Skip to content

Bump github.com/cert-manager/cert-manager from 1.19.2 to 1.19.3 in the gomodupdates group#1360

Merged
chris-rock merged 1 commit into
mainfrom
dependabot/go_modules/gomodupdates-8c04ba554f
Feb 3, 2026
Merged

Bump github.com/cert-manager/cert-manager from 1.19.2 to 1.19.3 in the gomodupdates group#1360
chris-rock merged 1 commit into
mainfrom
dependabot/go_modules/gomodupdates-8c04ba554f

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Feb 3, 2026

Bumps the gomodupdates group with 1 update: github.com/cert-manager/cert-manager.

Updates github.com/cert-manager/cert-manager from 1.19.2 to 1.19.3

Release notes

Sourced from github.com/cert-manager/cert-manager's releases.

v1.19.3

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release is contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.

Changes by Kind

Bug or Regression

  • Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. (#8415, @​cert-manager-bot)
  • Fixed an issue where HTTP-01 challenges failed when the Host header containing an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. (#8436, @​cert-manager-bot)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#8468, @​SgtCoDFish)

Other (Cleanup or Flake)

Commits
  • d4faed2 Merge pull request #8468 from SgtCoDFish/release-1.19-fqdn-patch
  • 8b62c22 [release-1.19] security: address GHSA-gx3x-vq4p-mhhv
  • 866f955 Merge pull request #8459 from SgtCoDFish/release-1.19-bumpgo
  • 0c04433 [release-1.19] Bump base images with hack/latest-base-images.sh
  • e4556ab [release-1.19] bump go to 1.25.6
  • 845a645 Merge pull request #8436 from cert-manager-bot/cherry-pick-8424-to-release-1.19
  • acd3120 fix(HTTP-01): handling of IPv6 address literals
  • d678763 Merge pull request #8421 from SgtCoDFish/release-1.19-bumpkind
  • 3caf308 [release-1.19] bump kind and bump kind images
  • b2ccdb8 Merge pull request #8415 from cert-manager-bot/cherry-pick-8403-to-release-1.19
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the gomodupdates group with 1 update: [github.com/cert-manager/cert-manager](https://github.com/cert-manager/cert-manager).


Updates `github.com/cert-manager/cert-manager` from 1.19.2 to 1.19.3
- [Release notes](https://github.com/cert-manager/cert-manager/releases)
- [Changelog](https://github.com/cert-manager/cert-manager/blob/master/RELEASE.md)
- [Commits](cert-manager/cert-manager@v1.19.2...v1.19.3)

---
updated-dependencies:
- dependency-name: github.com/cert-manager/cert-manager
  dependency-version: 1.19.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomodupdates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Feb 3, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Feb 3, 2026

Test Results

0 files   -   5  0 suites   - 41   0s ⏱️ - 36m 14s
0 tests  - 280  0 ✅  - 280  0 💤 ±0  0 ❌ ±0 
0 runs   - 295  0 ✅  - 295  0 💤 ±0  0 ❌ ±0 

Results for commit b220976. ± Comparison against base commit 3d2cea2.

@chris-rock chris-rock merged commit 99fc0ca into main Feb 3, 2026
37 checks passed
@chris-rock chris-rock deleted the dependabot/go_modules/gomodupdates-8c04ba554f branch February 3, 2026 18:10
@github-actions github-actions Bot locked and limited conversation to collaborators Feb 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant