Skip to content

chore(deps): update module gopkg.in/yaml.v2 to v3 - #296

Open
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/gopkg.in-yaml.v2-3.x
Open

chore(deps): update module gopkg.in/yaml.v2 to v3#296
red-hat-konflux-kflux-prd-rh03[bot] wants to merge 1 commit into
masterfrom
konflux/mintmaker/master/gopkg.in-yaml.v2-3.x

Conversation

@red-hat-konflux-kflux-prd-rh03

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot commented Jun 17, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
gopkg.in/yaml.v2 v2.4.0v3.0.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

go-yaml/yaml (gopkg.in/yaml.v2)

v3.0.1

Compare Source

v3.0.0

Compare Source


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • Between 02:00 AM and 04:59 AM, Monday through Friday (* 2-4 * * 1-5)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot added area/dependency Issues or PRs related to dependency changes major-update manual-review-required ok-to-test Indicates a non-member PR verified by an org member that is safe to test. labels Jun 17, 2026
@openshift-ci
openshift-ci Bot requested review from Tafhim and TheUndeadKing June 17, 2026 04:26
@openshift-ci

openshift-ci Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Hi @red-hat-konflux-kflux-prd-rh03[bot]. Thanks for your PR.

I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@codecov-commenter

codecov-commenter commented Jun 17, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 65.39%. Comparing base (b94404b) to head (aa64107).

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #296   +/-   ##
=======================================
  Coverage   65.39%   65.39%           
=======================================
  Files          23       23           
  Lines        1598     1598           
=======================================
  Hits         1045     1045           
  Misses        473      473           
  Partials       80       80           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/gopkg.in-yaml.v2-3.x branch from a60b780 to f12693f Compare July 8, 2026 04:08
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update module gopkg.in/yaml.v2 to v3 chore(deps): update module gopkg.in/yaml.v2 to v3 - autoclosed Jul 27, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot deleted the konflux/mintmaker/master/gopkg.in-yaml.v2-3.x branch July 27, 2026 08:03
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update module gopkg.in/yaml.v2 to v3 - autoclosed chore(deps): update module gopkg.in/yaml.v2 to v3 Jul 28, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/gopkg.in-yaml.v2-3.x branch from f12693f to 50ea4fe Compare July 28, 2026 04:11
@openshift-ci

openshift-ci Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux-kflux-prd-rh03[bot]
Once this PR has been reviewed and has the lgtm label, please assign charlesgong for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

1 similar comment
@openshift-ci

openshift-ci Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: red-hat-konflux-kflux-prd-rh03[bot]
Once this PR has been reviewed and has the lgtm label, please assign charlesgong for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update module gopkg.in/yaml.v2 to v3 chore(deps): update module gopkg.in/yaml.v2 to v3 - autoclosed Aug 2, 2026
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update module gopkg.in/yaml.v2 to v3 - autoclosed chore(deps): update module gopkg.in/yaml.v2 to v3 Aug 3, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/gopkg.in-yaml.v2-3.x branch 2 times, most recently from 50ea4fe to 36718b0 Compare August 3, 2026 04:10
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update module gopkg.in/yaml.v2 to v3 chore(deps): update module gopkg.in/yaml.v2 to v3 - autoclosed Aug 30, 2026
@fullsend-ai-retro

fullsend-ai-retro Bot commented Aug 30, 2026

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 8:04 PM UTC · Completed 8:17 PM UTC

Commit: 36718b0 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.38

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #296 — Renovate gopkg.in/yaml.v2 to v3 (autoclosed)

What happened: PR #296 was created by the MintMaker/Renovate bot on 2026-06-17 to "update" gopkg.in/yaml.v2 from v2.4.0 to v3.0.1. The PR was autoclosed/reopened 3 times over 74 days before being permanently closed on 2026-08-30. All Prow CI checks failed (coverage, lint, images, e2e). No human ever reviewed it. The only fullsend agent interaction was this retro, triggered by the final close event (workflow run 33332576701).

Key finding: The update is semantically invalid for Go modules. gopkg.in/yaml.v2 and gopkg.in/yaml.v3 are different Go modules with different import paths — you cannot "upgrade" one to the other by changing the version number. The actual diff just moved a line between require blocks in go.mod without changing anything meaningful. Renovate's own Dependency Dashboard (issue #187) lists gopkg.in/yaml.v2 as both an abandoned dependency and a lookup failure.

Broader pattern: This is not an isolated incident. Across 30+ closed MintMaker PRs, zero actual dependency updates have been merged (0% merge rate). Five similar major-version bump PRs remain open (#293, #294, #295, #308, #310), each open for 50-75+ days. A parallel PR #308 proposes the same invalid v2→v3 bump for go.yaml.in/yaml/v2. The Renovate config (inherited from openshift/boilerplate) correctly labels these as major-update and manual-review-required, but no one acts on them.

Fullsend workflow assessment: The fullsend routing worked correctly — the close event routed to the retro stage, and triage/code/review/fix agents were properly skipped. No agent-layer issues identified.

Existing issue note: Issue #330 covers a similar pattern for ubi9/ubi-minimal Dependabot PRs but targets a different dependency manager and package. The proposal below addresses the MintMaker/Renovate side of the same class of problem.

Proposals filed

Signed-off-by: red-hat-konflux-kflux-prd-rh03 <206760901+red-hat-konflux-kflux-prd-rh03[bot]@users.noreply.github.com>
@red-hat-konflux-kflux-prd-rh03 red-hat-konflux-kflux-prd-rh03 Bot changed the title chore(deps): update module gopkg.in/yaml.v2 to v3 - autoclosed chore(deps): update module gopkg.in/yaml.v2 to v3 Aug 31, 2026
@red-hat-konflux-kflux-prd-rh03
red-hat-konflux-kflux-prd-rh03 Bot force-pushed the konflux/mintmaker/master/gopkg.in-yaml.v2-3.x branch 2 times, most recently from 36718b0 to aa64107 Compare August 31, 2026 04:11
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:12 AM UTC · Completed 4:25 AM UTC

Commit: aa64107 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.22

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

High

  • [logic-error] go.mod:45 — The PR title claims to "update module gopkg.in/yaml.v2 to v3", but the actual diff only moves the gopkg.in/yaml.v2 v2.4.0 line from one require block to another within go.mod. No version update occurs — the dependency remains at v2.4.0. In Go modules, gopkg.in/yaml.v2 and gopkg.in/yaml.v3 are distinct module paths; a genuine upgrade requires changing all import statements in .go files, adapting to API differences, and removing the v2 dependency. gopkg.in/yaml.v3 v3.0.1 was already present before this PR. The change as written is a no-op with no functional effect.
    Remediation: Either (a) close this PR since it does not accomplish what it claims, or (b) perform the actual yaml.v2→v3 migration: update transitive dependencies, change import paths in source files, adapt to yaml.v3 API differences, remove the yaml.v2 require line, and run go mod tidy.

Low

  • [scope-intent-mismatch] go.mod — The PR title and body claim a major version upgrade from v2.4.0 to v3.0.1, but the diff only relocates gopkg.in/yaml.v2 v2.4.0 between require blocks with no version change. This appears to be a MintMaker/Renovate misconfiguration — the bot generated a PR that cannot accomplish a v2→v3 migration for a gopkg.in-style Go module path.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

Comment thread go.mod
go.yaml.in/yaml/v2 v2.4.4 // indirect
go.yaml.in/yaml/v3 v3.0.4 // indirect
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[high] logic-error

The PR title claims to 'update module gopkg.in/yaml.v2 to v3', but the actual diff only moves the gopkg.in/yaml.v2 v2.4.0 line from one require block to another within go.mod. No version update occurs — the dependency remains at v2.4.0. In Go modules, gopkg.in/yaml.v2 and gopkg.in/yaml.v3 are distinct module paths; a genuine upgrade requires changing all import statements in .go files, adapting to API differences, and removing the v2 dependency. gopkg.in/yaml.v3 v3.0.1 was already present before this PR. The change as written is a no-op with no functional effect.

Suggested fix: Either (a) close this PR since it does not accomplish what it claims, or (b) perform the actual yaml.v2-to-v3 migration: update transitive dependencies, change import paths in source files, adapt to yaml.v3 API differences, remove the yaml.v2 require line, and run go mod tidy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Issues or PRs related to dependency changes major-update manual-review-required ok-to-test Indicates a non-member PR verified by an org member that is safe to test.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant