chore(deps): update all-ci-updates #896
                
     Merged
            
            
          
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
This PR contains the following updates:
0.10.9->0.11.2v3.30.5->v3.31.0v2.4.2->v2.4.3v2.22.9->v2.22.10v3.10.0->v3.10.1Release Notes
projectcapsule/capsule (capsule)
v0.11.2Compare Source
v0.11.1Compare Source
v0.11.0Compare Source
Changelog
✨ New Features
c901412: feat(api): migrate capsule.clastix.io/managed-by to meta api (#1691) (@oliverbaehler)9fa1aba: feat(controller): allow owners to promote serviceaccounts within tenant as owners (#1626) (@oliverbaehler)5ac0f83: feat(controller): refactor namespace core loop and state management (#1680) (@oliverbaehler)2261ea6: feat(helm): add labels and annotations for capsuleconfiguration (#1710) (@oliverbaehler)beafe09: feat(tenant): allow additional metadata for rolebindings (#1695) (@oliverbaehler)dd70ac2: feat(tenant): owners are now an optional property (#1654) (@oliverbaehler)14e09ea: feat: pre-release correctures (#1682) (@oliverbaehler)🐛 Bug fixes
ea2b6ec: fix(chart): disable node webhook by default (#1685) (@oliverbaehler)deb4db7: fix(docs): add static width per logo for adopters (#1700) (@sandert-k8s)4878e1a: fix: bypass resourepool limits (#1669) (@Svarrogh1337)🛠 Dependency updates
ba15a83: fix(deps): update k8s.io/utils digest tobc988d5(#1676) (@renovate[bot])54e80f8: fix(deps): update module github.com/onsi/ginkgo/v2 to v2.25.3 (#1605) (@renovate[bot])40d17bc: fix(deps): update module github.com/onsi/ginkgo/v2 to v2.26.0 (#1678) (@renovate[bot])c65a142: fix(deps): update module github.com/prometheus/client_golang to v1.23.1 (#1639) (@renovate[bot])bb8a511: fix(deps): update module github.com/prometheus/client_golang to v1.23.2 (#1642) (@renovate[bot])b1d0f8b: fix(deps): update module sigs.k8s.io/cluster-api to v1.11.2 (#1688) (@renovate[bot])e2418ab: fix(deps): update module sigs.k8s.io/controller-runtime to v0.22.1 (#1620) (@renovate[bot])8254c55: fix(deps): update module sigs.k8s.io/controller-runtime to v0.22.2 (#1684) (@renovate[bot])e7da3b0: fix(deps): update module sigs.k8s.io/controller-runtime to v0.22.3 (#1697) (@renovate[bot])7ccb64d: fix(deps): update module sigs.k8s.io/gateway-api to v1.4.0 (#1681) (@renovate[bot])Full Changelog: projectcapsule/capsule@v0.10.9...v0.11.0
Docker Images
ghcr.io/projectcapsule/capsule:0.11.0ghcr.io/projectcapsule/capsule:latestHelm Chart
View this release on Artifact Hub or use the OCI helm chart:
ghcr.io/projectcapsule/charts/capsule:0.11.0Review the Major Changes section first before upgrading to a new version
Thanks to all the contributors! 🚀 🦄
github/codeql-action (github/codeql-action)
v3.31.0Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.31.0 - 24 Oct 2025
analyzeorupload-sarifactions, the CodeQL Action automatically performs post-processing steps to prepare the data for the upload. Previously, these post-processing steps were only performed before an upload took place. We are now changing this so that the post-processing steps will always be performed, even when the SARIF files are not uploaded. This does not change anything for theupload-sarifaction. Foranalyze, this may affect Advanced Setup for CodeQL users who specify a value other thanalwaysfor theuploadinput. #3222See the full CHANGELOG.md for more information.
v3.30.9Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.9 - 17 Oct 2025
setup-codeqlaction has been added which is similar toinit, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #3204See the full CHANGELOG.md for more information.
v3.30.8Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.8 - 10 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.7Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.7 - 06 Oct 2025
No user facing changes.
See the full CHANGELOG.md for more information.
v3.30.6Compare Source
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.6 - 02 Oct 2025
See the full CHANGELOG.md for more information.
ossf/scorecard-action (ossf/scorecard-action)
v2.4.3Compare Source
What's Changed
This update bumps the Scorecard version to the v5.3.0 release. For a complete list of changes, please refer to the Scorecard v5.3.0 release notes.
Documentation
GITHUB_TOKENpermissions needed for private repos by @pankajtaneja5 in #1574Other
New Contributors
Full Changelog: ossf/scorecard-action@v2.4.2...v2.4.3
securego/gosec (securego/gosec)
v2.22.10Compare Source
Changelog
6be2b51Update go to version 1.25.3 and 1.24.9 in CI (#1404)fddb942chore(deps): update all dependencies (#1402)f676031Update go to version 1.25.2 and 2.24.8 in CI (#1401)35f7ec2chore(deps): update all dependencies (#1399)01029f0check nil slices, partially check bounds (#1396)34db3deRemove unused target from the makefilef5a3b7aUse the ginkgo command install by the dependencies761fcbcKeep the go module at 1.24 version for compatibility reasons2238079Remove manual test depsbb08aa3fix: text must be supplied when markdown is used23597d2fix: improve error message of CheckAnalyzers8d7e9d5fix: log panic on SSA0d8255echore(deps): update all dependenciesf9c52aaUpdate gosec to version v.22.9 in the github actionsigstore/cosign-installer (sigstore/cosign-installer)
v3.10.1Compare Source
What's Changed?
Note: cosign-installer v3.x cannot be used to install Cosign v3.x. You must upgrade to cosign-installer v4 in order to use Cosign v3.
Note: This is planned to be the final release of Cosign v2, though we will cut new releases for any critical security or bug fixes. We recommend transitioning to Cosign v3.
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.