Skip to content

chore(deps): update urllib3 requirement from >=2.6.0 to >=2.8.0 in /operator - #10

Open
dependabot[bot] wants to merge 48 commits into
mainfrom
dependabot/pip/operator/urllib3-gte-2.8.0
Open

dependabot[bot] wants to merge 48 commits into
mainfrom
dependabot/pip/operator/urllib3-gte-2.8.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown

Updates the requirements on urllib3 to permit the latest version.

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

bobbyjohnstx and others added 30 commits June 22, 2026 11:01
- Helm chart: port corrected from 3000 to 4096 throughout
- CONTAINER.md: authoritative container interface contract
- README.md: UID corrected to 1001, image corrected to ghcr.io/bjohns/tiny-container:latest,
  spec table expanded, Ecosystem section added

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…missions

- Dockerfile: ENTRYPOINT uses kopf run --all-namespaces with liveness endpoint
- role.yaml: add watch on CRDs (required by kopf) and events RBAC

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
- config/rbac/role.yaml: add clusterrolebindings and events RBAC
- operator/main.py: use RbacV1Subject (k8s 29.0.0), switch SCC binding
  from ClusterRoleBinding to patching SCC users field directly (correct
  approach for custom SCCs that lack auto-generated system:openshift:scc:*
  ClusterRoles)
- helm-charts: remove hardcoded UID/fsGroup so OpenShift assigns from
  namespace range (RunAsAny); update default image to quay.io/bjohns/tiny-container
- config/crd: update default image to quay.io/bjohns/tiny-container

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
- config/scc/: change runAsUser/fsGroup from MustRunAs(1001) to RunAsAny
  so pods can run under the cluster-assigned UID range (e.g., 1000910000+
  on RHOAI). Hardcoded UID 1001 blocks pod creation on most managed clusters.

- config/rbac/role.yaml: add clusterrolebindings to RBAC rules (required by
  operator to create SCC bindings for instance ServiceAccounts)

- helm-charts/tinycode/templates/deployment.yaml: change imagePullPolicy to
  Always so updated :latest images are picked up on pod restart

- hack/install.sh: add instructions for creating the operator Helm RoleBinding
  in target namespaces (required for Helm to manage secrets/resources)

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
install.sh: scan all cluster Deployments for vLLM containers and warn
if --enable-auto-tool-choice / --tool-call-parser are missing. Shows a
prominent box with the exact fix and points to docs/vllm-tool-calling.md.

operator/main.py: after each successful Helm deploy, probe vLLM services
in the instance namespace for tool calling support. Adds a
ToolCallingWarning condition to the TinycodeInstance status so the issue
is visible via 'oc get tinycodeinstance' and 'oc describe tinycodeinstance'.

docs/vllm-tool-calling.md: full guide covering plain Deployment patch,
KServe InferenceService patch, verification steps, and tinycode config
cleanup after the fix.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…checks

docs/rhoai-cluster-setup.md (new):
  Full cluster provisioning guide for the RHOAI setup session. Covers:
  - Qwen3-30B deployment with tool calling + fp8 KV cache + 32k context
  - Llama-3.2-3B deployment as small_model for compaction
  - Pre-install verification commands
  - Required vLLM flags summary table
  - What the operator checks at install/reconcile time
  - Manual tinycode config steps (until operator issue #1 is complete)

hack/install.sh:
  Extended vLLM preflight to also check --max-model-len (warn if <16384)
  and --kv-cache-dtype (recommend fp8). Updated warning box to show both
  tool calling and context window requirements. References rhoai-cluster-setup.md.

operator/main.py:
  check_vllm_tool_calling() now also reads max_model_len from /v1/models
  and warns when context < 16384 (too small for coding sessions). Condition
  renamed ToolCallingWarning → VllmWarning to reflect broader scope.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…for tinycode

Idempotent script that configures vLLM deployments on RHOAI for tinycode:
- Adds tool calling flags (--enable-auto-tool-choice, --tool-call-parser)
- Adds fp8 KV cache (--kv-cache-dtype fp8) to enable 4x larger context
- Increases --max-model-len to 32768 (default, configurable)
- Labels services for Kubernetes auto-discovery
- Auto-detects Llama deployment by name
- Supports DRY_RUN=true preview mode
- Verifies tool calling and context window after applying
- Prints ready-to-use tinycode provider config for the deployed models

All settings configurable via environment variables. Idempotent — safe to
re-run if already partially configured.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
All 7 open questions resolved:
- curl: microdnf install in ContainerFile runtime stage
- oc binary: static binary (no library deps)
- download timeout: 60s readiness probe delay
- multi-context kubeconfig: document + operator warning in status
- token expiry: document + detect + helper command in docs
- replicas >1: document risk, recommend 1, don't enforce
- OpenShift vs k8s: auto-detect at startup, prompt adapts

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…sterAdmin

Adds a TinycodeInstance operating mode that provides a natural-language
OpenShift/Kubernetes cluster management interface via the oc CLI.

CRD: new spec.clusterAdmin section
  - enabled: mounts kubeconfig, downloads oc CLI, activates cluster-admin agent
  - kubeconfigSecretName/Key: Secret containing the kubeconfig to mount
  - ocVersion: oc binary channel (default: stable)

Helm chart:
  - ConfigMap with cluster-admin agent definition (bash:ask, no edit/write)
  - Agent prompt adapts to cluster type (OpenShift vs k8s) via TINYCODE_CLUSTER_TYPE
  - Kubeconfig Secret mounted read-only at /home/tinycode/.kube/config
  - Probes extended: readiness 60s, liveness 90s (accommodates oc download)
  - TINYCODE_CONFIG_CONTENT env var injects the agent config

Operator:
  - validate_cluster_admin(): checks Secret exists, key present
  - Warns in status on multiple kubeconfig contexts
  - Warns in status on short-lived OAuth tokens (sha256~ prefix)
  - ClusterAdminReady status condition (False on errors, True with warnings)

Decisions: Option A (user-provided Secret), static oc binary, curl via microdnf,
           60s readiness probe, multi-context warning not block, token expiry warn,
           replicas>1 documented not enforced, cluster auto-detected at startup.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Update all image references from quay.io/bjohns/tiny-container to
ghcr.io/bjohns/tinycode-container across Helm values, CRD defaults,
sample CRs, CSV, and documentation. Consolidates to a single registry.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The operator main.py had a stale fallback default (quay.io/tinycode/server:latest)
that didn't match the CRD or Helm defaults. All deployment-facing image references
now consistently use quay.io/bjohns/tinycode-container:latest.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Document options for deploying tinycode without the operator on
non-OpenShift clusters: raw Kustomize manifests and Tekton + Argo CD.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Document how users can self-provision TinycodeInstance CRs with
appropriate RBAC. No operator changes required — just a ClusterRole
and per-namespace RoleBindings.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Created bundle/metadata/annotations.yaml with OLM metadata
- Copied CRD to bundle/manifests/
- Fixed CSV: removed namespace placeholder, updated containerImage to v0.1.0, added icon, fixed command to match Dockerfile ENTRYPOINT
- Created bundle.Dockerfile for bundle image packaging
- Added Makefile targets: bundle-validate, bundle-build, bundle-push, catalog-build, catalog-push, test-bundle
- Created File-Based Catalog at catalog/tinycode-operator/catalog.yaml
- Created catalog.Dockerfile for catalog image
- Created config/catalog/catalogsource.yaml for private catalog deployment
- Added comprehensive docs/olm-bundle.md covering build, test, deployment, air-gapped, and troubleshooting

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…ensions

This commit implements three new features for the tinycode operator:

1. GitOps mode (issue #6):
   - New spec.git field for cloning repositories into /projects
   - Supports public and private repos via credentialsSecret
   - Init container handles clone/pull operations
   - Mutually exclusive with hostPath storage

2. Shared team workspace (issue #7):
   - New spec.storage.projectsAccessMode (ReadWriteOnce/ReadWriteMany)
   - Support for replicas > 1 with ReadWriteMany PVC
   - Session affinity via Route annotations
   - EmptyDir for data volume (SQLite can't be shared)

3. OpenShift management extensions (issue #5):
   - New spec.clusterAdmin.kubeconfigNamespace for cross-namespace Secrets
   - New spec.clusterAdmin.clusterRole for auto-provisioned SA mode
   - Privilege escalation guard (rejects admin/cluster-admin roles)

Changes:
- CRD: Added git, projectsAccessMode, kubeconfigNamespace, clusterRole fields
- Operator: Added validate_git_spec() and validate_shared_workspace()
- Helm: Git init container, conditional emptyDir volumes, session affinity
- Samples: gitops.yaml, gitops_private.yaml, shared.yaml

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
… quoting, RBAC fixes

CRITICAL security fixes across operator and Helm charts:

1. Shell injection prevention — quoted all user-controlled git values (url, branch) in init container
2. CRD validation tightening:
   - spec.git.url: strict URL pattern with allowed chars only
   - spec.git.branch: alphanumeric + path separators, 255 max
   - spec.clusterAdmin.clusterRole: blocklist → allowlist (view|edit|tinycode-*)
   - spec.image: allowlist for quay.io/bjohns, ghcr.io/bjohns, registry.access.redhat.com
3. SCC RBAC mismatch — added patch/update verbs to ClusterRole and CSV
4. SSRF prevention in vLLM probing — reject metadata endpoints (169.254.169.254, metadata.google.internal) and loopback
5. Kubeconfig exception sanitization — hide raw exception messages from status
6. Helm value quoting — added | quote to image, hostname, ollama.host, storageClassName, hostPath.path
7. NetworkPolicy template — default-deny ingress except port 4096
8. Audit logging — log all Secret reads with purpose (git_credentials, kubeconfig_validation)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…docs, complete env var table

- Replace obsolete manual config section (lines 265-310) with spec.vllm declarative example
- Remove "planned — operator issue #1" notes (issue #1 is done)
- Add cross-namespace discovery section with spec.discovery.namespaces example
- Update context window check section to show ContextWindowWarning condition
- Complete CONTAINER.md env vars table with all vars from entrypoint.sh, grouped by category:
  - Core: TINYCODE_SERVER_PASSWORD, TINYCODE_PORT, TINYCODE_SESSION_ID, TINYCODE_WORKDIR
  - LLM Providers: TINYCODE_OLLAMA_HOST, TINYCODE_VLLM_URL, TINYCODE_VLLM_HOST, TINYCODE_VLLM_MODEL, OPENROUTER_API_KEY
  - GitOps: TINYCODE_GIT_REPO, TINYCODE_GIT_BRANCH, TINYCODE_GIT_PULL_ON_RESTART, TINYCODE_GIT_CLONE_TIMEOUT
  - Cluster Management: TINYCODE_CLUSTER_ADMIN, TINYCODE_OC_VERSION
  - Auto-detection: TINYCODE_AUTO_DETECT, TINYCODE_DISABLE_LSP_DOWNLOAD
  - Operator-injected: TINYCODE_CONFIG_CONTENT, TINYCODE_DISCOVERY_NAMESPACES
  - Output: TINYCODE_CLUSTER_TYPE

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Updated TinycodeInstance spec reference with detailed documentation of validation patterns and security constraints:

- CRD Security Constraints: Documented validation for image registry, git URLs, git branches, clusterRole allowlist, and SSRF prevention
- Security Features: Added documentation for NetworkPolicy support, read-only root filesystem, security context, and audit logging
- Git URL/Branch Validation: Clarified that git.url only allows https:// and git:// schemes; git.branch prevents injection

These security features were implemented in earlier commits focused on hardening the operator for production Kubernetes/OpenShift environments.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Legal blocker for public use — each repo needs its own license file.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Added community files for open-source release readiness:
- CONTRIBUTING.md with operator development workflow, CRD changes, and testing guidance
- SECURITY.md with vulnerability reporting process

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
bobbyjohnstx and others added 18 commits June 26, 2026 11:06
The gitops_private sample CR contains two YAML documents (CR + Secret
example). yaml.safe_load() only handles single documents.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…cense section

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…eneration, RBAC tightening, Helm checksum

- Fix 1: hostPath SCC selection bug — check .path instead of .enabled
- Fix 2: Apply readOnly to hostPath volumeMount in Helm template
- Fix 3: Enforce UID 1001 in restricted/hostpath SCCs (MustRunAs), leave shell SCC flexible
- Fix 4: Add observedGeneration to status
- Fix 5: Remove list/watch from secret RBAC (only get needed)
- Fix 6: Add Helm download checksum verification in Dockerfile
- Fix 7: Compute spec hash to skip no-op Helm upgrades
- Fix 8: Reuse DynamicClient across calls
- Fix 9: Add --liveness flag to CSV command
- Fix 10: Document hostPath ephemeral data in sample YAML

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Added comprehensive unit tests for tinycode-operator covering:
- scc_name_for_spec: SCC selection logic (7 tests)
- validate_vllm_url: URL validation and security checks (10 tests)
- validate_shared_workspace: Multi-replica storage validation (6 tests)
- helm_values_for_spec: Helm values generation (11 tests)
- helm_release_name: Release name formatting (2 tests)
- validate_git_spec: Git configuration validation (3 tests)
- build_vllm_config: vLLM provider config generation (8 tests)

Total: 44 passing tests covering core operator logic.

Added test job to CI workflow to run pytest on every push/PR.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- hostPath SCC selection bug (checked `enabled` instead of `path`)
- readOnly hostPath applied in Helm deployment template
- SCC runAsUser enforced as MustRunAs UID 1001 (restricted + hostpath SCCs)
- observedGeneration set in CR status updates
- Cluster-wide secret RBAC reduced to get-only (removed list/watch)
- Helm binary download checksum verification
- Spec hash skip for no-op Helm upgrades
- DynamicClient reuse (cached instead of per-call)
- CSV liveness flag matches Dockerfile ENTRYPOINT
- 44 unit tests (pytest) covering pure functions and validation logic
- Dependabot configuration for GitHub Actions and pip

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…7, setup-python v6)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…37→1.44.6

kubernetes 36.0.2 fixes urllib3 CVE-2025-66471 (CVSS 8.9, decompression
bomb) and CVE-2025-66418. Also pins urllib3>=2.6.0 explicitly.

kopf 1.44.6 brings improved connection loss detection and proxy support.
All handler decorators and error classes are stable across this range.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The edit ClusterRole cannot create Roles/RoleBindings. The Helm chart
creates RBAC resources for service discovery, requiring admin.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…deploying instances

Cluster-admin must grant the operator admin (not edit) in each target
namespace before creating TinycodeInstance CRs. Documents why admin is
needed (Helm creates Roles/RoleBindings for service discovery) and
provides guidance for environments where cluster-admin is restricted.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- config/rbac/discovery_role.yaml: ClusterRole + ClusterRoleBinding for
  cross-namespace discovery (create/manage ClusterRoles per instance)
- hack/install.sh: apply discovery_role.yaml, update next-steps with
  model annotation and admin rolebinding instructions
- Dockerfile: architecture-aware Helm download (amd64/arm64)
- README: document cross-namespace discovery setup with annotation steps

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…hemes in README

- CONTRIBUTING.md: tinycode_v1_session.yaml → tinycode_v1alpha1_basic.yaml
- README.md: git URL validation lists all 4 allowed schemes (http, https, ssh, git)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Update operator version across Makefile, Chart.yaml, CSV, and catalog.
Pin all sample CRs and CRD defaults to tinycode-container:v1.17.0.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Update all image refs from v1.17.1 to v1.18.0 across CRD defaults,
  samples, bundle manifests, Helm values, and Chart appVersion
- Add docs/OC_CLI_Cheatsheet.md — oc command reference for OCP 4.18

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Updates the requirements on [urllib3](https://github.com/urllib3/urllib3) to permit the latest version.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.6.0...2.8.0)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant