main
fix: add check for image registry capability
test/extended: use NamespacePodSecurityLevel rather than NamespacePodSecurityEnforceLevel
priority class: Add an exception for Istio
bump(k8s): adjust codebase to align with the new go and k8s.io deps