reviewer and approver for release 4.13 [#2229](https://github.com/openshift/cluster-network-operator/pull/2229) * [OCPBUGS-22293](https://issues.redhat.com/browse/OCPBUGS-22293): remove all managed fields used by old manager [#2094](https://github.com/openshift/cluster-network-operator/pull/2094) * [OCPBUGS-24570](https://issues.redhat.com/browse/OCPBUGS-24570): Disable weak SSH cipher suitesRm weak ciphers 4.13 [#2163](https://github.com/openshift/cluster-network-operator/pull/2163) * [OCPBUGS-21716](https://issues.redhat.com/browse/OCPBUGS-21716): Bump golang.org/x/net and github.com/openshift/library-go [#2123](https://github.com/openshift/cluster-network-operator/pull/2123) * [OCPBUGS-22896](https://issues.redhat.com/browse/OCPBUGS-22896): run update-codegen after adding maxLogFiles cfg [#2162](https://github.com/openshift/cluster-network-operator/pull/2162) * [OCPBUGS-22971](https://issues.redhat.com/browse/OCPBUGS-22971): HyperShift: Use the local konnectivity proxy when checking proxy readiness [#2098](https://github.com/openshift/cluster-network-operator/pull/2098) * [OCPBUGS-22896](https://issues.redhat.com/browse/OCPBUGS-22896): Remove oldest ovn acl log files when file limit exceeded [#2097](https://github.com/openshift/cluster-network-operator/pull/2097) * [SDN-4184](https://issues.redhat.com/browse/SDN-4184): Limit OVN-Kubernetes RBAC permissions [#2093](https://github.com/openshift/cluster-network-operator/pull/2093) * [OCPBUGS-20278](https://issues.redhat.com/browse/OCPBUGS-20278): Edited multus-admission-controller deployment config to not add autoount a service account token [#1885](https://github.com/openshift/cluster-network-operator/pull/1885) * [OCPBUGS-19894](https://issues.redhat.com/browse/OCPBUGS-19894): remove prestop hooks for northd, sbdbd and nbdb [#2001](https://github.com/openshift/cluster-network-operator/pull/2001) * [OCPBUGS-18722](https://issues.redhat.com/browse/OCPBUGS-18722): IBMCloud specific: patch out management workload for dataplane component thats needed for bootstrapping [#1994](https://github.com/openshift/cluster-network-operator/pull/1994) * [OCPBUGS-18342](https://issues.redhat.com/browse/OCPBUGS-18342): Fix bond-cni's default directory in multus manifest [#1977](https://github.com/openshift/cluster-network-operator/pull/1977) * [OCPBUGS-13920](https://issues.redhat.com/browse/OCPBUGS-13920): add Hypershift release-image annotation to multus [#1817](https://github.com/openshift/cluster-network-operator/pull/1817) * [OCPBUGS-18099](https://issues.redhat.com/browse/OCPBUGS-18099): [release-4.13] Use encapsulation=true for IBM Cloud [#1932](https://github.com/openshift/cluster-network-operator/pull/1932) * [OCPBUGS-17721](https://issues.redhat.com/browse/OCPBUGS-17721): Enhance check controller to remove old check objects [#1950](https://github.com/openshift/cluster-network-operator/pull/1950) * [OCPBUGS-17457](https://issues.redhat.com/browse/OCPBUGS-17457): prevent creation of multiple cni-sysctl-allowlist-ds pods [#1936](https://github.com/openshift/cluster-network-operator/pull/1936) * [OCPBUGS-11539](https://issues.redhat.com/browse/OCPBUGS-11539): Hypershift: Add RollingUpdate parameters to multus-admission-controller [#1774](https://github.com/openshift/cluster-network-operator/pull/1774) * [OCPBUGS-15977](https://issues.redhat.com/browse/OCPBUGS-15977): Add logic to pick the openshift-sdn shims from right directories [#1880](https://github.com/openshift/cluster-network-operator/pull/1880) * [OCPBUGS-15962](https://issues.redhat.com/browse/OCPBUGS-15962): Add logic to pick the ovn-k8s-cni-overlay binary from the right dir [#1877](https://github.com/openshift/cluster-network-operator/pull/1877) * Change rhel7/8 to rhel8/9 [#1869](https://github.com/openshift/cluster-network-operator/pull/1869) * [OCPBUGS-15476](https://issues.redhat.com/browse/OCPBUGS-15476): Add release version annotation to whereabouts-reconciler [#1853](https://github.com/openshift/cluster-network-operator/pull/1853) * [OCPBUGS-15139](https://issues.redhat.com/browse/OCPBUGS-15139): Remove nodeSelector for architecture in whereabouts daemonset [#1840](https://github.com/openshift/cluster-network-operator/pull/1840) * [OCPBUGS-14871](https://issues.redhat.com/browse/OCPBUGS-14871): Do not rely on ControlPlaneTopology do determine if running in HyperShift [#1837](https://github.com/openshift/cluster-network-operator/pull/1837) * [OCPBUGS-13809](https://issues.redhat.com/browse/OCPBUGS-13809): Use `IfNotPresent` instead of `Always` in OVNK upgrades pre-puller [#1813](https://github.com/openshift/cluster-network-operator/pull/1813) * [OCPBUGS-14367](https://issues.redhat.com/browse/OCPBUGS-14367): High API requests due to allowlist and operconfig reconcilers running too often [#1824](https://github.com/openshift/cluster-network-operator/pull/1824) * [OCPBUGS-11750](https://issues.redhat.com/browse/OCPBUGS-11750): fix reconciliation process of the allowlist controller [#1793](https://github.com/openshift/cluster-network-operator/pull/1793) * [OCPBUGS-13155](https://issues.redhat.com/browse/OCPBUGS-13155): HyperShift: Support HostedControlPlane node selector [#1802](https://github.com/openshift/cluster-network-operator/pull/1802) * [OCPBUGS-12854](https://issues.redhat.com/browse/OCPBUGS-12854): AUTH: update cluster-reader to include k8s.ovn.org [#1797](https://github.com/openshift/cluster-network-operator/pull/1797) * [OCPBUGS-11558](https://issues.redhat.com/browse/OCPBUGS-11558): multus-admission-controller should not run as root under Hypershift [#1776](https://github.com/openshift/cluster-network-operator/pull/1776) * [OCPBUGS-11750](https://issues.redhat.com/browse/OCPBUGS-11750): Fix allowlist ds template [#1779](https://github.com/openshift/cluster-network-operator/pull/1779) * [OCPBUGS-11424](https://issues.redhat.com/browse/OCPBUGS-11424): Backport changes to whereabouts reconciler [#1769](https://github.com/openshift/cluster-network-operator/pull/1769) * [OCPBUGS-11503](https://issues.redhat.com/browse/OCPBUGS-11503): update 4.13 Dockerfile to use rhel-8 and go 1.19 [#1772](https://github.com/openshift/cluster-network-operator/pull/1772) * [OCPBUGS-11257](https://issues.redhat.com/browse/OCPBUGS-11257): Split out konnectivity certs [#1761](https://github.com/openshift/cluster-network-operator/pull/1761) * [OCPBUGS-11156](https://issues.redhat.com/browse/OCPBUGS-11156): Cno 4.13 kubernetes 1.26 [#1758](https://github.com/openshift/cluster-network-operator/pull/1758) * [OCPBUGS-10873](https://issues.redhat.com/browse/OCPBUGS-10873): use annotation on the daemonset to update hybrid overlay [#1751](https://github.com/openshift/cluster-network-operator/pull/1751) * [OCPBUGS-10890](https://issues.redhat.com/browse/OCPBUGS-10890): HyperShift: Add POD_NAME env to ovnkube-node [#1750](https://github.com/openshift/cluster-network-operator/pull/1750) * [OCPBUGS-10710](https://issues.redhat.com/browse/OCPBUGS-10710): operConfig reconcile can return nil error on failure [#1746](https://github.com/openshift/cluster-network-operator/pull/1746) * [OCPBUGS-10440](https://issues.redhat.com/browse/OCPBUGS-10440): Point libreswan to proper nss location [#1741](https://github.com/openshift/cluster-network-operator/pull/1741) * [OCPBUGS-10271](https://issues.redhat.com/browse/OCPBUGS-10271): OVN-K alerts: add OVS overflow alerts [#1723](https://github.com/openshift/cluster-network-operator/pull/1723) * [OCPBUGS-9968](https://issues.redhat.com/browse/OCPBUGS-9968): HyperShift: Set affinity, tolerations and co-location for all hcp resources created by CNO [#1733](https://github.com/openshift/cluster-network-operator/pull/1733) * [OCPBUGS-9926](https://issues.redhat.com/browse/OCPBUGS-9926): Enable configuration of node healthz server on ovnkube [#1730](https://github.com/openshift/cluster-network-operator/pull/1730) * [Full changelog](https://github.com/openshift/cluster-network-operator/compare/af41a362017b8f85e180d2f5e0db8f16c7db4b94...bc45a4d1dad2656dbf44f5143679f8795ebf3986) ### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/978a6c56e163f119f757d7116fa99d6b05f7d7f5) * E2E: workload hints: compare existing profile with changes being made to avoid mcp getting stuck (#1069) [#1069](https://github.com/openshift/cluster-node-tuning-operator/pull/1069) * [OCPBUGS-33030](https://issues.redhat.com/browse/OCPBUGS-33030): [release-4.13][manual]Reduce number of reboots in offline tests (#1048) [#1048](https://github.com/openshift/cluster-node-tuning-operator/pull/1048) * Scheduler plugin: ignore IRQs (#1027) [#1027](https://github.com/openshift/cluster-node-tuning-operator/pull/1027) * irqbalance: set banned cpus list to 0 (#1003) [#1003](https://github.com/openshift/cluster-node-tuning-operator/pull/1003) * [OCPBUGS-24353](https://issues.redhat.com/browse/OCPBUGS-24353): rps: cherry-picks of rps fixes (#865) [#865](https://github.com/openshift/cluster-node-tuning-operator/pull/865) * Disable HTTP/2 for webhook and metrics servers (#846) [#846](https://github.com/openshift/cluster-node-tuning-operator/pull/846) * Remove obsolete protocols and weak ciphers (#843) [#843](https://github.com/openshift/cluster-node-tuning-operator/pull/843) * [OCPBUGS-18493](https://issues.redhat.com/browse/OCPBUGS-18493): e2e: deflake IRQ load-balancing (#782) [#782](https://github.com/openshift/cluster-node-tuning-operator/pull/782) * Use RHEL9 as a base (#829) [#829](https://github.com/openshift/cluster-node-tuning-operator/pull/829) * [OCPBUGS-17943](https://issues.redhat.com/browse/OCPBUGS-17943): Add rtentsk plugin to pp tuned profile Signed-off-by: Brent Rowsell <browsell@redhat.com> (#796) [#796](https://github.com/openshift/cluster-node-tuning-operator/pull/796) * nto: avoid timeout when there are too many CSV (#818) [#818](https://github.com/openshift/cluster-node-tuning-operator/pull/818) * [OCPBUGS-19459](https://issues.redhat.com/browse/OCPBUGS-19459): check for object being nil (#820) [#820](https://github.com/openshift/cluster-node-tuning-operator/pull/820) * Add kubeconfig path for IBM Managed OpenShift (#814) [#814](https://github.com/openshift/cluster-node-tuning-operator/pull/814) * [OCPBUGS-14137](https://issues.redhat.com/browse/OCPBUGS-14137): e2e: perfprof: add SNO device recovery test (#653) (#806) [#653](https://github.com/openshift/cluster-node-tuning-operator/pull/653) * [OCPBUGS-18868](https://issues.redhat.com/browse/OCPBUGS-18868): [release-4.14] e2e: add expected max latancy to hwlatdetec test & rename constant (#788) (#808) [#788](https://github.com/openshift/cluster-node-tuning-operator/pull/788) * Sync DaemonSet if operand image changes (#786) [#786](https://github.com/openshift/cluster-node-tuning-operator/pull/786) * Revert "Revert "Release leader election on manager exit (#773)" (#797)" (#802) [#773](https://github.com/openshift/cluster-node-tuning-operator/pull/773) * [OCPBUGS-19351](https://issues.redhat.com/browse/OCPBUGS-19351): Keep Profile status.bootcmdline around (#803) [#803](https://github.com/openshift/cluster-node-tuning-operator/pull/803) * Revert "Release leader election on manager exit (#773)" (#797) [#773](https://github.com/openshift/cluster-node-tuning-operator/pull/773) * Release leader election on manager exit (#773) [#773](https://github.com/openshift/cluster-node-tuning-operator/pull/773) * Tighten the rules for modifying Tuned Profiles (#766) [#766](https://github.com/openshift/cluster-node-tuning-operator/pull/766) * [OCPBUGS-18063](https://issues.redhat.com/browse/OCPBUGS-18063): cgroup: Match the name of the cgroup to what is expected by kubelet (#774) [#774](https://github.com/openshift/cluster-node-tuning-operator/pull/774) * update tsc karg to tsc=reliable (#757) [#757](https://github.com/openshift/cluster-node-tuning-operator/pull/757) * [OCPBUGS-17845](https://issues.redhat.com/browse/OCPBUGS-17845): deflake ht aware test (#763) [#763](https://github.com/openshift/cluster-node-tuning-operator/pull/763) * [OCPBUGS-17794](https://issues.redhat.com/browse/OCPBUGS-17794): rps: use default rps mask kernel API (#760) [#760](https://github.com/openshift/cluster-node-tuning-operator/pull/760) * Improve render error handling (#755) [#755](https://github.com/openshift/cluster-node-tuning-operator/pull/755) * nto:tuned: remove sched_min_granularity_ns settings (#726) [#726](https://github.com/openshift/cluster-node-tuning-operator/pull/726) * Fix a race in e2e test rollback.go code (#740) [#740](https://github.com/openshift/cluster-node-tuning-operator/pull/740) * E2E: Add memory manager sanity test case (#573) (#695) [#573](https://github.com/openshift/cluster-node-tuning-operator/pull/573) * e2e: latency testing: increase the expected threshold (#709) [#709](https://github.com/openshift/cluster-node-tuning-operator/pull/709) * Do not rollback settings on TuneD exit (#704) [#704](https://github.com/openshift/cluster-node-tuning-operator/pull/704) * Switch to rslave/HostToContainer volume mount propagation (#705) [#705](https://github.com/openshift/cluster-node-tuning-operator/pull/705) * e2e: perf-prof: disable truncating gomega output (#707) [#707](https://github.com/openshift/cluster-node-tuning-operator/pull/707) * [OCPBUGS-14895](https://issues.redhat.com/browse/OCPBUGS-14895): Do not fail creating cgroups if they exist already (#684) [#684](https://github.com/openshift/cluster-node-tuning-operator/pull/684) * [OCPBUGS-14331](https://issues.redhat.com/browse/OCPBUGS-14331): Fix updating numa core siblings map in GetCpuSiblings function (#669) [#669](https://github.com/openshift/cluster-node-tuning-operator/pull/669) * render: remove uid from render-sync target (#594) (#609) [#594](https://github.com/openshift/cluster-node-tuning-operator/pull/594) * Remove cpu-quota.crio.io: disable annotation (#670) [#670](https://github.com/openshift/cluster-node-tuning-operator/pull/670) * Add PerformanceProfiles to 'oc adm must-gather' (#657) [#657](https://github.com/openshift/cluster-node-tuning-operator/pull/657) * [OCPBUGS-11709](https://issues.redhat.com/browse/OCPBUGS-11709): pao e2e: skip hugepages and numa tests properly (#643) [#643](https://github.com/openshift/cluster-node-tuning-operator/pull/643) * e2e: Fix RPS test for multi-worker cluster (#648) [#648](https://github.com/openshift/cluster-node-tuning-operator/pull/648) * OCPBUGS-12978 use WatchNamespace() when deleting Profiles (#645) [#645](https://github.com/openshift/cluster-node-tuning-operator/pull/645) * [OCPBUGS-11336](https://issues.redhat.com/browse/OCPBUGS-11336): pao e2e: fix update test suit timeouts (#642) [#642](https://github.com/openshift/cluster-node-tuning-operator/pull/642) * Address CVE-2022-41723 (#633) [#633](https://github.com/openshift/cluster-node-tuning-operator/pull/633) * [OCPBUGS-13148](https://issues.redhat.com/browse/OCPBUGS-13148): Configure cpu balancing cpu sets for all clusters (#647) [#647](https://github.com/openshift/cluster-node-tuning-operator/pull/647) * Revert PR558 and PR585 partially (#640) [#640](https://github.com/openshift/cluster-node-tuning-operator/pull/640) * workload-hints: disable stalld when rt disabled (#604) [#604](https://github.com/openshift/cluster-node-tuning-operator/pull/604) * e2e: add missing test id (#629) [#629](https://github.com/openshift/cluster-node-tuning-operator/pull/629) * Remove subPaths, they are broken (#624) [#624](https://github.com/openshift/cluster-node-tuning-operator/pull/624) * [OCPNODE-1539](https://issues.redhat.com/browse/OCPNODE-1539): perf profile: add script for preparing cgroups for CPU load balance disabling (#617) [#617](https://github.com/openshift/cluster-node-tuning-operator/pull/617) * Update NTO-generated MC on MachineCount <= 1 (#620) [#620](https://github.com/openshift/cluster-node-tuning-operator/pull/620) * [OCPBUGS-11336](https://issues.redhat.com/browse/OCPBUGS-11336): e2e: profile updates tests revised (#618) [#618](https://github.com/openshift/cluster-node-tuning-operator/pull/618) * [OCPBUGS-11813](https://issues.redhat.com/browse/OCPBUGS-11813): performance-profile: enable crun for high-performance runtime (#616) [#616](https://github.com/openshift/cluster-node-tuning-operator/pull/616) * A new env var NO_BZ_CHECKS disables Bz and Jira status checks (#614) [#614](https://github.com/openshift/cluster-node-tuning-operator/pull/614) * Revert #567 and cleanup PPC-generated TuneD config (#615) [#615](https://github.com/openshift/cluster-node-tuning-operator/pull/615) * Skip tests depending on Jira or Bz issue status (#599) [#599](https://github.com/openshift/cluster-node-tuning-operator/pull/599) * Recent 4.13 RHCOS incorporated RHEL9 kernel based on 5.14 which (#606) [#606](https://github.com/openshift/cluster-node-tuning-operator/pull/606) * Remove the preStop hook for openshift-tuned (#596) [#596](https://github.com/openshift/cluster-node-tuning-operator/pull/596) * Fix updating nodeSelector test (#598) [#598](https://github.com/openshift/cluster-node-tuning-operator/pull/598) * [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/5511c8df81e608a45bf37cb021707f7b9ede9c9a...978a6c56e163f119f757d7116fa99d6b05f7d7f5) ### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/f43d414da365c1bbe99f7bf2d4e7532d4c3bf5b2) * [OCPBUGS-76595](https://issues.redhat.com/browse/OCPBUGS-76595): CVE-2025-65637 - Bump github.com/sirupsen/logrus from v1.9.0 to v1.9.3 [release-4.13] [#659](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/659) * : OCPBUGS-20707: bump library-go to include switch to HTTP/1.1 [#555](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/555) * [OCPBUGS-22210](https://issues.redhat.com/browse/OCPBUGS-22210): increase timeout for probes [#553](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/553) * [OCPBUGS-13763](https://issues.redhat.com/browse/OCPBUGS-13763): dont log tokens [#541](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/541) * [OCPBUGS-10043](https://issues.redhat.com/browse/OCPBUGS-10043): update openshift/api to get new apiserver schema [#529](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/529) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#527](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/527) * [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/7125dc64ece6de40fa14e181e220e67bdfb8101f...f43d414da365c1bbe99f7bf2d4e7532d4c3bf5b2) ### [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator/tree/6e7e7835519d30ea22e4c4954039bab21de19c80) * [OCPBUGS-38455](https://issues.redhat.com/browse/OCPBUGS-38455): Update opentelemetry to mitigate CVE [#365](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/365) * [OCPBUGS-20796](https://issues.redhat.com/browse/OCPBUGS-20796): bump(k8s,openshift) to address CVE-2023-44487 [#310](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/310) * [OCPBUGS-7785](https://issues.redhat.com/browse/OCPBUGS-7785): migrate to using lease objects for leader election [#281](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/281) * [Full changelog](https://github.com/openshift/cluster-openshift-controller-manager-operator/compare/09d62091346f86f54938587acfd680f6bd6b7af6...6e7e7835519d30ea22e4c4954039bab21de19c80) ### [cluster-platform-operators-manager](https://github.com/openshift/platform-operators/tree/312c5f24b5711a764350de899b83443a87296983) * [OCPBUGS-20998](https://issues.redhat.com/browse/OCPBUGS-20998): [release-4.13] Bump golang.org/x/net to v0.17.0 [#97](https://github.com/openshift/platform-operators/pull/97) * [OCPBUGS-10404](https://issues.redhat.com/browse/OCPBUGS-10404): feat: add workload pinning annotations [#84](https://github.com/openshift/platform-operators/pull/84) * [Full changelog](https://github.com/openshift/platform-operators/compare/08fb27e72e32ea0a06ab02b3b746114148d96c25...312c5f24b5711a764350de899b83443a87296983) ### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/3b0d075530fdbfdacdfe574151a3313f5231459c) * [OCPBUGS-21103](https://issues.redhat.com/browse/OCPBUGS-21103): Bump deps to address CVE-2023-44487 [4.13] [#135](https://github.com/openshift/cluster-policy-controller/pull/135) * [OCPBUGS-14091](https://issues.redhat.com/browse/OCPBUGS-14091): [4.13] fix ClusterResourceQuotas to work for all api resources including custom resources [#116](https://github.com/openshift/cluster-policy-controller/pull/116) * [OCPBUGS-13731](https://issues.redhat.com/browse/OCPBUGS-13731): external template and route Informer [#112](https://github.com/openshift/cluster-policy-controller/pull/112) * [OCPBUGS-11473](https://issues.redhat.com/browse/OCPBUGS-11473): psalabelsyncer: handle empty namespace of a rolebinding subject [#108](https://github.com/openshift/cluster-policy-controller/pull/108) * [OCPBUGS-8710](https://issues.redhat.com/browse/OCPBUGS-8710): psalabelsyncer: invert the enforce/log logic to default to logging [#106](https://github.com/openshift/cluster-policy-controller/pull/106) * [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/219f6f6f072d867201d4923d39fd8bcaecbe7c59...3b0d075530fdbfdacdfe574151a3313f5231459c) ### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/b3496c0c8eb3b44086413fea2d6d0f28080db637) * [OCPBUGS-63520](https://issues.redhat.com/browse/OCPBUGS-63520): references to github.com/sclorg/django-ex.git now also refer to the branch [#662](https://github.com/openshift/cluster-samples-operator/pull/662) * [OCPBUGS-54812](https://issues.redhat.com/browse/OCPBUGS-54812): add rhdmalone to owners [#628](https://github.com/openshift/cluster-samples-operator/pull/628) * [OCPBUGS-49663](https://issues.redhat.com/browse/OCPBUGS-49663): add shannon and aroyoredhat as owners [#599](https://github.com/openshift/cluster-samples-operator/pull/599) * [OCPBUGS-21198](https://issues.redhat.com/browse/OCPBUGS-21198): update k8s.io/apiserver version [#589](https://github.com/openshift/cluster-samples-operator/pull/589) * [OCPBUGS-22390](https://issues.redhat.com/browse/OCPBUGS-22390): Sync library to remove invalid dockerhub references for OKD [#521](https://github.com/openshift/cluster-samples-operator/pull/521) * [OCPBUGS-15756](https://issues.redhat.com/browse/OCPBUGS-15756): Update Jenkins and Jenkins Agent Base image versions [#505](https://github.com/openshift/cluster-samples-operator/pull/505) * [OCPBUGS-14598](https://issues.redhat.com/browse/OCPBUGS-14598): Updating to use Jenkins 4.13 images [#503](https://github.com/openshift/cluster-samples-operator/pull/503) * [OCPBUGS-13029](https://issues.redhat.com/browse/OCPBUGS-13029): Update Cluster Sample Operator dependencies and libraries for OCP 4.13 [#501](https://github.com/openshift/cluster-samples-operator/pull/501) * [OCPBUGS-10965](https://issues.redhat.com/browse/OCPBUGS-10965): Add network tools imagestreams [#496](https://github.com/openshift/cluster-samples-operator/pull/496) * [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/63a0ae4b409b7eea4d7335f6c372e5b03be91238...b3496c0c8eb3b44086413fea2d6d0f28080db637) ### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/98cde3b2e47b0982c9e4ab9ec34930b0021beed3) * [OCPBUGS-67622](https://issues.redhat.com/browse/OCPBUGS-67622): Bump logrus to v1.8.3 [#656](https://github.com/openshift/cluster-storage-operator/pull/656) * [OCPBUGS-33468](https://issues.redhat.com/browse/OCPBUGS-33468): Fix problem-detector proxy setting [#473](https://github.com/openshift/cluster-storage-operator/pull/473) * [OCPBUGS-21284](https://issues.redhat.com/browse/OCPBUGS-21284): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#406](https://github.com/openshift/cluster-storage-operator/pull/406) * [OCPBUGS-18132](https://issues.redhat.com/browse/OCPBUGS-18132): Add patch for allowing configmap updates via clusterrole [#396](https://github.com/openshift/cluster-storage-operator/pull/396) * [OCPBUGS-19036](https://issues.redhat.com/browse/OCPBUGS-19036): Fix PodStartupStorageOperationsFailing alert [#397](https://github.com/openshift/cluster-storage-operator/pull/397) * [OCPBUGS-15378](https://issues.redhat.com/browse/OCPBUGS-15378): decrease severity for MultipleDefaultStorageClasses alert [#383](https://github.com/openshift/cluster-storage-operator/pull/383) * [OCPBUGS-13004](https://issues.redhat.com/browse/OCPBUGS-13004): OCPBUGS-13005: 4.13: bump prometheus [#367](https://github.com/openshift/cluster-storage-operator/pull/367) * [OCPBUGS-12478](https://issues.redhat.com/browse/OCPBUGS-12478): Add management workloads annotations [#366](https://github.com/openshift/cluster-storage-operator/pull/366) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): cluster-storage-operator must re-create in-tree StorageClass [#351](https://github.com/openshift/cluster-storage-operator/pull/351) * [OCPBUGS-11341](https://issues.redhat.com/browse/OCPBUGS-11341): [release-4.13]: Add missing workload label to openshift-manila-csi-driver NS [#356](https://github.com/openshift/cluster-storage-operator/pull/356) * [OCPBUGS-10645](https://issues.redhat.com/browse/OCPBUGS-10645): Hypershift: set control plane operand properties [#354](https://github.com/openshift/cluster-storage-operator/pull/354) * [OCPBUGS-8498](https://issues.redhat.com/browse/OCPBUGS-8498): assets: csi: hypershift: add pull-secret to aws-ebs-csi-driver-operator ServiceAccount [#348](https://github.com/openshift/cluster-storage-operator/pull/348) * [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/133655e33ac7c8623be39dd3d3f7dd09d82c99ca...98cde3b2e47b0982c9e4ab9ec34930b0021beed3) ### [cluster-update-keys](https://github.com/openshift/cluster-update-keys/tree/7033b4836e4c79a2237c66f31986396d98ac270b) * NO-ISSUE: Updating ose-cluster-update-keys-container image to be consistent with ART for 4.13 [#78](https://github.com/openshift/cluster-update-keys/pull/78) * [OCPBUGS-43886](https://issues.redhat.com/browse/OCPBUGS-43886): keys: Update Red Hat keys to use SHA256 signatures [#67](https://github.com/openshift/cluster-update-keys/pull/67) * Adding the new CI Signer public key [#50](https://github.com/openshift/cluster-update-keys/pull/50) * [Full changelog](https://github.com/openshift/cluster-update-keys/compare/1a7a6e229dc980540f51b969c4f1d9ef5dbc3ab5...7033b4836e4c79a2237c66f31986396d98ac270b) ### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/8b3acaebb7de946e86d20bfdf637e7caaaeb1fb3) * [OCPBUGS-45332](https://issues.redhat.com/browse/OCPBUGS-45332): deps: bump golang.org/x/net to 0.31.0 [#1121](https://github.com/openshift/cluster-version-operator/pull/1121) * [OCPBUGS-27049](https://issues.redhat.com/browse/OCPBUGS-27049): pkg/cvo/availableupdates: Only bump LastAttempt on Cincinnati pulls [#1019](https://github.com/openshift/cluster-version-operator/pull/1019) * [OCPBUGS-20744](https://issues.redhat.com/browse/OCPBUGS-20744): [4.13] Bump http-related deps [#989](https://github.com/openshift/cluster-version-operator/pull/989) * [OCPBUGS-19472](https://issues.redhat.com/browse/OCPBUGS-19472): Reconcile Volumes in SCCs and flag Upgradeable=False when detecting modified SCC [#969](https://github.com/openshift/cluster-version-operator/pull/969) * [OCPBUGS-20321](https://issues.redhat.com/browse/OCPBUGS-20321): pkg/cvo/sync_worker: Always enable the DeploymentConfig capability [#981](https://github.com/openshift/cluster-version-operator/pull/981) * [OCPBUGS-19828](https://issues.redhat.com/browse/OCPBUGS-19828): pkg/clusterconditions/promql: Warm cache with 1s delay [#974](https://github.com/openshift/cluster-version-operator/pull/974) * [OCPBUGS-20263](https://issues.redhat.com/browse/OCPBUGS-20263): pkg/clusterconditions/cache: Avoid panic on all-fresh-cache evaluation [#980](https://github.com/openshift/cluster-version-operator/pull/980) * [OCPBUGS-16613](https://issues.redhat.com/browse/OCPBUGS-16613): Add admin-gate ack-4.13-kube-1.27-api-removals-in-4.14 [#948](https://github.com/openshift/cluster-version-operator/pull/948) * [OCPBUGS-11435](https://issues.redhat.com/browse/OCPBUGS-11435): Update dnsPolicy to allow consistent resolution of the internal LB [#923](https://github.com/openshift/cluster-version-operator/pull/923) * [OCPBUGS-10221](https://issues.redhat.com/browse/OCPBUGS-10221): pkg/cvo/availableupdates: Prioritize conditional risks for largest target version [#912](https://github.com/openshift/cluster-version-operator/pull/912) * [Full changelog](https://github.com/openshift/cluster-version-operator/compare/a1bf930103a77b25e99130644504c3fecdcc4c67...8b3acaebb7de946e86d20bfdf637e7caaaeb1fb3) ### [console](https://github.com/openshift/console/tree/c9a9368dbd7a9e81faa7a17d657345295b8e0195) * [OCPBUGS-79432](https://issues.redhat.com/browse/OCPBUGS-79432): CVE-2026-29063 Bump immutable [#16330](https://github.com/openshift/console/pull/16330) * [ART-18919](https://issues.redhat.com/browse/ART-18919): pin fsevents to latest [#16481](https://github.com/openshift/console/pull/16481) * NO-JIRA: enable multi-architecture yarn builds [#16423](https://github.com/openshift/console/pull/16423) * [CONSOLE-5011](https://issues.redhat.com/browse/CONSOLE-5011): migrate to yarn berry [#16083](https://github.com/openshift/console/pull/16083) * NO-JIRA: Bump builder image to v29 [#15989](https://github.com/openshift/console/pull/15989) * [OCPBUGS-74437](https://issues.redhat.com/browse/OCPBUGS-74437): Bump lodash to latest [#15972](https://github.com/openshift/console/pull/15972) * [OCPBUGS-44160](https://issues.redhat.com/browse/OCPBUGS-44160): bump dompurify to latest [#15594](https://github.com/openshift/console/pull/15594) * [OCPBUGS-57100](https://issues.redhat.com/browse/OCPBUGS-57100): Add all files to `vendor` regardless of gitignore [#15136](https://github.com/openshift/console/pull/15136) * [OCPBUGS-54892](https://issues.redhat.com/browse/OCPBUGS-54892): Show Observe section without PROMETHEUS and MONITORING flags [#14960](https://github.com/openshift/console/pull/14960) * [OCPBUGS-45292](https://issues.redhat.com/browse/OCPBUGS-45292): A value submitted in From view is wrapped with single quotation after switching to Yaml view. [#14573](https://github.com/openshift/console/pull/14573) * [OCPBUGS-44356](https://issues.redhat.com/browse/OCPBUGS-44356): Application creation fail when manually entering input scaling value in local setup [#14509](https://github.com/openshift/console/pull/14509) * [OCPBUGS-45197](https://issues.redhat.com/browse/OCPBUGS-45197): Edit the secret and add the Chinese in the web-console, garbled characters will be displayed [#14552](https://github.com/openshift/console/pull/14552) * [OCPBUGS-44585](https://issues.redhat.com/browse/OCPBUGS-44585): Need to allow blank for Project/namespace when setting SA Subject in 'Project access tab' [#14497](https://github.com/openshift/console/pull/14497) * [OCPBUGS-36557](https://issues.redhat.com/browse/OCPBUGS-36557): Increase login flow state paramater length/entropy [#14483](https://github.com/openshift/console/pull/14483) * [OCPBUGS-42951](https://issues.redhat.com/browse/OCPBUGS-42951): The filepath including leading slash makes error during parsing devfile using Gitlab [#14383](https://github.com/openshift/console/pull/14383) * [OCPBUGS-41594](https://issues.redhat.com/browse/OCPBUGS-41594): Redirects to new PipelineRun logs URL from old PipelineRun logs URL [#14263](https://github.com/openshift/console/pull/14263) * [OCPBUGS-35259](https://issues.redhat.com/browse/OCPBUGS-35259): fix vCenter cluster being empty [#13952](https://github.com/openshift/console/pull/13952) * [OCPBUGS-32147](https://issues.redhat.com/browse/OCPBUGS-32147): Bump graphql-go to v1.3.0 [#13922](https://github.com/openshift/console/pull/13922) * [OCPBUGS-33978](https://issues.redhat.com/browse/OCPBUGS-33978): Helm Plugin's Catalog incorrectly renders a single index entry into multiple tiles [#13872](https://github.com/openshift/console/pull/13872) * [OCPBUGS-34342](https://issues.redhat.com/browse/OCPBUGS-34342): Fix PipelineRun Logs tab navigation [#13890](https://github.com/openshift/console/pull/13890) * [OCPBUGS-24395](https://issues.redhat.com/browse/OCPBUGS-24395): Extra space is in the translation text(Chinese) of 'Create rolebinding' and 'replicate rolebinding' [#13405](https://github.com/openshift/console/pull/13405) * [OCPBUGS-33777](https://issues.redhat.com/browse/OCPBUGS-33777): restrict Masthead logo to max-height to 60px [#13860](https://github.com/openshift/console/pull/13860) * [OCPBUGS-33749](https://issues.redhat.com/browse/OCPBUGS-33749): Add visual connector between VMs and non VMs workloads [#13857](https://github.com/openshift/console/pull/13857) * [OCPBUGS-33382](https://issues.redhat.com/browse/OCPBUGS-33382): Routes created by devfiles do not always use HTTPS [#13827](https://github.com/openshift/console/pull/13827) * [OCPBUGS-33650](https://issues.redhat.com/browse/OCPBUGS-33650): fix issues with Edit Route form [#13851](https://github.com/openshift/console/pull/13851) * [OCPBUGS-32500](https://issues.redhat.com/browse/OCPBUGS-32500): PipelineRuns in Console show wrong status or load indefinitely [#13780](https://github.com/openshift/console/pull/13780) * [OCPBUGS-31077](https://issues.redhat.com/browse/OCPBUGS-31077): Pipeline Name gets changed to "new-pipeline" on the Edit Pipeline YAML/Builder [#13683](https://github.com/openshift/console/pull/13683) * [OCPBUGS-31595](https://issues.redhat.com/browse/OCPBUGS-31595): Fix operands list endpoint. [#13714](https://github.com/openshift/console/pull/13714) * [OCPBUGS-29063](https://issues.redhat.com/browse/OCPBUGS-29063): add additional check to determine if file is binary [#13579](https://github.com/openshift/console/pull/13579) * [OCPBUGS-28788](https://issues.redhat.com/browse/OCPBUGS-28788): Copy response code from proxied plugin requests [#13561](https://github.com/openshift/console/pull/13561) * [OCPBUGS-29243](https://issues.redhat.com/browse/OCPBUGS-29243): Add a new allowInsecure option to the internet proxy [#13593](https://github.com/openshift/console/pull/13593) * [OCPBUGS-27406](https://issues.redhat.com/browse/OCPBUGS-27406): Add Pipeline metrics tab using plugin [#13525](https://github.com/openshift/console/pull/13525) * [OCPBUGS-23483](https://issues.redhat.com/browse/OCPBUGS-23483): add access to create, edit and delete silences for developer user from developer perspective [#13349](https://github.com/openshift/console/pull/13349) * [OCPBUGS-25427](https://issues.redhat.com/browse/OCPBUGS-25427): Fix plugin proxy handler [#13449](https://github.com/openshift/console/pull/13449) * [OCPBUGS-25465](https://issues.redhat.com/browse/OCPBUGS-25465): fix runtime error on Node details Overview when Machin… [#13452](https://github.com/openshift/console/pull/13452) * [OCPBUGS-25146](https://issues.redhat.com/browse/OCPBUGS-25146): add access review for impersonate [#13437](https://github.com/openshift/console/pull/13437) * [OCPBUGS-24591](https://issues.redhat.com/browse/OCPBUGS-24591): ConsolePlugin metrics must no longer be grouped by the vendor [#13424](https://github.com/openshift/console/pull/13424) * [OCPBUGS-22241](https://issues.redhat.com/browse/OCPBUGS-22241): Save also the location.search and .hash values in localStorage to restore them after login [#13271](https://github.com/openshift/console/pull/13271) * [OCPBUGS-24240](https://issues.redhat.com/browse/OCPBUGS-24240): Subsequent PipelineRuns take initial PipelineRun name into account [#13385](https://github.com/openshift/console/pull/13385) * [OCPBUGS-23497](https://issues.redhat.com/browse/OCPBUGS-23497): Cannot Edit Shipwright Build [#13352](https://github.com/openshift/console/pull/13352) * [OCPBUGS-11316](https://issues.redhat.com/browse/OCPBUGS-11316): Fix description for BuildAdapter SDK extension [#12703](https://github.com/openshift/console/pull/12703) * [OCPBUGS-22986](https://issues.redhat.com/browse/OCPBUGS-22986): Correct logout process [#13310](https://github.com/openshift/console/pull/13310) * [OCPBUGS-23065](https://issues.redhat.com/browse/OCPBUGS-23065): remove expandable toggle for conditional update risk d… [#13316](https://github.com/openshift/console/pull/13316) * [OCPBUGS-22784](https://issues.redhat.com/browse/OCPBUGS-22784): add support for new features annotations while preservi… [#13299](https://github.com/openshift/console/pull/13299) * [OCPBUGS-19532](https://issues.redhat.com/browse/OCPBUGS-19532): use active namespace in Create cta href of create action for operator backed [#13179](https://github.com/openshift/console/pull/13179) * [OCPBUGS-18271](https://issues.redhat.com/browse/OCPBUGS-18271): update the KnativeServing API version to v1beta1 for global-config extension [#13112](https://github.com/openshift/console/pull/13112) * [OCPBUGS-20232](https://issues.redhat.com/browse/OCPBUGS-20232): show all the legends for Pipeline metrics in PipelineRun TaskRun Duration chart [#13224](https://github.com/openshift/console/pull/13224) * [OCPBUGS-20231](https://issues.redhat.com/browse/OCPBUGS-20231): fetch TaskRuns without selector and reduces the get TaskRuns requests [#13223](https://github.com/openshift/console/pull/13223) * [OCPBUGS-20330](https://issues.redhat.com/browse/OCPBUGS-20330): Check if filtered object contains name property [#13227](https://github.com/openshift/console/pull/13227) * [OCPBUGS-13285](https://issues.redhat.com/browse/OCPBUGS-13285): add multipath device type to LocalVolumeSet [#12804](https://github.com/openshift/console/pull/12804) * [OCPBUGS-17481](https://issues.redhat.com/browse/OCPBUGS-17481): Fix that "Delete application" doesn't work in topology when Pipelines operator is not installed [#13083](https://github.com/openshift/console/pull/13083) * [OCPBUGS-18764](https://issues.redhat.com/browse/OCPBUGS-18764): Fixed Edit Application form for Knative Services [#13147](https://github.com/openshift/console/pull/13147) * [OCPBUGS-18538](https://issues.redhat.com/browse/OCPBUGS-18538): OCP console mandate secret for repository creation [#13135](https://github.com/openshift/console/pull/13135) * [OCPBUGS-18679](https://issues.redhat.com/browse/OCPBUGS-18679): [knative] Don't rely on openshift/hello-openshift as a sample image [#13140](https://github.com/openshift/console/pull/13140) * [OCPBUGS-18289](https://issues.redhat.com/browse/OCPBUGS-18289): Not able to import the repository with .tekton directory and func.yaml file present [#13116](https://github.com/openshift/console/pull/13116) * [OCPBUGS-18443](https://issues.redhat.com/browse/OCPBUGS-18443): Fix crash when filtering the quick start catalog [#13127](https://github.com/openshift/console/pull/13127) * [OCPBUGS-18312](https://issues.redhat.com/browse/OCPBUGS-18312): Web console slowness on Project>Project access page [#13119](https://github.com/openshift/console/pull/13119) * [OCPBUGS-18335](https://issues.redhat.com/browse/OCPBUGS-18335): Fix DeploymentConfig list performance issues by lazy loading their ReplicationControllers [#13120](https://github.com/openshift/console/pull/13120) * [OCPBUGS-17876](https://issues.redhat.com/browse/OCPBUGS-17876): Fix topology crash when a console.topology/data/factory extension tries to resolve a resource with version from the CRDs which doesn't exists [#13095](https://github.com/openshift/console/pull/13095) * [OCPBUGS-16668](https://issues.redhat.com/browse/OCPBUGS-16668): Dynamic plugin translation support for plurals broken [#13041](https://github.com/openshift/console/pull/13041) * [OCPBUGS-17181](https://issues.redhat.com/browse/OCPBUGS-17181): Creation of GH webhook and attaching it to repo while importing from git using PAC [#13060](https://github.com/openshift/console/pull/13060) * [OCPBUGS-16040](https://issues.redhat.com/browse/OCPBUGS-16040): fix bug where binary secret values are corrupted on edit and add test coverage [#13048](https://github.com/openshift/console/pull/13048) * [OCPBUGS-16659](https://issues.redhat.com/browse/OCPBUGS-16659): Fix RTE in bridge. [#13038](https://github.com/openshift/console/pull/13038) * [OCPBUGS-16158](https://issues.redhat.com/browse/OCPBUGS-16158): "Duplicate RoleBinding" leads to "Unsupported value" error [#13008](https://github.com/openshift/console/pull/13008) * [OCPBUGS-16434](https://issues.redhat.com/browse/OCPBUGS-16434): Fix stop PLR option [#13031](https://github.com/openshift/console/pull/13031) * [OCPBUGS-14265](https://issues.redhat.com/browse/OCPBUGS-14265): Regression: OpenShift Console no-longer filters SecretList when displaying ServiceAccount [#12865](https://github.com/openshift/console/pull/12865) * [OCPBUGS-13641](https://issues.redhat.com/browse/OCPBUGS-13641): Do not fetch catalog sources on CSV or Subscription details pages. [#12811](https://github.com/openshift/console/pull/12811) * [OCPBUGS-16421](https://issues.redhat.com/browse/OCPBUGS-16421): When removing the project owner from the project in GUI, instead of that user, the group (the default group added as project admin through the project template) will be removed. [#13030](https://github.com/openshift/console/pull/13030) * [OCPBUGS-15998](https://issues.redhat.com/browse/OCPBUGS-15998): Upload JAR file does not work if the Cluster Samples Operator is disabled [#12992](https://github.com/openshift/console/pull/12992) * [OCPBUGS-15810](https://issues.redhat.com/browse/OCPBUGS-15810): only show pipelines doc link for downstream [#12981](https://github.com/openshift/console/pull/12981) * [OCPBUGS-15982](https://issues.redhat.com/browse/OCPBUGS-15982): get Kamelets from the camel-k-operator namespace as well [#12988](https://github.com/openshift/console/pull/12988) * [OCPBUGS-16244](https://issues.redhat.com/browse/OCPBUGS-16244): Fix operator backed catalog page when copied CSVs disabled [#13019](https://github.com/openshift/console/pull/13019) * [OCPBUGS-15194](https://issues.redhat.com/browse/OCPBUGS-15194): Remove tech preview badge from Pipeline repository pages [#12916](https://github.com/openshift/console/pull/12916) * [OCPBUGS-10326](https://issues.redhat.com/browse/OCPBUGS-10326): re-enable operator-install-single-namespace.spec.ts test [#12653](https://github.com/openshift/console/pull/12653) * [OCPBUGS-15848](https://issues.redhat.com/browse/OCPBUGS-15848): The upgrade Helm Release tab in OpenShift GUI Developer console is not refreshing with updated values. [#12976](https://github.com/openshift/console/pull/12976) * [OCPBUGS-15890](https://issues.redhat.com/browse/OCPBUGS-15890): Use proxy with web socket connection and monitoring dashboard [#12978](https://github.com/openshift/console/pull/12978) * [OCPBUGS-15720](https://issues.redhat.com/browse/OCPBUGS-15720), [OCPBUGS-15721](https://issues.redhat.com/browse/OCPBUGS-15721), [OCPBUGS-15722](https://issues.redhat.com/browse/OCPBUGS-15722): Helm Chart installation form hangs on create if JSON-schema is using 2019-09 or 2020-20 standard revisions [#12963](https://github.com/openshift/console/pull/12963) * [OCPBUGS-14426](https://issues.redhat.com/browse/OCPBUGS-14426): account for single object in status.conditions instead… [#12875](https://github.com/openshift/console/pull/12875) * [OCPBUGS-14267](https://issues.redhat.com/browse/OCPBUGS-14267): Add Pipeline metrics unsupported empty page [#12864](https://github.com/openshift/console/pull/12864) * [OCPBUGS-15410](https://issues.redhat.com/browse/OCPBUGS-15410): Add Git Repository (PAC) doesn't setup GitLab and Bitbucket configuration correct [#12936](https://github.com/openshift/console/pull/12936) * [OCPBUGS-15787](https://issues.redhat.com/browse/OCPBUGS-15787): Remove access review check for PipelineResource from Pipeline section [#12967](https://github.com/openshift/console/pull/12967) * [OCPBUGS-15228](https://issues.redhat.com/browse/OCPBUGS-15228): Create helm release page doesn't show a YAML editor when schema isn't available (httpd-imagestreams chart) [#12937](https://github.com/openshift/console/pull/12937) * [release 4.13] OCPBUGS-15360: Serverless functions UI warning is misleading [#12931](https://github.com/openshift/console/pull/12931) * [OCPBUGS-14166](https://issues.redhat.com/browse/OCPBUGS-14166): Fixed Make Serverless Form Error [#12857](https://github.com/openshift/console/pull/12857) * [OCPBUGS-14336](https://issues.redhat.com/browse/OCPBUGS-14336): use service port name instead targetPort in the Pipeline Event listener route [#12870](https://github.com/openshift/console/pull/12870) * [OCPBUGS-14310](https://issues.redhat.com/browse/OCPBUGS-14310): Could not import multiple resources via JSON (while YAML supports this) [#12868](https://github.com/openshift/console/pull/12868) * [OCPBUGS-15335](https://issues.redhat.com/browse/OCPBUGS-15335): Delete annotation 'tekton.dev/v1beta1TaskRuns' when rerun the PLR [#12927](https://github.com/openshift/console/pull/12927) * [OCPBUGS-15130](https://issues.redhat.com/browse/OCPBUGS-15130): Helm Repository "Edit" button results in 404 [#12909](https://github.com/openshift/console/pull/12909) * [OCPBUGS-14189](https://issues.redhat.com/browse/OCPBUGS-14189): Corrected Labels for resolving the bug related to the Create Route Checkbox [#12858](https://github.com/openshift/console/pull/12858) * [OCPBUGS-13642](https://issues.redhat.com/browse/OCPBUGS-13642): Fix OLM k8sResourcePrefix descriptor dropdown behavior [#12812](https://github.com/openshift/console/pull/12812) * [OCPBUGS-11974](https://issues.redhat.com/browse/OCPBUGS-11974): Add page title to Devconsole pages [#12844](https://github.com/openshift/console/pull/12844) * [OCPBUGS-15465](https://issues.redhat.com/browse/OCPBUGS-15465), [OCPBUGS-15481](https://issues.redhat.com/browse/OCPBUGS-15481): Remove PipelineResource CRD check because it's not installed with PO 1.11 anymore and disable operator-uninstall test [#12949](https://github.com/openshift/console/pull/12949) * [OCPBUGS-14943](https://issues.redhat.com/browse/OCPBUGS-14943): visiting Configurations page returns error Cannot read… [#12897](https://github.com/openshift/console/pull/12897) * [OCPBUGS-12785](https://issues.redhat.com/browse/OCPBUGS-12785): Project admin can update and view subscription from operator details page [#12780](https://github.com/openshift/console/pull/12780) * [OCPBUGS-14574](https://issues.redhat.com/browse/OCPBUGS-14574): only copy workload annotations to debug pod [#12879](https://github.com/openshift/console/pull/12879) * [OCPBUGS-14258](https://issues.redhat.com/browse/OCPBUGS-14258): Add vSphere cluster field. [#12862](https://github.com/openshift/console/pull/12862) * [OCPBUGS-14195](https://issues.redhat.com/browse/OCPBUGS-14195): Topology UI doesn't recognize Serverless Rust function for proper UI icon [#12860](https://github.com/openshift/console/pull/12860) * [OCPBUGS-10527](https://issues.redhat.com/browse/OCPBUGS-10527): When there are 2 pipelines displayed in the dropdown menu, selecting one, unchecks the Add Pipeline checkbox [#12658](https://github.com/openshift/console/pull/12658) * [OCPBUGS-14165](https://issues.redhat.com/browse/OCPBUGS-14165): propagate labels to pipeline resources [#12856](https://github.com/openshift/console/pull/12856) * [OCPBUGS-13959](https://issues.redhat.com/browse/OCPBUGS-13959): Wait with CRD/model translation until i18n bundles are loaded [#12842](https://github.com/openshift/console/pull/12842) * [OCPBUGS-13783](https://issues.redhat.com/browse/OCPBUGS-13783): fix runtime error on OperatorHub details pages [#12830](https://github.com/openshift/console/pull/12830) * [OCPBUGS-12770](https://issues.redhat.com/browse/OCPBUGS-12770): fix buildconfig form ns [#12776](https://github.com/openshift/console/pull/12776) * [OCPBUGS-12850](https://issues.redhat.com/browse/OCPBUGS-12850): add support for minimal status of tekton [#12784](https://github.com/openshift/console/pull/12784) * [OCPBUGS-12740](https://issues.redhat.com/browse/OCPBUGS-12740): update helm release empty state text [#12773](https://github.com/openshift/console/pull/12773) * [OCPBUGS-11866](https://issues.redhat.com/browse/OCPBUGS-11866): delete associated pipeline, triggertemplate and eventlistener when deleting app [#12730](https://github.com/openshift/console/pull/12730) * [OCPBUGS-12186](https://issues.redhat.com/browse/OCPBUGS-12186): Pipeline doesn't render correctly when displayed but looks fine in edit mode [#12748](https://github.com/openshift/console/pull/12748) * [OCPBUGS-11218](https://issues.redhat.com/browse/OCPBUGS-11218): use PipelineRun template from 'pipelines-as-code-pipelinerun-go' configMap for Go runtime [#12696](https://github.com/openshift/console/pull/12696) * [OCPBUGS-12273](https://issues.redhat.com/browse/OCPBUGS-12273): When Creating Sample Devfile from the Samples Page, Topology Icon is not set [#12757](https://github.com/openshift/console/pull/12757) * [OCPBUGS-12272](https://issues.redhat.com/browse/OCPBUGS-12272): Importing a kn Service shows a non-working Open URL decorator also when the Add Route checkbox was unselected [#12756](https://github.com/openshift/console/pull/12756) * [OCPBUGS-12173](https://issues.redhat.com/browse/OCPBUGS-12173): taskrun ui fails when using object type results [#12745](https://github.com/openshift/console/pull/12745) * [OCPBUGS-10832](https://issues.redhat.com/browse/OCPBUGS-10832): Edit Deployment (and DC) form doesn't enable Save button when changing strategy type [#12674](https://github.com/openshift/console/pull/12674) * [OCPBUGS-11919](https://issues.redhat.com/browse/OCPBUGS-11919): Reduce metrics cardinality by grouping well-known and other perspectives and plugins [#12742](https://github.com/openshift/console/pull/12742) * [OCPBUGS-10266](https://issues.redhat.com/browse/OCPBUGS-10266): Fixes argocd link for non-KAM added application envs [#12649](https://github.com/openshift/console/pull/12649) * [OCPBUGS-10265](https://issues.redhat.com/browse/OCPBUGS-10265): Fixes resource status alignment issue [#12648](https://github.com/openshift/console/pull/12648) * [OCPBUGS-10299](https://issues.redhat.com/browse/OCPBUGS-10299): Fixes card sizes not even issue when commit info is not available on Environments page [#12651](https://github.com/openshift/console/pull/12651) * [OCPBUGS-12172](https://issues.redhat.com/browse/OCPBUGS-12172): Users don't know what type of resource is being created by Import from Git or Deploy Image flows [#12744](https://github.com/openshift/console/pull/12744) * [OCPBUGS-10678](https://issues.redhat.com/browse/OCPBUGS-10678): Do not show builder ImageStreams without `sampleRepo` as samples [#12668](https://github.com/openshift/console/pull/12668) * [OCPBUGS-11232](https://issues.redhat.com/browse/OCPBUGS-11232): fix All projects selection on Pipelines page in dev perspective [#12698](https://github.com/openshift/console/pull/12698) * [OCPBUGS-11390](https://issues.redhat.com/browse/OCPBUGS-11390): Move operator install status to it's own route/page [#12706](https://github.com/openshift/console/pull/12706) * [OCPBUGS-11107](https://issues.redhat.com/browse/OCPBUGS-11107): Fix alerts source display values [#12688](https://github.com/openshift/console/pull/12688) * [OCPBUGS-11248](https://issues.redhat.com/browse/OCPBUGS-11248): fix translation string for Image pull secret created alert [#12699](https://github.com/openshift/console/pull/12699) * [OCPBUGS-10833](https://issues.redhat.com/browse/OCPBUGS-10833): update the default pipelineRun template name [#12675](https://github.com/openshift/console/pull/12675) * [OCPBUGS-10679](https://issues.redhat.com/browse/OCPBUGS-10679): Show type of sample on the samples view [#12639](https://github.com/openshift/console/pull/12639) * [OCPBUGS-10474](https://issues.redhat.com/browse/OCPBUGS-10474): OpenShift pipeline TaskRun(s) column Duration is not present as column in UI [#12656](https://github.com/openshift/console/pull/12656) * And 1 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/console/compare/63e29cb1e0de321595a6f144f59678fea23e51d4...c9a9368dbd7a9e81faa7a17d657345295b8e0195) ### [console-operator](https://github.com/openshift/console-operator/tree/4056ea6e34adfac540eaef4ca04fbd18518dc0ca) * [OCPBUGS-77995](https://issues.redhat.com/browse/OCPBUGS-77995): [release-4.13] NO-JIRA: update go mod dependency for konflux [#1118](https://github.com/openshift/console-operator/pull/1118) * [OCPBUGS-18674](https://issues.redhat.com/browse/OCPBUGS-18674): Reset console operator's conditions [#894](https://github.com/openshift/console-operator/pull/894) * [OCPBUGS-30599](https://issues.redhat.com/browse/OCPBUGS-30599): Disable HTTP/2 for webhook [#875](https://github.com/openshift/console-operator/pull/875) * [OCPBUGS-21008](https://issues.redhat.com/browse/OCPBUGS-21008): [release-4.13] Bump library-go and golang.org/x/net [#866](https://github.com/openshift/console-operator/pull/866) * [OCPBUGS-6208](https://issues.redhat.com/browse/OCPBUGS-6208): Updating openshift-enterprise-console-operator images to be consistent with ART [#872](https://github.com/openshift/console-operator/pull/872) * [OCPBUGS-24591](https://issues.redhat.com/browse/OCPBUGS-24591): ConsolePlugin metrics must no longer be grouped by the vendor [#821](https://github.com/openshift/console-operator/pull/821) * [OCPBUGS-22333](https://issues.redhat.com/browse/OCPBUGS-22333): Make enabled plugins unique [#805](https://github.com/openshift/console-operator/pull/805) * [OCPBUGS-18972](https://issues.redhat.com/browse/OCPBUGS-18972): Manual backport of #761 [#793](https://github.com/openshift/console-operator/pull/793) * [OCPBUGS-18192](https://issues.redhat.com/browse/OCPBUGS-18192): Add haproxy timeout annotation to console routes [#787](https://github.com/openshift/console-operator/pull/787) * [OCPBUGS-16241](https://issues.redhat.com/browse/OCPBUGS-16241): Add missing watch permission for helm-chartrepos-viewers [#778](https://github.com/openshift/console-operator/pull/778) * [OCPBUGS-14039](https://issues.redhat.com/browse/OCPBUGS-14039): Backport #774 and #763 [#779](https://github.com/openshift/console-operator/pull/779) * [OCPBUGS-12461](https://issues.redhat.com/browse/OCPBUGS-12461): Add new PrometheusRule to collect metrics for cluster-monitoring-operator [#758](https://github.com/openshift/console-operator/pull/758) * [OCPBUGS-12722](https://issues.redhat.com/browse/OCPBUGS-12722): Proper cleanup of route sync conditions [#759](https://github.com/openshift/console-operator/pull/759) * [OCPBUGS-11462](https://issues.redhat.com/browse/OCPBUGS-11462): Disable multicluster tech preview [#754](https://github.com/openshift/console-operator/pull/754) * And 1 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/console-operator/compare/0920157ed70793287449904114540bc8bb1a31eb...4056ea6e34adfac540eaef4ca04fbd18518dc0ca) ### [container-networking-plugins](https://github.com/openshift/containernetworking-plugins/tree/3086cf651514b87cc891b3dfbb65a645bd0b100e) * [ART-13080](https://issues.redhat.com/browse/ART-13080): Fix Hermeto build issues [#197](https://github.com/openshift/containernetworking-plugins/pull/197) * [OCPBUGS-20594](https://issues.redhat.com/browse/OCPBUGS-20594): build(deps): bump golang.org/x/net from 0.10.0 to 0.17.0 [backport 4.13] [#130](https://github.com/openshift/containernetworking-plugins/pull/130) * [OCPBUGS-17728](https://issues.redhat.com/browse/OCPBUGS-17728): Default CNI binaries to RHEL 8 [#117](https://github.com/openshift/containernetworking-plugins/pull/117) * Add rhel9 binary [#102](https://github.com/openshift/containernetworking-plugins/pull/102) * [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/f769225964a6505cb706eb74e78c3d6eb3cae355...3086cf651514b87cc891b3dfbb65a645bd0b100e) ### [coredns](https://github.com/openshift/coredns/tree/d3037cb9c6c13078d0ea2a7c6e7a4b6c21b29362) * [OCPBUGS-60804](https://issues.redhat.com/browse/OCPBUGS-60804): Bump github.com/golang/glog to v1.2.4 [#150](https://github.com/openshift/coredns/pull/150) * [OCPBUGS-38431](https://issues.redhat.com/browse/OCPBUGS-38431): UPSTREAM: 6354: openshift: key cache on Checking Disabled (CD) bit [#129](https://github.com/openshift/coredns/pull/129) * [OCPBUGS-28205](https://issues.redhat.com/browse/OCPBUGS-28205): UPSTREAM: 6277: openshift: Fix OCPBUGS-28205 [#113](https://github.com/openshift/coredns/pull/113) * [OCPBUGS-21046](https://issues.redhat.com/browse/OCPBUGS-21046): UPSTREAM: <carry>: openshift: Address CVE-2023-39325 [#102](https://github.com/openshift/coredns/pull/102) * [OCPBUGS-19985](https://issues.redhat.com/browse/OCPBUGS-19985): UPSTREAM: <carry>: openshift: Fix OCPBUGS-19985 [#97](https://github.com/openshift/coredns/pull/97) * [Full changelog](https://github.com/openshift/coredns/compare/d10f7ff3322ac6844fc1ff070528664c8931ed24...d3037cb9c6c13078d0ea2a7c6e7a4b6c21b29362) ### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/25aa5f367399500e5634d86158e227ebad1936fe) * [OCPBUGS-79799](https://issues.redhat.com/browse/OCPBUGS-79799): Apply code mitigations for CVE-2026-33186 [#400](https://github.com/openshift/cloud-provider-openstack/pull/400) * [OCPBUGS-67628](https://issues.redhat.com/browse/OCPBUGS-67628): fix CVE-2025-65637 [#364](https://github.com/openshift/cloud-provider-openstack/pull/364) * [OCPBUGS-58888](https://issues.redhat.com/browse/OCPBUGS-58888): CARRY: don't ignore json files [#344](https://github.com/openshift/cloud-provider-openstack/pull/344) * [OCPBUGS-52414](https://issues.redhat.com/browse/OCPBUGS-52414): Merge https://github.com/kubernetes/cloud-provider-openstack:release-1.26 into release-4.13 [#313](https://github.com/openshift/cloud-provider-openstack/pull/313) * Switch to a new CI [#2444](https://github.com/openshift/cloud-provider-openstack/pull/2444) * update tags to v1.26.1 [#2119](https://github.com/openshift/cloud-provider-openstack/pull/2119) * update tags to v1.26.0 release [#2070](https://github.com/openshift/cloud-provider-openstack/pull/2070) * And 31 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/5ffe43c8ba7f7bb0549424daeec905b2c287cc21...25aa5f367399500e5634d86158e227ebad1936fe) ### [csi-driver-manila-operator](https://github.com/openshift/csi-driver-manila-operator/tree/67883f057e0db4d591e350734c06cd9421adcd47) * [OCPBUGS-67629](https://issues.redhat.com/browse/OCPBUGS-67629): Bump logrus [#254](https://github.com/openshift/csi-driver-manila-operator/pull/254) * [OCPBUGS-26224](https://issues.redhat.com/browse/OCPBUGS-26224): Fix selector for manila-csi-driver-controller-metrics service [#224](https://github.com/openshift/csi-driver-manila-operator/pull/224) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#195](https://github.com/openshift/csi-driver-manila-operator/pull/195) * [OCPBUGS-17160](https://issues.redhat.com/browse/OCPBUGS-17160): Don't cache OpenStack client [#196](https://github.com/openshift/csi-driver-manila-operator/pull/196) * [OCPBUGS-9942](https://issues.redhat.com/browse/OCPBUGS-9942): Bump go.mongodb.org/mongo-driver to v1.5.1 [#174](https://github.com/openshift/csi-driver-manila-operator/pull/174) * [Full changelog](https://github.com/openshift/csi-driver-manila-operator/compare/dfad3e86768684058148cc46c4ed3d97ae978f2b...67883f057e0db4d591e350734c06cd9421adcd47) ### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/61772d79c8c6b41c4bd0c8f972a20357cf427850) * [OCPBUGS-84928](https://issues.redhat.com/browse/OCPBUGS-84928): Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.64.1-sec.1 to avoid go version bump and fix CVE-2026-33186 [#185](https://github.com/openshift/csi-driver-nfs/pull/185) * [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/155b6abebd6815614a25e2fe471a8aba3b9a768c...61772d79c8c6b41c4bd0c8f972a20357cf427850) ### [csi-driver-shared-resource, csi-driver-shared-resource-webhook](https://github.com/openshift/csi-driver-shared-resource/tree/01bbb23b627835354f6177b4b44cfc50bd6d9a2e) * [OCPBUGS-28953](https://issues.redhat.com/browse/OCPBUGS-28953): Replace 'coreydaley' with 'sayan-biswas' in OWNERS file [#168](https://github.com/openshift/csi-driver-shared-resource/pull/168) * [OCPBUGS-23116](https://issues.redhat.com/browse/OCPBUGS-23116): Should reference configmaps instead of secrets [#153](https://github.com/openshift/csi-driver-shared-resource/pull/153) * [OCPBUGS-20719](https://issues.redhat.com/browse/OCPBUGS-20719): bump golang.org/x/net to v0.17.0 [#147](https://github.com/openshift/csi-driver-shared-resource/pull/147) * [OCPBUGS-12484](https://issues.redhat.com/browse/OCPBUGS-12484), [OCPBUGS-12527](https://issues.redhat.com/browse/OCPBUGS-12527), [OCPBUGS-14505](https://issues.redhat.com/browse/OCPBUGS-14505): Mitigating CVE-2022-41723 [#140](https://github.com/openshift/csi-driver-shared-resource/pull/140) * [Full changelog](https://github.com/openshift/csi-driver-shared-resource/compare/9232c1ff48df333dadc9f7dc275649866e55ced0...01bbb23b627835354f6177b4b44cfc50bd6d9a2e) ### [csi-driver-shared-resource-operator](https://github.com/openshift/csi-driver-shared-resource-operator/tree/bc169d2d8d1cd128770d2202c6cc00e5328e4e73) * [OCPBUGS-28958](https://issues.redhat.com/browse/OCPBUGS-28958): Replace 'coreydaley' with 'sayan-biswas' in OWNERS file [#104](https://github.com/openshift/csi-driver-shared-resource-operator/pull/104) * [OCPBUGS-20806](https://issues.redhat.com/browse/OCPBUGS-20806): bump golang.org/x/net to v0.17.0 [#87](https://github.com/openshift/csi-driver-shared-resource-operator/pull/87) * [OCPBUGS-11432](https://issues.redhat.com/browse/OCPBUGS-11432): add openshift workload annotation to driver daemonset [#74](https://github.com/openshift/csi-driver-shared-resource-operator/pull/74) * [Full changelog](https://github.com/openshift/csi-driver-shared-resource-operator/compare/c273cd52b791e69da41ac23fafb6d926c0530276...bc169d2d8d1cd128770d2202c6cc00e5328e4e73) ### [csi-external-attacher](https://github.com/openshift/csi-external-attacher/tree/d92908438817984fc47558fdaa03805d8c3b256c) * [OCPBUGS-21161](https://issues.redhat.com/browse/OCPBUGS-21161): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#61](https://github.com/openshift/csi-external-attacher/pull/61) * [OCPBUGS-16637](https://issues.redhat.com/browse/OCPBUGS-16637): [release-4.13] UPSTREAM: 415: fix: CVE-2022-41723 [#56](https://github.com/openshift/csi-external-attacher/pull/56) * [Full changelog](https://github.com/openshift/csi-external-attacher/compare/06e8ce0d36f7c23f0906327cd66ec6bd15165366...d92908438817984fc47558fdaa03805d8c3b256c) ### [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner/tree/0bf126b77a721ddaa4706fcb41f8b7be8d292492) * [OCPBUGS-20759](https://issues.redhat.com/browse/OCPBUGS-20759): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#73](https://github.com/openshift/csi-external-provisioner/pull/73) * [OCPBUGS-16609](https://issues.redhat.com/browse/OCPBUGS-16609): [release-4.13] UPSTREAM: 880: Bump golang.org/x/net [#67](https://github.com/openshift/csi-external-provisioner/pull/67) * [Full changelog](https://github.com/openshift/csi-external-provisioner/compare/e18ed7f00d8c80564a8dd5827013cd49f33ff0d7...0bf126b77a721ddaa4706fcb41f8b7be8d292492) ### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/e8036caff2482648a18c1ac776cf9d2474569d10) * [OCPBUGS-20908](https://issues.redhat.com/browse/OCPBUGS-20908): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#148](https://github.com/openshift/csi-external-resizer/pull/148) * [OCPBUGS-16639](https://issues.redhat.com/browse/OCPBUGS-16639): [release-4.13] UPSTREAM: 268: Bump golang.org/x/net [#143](https://github.com/openshift/csi-external-resizer/pull/143) * [Full changelog](https://github.com/openshift/csi-external-resizer/compare/59a701a4c8cd3105e272b12afdb1e62e411b2772...e8036caff2482648a18c1ac776cf9d2474569d10) ### [csi-external-snapshotter, csi-snapshot-controller, csi-snapshot-validation-webhook](https://github.com/openshift/csi-external-snapshotter/tree/c8a7a097f68b37ad06a87a4b5c480daeab45be85) * [OCPBUGS-29728](https://issues.redhat.com/browse/OCPBUGS-29728): cherry-pick:release-4.13: OCPBUGS-29244 Update VolumeSnapshot and VolumeSnapshotContent using JSON patch [#141](https://github.com/openshift/csi-external-snapshotter/pull/141) * [OCPBUGS-21011](https://issues.redhat.com/browse/OCPBUGS-21011): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#110](https://github.com/openshift/csi-external-snapshotter/pull/110) * [OCPBUGS-16638](https://issues.redhat.com/browse/OCPBUGS-16638): [release-4.13] UPSTREAM: 815: updated go module files [#103](https://github.com/openshift/csi-external-snapshotter/pull/103) * [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/a6834536936b16dcd9ee81a8753a2ef6dc208541...c8a7a097f68b37ad06a87a4b5c480daeab45be85) ### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/3587db51b8a672a2d3be2ac48ea107e474f33402) * [OCPBUGS-20636](https://issues.redhat.com/browse/OCPBUGS-20636): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#51](https://github.com/openshift/csi-livenessprobe/pull/51) * [OCPBUGS-16600](https://issues.redhat.com/browse/OCPBUGS-16600): [release-4.13] UPSTREAM: 179: fix: CVE-2022-41723 [#46](https://github.com/openshift/csi-livenessprobe/pull/46) * [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/a9bcbde134a17d3335f68a49aaad4befa8d7cc08...3587db51b8a672a2d3be2ac48ea107e474f33402) ### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/9ea90f34485500a525fcaad3d79ee82a41402d47) * [OCPBUGS-20686](https://issues.redhat.com/browse/OCPBUGS-20686): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#53](https://github.com/openshift/csi-node-driver-registrar/pull/53) * [OCPBUGS-16608](https://issues.redhat.com/browse/OCPBUGS-16608): [release-4.13] UPSTREAM: 284: Bump golang.org/x/net [#48](https://github.com/openshift/csi-node-driver-registrar/pull/48) * [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/9dcaa7f5b7573e7ef9dbec1439abc32171003799...9ea90f34485500a525fcaad3d79ee82a41402d47) ### [docker-builder](https://github.com/openshift/builder/tree/b379980d6f626dc45a91f0a715bc94e75fb4b309) * [OCPBUGS-43295](https://issues.redhat.com/browse/OCPBUGS-43295): Buildah dependency bump to 1.29.5 [#460](https://github.com/openshift/builder/pull/460) * [OCPBUGS-43191](https://issues.redhat.com/browse/OCPBUGS-43191): runc library bump to 1.1.12 [#439](https://github.com/openshift/builder/pull/439) * [OCPBUGS-48836](https://issues.redhat.com/browse/OCPBUGS-48836): skipping some unit tests to avoid failures as they are duplicate [#434](https://github.com/openshift/builder/pull/434) * [OCPBUGS-48655](https://issues.redhat.com/browse/OCPBUGS-48655): Add new team members to the OWNERS file [#431](https://github.com/openshift/builder/pull/431) * Replace 'coreydaley' with 'sayan-biswas' [#407](https://github.com/openshift/builder/pull/407) * [BUILD-854](https://issues.redhat.com/browse/BUILD-854): Add adambkaplan as approver [#405](https://github.com/openshift/builder/pull/405) * [OCPBUGS-22468](https://issues.redhat.com/browse/OCPBUGS-22468): [release-4.13] Bump github.com/sigstore/rekor [#374](https://github.com/openshift/builder/pull/374) * [OCPBUGS-23021](https://issues.redhat.com/browse/OCPBUGS-23021): Add -p flag to cp command to preserve timestamps [#371](https://github.com/openshift/builder/pull/371) * [OCPBUGS-20709](https://issues.redhat.com/browse/OCPBUGS-20709): [release-4.13] Bump golang.org/x/net [#363](https://github.com/openshift/builder/pull/363) * [OCPBUGS-15606](https://issues.redhat.com/browse/OCPBUGS-15606): Add the git-lfs package [#352](https://github.com/openshift/builder/pull/352) * [OCPBUGS-10002](https://issues.redhat.com/browse/OCPBUGS-10002), [OCPBUGS-8159](https://issues.redhat.com/browse/OCPBUGS-8159), [OCPBUGS-8191](https://issues.redhat.com/browse/OCPBUGS-8191): Mitigate CVE-2023-26054 [#348](https://github.com/openshift/builder/pull/348) * [OCPBUGS-11387](https://issues.redhat.com/browse/OCPBUGS-11387): bump(github.com/containers/common) to v0.51.2 [#336](https://github.com/openshift/builder/pull/336) * [Full changelog](https://github.com/openshift/builder/compare/57539b86d3c60b773090f6dc05790aad032444c3...b379980d6f626dc45a91f0a715bc94e75fb4b309) ### [docker-registry](https://github.com/openshift/image-registry/tree/d00c2694d7ccfe28536fad6ac9b9dd3967d01107) * [OCPBUGS-53653](https://issues.redhat.com/browse/OCPBUGS-53653): bump jwt and oauth dependencies [#436](https://github.com/openshift/image-registry/pull/436) * [OCPBUGS-19655](https://issues.redhat.com/browse/OCPBUGS-19655): increase rest.Config QPS and Burst [#383](https://github.com/openshift/image-registry/pull/383) * [OCPBUGS-18321](https://issues.redhat.com/browse/OCPBUGS-18321): bump docker-distribution [#376](https://github.com/openshift/image-registry/pull/376) * [Full changelog](https://github.com/openshift/image-registry/compare/ce0483f140c5065a1b4aafbbbb94b1b9ca5f29e1...d00c2694d7ccfe28536fad6ac9b9dd3967d01107) ### [driver-toolkit](https://github.com/openshift/driver-toolkit/tree/d719bdcfa49bc18b729117ee513a86a1ddecb63a) * Upgrade glibc, use dnf (#130) [#130](https://github.com/openshift/driver-toolkit/pull/130) * Fixing the regexp used to get the correct GCC version. (#129) [#129](https://github.com/openshift/driver-toolkit/pull/129) * Updating the docs to use `ubi9` instead of `ubi8`. (#128) [#128](https://github.com/openshift/driver-toolkit/pull/128) * Moving to `rhel9` base image. (#125) [#125](https://github.com/openshift/driver-toolkit/pull/125) * Remove abi since it was not in 9.2 rpms (#124) [#124](https://github.com/openshift/driver-toolkit/pull/124) * [Full changelog](https://github.com/openshift/driver-toolkit/compare/cafed17b0c2b4cf8d8310304888787ed7adf7474...d719bdcfa49bc18b729117ee513a86a1ddecb63a) ### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/dfe03737f1562e81aa09101e4a48f039245bd339) * [OCPBUGS-11648](https://issues.redhat.com/browse/OCPBUGS-11648): update go-yaml to v2.4.0 [#68](https://github.com/openshift/egress-router-cni/pull/68) * Add rhel9 binary [#71](https://github.com/openshift/egress-router-cni/pull/71) * [Full changelog](https://github.com/openshift/egress-router-cni/compare/96f2f54fec843fc9e8dec826d7b3fa25cdf38d7f...dfe03737f1562e81aa09101e4a48f039245bd339) ### [etcd](https://github.com/openshift/etcd/tree/a6b7ad436ea8139436c6e9a456fdacd09ec7f054) * [OCPBUGS-32920](https://issues.redhat.com/browse/OCPBUGS-32920): Revert "Merge pull request #262 from Elbehery/rebase-etcd-3.5.13-open… [#266](https://github.com/openshift/etcd/pull/266) * [OCPBUGS-31653](https://issues.redhat.com/browse/OCPBUGS-31653): Rebase etcd 3.5.13 openshift 4.13 [#262](https://github.com/openshift/etcd/pull/262) * [ETCD-537](https://issues.redhat.com/browse/ETCD-537): Revert "bump build root go1.20" [#263](https://github.com/openshift/etcd/pull/263) * [OCPBUGS-28734](https://issues.redhat.com/browse/OCPBUGS-28734): Rebase etcd 3.5.12 openshift 4.13 [#245](https://github.com/openshift/etcd/pull/245) * [ETCD-537](https://issues.redhat.com/browse/ETCD-537): bump build root go1.20 [#252](https://github.com/openshift/etcd/pull/252) * [OCPBUGS-26925](https://issues.redhat.com/browse/OCPBUGS-26925): Rebase etcd 3.5.11 openshift 4.13 [#239](https://github.com/openshift/etcd/pull/239) * [OCPBUGS-22697](https://issues.redhat.com/browse/OCPBUGS-22697): [4.13] Carrying fixes for CVE-2023-44487 [#225](https://github.com/openshift/etcd/pull/225) * [OCPBUGS-18497](https://issues.redhat.com/browse/OCPBUGS-18497): Updating ose-etcd images to be consistent with ART [#214](https://github.com/openshift/etcd/pull/214) * [OCPBUGS-18398](https://issues.redhat.com/browse/OCPBUGS-18398): UPSTREAM <carry>: update build images to rhel9 [#212](https://github.com/openshift/etcd/pull/212) * [OCPBUGS-15859](https://issues.redhat.com/browse/OCPBUGS-15859): [4.13] Rebase openshift/etcd to 3.5.9 [#204](https://github.com/openshift/etcd/pull/204) * Update owners [#177](https://github.com/openshift/etcd/pull/177) * [Full changelog](https://github.com/openshift/etcd/compare/5ed5044c5661c55d297ab0348056b50969af9627...a6b7ad436ea8139436c6e9a456fdacd09ec7f054) ### [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp/tree/507fea9800dc63da95ce551d2fb03219d0b0597a) * [OCPBUGS-21303](https://issues.redhat.com/browse/OCPBUGS-21303): Bump golang.org/x/net to v0.18.0 [#43](https://github.com/openshift/cloud-provider-gcp/pull/43) * [OCPBUGS-12603](https://issues.redhat.com/browse/OCPBUGS-12603): Bump x/net package to v0.10.0 [#32](https://github.com/openshift/cloud-provider-gcp/pull/32) * [Full changelog](https://github.com/openshift/cloud-provider-gcp/compare/09e96a91c4c95e4f8a3d77bae81875c570dd9e3c...507fea9800dc63da95ce551d2fb03219d0b0597a) ### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/47ec07a8b42dd7b40f354b395affeb3e16133b5e) * [OCPBUGS-78283](https://issues.redhat.com/browse/OCPBUGS-78283): [release-4.13] hermetic migration 4.13 [#279](https://github.com/openshift/cluster-api-provider-gcp/pull/279) * [OCPBUGS-78283](https://issues.redhat.com/browse/OCPBUGS-78283): [release-4.13] hermetic migration 4.13 [#270](https://github.com/openshift/cluster-api-provider-gcp/pull/270) * [OCPBUGS-21398](https://issues.redhat.com/browse/OCPBUGS-21398): Bump golang.org/x/net to v0.17.0 [#204](https://github.com/openshift/cluster-api-provider-gcp/pull/204) * [OCPBUGS-12604](https://issues.redhat.com/browse/OCPBUGS-12604): Bump x/net package to v0.10.0 [#196](https://github.com/openshift/cluster-api-provider-gcp/pull/196) * [OCPBUGS-8481](https://issues.redhat.com/browse/OCPBUGS-8481): [release-4.13] Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:release-1.2 (1d8cf4c) into release-4.13 [#192](https://github.com/openshift/cluster-api-provider-gcp/pull/192) * [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/8fa3332c2730fbc5bd8b886885052b6a593c0d72...47ec07a8b42dd7b40f354b395affeb3e16133b5e) ### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/d0cb21644eb49b82f450f3c2e393858935a6cd47) * [OCPBUGS-79795](https://issues.redhat.com/browse/OCPBUGS-79795): Address CVE-2026-33186 [#173](https://github.com/openshift/machine-api-provider-gcp/pull/173) * [OCPBUGS-78182](https://issues.redhat.com/browse/OCPBUGS-78182): hermetic 4.13 [#142](https://github.com/openshift/machine-api-provider-gcp/pull/142) * [OCPBUGS-56916](https://issues.redhat.com/browse/OCPBUGS-56916): Disable shielded VMs for non-UEFI disks [#120](https://github.com/openshift/machine-api-provider-gcp/pull/120) * [OCPBUGS-24563](https://issues.redhat.com/browse/OCPBUGS-24563): Reduce metrics cardinality. [#74](https://github.com/openshift/machine-api-provider-gcp/pull/74) * [OCPBUGS-20851](https://issues.redhat.com/browse/OCPBUGS-20851): Bump x/net package to v0.18.0 [#68](https://github.com/openshift/machine-api-provider-gcp/pull/68) * [OCPBUGS-13046](https://issues.redhat.com/browse/OCPBUGS-13046): Bump x/net to v0.7.0 [#50](https://github.com/openshift/machine-api-provider-gcp/pull/50) * [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/b4b551be8c8bca597db25cae752277da957dfacd...d0cb21644eb49b82f450f3c2e393858935a6cd47) ### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/81e6074605854246cdab8425a7289ad83169571a) * [OCPBUGS-20735](https://issues.redhat.com/browse/OCPBUGS-20735): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#46](https://github.com/openshift/gcp-pd-csi-driver/pull/46) * [OCPBUGS-16331](https://issues.redhat.com/browse/OCPBUGS-16331): 4.13: UPSTREAM: 1169: Fix CVE-2022-41723 [#38](https://github.com/openshift/gcp-pd-csi-driver/pull/38) * [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/8a626fe5354a7cb28e31034dc8afe9c00d4b5a03...81e6074605854246cdab8425a7289ad83169571a) ### [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator/tree/08c561b8292b4a5de3d5bc553a3e463b1f93ec0c) * [OCPBUGS-20827](https://issues.redhat.com/browse/OCPBUGS-20827): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#88](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/88) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#80](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/80) * [Full changelog](https://github.com/openshift/gcp-pd-csi-driver-operator/compare/95d55a043a60b584a9fe28d37825761282305840...08c561b8292b4a5de3d5bc553a3e463b1f93ec0c) ### [haproxy-router](https://github.com/openshift/router/tree/85bc0d9ce7d4f6caabfdb17fcc917e04ae628f56) * [OCPBUGS-86710](https://issues.redhat.com/browse/OCPBUGS-86710): Strip X-SSL-* headers for plain HTTP [#808](https://github.com/openshift/router/pull/808) * [OCPBUGS-74945](https://issues.redhat.com/browse/OCPBUGS-74945): Adding escapeHAProxySingleQuotes for sanitize [release-4.13] [#783](https://github.com/openshift/router/pull/783) * [OCPBUGS-78109](https://issues.redhat.com/browse/OCPBUGS-78109): [release-4.13] hermetic 4.13 [#743](https://github.com/openshift/router/pull/743) * [OCPBUGS-43095](https://issues.redhat.com/browse/OCPBUGS-43095): add duplicate_te_header_total metric [#626](https://github.com/openshift/router/pull/626) * [OCPBUGS-34673](https://issues.redhat.com/browse/OCPBUGS-34673): Properly handle rewrite-target annotation [#608](https://github.com/openshift/router/pull/608) * [OCPBUGS-33911](https://issues.redhat.com/browse/OCPBUGS-33911): Reject routes with MD5 certs [#600](https://github.com/openshift/router/pull/600) * [OCPBUGS-33448](https://issues.redhat.com/browse/OCPBUGS-33448): Count active services before setting weight to 1 [#594](https://github.com/openshift/router/pull/594) * [OCPBUGS-33280](https://issues.redhat.com/browse/OCPBUGS-33280): Route 'haproxy.router.openshift.io/timeout' value is not validated [#591](https://github.com/openshift/router/pull/591) * [OCPBUGS-21117](https://issues.redhat.com/browse/OCPBUGS-21117): Bump golang.org/x/net to v0.17.0 to address CVE-2023-39325 [#531](https://github.com/openshift/router/pull/531) * [OCPBUGS-17762](https://issues.redhat.com/browse/OCPBUGS-17762): haproxy/template: mitigate CVE-2023-40225 [#506](https://github.com/openshift/router/pull/506) * [OCPBUGS-17107](https://issues.redhat.com/browse/OCPBUGS-17107): properly handle weight=0 [#501](https://github.com/openshift/router/pull/501) * [OCPBUGS-13964](https://issues.redhat.com/browse/OCPBUGS-13964), [OCPBUGS-13967](https://issues.redhat.com/browse/OCPBUGS-13967): Handle mTLS CRLs, and fix accidental CRL duplication [#485](https://github.com/openshift/router/pull/485) * [OCPBUGS-10519](https://issues.redhat.com/browse/OCPBUGS-10519): Revert "NE-1115: Update haproxy container builds to use haproxy 2.6" [#461](https://github.com/openshift/router/pull/461) * [Full changelog](https://github.com/openshift/router/compare/20c72c83cc4ba4e2250e0de58709d100898aeb7b...85bc0d9ce7d4f6caabfdb17fcc917e04ae628f56) ### [hyperkube, pod](https://github.com/openshift/kubernetes/tree/bbc7c0c199f92a78a858a36e78998abea5f36bef) * [OCPBUGS-77660](https://issues.redhat.com/browse/OCPBUGS-77660): Skip E2e: attach on previously attached volumes should work [#2606](https://github.com/openshift/kubernetes/pull/2606) * [OCPBUGS-67556](https://issues.redhat.com/browse/OCPBUGS-67556), [OCPBUGS-67652](https://issues.redhat.com/browse/OCPBUGS-67652): CVE-2025-65637 - bump github.com/sirupsen/logrus to v1.9.3 [4.13] [#2626](https://github.com/openshift/kubernetes/pull/2626) * [OCPBUGS-77800](https://issues.redhat.com/browse/OCPBUGS-77800): UPSTREAM: 133262: Remove permafailing tests using an expired GCP project [#2611](https://github.com/openshift/kubernetes/pull/2611) * [OCPBUGS-41678](https://issues.redhat.com/browse/OCPBUGS-41678): mount-utils: treat syscall.ENODEV as corrupted mount [#2083](https://github.com/openshift/kubernetes/pull/2083) * [OCPBUGS-37280](https://issues.redhat.com/browse/OCPBUGS-37280): UPSTREAM: 126104: Add funcs in pkg/filesystem/util that can actually … [#2045](https://github.com/openshift/kubernetes/pull/2045) * [OCPBUGS-28660](https://issues.redhat.com/browse/OCPBUGS-28660): UPSTREAM: <carry>: kubelet/cm: use MkdirAll when creating cpuset to ignore file exists error [#1875](https://github.com/openshift/kubernetes/pull/1875) * UPSTREAM: <drop>: Bump golang.org/x/net to v0.23.0 [#1938](https://github.com/openshift/kubernetes/pull/1938) * [OCPBUGS-31505](https://issues.redhat.com/browse/OCPBUGS-31505): Update to kubernetes 1.26.15 [#1930](https://github.com/openshift/kubernetes/pull/1930) * Address CVE [#14](https://github.com/openshift/kubernetes/pull/14) * [OCPBUGS-29663](https://issues.redhat.com/browse/OCPBUGS-29663): Update to kubernetes 1.26.14 [#1889](https://github.com/openshift/kubernetes/pull/1889) * [OCPBUGS-12210](https://issues.redhat.com/browse/OCPBUGS-12210): Prevent partially filled HPA behaviors from crashing kube-controller-manager [#1876](https://github.com/openshift/kubernetes/pull/1876) * [OCPBUGS-27370](https://issues.redhat.com/browse/OCPBUGS-27370): Update to kubernetes 1.26.13 [#1859](https://github.com/openshift/kubernetes/pull/1859) * [OCPBUGS-25814](https://issues.redhat.com/browse/OCPBUGS-25814): Fix device uncertain errors on reboot - 4.13 [#1831](https://github.com/openshift/kubernetes/pull/1831) * [OCPBUGS-25988](https://issues.redhat.com/browse/OCPBUGS-25988): Update to kubernetes 1.26.12 [#1839](https://github.com/openshift/kubernetes/pull/1839) * [OCPBUGS-25767](https://issues.redhat.com/browse/OCPBUGS-25767): legacy-cloud-providers: prevent index out-of-range in getNextUnitNumber [#1834](https://github.com/openshift/kubernetes/pull/1834) * [OCPBUGS-23521](https://issues.redhat.com/browse/OCPBUGS-23521): UPSTREAM: <carry>: support for both icsp and idms objects [#1798](https://github.com/openshift/kubernetes/pull/1798) * [OCPBUGS-23567](https://issues.redhat.com/browse/OCPBUGS-23567): Update to kubernetes 1.26.11 [#1809](https://github.com/openshift/kubernetes/pull/1809) * [OCPBUGS-18829](https://issues.redhat.com/browse/OCPBUGS-18829): cm: reorder setting of sched_load_balance for sandbox slice [#1696](https://github.com/openshift/kubernetes/pull/1696) * [OCPBUGS-23287](https://issues.redhat.com/browse/OCPBUGS-23287): UPSTREAM: 121881: Use golang library instead of mklink [#1802](https://github.com/openshift/kubernetes/pull/1802) * openshift-hack: Fix sporadic 141 errors in build-rpms [#1773](https://github.com/openshift/kubernetes/pull/1773) * [OCPBUGS-20114](https://issues.redhat.com/browse/OCPBUGS-20114): UPSTREAM: <carry>: Do not allow nodes to set forbidden openshift labels [#1746](https://github.com/openshift/kubernetes/pull/1746) * [OCPBUGS-21063](https://issues.redhat.com/browse/OCPBUGS-21063): [release-4.13] UPSTREAM: 121126: [1.26][CVE-2023-39325] .: bump golang.org/x/net to v0.17.0 [#1759](https://github.com/openshift/kubernetes/pull/1759) * [OCPBUGS-19885](https://issues.redhat.com/browse/OCPBUGS-19885): UPSTREAM: 120789: change rolling update logic to exclude sunsetting nodes [#1725](https://github.com/openshift/kubernetes/pull/1725) * [OCPBUGS-18287](https://issues.redhat.com/browse/OCPBUGS-18287), [OCPBUGS-19480](https://issues.redhat.com/browse/OCPBUGS-19480): Update to Kubernetes 1.26.9 [#1715](https://github.com/openshift/kubernetes/pull/1715) * [OCPBUGS-18677](https://issues.redhat.com/browse/OCPBUGS-18677): UPSTREAM: <carry>: Force using host go always and use host libriaries [#1689](https://github.com/openshift/kubernetes/pull/1689) * [OCPBUGS-17187](https://issues.redhat.com/browse/OCPBUGS-17187): Update to Kubernetes 1.26.7 [#1649](https://github.com/openshift/kubernetes/pull/1649) * [OCPBUGS-17145](https://issues.redhat.com/browse/OCPBUGS-17145): Increase service idle max timeout to 100 minutes [#1657](https://github.com/openshift/kubernetes/pull/1657) * [OCPBUGS-15866](https://issues.redhat.com/browse/OCPBUGS-15866): remove readiness check for cache exclusion [#1625](https://github.com/openshift/kubernetes/pull/1625) * [OCPBUGS-15866](https://issues.redhat.com/browse/OCPBUGS-15866): UPSTREAM: <drop>: hack/update-vendor.sh [#1637](https://github.com/openshift/kubernetes/pull/1637) * [OCPBUGS-15246](https://issues.redhat.com/browse/OCPBUGS-15246): Bump to k8s 1.26.6 [#1610](https://github.com/openshift/kubernetes/pull/1610) * [OCPBUGS-8738](https://issues.redhat.com/browse/OCPBUGS-8738): bump apiserver-lib-go [#1611](https://github.com/openshift/kubernetes/pull/1611) * [OCPBUGS-14589](https://issues.redhat.com/browse/OCPBUGS-14589): [release-4.13] UPSTREAM: 118383: bump cadvisor for upstream patch 3301 [#1596](https://github.com/openshift/kubernetes/pull/1596) * [OCPBUGS-13747](https://issues.redhat.com/browse/OCPBUGS-13747): 4.13: kubelet/cm: disable cpu load balancing on slices when using static cpu manager policy [#1580](https://github.com/openshift/kubernetes/pull/1580) * [OCPBUGS-14048](https://issues.redhat.com/browse/OCPBUGS-14048): Bump to k8s 1.26.5 [#1586](https://github.com/openshift/kubernetes/pull/1586) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): Enable CSI migration configuration via env vars [#1514](https://github.com/openshift/kubernetes/pull/1514) * [OCPBUGS-11823](https://issues.redhat.com/browse/OCPBUGS-11823): UPSTREAM: 117311: kube-aggregator: correctly use client-go TLS cache with custom dialer [#1549](https://github.com/openshift/kubernetes/pull/1549) * [OCPBUGS-7268](https://issues.redhat.com/browse/OCPBUGS-7268): Extractor more fixes 4.13 [#1544](https://github.com/openshift/kubernetes/pull/1544) * UPSTREAM: <carry>: OCPNODE-1548,OCPNODE-1584: disable load balancing on created cgroups when managed is enabled [#1543](https://github.com/openshift/kubernetes/pull/1543) * [OCPBUGS-11669](https://issues.redhat.com/browse/OCPBUGS-11669): Bump to k8s 1.26.3 [#1540](https://github.com/openshift/kubernetes/pull/1540) * [OCPBUGS-10432](https://issues.redhat.com/browse/OCPBUGS-10432): CSI Inline Volume admission plugin does not log object name correctly [#1515](https://github.com/openshift/kubernetes/pull/1515) * [OCPBUGS-6201](https://issues.redhat.com/browse/OCPBUGS-6201): Updating openshift-enterprise-pod images to be consistent with ART [#1435](https://github.com/openshift/kubernetes/pull/1435) * [OCPBUGS-7359](https://issues.redhat.com/browse/OCPBUGS-7359): Azure: move to kube-proxy LB probes, don't detach masters when unready [#1506](https://github.com/openshift/kubernetes/pull/1506) * [OCPBUGS-10515](https://issues.redhat.com/browse/OCPBUGS-10515): UPSTREAM: 115328: apiserver: annotate early (server not ready) and late (during shutdown) requests [#1517](https://github.com/openshift/kubernetes/pull/1517) * [OCPBUGS-8412](https://issues.redhat.com/browse/OCPBUGS-8412): Fix mounted volume expansion tests [#1502](https://github.com/openshift/kubernetes/pull/1502) * [OCPBUGS-8308](https://issues.redhat.com/browse/OCPBUGS-8308): Bump to k8s 1.26.2 [#1495](https://github.com/openshift/kubernetes/pull/1495) * [Full changelog](https://github.com/openshift/kubernetes/compare/288be6b27cc18fa1d0d547dea2f02ac89c0a425b...bbc7c0c199f92a78a858a36e78998abea5f36bef) ### [hypershift](https://github.com/openshift/hypershift/tree/bc2d7cdad75b7c36aa5c19fa979ec965483185a0) * [OCPBUGS-77756](https://issues.redhat.com/browse/OCPBUGS-77756): fix vendor for hermetic 4.13 [#7822](https://github.com/openshift/hypershift/pull/7822) * [OCPBUGS-53901](https://issues.redhat.com/browse/OCPBUGS-53901): bump golang-jwt v4 [#5948](https://github.com/openshift/hypershift/pull/5948) * [OCPBUGS-39184](https://issues.redhat.com/browse/OCPBUGS-39184): fix: bump github.com/IBM/go-sdk-core/v5 [#4627](https://github.com/openshift/hypershift/pull/4627) * [OCPBUGS-41515](https://issues.redhat.com/browse/OCPBUGS-41515): set Konnectivity cipher suites [#4284](https://github.com/openshift/hypershift/pull/4284) * NO-JIRA: hack: make the e2e script generic [#4202](https://github.com/openshift/hypershift/pull/4202) * [HOSTEDCP-1146](https://issues.redhat.com/browse/HOSTEDCP-1146): cpo: use CPO spec container image if it is a sha256 reference [#3296](https://github.com/openshift/hypershift/pull/3296) * [OCPBUGS-22971](https://issues.redhat.com/browse/OCPBUGS-22971): Add konnectivity-proxy container to CNO [#3167](https://github.com/openshift/hypershift/pull/3167) * [OCPBUGS-23455](https://issues.redhat.com/browse/OCPBUGS-23455): Use the same etcd snapshot for all replicas during etcd restore [#3205](https://github.com/openshift/hypershift/pull/3205) * NO-JIRA: Red Hat Trusted App Pipeline purge hypershift-operator-release-413 [#3217](https://github.com/openshift/hypershift/pull/3217) * chore(deps): update rhtap references (release-4.13) [#3043](https://github.com/openshift/hypershift/pull/3043) * Update RHTAP references (release-4.13) [#2996](https://github.com/openshift/hypershift/pull/2996) * [OCPBUGS-17182](https://issues.redhat.com/browse/OCPBUGS-17182): add need-management-kas-access label to olm-collect-profiles pods [#2871](https://github.com/openshift/hypershift/pull/2871) * [OCPBUGS-16225](https://issues.redhat.com/browse/OCPBUGS-16225): Add missing probes to two services [#2821](https://github.com/openshift/hypershift/pull/2821) * fix(olm): Use 4.13 catalog source images [#2978](https://github.com/openshift/hypershift/pull/2978) * Updated secret permissions for openshift-route-controller-manager [#2923](https://github.com/openshift/hypershift/pull/2923) * [HOSTEDCP-1121](https://issues.redhat.com/browse/HOSTEDCP-1121): Ensure SG reconciliation for aws endpoint [#2885](https://github.com/openshift/hypershift/pull/2885) * chore(deps): update rhtap references (release-4.13) [#2921](https://github.com/openshift/hypershift/pull/2921) * Revert "HOSTEDCP-1110: [backport-4.13] Allow HCP Specification to Support ICSP & IDMS" [#2931](https://github.com/openshift/hypershift/pull/2931) * chore(deps): update rhtap references (release-4.13) [#2904](https://github.com/openshift/hypershift/pull/2904) * Update RHTAP references (release-4.13) [#2866](https://github.com/openshift/hypershift/pull/2866) * [HOSTEDCP-1046](https://issues.redhat.com/browse/HOSTEDCP-1046): Add ImageDigestMirrorSet to Config API comment [#2870](https://github.com/openshift/hypershift/pull/2870) * [HOSTEDCP-1046](https://issues.redhat.com/browse/HOSTEDCP-1046): Add IDMS to the list of valid config manifests [#2863](https://github.com/openshift/hypershift/pull/2863) * Update RHTAP references (release-4.13) [#2833](https://github.com/openshift/hypershift/pull/2833) * [HOSTEDCP-1110](https://issues.redhat.com/browse/HOSTEDCP-1110): [backport-4.13] Allow HCP Specification to Support ICSP & IDMS [#2839](https://github.com/openshift/hypershift/pull/2839) * [OCPBUGS-15743](https://issues.redhat.com/browse/OCPBUGS-15743): Let getMachinesForNodePool return machines ordered by creation Timestamp [#2767](https://github.com/openshift/hypershift/pull/2767) * 4.13: Add management cluster KAS network policy [#2786](https://github.com/openshift/hypershift/pull/2786) * Leader election config update. [#2801](https://github.com/openshift/hypershift/pull/2801) * [OCPBUGS-16160](https://issues.redhat.com/browse/OCPBUGS-16160): fix deletion bug when hostedzone is already deleted [#2813](https://github.com/openshift/hypershift/pull/2813) * [HOSTEDCP-1061](https://issues.redhat.com/browse/HOSTEDCP-1061): [release-4.13] Implement dedicated request serving nodes for HostedClusters [#2809](https://github.com/openshift/hypershift/pull/2809) * Update RHTAP references (release-4.13) [#2816](https://github.com/openshift/hypershift/pull/2816) * [OCPBUGS-16057](https://issues.redhat.com/browse/OCPBUGS-16057): use ignition-proxy Service to populate ignitionEndpoint with strategy NodePort [#2798](https://github.com/openshift/hypershift/pull/2798) * OCPBUGS-14862 Improve clarity around hypershift operator permissions [#2810](https://github.com/openshift/hypershift/pull/2810) * [HOSTEDCP-1101](https://issues.redhat.com/browse/HOSTEDCP-1101): Add snyk-secret HO RHTAP scripts [#2799](https://github.com/openshift/hypershift/pull/2799) * [OCPBUGS-16125](https://issues.redhat.com/browse/OCPBUGS-16125): [release-4.13] Update vendored dependencies [#2797](https://github.com/openshift/hypershift/pull/2797) * [OCPBUGS-15774](https://issues.redhat.com/browse/OCPBUGS-15774): autoscaling balance similar groups [#2805](https://github.com/openshift/hypershift/pull/2805) * [OCPBUGS-15965](https://issues.redhat.com/browse/OCPBUGS-15965): Reject VPCE Connections during VPCE Service cleanup [#2789](https://github.com/openshift/hypershift/pull/2789) * Update RHTAP references (release-4.13) [#2751](https://github.com/openshift/hypershift/pull/2751) * [OCPBUGS-15171](https://issues.redhat.com/browse/OCPBUGS-15171): Skip AWS resource deletion for 'Unknown' OIDC state [#2701](https://github.com/openshift/hypershift/pull/2701) * [HOSTEDCP-1008](https://issues.redhat.com/browse/HOSTEDCP-1008): Add NodePoolTransitionSeconds metric [#2758](https://github.com/openshift/hypershift/pull/2758) * [OCPBUGS-15281](https://issues.redhat.com/browse/OCPBUGS-15281): Check OwningIngressController also in Labels [#2715](https://github.com/openshift/hypershift/pull/2715) * [HOSTEDCP-1060](https://issues.redhat.com/browse/HOSTEDCP-1060): refactor ignition-server reconcilation and add ignition-server proxy [#2748](https://github.com/openshift/hypershift/pull/2748) * [HOSTEDCP-1073](https://issues.redhat.com/browse/HOSTEDCP-1073): enforce blocked rollout of HCP [#2735](https://github.com/openshift/hypershift/pull/2735) * [HOSTEDCP-1003](https://issues.redhat.com/browse/HOSTEDCP-1003): Set AWS conditions only for AWS platform [#2670](https://github.com/openshift/hypershift/pull/2670) * OCPBUGS-15268 properly handle user CA bundle not existing [#2710](https://github.com/openshift/hypershift/pull/2710) * [OCPBUGS-15301](https://issues.redhat.com/browse/OCPBUGS-15301): [release-4.13] fix(oauth): Do not proxy IBM Cloud IAM endpoints [#2696](https://github.com/openshift/hypershift/pull/2696) * [OCPBUGS-14030](https://issues.redhat.com/browse/OCPBUGS-14030): Include default ingress CA in root CA bundle [#2599](https://github.com/openshift/hypershift/pull/2599) * [OCPBUGS-14490](https://issues.redhat.com/browse/OCPBUGS-14490): Enable HCCO to reconcile over the OperatorHub's disableAllDefaultSources object [#2645](https://github.com/openshift/hypershift/pull/2645) * [OCPBUGS-14801](https://issues.redhat.com/browse/OCPBUGS-14801): Set `DisableStrictZoneCheck = true` in the AWS Cloud Provider config [#2666](https://github.com/openshift/hypershift/pull/2666) * [HOSTEDCP-1048](https://issues.redhat.com/browse/HOSTEDCP-1048): Add impersonate feature to the CLI and document HC dump procedure [#2681](https://github.com/openshift/hypershift/pull/2681) * [OCPBUGS-14872](https://issues.redhat.com/browse/OCPBUGS-14872): Honor global ingress configuration LoadBalancer type on AWS [#2677](https://github.com/openshift/hypershift/pull/2677) * [OCPBUGS-14436](https://issues.redhat.com/browse/OCPBUGS-14436): Add ClusterUpgradeDuration metric [#2637](https://github.com/openshift/hypershift/pull/2637) * [HOSTEDCP-1009](https://issues.redhat.com/browse/HOSTEDCP-1009): Allow external-dns image to be set in install cli [#2652](https://github.com/openshift/hypershift/pull/2652) * Red Hat Trusted App Pipeline update hypershift-operator-release-413 [#2641](https://github.com/openshift/hypershift/pull/2641) * Red Hat Trusted App Pipeline purge hypershift [#2640](https://github.com/openshift/hypershift/pull/2640) * [OCPBUGS-13735](https://issues.redhat.com/browse/OCPBUGS-13735): Cluster-api SA can't create events and fix permissions wrongly included [#2610](https://github.com/openshift/hypershift/pull/2610) * [OCPBUGS-14242](https://issues.redhat.com/browse/OCPBUGS-14242): Remove external-dns --events flag [#2621](https://github.com/openshift/hypershift/pull/2621) * [OCPBUGS-14155](https://issues.redhat.com/browse/OCPBUGS-14155): Reconcile oauthDeployment annotations even if kubeadmin secret is not found [#2613](https://github.com/openshift/hypershift/pull/2613) * [OCPBUGS-13399](https://issues.redhat.com/browse/OCPBUGS-13399): Fix errors from HCP controller removeServiceCAAnnotationAndSecret() [#2552](https://github.com/openshift/hypershift/pull/2552) * [HOSTEDCP-1010](https://issues.redhat.com/browse/HOSTEDCP-1010): Set ETCD Storage Size as immutable field and equalised the default size among both api versions [#2611](https://github.com/openshift/hypershift/pull/2611) * [HOSTEDCP-947](https://issues.redhat.com/browse/HOSTEDCP-947): Increases default etcd PV size to 8Gi [#2569](https://github.com/openshift/hypershift/pull/2569) * [HOSTEDCP-926](https://issues.redhat.com/browse/HOSTEDCP-926): Send metric when HO/CPO decide to skip cloud resource deletion [#2594](https://github.com/openshift/hypershift/pull/2594) * [HOSTEDCP-975](https://issues.redhat.com/browse/HOSTEDCP-975): Backport nodepools metrics [#2601](https://github.com/openshift/hypershift/pull/2601) * Red Hat Trusted App Pipeline update hypershift [#2603](https://github.com/openshift/hypershift/pull/2603) * [OCPBUGS-13594](https://issues.redhat.com/browse/OCPBUGS-13594): Sync proxy TrustedCA to guest cluster [#2556](https://github.com/openshift/hypershift/pull/2556) * fix nil deref in DefaultWorkerSecurityGroupID check [#2574](https://github.com/openshift/hypershift/pull/2574) * [OCPBUGS-13215](https://issues.redhat.com/browse/OCPBUGS-13215): Let the aws endpoint to use the hypershift owned SG [#2529](https://github.com/openshift/hypershift/pull/2529) * [OCPBUGS-13497](https://issues.redhat.com/browse/OCPBUGS-13497): Add internal/external elb tags to subnets [#2553](https://github.com/openshift/hypershift/pull/2553) * [OCPBUGS-13531](https://issues.redhat.com/browse/OCPBUGS-13531): Clean up existing VPC endpoint connections [#2554](https://github.com/openshift/hypershift/pull/2554) * Stop triggering rollout on labels/taint change [#2548](https://github.com/openshift/hypershift/pull/2548) * Fixes HCCO reconcile error for kubevirt csi driver [#2538](https://github.com/openshift/hypershift/pull/2538) * Fix kubevirt csi daemonset reconcile loop [#2542](https://github.com/openshift/hypershift/pull/2542) * [HOSTEDCP-980](https://issues.redhat.com/browse/HOSTEDCP-980): Include HostedClusterDegraded in hypershift_hostedclusters_failure_conditions metric [#2525](https://github.com/openshift/hypershift/pull/2525) * Bug HOSTEDCP-788: [release-4.13] Configurable SRE MetricsSet [#2544](https://github.com/openshift/hypershift/pull/2544) * ACM-5173 [backport 4.13] get pull secret instead of dockerconfigjson from mce credentials [#2487](https://github.com/openshift/hypershift/pull/2487) * [OCPBUGS-13085](https://issues.redhat.com/browse/OCPBUGS-13085): Account for expectedState == false when capturing hostedClustersWithFailureCondition [#2516](https://github.com/openshift/hypershift/pull/2516) * [OCPBUGS-13076](https://issues.redhat.com/browse/OCPBUGS-13076): Ensure ingress controllers are removed before load balancers [#2514](https://github.com/openshift/hypershift/pull/2514) * [HOSTEDCP-937](https://issues.redhat.com/browse/HOSTEDCP-937): Add new metric to expose hypershift operator info [#2499](https://github.com/openshift/hypershift/pull/2499) * Fixed assignment to entry in nil map [#2510](https://github.com/openshift/hypershift/pull/2510) * [OCPBUGS-12786](https://issues.redhat.com/browse/OCPBUGS-12786): fix(hcco): Get OLM CatalogSource images from defined map [#2484](https://github.com/openshift/hypershift/pull/2484) * add hyperv1.SilenceClusterAlertsLabel to HostedCluster on deletion [#2480](https://github.com/openshift/hypershift/pull/2480) * [OCPBUGS-12844](https://issues.redhat.com/browse/OCPBUGS-12844): Delete kubeadmin secret when an idp is defined [#2491](https://github.com/openshift/hypershift/pull/2491) * [HOSTEDCP-917](https://issues.redhat.com/browse/HOSTEDCP-917): Add publicAndPrivate <-> Private e2e test [#2490](https://github.com/openshift/hypershift/pull/2490) * [OCPBUGS-12689](https://issues.redhat.com/browse/OCPBUGS-12689): hosted clusters default KAS PDA config should be consistent with OCP [#2496](https://github.com/openshift/hypershift/pull/2496) * [HOSTEDCP-969](https://issues.redhat.com/browse/HOSTEDCP-969): Consolidate labels for metrics [#2497](https://github.com/openshift/hypershift/pull/2497) * [HOSTEDCP-969](https://issues.redhat.com/browse/HOSTEDCP-969): Move metrics [#2495](https://github.com/openshift/hypershift/pull/2495) * [OCPBUGS-12737](https://issues.redhat.com/browse/OCPBUGS-12737): Pass OPENSHIFT_RELEASE_IMAGE env variable to CNO [#2472](https://github.com/openshift/hypershift/pull/2472) * [OCPBUGS-12225](https://issues.redhat.com/browse/OCPBUGS-12225): Add new OCP 4.13 storage admission plugin [#2462](https://github.com/openshift/hypershift/pull/2462) * [OCPBUGS-12198](https://issues.redhat.com/browse/OCPBUGS-12198): remove ACL for aws bucket [#2457](https://github.com/openshift/hypershift/pull/2457) * kubevirt: Block metadata server egress [#2439](https://github.com/openshift/hypershift/pull/2439) * [HOSTEDCP-638](https://issues.redhat.com/browse/HOSTEDCP-638): Add latest ocp supported info to -v command for cli and operator [#2447](https://github.com/openshift/hypershift/pull/2447) * add pull-secret to imagePullSecrets for NTO, CNO, and olm-collect-profiles [#2432](https://github.com/openshift/hypershift/pull/2432) * e2e: Cleanup shared OIDC provider on SIGTERM [#2448](https://github.com/openshift/hypershift/pull/2448) * [OCPBUGS-11842](https://issues.redhat.com/browse/OCPBUGS-11842): allow z-stream upgrade even if CVO Upgradeable is false [#2431](https://github.com/openshift/hypershift/pull/2431) * Relax MCO API strict decoding [#2442](https://github.com/openshift/hypershift/pull/2442) * Enable monitoring for hypershift & HCP namespace [#2429](https://github.com/openshift/hypershift/pull/2429) * [OCPBUGS-11545](https://issues.redhat.com/browse/OCPBUGS-11545): Pass runAsUser to CNO so it can run its managed services with proper security context [#2392](https://github.com/openshift/hypershift/pull/2392) * [OCPBUGS-10422](https://issues.redhat.com/browse/OCPBUGS-10422): Create new EC2 client for AWS identity provider health check [#2402](https://github.com/openshift/hypershift/pull/2402) * [OCPBUGS-10995](https://issues.redhat.com/browse/OCPBUGS-10995): Honor scheduler profile in HostedCluster configuration [#2337](https://github.com/openshift/hypershift/pull/2337) * [OCPBUGS-11725](https://issues.redhat.com/browse/OCPBUGS-11725): Update HostedCluster oauthCallbackURLTemplate [#2409](https://github.com/openshift/hypershift/pull/2409) * [HOSTEDCP-568](https://issues.redhat.com/browse/HOSTEDCP-568): Update Konnectiviy socks5 proxy for IBM exception [#2404](https://github.com/openshift/hypershift/pull/2404) * bug OCPBUGS-10422: Preserve false status of ValidAWSIdentityProvider condition [#2401](https://github.com/openshift/hypershift/pull/2401) * [HOSTEDCP-802](https://issues.redhat.com/browse/HOSTEDCP-802): add cli flag to enable upgrade type [#2388](https://github.com/openshift/hypershift/pull/2388) * [OCPBUGS-11606](https://issues.redhat.com/browse/OCPBUGS-11606): properly reconcile with user specified changes for in proxy configuration [#2394](https://github.com/openshift/hypershift/pull/2394) * Let install apply to aggregate errors [#2375](https://github.com/openshift/hypershift/pull/2375) * Revert "Create a second scheme that always registers prometheusoperatorv1 GVKs [#2376](https://github.com/openshift/hypershift/pull/2376) * [HOSTEDCP-939](https://issues.redhat.com/browse/HOSTEDCP-939): [release-4.13] Setup shared OIDC provider for e2e clusters [#2364](https://github.com/openshift/hypershift/pull/2364) * [OCPBUGS-10422](https://issues.redhat.com/browse/OCPBUGS-10422): Ensure identity provider health check condition is persisted and remove awsendpoint control plane finalizer if invalid aws creds [#2283](https://github.com/openshift/hypershift/pull/2283) * [HOSTEDCP-850](https://issues.redhat.com/browse/HOSTEDCP-850): Fix nodepool autoscaler logic [#2363](https://github.com/openshift/hypershift/pull/2363) * [HOSTEDCP-806](https://issues.redhat.com/browse/HOSTEDCP-806): Fix ValidAWSKMSConfig condition [#2361](https://github.com/openshift/hypershift/pull/2361) * [OCPBUGS-10867](https://issues.redhat.com/browse/OCPBUGS-10867): Switch NTO metrics auth to certs generated by HCP controller [#2331](https://github.com/openshift/hypershift/pull/2331) * OCPBUGS-10823 ensure well known public domains do not get proxied on image imports [#2353](https://github.com/openshift/hypershift/pull/2353) * [OCPBUGS-10645](https://issues.redhat.com/browse/OCPBUGS-10645): Add storage operators perms. to watch HostedControlPlane [#2305](https://github.com/openshift/hypershift/pull/2305) * [SDA-8706](https://issues.redhat.com/browse/SDA-8706): No more specifying the scrape interval at servicemonitors & podmonitors level [#2355](https://github.com/openshift/hypershift/pull/2355) * [OCPBUGS-11013](https://issues.redhat.com/browse/OCPBUGS-11013): Do not proxy when guest cluster resolution fails [#2339](https://github.com/openshift/hypershift/pull/2339) * [OCPBUGS-11055](https://issues.redhat.com/browse/OCPBUGS-11055): fix external APIServer address selection based on endpointAccess [#2349](https://github.com/openshift/hypershift/pull/2349) * [HOSTEDCP-934](https://issues.redhat.com/browse/HOSTEDCP-934): [release-4.13] Validate PublishingStrategyMapping [#2343](https://github.com/openshift/hypershift/pull/2343) * [HOSTEDCP-900](https://issues.redhat.com/browse/HOSTEDCP-900): Modified AWSPrivateLinkController and AWSEndpointServiceController to respect PausedUntil spec field [#2284](https://github.com/openshift/hypershift/pull/2284) * [HOSTEDCP-903](https://issues.redhat.com/browse/HOSTEDCP-903): Propagate AWSEndpointService conditions [#2307](https://github.com/openshift/hypershift/pull/2307) * [OCPBUGS-10792](https://issues.redhat.com/browse/OCPBUGS-10792): [release-4.13] Create a second scheme that always registers `prometheusoperatorv1` GVKs [#2312](https://github.com/openshift/hypershift/pull/2312) * [HOSTEDCP-801](https://issues.redhat.com/browse/HOSTEDCP-801): [release-4.13] Expose external DNS for private cluster endpoints [#2313](https://github.com/openshift/hypershift/pull/2313) * Update HCP version in capi cluster ref [#2266](https://github.com/openshift/hypershift/pull/2266) * [OCPBUGS-10504](https://issues.redhat.com/browse/OCPBUGS-10504): Deletion of the VPCEnpoint on conflicting service names [#2309](https://github.com/openshift/hypershift/pull/2309) * [HOSTEDCP-839](https://issues.redhat.com/browse/HOSTEDCP-839): Audit log sidecars for openshift-apiserver and openshift-oauth-apiserver [#2296](https://github.com/openshift/hypershift/pull/2296) * [OCPBUGS-10586](https://issues.redhat.com/browse/OCPBUGS-10586): Use appropriate serving certificate for OAuth [#2294](https://github.com/openshift/hypershift/pull/2294) * Validate etcd KMS config [#2260](https://github.com/openshift/hypershift/pull/2260) * Force controleplane upgrade always [#2291](https://github.com/openshift/hypershift/pull/2291) * Disable inplace upgrade e2e tests [#2303](https://github.com/openshift/hypershift/pull/2303) * [HOSTEDCP-809](https://issues.redhat.com/browse/HOSTEDCP-809): Clone CA key/cert to TLS key/cert [#2262](https://github.com/openshift/hypershift/pull/2262) * [OCPBUGS-8369](https://issues.redhat.com/browse/OCPBUGS-8369): Fix cleanup of volumes on cluster deletion [#2252](https://github.com/openshift/hypershift/pull/2252) * [Full changelog](https://github.com/openshift/hypershift/compare/fc3b4919f8f931d1b1955ed2e81f90f50eac0815...bc2d7cdad75b7c36aa5c19fa979ec965483185a0) ### [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm/tree/b5bcaf9caa96561a32ec5e7b79ca41e173ecfe25) * [OCPBUGS-24999](https://issues.redhat.com/browse/OCPBUGS-24999): Add Snyk file to exclude vendor directory on scan [#66](https://github.com/openshift/cloud-provider-ibm/pull/66) * [OCPBUGS-21137](https://issues.redhat.com/browse/OCPBUGS-21137): Bump golang.org/x/net to v0.18.0 [#56](https://github.com/openshift/cloud-provider-ibm/pull/56) * [OCPBUGS-12612](https://issues.redhat.com/browse/OCPBUGS-12612): Update x/net to v0.7.0 [#52](https://github.com/openshift/cloud-provider-ibm/pull/52) * [Full changelog](https://github.com/openshift/cloud-provider-ibm/compare/f39488c53ab5151cebf11e8f82510a255a8005d3...b5bcaf9caa96561a32ec5e7b79ca41e173ecfe25) ### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/648d0cc72a42d3ab7f9e05a522ab11ba88e1203b) * [OCPBUGS-77213](https://issues.redhat.com/browse/OCPBUGS-77213): [release-4.13] standardize build paths [#127](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/127) * [OCPBUGS-59124](https://issues.redhat.com/browse/OCPBUGS-59124): bump github.com/golang/glog to v1.2.4 [#110](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/110) * [OCPBUGS-56066](https://issues.redhat.com/browse/OCPBUGS-56066): tech debt: rework vendor patches [#94](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/94) * [OCPBUGS-53909](https://issues.redhat.com/browse/OCPBUGS-53909): bump github.com/golang-jwt/jwt/v4 to v4.5.2 [#87](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/87) * [OCPBUGS-36064](https://issues.redhat.com/browse/OCPBUGS-36064): CVE-2024-6104: bump github.com/hashicorp/go-retryablehttp to v0.7.7 [#74](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/74) * [OCPBUGS-18143](https://issues.redhat.com/browse/OCPBUGS-18143): [IBM VPC] failed provisioning volume in proxy cluster [#47](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/47) * [OCPBUGS-21230](https://issues.redhat.com/browse/OCPBUGS-21230): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#51](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/51) * [OCPBUGS-16378](https://issues.redhat.com/browse/OCPBUGS-16378): 4.13: UPSTREAM: 157: K8S and grpc package upgrade [#40](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/40) * [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/b10d9f7edea77d69dd79729007d6fbd1e380f52d...648d0cc72a42d3ab7f9e05a522ab11ba88e1203b) ### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/30262c098a2124f8fb8ed334df7b4e48c75dbeaa) * [OCPBUGS-67656](https://issues.redhat.com/browse/OCPBUGS-67656), [OCPBUGS-67657](https://issues.redhat.com/browse/OCPBUGS-67657): bump github.com/sirupsen/logrus to v1.8.3 [#164](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/164) * [OCPBUGS-59874](https://issues.redhat.com/browse/OCPBUGS-59874): [IBM VPC] set offlineExpansion to false in e2e test manifest [#152](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/152) * [OCPBUGS-36070](https://issues.redhat.com/browse/OCPBUGS-36070): CVE-2024-6104: bump github.com/hashicorp/go-retryablehttp to v0.7.7 [#123](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/123) * [OCPBUGS-21319](https://issues.redhat.com/browse/OCPBUGS-21319): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#82](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/82) * [OCPBUGS-18143](https://issues.redhat.com/browse/OCPBUGS-18143): [IBM VPC] failed provisioning volume in proxy cluster [#76](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/76) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#73](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/73) * [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/a38b8d883fc282608c22d8e0dcde24aaa97de8bf...30262c098a2124f8fb8ed334df7b4e48c75dbeaa) ### [ibm-vpc-node-label-updater](https://github.com/openshift/ibm-vpc-node-label-updater/tree/6d619f62a27ba0ac0cab05e035f07aef9095d9c9) * [OCPBUGS-56066](https://issues.redhat.com/browse/OCPBUGS-56066): tech debt: rework vendor patches [#51](https://github.com/openshift/ibm-vpc-node-label-updater/pull/51) * [OCPBUGS-53541](https://issues.redhat.com/browse/OCPBUGS-53541): bump github.com/golang-jwt/jwt/v4 to v4.5.2 [#47](https://github.com/openshift/ibm-vpc-node-label-updater/pull/47) * [OCPBUGS-36010](https://issues.redhat.com/browse/OCPBUGS-36010): CVE-2024-6104: bump github.com/hashicorp/go-retryablehttp to v0.7.7 [#43](https://github.com/openshift/ibm-vpc-node-label-updater/pull/43) * [OCPBUGS-21432](https://issues.redhat.com/browse/OCPBUGS-21432): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#28](https://github.com/openshift/ibm-vpc-node-label-updater/pull/28) * [OCPBUGS-14073](https://issues.redhat.com/browse/OCPBUGS-14073): UPSTREAM: 20: Bump (golang.org/x/net): to address CVE-2022-41723 [#24](https://github.com/openshift/ibm-vpc-node-label-updater/pull/24) * [Full changelog](https://github.com/openshift/ibm-vpc-node-label-updater/compare/01349bbdf3c459146c5e58b0a96526a2ba78391c...6d619f62a27ba0ac0cab05e035f07aef9095d9c9) ### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/4faedb550f51dcbce19dc6bf2cdb0e89fdb691d6) * [OCPBUGS-67291](https://issues.redhat.com/browse/OCPBUGS-67291): [release-4.13] Fix incomplete vendor/ [#135](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/135) * [OCPBUGS-36076](https://issues.redhat.com/browse/OCPBUGS-36076): UPSTREAM: <carry>: Fix go-retryablehttp CVE - 4.13 [#90](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/90) * [OCPBUGS-21418](https://issues.redhat.com/browse/OCPBUGS-21418): UPSTREAM: <carry>: bump golang.org/x/net to v0.18.0 [#66](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/66) * [OCPBUGS-12615](https://issues.redhat.com/browse/OCPBUGS-12615): Update IBM Packages [#55](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/55) * [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/b69846edfe7bb171f60229dc7a7b43ea64513644...4faedb550f51dcbce19dc6bf2cdb0e89fdb691d6) ### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/a6c7dcd9ed993e2ebf7272ff52cfa71cc7be856b) * [OCPBUGS-78275](https://issues.redhat.com/browse/OCPBUGS-78275): hermetic 4.13 [#78](https://github.com/openshift/machine-api-provider-ibmcloud/pull/78) * [OCPBUGS-36082](https://issues.redhat.com/browse/OCPBUGS-36082): Bump dependency for CVE [#56](https://github.com/openshift/machine-api-provider-ibmcloud/pull/56) * [OCPBUGS-12616](https://issues.redhat.com/browse/OCPBUGS-12616): Bump x/net to v0.7.0 [#23](https://github.com/openshift/machine-api-provider-ibmcloud/pull/23) * [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/a63c6aabeb484cf8d7f976edc80622de959abde4...a6c7dcd9ed993e2ebf7272ff52cfa71cc7be856b) ### [insights-operator](https://github.com/openshift/insights-operator/tree/162554e15ece3653649c9a61567d332a462f079a) * [OCPBUGS-36475](https://issues.redhat.com/browse/OCPBUGS-36475): properly encode the URL for the advisor links (#962) (#965) [#962](https://github.com/openshift/insights-operator/pull/962) * [OCPBUGS-33449](https://issues.redhat.com/browse/OCPBUGS-33449): anonymization - externalIP can be nil (#931) (#933) (#935) [#931](https://github.com/openshift/insights-operator/pull/931) * [OCPBUGS-31991](https://issues.redhat.com/browse/OCPBUGS-31991): bump golang.org/x/net version (#927) [#927](https://github.com/openshift/insights-operator/pull/927) * [OCPBUGS-28157](https://issues.redhat.com/browse/OCPBUGS-28157): Add extra check in ids to bypass validations (#905) [#905](https://github.com/openshift/insights-operator/pull/905) * gather etcd_server_slow metrics (#902) (#909) [#902](https://github.com/openshift/insights-operator/pull/902) * [OCPBUGS-23962](https://issues.redhat.com/browse/OCPBUGS-23962): adds helm information gather (#868) (#883) [#868](https://github.com/openshift/insights-operator/pull/868) * [OCPBUGS-22958](https://issues.redhat.com/browse/OCPBUGS-22958): adds cluster storageclasses gather (#858) (#875) [#858](https://github.com/openshift/insights-operator/pull/858) * [OCPBUGS-22953](https://issues.redhat.com/browse/OCPBUGS-22953): create Prometheus rules programmatically according the… (#860) [#860](https://github.com/openshift/insights-operator/pull/860) * [OCPBUGS-22914](https://issues.redhat.com/browse/OCPBUGS-22914): remove username & password config options (#859) [#859](https://github.com/openshift/insights-operator/pull/859) * [OCPBUGS-20750](https://issues.redhat.com/browse/OCPBUGS-20750): update dependencies (#840) [#840](https://github.com/openshift/insights-operator/pull/840) * Add cherry-pick from 4.14 (#848) [#848](https://github.com/openshift/insights-operator/pull/848) * [OCPBUGS-19476](https://issues.redhat.com/browse/OCPBUGS-19476): update Insights report config logging (#828) [#828](https://github.com/openshift/insights-operator/pull/828) * [OCPBUGS-17661](https://issues.redhat.com/browse/OCPBUGS-17661): workload info gatherer, add external image repo (#816) [#816](https://github.com/openshift/insights-operator/pull/816) * [OCPBUGS-14773](https://issues.redhat.com/browse/OCPBUGS-14773): extend configmap gatherer to get gateway-mode-config (#788) (#791) [#788](https://github.com/openshift/insights-operator/pull/788) * [release-4.13 ]OCPBUGS-15031: fix the config serialization & add test (#794) (#796) [#794](https://github.com/openshift/insights-operator/pull/794) * [OCPBUGS-14318](https://issues.redhat.com/browse/OCPBUGS-14318): gather PDBs only from openshift namespaces (#786) [#786](https://github.com/openshift/insights-operator/pull/786) * [OCPBUGS-12618](https://issues.redhat.com/browse/OCPBUGS-12618): update golang.org/x/net version (#775) [#775](https://github.com/openshift/insights-operator/pull/775) * [OCPBUGS-8243](https://issues.redhat.com/browse/OCPBUGS-8243): Collect info about monitoring pods pv (#753) [#753](https://github.com/openshift/insights-operator/pull/753) * [OCPBUGS-11008](https://issues.redhat.com/browse/OCPBUGS-11008): update the cluster transfer interval to 12h (#762) [#762](https://github.com/openshift/insights-operator/pull/762) * [OCPBUGS-10239](https://issues.redhat.com/browse/OCPBUGS-10239): service_accounts.go Marshal fix (#750) [#750](https://github.com/openshift/insights-operator/pull/750) * [Full changelog](https://github.com/openshift/insights-operator/compare/acc99f557871cbf137f57a540f26989c27bb1301...162554e15ece3653649c9a61567d332a462f079a) ### [ironic](https://github.com/openshift/ironic-image/tree/7edd609de1fd2d1e9c8c5a46018b4f97b7474d15) * [OCPBUGS-69791](https://issues.redhat.com/browse/OCPBUGS-69791): Bump eventlet version to 0.33.1-7 [#766](https://github.com/openshift/ironic-image/pull/766) * [OCPBUGS-48146](https://issues.redhat.com/browse/OCPBUGS-48146), [OCPBUGS-48595](https://issues.redhat.com/browse/OCPBUGS-48595): Bump jinja2 to 3.0.1-6.el9.2 [#626](https://github.com/openshift/ironic-image/pull/626) * [OCPBUGS-43952](https://issues.redhat.com/browse/OCPBUGS-43952), [OCPBUGS-43960](https://issues.redhat.com/browse/OCPBUGS-43960): Bump python-waitress [4.13] [#608](https://github.com/openshift/ironic-image/pull/608) * [OCPBUGS-37764](https://issues.redhat.com/browse/OCPBUGS-37764), [OCPBUGS-39384](https://issues.redhat.com/browse/OCPBUGS-39384): Include fixes for CVE-2024-44082 [#585](https://github.com/openshift/ironic-image/pull/585) * [OCPBUGS-38509](https://issues.redhat.com/browse/OCPBUGS-38509): set min version for python3-webob [#557](https://github.com/openshift/ironic-image/pull/557) * [OCPBUGS-33374](https://issues.redhat.com/browse/OCPBUGS-33374): bump werkzeug [#543](https://github.com/openshift/ironic-image/pull/543) * [OCPBUGS-34898](https://issues.redhat.com/browse/OCPBUGS-34898): bump jinja2 [#538](https://github.com/openshift/ironic-image/pull/538) * [OCPBUGS-37116](https://issues.redhat.com/browse/OCPBUGS-37116): Update eventlet version [#525](https://github.com/openshift/ironic-image/pull/525) * [OCPBUGS-32363](https://issues.redhat.com/browse/OCPBUGS-32363): [4.13] remove unused prometheus-exporter [#488](https://github.com/openshift/ironic-image/pull/488) * [OCPBUGS-32387](https://issues.redhat.com/browse/OCPBUGS-32387): Use unix sockets by default for reverse proxy communication [#476](https://github.com/openshift/ironic-image/pull/476) * [OCPBUGS-29190](https://issues.redhat.com/browse/OCPBUGS-29190): Fix Inspector iPXE config for IPv6 addresses [#453](https://github.com/openshift/ironic-image/pull/453) * [OCPBUGS-23978](https://issues.redhat.com/browse/OCPBUGS-23978): Ironic side of external_http_url (METAL-163) is not wired in correctly [#430](https://github.com/openshift/ironic-image/pull/430) * [OCPBUGS-23506](https://issues.redhat.com/browse/OCPBUGS-23506): Uplift eventlet version [#427](https://github.com/openshift/ironic-image/pull/427) * [OCPBUGS-23356](https://issues.redhat.com/browse/OCPBUGS-23356): Upgrade werkzeug dependency [#422](https://github.com/openshift/ironic-image/pull/422) * [OCPBUGS-19078](https://issues.redhat.com/browse/OCPBUGS-19078): Handle Eject DVD 4.13 [#416](https://github.com/openshift/ironic-image/pull/416) * [OCPBUGS-23072](https://issues.redhat.com/browse/OCPBUGS-23072): Use bash process substitution instead of pipe [#413](https://github.com/openshift/ironic-image/pull/413) * [OCPBUGS-17837](https://issues.redhat.com/browse/OCPBUGS-17837): Fix PROVISIONING_MACS unbound [#393](https://github.com/openshift/ironic-image/pull/393) * [OCPBUGS-17158](https://issues.redhat.com/browse/OCPBUGS-17158): [4.13] Update packages with latest bugfix [#388](https://github.com/openshift/ironic-image/pull/388) * [OCPBUGS-17551](https://issues.redhat.com/browse/OCPBUGS-17551): Expand regex for fcos/okd packages list [#390](https://github.com/openshift/ironic-image/pull/390) * Bug OCPBUGS-15235: Incrementing Ironic versions to include backported SNMPv3 FIPS fix. [#383](https://github.com/openshift/ironic-image/pull/383) * [OCPBUGS-13587](https://issues.redhat.com/browse/OCPBUGS-13587): Add python-flask dependency [#372](https://github.com/openshift/ironic-image/pull/372) * [OCPBUGS-14135](https://issues.redhat.com/browse/OCPBUGS-14135): ironic.conf.j2: Bump min_command_interval to 30 on SCOS [#378](https://github.com/openshift/ironic-image/pull/378) * Bug OCPBUGS-13334: Bump ironic version to include fix to OCPBUGS-13334. [#366](https://github.com/openshift/ironic-image/pull/366) * [OCPBUGS-12703](https://issues.redhat.com/browse/OCPBUGS-12703): Bump python-sushy [#362](https://github.com/openshift/ironic-image/pull/362) * [OCPBUGS-11985](https://issues.redhat.com/browse/OCPBUGS-11985): allow inspector to also be proxied [#361](https://github.com/openshift/ironic-image/pull/361) * [Full changelog](https://github.com/openshift/ironic-image/compare/3b9c179dd961fca96316e797831ddc19acafb04a...7edd609de1fd2d1e9c8c5a46018b4f97b7474d15) ### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/bad3f37dea29e412399362fd63ae1419024fc62d) * [OCPBUGS-96902](https://issues.redhat.com/browse/OCPBUGS-96902): Replace individual package removal with a single rpm -e loop [#279](https://github.com/openshift/ironic-agent-image/pull/279) * [OCPBUGS-69776](https://issues.redhat.com/browse/OCPBUGS-69776): adding eventlet-0.33.1-7 [#235](https://github.com/openshift/ironic-agent-image/pull/235) * [OCPBUGS-39384](https://issues.redhat.com/browse/OCPBUGS-39384): Include fixes for CVE-2024-44082 [#164](https://github.com/openshift/ironic-agent-image/pull/164) * [OCPBUGS-38509](https://issues.redhat.com/browse/OCPBUGS-38509): set webob and bump werkzeug [#152](https://github.com/openshift/ironic-agent-image/pull/152) * [OCPBUGS-29725](https://issues.redhat.com/browse/OCPBUGS-29725): Always add ignition to set hostname on /etc/hostname [#111](https://github.com/openshift/ironic-agent-image/pull/111) * [OCPBUGS-19006](https://issues.redhat.com/browse/OCPBUGS-19006): backport hostname fixes [#89](https://github.com/openshift/ironic-agent-image/pull/89) * Switch to udevadm command install instead of package [OKD] [#83](https://github.com/openshift/ironic-agent-image/pull/83) * "Bug OCPBUGS-15777: Switch to udevadm command install instead of package" [#81](https://github.com/openshift/ironic-agent-image/pull/81) * [OCPBUGS-8380](https://issues.redhat.com/browse/OCPBUGS-8380): Adding dep on python3-werkzeug >= 2.0.3-4 [#70](https://github.com/openshift/ironic-agent-image/pull/70) * [Full changelog](https://github.com/openshift/ironic-agent-image/compare/cc4f46696731ac4262df5ba4d1acf42fdf27e08e...bad3f37dea29e412399362fd63ae1419024fc62d) ### [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader/tree/74713cce321c26cf8b8d429baadd2e29ae05ffb1) * [OCPBUGS-87170](https://issues.redhat.com/browse/OCPBUGS-87170): CI build root image tag and go version in go.mod version synced with ART 4.13 [#119](https://github.com/openshift/ironic-rhcos-downloader/pull/119) * [OCPBUGS-15734](https://issues.redhat.com/browse/OCPBUGS-15734): Binary should be compiled on rhel9 [#91](https://github.com/openshift/ironic-rhcos-downloader/pull/91) * [Full changelog](https://github.com/openshift/ironic-rhcos-downloader/compare/ac636fd1a6f5a42b9317207403838466ca129766...74713cce321c26cf8b8d429baadd2e29ae05ffb1) ### [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager/tree/4536724a8644fda91a74b23901ba1789eaff7179) * [OCPBUGS-14315](https://issues.redhat.com/browse/OCPBUGS-14315): Flush addresses on provisioning interface with global scope only [#36](https://github.com/openshift/ironic-static-ip-manager/pull/36) * [Full changelog](https://github.com/openshift/ironic-static-ip-manager/compare/1b194fd16b59c4a48223a2c9ac1bfb998a55c615...4536724a8644fda91a74b23901ba1789eaff7179) ### [k8s-prometheus-adapter](https://github.com/openshift/k8s-prometheus-adapter/tree/0fce7c7c97d56ba0a0ae4c6a2ba32e559b8a03d7) * [OCPBUGS-21457](https://issues.redhat.com/browse/OCPBUGS-21457): upgrade golang.org/x/net to 0.17.0 to address CVE [#90](https://github.com/openshift/k8s-prometheus-adapter/pull/90) * [OCPBUGS-20405](https://issues.redhat.com/browse/OCPBUGS-20405): limit number of simultaneous client requests [#78](https://github.com/openshift/k8s-prometheus-adapter/pull/78) * [Full changelog](https://github.com/openshift/k8s-prometheus-adapter/compare/801a912b3a60d7e840fb1ff38b5ca992f47327fd...0fce7c7c97d56ba0a0ae4c6a2ba32e559b8a03d7) ### [keepalived-ipfailover](https://github.com/openshift/images/tree/1a14e5c9896976b43767ab325a6fe35527a514a5) * [OCPBUGS-6236](https://issues.redhat.com/browse/OCPBUGS-6236): Updating openshift-enterprise-egress-router images to be consistent with ART [#121](https://github.com/openshift/images/pull/121) * [OCPBUGS-10519](https://issues.redhat.com/browse/OCPBUGS-10519): Revert "bump RHEL8 egress-dns-proxy image to haproxy26" [#135](https://github.com/openshift/images/pull/135) * [Full changelog](https://github.com/openshift/images/compare/03e5f40783e1b573f3d07d7640619ad9592f9a77...1a14e5c9896976b43767ab325a6fe35527a514a5) ### [kube-proxy, sdn](https://github.com/openshift/sdn/tree/9c882377e3a4cfc447b490e0a760697f3c9fa9ba) * [OCPBUGS-55758](https://issues.redhat.com/browse/OCPBUGS-55758): Handle `openshift-host-network` namespace as special when it modifies [#656](https://github.com/openshift/sdn/pull/656) * [OCPBUGS-20771](https://issues.redhat.com/browse/OCPBUGS-20771): update x/net to v0.17.0 [#590](https://github.com/openshift/sdn/pull/590) * [OCPBUGS-22932](https://issues.redhat.com/browse/OCPBUGS-22932): Change the permission of 80-openshift-network.conf to 600 [#582](https://github.com/openshift/sdn/pull/582) * [OCPBUGS-14504](https://issues.redhat.com/browse/OCPBUGS-14504): Use the ovsver build arg to infer the openvswitch short version number [#572](https://github.com/openshift/sdn/pull/572) * [OCPBUGS-15977](https://issues.redhat.com/browse/OCPBUGS-15977): Dockerfile: keep a RHEL-8 CNI shim binary in the default /opt/cni/bin dir [#558](https://github.com/openshift/sdn/pull/558) * [OCPBUGS-15977](https://issues.redhat.com/browse/OCPBUGS-15977): Dockerfile changes to build both rhel8 and rhel9 binaries [#557](https://github.com/openshift/sdn/pull/557) * [OCPBUGS-14278](https://issues.redhat.com/browse/OCPBUGS-14278): fix possible concurrent map read/write [#550](https://github.com/openshift/sdn/pull/550) * [OCPBUGS-12234](https://issues.redhat.com/browse/OCPBUGS-12234): CVE-2018-17419 ose-node-container: dns: Denial of Service (DoS) [#536](https://github.com/openshift/sdn/pull/536) * [OCPBUGS-13150](https://issues.redhat.com/browse/OCPBUGS-13150): EgressNetworkPolicy DNS resolution does not fall back to TCP [#540](https://github.com/openshift/sdn/pull/540) * [OCPBUGS-12994](https://issues.redhat.com/browse/OCPBUGS-12994): Prefer local TCP endpoint for cluster DNS service [#533](https://github.com/openshift/sdn/pull/533) * [OCPBUGS-11887](https://issues.redhat.com/browse/OCPBUGS-11887): save and delete the old egress network policy [#527](https://github.com/openshift/sdn/pull/527) * [OCPBUGS-10624](https://issues.redhat.com/browse/OCPBUGS-10624): Fix race in Egress IP Tracker start [#520](https://github.com/openshift/sdn/pull/520) * [Full changelog](https://github.com/openshift/sdn/compare/1f611c53ca22ebcf23d6a34ca07121f4fa2808d6...9c882377e3a4cfc447b490e0a760697f3c9fa9ba) ### [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy/tree/f35f954ae0550e6ebeb94e244401fc069dc346b8) * [OCPBUGS-31987](https://issues.redhat.com/browse/OCPBUGS-31987): CVE-2023-45288 [4.13] [#107](https://github.com/openshift/kube-rbac-proxy/pull/107) * [OCPBUGS-20702](https://issues.redhat.com/browse/OCPBUGS-20702): v0.15.0 downstream release 4.13 [#84](https://github.com/openshift/kube-rbac-proxy/pull/84) * [OCPBUGS-12513](https://issues.redhat.com/browse/OCPBUGS-12513): go.mod: update golang.org/x/net to v0.7.0 [#68](https://github.com/openshift/kube-rbac-proxy/pull/68) * [OCPBUGS-11643](https://issues.redhat.com/browse/OCPBUGS-11643): Updating kube-rbac-proxy images to be consistent with ART [#61](https://github.com/openshift/kube-rbac-proxy/pull/61) * [Full changelog](https://github.com/openshift/kube-rbac-proxy/compare/b8b8259584046eabb7565f262c8105c2686107a4...f35f954ae0550e6ebeb94e244401fc069dc346b8) ### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/fd791df54d7271c1611090505509a03454168689) * [OCPBUGS-20778](https://issues.redhat.com/browse/OCPBUGS-20778): bump x/net to v0.17.0 [#102](https://github.com/openshift/kube-state-metrics/pull/102) * [Full changelog](https://github.com/openshift/kube-state-metrics/compare/db0c54994a6aad9155a94513eaa3480c1812f45e...fd791df54d7271c1611090505509a03454168689) ### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/ac20da35bc6d9cded6dbf7fa0c27e867c7a69cb7) * NO-JIRA: Add DOWNSTREAM_OWNERS (release 4-13). [#230](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/230) * [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/b533e08c1ee5ac79d5b9219ec0ac2fefca353d9d...ac20da35bc6d9cded6dbf7fa0c27e867c7a69cb7) ### [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt/tree/baa67b6e7cc5f7c19360de9a4a766f6faf01f7a1) * [OCPBUGS-95079](https://issues.redhat.com/browse/OCPBUGS-95079): OWNERS: Update component to Cloud Compute / KubeVirt Provider [#78](https://github.com/openshift/cloud-provider-kubevirt/pull/78) * [Full changelog](https://github.com/openshift/cloud-provider-kubevirt/compare/e320958fd283d9f9995fc5e3b6441e6d4c57782a...baa67b6e7cc5f7c19360de9a4a766f6faf01f7a1) ### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/9d909f7f3a3efd27d7efb71bf0324796aa6e8788) * "OCPBUGS-29791: [release-4.13] Address CVE-2024-1725: Restrict access to infrastructure PVCs by requiring matching infraClusterLabels on tenant PVCs" [#35](https://github.com/openshift/kubevirt-csi-driver/pull/35) * [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/48fafc4a9edc202c5ff674b5f631568b4d62f7f5...9d909f7f3a3efd27d7efb71bf0324796aa6e8788) ### [kuryr-cni, kuryr-controller](https://github.com/openshift/kuryr-kubernetes/tree/36754b7b90928e26811e1c5ea13e7d0bd85709de) * Bug OCPBUGS-16340: Fix np retry [#738](https://github.com/openshift/kuryr-kubernetes/pull/738) * [OCPBUGS-15457](https://issues.redhat.com/browse/OCPBUGS-15457): Remove unneeded grpcio dependencies from RPM [#735](https://github.com/openshift/kuryr-kubernetes/pull/735) * [OCPBUGS-13427](https://issues.redhat.com/browse/OCPBUGS-13427): KuryrPort cleanup: Fix issue of subport not found [#726](https://github.com/openshift/kuryr-kubernetes/pull/726) * Bug OCPBUGS-11982: Fix ValueError when Pod has no IP address [#720](https://github.com/openshift/kuryr-kubernetes/pull/720) * [Full changelog](https://github.com/openshift/kuryr-kubernetes/compare/8926a294348d3791040748774b0ac0892b968494...36754b7b90928e26811e1c5ea13e7d0bd85709de) ### [libvirt-machine-controllers](https://github.com/openshift/cluster-api-provider-libvirt/tree/8f825e59b9e80bc0123d360365b306ae2f464699) * [OCPBUGS-77199](https://issues.redhat.com/browse/OCPBUGS-77199): Fix incomplete vendor [#305](https://github.com/openshift/cluster-api-provider-libvirt/pull/305) * "OCPBUGS-19927: libvirt: Don't force use of virtio console" [#268](https://github.com/openshift/cluster-api-provider-libvirt/pull/268) * [Full changelog](https://github.com/openshift/cluster-api-provider-libvirt/compare/3d82606aad9b4a1b3a77e960a160bbc59975954b...8f825e59b9e80bc0123d360365b306ae2f464699) ### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/b3b92854d3f8b19ba72c3800e3f0d485c4ebd0b7) * [OCPBUGS-78270](https://issues.redhat.com/browse/OCPBUGS-78270): hermetic 4.13 [#1469](https://github.com/openshift/machine-api-operator/pull/1469) * [OCPBUGS-67672](https://issues.redhat.com/browse/OCPBUGS-67672): bumped logrus to v1.9.3 [#1461](https://github.com/openshift/machine-api-operator/pull/1461) * [OCPBUGS-43856](https://issues.redhat.com/browse/OCPBUGS-43856): install/0000_30_machine-api-operator_00_credentials-request: Set skipServiceCheck again for GCP [#1304](https://github.com/openshift/machine-api-operator/pull/1304) * [OCPBUGS-32015](https://issues.redhat.com/browse/OCPBUGS-32015): Fix zone tag value reconciliation for vSphere machines [#1225](https://github.com/openshift/machine-api-operator/pull/1225) * [OCPBUGS-31994](https://issues.redhat.com/browse/OCPBUGS-31994): Update x/net to v0.25.0 [#1245](https://github.com/openshift/machine-api-operator/pull/1245) * NO-JIRA: [release-4.13] Fix data race conditions in unit tests [#1254](https://github.com/openshift/machine-api-operator/pull/1254) * [OCPBUGS-25165](https://issues.redhat.com/browse/OCPBUGS-25165): Add Snyk file to exclude vendor directory on scan [#1194](https://github.com/openshift/machine-api-operator/pull/1194) * [OCPBUGS-24277](https://issues.redhat.com/browse/OCPBUGS-24277): Update reference URL [#1188](https://github.com/openshift/machine-api-operator/pull/1188) * [OCPBUGS-24277](https://issues.redhat.com/browse/OCPBUGS-24277): Use docs URL instead of KCS article [#1181](https://github.com/openshift/machine-api-operator/pull/1181) * [OCPBUGS-21513](https://issues.redhat.com/browse/OCPBUGS-21513): Bump golang.org/x/net to v0.18.0 [#1175](https://github.com/openshift/machine-api-operator/pull/1175) * [OCPBUGS-12626](https://issues.redhat.com/browse/OCPBUGS-12626): Update golang.org/x/net dependency [#1148](https://github.com/openshift/machine-api-operator/pull/1148) * [OCPBUGS-10661](https://issues.redhat.com/browse/OCPBUGS-10661): Fix empty component version [#1130](https://github.com/openshift/machine-api-operator/pull/1130) * [Full changelog](https://github.com/openshift/machine-api-operator/compare/19133ba974fbf8039a1551702ca7f21f91689ffb...b3b92854d3f8b19ba72c3800e3f0d485c4ebd0b7) ### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/a57ca291235422f8466ac53496e9d192eecfe1e4) * [OCPBUGS-61234](https://issues.redhat.com/browse/OCPBUGS-61234): Trigger a new build [#5278](https://github.com/openshift/machine-config-operator/pull/5278) * [OCPBUGS-59125](https://issues.redhat.com/browse/OCPBUGS-59125): [release-4.13] Bump golang/glog to fix CVE-2024-45339 [#5175](https://github.com/openshift/machine-config-operator/pull/5175) * [OCPBUGS-44206](https://issues.redhat.com/browse/OCPBUGS-44206): Panic seen in CI job for MCC pod [#4680](https://github.com/openshift/machine-config-operator/pull/4680) * [OCPBUGS-38372](https://issues.redhat.com/browse/OCPBUGS-38372): Revert "MCD-pull: run after network-online.target in Azure" [#4527](https://github.com/openshift/machine-config-operator/pull/4527) * [OCPBUGS-38295](https://issues.redhat.com/browse/OCPBUGS-38295): daemon/update: disable systemd unit before overwriting [#4522](https://github.com/openshift/machine-config-operator/pull/4522) * [OCPBUGS-37783](https://issues.redhat.com/browse/OCPBUGS-37783): Openshift uncordoned compute-node that was intentionally cordoned [#4507](https://github.com/openshift/machine-config-operator/pull/4507) * [OCPBUGS-37160](https://issues.redhat.com/browse/OCPBUGS-37160): MCD-pull: run after network-online.target in Azure [#4474](https://github.com/openshift/machine-config-operator/pull/4474) * [OCPBUGS-36782](https://issues.redhat.com/browse/OCPBUGS-36782): daemon: Handle correctly OS Version for 4.1 and 4.2 bootimages [#4464](https://github.com/openshift/machine-config-operator/pull/4464) * [OCPBUGS-32208](https://issues.redhat.com/browse/OCPBUGS-32208): Run resolv-prepender entirely async [#4314](https://github.com/openshift/machine-config-operator/pull/4314) * [OCPBUGS-33327](https://issues.redhat.com/browse/OCPBUGS-33327): make verify should use MCO's kube version [#4352](https://github.com/openshift/machine-config-operator/pull/4352) * [OCPBUGS-29721](https://issues.redhat.com/browse/OCPBUGS-29721): Add existing kubeletconfig/ctrcfg mc-name-suffix annotation [#4206](https://github.com/openshift/machine-config-operator/pull/4206) * [OCPBUGS-30285](https://issues.redhat.com/browse/OCPBUGS-30285): set nodeStatusReportFrequency [#4243](https://github.com/openshift/machine-config-operator/pull/4243) * [OCPBUGS-28740](https://issues.redhat.com/browse/OCPBUGS-28740): crio: drop automatic image cleanup on upgrades [#4154](https://github.com/openshift/machine-config-operator/pull/4154) * [OCPBUGS-29151](https://issues.redhat.com/browse/OCPBUGS-29151): fix nodeStatusUpdateFrequency [#4170](https://github.com/openshift/machine-config-operator/pull/4170) * [OCPBUGS-24661](https://issues.redhat.com/browse/OCPBUGS-24661): daemon: Add support for new nmstate logic [#4036](https://github.com/openshift/machine-config-operator/pull/4036) * [OCPBUGS-27816](https://issues.redhat.com/browse/OCPBUGS-27816): use *resource.Quantity to not automatically set 0 [#4141](https://github.com/openshift/machine-config-operator/pull/4141) * [OCPBUGS-22272](https://issues.redhat.com/browse/OCPBUGS-22272), [OCPBUGS-27172](https://issues.redhat.com/browse/OCPBUGS-27172): kubelet: fix kubelet labels [#4120](https://github.com/openshift/machine-config-operator/pull/4120) * [OCPBUGS-27096](https://issues.redhat.com/browse/OCPBUGS-27096): Azure Run ovs-configuration.service before dnsmasq.service [#4115](https://github.com/openshift/machine-config-operator/pull/4115) * [OCPBUGS-19658](https://issues.redhat.com/browse/OCPBUGS-19658): After dual-stack conversion reconcile IPFamilies [#3935](https://github.com/openshift/machine-config-operator/pull/3935) * [OCPBUGS-23468](https://issues.redhat.com/browse/OCPBUGS-23468): support icsp and idms objects [#4027](https://github.com/openshift/machine-config-operator/pull/4027) * [OCPBUGS-23536](https://issues.redhat.com/browse/OCPBUGS-23536): Introduce kubelet-dependencies.target and firstboot-osupdate.target [#4043](https://github.com/openshift/machine-config-operator/pull/4043) * [OCPBUGS-21052](https://issues.redhat.com/browse/OCPBUGS-21052): Update library-go and kube deps to latest version [#4011](https://github.com/openshift/machine-config-operator/pull/4011) * [OCPBUGS-22205](https://issues.redhat.com/browse/OCPBUGS-22205): Consider ingress VIPs when selecting node IP [#3991](https://github.com/openshift/machine-config-operator/pull/3991) * [OCPBUGS-18031](https://issues.redhat.com/browse/OCPBUGS-18031): on-prem: run resolv-prepender on NM reapply event [#3880](https://github.com/openshift/machine-config-operator/pull/3880) * [OCPBUGS-22412](https://issues.redhat.com/browse/OCPBUGS-22412): bootstrap_test: always set APIVersion and Kind for DNS [#4002](https://github.com/openshift/machine-config-operator/pull/4002) * [OCPBUGS-21721](https://issues.redhat.com/browse/OCPBUGS-21721): install/0000_90_machine-config-operator_90_deletion: Drop this file [#3983](https://github.com/openshift/machine-config-operator/pull/3983) * [OCPBUGS-20333](https://issues.redhat.com/browse/OCPBUGS-20333): resolv-prepender: avoid pulling baremetalRuntimeCfgImage again if it … [#3962](https://github.com/openshift/machine-config-operator/pull/3962) * [OCPBUGS-18803](https://issues.redhat.com/browse/OCPBUGS-18803): Soften grep pattern for ingress default router [#3908](https://github.com/openshift/machine-config-operator/pull/3908) * [OCPBUGS-19958](https://issues.redhat.com/browse/OCPBUGS-19958): [release-4.13] Backport logspam PRs [#3950](https://github.com/openshift/machine-config-operator/pull/3950) * [OCPBUGS-19675](https://issues.redhat.com/browse/OCPBUGS-19675): daemon: always use `podman cp` to copy extensions container content [#3938](https://github.com/openshift/machine-config-operator/pull/3938) * [OCPBUGS-19400](https://issues.redhat.com/browse/OCPBUGS-19400): install: Recreate and delayed default ServiceAccount deletion [#3923](https://github.com/openshift/machine-config-operator/pull/3923) * [OCPBUGS-19509](https://issues.redhat.com/browse/OCPBUGS-19509): Ignore invoking nbctl calls if its SDN [#3929](https://github.com/openshift/machine-config-operator/pull/3929) * [OCPBUGS-19414](https://issues.redhat.com/browse/OCPBUGS-19414): The kubeconfig copied on to each node has 644 permissions [#3924](https://github.com/openshift/machine-config-operator/pull/3924) * [OCPBUGS-18159](https://issues.redhat.com/browse/OCPBUGS-18159): Ensure azure-routes hack for internalLB hairpin traffic works for SGW [#3904](https://github.com/openshift/machine-config-operator/pull/3904) * [OCPBUGS-16218](https://issues.redhat.com/browse/OCPBUGS-16218): Prevent NM from unsetting the hostname [#3805](https://github.com/openshift/machine-config-operator/pull/3805) * [OCPBUGS-17997](https://issues.redhat.com/browse/OCPBUGS-17997): SSHkeys fails to write on upgrade to 4.13.rc3 [#3879](https://github.com/openshift/machine-config-operator/pull/3879) * [OCPBUGS-18076](https://issues.redhat.com/browse/OCPBUGS-18076): daemon: create /etc/systemd/network directory on node [#3888](https://github.com/openshift/machine-config-operator/pull/3888) * [OCPBUGS-17769](https://issues.redhat.com/browse/OCPBUGS-17769): Agent-based install process the container machine-config-controller will be oom [#3868](https://github.com/openshift/machine-config-operator/pull/3868) * [OKD-174](https://issues.redhat.com/browse/OKD-174): Dockerfile: OKD: Reenable extensions image on SCOS [#3845](https://github.com/openshift/machine-config-operator/pull/3845) * [OCPBUGS-17430](https://issues.redhat.com/browse/OCPBUGS-17430): The machine-config-controller pod restart in SNO+1 causing daemonsets to restart [#3841](https://github.com/openshift/machine-config-operator/pull/3841) * [OCPBUGS-17163](https://issues.redhat.com/browse/OCPBUGS-17163): daemon: Always replace binary [#3833](https://github.com/openshift/machine-config-operator/pull/3833) * [OCPBUGS-16888](https://issues.redhat.com/browse/OCPBUGS-16888): daemon: Make binary writing idempotent [#3826](https://github.com/openshift/machine-config-operator/pull/3826) * [OCPBUGS-16888](https://issues.redhat.com/browse/OCPBUGS-16888): daemon: no need to reexec when target and source rhel version is same [#3824](https://github.com/openshift/machine-config-operator/pull/3824) * [OCPBUGS-16622](https://issues.redhat.com/browse/OCPBUGS-16622): daemon: Copy matching binary to host, re-exec with it [#3812](https://github.com/openshift/machine-config-operator/pull/3812) * [OCPNODE-1717](https://issues.redhat.com/browse/OCPNODE-1717): Update config node spec while explicitly updating the cgroups mode [#3793](https://github.com/openshift/machine-config-operator/pull/3793) * 4.13: Revert rhel9 binaries builds [#3802](https://github.com/openshift/machine-config-operator/pull/3802) * [OCPBUGS-14459](https://issues.redhat.com/browse/OCPBUGS-14459): daemon: Remove noisy log message [#3723](https://github.com/openshift/machine-config-operator/pull/3723) * [OCPBUGS-15580](https://issues.redhat.com/browse/OCPBUGS-15580): 4.13: Dockerfile: update rhel7 nmstate pin [#3764](https://github.com/openshift/machine-config-operator/pull/3764) * [OCPBUGS-15463](https://issues.redhat.com/browse/OCPBUGS-15463): Minor fix to support protectKernelDefaults field in Kubelet Config [#3757](https://github.com/openshift/machine-config-operator/pull/3757) * 4.13: Dockerfile: use proper rhel9 image [#3771](https://github.com/openshift/machine-config-operator/pull/3771) * 4.13: use rhel9 builder for daemon binary [#3760](https://github.com/openshift/machine-config-operator/pull/3760) * [OCPBUGS-13311](https://issues.redhat.com/browse/OCPBUGS-13311): daemon: write certs in firstboot-complete path [#3702](https://github.com/openshift/machine-config-operator/pull/3702) * [OCPBUGS-13404](https://issues.redhat.com/browse/OCPBUGS-13404), [OCPBUGS-14298](https://issues.redhat.com/browse/OCPBUGS-14298): Dockerfile: pin to nmstate-2.2.9-6.rhaos4.13.el8 [#3716](https://github.com/openshift/machine-config-operator/pull/3716) * [OCPBUGS-14850](https://issues.redhat.com/browse/OCPBUGS-14850): Allow userfaultfd syscall to be used by unprivileged users [#3743](https://github.com/openshift/machine-config-operator/pull/3743) * [OCPBUGS-13974](https://issues.redhat.com/browse/OCPBUGS-13974): MCO-496: Support ignition versions 3.3 + 3.4 but keep version 3.2 as default [#3714](https://github.com/openshift/machine-config-operator/pull/3714) * [OCPBUGS-13138](https://issues.redhat.com/browse/OCPBUGS-13138): daemon: Don't traverse `/run/ostree/auth.json` symlink [#3697](https://github.com/openshift/machine-config-operator/pull/3697) * [OCPBUGS-11302](https://issues.redhat.com/browse/OCPBUGS-11302): Fix regex dot in coredns config file [#3659](https://github.com/openshift/machine-config-operator/pull/3659) * [OCPBUGS-12784](https://issues.redhat.com/browse/OCPBUGS-12784), [OCPBUGS-4476](https://issues.redhat.com/browse/OCPBUGS-4476): keepalived/ingress: change healthcheck script [#3687](https://github.com/openshift/machine-config-operator/pull/3687) * [OCPBUGS-12919](https://issues.redhat.com/browse/OCPBUGS-12919): The MCD has a non-functional pivot command that should be removed [#3690](https://github.com/openshift/machine-config-operator/pull/3690) * [OCPBUGS-10966](https://issues.redhat.com/browse/OCPBUGS-10966): configure-ovs: support UUID in vlan.parent [#3639](https://github.com/openshift/machine-config-operator/pull/3639) * [OCPBUGS-13312](https://issues.redhat.com/browse/OCPBUGS-13312): daemon: event only on actual OS updates [#3703](https://github.com/openshift/machine-config-operator/pull/3703) * [OCPBUGS-11598](https://issues.redhat.com/browse/OCPBUGS-11598): Do not trigger openshift-azure-routes/openshift-alibaba-routes service based on file existence [#3681](https://github.com/openshift/machine-config-operator/pull/3681) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): update cloud provider flags on vSphere for storage options [#3655](https://github.com/openshift/machine-config-operator/pull/3655) * [OCPBUGS-11778](https://issues.redhat.com/browse/OCPBUGS-11778): Fixing forcedns dispatcher script permission issue for assisted sno rhel9 upgrade [#3678](https://github.com/openshift/machine-config-operator/pull/3678) * [OCPBUGS-11051](https://issues.redhat.com/browse/OCPBUGS-11051): Splitting NetworkManager-onprem.conf.yaml to 2 files: [#3642](https://github.com/openshift/machine-config-operator/pull/3642) * [OCPBUGS-10946](https://issues.redhat.com/browse/OCPBUGS-10946): Fix kubelet.service node-ip for v6-primary dual-stack [#3638](https://github.com/openshift/machine-config-operator/pull/3638) * [OCPBUGS-11507](https://issues.redhat.com/browse/OCPBUGS-11507): Accomodate ART limitation in parsing [[]] bash [#3671](https://github.com/openshift/machine-config-operator/pull/3671) * [OCPBUGS-11507](https://issues.redhat.com/browse/OCPBUGS-11507): Persist static IP addressed NIC names from rhel8 [#3664](https://github.com/openshift/machine-config-operator/pull/3664) * [OCPBUGS-11289](https://issues.redhat.com/browse/OCPBUGS-11289): daemon: write certificate in OnceFrom and HyperShift [#3658](https://github.com/openshift/machine-config-operator/pull/3658) * [OCPBUGS-11040](https://issues.redhat.com/browse/OCPBUGS-11040): remove container runtime flag [#3641](https://github.com/openshift/machine-config-operator/pull/3641) * [OCPBUGS-11068](https://issues.redhat.com/browse/OCPBUGS-11068): Enable base nodeip-configuration for vsphere upi [#3644](https://github.com/openshift/machine-config-operator/pull/3644) * [OCPBUGS-8317](https://issues.redhat.com/browse/OCPBUGS-8317): Wrap podman commands in a while loop [#3605](https://github.com/openshift/machine-config-operator/pull/3605) * [OCPBUGS-10367](https://issues.redhat.com/browse/OCPBUGS-10367): MCO-503: daemon: have a special path to sync in certs [#3612](https://github.com/openshift/machine-config-operator/pull/3612) * [OCPBUGS-10427](https://issues.redhat.com/browse/OCPBUGS-10427): daemon: Drop duplicate `--authfile` used in `run` [#3616](https://github.com/openshift/machine-config-operator/pull/3616) * [OCPBUGS-10220](https://issues.redhat.com/browse/OCPBUGS-10220): Remove hard requirement for the afterburn from early-running aws-related services [#3610](https://github.com/openshift/machine-config-operator/pull/3610) * [COS-1926](https://issues.redhat.com/browse/COS-1926), [MCO-116](https://issues.redhat.com/browse/MCO-116), [OCPBUGS-8703](https://issues.redhat.com/browse/OCPBUGS-8703), [OCPBUGS-9951](https://issues.redhat.com/browse/OCPBUGS-9951): rhel coreos 9 4.13 katamari [#3604](https://github.com/openshift/machine-config-operator/pull/3604) * [OCPBUGS-8702](https://issues.redhat.com/browse/OCPBUGS-8702): Revert "daemon: Temporarily copy auth file with more open perms on FCOS" [#3594](https://github.com/openshift/machine-config-operator/pull/3594) * [OCPBUGS-8445](https://issues.redhat.com/browse/OCPBUGS-8445): Default the cgroup version to "v1" via base template controller [#3587](https://github.com/openshift/machine-config-operator/pull/3587) * [OCPBUGS-8703](https://issues.redhat.com/browse/OCPBUGS-8703): Backport switchkernel 4.13 [#3595](https://github.com/openshift/machine-config-operator/pull/3595) * [Full changelog](https://github.com/openshift/machine-config-operator/compare/00b2e0b1cc83e119995bbbe2ae06665c3d1655d7...a57ca291235422f8466ac53496e9d192eecfe1e4) ### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/d722cc362b450bd97794fd5ea4c35a2924a6f13a) * [OCPBUGS-67658](https://issues.redhat.com/browse/OCPBUGS-67658): bumped logrus to v1.9.3 [#160](https://github.com/openshift/image-customization-controller/pull/160) * [OCPBUGS-27089](https://issues.redhat.com/browse/OCPBUGS-27089): configurable ironic agent vlan creation [#117](https://github.com/openshift/image-customization-controller/pull/117) * [OCPBUGS-21549](https://issues.redhat.com/browse/OCPBUGS-21549): Uplift x/net to v0.17.0 [#105](https://github.com/openshift/image-customization-controller/pull/105) * [OCPBUGS-19006](https://issues.redhat.com/browse/OCPBUGS-19006): Pass BareMetalHost name to IPA (take 2) [#98](https://github.com/openshift/image-customization-controller/pull/98) * [OCPBUGS-14250](https://issues.redhat.com/browse/OCPBUGS-14250): Watch networkData Secrets for changes [#95](https://github.com/openshift/image-customization-controller/pull/95) * [OCPBUGS-12694](https://issues.redhat.com/browse/OCPBUGS-12694): Uplift x/net to 0.7.0 [#86](https://github.com/openshift/image-customization-controller/pull/86) * [Full changelog](https://github.com/openshift/image-customization-controller/compare/1bff221eb64c41124fdf72c90b72498197291a6a...d722cc362b450bd97794fd5ea4c35a2924a6f13a) ### [machine-os-images](https://github.com/openshift/machine-os-images/tree/cb22deaa429516b8212358958d92630829759082) * [OCPBUGS-87881](https://issues.redhat.com/browse/OCPBUGS-87881): Add support for hermetic builds via Cachi2 prefetched CoreOS ISOs [#105](https://github.com/openshift/machine-os-images/pull/105) * [OCPBUGS-54172](https://issues.redhat.com/browse/OCPBUGS-54172): Change rhcos release browser url [#60](https://github.com/openshift/machine-os-images/pull/60) * Force updating rhcos image to version 413.92.202303190222-0 [#27](https://github.com/openshift/machine-os-images/pull/27) * [Full changelog](https://github.com/openshift/machine-os-images/compare/197f328f2b1459b03883464ab0e13158ec84d130...cb22deaa429516b8212358958d92630829759082) ### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/39a2173ffa2fb9b0cdc812121a67d0b46ecd19bd) * [OCPBUGS-60293](https://issues.redhat.com/browse/OCPBUGS-60293): Bump github.com/golang/glog to v1.2.4 [#106](https://github.com/openshift/multus-admission-controller/pull/106) * [OCPBUGS-60841](https://issues.redhat.com/browse/OCPBUGS-60841): Update owners [#108](https://github.com/openshift/multus-admission-controller/pull/108) * [OCPBUGS-21353](https://issues.redhat.com/browse/OCPBUGS-21353): Update go.mod for CVE-2023-39325 [Release-4.13] [#72](https://github.com/openshift/multus-admission-controller/pull/72) * [OCPBUGS-13709](https://issues.redhat.com/browse/OCPBUGS-13709): Bump golang.org/x/net from 0.0.0-20211209124913-491a49abca63 to 0.7.0 [#68](https://github.com/openshift/multus-admission-controller/pull/68) * [Full changelog](https://github.com/openshift/multus-admission-controller/compare/75d37a9cae194ebba203a9e6442dc0d90c02aba4...39a2173ffa2fb9b0cdc812121a67d0b46ecd19bd) ### [multus-cni](https://github.com/openshift/multus-cni/tree/12897bd18a928b8d0ea22fca0c05cee480285752) * [OCPBUGS-28020](https://issues.redhat.com/browse/OCPBUGS-28020): Fix SAST scan issues for multus-cni-container [4.13] [#224](https://github.com/openshift/multus-cni/pull/224) * [OCPBUGS-21076](https://issues.redhat.com/browse/OCPBUGS-21076): Update go.mod for CVE-2023-39325 [Release-4.13] [#195](https://github.com/openshift/multus-cni/pull/195) * Add rhel9 binary for multus [#169](https://github.com/openshift/multus-cni/pull/169) * [OCPBUGS-8398](https://issues.redhat.com/browse/OCPBUGS-8398): Multus entrypoint should regenerate kubeconfig if secret changes [backport 4.13] [#154](https://github.com/openshift/multus-cni/pull/154) * [OCPBUGS-13759](https://issues.redhat.com/browse/OCPBUGS-13759): Bump golang.org/x/net from 0.1.0 to 0.7.0 (#1039) [#161](https://github.com/openshift/multus-cni/pull/161) * [OCPBUGS-13814](https://issues.redhat.com/browse/OCPBUGS-13814): Fix multus to support CNI plugin which does not create interface [backport 4.13] [#163](https://github.com/openshift/multus-cni/pull/163) * [Full changelog](https://github.com/openshift/multus-cni/compare/e3c26de3692410c14a4a2f075b6c0946fa9f1e4c...12897bd18a928b8d0ea22fca0c05cee480285752) ### [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy/tree/7176ab75edaf6328bb1da06ba55378815271d218) * [OCPBUGS-12641](https://issues.redhat.com/browse/OCPBUGS-12641): CVE-2022-41723: Update vendors to fix dependabot alerts [#28](https://github.com/openshift/multus-networkpolicy/pull/28) * And 1 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/multus-networkpolicy/compare/f670647c0cb7b6f870f8176b26f83ce6614e209e...7176ab75edaf6328bb1da06ba55378815271d218) ### [multus-route-override-cni](https://github.com/openshift/route-override-cni/tree/ca3bbec5c75ebcd6814bdd74856b27db755c9fa3) * Add rhel9 binary [#37](https://github.com/openshift/route-override-cni/pull/37) * [Full changelog](https://github.com/openshift/route-override-cni/compare/5965fed661f71112104ca6cef22aa883f542226d...ca3bbec5c75ebcd6814bdd74856b27db755c9fa3) ### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/9f8d13c74cfe33562c520a77b1a7dbf2e1bd1ef9) * [OCPBUGS-37941](https://issues.redhat.com/browse/OCPBUGS-37941), [OCPBUGS-37944](https://issues.redhat.com/browse/OCPBUGS-37944): [release-4.13] Stateful fixes [#306](https://github.com/openshift/whereabouts-cni/pull/306) * [OCPBUGS-27958](https://issues.redhat.com/browse/OCPBUGS-27958): Enable reconciler configuration [#241](https://github.com/openshift/whereabouts-cni/pull/241) * [OCPBUGS-27367](https://issues.redhat.com/browse/OCPBUGS-27367): [release-4.13] Backport fix assignment [#236](https://github.com/openshift/whereabouts-cni/pull/236) * [OCPBUGS-21512](https://issues.redhat.com/browse/OCPBUGS-21512): update golang.org/x/net to v0.17.0 [#208](https://github.com/openshift/whereabouts-cni/pull/208) * [OCPBUGS-4417](https://issues.redhat.com/browse/OCPBUGS-4417): Denormalize IP name before checking if pod is alive [Backport 4.13] [#168](https://github.com/openshift/whereabouts-cni/pull/168) * [OCPBUGS-15956](https://issues.redhat.com/browse/OCPBUGS-15956): Updating ose-multus-whereabouts-ipam-cni images to be consistent with ART [#138](https://github.com/openshift/whereabouts-cni/pull/138) * [Bug 16002](https://bugzilla.redhat.com/show_bug.cgi?id=16002): Change default binary to RHEL8 image [#144](https://github.com/openshift/whereabouts-cni/pull/144) * Restores RHEL specific binary build in dockerfile and updates to rhel9/8 [#139](https://github.com/openshift/whereabouts-cni/pull/139) * [OCPBUGS-11427](https://issues.redhat.com/browse/OCPBUGS-11427): Fix network status annotation to k8s.v1.cni.cncf.io/network-status [#127](https://github.com/openshift/whereabouts-cni/pull/127) * [OCPBUGS-11424](https://issues.redhat.com/browse/OCPBUGS-11424): Use downward API to pass current spec.nodeName to pod [#126](https://github.com/openshift/whereabouts-cni/pull/126) * [OCPBUGS-11322](https://issues.redhat.com/browse/OCPBUGS-11322): respect requested allocation range when exluding ranges [Backport 4.13] [#122](https://github.com/openshift/whereabouts-cni/pull/122) * [OCPBUGS-7301](https://issues.redhat.com/browse/OCPBUGS-7301): Invalid ipv6 backport 4.13 [#125](https://github.com/openshift/whereabouts-cni/pull/125) * [Full changelog](https://github.com/openshift/whereabouts-cni/compare/f95487b0831b560de7b8d7c5d1c986338224800b...9f8d13c74cfe33562c520a77b1a7dbf2e1bd1ef9) ### [must-gather](https://github.com/openshift/must-gather/tree/339046b6478094030fa5ebf1ebceed2bb03a55f4) * [OCPBUGS-48085](https://issues.redhat.com/browse/OCPBUGS-48085): Update owners [#476](https://github.com/openshift/must-gather/pull/476) * [OCPBUGS-19928](https://issues.redhat.com/browse/OCPBUGS-19928): [release-4.13] Add csi-proxy logs collection in must-gather for Windows nodes [#383](https://github.com/openshift/must-gather/pull/383) * [Full changelog](https://github.com/openshift/must-gather/compare/b8585ca862a3fbe77134e5cbe6155d7c04efc269...339046b6478094030fa5ebf1ebceed2bb03a55f4) ### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/84bda2afb2ab260253b77d5d282df773cc6b3438) * Add rhel9 binary [#56](https://github.com/openshift/bond-cni/pull/56) * [OCPBUGS-11881](https://issues.redhat.com/browse/OCPBUGS-11881): Ignore missing links during delete command [#49](https://github.com/openshift/bond-cni/pull/49) * [Full changelog](https://github.com/openshift/bond-cni/compare/29f61f6b05d958c40e7213937064f26a63a8e6d9...84bda2afb2ab260253b77d5d282df773cc6b3438) ### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/aa24d460383cf426963226783e3db981f0d3b714) * [OCPBUGS-59699](https://issues.redhat.com/browse/OCPBUGS-59699): Bump github.com/golang/glog to v1.2.4 (#117) [#117](https://github.com/openshift/network-metrics-daemon/pull/117) * [release 4.13] OCPBUGS-60541: Replace e2e test image (#132) [#132](https://github.com/openshift/network-metrics-daemon/pull/132) * swtich golint install method (#129) [#129](https://github.com/openshift/network-metrics-daemon/pull/129) * Correct 4.16 owners file (#130) [#130](https://github.com/openshift/network-metrics-daemon/pull/130) * Added METRIC_TEST_IMAGE var (#90) [#90](https://github.com/openshift/network-metrics-daemon/pull/90) * Update the k8s dependencies to 1.26.10 (#83) [#83](https://github.com/openshift/network-metrics-daemon/pull/83) * [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/84d7ac4e326e55fea98629d3851e98730c8d44a9...aa24d460383cf426963226783e3db981f0d3b714) ### [network-tools](https://github.com/openshift/network-tools/tree/073feda14fbd894c4238d693afa38a06392f2360) * Dockerfile: move to RHEL9 base image [#83](https://github.com/openshift/network-tools/pull/83) * Updating ose-network-tools images to be consistent with ART [#75](https://github.com/openshift/network-tools/pull/75) * [Full changelog](https://github.com/openshift/network-tools/compare/e79d8173c5628065da85425bc7e4cb1d94f3c919...073feda14fbd894c4238d693afa38a06392f2360) ### [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix/tree/4fe0c590767f41ca443bdd2688e1decd4f66d60a) * [OCPBUGS-12645](https://issues.redhat.com/browse/OCPBUGS-12645), [OCPBUGS-20879](https://issues.redhat.com/browse/OCPBUGS-20879): bump golang.org/x/net to v0.17.0 [#36](https://github.com/openshift/cloud-provider-nutanix/pull/36) * Updating ose-nutanix-cloud-controller-manager images to be consistent with ART [#15](https://github.com/openshift/cloud-provider-nutanix/pull/15) * [OCPBUGS-13254](https://issues.redhat.com/browse/OCPBUGS-13254): update kubernetes dependencies to 1.26 [#13](https://github.com/openshift/cloud-provider-nutanix/pull/13) * [Full changelog](https://github.com/openshift/cloud-provider-nutanix/compare/8930f295dfa97cc63321c63192c93a78306fe23b...4fe0c590767f41ca443bdd2688e1decd4f66d60a) ### [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix/tree/5f8dfaa95227ce121563ca21a9f1a250bb253aeb) * [OCPBUGS-78157](https://issues.redhat.com/browse/OCPBUGS-78157): hermetic 4.13 [#131](https://github.com/openshift/machine-api-provider-nutanix/pull/131) * [OCPBUGS-51856](https://issues.redhat.com/browse/OCPBUGS-51856): Fixing CVE-2025-22868 [#119](https://github.com/openshift/machine-api-provider-nutanix/pull/119) * [OCPBUGS-47262](https://issues.redhat.com/browse/OCPBUGS-47262): fixing CVE-2024-45338 [#115](https://github.com/openshift/machine-api-provider-nutanix/pull/115) * [OCPBUGS-20976](https://issues.redhat.com/browse/OCPBUGS-20976): bump golang.org/x/net to v0.17.0 [#86](https://github.com/openshift/machine-api-provider-nutanix/pull/86) * [OCPBUGS-24563](https://issues.redhat.com/browse/OCPBUGS-24563): Reduce metrics cardinality [#59](https://github.com/openshift/machine-api-provider-nutanix/pull/59) * [OCPBUGS-25459](https://issues.redhat.com/browse/OCPBUGS-25459): Fix CI by running tests natively by default [#60](https://github.com/openshift/machine-api-provider-nutanix/pull/60) * [OCPBUGS-10493](https://issues.redhat.com/browse/OCPBUGS-10493): Nutanix Hostname of the VM is not set when using DHCP network config [#44](https://github.com/openshift/machine-api-provider-nutanix/pull/44) * [Full changelog](https://github.com/openshift/machine-api-provider-nutanix/compare/c06616804f2de1635fb34fd45fdb625fd0b1b506...5f8dfaa95227ce121563ca21a9f1a250bb253aeb) ### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/6a5971643b971170d28b96f676225b344c4cff3c) * [OCPBUGS-31996](https://issues.redhat.com/browse/OCPBUGS-31996): bump x/net to 0.24.0 [#112](https://github.com/openshift/oauth-apiserver/pull/112) * [OCPBUGS-28674](https://issues.redhat.com/browse/OCPBUGS-28674): Fix HTTP/2 deps for release-4.13 [#102](https://github.com/openshift/oauth-apiserver/pull/102) * [Full changelog](https://github.com/openshift/oauth-apiserver/compare/245539e8902062afc29bb4efa59b4eab7c0bc48f...6a5971643b971170d28b96f676225b344c4cff3c) ### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/44af5a3a021fd158c2e44d9951ad59a3d474cdf3) * [OCPBUGS-16805](https://issues.redhat.com/browse/OCPBUGS-16805): Updating golang-github-openshift-oauth-proxy images to be consistent with ART [#261](https://github.com/openshift/oauth-proxy/pull/261) * [Full changelog](https://github.com/openshift/oauth-proxy/compare/a4a2f270a57af830508e8cef52d4c8d4f4dfba76...44af5a3a021fd158c2e44d9951ad59a3d474cdf3) ### [oauth-server](https://github.com/openshift/oauth-server/tree/eb54be281d8f215a6eaa6e10ed1b303c7d064bac) * [AUTH-443](https://issues.redhat.com/browse/AUTH-443): update osin to latest version [#139](https://github.com/openshift/oauth-server/pull/139) * [OCPBUGS-10888](https://issues.redhat.com/browse/OCPBUGS-10888): bump lib-go for group cache fix, kube 1.24->1.26 [#126](https://github.com/openshift/oauth-server/pull/126) * [Full changelog](https://github.com/openshift/oauth-server/compare/35f4739f342a5838fe6ceaf7a459c78f3777166d...eb54be281d8f215a6eaa6e10ed1b303c7d064bac) ### [oc-mirror](https://github.com/openshift/oc-mirror/tree/96338efcec8152baebfd57036b728697b2fda89a) * changes the owners file (#1012) [#1012](https://github.com/openshift/oc-mirror/pull/1012) * [OCPBUGS-48513](https://issues.redhat.com/browse/OCPBUGS-48513): e2e: use same version of crane as in go.mod (#1025) [#1025](https://github.com/openshift/oc-mirror/pull/1025) * Bump version to include v5.11.0 of go-git (#823) [#823](https://github.com/openshift/oc-mirror/pull/823) * [OCPBUGS-385](https://issues.redhat.com/browse/OCPBUGS-385): Capability to override default channel (#749) (#791) [#749](https://github.com/openshift/oc-mirror/pull/749) * [OCPBUGS-19429](https://issues.redhat.com/browse/OCPBUGS-19429): Fix cross EUS channel upgrade path calculation (#775) [#775](https://github.com/openshift/oc-mirror/pull/775) * [OCPBUGS-21460](https://issues.redhat.com/browse/OCPBUGS-21460): Fix CVE-2023-44487 and CVE-2023-39325 (#714) [#714](https://github.com/openshift/oc-mirror/pull/714) * Fix OCPBUGS-17546: pod catalogsource generated by oc-mirror will crashloopBackOff randomly (#700) [#700](https://github.com/openshift/oc-mirror/pull/700) * Fix OCPBUGS-14402 (#675) [#675](https://github.com/openshift/oc-mirror/pull/675) * [OCPBUGS-18556](https://issues.redhat.com/browse/OCPBUGS-18556): operator catalogs from oc-mirror fail to deploy because of invalid caches (#691) [#691](https://github.com/openshift/oc-mirror/pull/691) * [OCPBUGS-18106](https://issues.redhat.com/browse/OCPBUGS-18106): manual cherrypick (#684) [#684](https://github.com/openshift/oc-mirror/pull/684) * [OCPBUGS-17998](https://issues.redhat.com/browse/OCPBUGS-17998): fix: ICSP with incorrect mirror path (#685) [#685](https://github.com/openshift/oc-mirror/pull/685) * [OCPBUGS-17453](https://issues.redhat.com/browse/OCPBUGS-17453): Fix " OCI index found, but accept header does not support OCI indexes (#677) [#677](https://github.com/openshift/oc-mirror/pull/677) * [OCPBUGS-16372](https://issues.redhat.com/browse/OCPBUGS-16372): A variety of changes needed for correct operation with multi… (#661) [#661](https://github.com/openshift/oc-mirror/pull/661) * [OCPBUGS-13871](https://issues.redhat.com/browse/OCPBUGS-13871): fix: changes on help info content (#654) [#654](https://github.com/openshift/oc-mirror/pull/654) * Fix OCPBUGS-11840: ParseImageReference supports cases where both tag and digest are present in a ref (#637) [#637](https://github.com/openshift/oc-mirror/pull/637) * Removes Ross and adds Jeremy in the OWNER file (#645) [#645](https://github.com/openshift/oc-mirror/pull/645) * [OCPBUGS-13591](https://issues.redhat.com/browse/OCPBUGS-13591), [OCPBUGS-13592](https://issues.redhat.com/browse/OCPBUGS-13592): Limit the nested repository path while mirroring the images (#635) [#635](https://github.com/openshift/oc-mirror/pull/635) * [CFE-658](https://issues.redhat.com/browse/CFE-658): Implementation of filtering by channel for OCI catalog (#628) [#628](https://github.com/openshift/oc-mirror/pull/628) * Deprecate --use-oci-feature in favor of --include-local-oci-catalogs (#621) [#621](https://github.com/openshift/oc-mirror/pull/621) * Update OWNERS for CFE team (#625) [#625](https://github.com/openshift/oc-mirror/pull/625) * Revert adding '--cache-dir /tmp/cache' to catalog images (#616) [#616](https://github.com/openshift/oc-mirror/pull/616) * [OCPBUGS-12259](https://issues.redhat.com/browse/OCPBUGS-12259): fix: skips bundles with 'skips' field on head bundle (#617) [#617](https://github.com/openshift/oc-mirror/pull/617) * fix: work around OCPBUGS-6741 by explicitly setting --cache-dir (#606) [#606](https://github.com/openshift/oc-mirror/pull/606) * [OCPBUGS-11908](https://issues.redhat.com/browse/OCPBUGS-11908): Fix (#607) [#607](https://github.com/openshift/oc-mirror/pull/607) * OCPBUGS-10348 fix: changes to include the registry path (#602) [#602](https://github.com/openshift/oc-mirror/pull/602) * Fix OCPBUGS-8156: Upgrade to containerd v1.6.18 (#596) [#596](https://github.com/openshift/oc-mirror/pull/596) * fix extract dir for cincinnati-graph-data container (#584) [#584](https://github.com/openshift/oc-mirror/pull/584) * Bugfix check imagesetconfig for valid oci protocol when oci feature is used (#595) [#595](https://github.com/openshift/oc-mirror/pull/595) * Remove "unsupported" wording from info on console (#594) [#594](https://github.com/openshift/oc-mirror/pull/594) * Bugfix for destination registry nested paths length (#583) [#583](https://github.com/openshift/oc-mirror/pull/583) * Fix OCPBUGS-5168: Upgrade helm.sh/helm/v3 to v3.11.2 fixing CVE-2022-23526 and CVE-2022-23525 (#592) [#592](https://github.com/openshift/oc-mirror/pull/592) * [OCPBUGS-10051](https://issues.redhat.com/browse/OCPBUGS-10051): fix: remove catalog reference from ImageContentSourcePolicy.yaml (#587) [#587](https://github.com/openshift/oc-mirror/pull/587) * [OCPBUGS-8216](https://issues.redhat.com/browse/OCPBUGS-8216): fix: remove an unecessary error message (#581) [#581](https://github.com/openshift/oc-mirror/pull/581) * docs: add information about unsupported scenario (#578) [#578](https://github.com/openshift/oc-mirror/pull/578) * Updating oc-mirror-plugin images to be consistent with ART (#570) [#570](https://github.com/openshift/oc-mirror/pull/570) * [Full changelog](https://github.com/openshift/oc-mirror/compare/056043d10e0713432e541d58a285f41829c0be6e...96338efcec8152baebfd57036b728697b2fda89a) ### [olm-rukpak](https://github.com/openshift/operator-framework-rukpak/tree/7dde3cd3e7a7dbbc9b5d134cc4f69f1503ed0a68) * : OCPBUGS-27594,OCPBUGS-27679: Update go-git to v5.11.0 [#75](https://github.com/openshift/operator-framework-rukpak/pull/75) * [OCPBUGS-23403](https://issues.redhat.com/browse/OCPBUGS-23403): [release-4.13] Address http2 vulnerability [#58](https://github.com/openshift/operator-framework-rukpak/pull/58) * [OCPBUGS-21363](https://issues.redhat.com/browse/OCPBUGS-21363): [release-4.13] Bump golang.org/x/net to v0.17.0 [#40](https://github.com/openshift/operator-framework-rukpak/pull/40) * UPSTREAM: <carry>: add downstream owners [#42](https://github.com/openshift/operator-framework-rukpak/pull/42) * [OCPBUGS-7683](https://issues.redhat.com/browse/OCPBUGS-7683): Bump helm to v3.11.1 to address CVE-2023-25165 [#19](https://github.com/openshift/operator-framework-rukpak/pull/19) * [OCPBUGS-6447](https://issues.redhat.com/browse/OCPBUGS-6447): bump golang/x/net to v0.4.0 for CVE-2022-41717 [#17](https://github.com/openshift/operator-framework-rukpak/pull/17) * Update owners file [#18](https://github.com/openshift/operator-framework-rukpak/pull/18) * Updating ose-olm-rukpak images to be consistent with ART [#14](https://github.com/openshift/operator-framework-rukpak/pull/14) * image source: avoid shadowing /bin with emptyDir mount [#12](https://github.com/openshift/operator-framework-rukpak/pull/12) * Merge the upstream v0.10.0 rukpak tag [#11](https://github.com/openshift/operator-framework-rukpak/pull/11) * Merge the upstream v0.9.0 tag [#10](https://github.com/openshift/operator-framework-rukpak/pull/10) * Updating ose-olm-rukpak images to be consistent with ART [#9](https://github.com/openshift/operator-framework-rukpak/pull/9) * Add BZ component to OWNERS [#8](https://github.com/openshift/operator-framework-rukpak/pull/8) * downstream sync 8/8/2022 [#7](https://github.com/openshift/operator-framework-rukpak/pull/7) * Ensure the non-e2e CI checks can run successfully [#5](https://github.com/openshift/operator-framework-rukpak/pull/5) * Dockerfile: Disable workspace mode [#4](https://github.com/openshift/operator-framework-rukpak/pull/4) * Bootstrap the rukpak repository [#2](https://github.com/openshift/operator-framework-rukpak/pull/2) * Create OWNERS [#1](https://github.com/openshift/operator-framework-rukpak/pull/1) * And 2 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/operator-framework-rukpak/compare/c9409c62cb6bc57cde167452f1da7f3eab8cff79...7dde3cd3e7a7dbbc9b5d134cc4f69f1503ed0a68) ### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/d6a5de03a7691ee447a323d42fba383ea11d6908) * [OCPBUGS-90519](https://issues.redhat.com/browse/OCPBUGS-90519): Address CVE-2026-35469 [#662](https://github.com/openshift/openshift-apiserver/pull/662) * [OCPBUGS-78596](https://issues.redhat.com/browse/OCPBUGS-78596): Fix image reference in TestImageStreamImportQuayIO [release-4.13] [#622](https://github.com/openshift/openshift-apiserver/pull/622) * [OCPBUGS-76482](https://issues.redhat.com/browse/OCPBUGS-76482): CVE-2025-65637 - Bump github.com/sirupsen/logrus from v1.9.0 to v1.9.3 [release-4.13] [#613](https://github.com/openshift/openshift-apiserver/pull/613) * [OCPBUGS-32446](https://issues.redhat.com/browse/OCPBUGS-32446): bump(x/net) to v0.23.0 [#430](https://github.com/openshift/openshift-apiserver/pull/430) * : OCPBUGS-21449: Enable HTTP/2 CVE mitigation [#398](https://github.com/openshift/openshift-apiserver/pull/398) * [OCPBUGS-6448](https://issues.redhat.com/browse/OCPBUGS-6448): Bump k8s 1.26.2 proof [#361](https://github.com/openshift/openshift-apiserver/pull/361) * [OCPBUGS-8701](https://issues.redhat.com/browse/OCPBUGS-8701): Clear metadata.namespace on projects before write. [#357](https://github.com/openshift/openshift-apiserver/pull/357) * [Full changelog](https://github.com/openshift/openshift-apiserver/compare/b699a1b2211928d91676e46c09bc95b481e9e246...d6a5de03a7691ee447a323d42fba383ea11d6908) ### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/00cef287411eb1f8b69a73bcac0e8e0b2b7e129b) * [OCPBUGS-58035](https://issues.redhat.com/browse/OCPBUGS-58035): Set node-pullsecrets volume to read-only to protect image pull credentials [#402](https://github.com/openshift/openshift-controller-manager/pull/402) * [OCPBUGS-57051](https://issues.redhat.com/browse/OCPBUGS-57051): Empty proxy variables are causing issues during the build [#388](https://github.com/openshift/openshift-controller-manager/pull/388) * [OCPBUGS-48656](https://issues.redhat.com/browse/OCPBUGS-48656): Add new team members to the OWNERS file [#362](https://github.com/openshift/openshift-controller-manager/pull/362) * [release 4.13] OCPBUGS-38407, OCPBUGS-38408: Update opentelemetry dependency [#326](https://github.com/openshift/openshift-controller-manager/pull/326) * [OCPBUGS-41952](https://issues.redhat.com/browse/OCPBUGS-41952): Add adambkaplan as approver [#335](https://github.com/openshift/openshift-controller-manager/pull/335) * [OCPBUGS-11091](https://issues.redhat.com/browse/OCPBUGS-11091): mount build.Spec.Source.ConfigMaps for custom builder images [#257](https://github.com/openshift/openshift-controller-manager/pull/257) * [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/1c76570bb6ca3b55faa0461f085e43097cc06c50...00cef287411eb1f8b69a73bcac0e8e0b2b7e129b) ### [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics/tree/9be421f0c013c7f134c1d7cfe1c0ee2f2ae8eaf6) * [OCPBUGS-20723](https://issues.redhat.com/browse/OCPBUGS-20723): bump `x/net` to v0.17.0 [#108](https://github.com/openshift/openshift-state-metrics/pull/108) * [Full changelog](https://github.com/openshift/openshift-state-metrics/compare/dff4b0f47e639fe2382e8c4c17208fccaacfcbdf...9be421f0c013c7f134c1d7cfe1c0ee2f2ae8eaf6) ### [openstack-cinder-csi-driver-operator](https://github.com/openshift/openstack-cinder-csi-driver-operator/tree/0e50c414d5480c738e7aa685e490c04822a99940) * [OCPBUGS-67685](https://issues.redhat.com/browse/OCPBUGS-67685): Bump logrus [#190](https://github.com/openshift/openstack-cinder-csi-driver-operator/pull/190) * [OCPBUGS-21565](https://issues.redhat.com/browse/OCPBUGS-21565): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#136](https://github.com/openshift/openstack-cinder-csi-driver-operator/pull/136) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#125](https://github.com/openshift/openstack-cinder-csi-driver-operator/pull/125) * [OCPBUGS-17071](https://issues.redhat.com/browse/OCPBUGS-17071): Fix SCC admission failure race during initial deployment [#124](https://github.com/openshift/openstack-cinder-csi-driver-operator/pull/124) * [Full changelog](https://github.com/openshift/openstack-cinder-csi-driver-operator/compare/ae646edbc646b7120891870d23fef2908ac69172...0e50c414d5480c738e7aa685e490c04822a99940) ### [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack/tree/d9ef72dfdf6a5226515f53027a969f49cd82925e) * [OCPBUGS-78174](https://issues.redhat.com/browse/OCPBUGS-78174): hermetic 4.13 [#166](https://github.com/openshift/machine-api-provider-openstack/pull/166) * [OCPBUGS-34422](https://issues.redhat.com/browse/OCPBUGS-34422): Ensure portSecurity is correctly set in the Instance Ports [#119](https://github.com/openshift/machine-api-provider-openstack/pull/119) * Bug OCPBUGS-19460: Set controller's SyncPeriod to 1 hour [#85](https://github.com/openshift/machine-api-provider-openstack/pull/85) * [OCPBUGS-12630](https://issues.redhat.com/browse/OCPBUGS-12630): Address CVE-2022-41723 [#71](https://github.com/openshift/machine-api-provider-openstack/pull/71) * [OCPBUGS-10558](https://issues.redhat.com/browse/OCPBUGS-10558): machineset_controller: Stop caching clouds credentials [#64](https://github.com/openshift/machine-api-provider-openstack/pull/64) * [OCPBUGS-10298](https://issues.redhat.com/browse/OCPBUGS-10298): Use TenantID if ProjectID is empty [#62](https://github.com/openshift/machine-api-provider-openstack/pull/62) * [Full changelog](https://github.com/openshift/machine-api-provider-openstack/compare/471ed47556b6fa51cef6c270e70cc6a48feab0aa...d9ef72dfdf6a5226515f53027a969f49cd82925e) ### [operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/9e62118dc051d9d3983ae7a984927ae658c73bb7) * [OCPBUGS-82051](https://issues.redhat.com/browse/OCPBUGS-82051): Drop github.com/distribution/distribution from go.mod [#1305](https://github.com/openshift/operator-framework-olm/pull/1305) * [OCPBUGS-61470](https://issues.redhat.com/browse/OCPBUGS-61470): [release-4.13] Add NetworkPolicy as a supported kind [#1053](https://github.com/openshift/operator-framework-olm/pull/1053) * [OCPBUGS-61391](https://issues.redhat.com/browse/OCPBUGS-61391): [4.13] e2e stability fixes [#1086](https://github.com/openshift/operator-framework-olm/pull/1086) * [OCPBUGS-46924](https://issues.redhat.com/browse/OCPBUGS-46924), [OCPBUGS-46931](https://issues.redhat.com/browse/OCPBUGS-46931), [OCPBUGS-47311](https://issues.redhat.com/browse/OCPBUGS-47311): x/net bump to v0.34.0 [release-4.13] [#942](https://github.com/openshift/operator-framework-olm/pull/942) * [OCPBUGS-47507](https://issues.redhat.com/browse/OCPBUGS-47507): CRD upgrade existing CR validation fix (#3442) [#924](https://github.com/openshift/operator-framework-olm/pull/924) * NO-ISSUE: [release-4.13] Backport e2e fixes [#876](https://github.com/openshift/operator-framework-olm/pull/876) * [OCPBUGS-42146](https://issues.redhat.com/browse/OCPBUGS-42146): adds paginating lister for evaluating CRs' upgrade fitness versus new CRDs. [#871](https://github.com/openshift/operator-framework-olm/pull/871) * [OCPBUGS-38254](https://issues.redhat.com/browse/OCPBUGS-38254): [CARRY] perform operator apiService certificate validity checks directly [#836](https://github.com/openshift/operator-framework-olm/pull/836) * [OCPBUGS-38608](https://issues.redhat.com/browse/OCPBUGS-38608): (fix) Resolver: list CatSrc using client, instead of referring to registry-server cache (#3349) [#843](https://github.com/openshift/operator-framework-olm/pull/843) * [OCPBUGS-32856](https://issues.redhat.com/browse/OCPBUGS-32856): bump go-jose to v2.6.3 [#780](https://github.com/openshift/operator-framework-olm/pull/780) * [OCPBUGS-35241](https://issues.redhat.com/browse/OCPBUGS-35241): Unblock CI [#772](https://github.com/openshift/operator-framework-olm/pull/772) * [OCPBUGS-27564](https://issues.redhat.com/browse/OCPBUGS-27564), [OCPBUGS-27569](https://issues.redhat.com/browse/OCPBUGS-27569), [OCPBUGS-27649](https://issues.redhat.com/browse/OCPBUGS-27649), [OCPBUGS-27654](https://issues.redhat.com/browse/OCPBUGS-27654): bump go-git/v5 to 5.11.0 [#682](https://github.com/openshift/operator-framework-olm/pull/682) * [OCPBUGS-28228](https://issues.redhat.com/browse/OCPBUGS-28228): Registry Pod Controller Flag [#672](https://github.com/openshift/operator-framework-olm/pull/672) * [OCPBUGS-27891](https://issues.redhat.com/browse/OCPBUGS-27891): [CARRY] SSC RBAC [#669](https://github.com/openshift/operator-framework-olm/pull/669) * [OCPBUGS-8653](https://issues.redhat.com/browse/OCPBUGS-8653): bump golang-migrate to v4.16.1 (#1107) [#649](https://github.com/openshift/operator-framework-olm/pull/649) * [OCPBUGS-20815](https://issues.redhat.com/browse/OCPBUGS-20815): [release-4.13] fix apiserver vulnerability [#616](https://github.com/openshift/operator-framework-olm/pull/616) * [OCPBUGS-22133](https://issues.redhat.com/browse/OCPBUGS-22133): [release-4.13] Bump golang.org/x/net to v0.17.0 [#589](https://github.com/openshift/operator-framework-olm/pull/589) * [OCPBUGS-18305](https://issues.redhat.com/browse/OCPBUGS-18305), [RHIBMCS-151](https://issues.redhat.com/browse/RHIBMCS-151): Copied csv listing backport [#548](https://github.com/openshift/operator-framework-olm/pull/548) * [OCPBUGS-17791](https://issues.redhat.com/browse/OCPBUGS-17791): opm: always serve pprof endpoints, improve server allocations (#1129) [#540](https://github.com/openshift/operator-framework-olm/pull/540) * Introduce DOWNSTREAM_OWNERS file [#538](https://github.com/openshift/operator-framework-olm/pull/538) * Allow cpb to be statically compiled / exempt from FIPS compliance [#519](https://github.com/openshift/operator-framework-olm/pull/519) * [OCPBUGS-15589](https://issues.redhat.com/browse/OCPBUGS-15589): fix dynamic conversion webhook [#499](https://github.com/openshift/operator-framework-olm/pull/499) * [OCPBUGS-13321](https://issues.redhat.com/browse/OCPBUGS-13321): OCPBUGS-1684: Optimize certificate generation [#488](https://github.com/openshift/operator-framework-olm/pull/488) * [OCPBUGS-11469](https://issues.redhat.com/browse/OCPBUGS-11469): [release4.13] exclude bundles with `olm.deprecated` property when rendering [#479](https://github.com/openshift/operator-framework-olm/pull/479) * [Full changelog](https://github.com/openshift/operator-framework-olm/compare/905f2870ad2518975103720e89a41062b448739f...9e62118dc051d9d3983ae7a984927ae658c73bb7) ### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/2a1df4ec9d0216a716ae239921cdbe8ecb3776fd) * [OCPBUGS-49430](https://issues.redhat.com/browse/OCPBUGS-49430): Upgrade golang.org/x/net [release-4.13] [#590](https://github.com/operator-framework/operator-marketplace/pull/590) * [OCPBUGS-32074](https://issues.redhat.com/browse/OCPBUGS-32074): update golang.org/x/net for CVE-2023-45288 [#566](https://github.com/operator-framework/operator-marketplace/pull/566) * [OCPBUGS-20977](https://issues.redhat.com/browse/OCPBUGS-20977): [release-4.13] bump golang.org/x/net to 0.17.0 [#549](https://github.com/operator-framework/operator-marketplace/pull/549) * [OCPBUGS-19085](https://issues.redhat.com/browse/OCPBUGS-19085): Updating marketplace-operator images to be consistent with ART [#538](https://github.com/operator-framework/operator-marketplace/pull/538) * [OCPBUGS-18502](https://issues.redhat.com/browse/OCPBUGS-18502): remove a race condition [#532](https://github.com/operator-framework/operator-marketplace/pull/532) * [OCPBUGS-12979](https://issues.redhat.com/browse/OCPBUGS-12979): update community index to 4.13 tag [#518](https://github.com/operator-framework/operator-marketplace/pull/518) * [OCPBUGS-12789](https://issues.redhat.com/browse/OCPBUGS-12789): update image tag to 4.13 for all but community operators [#516](https://github.com/operator-framework/operator-marketplace/pull/516) * [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/63ccdc559d1944457375d190b4a209ce0c85d27c...2a1df4ec9d0216a716ae239921cdbe8ecb3776fd) ### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/16fa55557367097b075093d2549e0205558c7527) * [OCPBUGS-36094](https://issues.redhat.com/browse/OCPBUGS-36094): Fix CVE-2024-6104 by updating http-retryable to 0.7.7 [#91](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/91) * [OCPBUGS-33638](https://issues.redhat.com/browse/OCPBUGS-33638): Fix CVE2023-45288 by bumping x/net to v0.24.0 -4.13 [#82](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/82) * [OCPBUGS-24728](https://issues.redhat.com/browse/OCPBUGS-24728): synk: ignore vendor dir [#61](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/61) * [OCPBUGS-21089](https://issues.redhat.com/browse/OCPBUGS-21089): CVE-2023-39325 - Update net dependencies - 4.13 [#52](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/52) * Update OWNERS add yussufsh [#54](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/54) * Updated golang.org/x/net/html dependency. [#44](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/44) * Openshiftrelease 4.13 [#41](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/41) * [OCPBUGS-12950](https://issues.redhat.com/browse/OCPBUGS-12950): Updated net dependencies [#31](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/31) * [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/988f7109b4493f62cb13187bc190eae60c77d1e7...16fa55557367097b075093d2549e0205558c7527) ### [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/tree/f5209f48188fdee114946e56f7baff78a0ab87b4) * [OCPBUGS-67694](https://issues.redhat.com/browse/OCPBUGS-67694): Fix CVE-2025-65637 by bumping logrus to v1.8.3 [#101](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/101) * [OCPBUGS-25716](https://issues.redhat.com/browse/OCPBUGS-25716): snyk: ignore vendor dir [#61](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/61) * [OCPBUGS-21186](https://issues.redhat.com/browse/OCPBUGS-21186): CVE-2023-39325 - Update net dependencies - 4.13 [#41](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/41) * Update OWNERS add yussufsh [#45](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/45) * [OCPBUGS-16250](https://issues.redhat.com/browse/OCPBUGS-16250): Add management workloads annotations [#34](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/34) * [OCPBUGS-12656](https://issues.redhat.com/browse/OCPBUGS-12656): Updated net dependencies [#27](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/27) * Adding storage team to OWNERS so they can perform lib-go updates. [#22](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/22) * [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/compare/d89d56a28875917e4d00c61c5eba7a6a6e271f25...f5209f48188fdee114946e56f7baff78a0ab87b4) ### [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs/tree/c040f3774af48d6d0bd8c31188626cb445be5b83) * [OCPBUGS-36104](https://issues.redhat.com/browse/OCPBUGS-36104): UPSTREAM: <carry>: Fix go-retryablehttp CVE 4.13 [#76](https://github.com/openshift/cloud-provider-powervs/pull/76) * [OCPBUGS-24731](https://issues.redhat.com/browse/OCPBUGS-24731): UPSTREAM: <carry>: snyk code scan exclude vendor directory [#53](https://github.com/openshift/cloud-provider-powervs/pull/53) * [OCPBUGS-21280](https://issues.redhat.com/browse/OCPBUGS-21280): CVE-2023-39325 - Update net dependencies - 4.13 [#46](https://github.com/openshift/cloud-provider-powervs/pull/46) * [OCPBUGS-12657](https://issues.redhat.com/browse/OCPBUGS-12657): Updated net dependencies [#34](https://github.com/openshift/cloud-provider-powervs/pull/34) * [Full changelog](https://github.com/openshift/cloud-provider-powervs/compare/19cf1d3f4985a22e9777aad16531a382c4feed45...c040f3774af48d6d0bd8c31188626cb445be5b83) ### [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs/tree/c35d169e1b9f0b27bf9b5dff346dc49d2ad500bd) * [OCPBUGS-78041](https://issues.redhat.com/browse/OCPBUGS-78041): hermetic 4.13 [#137](https://github.com/openshift/machine-api-provider-powervs/pull/137) * [OCPBUGS-54013](https://issues.redhat.com/browse/OCPBUGS-54013): Fix for CVE-2025-30204 & CVE-2024-51744 in github.com/golang-jwt/jwt/v4 in release-4.13 [#122](https://github.com/openshift/machine-api-provider-powervs/pull/122) * [OCPBUGS-41980](https://issues.redhat.com/browse/OCPBUGS-41980): Update go.mod to fix CVE - 4.13 [#87](https://github.com/openshift/machine-api-provider-powervs/pull/87) * [OCPBUGS-24563](https://issues.redhat.com/browse/OCPBUGS-24563): Reduce metrics cardinality [#69](https://github.com/openshift/machine-api-provider-powervs/pull/69) * [OCPBUGS-24741](https://issues.redhat.com/browse/OCPBUGS-24741): snyk code scan exclude vendor directory [#64](https://github.com/openshift/machine-api-provider-powervs/pull/64) * [OCPBUGS-21880](https://issues.redhat.com/browse/OCPBUGS-21880): CVE-2023-39325 - Bump golang.org/x/net to v0.17.0 - 4.13 [#55](https://github.com/openshift/machine-api-provider-powervs/pull/55) * [Full changelog](https://github.com/openshift/machine-api-provider-powervs/compare/dcca41df34618fa0dad8cfceeb79f3afd6d98a4b...c35d169e1b9f0b27bf9b5dff346dc49d2ad500bd) ### [prometheus](https://github.com/openshift/prometheus/tree/59ce8f40e6d3f319e3ca6686384d1c13e608da9a) * [OCPBUGS-86877](https://issues.redhat.com/browse/OCPBUGS-86877): Bump google.golang.org/grpc [#324](https://github.com/openshift/prometheus/pull/324) * [OCPBUGS-67695](https://issues.redhat.com/browse/OCPBUGS-67695): chore: CVE-2025-65637: bump sirupsen/logrus to 1.9.3 [#290](https://github.com/openshift/prometheus/pull/290) * [OCPBUGS-26423](https://issues.redhat.com/browse/OCPBUGS-26423): Add Exemplars support for all time series [#191](https://github.com/openshift/prometheus/pull/191) * [OCPBUGS-21240](https://issues.redhat.com/browse/OCPBUGS-21240): update golang.org/x/net to v0.17.0 [4.13] [#174](https://github.com/openshift/prometheus/pull/174) * [OCPBUGS-12508](https://issues.redhat.com/browse/OCPBUGS-12508): go.mod: update golang.org/x/net to v0.7.0 [#161](https://github.com/openshift/prometheus/pull/161) * [Full changelog](https://github.com/openshift/prometheus/compare/e62d2c6d0239482f97dee43aa92bd463b2c5cb95...59ce8f40e6d3f319e3ca6686384d1c13e608da9a) ### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/a99f9b69568e59152de12f29990d721345c3d5b9) * [OCPBUGS-77849](https://issues.redhat.com/browse/OCPBUGS-77849): Include go-verify-deps expected files in gitignore [#122](https://github.com/openshift/prometheus-alertmanager/pull/122) * [OCPBUGS-21043](https://issues.redhat.com/browse/OCPBUGS-21043): Bump golang.org/x/net to v0.17.0 [#81](https://github.com/openshift/prometheus-alertmanager/pull/81) * [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/f4e6d02ebd3d35951780ef97ce0786f41974f237...a99f9b69568e59152de12f29990d721345c3d5b9) ### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/30fdccd139b2c63a9207bd30509aec8ddec7ff5d) * [OCPBUGS-20861](https://issues.redhat.com/browse/OCPBUGS-20861): Bump golang.org/x/net to v0.17.0 [#248](https://github.com/openshift/prometheus-operator/pull/248) * [OCPBUGS-12672](https://issues.redhat.com/browse/OCPBUGS-12672): update golang.org/x/net [#237](https://github.com/openshift/prometheus-operator/pull/237) * [Full changelog](https://github.com/openshift/prometheus-operator/compare/a4b845a7ae4e1ffb62eae963406481f1c3456bfe...30fdccd139b2c63a9207bd30509aec8ddec7ff5d) ### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/59d699cac664bfbfe83ef6a1615e34e062fd283d) * [OCPBUGS-21143](https://issues.redhat.com/browse/OCPBUGS-21143): upgrade golang.org/x/net to v0.17.0 [#135](https://github.com/openshift/node_exporter/pull/135) * [OCPBUGS-14274](https://issues.redhat.com/browse/OCPBUGS-14274): Upgrade golang.org/x/net to v0.10.0 to fix the CVE [#127](https://github.com/openshift/node_exporter/pull/127) * [Full changelog](https://github.com/openshift/node_exporter/compare/5ee0a9d957a04756ba76623a8bbc12be9949109f...59d699cac664bfbfe83ef6a1615e34e062fd283d) ### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/2a7399846328907956b7e3dc91dd5a1991e7ffae) * [OCPBUGS-86884](https://issues.redhat.com/browse/OCPBUGS-86884): [release-4.13] bump google.golang.org/grpc to v1.64.1-sec.1 [#96](https://github.com/openshift/route-controller-manager/pull/96) * [OCPBUGS-14276](https://issues.redhat.com/browse/OCPBUGS-14276): Bump k8s to 1.26.5 [#26](https://github.com/openshift/route-controller-manager/pull/26) * [Full changelog](https://github.com/openshift/route-controller-manager/compare/9a12e08adc28a8de13eb6e36679db94ff4a518b5...2a7399846328907956b7e3dc91dd5a1991e7ffae) ### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/dba00dc5b1874904542bed87f49974bf64be168a) * [OCPBUGS-28759](https://issues.redhat.com/browse/OCPBUGS-28759): Fix HTTP/2 (4.13) [#232](https://github.com/openshift/service-ca-operator/pull/232) * [OCPBUGS-16806](https://issues.redhat.com/browse/OCPBUGS-16806): Updating ose-service-ca-operator images to be consistent with ART [#214](https://github.com/openshift/service-ca-operator/pull/214) * [Full changelog](https://github.com/openshift/service-ca-operator/compare/3c3f82f7112ee4b5656e5c554f9887acdf881175...dba00dc5b1874904542bed87f49974bf64be168a) ### [telemeter](https://github.com/openshift/telemeter/tree/0634a6d029bfd8fd311e99ccf5f2fd45b5751fa8) * [OCPBUGS-34829](https://issues.redhat.com/browse/OCPBUGS-34829): fix issuer check during JWT authentication 4.13 [#540](https://github.com/openshift/telemeter/pull/540) * [OCPBUGS-21327](https://issues.redhat.com/browse/OCPBUGS-21327): [release-4.13]: Bump golang.org/x/net to v0.17.0 [#485](https://github.com/openshift/telemeter/pull/485) * [OCPBUGS-14418](https://issues.redhat.com/browse/OCPBUGS-14418): Update golang.org/x/net to lastest version [#463](https://github.com/openshift/telemeter/pull/463) * [Full changelog](https://github.com/openshift/telemeter/compare/1f7268163afc74f9f3c1ff89d8c0149760694e6c...0634a6d029bfd8fd311e99ccf5f2fd45b5751fa8) ### [tests](https://github.com/openshift/origin/tree/d14f9b8ec0093014491f498a1efaaa1d1fd57a81) * [OCPBUGS-55954](https://issues.redhat.com/browse/OCPBUGS-55954): [build] Ensure Git Clone Does Not Run Privileged [#29769](https://github.com/openshift/origin/pull/29769) * [OCPBUGS-54771](https://issues.redhat.com/browse/OCPBUGS-54771): Component Readiness: [Networking / ovn-kubernetes] [EgressFirewall] test regressed [#29661](https://github.com/openshift/origin/pull/29661) * [OCPBUGS-53285](https://issues.redhat.com/browse/OCPBUGS-53285): Add/remove team members to the OWNERS file for Builds [#29608](https://github.com/openshift/origin/pull/29608) * [OCPBUGS-53297](https://issues.redhat.com/browse/OCPBUGS-53297): Disable:Broken for [sig-builds][Feature:Builds][Slow] can use private repositories as build input build using an HTTP token should be able to clone source code via an HTTP token [#29610](https://github.com/openshift/origin/pull/29610) * [OCPBUGS-52584](https://issues.redhat.com/browse/OCPBUGS-52584): Use payload pullspec for image info test [#29592](https://github.com/openshift/origin/pull/29592) * [OCPBUGS-37921](https://issues.redhat.com/browse/OCPBUGS-37921): Removes dependency on samples operator images [#29007](https://github.com/openshift/origin/pull/29007) * [OCPBUGS-35053](https://issues.redhat.com/browse/OCPBUGS-35053): updated timeout to 3 seconds to account for network timing issues [#28862](https://github.com/openshift/origin/pull/28862) * [OCPBUGS-36501](https://issues.redhat.com/browse/OCPBUGS-36501): test/extended: skip etcd leader change check on hypershift [#28922](https://github.com/openshift/origin/pull/28922) * [OCPBUGS-35857](https://issues.redhat.com/browse/OCPBUGS-35857): Use centos7 tag instead of latest for cmd images tests [#28895](https://github.com/openshift/origin/pull/28895) * [OCPBUGS-33985](https://issues.redhat.com/browse/OCPBUGS-33985): Provide SCC access via RBAC [#28835](https://github.com/openshift/origin/pull/28835) * [AUTH-443](https://issues.redhat.com/browse/AUTH-443): Add oauth-server redirect URI validation e2e tests [#28396](https://github.com/openshift/origin/pull/28396) * [OCPBUGS-19378](https://issues.redhat.com/browse/OCPBUGS-19378): [4.13] backport etcd restore tests [#28267](https://github.com/openshift/origin/pull/28267) * Bug OCPBUGS-17469: Correct condition for rejecting connection [#28151](https://github.com/openshift/origin/pull/28151) * [OCPBUGS-20361](https://issues.redhat.com/browse/OCPBUGS-20361): Update image stream test to create a manifest list image by default [#28318](https://github.com/openshift/origin/pull/28318) * [OCPBUGS-16241](https://issues.redhat.com/browse/OCPBUGS-16241): Update permission to incl. watch for helmchartrepositories for console users [#28054](https://github.com/openshift/origin/pull/28054) * [OCPBUGS-16164](https://issues.redhat.com/browse/OCPBUGS-16164): allow cluster-config-operator to manage featuregate upgrade block [#28050](https://github.com/openshift/origin/pull/28050) * [OCPBUGS-15892](https://issues.redhat.com/browse/OCPBUGS-15892): remove references to registry.centos.org [#28031](https://github.com/openshift/origin/pull/28031) * [OCPBUGS-15746](https://issues.redhat.com/browse/OCPBUGS-15746): Skip CCM upgradable condition on AlibabaCloud [#28025](https://github.com/openshift/origin/pull/28025) * [OCPBUGS-7762](https://issues.redhat.com/browse/OCPBUGS-7762): Bump with latest openshift/kubernetes at 4.13 [#27973](https://github.com/openshift/origin/pull/27973) * [OCPBUGS-5029](https://issues.redhat.com/browse/OCPBUGS-5029): [release-4.13] OpenStack: Restore in-tree cinder provisioner tests [#27827](https://github.com/openshift/origin/pull/27827) * [OCPBUGS-14342](https://issues.redhat.com/browse/OCPBUGS-14342): Increase timeout in sysctl allowlist test [#27956](https://github.com/openshift/origin/pull/27956) * [OCPBUGS-13840](https://issues.redhat.com/browse/OCPBUGS-13840): Add missing error check in sysctl allowlist test [#27929](https://github.com/openshift/origin/pull/27929) * [OCPBUGS-14127](https://issues.redhat.com/browse/OCPBUGS-14127): Move from registry.centos.org to quay.io [#27948](https://github.com/openshift/origin/pull/27948) * [OCPBUGS-12700](https://issues.redhat.com/browse/OCPBUGS-12700): update-etcd-scaling-test [#27892](https://github.com/openshift/origin/pull/27892) * [CCO-367](https://issues.redhat.com/browse/CCO-367): Allow CCO to be Upgradeable=False when credentialsMode=Manual [#27895](https://github.com/openshift/origin/pull/27895) * [OCPBUGS-11449](https://issues.redhat.com/browse/OCPBUGS-11449): [release-4.13] Allow cluster daemonsets to use maxSurge [#27859](https://github.com/openshift/origin/pull/27859) * [OCPBUGS-12878](https://issues.redhat.com/browse/OCPBUGS-12878): [release-4.13] Add (optional) dual-stack tests to the CNI certification test suite [#27877](https://github.com/openshift/origin/pull/27877) * [OCPBUGS-12271](https://issues.redhat.com/browse/OCPBUGS-12271): test/extended: cpu-partitioning: skip cluster infrastructure for Hypershift [#27885](https://github.com/openshift/origin/pull/27885) * Revert "TRT-889: Temp flake all azure disruption" [#27870](https://github.com/openshift/origin/pull/27870) * [OCPBUGS-11307](https://issues.redhat.com/browse/OCPBUGS-11307): Add test for Egress Firewall node selector [#27845](https://github.com/openshift/origin/pull/27845) * add specific test for failing cgroups path [#27855](https://github.com/openshift/origin/pull/27855) * [OCPBUGS-11335](https://issues.redhat.com/browse/OCPBUGS-11335): fix: add namespace annotation helper for egress cni test [#27848](https://github.com/openshift/origin/pull/27848) * [OCPBUGS-11315](https://issues.redhat.com/browse/OCPBUGS-11315): Increasing limits for Nodes OSUpdateStaged time test [#27847](https://github.com/openshift/origin/pull/27847) * [OCPBUGS-11295](https://issues.redhat.com/browse/OCPBUGS-11295): e2e: Config v1 client shim for static configuration manifests with read-only operations [#27840](https://github.com/openshift/origin/pull/27840) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): DisableSC test should ignore in-tree storage classes [#27831](https://github.com/openshift/origin/pull/27831) * [OCPBUGS-10968](https://issues.redhat.com/browse/OCPBUGS-10968): fix: add poll to get deployment status and avoid false positive [#27825](https://github.com/openshift/origin/pull/27825) * 4.13 disruption/alert data update [#27813](https://github.com/openshift/origin/pull/27813) * [OCPBUGS-10662](https://issues.redhat.com/browse/OCPBUGS-10662): Add cpu partitioning tests [#27812](https://github.com/openshift/origin/pull/27812) * [OCPBUGS-8488](https://issues.redhat.com/browse/OCPBUGS-8488): Realtime Kernel Tests [#27778](https://github.com/openshift/origin/pull/27778) * [TRT-910](https://issues.redhat.com/browse/TRT-910): Temporarily flake ALL P99 disruption tests in 4.13 [#27810](https://github.com/openshift/origin/pull/27810) * [OCPBUGS-9913](https://issues.redhat.com/browse/OCPBUGS-9913): add test for UnhealthyPodEvictionPolicy for PDBs [#27785](https://github.com/openshift/origin/pull/27785) * [OCPBUGS-8412](https://issues.redhat.com/browse/OCPBUGS-8412): Bump(openshift/kubernetes): to get fix for resizing flake [#27792](https://github.com/openshift/origin/pull/27792) * [OCPBUGS-9915](https://issues.redhat.com/browse/OCPBUGS-9915): Temp flake all azure disruption [#27786](https://github.com/openshift/origin/pull/27786) * [OCPBUGS-8742](https://issues.redhat.com/browse/OCPBUGS-8742): Revert "Switch to readyz path for health probes on Azure" [#27784](https://github.com/openshift/origin/pull/27784) * [OCPBUGS-8401](https://issues.redhat.com/browse/OCPBUGS-8401): Bump to 1.26.2 [#27769](https://github.com/openshift/origin/pull/27769) * [Full changelog](https://github.com/openshift/origin/compare/d885e43f7985efe72dbf3e949ea3caf7dcee81b8...d14f9b8ec0093014491f498a1efaaa1d1fd57a81) ### [thanos](https://github.com/openshift/thanos/tree/c48cc849a61be5d66103ef1319d287b186d9fb7d) * [OCPBUGS-76959](https://issues.redhat.com/browse/OCPBUGS-76959): CVE-2025-65637 Update sirupsen/logrus to 1.9.3 [#168](https://github.com/openshift/thanos/pull/168) * [OCPBUGS-27206](https://issues.redhat.com/browse/OCPBUGS-27206): Bump otel/http to 0.44.0 [openshift-4.13.z] [#138](https://github.com/openshift/thanos/pull/138) * [OCPBUGS-21157](https://issues.redhat.com/browse/OCPBUGS-21157): Bump golang.org/x/net to v0.17.0 [#125](https://github.com/openshift/thanos/pull/125) * [OCPBUGS-12663](https://issues.redhat.com/browse/OCPBUGS-12663): go.mod: update golang.org/x/net to v0.7.0 [#109](https://github.com/openshift/thanos/pull/109) * [Full changelog](https://github.com/openshift/thanos/compare/25bdf4b7cf52346785549eb39b3c62803dd95688...c48cc849a61be5d66103ef1319d287b186d9fb7d) ### [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere/tree/117e8a1a3374361c18c57297dabb35a8195be7e8) * [OCPBUGS-78032](https://issues.redhat.com/browse/OCPBUGS-78032): hermetic migration 4.13 [#110](https://github.com/openshift/cloud-provider-vsphere/pull/110) * [OCPBUGS-21506](https://issues.redhat.com/browse/OCPBUGS-21506): Bump golang.org/x/net to v0.18.0 [#55](https://github.com/openshift/cloud-provider-vsphere/pull/55) * [OCPBUGS-17103](https://issues.redhat.com/browse/OCPBUGS-17103): update x/net dependency to 0.7.0 [#46](https://github.com/openshift/cloud-provider-vsphere/pull/46) * [Full changelog](https://github.com/openshift/cloud-provider-vsphere/compare/b1aaff4cb5acd1df600322dbbf5a7b8ee65952e0...117e8a1a3374361c18c57297dabb35a8195be7e8) ### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/fc5cc4b0f7987b9ae6b2141ad2bf7ef0382551bf) * [OCPBUGS-78024](https://issues.redhat.com/browse/OCPBUGS-78024): hermetic migration 4.13 [#89](https://github.com/openshift/cluster-api-provider-vsphere/pull/89) * [OCPBUGS-21556](https://issues.redhat.com/browse/OCPBUGS-21556): bump golang.org/x/net to v0.17.0 [#23](https://github.com/openshift/cluster-api-provider-vsphere/pull/23) * [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/c1758a0d0531d551f47c068762f3b9d232ce7164...fc5cc4b0f7987b9ae6b2141ad2bf7ef0382551bf) ### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/99c8edb4437acd104fd0d1f4389a6ab7e2d4ea1a) * [OCPBUGS-67712](https://issues.redhat.com/browse/OCPBUGS-67712): CVE-2025-65637: Bump github.com/sirupsen/logrus to v1.8.3 [#161](https://github.com/openshift/vmware-vsphere-csi-driver/pull/161) * [OCPBUGS-21561](https://issues.redhat.com/browse/OCPBUGS-21561): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#91](https://github.com/openshift/vmware-vsphere-csi-driver/pull/91) * [OCPBUGS-16398](https://issues.redhat.com/browse/OCPBUGS-16398): Rebase v3.0.2 [#83](https://github.com/openshift/vmware-vsphere-csi-driver/pull/83) * [OCPBUGS-13563](https://issues.redhat.com/browse/OCPBUGS-13563): Fix node resync master [#79](https://github.com/openshift/vmware-vsphere-csi-driver/pull/79) * [OCPBUGS-13162](https://issues.redhat.com/browse/OCPBUGS-13162): Rebase against 3.0.1 version [#77](https://github.com/openshift/vmware-vsphere-csi-driver/pull/77) * [OCPBUGS-11672](https://issues.redhat.com/browse/OCPBUGS-11672): UPSTREAM: 2326: Update opencontainers/runc for CVE-2023-27561 [#69](https://github.com/openshift/vmware-vsphere-csi-driver/pull/69) * [OCPBUGS-11786](https://issues.redhat.com/browse/OCPBUGS-11786), [OCPBUGS-11787](https://issues.redhat.com/browse/OCPBUGS-11787): Add .gitattributes [#70](https://github.com/openshift/vmware-vsphere-csi-driver/pull/70) * [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/96d5fbc02df71945bd76b4bbad3911cf19a2c16e...99c8edb4437acd104fd0d1f4389a6ab7e2d4ea1a) ### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/2762d9ab8d76bb2dce542bc0e76e0662d1f66810) * [OCPBUGS-67711](https://issues.redhat.com/browse/OCPBUGS-67711), [OCPBUGS-67717](https://issues.redhat.com/browse/OCPBUGS-67717): CVE-2025-65637: Bump github.com/sirupsen/logrus to v1.8.3 [#326](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/326) * [OCPBUGS-21434](https://issues.redhat.com/browse/OCPBUGS-21434): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#174](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/174) * [OCPBUGS-18132](https://issues.redhat.com/browse/OCPBUGS-18132): Block 4.14 upgrades with admin ack [#169](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/169) * [OCPBUGS-18332](https://issues.redhat.com/browse/OCPBUGS-18332): disable controller hostNetwork [#166](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/166) * [OCPBUGS-11294](https://issues.redhat.com/browse/OCPBUGS-11294): Add CSI migration metric [#146](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/146) * [OCPBUGS-12478](https://issues.redhat.com/browse/OCPBUGS-12478): Add management workloads annotations [#151](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/151) * [OCPBUGS-12468](https://issues.redhat.com/browse/OCPBUGS-12468): Add backoff for successful storage policy creations [#150](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/150) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): Mark cluster un-upgradeable when CSI migration is disabled [#145](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/145) * [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/6593723fbb3189b25df4634e3b75bb02b5b9e611...2762d9ab8d76bb2dce542bc0e76e0662d1f66810) ### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/692784527ba64bc6e446b2b5d5f623f019914311) * [OCPBUGS-67723](https://issues.redhat.com/browse/OCPBUGS-67723): bump github.com/sirupsen/logrus to v1.9.3 [#203](https://github.com/openshift/vsphere-problem-detector/pull/203) * [OCPBUGS-57511](https://issues.redhat.com/browse/OCPBUGS-57511): Ported VPD changes for permission check [#184](https://github.com/openshift/vsphere-problem-detector/pull/184) * [OCPBUGS-21577](https://issues.redhat.com/browse/OCPBUGS-21577): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#130](https://github.com/openshift/vsphere-problem-detector/pull/130) * [OCPBUGS-14571](https://issues.redhat.com/browse/OCPBUGS-14571): Check all storage classes including CSI storageclasses [#120](https://github.com/openshift/vsphere-problem-detector/pull/120) * [OCPBUGS-14098](https://issues.redhat.com/browse/OCPBUGS-14098): In UPI clusters VSphere platform could be nil [#118](https://github.com/openshift/vsphere-problem-detector/pull/118) * [OCPBUGS-14085](https://issues.redhat.com/browse/OCPBUGS-14085): Log vcenter version information [#117](https://github.com/openshift/vsphere-problem-detector/pull/117) * [OCPBUGS-11146](https://issues.redhat.com/browse/OCPBUGS-11146): Check migration status [#108](https://github.com/openshift/vsphere-problem-detector/pull/108) * [OCPBUGS-10811](https://issues.redhat.com/browse/OCPBUGS-10811): Add build number to metrics [#103](https://github.com/openshift/vsphere-problem-detector/pull/103) * [OCPBUGS-11287](https://issues.redhat.com/browse/OCPBUGS-11287): day 2 multi-zone configuration fails if tags are not defined [#105](https://github.com/openshift/vsphere-problem-detector/pull/105) * [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/664a9e321965e1a6c98cf2551506a8b10a6cf2f6...692784527ba64bc6e446b2b5d5f623f019914311)