6835 Commits
Author SHA1 Message Date
KrishhnaTandGitHub 4e481fb7c2 test: use the Kind constant instead of the string literal (#10524)
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
* test: use the Kind constant instead of the string literal

test/types.go defines `const Kind = "kind"` and most of the suite compares
against it, but three sites still use the bare string. deletion.go is
inconsistent with itself: the BeforeEach skip uses Kind while the one in
runBackupDeletionTests uses "kind", and its skip message hardcodes the
provider name where the other formats it.

namespace-mapping.go dot-imports test/e2e/test rather than test, so the
constant was not in scope there. Import the test package by name, as
test/e2e/migration/migration.go already does alongside its framework
import, and reference test.Kind.

No behavioural change: the constant's value is the string being replaced.

Signed-off-by: krishhna24 <krishhnatupedev@gmail.com>

* Add changelog for #10524

Signed-off-by: krishhna24 <krishhnatupedev@gmail.com>

---------

Signed-off-by: krishhna24 <krishhnatupedev@gmail.com>
2026-09-11 14:21:41 -07:00
lyndon-liandGitHub 7e67f03796 Merge pull request #10513 from ywk253100/cli
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Update volume info in restore finalizing stage
2026-09-11 16:02:50 +08:00
lyndon-liandGitHub 34a9f500cc let uploader to control fallback centrally (#10523)
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-11 00:34:13 -04:00
Chlins ZhangandGitHub 3df8ef0567 Regenerate CRDs for the sourceSize status field (#10516)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Scorecard supply-chain security / Scorecard analysis (push) Skipped
Main CI / get-go-version (push) Failing after 9s
Main CI / Build (push) Skipped
#10506 added SourceSize to the PodVolumeBackup and DataUpload status
types but did not regenerate the CRD manifests. Without the field in the
CRD schema, the API server silently drops status.sourceSize on write, so
the recorded source size never reaches the cluster objects.

Generated with hack/update-3generated-crd-code.sh (controller-gen
v0.16.5).

Signed-off-by: chlins <chlins.zhang@gmail.com>
2026-09-10 15:46:08 +08:00
Wenkai Yin (尹文开) a3d744db6a Update volume info in restore finalizing stage
Update volume info in restore finalizing stage to record info from DataDownload result

Signed-off-by: Wenkai Yin (尹文开) <wenkai.yin@broadcom.com>
2026-09-10 15:04:54 +08:00
lyndon-liandGitHub 87b45ed7fd Merge pull request #10506 from Lyndon-Li/save-source-size-to-backup
Save source size to volume info
2026-09-10 14:29:48 +08:00
lyndon-liandGitHub e8af012ac5 Merge pull request #10479 from Lyndon-Li/report-incremental-fallback
Report incremental fallback message
2026-09-10 14:29:19 +08:00
Max Freedom PollardandGitHub 4c007c0af4 Scope schedule and repo CLI list calls to the Velero namespace (#10482)
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 7s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Scorecard supply-chain security / Scorecard analysis (push) Skipped
* Scope schedule and repo CLI list calls to the Velero namespace

velero schedule get, velero schedule describe, velero schedule
pause/unpause and velero repo get built a ctrlclient.ListOptions with a
LabelSelector but no Namespace, so the list ran across every namespace in
the cluster. Their single-name paths in the same functions already scope
to f.Namespace(), and every sibling command (backup get, restore get,
backup describe, restore describe, snapshot-location get, schedule
delete) passes Namespace too, so the omission was an oversight rather
than intent.

The read commands print another installation's Schedules and
BackupRepositories. runPause is worse: velero schedule pause --all and
velero schedule unpause --all fetch Schedules from every namespace and
then write Spec.Paused on each, so pausing one installation's schedules
pauses every other installation's schedules as well.

Add Namespace: f.Namespace() to the four List calls:

  pkg/cmd/cli/schedule/get.go:61
  pkg/cmd/cli/schedule/describe.go:59
  pkg/cmd/cli/schedule/pause.go:114
  pkg/cmd/cli/repo/get.go:61

Neither pkg/cmd/cli/schedule nor pkg/cmd/cli/repo had any tests, so the
regression tests are new files. Each seeds a fake client with one object
in the Velero namespace and one in another-velero, and asserts the second
is neither listed, described, nor paused.

Signed-off-by: Max Freedom Pollard <272618364+MaxFreedomPollard@users.noreply.github.com>

* Add changelog for PR 10482

Signed-off-by: Max Freedom Pollard <272618364+MaxFreedomPollard@users.noreply.github.com>

---------

Signed-off-by: Max Freedom Pollard <272618364+MaxFreedomPollard@users.noreply.github.com>
2026-09-09 16:52:11 -04:00
Shubham PampattiwarandGitHub 15458caf4a Add OpenSSF Scorecard workflow and README badge (#10467)
Velero has no published OpenSSF Scorecard results, so the Scorecard
badge does not resolve and CLOMonitor flags the openssf_scorecard_badge
check as missing.

Add the ossf/scorecard-action workflow (SHA-pinned, least-privilege
permissions, publish_results enabled) running weekly and on push to
main. Once it runs post-merge, results publish to the OpenSSF API and
the README badge resolves. This also surfaces the project's security
posture (currently 6.2/10) to guide further hardening.

Part of the CNCF incubation readiness work (#10383).

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-09 12:26:29 -07:00
HeonJe LeeandGitHub cbd9059f80 Fix user version priorities parsing to handle CRLF line endings (#10496)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 5s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
formatUserPriorities stripped only spaces, so an enableapigroupversions
ConfigMap written with CRLF line endings (common for files edited on
Windows) kept a trailing carriage return in each version string, e.g.
"v2beta1\r". versionsContain compares versions with equality, so the
user priority never matched and was silently ignored. Trim the trailing
carriage return so stored versions match again.

Signed-off-by: HeonJe LEE <lhjnano@gmail.com>
2026-09-09 10:24:42 -04:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
267e8fe4a3 Bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#10504)
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.83.1 to 1.83.2.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-09 09:56:38 -04:00
Lyndon-Li daed42b1d8 save source size to volume info for DU and PVB
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-09 17:34:17 +08:00
Lyndon-Li e0e600d715 save source size for PVB
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-09 16:09:08 +08:00
Lyndon-Li e52bf08c99 refactor CBT retrievement to report the concrete error
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-09 15:55:01 +08:00
Lyndon-Li 6b549f35b3 Merge branch 'main' into save-source-size-to-backup 2026-09-09 15:50:06 +08:00
Tiger KaovilaiandGitHub 193cfdc58f Fix datamover backup arg mismatch for CSI CBT service account name (#10318)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 6s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
* Fix datamover backup arg mismatch for CSI CBT service account name

The exposer built the pod command with --csi-snapshot-metadata-service-sa,
but the datamover backup command only registered --cbt-sa-name. cobra
rejects unknown flags, so the data mover pod exited immediately whenever
a dedicated CBT service account was configured -- and the reverse also
held: since the flags never matched, the SA name never actually reached
the pod, so any code path depending on it stayed unreachable.

Not limited to the block data mover: this line sits outside the
DataMoverTypeVeleroBlock gate and the cbtInfo != nil gate, so it fires
for any CSI snapshot data-movement backup.

Fix: emit --cbt-sa-name (already consumed by the backup command), naming
it consistently with the other CBT flags on the same line (--change-id,
--volume-id, --snapshot-id).

Add a regression test asserting the emitted flag string parses cleanly
against NewBackupCommand's own flag set, so the two sides can't drift
apart again without a test failure.

* Add changelog for #10318

Signed-off-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-09 06:34:06 +00:00
Lyndon-Li 44f09189c2 Merge branch 'main' into report-incremental-fallback 2026-09-09 14:19:59 +08:00
Yonghui Li 9d85334d40 refactor CBT retrievement to report the concrete error
Signed-off-by: Yonghui Li <lyonghui@vmware.com>
2026-09-09 14:14:54 +08:00
Xun Jiang/Bruce JiangandGitHub c7a93be95a Add MustIncludeAdditionalItemPVCs to help track BIA added PVC's PVB creation. (#10501)
* Add MustIncludeAdditionalItemPVCs structure in backup. It's used to track PVCs returned by BIA with mustIncluded annotaion and PVC is excluded from backup by global filter.
* Modfiy the volumeHelper interface to add a parameter function for ShouldPerformFSBackup.
* Modify to support fine-grained backup filters.
* Modify according to comments. Use a read-only interface to replace the parameter function.

Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
2026-09-09 14:04:57 +08:00
lyndon-liandGitHub 88da86fb67 Merge pull request #10500 from Lyndon-Li/add-id-to-repo-snapshot
Add ID to repo snapshot
2026-09-09 11:02:49 +08:00
lyndon-liandGitHub 32c918b0fa Merge pull request #10307 from kaovilai/pr-bug4-gap6
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 10s
Run the E2E test on kind / get-go-version (push) Failing after 11s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Fix generic CSI changeID retrieval and honor snapshot class deletion policy for CBT retention
2026-09-09 08:36:31 +08:00
Daniel JiangandGitHub 907b181239 Fix the link of slack channels in README.md (#10499)
Signed-off-by: Daniel Jiang <daniel.jiang@broadcom.com>
2026-09-08 19:21:35 -04:00
Yonghui Li 8e604b17b2 add ID to repo snapshot
Signed-off-by: Yonghui Li <lyonghui@vmware.com>
2026-09-08 18:15:34 +08:00
dependabot[bot]GitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
84eb5669ac Bump helm/kind-action in the github-actions group (#10481)
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
e2e-test-kind.yaml / extract (push) Failing after 11s
Run the E2E test on kind / get-go-version (push) Failing after 12s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
Bumps the github-actions group with 1 update: [helm/kind-action](https://github.com/helm/kind-action).


Updates `helm/kind-action` from c72b4750145dbfb1c71734c3782a4db35a1c65c0 to 06c1ae10762d3b9c1644e7fe69596ae519e015a2
- [Release notes](https://github.com/helm/kind-action/releases)
- [Commits](https://github.com/helm/kind-action/compare/c72b4750145dbfb1c71734c3782a4db35a1c65c0...06c1ae10762d3b9c1644e7fe69596ae519e015a2)

---
updated-dependencies:
- dependency-name: helm/kind-action
  dependency-version: 06c1ae10762d3b9c1644e7fe69596ae519e015a2
  dependency-type: direct:production
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-08 16:42:26 +08:00
Xun Jiang/Bruce JiangGitHubdependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
a7f836051e Bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#10462)
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.1 to 1.83.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.82.1...v1.83.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.83.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-08 15:50:31 +08:00
Yonghui Li 9fedb48e9a Merge branch 'main' into report-incremental-fallback 2026-09-08 14:11:24 +08:00
0255c6b8bf Add block data mover support for Velero backup/restore describe CLI. (#10436)
e2e-test-kind.yaml / extract (push) Failing after 10s
Run the E2E test on kind / get-go-version (push) Failing after 11s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 3s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
* Add block data mover support for Velero backup/restore describe CLI.

Update output tests to accommodate RestoreType in VolumeInfo
This commit addresses the compilation and assertion errors caused by the introduction of `RestoreType` in `VolumeInfo` and the separation of `SnapshotDataMovementInfo` / `PodVolumeInfo` into their backup and restore counterparts. It fixes references across the test fixtures and the print guard conditions in `restore_describer.go`.

* Modify according to comments
* Add missing JSON tag in the VolumeInfo structures.
* Get uploaderType from the DU and DD's dataMover for the data mover volume info.
* Add IncrementalSize in the data mover volume info.
* Add existingVolumeDataPolicy and restoreType in the restore describe CLI output
* Add more UTs.
* Add some fields value setting that were previously missed.
* Fix the timestamp compare error only found in the GitHub action.

Signed-off-by: Xun Jiang <xun.jiang@broadcom.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-07 14:48:41 +08:00
Lyndon-Li e1600caab3 record source size to volume info
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 19:50:45 +08:00
Lyndon-Li 6c86921876 du support source size
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 19:49:12 +08:00
Lyndon-Li d0884e7ce7 return source size from uploader
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 19:45:12 +08:00
Lyndon-Li df709d39d6 report incremental fallback message
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 17:21:57 +08:00
Lyndon-Li 9687d1e30e Merge branch 'main' into report-incremental-fallback 2026-09-04 16:15:06 +08:00
Lyndon-Li b93c24c58a report incremental fallback message
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 16:10:54 +08:00
Lyndon-Li 5146992b5b add UT for progress message
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 16:04:38 +08:00
Chlins ZhangandGitHub f2ad7f081b Merge pull request #10475 from chlins/feat/inplace-preflight-check2
Run the E2E test on kind / setup-test-matrix (push) Failing after 7s
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 6s
Main CI / get-go-version (push) Failing after 7s
Main CI / Build (push) Skipped
Add in-place restore pre-flight check: PVC must be bound to the backed-up PV
2026-09-04 15:45:49 +08:00
Shubham PampattiwarandGitHub 89a3c1c1be Add .clomonitor.yml with Artifact Hub badge exemption (#10469)
The Velero core repository is not distributed as an Artifact Hub package,
so the CLOMonitor artifacthub_badge check is not applicable. Declare an
exemption with justification per CLOMonitor's metadata schema.

Part of the CNCF incubation readiness work (#10383).

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-04 15:28:05 +08:00
Lyndon-Li 1048f26c20 controllers support message in progress
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 14:28:31 +08:00
Lyndon-Li 67923bca6f uploader report incremental fallback
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 14:17:28 +08:00
Lyndon-Li 7e968e10d8 UT for new bitmap implementation
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 13:48:17 +08:00
Lyndon-Li 6ec84c30f8 enhance CBT retrievement to indicate the result in error message
Signed-off-by: Lyndon-Li <lyonghui@vmware.com>
2026-09-04 13:32:24 +08:00
Shubham PampattiwarandGitHub 0af5adf8d5 Fix governance discoverability for CLOMonitor (MAINTAINERS.md link + README section) (#10466)
e2e-test-kind.yaml / extract (push) Failing after 8s
Run the E2E test on kind / get-go-version (push) Failing after 9s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
* Fix dead GOVERNANCE.md link in MAINTAINERS.md

The GOVERNANCE.md link pointed to the old vmware-tanzu/velero path,
which now returns a 404. Governance now lives at the org level under
velero-io/.github. Repoint the link so it resolves correctly.

Part of the CNCF incubation readiness work (#10383).

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>

* Add Governance section to README for discoverability

CLOMonitor's governance check looks for a governance file or a
governance reference (header/link) in the README, not in MAINTAINERS.md.
Add a Governance section to the README linking the org-level
GOVERNANCE.md so the check passes and the info is discoverable.

Part of the CNCF incubation readiness work (#10383).

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>

---------

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-04 13:31:20 +08:00
KrishhnaTandGitHub df180c039c Merge pull request #10477 from krishhna24/e2e-gitignore-debug-bundle
Ignore e2e debug bundles
2026-09-04 11:16:42 +08:00
Xun Jiang/Bruce JiangandGitHub 39789bdd24 Merge pull request #10471 from shubham-pampattiwar/ci/workflow-token-permissions
Set least-privilege GITHUB_TOKEN permissions in workflows
2026-09-04 11:07:29 +08:00
31333f7610 Add structured JSON output for velero restore describe command (#9983)
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 9s
Run the E2E test on kind / get-go-version (push) Failing after 10s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 5s
Main CI / get-go-version (push) Failing after 6s
Main CI / Build (push) Skipped
* Add structured JSON output for velero restore describe command

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Add changelog for PR 9983

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Fix CSI snapshot restore JSON output to distinguish snapshot vs dataMovement type

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Remove the redundant details wrapper key from podVolumeRestores so phase counts sit flat alongside uploaderType, matching the plaintext output structure.

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Add missing resourcePolicy to json struct

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Fix linter issue

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* fix codecoverage

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Handle nil CSI snapshot fields in restore JSON describe

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

* Fix lint issue

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>

---------

Signed-off-by: Prasad Joshi <prajoshi@redhat.com>
Co-authored-by: lyndon-li <98304688+Lyndon-Li@users.noreply.github.com>
Co-authored-by: Tiger Kaovilai <tkaovila@redhat.com>
2026-09-03 14:36:51 -04:00
Shubham PampattiwarandGitHub a96f567f38 Add Community section with meeting info to README (#10468)
The README had no reference to Velero's community meetings, which CLOMonitor
flags via the community_meeting check. Community meeting details already live
on the community page but were not discoverable from the README.

Add a Community section linking the bi-weekly community meetings, project
meeting calendar, YouTube archive, Slack, and mailing list.

Part of the CNCF incubation readiness work (#10383).

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-03 13:55:19 -04:00
Shubham Pampattiwar 3191e38ac3 Set least-privilege GITHUB_TOKEN permissions in workflows
Add an explicit top-level permissions block to the GitHub Actions
workflows that were relying on the default token permissions. Each
workflow now defaults to contents: read, with additional scopes granted
only where a job needs them:

* nightly-trivy-scan keeps security-events: write at the job level to
  upload SARIF results, plus contents: read for checkout.
* stale-issues gets issues: write and pull-requests: write for the
  actions/stale action to label and close stale items.

Setting least-privilege permissions reduces the blast radius if a
workflow or one of its dependencies is compromised, and satisfies the
CLOMonitor token_permissions check.

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-03 10:14:23 -07:00
Shubham PampattiwarandGitHub 1d9391b85e Evaluate changelog exemption labels from live PR state (#10472)
The changelog check decided whether a PR was exempt using the labels in
the triggering event payload (github.event.pull_request.labels). That
payload is frozen at event time, so a PR that gets the
kind/changelog-not-required label after its first run could not pass by
re-running the failed job, and the exemption only took effect if a brand
new event happened to fire afterward.

Move the exemption logic into hack/changelog-check.sh and query the PR's
current labels via the GitHub API instead. Re-runs and labels added after
the initial run are now evaluated correctly. The workflow grants
pull-requests: read and passes github.token so the script can read labels.

The exempt label set (kind/changelog-not-required, Design, Website,
Documentation) is unchanged.

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-03 09:58:20 -07:00
Shubham PampattiwarandGitHub fea3e27e9a Add OpenSSF Security Insights manifest and dependency management docs (#10470)
Add a schema-valid OpenSSF Security Insights v2 (2.2.0) manifest at
SECURITY-INSIGHTS.yml describing the project's maintainers, vulnerability
reporting process, license, and links to governance, security, and
dependency management policies.

Also add a Dependency management section to the development docs covering
Go modules, Dependabot automation, review process, and how security
relevant dependency updates are handled. The manifest references this
section as the dependency management policy.

This improves the project's CLOMonitor score by satisfying the
security_insights and dependencies_policy checks.

Signed-off-by: Shubham Pampattiwar <spampatt@redhat.com>
2026-09-03 11:39:42 -04:00
Wenkai Yin(尹文开)andGitHub ccfdce30f9 Fall back to full restore rather than fail if fail to get the volume ID (#10465)
Run the E2E test on kind / setup-test-matrix (push) Failing after 4s
e2e-test-kind.yaml / extract (push) Failing after 7s
Run the E2E test on kind / get-go-version (push) Failing after 8s
Run the E2E test on kind / build (push) Skipped
Run the E2E test on kind / run-e2e-test (push) Skipped
push.yml / extract (push) Failing after 7s
Main CI / get-go-version (push) Failing after 8s
Main CI / Build (push) Skipped
Fall back to full restore rather than fail if fail to get the volum
e ID

Signed-off-by: Wenkai Yin(尹文开) <yinw@vmware.com>
2026-09-03 14:56:35 +08:00
chlins fa717d4e48 Add in-place restore pre-flight check: PVC must be bound to the backed-up PV
An in-place restore onto a different volume than the one backed up is
unsafe: an incremental (CBT) restore computes deltas against a different
volume lineage, and even a full restore would patch and write into an
unrelated volume. Verify the existing PVC is bound and still bound to
the PV recorded at backup time before any side effect, on both the CSI
data mover path (using the backed-up PVC's volume name) and the file
system path (using the PVC-to-PV mapping from the backup volume info).

The PV comparison is skipped for namespace-mapped restores, where the
target PVC is necessarily bound to a different PV (the documented
cross-namespace clone-and-restore workflow).

Signed-off-by: chlins <chlins.zhang@gmail.com>
2026-09-03 13:59:42 +08:00