Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
3536 commits
Select commit Hold shift + click to select a range
5c0d4d2
Merge pull request #8501 from hjoshi123/feat/xlistenerset-listenerset…
cert-manager-prow[bot] Feb 16, 2026
f10f4e2
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Feb 17, 2026
a66808b
Merge pull request #8517 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Feb 17, 2026
7e94cf3
gatewayapi-listenerset.md: fix second diagram
maelvls Feb 16, 2026
5593772
Merge pull request #8515 from cert-manager/maelvls-patch-1
cert-manager-prow[bot] Feb 17, 2026
45c14f7
simplify finalizer logic & remove useless tests
inteon Feb 17, 2026
45446ac
Merge pull request #8521 from inteon/challenge_finalizer_cleanup
cert-manager-prow[bot] Feb 17, 2026
50ad587
fix(deps): update cloud go deps
renovate[bot] Feb 18, 2026
2efa6f9
Merge pull request #8524 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Feb 19, 2026
4ead253
adding overrides for parentRef
hjoshi123 Feb 17, 2026
b5a7540
chore(deps): update github/codeql-action action to v4.32.4
renovate[bot] Feb 20, 2026
32502fe
fix(deps): update module github.com/aws/smithy-go to v1.24.1
renovate[bot] Feb 21, 2026
decd70e
Merge pull request #8532 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Feb 22, 2026
c4622fc
Merge pull request #8533 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Feb 22, 2026
a2e947f
Merge pull request #8518 from hjoshi123/feat/httproute-parentref-bug
cert-manager-prow[bot] Feb 22, 2026
7f18c99
Always use SSA for finalizer handling
inteon Feb 18, 2026
216a0c8
address all review comments
inteon Feb 23, 2026
6208dfe
bump otel to address https://pkg.go.dev/vuln/GO-2026-4394
SgtCoDFish Feb 23, 2026
2238b3d
Merge pull request #8538 from SgtCoDFish/bump-otel
cert-manager-prow[bot] Feb 23, 2026
09de898
fix(deps): update cloud go deps
renovate[bot] Feb 23, 2026
240d8d1
Merge pull request #8540 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Feb 24, 2026
ead89df
only migrate status to SSA when feature gate is enabled
inteon Feb 24, 2026
5ab70f7
remove non-breaking space characters from comments
SgtCoDFish Feb 25, 2026
41027de
Merge pull request #8543 from SgtCoDFish/remove-nbsp
cert-manager-prow[bot] Feb 25, 2026
528e24f
fix(deps): update module google.golang.org/api to v0.269.0
renovate[bot] Feb 25, 2026
97b0b0e
Merge pull request #8541 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Feb 25, 2026
0dabb84
rename test cases
inteon Feb 26, 2026
f9f713f
change upgradeOptions construction based on PR feedback
inteon Feb 26, 2026
05cdc60
fix(deps): update module sigs.k8s.io/gateway-api to v1.5.0-rc.3
renovate[bot] Feb 26, 2026
115cfd0
fix(deps): update module github.com/digitalocean/godo to v1.176.0
renovate[bot] Feb 26, 2026
8d5e450
Merge pull request #8519 from inteon/ssa_challenge_finalizers
cert-manager-prow[bot] Feb 26, 2026
44dec54
Merge pull request #8545 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Feb 26, 2026
07cce19
chore(deps): update actions/upload-artifact action to v7
renovate[bot] Feb 26, 2026
3da2a47
Merge pull request #8547 from cert-manager/renovate/master-major-misc…
cert-manager-prow[bot] Feb 26, 2026
94754e6
adding support for azure private zones
hjoshi123 Feb 9, 2026
4c353cb
Merge pull request #8494 from hjoshi123/feat/azure-private-zones
cert-manager-prow[bot] Feb 26, 2026
e8959e2
Merge pull request #8542 from cert-manager/renovate/master-sigs.k8s.i…
cert-manager-prow[bot] Feb 26, 2026
7d6a429
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Feb 26, 2026
d3daa3a
Fix/suppress new (gosec) lint errors
erikgb Feb 26, 2026
9badd25
fix(deps): update k8s.io/utils digest to b8788ab
renovate[bot] Feb 26, 2026
e30939b
fix(deps): update module github.com/akamai/akamaiopen-edgegrid-golang…
renovate[bot] Feb 26, 2026
3df86b9
Merge pull request #8550 from cert-manager/renovate/master-k8s.io-uti…
cert-manager-prow[bot] Feb 26, 2026
3c4f6b6
fix(deps): update k8s.io/kube-openapi digest to a19766b
renovate[bot] Feb 26, 2026
3dbe128
Merge pull request #8549 from cert-manager/renovate/master-k8s.io-kub…
cert-manager-prow[bot] Feb 26, 2026
9712d17
Fix akamai v13 breaking chnges
erikgb Feb 26, 2026
9bd43ba
Merge pull request #8551 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Feb 27, 2026
670a8d9
fix(deps): update module k8s.io/kube-aggregator to v0.35.2
renovate[bot] Feb 27, 2026
37878b7
Merge pull request #8556 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Feb 27, 2026
d315f25
fix(deps): update kubernetes go patches to v0.35.2
renovate[bot] Feb 27, 2026
805c7b1
Merge pull request #8557 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Feb 27, 2026
acb1e7f
fix(deps): update module k8s.io/kubectl to v0.35.2
renovate[bot] Feb 27, 2026
b178825
Merge pull request #8558 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Feb 27, 2026
40f67a6
Merge pull request #8548 from erikgb/lint-fixes
cert-manager-prow[bot] Feb 27, 2026
904a77e
Adding regex for Renovate upgrades based on markers (#8555)
erikgb Feb 27, 2026
c824f72
chore(deps): update module sigs.k8s.io/gateway-api to v1.5.0
renovate[bot] Feb 27, 2026
321d510
fix(deps): update module sigs.k8s.io/gateway-api to v1.5.0
renovate[bot] Feb 27, 2026
790d40f
Merge pull request #8559 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Feb 27, 2026
baa5553
Merge pull request #8560 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Feb 27, 2026
c5a1460
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Feb 27, 2026
5891fcb
Merge pull request #8537 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Feb 27, 2026
53a89e1
fix GO-2026-4559 by upgrade to golang.org/x/net@v0.51.0
maelvls Feb 27, 2026
3256746
Merge pull request #8561 from maelvls/fix-GO-2026-4559
cert-manager-prow[bot] Feb 27, 2026
2c0e667
fix(deps): update cloud go deps
renovate[bot] Feb 28, 2026
1e25eb5
Merge pull request #8562 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Feb 28, 2026
e0159ea
added initial tests and code for renewal policies
hjoshi123 Nov 25, 2025
800c147
Update Go documentation badge from godoc.org to pkg.go.dev
archy-rock3t-cloud Mar 2, 2026
3b6a10e
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Mar 3, 2026
3519898
feat(helm): add opt-in ttlSecondsAfterFinished for startupapicheck Job
dap0am Feb 17, 2026
fd9a4ca
Merge pull request #8568 from sophotechlabs/fix/update-godoc-badge-to…
cert-manager-prow[bot] Mar 3, 2026
b192828
Merge pull request #8565 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Mar 3, 2026
fe37983
fix(deps): update cloud go deps
renovate[bot] Mar 4, 2026
5938ce0
Merge pull request #8573 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 4, 2026
6630079
chore(deps): update github/codeql-action action to v4.32.5
renovate[bot] Mar 5, 2026
be6dc8c
Merge pull request #8564 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Mar 5, 2026
1896a29
fix(deps): update module github.com/go-openapi/jsonreference to v0.21.5
renovate[bot] Mar 5, 2026
ba0a890
fix(deps): update module sigs.k8s.io/controller-runtime to v0.23.3
renovate[bot] Mar 5, 2026
aaae97c
Merge pull request #8575 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Mar 5, 2026
7e27be8
fix: harden the creation of private key secrets to avoid creating dup…
ThatsMrTalbot Mar 5, 2026
ade886e
chore(deps): update github/codeql-action action to v4.32.6
renovate[bot] Mar 5, 2026
bad1bb6
trying to fix flaky tests
hjoshi123 Mar 3, 2026
e5a66b1
fix(deps): update module k8s.io/klog/v2 to v2.140.0
renovate[bot] Mar 6, 2026
89d7c25
feat: emit event when passwordSecretRef not found
ThatsMrTalbot Mar 6, 2026
06b8355
Initial plan
Copilot Mar 6, 2026
a78f726
cainjector: promote CAInjectorMerging feature gate to GA (v1.21)
Copilot Mar 6, 2026
19365ff
Merge pull request #8583 from cert-manager/copilot/promote-cainjector…
cert-manager-prow[bot] Mar 7, 2026
60c5fb4
fix(deps): update golang.org/x deps
renovate[bot] Mar 8, 2026
eb398a6
Merge pull request #8587 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Mar 8, 2026
86c6668
Merge pull request #8580 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Mar 9, 2026
427bbdf
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Mar 9, 2026
ae8ad67
Merge pull request #8589 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Mar 9, 2026
3ec23e3
configure contextual test logger for controller-runtime webhook only
inteon Mar 9, 2026
ecb6e08
Merge pull request #8590 from inteon/webhook_test_logger
cert-manager-prow[bot] Mar 9, 2026
d054c32
disable metrics server for test webhook
inteon Mar 9, 2026
f1b48ba
Merge pull request #8595 from inteon/disable_metrics_server
cert-manager-prow[bot] Mar 9, 2026
c3e1443
Merge pull request #8566 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Mar 9, 2026
6eaa3a7
Merge pull request #8581 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Mar 9, 2026
4f40b60
fix(deps): update module google.golang.org/api to v0.270.0
renovate[bot] Mar 10, 2026
63cec98
Merge pull request #8593 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 10, 2026
46f66d4
Merge pull request #8579 from ThatsMrTalbot/fix/harden-private-key-se…
cert-manager-prow[bot] Mar 10, 2026
869f802
Merge pull request #8582 from ThatsMrTalbot/feat/emit-event-when-pass…
cert-manager-prow[bot] Mar 10, 2026
ce25333
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Mar 11, 2026
a7ca5e8
Merge pull request #8601 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Mar 11, 2026
825062e
fix(deps): update cloud go deps
renovate[bot] Mar 11, 2026
8502981
remove incorrect github.com/segmentio/encoding dependency
inteon Mar 11, 2026
e22afb5
Merge pull request #8603 from cert-manager/remove_dependency
cert-manager-prow[bot] Mar 11, 2026
974785d
Merge pull request #8600 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 11, 2026
a151651
fix(deps): update module golang.org/x/crypto to v0.49.0
renovate[bot] Mar 12, 2026
dde59df
Merge pull request #8605 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Mar 12, 2026
8a682f7
helm's readme.md: point to the supported releases page
maelvls Mar 12, 2026
eec9834
Merge pull request #8607 from maelvls/fix-kubernetes-version
cert-manager-prow[bot] Mar 12, 2026
8f6f17d
added flag for renewal check on failure
hjoshi123 Mar 1, 2026
2cf241c
fix(deps): update cloud go deps
renovate[bot] Mar 13, 2026
60fcccc
chore(deps): update module sigs.k8s.io/gateway-api to v1.5.1
renovate[bot] Mar 14, 2026
b29c0a6
fix(deps): update module sigs.k8s.io/gateway-api to v1.5.1
renovate[bot] Mar 14, 2026
330e711
fix(keymanager): preserve expected secret when cleaning up duplicates…
putongyong Mar 14, 2026
e0e6fbc
Merge pull request #8617 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Mar 15, 2026
daf25fe
Merge pull request #8616 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Mar 15, 2026
b6be3f6
Merge pull request #8615 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 16, 2026
896d503
chore(deps): update github/codeql-action action to v4.33.0
renovate[bot] Mar 16, 2026
ef17439
fix(deps): update cloud go deps
renovate[bot] Mar 16, 2026
2d4d4b4
Merge pull request #8621 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 17, 2026
ec90906
Merge pull request #8620 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Mar 17, 2026
9ba6ff0
fix(deps): update module github.com/go-ldap/ldap/v3 to v3.4.13
renovate[bot] Mar 18, 2026
aacc273
Merge pull request #8623 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Mar 18, 2026
8ba0941
remove deprecated ObjectReference
inteon Mar 19, 2026
a7118f6
Merge pull request #8625 from cert-manager/remove_objectreference
cert-manager-prow[bot] Mar 19, 2026
09d6a83
chore(deps): update module google.golang.org/grpc to v1.79.3 [security]
renovate[bot] Mar 19, 2026
f5528ff
fix(deps): update kubernetes go patches to v0.35.3
renovate[bot] Mar 19, 2026
1ddacc8
Merge pull request #8627 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Mar 19, 2026
e65233a
chore(deps): update github/codeql-action action to v4.34.0
renovate[bot] Mar 20, 2026
b374495
Merge pull request #8635 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Mar 20, 2026
3d70790
Merge pull request #8407 from inteon/use_typed_predicates
cert-manager-prow[bot] Mar 20, 2026
341faa3
Merge pull request #8571 from hjoshi123/fix/flaky-ls-tests
cert-manager-prow[bot] Mar 20, 2026
8d6c1c8
removing duplicate parentRefs
hjoshi123 Mar 16, 2026
788c2f2
Merge pull request #8619 from hjoshi123/fix/remove-duplicate-parentRef
cert-manager-prow[bot] Mar 20, 2026
1756a82
removing flag and always renewing on window failure
hjoshi123 Mar 14, 2026
1f06dd5
chore(deps): update github/codeql-action action to v4.34.1
renovate[bot] Mar 20, 2026
a4de43e
venafi: remove unused RenewCertificate method from Connector interface
Nishant-k-sagar Mar 22, 2026
15baece
Merge pull request #8258 from hjoshi123/feat/renewal-policy-windows
cert-manager-prow[bot] Mar 23, 2026
ab24644
feat: Add AWS authentication method for Vault Issuer (#8422)
bitloi Mar 23, 2026
204cd8b
Merge pull request #8638 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Mar 23, 2026
ae623f8
fix(deps): update misc go deps
renovate[bot] Mar 23, 2026
6d83eb6
fix(webhook): cache negative API discovery results in certificateRequ…
mateenali66 Mar 24, 2026
5aea634
Merge pull request #8626 from cert-manager/renovate/master-go-google.…
cert-manager-prow[bot] Mar 24, 2026
52bddef
Merge pull request #8646 from Nishant-k-sagar/remove-dead-RenewCertif…
cert-manager-prow[bot] Mar 24, 2026
aaf97c9
Merge pull request #8633 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Mar 25, 2026
589d82d
fix(webhook): evict expired negative cache entries in isNegativelyCached
mateenali66 Mar 26, 2026
2ff4c7b
test(e2e): wait for CRD establishment before approval tests
mateenali66 Mar 26, 2026
6372d90
test(e2e): wait for CRD to be discoverable before approval tests
mateenali66 Mar 26, 2026
bd5c75d
test(e2e): fix nilerr lint: restructure transient discovery error han…
mateenali66 Mar 26, 2026
7051d2a
fix(webhook): only cache negative discovery results when group is reg…
mateenali66 Mar 26, 2026
ba49235
Fixed infinite re-issuance loop when issuer returns an already expire…
onurmicoogullari Mar 13, 2026
7ea87f7
fix(deps): update cloud go deps
renovate[bot] Mar 27, 2026
b4009b8
Fix RBAC to support clusters with OwnerReferencesPermissionEnforcemen…
erikgb Mar 27, 2026
a69eb16
Merge pull request #8654 from erikgb/fix-owner-ref-rbac
cert-manager-prow[bot] Mar 27, 2026
580117d
Bump release branches considered by Renovate
erikgb Mar 27, 2026
d2f7413
Merge pull request #8651 from mateenali66/fix/issue-8644-negative-api…
cert-manager-prow[bot] Mar 27, 2026
f916ff0
chore(deps): update github/codeql-action action to v4.35.1
renovate[bot] Mar 27, 2026
eb6899b
Merge pull request #8660 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Mar 28, 2026
ea0ff61
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Mar 28, 2026
21ab2e4
fix: address new golangci-lint v2.11.3 violations
Copilot Mar 28, 2026
46204a0
Merge pull request #8604 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Mar 28, 2026
93a048b
Merge pull request #8652 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 28, 2026
a860e59
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Mar 29, 2026
4c1589f
Merge pull request #8662 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Mar 29, 2026
9ce33d5
fix(cainjector): clarify secret annotation mismatch log (#8647)
naveenkgrg Mar 29, 2026
c4b186a
Fix indentation in webhook-deployment when both webhook.volumes and w…
jnohlgard Mar 30, 2026
2e45c01
Merge pull request #8664 from jnohlgard/helm-webhook-deployment-indent
cert-manager-prow[bot] Mar 30, 2026
073a3be
fix(deps): update cloud go deps
renovate[bot] Mar 30, 2026
99f0c0c
Merge pull request #8666 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Mar 31, 2026
70ad773
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 2, 2026
401b3e1
Merge pull request #8673 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 2, 2026
03e39c4
Merge pull request #8675 from erikgb/bump-release-branches
cert-manager-prow[bot] Apr 2, 2026
5baaed2
fix(deps): update cloud go deps
renovate[bot] Apr 2, 2026
4f292d9
Merge pull request #8669 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Apr 3, 2026
6e74edc
chore(deps): update module github.com/go-jose/go-jose/v4 to v4.1.4 [s…
renovate[bot] Apr 3, 2026
af1edf1
Merge pull request #8676 from cert-manager/renovate/master-go-github.…
cert-manager-prow[bot] Apr 3, 2026
27514ea
Full re-generation
erikgb Apr 3, 2026
2c965cd
Merge pull request #8677 from erikgb/regen
cert-manager-prow[bot] Apr 3, 2026
0007286
Improve CAInjector SSA code
erikgb Apr 3, 2026
fa5486a
fix(deps): update module github.com/cloudflare/cloudflare-go/v6 to v6…
renovate[bot] Apr 3, 2026
6057c30
feat(gateway): make Gateway API TLS protocols configurable
ThatsMrTalbot Apr 4, 2026
a232cb0
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 6, 2026
df6152a
Merge pull request #8684 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 6, 2026
987a811
Merge pull request #8680 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Apr 6, 2026
7409d5b
Merge pull request #8678 from erikgb/cainjector-ssa-improve
cert-manager-prow[bot] Apr 7, 2026
07728df
Fix typo in Order Duration field comment
archy-rock3t-cloud Mar 2, 2026
1485395
Merge pull request #8567 from sophotechlabs/fix/typo-as-per-acme-orde…
cert-manager-prow[bot] Apr 7, 2026
fd74ef8
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 7, 2026
b44fb4a
Merge pull request #8689 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 7, 2026
932bd64
adding helm unittest targets
hjoshi123 Apr 7, 2026
1d5755d
fix(deps): update module github.com/hashicorp/vault/sdk to v0.25.1
renovate[bot] Apr 7, 2026
437c314
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 8, 2026
1941a04
Merge pull request #8694 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 8, 2026
6dd6a8c
Merge pull request #8693 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Apr 9, 2026
50bbe17
chore(deps): update module go.opentelemetry.io/otel/sdk to v1.43.0 [s…
renovate[bot] Apr 9, 2026
d698af4
Merge pull request #8695 from cert-manager/renovate/master-go-go.open…
cert-manager-prow[bot] Apr 9, 2026
1244536
fix(deps): update module golang.org/x/crypto to v0.50.0
renovate[bot] Apr 9, 2026
f83bb57
Merge pull request #8700 from cert-manager/renovate/master-golang.org…
cert-manager-prow[bot] Apr 9, 2026
34fe4fa
chore(deps): update base images
renovate[bot] Apr 10, 2026
42a2592
Merge pull request #8701 from cert-manager/renovate/master-base-images
cert-manager-prow[bot] Apr 10, 2026
4717746
chore(deps): update actions/upload-artifact action to v7.0.1
renovate[bot] Apr 10, 2026
52f2e40
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 11, 2026
0523778
Merge pull request #8708 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 11, 2026
4ba78fc
Merge pull request #8707 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Apr 11, 2026
e6bbc98
Merge pull request #8523 from dap0am/feature/startupapicheck-ttlSecon…
cert-manager-prow[bot] Apr 12, 2026
4837022
Migrate upgrade e2e test to Helm OCI
erikgb Apr 13, 2026
43ceb12
Merge pull request #8711 from erikgb/upgrade-test-oci
cert-manager-prow[bot] Apr 13, 2026
f77a389
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 13, 2026
9bda588
Merge pull request #8710 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 13, 2026
d25cddb
fix(deps): update misc go deps
renovate[bot] Apr 13, 2026
fef26cc
Merge pull request #8699 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Apr 13, 2026
93e3cfd
chore: refactor gateway-api-extra-protocols to use sets based on PR f…
ThatsMrTalbot Apr 13, 2026
b144e1a
Merge pull request #8610 from onurmicoogullari/fix/expired-cert-reiss…
cert-manager-prow[bot] Apr 14, 2026
6087920
fix(deps): update cloud go deps
renovate[bot] Apr 14, 2026
07f6470
Merge pull request #8691 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Apr 15, 2026
fcf5093
Merge pull request #8683 from ThatsMrTalbot/feat/gateway-configurable…
cert-manager-prow[bot] Apr 15, 2026
ccc8cac
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 16, 2026
ac5fc6d
fix(deps): update module sigs.k8s.io/structured-merge-diff/v6 to v6.4.0
renovate[bot] Apr 16, 2026
b338e77
Merge pull request #8719 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 16, 2026
9e677d7
fix(deps): update kubernetes go patches to v0.35.4
renovate[bot] Apr 16, 2026
dad8157
Merge pull request #8721 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Apr 16, 2026
7cc2413
Merge pull request #8690 from hjoshi123/fix/helm-unittest-targets
cert-manager-prow[bot] Apr 16, 2026
2906014
Merge pull request #8720 from cert-manager/renovate/master-kubernetes…
cert-manager-prow[bot] Apr 16, 2026
a30e022
chore(deps): update github/codeql-action action to v4.35.2
renovate[bot] Apr 16, 2026
c232d6b
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 17, 2026
2ddb865
Remove leftover references to legacy Helm repo
erikgb Apr 16, 2026
c03e0a4
Merge pull request #8725 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 17, 2026
a1348ff
Merge pull request #8724 from erikgb/remove-legacy-chart-leftovers
cert-manager-prow[bot] Apr 17, 2026
10b8ecf
fix(deps): update module github.com/venafi/vcert/v5 to v5.13.1
renovate[bot] Apr 17, 2026
2ab9c52
BOT: run 'make upgrade-klone' and 'make generate'
cert-manager-bot Apr 18, 2026
d73d487
Merge pull request #8728 from cert-manager/self-upgrade-master
cert-manager-prow[bot] Apr 18, 2026
aad2e29
fix(deps): update cloud go deps
renovate[bot] Apr 18, 2026
1a5ae9e
Merge pull request #8715 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Apr 18, 2026
34b9615
Merge pull request #8714 from cert-manager/renovate/master-misc-githu…
cert-manager-prow[bot] Apr 18, 2026
e654879
Merge pull request #8726 from cert-manager/renovate/master-misc-go-deps
cert-manager-prow[bot] Apr 18, 2026
f293cbc
feat: move enableGatewayAPI/enableGatewayAPIListenerSet into GatewayA…
ThatsMrTalbot Apr 18, 2026
81bb25b
chore: ignore .claude AI workspace directory
ThatsMrTalbot Apr 18, 2026
85a9952
test: fix TestControllerConfigurationDefaults and TestRoundTripTypes
ThatsMrTalbot Apr 18, 2026
de88871
chore: update values.yaml comment to reflect GatewayAPIConfig struct
ThatsMrTalbot Apr 19, 2026
77d5375
adding listener ignore annotation
hjoshi123 Apr 17, 2026
78ef907
fix(deps): update module github.com/digitalocean/godo to v1.187.0
renovate[bot] Apr 22, 2026
49f86f7
Merge pull request #8727 from hjoshi123/feat/gwapi-listener-ignore
cert-manager-prow[bot] Apr 22, 2026
e416444
Merge pull request #8741 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Apr 23, 2026
2eb5beb
Merge pull request #8732 from ThatsMrTalbot/feat/gateway-api-config-s…
cert-manager-prow[bot] Apr 23, 2026
59d77cb
Feature/ignore namespaces (#8614)
figaw Apr 23, 2026
94628e5
fix(deps): update cloud go deps
renovate[bot] Apr 23, 2026
efbb9cd
Merge pull request #8744 from cert-manager/renovate/master-cloud-go-deps
cert-manager-prow[bot] Apr 24, 2026
14169eb
fix(deps): update module github.com/onsi/ginkgo/v2 to v2.28.2
renovate[bot] Apr 27, 2026
b796510
Merge pull request #8750 from cert-manager/renovate/master-github.com…
cert-manager-prow[bot] Apr 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 0 additions & 2 deletions .bazelignore

This file was deleted.

7 changes: 0 additions & 7 deletions .bazelrc

This file was deleted.

9 changes: 9 additions & 0 deletions .clomonitor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# License scanning information
licenseScanning:
# URL with the repository's license scanning results
#
# CLOMonitor can extract license scanning results from FOSSA and Snyk badges
# in the repository README.md file automatically. If your repository uses a
# different scanning solution, this url can be set to pass the corresponding
# check.
url: https://github.com/cert-manager/cert-manager/blob/master/LICENSES
6 changes: 3 additions & 3 deletions .github/ISSUE_TEMPLATE/bug.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ about: Report a bug to help us improve cert-manager
<!--
Bugs should be filed for issues encountered whilst operating cert-manager.
You should first attempt to resolve your issues through the community support
channels, e.g. Slack, in order to rule out individual configuration errors.
channels, e.g., Slack, in order to rule out individual configuration errors.
Please provide as much detail as possible.
-->

Expand All @@ -30,10 +30,10 @@ gain an understanding of the problem.-->

**Anything else we need to know?**:

**Environment details:**:
**Environment details**:
- Kubernetes version:
- Cloud-provider/provisioner:
- cert-manager version:
- Install method: e.g. helm/static manifests
- Install method: e.g., helm/static manifests

/kind bug
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/feature-request.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ about: Suggest an idea to improve cert-manager
- Kubernetes version:
- Cloud-provider/provisioner:
- cert-manager version:
- Install method: e.g. helm/static manifests
- Install method: e.g., helm/static manifests


/kind feature
7 changes: 6 additions & 1 deletion .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,14 @@ Thanks for opening a pull request! Here are some tips to get everything merged s

### Kind

<!--
The kind(s) listed after "kind" after this comment will be used by a bot to add labels when the PR is opened.
If omitted at PR creation, someone will need to make a new comment with them later (editing the description after the fact will not trigger the bot).
-->
/kind
<!--

Pick a kind which best describes your PR from the following list:
Pick the kind(s) which best describe your PR from the following list:

<cleanup | bug | feature | documentation | design | flake>

Expand Down
10 changes: 10 additions & 0 deletions .github/chainguard/make-self-upgrade.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/repository-base/base/.github/chainguard/make-self-upgrade.sts.yaml instead.

issuer: https://token.actions.githubusercontent.com
subject_pattern: ^repo:cert-manager/cert-manager:ref:refs/heads/(main|master)$

permissions:
contents: write
pull_requests: write
workflows: write
79 changes: 79 additions & 0 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
{
$schema: 'https://docs.renovatebot.com/renovate-schema.json',
extends: [
'github>cert-manager/makefile-modules:renovate-config.json5'
],
baseBranchPatterns: [
'master',
'release-1.20',
'release-1.19',
],
addLabels: [
'kind/cleanup',
'release-note-none',
],
customManagers: [
{
customType: 'regex',
managerFilePatterns: [
'make/base_images.mk',
],
matchStrings: [
'(?<depName>gcr\\.io\/[^@]+)@(?<currentDigest>sha256:[a-f0-9]{64})',
],
datasourceTemplate: 'docker',
// this tag must match the tag used in hack/latest-base-images.sh
currentValueTemplate: 'nonroot'
},
{
customType: 'regex',
managerFilePatterns: [
'hack/latest-kind-images.sh',
'make/02_mod.mk',
],
matchStrings: [
"#\\s*renovate:\\s*datasource=(?<datasource>\\S+)\\s+packageName=(?<packageName>\\S+)\\s*\\n(?<varName>[A-Za-z0-9_]+)\\s*(?::=|\\?=|=)\\s*(?<currentValue>\\S+)"
]
},
],
packageRules: [
{
groupName: 'Base Images',
matchManagers: [
'custom.regex',
],
},
{
groupName: null,
matchManagers: [
'custom.regex',
],
matchPackageNames: [
'kubernetes-sigs/kind',
],
postUpgradeTasks: {
commands: [
'hack/latest-kind-images.sh',
],
},
},
{
matchBaseBranches: [
'/^release-.*/',
],
enabled: false,
},
{
matchBaseBranches: [
'/^release-.*/',
],
matchUpdateTypes: [
'patch',
'pin',
'pinDigest',
'digest',
],
enabled: true,
},
],
}
37 changes: 37 additions & 0 deletions .github/workflows/govulncheck.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/go/base/.github/workflows/govulncheck.yaml instead.

# Run govulncheck at midnight every night on the main branch,
# to alert us to recent vulnerabilities which affect the Go code in this
# project.
name: govulncheck
on:
workflow_dispatch: {}
schedule:
- cron: '0 0 * * *'

permissions:
contents: read

jobs:
govulncheck:
runs-on: ubuntu-latest

if: github.repository == 'cert-manager/cert-manager'

steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Adding `fetch-depth: 0` makes sure tags are also fetched. We need
# the tags so `git describe` returns a valid version.
# see https://github.com/actions/checkout/issues/701 for extra info about this option
with: { fetch-depth: 0 }

- id: go-version
run: |
make print-go-version >> "$GITHUB_OUTPUT"

- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ steps.go-version.outputs.result }}

- run: make verify-govulncheck
114 changes: 114 additions & 0 deletions .github/workflows/make-self-upgrade.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
# THIS FILE IS AUTOMATICALLY GENERATED. DO NOT EDIT.
# Edit https://github.com/cert-manager/makefile-modules/blob/main/modules/repository-base/base/.github/workflows/make-self-upgrade.yaml instead.

name: make-self-upgrade
concurrency: make-self-upgrade
on:
workflow_dispatch: {}
schedule:
- cron: '0 0 * * *'

permissions:
contents: read

jobs:
self_upgrade:
runs-on: ubuntu-latest

if: github.repository == 'cert-manager/cert-manager'

permissions:
id-token: write

env:
SOURCE_BRANCH: "${{ github.ref_name }}"
SELF_UPGRADE_BRANCH: "self-upgrade-${{ github.ref_name }}"

steps:
- name: Fail if branch is not head of branch.
if: ${{ !startsWith(github.ref, 'refs/heads/') && env.SOURCE_BRANCH != '' && env.SELF_UPGRADE_BRANCH != '' }}
run: |
echo "This workflow should not be run on a non-branch-head."
exit 1

- name: Octo STS Token Exchange
uses: octo-sts/action@f603d3be9d8dd9871a265776e625a27b00effe05 # v1.1.1
id: octo-sts
with:
scope: 'cert-manager/cert-manager'
identity: make-self-upgrade

- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Adding `fetch-depth: 0` makes sure tags are also fetched. We need
# the tags so `git describe` returns a valid version.
# see https://github.com/actions/checkout/issues/701 for extra info about this option
with:
fetch-depth: 0
token: ${{ steps.octo-sts.outputs.token }}

- id: go-version
run: |
make print-go-version >> "$GITHUB_OUTPUT"

- uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: ${{ steps.go-version.outputs.result }}

- run: |
git checkout -B "$SELF_UPGRADE_BRANCH"

- run: |
make -j upgrade-klone
make -j generate

- id: is-up-to-date
shell: bash
run: |
git_status=$(git status -s)
is_up_to_date="true"
if [ -n "$git_status" ]; then
is_up_to_date="false"
echo "The following changes will be committed:"
echo "$git_status"
fi
echo "result=$is_up_to_date" >> "$GITHUB_OUTPUT"

- if: ${{ steps.is-up-to-date.outputs.result != 'true' }}
run: |
git config --global user.name "cert-manager-bot"
git config --global user.email "cert-manager-bot@users.noreply.github.com"
git add -A && git commit -m "BOT: run 'make upgrade-klone' and 'make generate'" --signoff
git push -f origin "$SELF_UPGRADE_BRANCH"

- if: ${{ steps.is-up-to-date.outputs.result != 'true' }}
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
with:
github-token: ${{ steps.octo-sts.outputs.token }}
script: |
const { repo, owner } = context.repo;
const pulls = await github.rest.pulls.list({
owner: owner,
repo: repo,
head: owner + ':' + process.env.SELF_UPGRADE_BRANCH,
base: process.env.SOURCE_BRANCH,
state: 'open',
});

if (pulls.data.length < 1) {
const result = await github.rest.pulls.create({
title: '[CI] Merge ' + process.env.SELF_UPGRADE_BRANCH + ' into ' + process.env.SOURCE_BRANCH,
owner: owner,
repo: repo,
head: process.env.SELF_UPGRADE_BRANCH,
base: process.env.SOURCE_BRANCH,
body: [
'This PR is auto-generated to bump the Makefile modules.',
].join('\n'),
});
await github.rest.issues.addLabels({
owner,
repo,
issue_number: result.data.number,
labels: ['ok-to-test', 'skip-review', 'release-note-none', 'kind/cleanup']
});
}
55 changes: 55 additions & 0 deletions .github/workflows/scorecards.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: Scorecards supply-chain security
on:
# Only the default branch is supported.
branch_protection_rule:
schedule:
- cron: '43 13 * * 6'
push:
branches: [ "master" ]

# Declare default permissions as read only.
permissions: read-all

jobs:
analysis:
name: Scorecards analysis
runs-on: ubuntu-latest
if: github.ref_name == github.event.repository.default_branch
permissions:
# Needed to upload the results to code-scanning dashboard.
security-events: write
# Used to receive a badge.
id-token: write

steps:
- name: "Checkout code"
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false

- name: "Run analysis"
uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
with:
results_file: results.sarif
results_format: sarif

# Publish the results for public repositories to enable scorecard badges. For more details, see
# https://github.com/ossf/scorecard-action#publishing-results.
# For private repositories, `publish_results` will automatically be set to `false`, regardless
# of the value entered here.
publish_results: true

# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: "Upload artifact"
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: SARIF file
path: results.sarif
retention-days: 5

# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@95e58e9a2cdfd71adc6e0353d5c52f41a045d225 # v4.35.2
with:
sarif_file: results.sarif
5 changes: 3 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,14 @@
/hack/build/dockerfiles/cert-manager-*_*_*
.vscode
.venv
bazel-*
/.settings/
/.project
_artifacts/
/vendor/
bin/
_bin/
.bin/
user.bazelrc
*.bak
/go.work.sum
**/go.work
.claude
Loading