From 70988d13277d52d6aba85b167d562005748b3f9a Mon Sep 17 00:00:00 2001 From: GitHub Action Date: Tue, 22 Sep 2026 13:29:44 +0000 Subject: [PATCH 01/11] Set new SNAPSHOT version into pom files. --- bootstrapper-maven-plugin/pom.xml | 2 +- caffeine-bounded-cache-support/pom.xml | 2 +- micrometer-support/pom.xml | 2 +- migration/pom.xml | 2 +- operator-framework-bom/pom.xml | 2 +- operator-framework-core/pom.xml | 2 +- operator-framework-junit/pom.xml | 2 +- operator-framework/pom.xml | 2 +- pom.xml | 2 +- sample-operators/controller-namespace-deletion/pom.xml | 2 +- sample-operators/kotlin-operator/pom.xml | 2 +- sample-operators/leader-election/pom.xml | 2 +- sample-operators/mysql-schema/pom.xml | 2 +- sample-operators/operations/pom.xml | 2 +- sample-operators/pom.xml | 2 +- sample-operators/tomcat-operator/pom.xml | 2 +- sample-operators/webpage/pom.xml | 2 +- test-index-processor/pom.xml | 2 +- 18 files changed, 18 insertions(+), 18 deletions(-) diff --git a/bootstrapper-maven-plugin/pom.xml b/bootstrapper-maven-plugin/pom.xml index 99fb569606..1cf3bff1c3 100644 --- a/bootstrapper-maven-plugin/pom.xml +++ b/bootstrapper-maven-plugin/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT bootstrapper diff --git a/caffeine-bounded-cache-support/pom.xml b/caffeine-bounded-cache-support/pom.xml index 12c57f1a4b..0e737eb51a 100644 --- a/caffeine-bounded-cache-support/pom.xml +++ b/caffeine-bounded-cache-support/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT caffeine-bounded-cache-support diff --git a/micrometer-support/pom.xml b/micrometer-support/pom.xml index cdab82d873..6c92703857 100644 --- a/micrometer-support/pom.xml +++ b/micrometer-support/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT micrometer-support diff --git a/migration/pom.xml b/migration/pom.xml index 2a081e7f77..c989e61129 100644 --- a/migration/pom.xml +++ b/migration/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT migration diff --git a/operator-framework-bom/pom.xml b/operator-framework-bom/pom.xml index b603baebe2..ad148d0b33 100644 --- a/operator-framework-bom/pom.xml +++ b/operator-framework-bom/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk operator-framework-bom - 5.6.2 + 5.6.3-SNAPSHOT pom Operator SDK - Bill of Materials Java SDK for implementing Kubernetes operators diff --git a/operator-framework-core/pom.xml b/operator-framework-core/pom.xml index 7d4f0780ed..6ffbff6a4d 100644 --- a/operator-framework-core/pom.xml +++ b/operator-framework-core/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT ../pom.xml diff --git a/operator-framework-junit/pom.xml b/operator-framework-junit/pom.xml index f1d74a46a4..730564330e 100644 --- a/operator-framework-junit/pom.xml +++ b/operator-framework-junit/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT operator-framework-junit diff --git a/operator-framework/pom.xml b/operator-framework/pom.xml index cb5075723d..6bc2fd00bc 100644 --- a/operator-framework/pom.xml +++ b/operator-framework/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT operator-framework diff --git a/pom.xml b/pom.xml index 5ad5452677..523c68f770 100644 --- a/pom.xml +++ b/pom.xml @@ -21,7 +21,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT pom Operator SDK for Java Java SDK for implementing Kubernetes operators diff --git a/sample-operators/controller-namespace-deletion/pom.xml b/sample-operators/controller-namespace-deletion/pom.xml index 6d9ed7480c..29b809a4ad 100644 --- a/sample-operators/controller-namespace-deletion/pom.xml +++ b/sample-operators/controller-namespace-deletion/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-controller-namespace-deletion diff --git a/sample-operators/kotlin-operator/pom.xml b/sample-operators/kotlin-operator/pom.xml index 4f92755d85..c23edaa30c 100644 --- a/sample-operators/kotlin-operator/pom.xml +++ b/sample-operators/kotlin-operator/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-kotlin-operator diff --git a/sample-operators/leader-election/pom.xml b/sample-operators/leader-election/pom.xml index ca6c3f3385..f56ae0c4e8 100644 --- a/sample-operators/leader-election/pom.xml +++ b/sample-operators/leader-election/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-leader-election diff --git a/sample-operators/mysql-schema/pom.xml b/sample-operators/mysql-schema/pom.xml index 611925abe4..91fb64b465 100644 --- a/sample-operators/mysql-schema/pom.xml +++ b/sample-operators/mysql-schema/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-mysql-schema-operator diff --git a/sample-operators/operations/pom.xml b/sample-operators/operations/pom.xml index d102757677..c2ade9133f 100644 --- a/sample-operators/operations/pom.xml +++ b/sample-operators/operations/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-operations diff --git a/sample-operators/pom.xml b/sample-operators/pom.xml index bfe00acf09..d72c098c6d 100644 --- a/sample-operators/pom.xml +++ b/sample-operators/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT sample-operators diff --git a/sample-operators/tomcat-operator/pom.xml b/sample-operators/tomcat-operator/pom.xml index 2aa7533705..204bf77d05 100644 --- a/sample-operators/tomcat-operator/pom.xml +++ b/sample-operators/tomcat-operator/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-tomcat-operator diff --git a/sample-operators/webpage/pom.xml b/sample-operators/webpage/pom.xml index 704f79c57b..0a3648befd 100644 --- a/sample-operators/webpage/pom.xml +++ b/sample-operators/webpage/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk sample-operators - 5.6.2 + 5.6.3-SNAPSHOT sample-webpage-operator diff --git a/test-index-processor/pom.xml b/test-index-processor/pom.xml index b06bdaabaa..0440c2b654 100644 --- a/test-index-processor/pom.xml +++ b/test-index-processor/pom.xml @@ -22,7 +22,7 @@ io.javaoperatorsdk java-operator-sdk - 5.6.2 + 5.6.3-SNAPSHOT test-index-processor From 53f2170ada773bc01499e75ec53971881623a010 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 25 Sep 2026 14:04:07 +0200 Subject: [PATCH 02/11] chore(deps): bump com.github.ben-manes.caffeine:caffeine (#3633) Bumps [com.github.ben-manes.caffeine:caffeine](https://github.com/ben-manes/caffeine) from 3.2.4 to 3.3.0. - [Release notes](https://github.com/ben-manes/caffeine/releases) - [Commits](https://github.com/ben-manes/caffeine/compare/v3.2.4...v3.3.0) --- updated-dependencies: - dependency-name: com.github.ben-manes.caffeine:caffeine dependency-version: 3.3.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 523c68f770..814f0dcc26 100644 --- a/pom.xml +++ b/pom.xml @@ -82,7 +82,7 @@ 4.3.0 2.7.3 1.17.1 - 3.2.4 + 3.3.0 0.9.14 2.22.0 4.17 From 7c3ec5e159b7565529c3d6b9f868a2120303be1e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Attila=20M=C3=A9sz=C3=A1ros?= Date: Fri, 25 Sep 2026 14:04:53 +0200 Subject: [PATCH 03/11] fix: harden the release workflow against irreversible failures (#3632) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Once artifacts are deployed to Maven Central they cannot be changed, so anything that would make the release fail afterwards is now checked before deploying, and the final push can no longer overwrite someone else's changes. Before deploying: - Check that the release tag, if it already exists, points into the history of the branch being released. This needs a full checkout with tags. - Refuse to release a version older than the one the branch is already developing. That means the wrong branch was picked for the tag, and finalize would otherwise move the branch back onto versions that are already released. Finalize: - Repeat the backwards-version check on the computed next -SNAPSHOT version. - Push the tag with --force-with-lease against the value seen during the ancestry check, instead of force-pushing it. With --atomic, a tag or branch moved by someone else during the release now fails the whole push and nothing is overwritten. - Explain in a comment how to finish the release by hand if that push is rejected. Also: - Move the pom version parser into a shared inline POM_VERSION_PY script, used by both jobs, that fails clearly when the pom has no version. It stays inline because older maintenance branches would not have a script file in the repo. - Keep the concurrency group, with a comment explaining why two releases must not run at the same time. Signed-off-by: Attila Mészáros --- .github/workflows/release-project-in-dir.yml | 131 +++++++++++++++++-- .github/workflows/release.yml | 6 +- 2 files changed, 122 insertions(+), 15 deletions(-) diff --git a/.github/workflows/release-project-in-dir.yml b/.github/workflows/release-project-in-dir.yml index 54c01f20a5..52ce25ea72 100644 --- a/.github/workflows/release-project-in-dir.yml +++ b/.github/workflows/release-project-in-dir.yml @@ -17,6 +17,22 @@ env: # set the target pom to use the input directory as root MAVEN_ARGS: -V -ntp -e -f ${{ inputs.project_dir }}/pom.xml ROOT_POM: ${{ inputs.project_dir }}/pom.xml + # Prints the version of the pom given as argument, falling back to the + # parent's version. Used instead of `help:evaluate`, whose banner and log + # output would have to be filtered off stdout first. Kept inline rather than + # as a script in the repo because the jobs check out the release branch, and + # older maintenance branches would not have such a script. + POM_VERSION_PY: | + import sys + import xml.etree.ElementTree as ET + NS = "{http://maven.apache.org/POM/4.0.0}" + root = ET.parse(sys.argv[1]).getroot() + version = root.findtext(NS + "version") + if version is None: + version = root.findtext(NS + "parent/" + NS + "version") + if version is None: + raise SystemExit("no version and no parent version in " + sys.argv[1]) + print(version.strip()) jobs: publish: @@ -29,11 +45,43 @@ jobs: uses: actions/checkout@v7 with: ref: "${{ inputs.version_branch }}" + # Full history and tags are needed to check where the release tag + # currently points relative to the branch. + fetch-depth: 0 + fetch-tags: true - name: Resolve checked-out commit id: resolve-sha run: echo "commit=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" + - name: Check the release tag can be moved onto this branch + env: + RELEASE_TAG: ${{ inputs.release_tag }} + TARGET_BRANCH: ${{ inputs.version_branch }} + run: | + set -euo pipefail + + # finalize-release moves the tag onto a commit built on top of this + # one, which is only legitimate if the tag already points into this + # branch's history. Checking it here rather than after the deploy + # means a release cut from an unrelated commit fails while it can + # still be retried - once artifacts are in Maven Central they are + # immutable. + # + # Peel the tag in a separate step from testing its existence: a tag + # that resolves to something other than a commit must fail loudly + # rather than look like an absent tag and skip the check. + if git rev-parse -q --verify "refs/tags/${RELEASE_TAG}" >/dev/null; then + if ! CURRENT_TAGGED="$(git rev-parse -q --verify "refs/tags/${RELEASE_TAG}^{commit}")"; then + echo "Tag ${RELEASE_TAG} does not resolve to a commit" + exit 1 + fi + if ! git merge-base --is-ancestor "${CURRENT_TAGGED}" HEAD; then + echo "Tag ${RELEASE_TAG} points at ${CURRENT_TAGGED}, which is not an ancestor of ${TARGET_BRANCH}" + exit 1 + fi + fi + - name: Set up Java and Maven uses: actions/setup-java@v6 with: @@ -49,6 +97,7 @@ jobs: - name: Change version to release version env: RELEASE_TAG: ${{ inputs.release_tag }} + TARGET_BRANCH: ${{ inputs.version_branch }} run: | set -euo pipefail RELEASE_VERSION="${RELEASE_TAG#v}" @@ -63,6 +112,20 @@ jobs: exit 1 fi + # finalize-release derives the next development version from the + # released one, so releasing a version older than the branch already + # develops would set the branch back onto versions that are already + # released. That means the wrong branch was selected for this tag. + # Checked here because the deploy that follows cannot be undone. + DEVELOPMENT_VERSION="$(python3 -c "${POM_VERSION_PY}" "${ROOT_POM}")" + DEVELOPMENT_BASE="${DEVELOPMENT_VERSION%-SNAPSHOT}" + if [ "${RELEASE_VERSION}" != "${DEVELOPMENT_BASE}" ] && \ + [ "$(printf '%s\n%s\n' "${RELEASE_VERSION}" "${DEVELOPMENT_BASE}" | sort -V | head -1)" = "${RELEASE_VERSION}" ]; then + echo "${TARGET_BRANCH} develops ${DEVELOPMENT_VERSION}, which is newer than ${RELEASE_VERSION}" + echo "Is ${RELEASE_TAG} being released from the right branch?" + exit 1 + fi + ./mvnw ${MAVEN_ARGS} versions:set -DnewVersion="${RELEASE_VERSION}" versions:commit -DprocessAllModules - name: Publish to Apache Maven Central @@ -106,17 +169,16 @@ jobs: id: commits env: RELEASE_TAG: ${{ inputs.release_tag }} + TARGET_BRANCH: ${{ inputs.version_branch }} run: | set -euo pipefail - # Reads the version of the root pom directly, rather than through - # help:evaluate, whose banner and log output would have to be filtered - # out of stdout first. pom_version() { - python3 -c 'import sys, xml.etree.ElementTree as ET; ns = "{http://maven.apache.org/POM/4.0.0}"; root = ET.parse(sys.argv[1]).getroot(); version = root.findtext(ns + "version") or root.findtext(ns + "parent/" + ns + "version"); print(version.strip())' "${ROOT_POM}" + python3 -c "${POM_VERSION_PY}" "${ROOT_POM}" } RELEASE_VERSION="${RELEASE_TAG#v}" + DEVELOPMENT_VERSION="$(pom_version)" git config --local user.email "action@github.com" git config --local user.name "GitHub Action" @@ -160,6 +222,17 @@ jobs: ;; esac + # The bump is derived from the released version, so releasing a tag + # older than the branch's own development version would move the + # branch backwards - onto versions that have already been released. + # That means the wrong branch was selected for the tag, so stop. + if [ "${NEXT_VERSION}" != "${DEVELOPMENT_VERSION}" ] && \ + [ "$(printf '%s\n%s\n' "${NEXT_VERSION}" "${DEVELOPMENT_VERSION}" | sort -V | head -1)" = "${NEXT_VERSION}" ]; then + echo "Next development version ${NEXT_VERSION} would move ${TARGET_BRANCH} back from ${DEVELOPMENT_VERSION}" + echo "Is ${RELEASE_TAG} being released from the right branch?" + exit 1 + fi + if git diff --quiet; then echo "Branch would be left on release version ${RELEASE_VERSION}" exit 1 @@ -168,6 +241,7 @@ jobs: echo "Next development version: ${NEXT_VERSION}" - name: Move release tag onto the release commit + id: tag env: RELEASE_TAG: ${{ inputs.release_tag }} RELEASE_COMMIT: ${{ steps.commits.outputs.release_commit }} @@ -176,16 +250,25 @@ jobs: # GitHub created the tag on whatever the branch tip was when the # release was published, so it is expected to move - but only forward, - # onto a descendant. Anything else means the release was cut from a - # commit this workflow did not build, and silently discarding it would - # lose the tagged state. - if git rev-parse -q --verify "refs/tags/${RELEASE_TAG}^{commit}" >/dev/null; then + # onto a descendant. publish already checked this against the branch; + # repeat it here because the release commit is what actually gets + # tagged. + # + # The OID recorded here is the tag ref itself, not the commit it peels + # to, because that is what the push has to lease against. An empty + # value means the tag did not exist, which --force-with-lease reads as + # "must still not exist". + if git rev-parse -q --verify "refs/tags/${RELEASE_TAG}" >/dev/null; then + EXPECTED_TAG_OID="$(git rev-parse "refs/tags/${RELEASE_TAG}")" CURRENT_TAGGED="$(git rev-parse "refs/tags/${RELEASE_TAG}^{commit}")" if ! git merge-base --is-ancestor "${CURRENT_TAGGED}" "${RELEASE_COMMIT}"; then echo "Tag ${RELEASE_TAG} points at ${CURRENT_TAGGED}, which is not an ancestor of ${RELEASE_COMMIT}" exit 1 fi + else + EXPECTED_TAG_OID="" fi + echo "expected_tag_oid=${EXPECTED_TAG_OID}" >> "$GITHUB_OUTPUT" git tag -f -a "${RELEASE_TAG}" "${RELEASE_COMMIT}" -m "Release ${RELEASE_TAG}" @@ -193,13 +276,35 @@ jobs: env: RELEASE_TAG: ${{ inputs.release_tag }} TARGET_BRANCH: ${{ inputs.version_branch }} + EXPECTED_TAG_OID: ${{ steps.tag.outputs.expected_tag_oid }} run: | set -euo pipefail # One atomic push so the branch is never left holding the release - # commit without the SNAPSHOT commit that follows it. The branch - # refspec is not forced: if something landed on the branch while the - # release was being deployed, this fails instead of clobbering it. - git push --atomic origin \ + # commit without the SNAPSHOT commit that follows it. + # + # Neither ref can be clobbered: the branch refspec is not forced, so a + # commit landing during the deploy fails the push, and the tag is + # leased against the OID observed during the ancestry check, so a tag + # moved by anyone else since then fails it too. --atomic means either + # both refs update or neither does. + # + # Recovering from a rejected push: by now the artifacts are in Maven + # Central, so re-running the workflow fails in publish, and re-running + # just this job rebuilds on the same stale commit and is rejected + # again. Both refs are still in a safe state - the branch on a + # SNAPSHOT version, the tag where GitHub created it - so finish the + # release by hand: + # 1. Check out the commit this job built on (the one shown by its + # checkout step, i.e. what was deployed), set the released + # version with versions:set, commit "Release ", and move + # the tag onto that commit with an annotated tag. Push the tag + # with --force-with-lease against its current remote value. + # 2. Check out the current branch tip, set the next -SNAPSHOT + # version with versions:set, and push that as an ordinary + # commit. + git push --atomic \ + --force-with-lease="refs/tags/${RELEASE_TAG}:${EXPECTED_TAG_OID}" \ + origin \ "HEAD:refs/heads/${TARGET_BRANCH}" \ - "+refs/tags/${RELEASE_TAG}" + "refs/tags/${RELEASE_TAG}:refs/tags/${RELEASE_TAG}" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index b42dd02233..3b144d6cc7 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,8 +5,10 @@ on: release: types: [ released ] -# Releases push commits to the branch they are cut from, so run them one at a -# time rather than letting two overlap on the same branch. +# Two releases cut from the same branch must not overlap: both would deploy to +# Maven Central, then one would lose the branch push and be left with immutable +# artifacts and no release commit. Serializing means the worst case is instead a +# release that does not start, which can simply be re-run. concurrency: group: ${{ github.workflow }} cancel-in-progress: false From cd98a11360b19915e2be84f61e9220d8640412cb Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 08:50:39 +0200 Subject: [PATCH 04/11] chore(deps): bump org.mockito:mockito-core from 5.23.0 to 5.24.0 (#3638) Bumps [org.mockito:mockito-core](https://github.com/mockito/mockito) from 5.23.0 to 5.24.0. - [Release notes](https://github.com/mockito/mockito/releases) - [Commits](https://github.com/mockito/mockito/compare/v5.23.0...v5.24.0) --- updated-dependencies: - dependency-name: org.mockito:mockito-core dependency-version: 5.24.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 814f0dcc26..b15f788ac1 100644 --- a/pom.xml +++ b/pom.xml @@ -74,7 +74,7 @@ 7.9.0 2.0.19 2.26.1 - 5.23.0 + 5.24.0 3.20.0 0.23.0 1.13.0 From d2e9cf5674d34ea83ad862a8257639171158633f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 08:51:04 +0200 Subject: [PATCH 05/11] chore(deps): bump org.slf4j:slf4j-api from 2.0.19 to 2.0.20 (#3637) Bumps org.slf4j:slf4j-api from 2.0.19 to 2.0.20. --- updated-dependencies: - dependency-name: org.slf4j:slf4j-api dependency-version: 2.0.20 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index b15f788ac1..b30dddea0a 100644 --- a/pom.xml +++ b/pom.xml @@ -72,7 +72,7 @@ jdk 6.1.3 7.9.0 - 2.0.19 + 2.0.20 2.26.1 5.24.0 3.20.0 From 49eda9fced53a9bcf79de401685dfb32aad0ce9f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Attila=20M=C3=A9sz=C3=A1ros?= Date: Mon, 28 Sep 2026 09:31:26 +0200 Subject: [PATCH 06/11] test: fix flaky TriggerReconcilerOnAllEventIT.additionalEventDuringRetryOnDeleteEvent (#3634) The test assumed at least 3 reconciliations happen before the reconciler starts waiting on the first retry. If the delete event arrives before the first reconciliation reads the resource, the finalizer-adding reconciliation is skipped, the reconciler starts waiting at count 2, and the test and the reconciler block on each other until timeout. Wait for the reconciler to be waiting and snapshot the event count then instead. --- .../eventing/TriggerReconcilerOnAllEventIT.java | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/operator-framework/src/test/java/io/javaoperatorsdk/operator/baseapi/triggerallevent/eventing/TriggerReconcilerOnAllEventIT.java b/operator-framework/src/test/java/io/javaoperatorsdk/operator/baseapi/triggerallevent/eventing/TriggerReconcilerOnAllEventIT.java index a8b022b642..3226611ea1 100644 --- a/operator-framework/src/test/java/io/javaoperatorsdk/operator/baseapi/triggerallevent/eventing/TriggerReconcilerOnAllEventIT.java +++ b/operator-framework/src/test/java/io/javaoperatorsdk/operator/baseapi/triggerallevent/eventing/TriggerReconcilerOnAllEventIT.java @@ -181,19 +181,16 @@ void additionalEventDuringRetryOnDeleteEvent() { extension.create(res); extension.delete(getResource()); - await() - .pollDelay(Duration.ofMillis(30)) - .untilAsserted( - () -> { - assertThat(reconciler.getEventCount()).isGreaterThan(2); - }); - var eventCount = reconciler.getEventCount(); - + // Don't assume a fixed number of reconciliations before the first retry: if the delete event + // arrives before the first reconciliation reads the resource, the finalizer-adding + // reconciliation is skipped. The reconciler increments the counter before it starts waiting, + // and nothing else reconciles while it waits, so the count read after this is stable. await() .untilAsserted( () -> { assertThat(reconciler.isWaiting()).isTrue(); }); + var eventCount = reconciler.getEventCount(); // trigger reconciliation while waiting in reconciler res = getResource(); From 29d60fcac2266fbd092dcfff26bbbd42e2309b37 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 10:16:49 +0200 Subject: [PATCH 07/11] chore(deps): bump manusa/actions-setup-minikube from 2.18.0 to 2.19.0 (#3635) Bumps [manusa/actions-setup-minikube](https://github.com/manusa/actions-setup-minikube) from 2.18.0 to 2.19.0. - [Release notes](https://github.com/manusa/actions-setup-minikube/releases) - [Commits](https://github.com/manusa/actions-setup-minikube/compare/v2.18.0...v2.19.0) --- updated-dependencies: - dependency-name: manusa/actions-setup-minikube dependency-version: 2.19.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .github/workflows/e2e-test.yml | 2 +- .github/workflows/integration-tests.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/e2e-test.yml b/.github/workflows/e2e-test.yml index 2a0129d5ae..6898ffd4ee 100644 --- a/.github/workflows/e2e-test.yml +++ b/.github/workflows/e2e-test.yml @@ -32,7 +32,7 @@ jobs: uses: actions/checkout@v7 - name: Setup Minikube-Kubernetes - uses: manusa/actions-setup-minikube@v2.18.0 + uses: manusa/actions-setup-minikube@v2.19.0 with: minikube version: 'v1.38.1' # Use the latest versions supported by minikube, otherwise GitHub it will diff --git a/.github/workflows/integration-tests.yml b/.github/workflows/integration-tests.yml index 95537f33ee..43ab7a6162 100644 --- a/.github/workflows/integration-tests.yml +++ b/.github/workflows/integration-tests.yml @@ -39,7 +39,7 @@ jobs: java-version: ${{ inputs.java-version }} cache: 'maven' - name: Set up Minikube - uses: manusa/actions-setup-minikube@v2.18.0 + uses: manusa/actions-setup-minikube@v2.19.0 with: minikube version: 'v1.38.1' kubernetes version: '${{ inputs.kube-version }}' From aff1c646f567d5297e0f0ef2286e29440ae3ba56 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Attila=20M=C3=A9sz=C3=A1ros?= Date: Mon, 28 Sep 2026 12:26:12 +0200 Subject: [PATCH 08/11] chore(ci): test against Kubernetes 1.37, drop EOL 1.32 and 1.33 (#3602) Bump minikube to v1.39.0 (newest supported Kubernetes version is v1.37.0) and update the tested Kubernetes versions to the four currently supported upstream minors: 1.34, 1.35, 1.36 and 1.37. --- .github/workflows/build.yml | 4 ++-- .github/workflows/e2e-test.yml | 4 ++-- .github/workflows/integration-tests.yml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 5006fb4de9..6441364993 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -14,7 +14,7 @@ jobs: # Use the latest versions supported by minikube, otherwise GitHub it will # end up in a throttling requests from minikube and workflow will fail. # Minikube does such requests only if a version is not officially supported. - kubernetes: [ 'v1.32.13', 'v1.33.9', 'v1.34.5', 'v1.35.2' ] + kubernetes: [ 'v1.34.11', 'v1.35.8', 'v1.36.4', 'v1.37.0' ] uses: ./.github/workflows/integration-tests.yml with: java-version: ${{ matrix.java }} @@ -27,7 +27,7 @@ jobs: uses: ./.github/workflows/integration-tests.yml with: java-version: 25 - kube-version: 'v1.35.2' + kube-version: 'v1.37.0' http-client: ${{ matrix.httpclient }} experimental: true diff --git a/.github/workflows/e2e-test.yml b/.github/workflows/e2e-test.yml index 6898ffd4ee..9bb0e359a0 100644 --- a/.github/workflows/e2e-test.yml +++ b/.github/workflows/e2e-test.yml @@ -34,11 +34,11 @@ jobs: - name: Setup Minikube-Kubernetes uses: manusa/actions-setup-minikube@v2.19.0 with: - minikube version: 'v1.38.1' + minikube version: 'v1.39.0' # Use the latest versions supported by minikube, otherwise GitHub it will # end up in a throttling requests from minikube and workflow will fail. # Minikube does such requests only if a version is not officially supported. - kubernetes version: 'v1.35.2' + kubernetes version: 'v1.37.0' github token: ${{ secrets.GITHUB_TOKEN }} driver: docker diff --git a/.github/workflows/integration-tests.yml b/.github/workflows/integration-tests.yml index 43ab7a6162..31f69ec5e4 100644 --- a/.github/workflows/integration-tests.yml +++ b/.github/workflows/integration-tests.yml @@ -41,7 +41,7 @@ jobs: - name: Set up Minikube uses: manusa/actions-setup-minikube@v2.19.0 with: - minikube version: 'v1.38.1' + minikube version: 'v1.39.0' kubernetes version: '${{ inputs.kube-version }}' github token: ${{ github.token }} From 97d0036836497992d8b75e7837be9d2136e7f290 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 11:10:11 +0200 Subject: [PATCH 09/11] chore(deps): bump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0 (#3640) Bumps org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0. --- updated-dependencies: - dependency-name: org.apache.commons:commons-lang3 dependency-version: 3.21.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index b30dddea0a..46f530283e 100644 --- a/pom.xml +++ b/pom.xml @@ -75,7 +75,7 @@ 2.0.20 2.26.1 5.24.0 - 3.20.0 + 3.21.0 0.23.0 1.13.0 3.27.7 From 15341c9ab712fa545dbbb1f676802bd4a4a0c660 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 14:06:27 +0200 Subject: [PATCH 10/11] chore(deps): bump org.apache.maven:apache-maven from 3.9.16 to 3.10.0 (#3642) Bumps org.apache.maven:apache-maven from 3.9.16 to 3.10.0. --- updated-dependencies: - dependency-name: org.apache.maven:apache-maven dependency-version: 3.10.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .mvn/wrapper/maven-wrapper.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.mvn/wrapper/maven-wrapper.properties b/.mvn/wrapper/maven-wrapper.properties index 216df05897..bb58b3c263 100644 --- a/.mvn/wrapper/maven-wrapper.properties +++ b/.mvn/wrapper/maven-wrapper.properties @@ -1,3 +1,3 @@ wrapperVersion=3.3.4 distributionType=only-script -distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.16/apache-maven-3.9.16-bin.zip +distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.10.0/apache-maven-3.10.0-bin.zip From b300073fc6bd7596cc5bab92f1539224cf9566a2 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 14:06:51 +0200 Subject: [PATCH 11/11] chore(deps): bump org.apache.maven:maven-plugin-api (#3641) Bumps [org.apache.maven:maven-plugin-api](https://github.com/apache/maven) from 3.9.16 to 3.10.0. - [Release notes](https://github.com/apache/maven/releases) - [Commits](https://github.com/apache/maven/compare/maven-3.9.16...maven-3.10.0) --- updated-dependencies: - dependency-name: org.apache.maven:maven-plugin-api dependency-version: 3.10.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- bootstrapper-maven-plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/bootstrapper-maven-plugin/pom.xml b/bootstrapper-maven-plugin/pom.xml index 1cf3bff1c3..d7ee87f333 100644 --- a/bootstrapper-maven-plugin/pom.xml +++ b/bootstrapper-maven-plugin/pom.xml @@ -32,7 +32,7 @@ 3.16.0 - 3.9.16 + 3.10.0 3.1.1 3.16.0