chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.5.1 - #6845
chore(deps): bump github.com/siderolabs/image-factory from 1.3.3 to 1.5.1#6845dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [github.com/siderolabs/image-factory](https://github.com/siderolabs/image-factory) from 1.3.3 to 1.5.1. - [Release notes](https://github.com/siderolabs/image-factory/releases) - [Changelog](https://github.com/siderolabs/image-factory/blob/main/CHANGELOG.md) - [Commits](siderolabs/image-factory@v1.3.3...v1.5.1) --- updated-dependencies: - dependency-name: github.com/siderolabs/image-factory dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
✅MegaLinter analysis: Success✅ Linters with no issuesactionlint, bash-exec, git_diff, hadolint, jscpd, jsonlint, lychee, markdown-table-formatter, markdownlint, prettier, prettier, shellcheck, shfmt, stylelint, syft, trivy-sbom, trufflehog, v8r, v8r, yamllint Notices
See detailed reports in MegaLinter artifacts
|
Parked on a named blocker — recording it here, because this PR carried no blocker record. Blocker: #6776 | last-verified 2026-09-02: still OPEN ( Why this bump is affected even though it never mentions Talos. Verified live on this PR's current head
Why it cannot self-progress. The branch is Not actionable as a rebase or a recreate. Unblocks when #6776 lands. |
Parked on a named, live-verified blocker: #6728 — same root cause as #6826, reached by a different route.
A rebase will not fix this one. Worth stating explicitly, because #6839 sitting alongside it is rebase-fixable — its only failing check is Live-verified today (module proxy): Control: Left open and parked; it becomes mergeable once the vcluster stack supports k8s 0.37. |
Pull request was converted to draft
Attempted a base-update rescue, aborted it, and re-confirmed the park on #6728Sibling PR #6839 was rescued this tick by a plain branch update — its only red check was a What I did, so the state change is on the record: converted to draft (which also dropped the Why it cannot be rescued mechanically. The local build failed with the same signature as this
Both hit That is exactly the chain already documented in #6728, which stays the named blocker. Re-verified Also worth recording, since it cost time on #6839: |
This bump is still wanted — @dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
Following up on my own rebase request above, which was rejected — Dependabot replied that the branch "has been edited by someone other than Dependabot", so it cannot rebase this PR. That is a permanent property of the branch, not a transient failure: I should also have led with the blocker rather than the conflict. The conflict is a symptom; the reason this PR cannot land is #6728 — Leaving this parked on #6728, which is the correct terminal state. No action needed. |
|
A newer version of github.com/siderolabs/image-factory exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Blocker: #6776 | last-verified 2026-09-04: still OPEN ( Re-verified live this run rather than inherited from the 2026-09-02 record. #6776 ("Migrate off the Terminal state unchanged: parked on a named, live-verified blocker. |
Blocker: #6776 | last-verified 2026-09-06: still OPEN ( Re-read live this run: #6776 ("Migrate off the removed Talos MachineConfig.Kubelet / ClusterConfig.CoreDNS accessors") remains open and Terminal state unchanged: parked on a named, live-verified blocker. The head is DIRTY and Dependabot has forfeited the rebase, so it cannot self-heal. |
Parked on a named blocker: #6913. Diagnosed rather than retried. Every failing check here traces to one build error, not to flakiness or to the conflict with the base branch: This branch resolves Both modules are indirect, so nothing in this update's stated intent asks for the release candidate — which is why a rebase is not the fix here. Re-resolving the same graph reproduces the same pre-release pick. The constraint has to change first; that is what the linked issue covers. No adaptation commit pushed: the correct fix constrains the module graph for every future bump rather than hand-editing this one branch. |
Parked on a named blocker: #6728. The previous note points to #6913, which was closed as a duplicate of #6728. The canonical issue remains open; closing the duplicate did not unblock this PR. At unchanged head |
Parking this on a named blocker rather than regenerating it now, so it is not left aging red. Blocker: ksail#6826 | upstream | last-verified 2026-09-06: conflicting, #6826 regeneration requested Why it is blocked, verified 2026-09-06:
This PR's target is also already superseded. It bumps Next step: once #6826 regenerates onto the GA versions and lands, this PR should be recreated so it re-resolves to The |
Correcting my previous comment. The blocker line it posted was wrong; the canonical blocker remains #6728. I wrote
Restoring the canonical state, unchanged from the 12:27Z note: Blocker: loft-sh/apiserver k8s-0.37-compatible release | upstream | last-verified 2026-09-05: not shipped Compatibility tracked in #6728, Talos call-site migration in #6776. My #6915 duplicated both and is closed. One observation for whoever picks this up next: this PR has now been parked four times today — 02:53Z on #6776, 10:06Z on #6913, 12:27Z on #6728, and 14:00Z by me on #6826 — each re-deriving the blocker from scratch, and the chain drifted across three different issue numbers before returning to #6728. The blocker itself has not moved. That re-derivation cost is worth fixing rather than repeating. |
Blocker: #6728 | upstream | last-verified 2026-09-08: still OPEN ( Re-verified live this run rather than inheriting the previous note. Park stands; not regenerating or re-running. Corroborating evidence gathered this run on the sibling PR #6826, which reaches the same blocker by a different route: its build fails on |
Parked on the same blockers as #6826, and redundant with it. Not closing — see the last paragraph. This PR is
#6826 covers the same modules by a strictly better route. It moves to tagged releases ( I considered closing this as superseded, which is the terminal state the redundancy would normally argue for, and decided against it: closing a Dependabot PR records that version as declined, and 1.5.1 would then be skipped rather than re-offered. Once #6826 merges, Dependabot will rebase this branch onto the new baseline and it will either resolve to a clean, non-conflicting 1.4.0 → 1.5.1 bump or close itself as empty. Both outcomes are better than a manual close, and neither needs anyone to remember to re-open anything. So: parked behind #6728 → #6962 → #6826, no action needed here in the meantime. |
@dependabot rebase |
|
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry! If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request |
Blocker: #6728 | upstream | last-verified 2026-09-12: not shipped — Re-verified live this run rather than inherited. Module proxy, non-repository source:
The control matters: an empty response from a proxy that is simply not answering would look Park stands. Correcting a misreading of this PR's red CI, so it does not cost someone a runA survey this run flagged #6845, #6826 and #6997 as sharing an identical whole-suite failure
The identical signature is explained by three stale heads sharing one upstream dependency The distinction is load-bearing: a systemic-CI reading sends someone into ksail's workflows; the |

Bumps github.com/siderolabs/image-factory from 1.3.3 to 1.5.1.
Release notes
Sourced from github.com/siderolabs/image-factory's releases.
... (truncated)
Changelog
Sourced from github.com/siderolabs/image-factory's changelog.
... (truncated)
Commits
43adb19release(v1.5.1): prepare release5f1f197feat: update Talos to 1.14.0-rc.2b7908c1feat(enterprise): add Auth0 Management API client for node tokens36fedd7feat: add WithBearerToken to include m2m tokene783a3dfeat(frontend): preserve whitespace for vuln descriptions18f56f7chore: make sure check-dirty also checks docs196a447fix: enforce canonical image references26b95cafeat(enterprise): require auth0 clientID and clientSecret always25561f7fix: retry put when joining a failed get flightaab14fffeat: add spdx and vex reports to factory clientDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)