Skip to content

Bump github.com/stacklok/toolhive from 0.3.7 to 0.5.0 in /kagenti-webhook#10

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/kagenti-webhook/github.com/stacklok/toolhive-0.5.0
Closed

Bump github.com/stacklok/toolhive from 0.3.7 to 0.5.0 in /kagenti-webhook#10
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/kagenti-webhook/github.com/stacklok/toolhive-0.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 27, 2025

Copy link
Copy Markdown
Contributor

Bumps github.com/stacklok/toolhive from 0.3.7 to 0.5.0.

Release notes

Sourced from github.com/stacklok/toolhive's releases.

v0.5.0

What's Changed

Full Changelog: stacklok/toolhive@v0.4.2...v0.5.0

v0.4.2

What's Changed

Full Changelog: stacklok/toolhive@v0.4.1...v0.4.2

v0.4.1

🚀 Toolhive v0.4.1 is live!

This release focuses on improved networking flexibility, observability enhancements, and better resource efficiency in Kubernetes deployments.

Networking & Infrastructure • Added --network option for more flexible network configurations • Kubernetes agents can now be merged between local and project-specific setups for streamlined deployments

Observability & Telemetry • Custom OpenTelemetry resource attributes are now supported for richer trace metadata • Registry data source API added for better integration and data access

Developer Experience • New /check-contribution command added to Claude integration for easier contribution validation • Controller helpers extracted into dedicated package for cleaner codebase architecture • MCPServer CRD size reduced by optimizing PodTemplateSpec handling

... (truncated)

Commits
  • d80d678 Run task operator-manifests (#2334)
  • 398e5bf Update registry from toolhive-registry release v2025.10.27 (#2332)
  • 977eabf Update registry from toolhive-registry release v2025.10.26 (#2331)
  • 3492223 adds new port values for MCPServer CRD (#2330)
  • e2e4614 Update registry from toolhive-registry release v2025.10.25 (#2308)
  • 18b05d0 Add GitHub.com OAuth authentication provider for token introspection (#2322)
  • bb0e6c9 Add SecretKeyRef support to InlineOIDCConfig for enhanced secret management (...
  • 3fffdcc fix: prevent zombie supervisor processes on restart (#2306)
  • 915c1e5 Fix MCPServer and MCPRemoteProxy operator spec change reconciliation (#2320)
  • 0083fd7 Add environment variable support for OIDC client secret (#2325)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/stacklok/toolhive](https://github.com/stacklok/toolhive) from 0.3.7 to 0.5.0.
- [Release notes](https://github.com/stacklok/toolhive/releases)
- [Changelog](https://github.com/stacklok/toolhive/blob/main/.goreleaser.yaml)
- [Commits](stacklok/toolhive@v0.3.7...v0.5.0)

---
updated-dependencies:
- dependency-name: github.com/stacklok/toolhive
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 27, 2025

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, go. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Nov 3, 2025

Copy link
Copy Markdown
Contributor Author

Superseded by #15.

@dependabot dependabot Bot closed this Nov 3, 2025
@dependabot
dependabot Bot deleted the dependabot/go_modules/kagenti-webhook/github.com/stacklok/toolhive-0.5.0 branch November 3, 2025 23:36
huang195 added a commit to huang195/kagenti-extensions that referenced this pull request May 7, 2026
Must-fix:
- rossoctl#1+rossoctl#7: Plugins spawned credential watchers with initCtx (60s), so a
  slow client-registration orphaned the plugin after Start's deadline
  and OnRequest returned 503 for the pod's lifetime. Watchers now run
  on process-lifetime contexts created in Init via context.Background()
  + context.WithCancel; the cancel func is stored on the plugin and
  fired in Shutdown. Both JWTValidation and TokenExchange now
  implement pipeline.Shutdowner. Removed the orphaned
  context.WithCancel at main.go:89 that looked like it was meant to
  be that context.

- rossoctl#2: testutil.go moved out of the plugins package into a dedicated
  sub-package authlib/plugins/plugintesting/ so it can't be imported
  by the production binary. Rewrote the helpers as stub plugin
  adapters that mimic jwt-validation / token-exchange OnRequest but
  don't touch plugin internals — listener tests inject an
  *auth.Auth via plugintesting.NewJWTValidation / NewTokenExchange,
  wire through plugintesting.BuildPipeline, and never see the real
  Configure path. All four listener tests updated.

- rossoctl#11: Removed identity sub-validation that applyDefaults made
  unreachable; class-of-error compensated by logging a boot-time
  WARN when Configure's best-effort ReadCredentialFile fails (see
  also rossoctl#12).

Suggestions:
- rossoctl#3: pollCredentials no longer mutates p.cfg. Reads credential
  values into locals and feeds them through auth.UpdateIdentity. cfg
  is now immutable after Configure returns. Added a
  buildClientAuthFrom helper that takes explicit args so the
  goroutine doesn't read p.cfg either.

- rossoctl#4: Rewrote the NoTokenPolicy doc comment to state the current
  behavior ("deny in all modes; operators who need allow or
  client-credentials must set it explicitly") instead of referring
  to the removed config.NoTokenPolicyForMode.

- rossoctl#5: Deleted unused DefaultInboundPlugins/DefaultOutboundPlugins
  and the whole defaults.go file. Fixed the stale PipelineConfig
  docstring in config.go that said "defaults kick in when
  pipeline section is omitted" — they don't.

- rossoctl#6: PluginEntry.UnmarshalYAML normalizes explicit `config: null`
  (and any other !!null-tagged scalar under `config:`) to a nil
  RawMessage, so Build's "plugin does not accept configuration"
  gate doesn't fire spuriously on the four bytes "null".

- rossoctl#12: Deleted unreachable validate() branches: static-mode's
  audience emptiness check, spiffe's missing-path check,
  client-secret's missing-id / missing-secret checks. applyDefaults
  fills the matching field in every case; the branches were dead
  code that obscured what the plugin actually validated.

Nits:
- rossoctl#8: Renamed TestPluginEntry_IDDefaultsToName →
  TestPluginEntry_IDOmittedStaysEmpty.

- rossoctl#9: TestBuild_ConfigForNonConfigurablePlugin now asserts the error
  text contains "does not accept configuration" — operator-facing
  contract.

- rossoctl#10: Renamed TestConfigurable_ErrorAborts →
  TestConfigurable_ErrorPropagates and noted in the comment that
  Build-level abort coverage lives in plugins_test.go.

- rossoctl#13: Documented on jwtValidationConfig.AudienceFile that empty-
  string is treated as "unset" and triggers the default. Operators
  who want no file backing must supply an explicit Audience.

- rossoctl#14: Added TestAuthbridgeCombinedYAML_Loads — parses the in-repo
  authbridge-combined.yaml with env vars set, asserts both inbound
  and outbound pipelines Build cleanly. A future rename of any
  default constant that the YAML relies on breaks this test in CI
  rather than silently shipping a broken image.

Assisted-By: Claude (Anthropic AI) <noreply@anthropic.com>
Signed-off-by: Hai Huang <huang195@gmail.com>
huang195 added a commit to huang195/kagenti-extensions that referenced this pull request May 7, 2026
Must-fix:
- rossoctl#1+rossoctl#7: Plugins spawned credential watchers with initCtx (60s), so a
  slow client-registration orphaned the plugin after Start's deadline
  and OnRequest returned 503 for the pod's lifetime. Watchers now run
  on process-lifetime contexts created in Init via context.Background()
  + context.WithCancel; the cancel func is stored on the plugin and
  fired in Shutdown. Both JWTValidation and TokenExchange now
  implement pipeline.Shutdowner. Removed the orphaned
  context.WithCancel at main.go:89 that looked like it was meant to
  be that context.

- rossoctl#2: testutil.go moved out of the plugins package into a dedicated
  sub-package authlib/plugins/plugintesting/ so it can't be imported
  by the production binary. Rewrote the helpers as stub plugin
  adapters that mimic jwt-validation / token-exchange OnRequest but
  don't touch plugin internals — listener tests inject an
  *auth.Auth via plugintesting.NewJWTValidation / NewTokenExchange,
  wire through plugintesting.BuildPipeline, and never see the real
  Configure path. All four listener tests updated.

- rossoctl#11: Removed identity sub-validation that applyDefaults made
  unreachable; class-of-error compensated by logging a boot-time
  WARN when Configure's best-effort ReadCredentialFile fails (see
  also rossoctl#12).

Suggestions:
- rossoctl#3: pollCredentials no longer mutates p.cfg. Reads credential
  values into locals and feeds them through auth.UpdateIdentity. cfg
  is now immutable after Configure returns. Added a
  buildClientAuthFrom helper that takes explicit args so the
  goroutine doesn't read p.cfg either.

- rossoctl#4: Rewrote the NoTokenPolicy doc comment to state the current
  behavior ("deny in all modes; operators who need allow or
  client-credentials must set it explicitly") instead of referring
  to the removed config.NoTokenPolicyForMode.

- rossoctl#5: Deleted unused DefaultInboundPlugins/DefaultOutboundPlugins
  and the whole defaults.go file. Fixed the stale PipelineConfig
  docstring in config.go that said "defaults kick in when
  pipeline section is omitted" — they don't.

- rossoctl#6: PluginEntry.UnmarshalYAML normalizes explicit `config: null`
  (and any other !!null-tagged scalar under `config:`) to a nil
  RawMessage, so Build's "plugin does not accept configuration"
  gate doesn't fire spuriously on the four bytes "null".

- rossoctl#12: Deleted unreachable validate() branches: static-mode's
  audience emptiness check, spiffe's missing-path check,
  client-secret's missing-id / missing-secret checks. applyDefaults
  fills the matching field in every case; the branches were dead
  code that obscured what the plugin actually validated.

Nits:
- rossoctl#8: Renamed TestPluginEntry_IDDefaultsToName →
  TestPluginEntry_IDOmittedStaysEmpty.

- rossoctl#9: TestBuild_ConfigForNonConfigurablePlugin now asserts the error
  text contains "does not accept configuration" — operator-facing
  contract.

- rossoctl#10: Renamed TestConfigurable_ErrorAborts →
  TestConfigurable_ErrorPropagates and noted in the comment that
  Build-level abort coverage lives in plugins_test.go.

- rossoctl#13: Documented on jwtValidationConfig.AudienceFile that empty-
  string is treated as "unset" and triggers the default. Operators
  who want no file backing must supply an explicit Audience.

- rossoctl#14: Added TestAuthbridgeCombinedYAML_Loads — parses the in-repo
  authbridge-combined.yaml with env vars set, asserts both inbound
  and outbound pipelines Build cleanly. A future rename of any
  default constant that the YAML relies on breaks this test in CI
  rather than silently shipping a broken image.

Assisted-By: Claude (Anthropic AI) <noreply@anthropic.com>
Signed-off-by: Hai Huang <huang195@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants