Skip to content

fix(deps): update bump-dependencies#6

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate.bump-dependencies
Open

fix(deps): update bump-dependencies#6
renovate[bot] wants to merge 1 commit into
mainfrom
renovate.bump-dependencies

Conversation

@renovate

@renovate renovate Bot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/GoogleCloudPlatform/prometheus-engine v0.8.0v0.17.2 age confidence require minor
github.com/prometheus/client_golang v1.23.2v1.24.1 age confidence require minor
golang (source) 1.25.12-alpine1.26.5-alpine age confidence stage minor

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

GoogleCloudPlatform/prometheus-engine (github.com/GoogleCloudPlatform/prometheus-engine)

v0.17.2

Compare Source

v0.17.0

Compare Source

We have just released version v0.17.0 of our managed collection for Kubernetes and v2.53.5-gmp.0 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.34 or newer. Self-deployed collection users should upgrade their binaries to use v2.53.5-gmp.0-gke.13.

Changes in managed collection v0.17.0:

[FEATURE] VPA is now expanded to all GMP components (b8427b45e).
[FEATURE] Added the --grafana-api-token-filepath flag to the datasource-syncer (85e3bc5d0).
[FEATURE] Added log level flags to the frontend and rule-evaluator (ea0e58aa2, 4a68fa476).
[FEATURE] Added /api/v1/status/buildinfo endpoint for Grafana compatibility (16440f14a).
[FEATURE] Webhook validation is now performed using CEL expressions (bc5cd97bc, ef84205e6, adeb41d19, e700f5a1e, 00200bcea, fd42d6434, 40af9fb7b, d4edf985e, 99aa5116f).
[ENHANCEMENT] Upgraded to Prometheus v2.53.5 (ff932eec2, 4a32e4be4, 719d6e36b, a79ab1562).
[ENHANCEMENT] Updated various dependencies, including Kubernetes APIs and client libraries, to their latest versions (f4a0f0b24, ecdf31c26, 64300fb03, 7c4bab33c, 71142b9c5, 1da3e4b90, 5635c20d3).
[BUGFIX] Fixed an issue where the operator did not propagate the correct compression for collection (c60d3bbd5).
[BUGFIX] Fixed an issue where endpoint statuses were not cleared for PodMonitoring without endpoints (903f7ecd5, a342d9b79).
[BUGFIX] Fixed a typo in Dockerfiles for TARGETARCH (f4579b120).
[BUGFIX] Fixed an issue where podmonitorings were not defaulted correctly (8bd22c64b).
[BUGFIX] Fixed an issue where the collector config was exported with an empty string (c8695de5d, 3190e05e3).
[BUGFIX] Fixed an issue where the frontend version was invalid (e2cd07628).
[BUGFIX] Fixed an issue where the frompod source label was not validated (d5ed65858).
[BUGFIX] Fixed an issue where rule name patterns were incorrect (6abd2625b).
[BUGFIX] Fixed an issue where gke-managed-component nodes were not tolerated (5fe14e06d).
[SECURITY] Updated Go version to 1.24.1 to include the latest security patches (d65df00de, a6e7572f4, cf6fe7124, bcfe05caa, 2a523aded, cd4a76836, 4349fa7a4).
[SECURITY] Updated Docker base images to include the latest security patches (f4a0f0b24, a58a8ef4a, 10c5314b0, 88ace122a, ef6fa4ad7, b62d0b63e, 341340a63, bc98998a7, 7d50e0159).
[SECURITY] Addressed vulnerabilities by bumping libc and other dependencies (3aa0c2858, 0cb26d856, f98d068a2).

v0.15.3

Compare Source

v0.15.1

Compare Source

We have just released version v0.15.1 of our managed collection for Kubernetes and v2.45.3-gmp.10-gke.0 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.32 or newer. Self-deployed collection users should upgrade their binaries to use v2.45.3-gmp.10-gke.0.

Changes in managed collection v0.15.1 (compared to 0.14.0):

  • [SECURITY] Upgraded Go dependencies.
  • [ENHANCEMENT] Switched to Google maintained google-go.pkg.dev/golang images for building Go code.
  • [ENHANCEMENT] By default operator configures collection relabelling to add top_level_controller and top_level_controller_type labels that tracks the controller type and name for pod workloads. For example a pod from the deployment dpl-foo should have top_level_controller="dpl-foo", top_level_controller_type="Deployment" labels added to all metrics.

Changes in self-deployed collection v2.45.3-gmp.10-gke.0:

  • [SECURITY] Upgraded Go and UI dependencies.

v0.14.1

Compare Source

v0.14.0

Compare Source

We have just released version v0.14.0 of our managed collection for Kubernetes and v2.45.3-gmp.9-gke.0 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.31 or newer. Self-deployed collection users should upgrade their binaries to use v2.45.3-gmp.9-gke.0.

Changes in managed collection v0.14.0:

  • [SECURITY] Use scale subresource to update replica counts.
  • [SECURITY] Do not automount initcontainer service account token in Managed Alertmanager.
  • [SECURITY] Remove operator RBAC permissions to update managed collector, rule-evaluator, and alertmanager deployments.
  • [ENHANCEMENT] Add mdox formating and binary flag doc autogen for better READMEs for our binaries.
  • [ENHANCEMENT] Prevent collector pod restarts on startup.
  • [ENHANCEMENT] Default OperatorConfig's external labels for project_id, location, and cluster from values passed to or auto-discovered by the operator to be explicit about relabeling.
  • [ENHANCEMENT] Default to Google Cloud links for Alerts in Managed Alertmanager.
  • [ENHANCEMENT] Allow updating collector, rule-evaluator, and alertmanager options at runtime.
  • [ENHANCEMENT] Add samples sent error counter gcm_export_samples_sent_errors_total when encountering errors on export.
  • [ENHANCEMENT] Allow GRAFANA_SERVICE_ACCOUNT_TOKEN environment variable for datasource-syncer
  • [ENHANCEMENT] Use protobuf encoding for core K8s API communication
  • [BUGFIX] cadvisor and kubelet ClusterNodeMonitoring examples regex fix.

Changes in self-deployed collection v2.45.3-gmp.9-gke.0:

  • [ENHANCEMENT] Google Cloud settings can now be configured via the config file. This allows operators to update Prometheus without needing DaemonSet PATCH/UPDATE RBAC permissions.

EDIT(June 2025): breaking change We accidently turned off operatorconfig.collection.filter feature and decided to deprecate and remove this feature going forward (details). See the https://cloud.google.com/stackdriver/docs/managed-prometheus/setup-managed#filter-metrics for the alternatives to use instead. Apologies for any inconvenience, we will make our best to catch those breakage before release.

v0.13.1

Compare Source

We have just released version v0.13.1 of our managed collection for Kubernetes.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.30 or newer.

Changes in managed collection v0.13.1:

  • [BUGFIX] Fix an issue where target status reporting errors when parsing ClusterNodeMonitoring configs for cadvisor and kubelet scraping.

v0.13.0

Compare Source

We have just released version v0.13.0 of our managed collection for Kubernetes and v2.45.3-gmp.9 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.31 or newer. Self-deployed collection users should upgrade their binaries to use v2.45.3-gmp.9.

Changes in managed collection v0.13.0:

  • [FEATURE] Vertifical Pod Autoscaling (VPA) can now be enabled via OperatorConfig.
  • [ENHANCEMENT] Collectors now skip WAL playback on startup, which can avoid slow startup and crashloop issues.
  • [ENHANCEMENT] Webhooks are now optional. In this case, the operator now performs validation and updates the status subresources in the reconcile loop.
  • [ENHANCEMENT] Add status field to Rules, ClusterRules, and GlobalRules to inform whether a successful configuration was generated or not.
  • [ENHANCEMENT] ClusterNodeMonitoring now supports insecure-skip-verify, achieving full feature parity with the existing Kubelet scraping configuration.
  • [ENHANCEMENT] The collector and rule-evaluator can now start up without previously flags if there is no configuration to parse.
  • [SECURITY] Use readOnlyRootFilesystem where possible to mitigate attack vectors.
  • [SECURITY] Disable automountServiceAccountToken for the alertmanager, which does not use the K8s API.
  • [BUGFIX] Fix ARM64 builds by using upstream go bas image.
  • [BUGFIX] Allow datasource-syncer manifest to run on ARM64 nodes.
  • [BUGFIX] Use the shard count value instead of batch size when handling sample export.

v0.12.1

Compare Source

We have just released version v0.12.1 of our managed collection for Kubernetes and v2.45.3-gmp.7 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.29 or newer. Self-deployed collection users should upgrade their binaries to use v2.45.3-gmp.7.

Changes in managed collection v0.12.1:

  • [ENHANCEMENT] Use Docker image tags in manifests.
  • [BUGFIX] Use proper regex for ClusterNodeMonitoring example to collect kubelet and cadvisor metrics.

v0.12.0

We have just released version v0.12.0 of our managed collection for Kubernetes and v2.45.3-gmp.7-rc.0 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.28 or newer. Self-deployed collection users should upgrade their binaries to use v2.45.3-gmp.7-rc.0.

Changes in managed collection v0.12.0:

  • [ENHANCEMENT] Added support for specifying a remote write URL.
  • [ENHANCEMENT] Enabled Boringcrypto.
  • [ENHANCEMENT] Added support for compression for Rules resources.
  • [ENHANCEMENT] Added the ability to reference BasicAuth passwords used to authenticate against scrape endpoints.
  • [ENHANCEMENT] Added the ability to reference Authentication credentials used to authenticate against scrape endpoints.
  • [ENHANCEMENT] Added the ability to reference OAuth client secrets used to authenticate against scrape endpoints.
  • [ENHANCEMENT] Added the ability to reference TLS certificates used to authenticate against scrape endpoints.
  • [ENHANCEMENT] The operator now supports healthz and readyz endpoints.
  • [BUGFIX] Config reloader is more resiliant against errors.

v0.10.0

Compare Source

We have just released version v0.10.0 of our managed collection for Kubernetes and prometheus:v2.43.1-gmp.0-gke.0 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation. Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.27 or newer. Self-deployed collection users should upgrade their binaries to use gke.gcr.io/prometheus-engine/prometheus:v2.43.1-gmp.0-gke.0.

Changes in managed collection v0.10.0:

  • [ENHANCEMENT] Introduced the datasource-syncer as a preferred way to authorize Grafana for querying, replacing the frontend binary.
    • [ENHANCEMENT] Added mTLS parameters for datasource-syncer.
  • [ENHANCEMENT] Added mTLS settings (excluding certificates) for scrape configurations.
  • [ENHANCEMENT] Removed some unused RBAC permissions.
  • [ENHANCEMENT] Managed Rule-evaluator and Alertmanager now scale down when no rules or alerts are configured.
  • [ENHANCEMENT] Added BasicAuth Username setting for scrape endpoints (password coming soon)
  • [ENHANCEMENT] Added Authorization Header Scheme setting for scrape endpoints (credentials coming soon)
  • [ENHANCEMENT] Added OAuth 2 settings (excluding client secrets) for scrape endpoints
  • [ENHANCEMENT] Add support for web.external-url for managed alertmanager
  • [SECURITY] Reduce RBAC permissions of components

v0.8.2

Compare Source

We have just released version v0.8.2 of our managed collection for Kubernetes and prometheus:v2.41.0-gmp.9-gke.0 of self-deployed collection.

Users who deploy managed collection using kubectl should reapply the manifests in the documentation.

Users who deploy the service using gcloud or the GKE UI are being upgraded on clusters running version 1.25 or newer.

Self-deployed collection users should upgrade their binaries to use gke.gcr.io/prometheus-engine/prometheus:v2.41.0-gmp.9-gke.0.

Changes in managed collection v0.8.2:

prometheus/client_golang (github.com/prometheus/client_golang)

v1.24.1

Compare Source

v1.24.0: - 2026-07-20

Compare Source

Changes
  • [CHANGE] Minimum required Go version is now 1.25, only the two latest Go versions (1.25 and 1.26) are supported from now on. #​1862
  • [CHANGE] prometheus: Name validation now always uses the UTF-8 scheme instead of the deprecated model.NameValidationScheme global. Default behavior is unchanged; code that set NameValidationScheme = LegacyValidation no longer gets legacy enforcement at metric, label, and push-grouping construction. #​2051
  • [CHANGE] api/prometheus/v1: Support matchers (matches[] parameter) in Rules method (Rules(ctx context.Context, matches []string) (RulesResult, error)). #​1843
  • [CHANGE] api/prometheus/v1: Refactor LabelNames method to return model.LabelNames instead of []string for consistency across the API. #​1850
  • [CHANGE] exp/api/remote: Simplify Store interface, rename Handler to WriteHandler, and encapsulate write response handling. #​1855
  • [FEATURE] prometheus: Add new Go 1.26 runtime metrics (/sched/goroutines-created:goroutines, /sched/goroutines/not-in-go:goroutines, /sched/goroutines/runnable:goroutines, /sched/goroutines/running:goroutines, /sched/goroutines/waiting:goroutines, /sched/threads/total:threads). #​1942
  • [FEATURE] prometheus: Add WithUnit(unit string) option and explicit OpenMetrics unit support in CounterOpts, GaugeOpts, SummaryOpts, and HistogramOpts. #​1392
  • [FEATURE] prometheus: Expose descriptor construction error through public Err() method on Desc. #​1902
  • [FEATURE] promhttp: Add opt-in HandlerOpts.CoalesceGather to deduplicate concurrent Gather calls so overlapping scrapes share one collection cycle, preventing goroutine pile-up when the scrape rate outpaces collection time. #​1969
  • [FEATURE] promhttp: HTTP handlers created by promhttp package now support metrics filtering by providing one or more name[] query parameters. The default behavior when none are provided remains the same, returning all metrics. #​1925
  • [FEATURE] api/prometheus/v1: Add query formatting endpoint support (/format_query) and FormatQuery(ctx context.Context, query string) (string, error) method. #​1846, #​1856
  • [FEATURE] api/prometheus/v1: Add support for /status/tsdb/blocks endpoint via TSDBBlocks(ctx context.Context) ([]TSDBBlock, error) method. #​1896
  • [FEATURE] exp/api/remote: Export BackoffConfig to allow customization when using WithAPIBackoff. #​1895
  • [FEATURE] exp/api/remote: Add RetryCallBack to allow custom logging or handling on retry attempts in the remote write client. #​1888, #​1890
  • [ENHANCEMENT] prometheus/collectors/version: Allow specifying custom labels when registering the version collector. #​1860
  • [ENHANCEMENT] api: Use cloned http.DefaultTransport when constructing default HTTP clients to prevent accidental mutations of shared global transport state. #​1885
  • [BUGFIX] prometheus: Recover from collector panics during Gather() and return an error instead of crashing the process. #​1961
  • [BUGFIX] prometheus: Fix cpu-seconds unit suffix handling for metric go_cpu_classes_gc_mark_assist_cpu_seconds. #​1991
  • [BUGFIX] promhttp: InstrumentHandlerDuration and InstrumentHandlerCounter no longer panic when given an observer/counter that does not implement ExemplarObserver/ExemplarAdder (e.g. a SummaryVec). The exemplar is dropped and the value is recorded via the plain Observe/Add path, matching the safe-cast already used by Timer.ObserveDurationWithExemplar. #​2005
  • [BUGFIX] api/prometheus/v1: Fall back to GET requests when POST requests return 403 Forbidden or method not allowed. #​2030
  • [BUGFIX] api: Respect context cancellation inside httpClient.Do. #​1971
  • [BUGFIX] exp/api/remote: Fix compression buffer pooling where compressed buffers were released prematurely, causing corrupted remote-write payloads. #​1889
  • [BUGFIX] exp/api/remote: Reject malformed snappy payloads declaring huge decoded sizes. Enforce a 32MB decoded-size limit to prevent OOM from oversized remote-write requests. #​1917
  • [BUGFIX] exp/api/remote: Ensure remote write v2 headers cannot be returned on v1 requests. #​1927
All commits

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Wednesday (* * * * 3)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate

renovate Bot commented Mar 25, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: go.sum
Command failed: go get -t ./...
go: downloading github.com/GoogleCloudPlatform/prometheus-engine v0.17.2
go: downloading github.com/prometheus/client_golang v1.24.1
go: downloading github.com/prometheus/common v0.70.1
go: downloading github.com/prometheus/procfs v0.21.1
go: downloading golang.org/x/sys v0.47.0
go: downloading golang.org/x/net v0.57.0
go: downloading golang.org/x/text v0.40.0
go: github.com/libops/cap/scraper imports
	github.com/GoogleCloudPlatform/prometheus-engine/pkg/export: cannot find module providing package github.com/GoogleCloudPlatform/prometheus-engine/pkg/export

@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 3 times, most recently from 17c22c7 to 1860de5 Compare April 13, 2026 20:58
@renovate renovate Bot changed the title fix(deps): update bump-dependencies fix(deps): update module github.com/googlecloudplatform/prometheus-engine to v0.17.2 Apr 13, 2026
@renovate renovate Bot changed the title fix(deps): update module github.com/googlecloudplatform/prometheus-engine to v0.17.2 fix(deps): update bump-dependencies to v0.17.2 Jun 2, 2026
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 2 times, most recently from 878582e to 3f60522 Compare June 13, 2026 22:51
@renovate renovate Bot changed the title fix(deps): update bump-dependencies to v0.17.2 fix(deps): update bump-dependencies Jun 13, 2026
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch from 3f60522 to 2b3a2dc Compare June 13, 2026 22:54
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch from 2b3a2dc to 9659c5e Compare June 21, 2026 17:15
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 2 times, most recently from 3b06b37 to da6cac4 Compare July 9, 2026 11:53
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch 2 times, most recently from 42e5ee1 to c395c28 Compare July 15, 2026 11:29
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch from c395c28 to 3bb76dd Compare July 20, 2026 05:00
@renovate
renovate Bot force-pushed the renovate.bump-dependencies branch from 3bb76dd to cc9150e Compare July 25, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants