fix(container): update flux controllers (patch) #448

Open
renovate wants to merge 3 commits from renovate/patch-flux-controllers into main
Member

This PR contains the following updates:

Package Update Change Released Age (d)
ghcr.io/coredns/charts/coredns (source) patch 1.46.01.46.2
ghcr.io/k8s-gateway/charts/k8s-gateway patch 3.7.13.7.2
ghcr.io/kyverno/charts/kyverno (source) patch 3.8.13.8.2
ghcr.io/spegel-org/helm-charts/spegel patch 0.7.10.7.4
harbor.webgrip.dev/forgejo/forgejo-helm/forgejo (source) patch 17.1.017.1.4
harbor.webgrip.dev/ghcr/grafana/helm-charts/pyroscope (source) patch 2.0.22.0.3
harbor.webgrip.dev/ghcr/home-operations/charts-mirror/metrics-server patch 3.13.03.13.1
harbor.webgrip.dev/ghcr/opencost/charts/opencost patch 2.5.252.5.28
harbor.webgrip.dev/ghcr/prometheus-community/charts/kube-state-metrics patch 7.5.17.5.3
harbor.webgrip.dev/ghcr/prometheus-community/charts/prometheus-node-exporter patch 4.55.04.55.1
harbor.webgrip.dev/ghcr/prometheus-community/charts/prometheus-operator-crds patch 30.0.030.0.1
harbor.webgrip.dev/ghcr/stakater/charts/reloader patch 2.2.122.2.14
harbor.webgrip.dev/ghcr/victoriametrics/helm-charts/victoria-metrics-operator (source) patch 0.66.20.66.3
keda patch 2.20.02.20.2 2026-07-31T09:12:31.058Z 4d
longhorn (source) patch 1.11.21.11.3 2026-07-02T00:56:51.480Z 34d
mirror.gcr.io/envoyproxy/gateway-helm (source) patch v1.8.01.8.3 2026-07-22T18:58:01.651Z 13d
quay.io/jetstack/charts/cert-manager (source) patch v1.20.2v1.20.3

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

📦 Grouped update: confirm the group is operationally coherent before merging.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Grouped GitOps PR: confirm the group is operationally coherent before enabling automerge.

Released is the upstream publish time; means this registry reports no timestamp, so no soak applies and the PR is eligible on the next Renovate run. Otherwise add the soak for this update type (patch 1d, minor 3d, digest 0d) to Released — the first hourly run after that merges it.


Release Notes

forgejo-helm/forgejo-helm (harbor.webgrip.dev/forgejo/forgejo-helm/forgejo)

v17.1.4: 17.1.4

Compare Source

Bug Fixes
Continuous Integration
Miscellaneous Chores

v17.1.3: 17.1.3

Compare Source

Bug Fixes
Tests
Continuous Integration
Miscellaneous Chores

v17.1.2: 17.1.2

Compare Source

Bug Fixes
Continuous Integration
Miscellaneous Chores

v17.1.1: 17.1.1

Compare Source

Bug Fixes
Continuous Integration
Miscellaneous Chores
grafana/pyroscope (harbor.webgrip.dev/ghcr/grafana/helm-charts/pyroscope)

v2.0.3

Compare Source

Changelog

As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:

Docker Images

  docker pull grafana/pyroscope:2.0.3
kedacore/keda (keda)

v2.20.2

Compare Source

Improvements
  • General: Introduce a dedicated HPAActive condition on ScaledObject mirroring the HPA's own ScalingActive status, so transient HPA metric gaps no longer flip the Ready condition to False (#​7914)
Fixes
  • General: Fix concurrent map writes panic in the shared root CA CertPool (#​7910)
  • General: Fix nil pointer dereference in AWS Secret Manager TriggerAuthentication when awsSecretManager.credentials is omitted and no awsSecretManager.podIdentity is set (#​7927)
  • General: Fix nil pointer dereference in customScalingStrategy.GetEffectiveMaxScale when customScalingQueueLengthDeduction is omitted; the optional field is now treated as zero deduction instead of panicking (#​7798)
  • General: Fix nil pointer dereference in GetCurrentReplicas when a Deployment/StatefulSet/ReplicaSet is returned from the informer cache with an undefaulted spec.replicas; a nil value is now treated as the Kubernetes default of 1 instead of panicking (#​7863)
  • General: Fix ScaledJob CRD validation to include "default" as a valid value for scalingStrategy.strategy (#​7855)
  • General: Guard GetCurrentReplicas against nil Status.ScaleTargetGVKR to prevent operator panics under the cache race documented in (#​4389) / (#​4955)
  • General: Restore core "" API group in events RBAC so that client-go's event broadcaster can write legacy events (#​7922)
  • General: Restore gRPC reconnect backoff in the metrics service client; an unset Backoff in WithConnectParams disabled backoff and caused a zero-delay reconnect loop that flooded logs when keda-operator was unreachable (#​7856)
  • General: Share HTTP transports across scalers to reuse connection pools and avoid re-dial storms at high ScaledObject counts (#​7789)
  • General: Treat negative external metric values as zero to prevent incorrect HPA scaling (#​7880)
  • Azure Blob Storage Scaler: Fix globPattern never matching when written in path-style with a leading /, since blob names never have one (#​6492)
  • MongoDB Scaler: Disconnect the client when the initial Ping fails so the background topology-monitoring connections opened by mongo.Connect are not leaked (#​5612)

v2.20.1

Compare Source

Fixes
  • General: Fix concurrent map read/write data race in fallback updateStatus that caused panics when multiple triggers were scaling simultaneously (#​7838)
  • General: Fix KEDAScalersStarted "Started scalers watch" event not being emitted for ScaledJobs because it shared an events.k8s.io aggregation key with the per-scaler "scaler is built" event (#​7820)
longhorn/charts (longhorn)

v1.11.3

Compare Source

Longhorn is a distributed block storage system for Kubernetes.

envoyproxy/gateway (mirror.gcr.io/envoyproxy/gateway-helm)

v1.8.3

Compare Source

Release Announcement

Check out the v1.8.3 release announcement to learn more about the release.

What's Changed

Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3

v1.8.3

Compare Source

Release Announcement

Check out the v1.8.3 release announcement to learn more about the release.

What's Changed

Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3

v1.8.2

Compare Source

Release Announcement

Check out the v1.8.2 release announcement to learn more about the release.

What's Changed

Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2

v1.8.2

Compare Source

Release Announcement

Check out the v1.8.2 release announcement to learn more about the release.

What's Changed

Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2

v1.8.1

Compare Source

Release Announcement

Check out the v1.8.1 release announcement to learn more about the release.

What's Changed

Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1

v1.8.1

Compare Source

Release Announcement

Check out the v1.8.1 release announcement to learn more about the release.

What's Changed

Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1

cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)

v1.20.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.

All users should upgrade.

[!WARNING]
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.

Changes by Kind
Bug or Regression
Other (Cleanup or Flake)

v1.20.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.

All users should upgrade.

[!WARNING]
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.

Changes by Kind
Bug or Regression
Other (Cleanup or Flake)

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Update | Change | Released | Age (d) | |---|---|---|---|---| | [ghcr.io/coredns/charts/coredns](https://coredns.io) ([source](https://github.com/coredns/coredns)) | patch | `1.46.0` → `1.46.2` | — | — | | [ghcr.io/k8s-gateway/charts/k8s-gateway](https://github.com/k8s-gateway/k8s_gateway) | patch | `3.7.1` → `3.7.2` | — | — | | [ghcr.io/kyverno/charts/kyverno](https://kyverno.io/) ([source](https://github.com/kyverno/kyverno)) | patch | `3.8.1` → `3.8.2` | — | — | | ghcr.io/spegel-org/helm-charts/spegel | patch | `0.7.1` → `0.7.4` | — | — | | [harbor.webgrip.dev/forgejo/forgejo-helm/forgejo](https://forgejo.org/) ([source](https://code.forgejo.org/forgejo-helm/forgejo-helm)) | patch | `17.1.0` → `17.1.4` | — | — | | [harbor.webgrip.dev/ghcr/grafana/helm-charts/pyroscope](https://grafana.com/oss/pyroscope/) ([source](https://github.com/grafana/pyroscope)) | patch | `2.0.2` → `2.0.3` | — | — | | [harbor.webgrip.dev/ghcr/home-operations/charts-mirror/metrics-server](https://github.com/kubernetes-sigs/metrics-server) | patch | `3.13.0` → `3.13.1` | — | — | | [harbor.webgrip.dev/ghcr/opencost/charts/opencost](https://github.com/opencost/opencost-helm-chart) | patch | `2.5.25` → `2.5.28` | — | — | | [harbor.webgrip.dev/ghcr/prometheus-community/charts/kube-state-metrics](https://github.com/kubernetes/kube-state-metrics) | patch | `7.5.1` → `7.5.3` | — | — | | [harbor.webgrip.dev/ghcr/prometheus-community/charts/prometheus-node-exporter](https://github.com/prometheus/node_exporter) | patch | `4.55.0` → `4.55.1` | — | — | | [harbor.webgrip.dev/ghcr/prometheus-community/charts/prometheus-operator-crds](https://github.com/prometheus-community/helm-charts) | patch | `30.0.0` → `30.0.1` | — | — | | [harbor.webgrip.dev/ghcr/stakater/charts/reloader](https://github.com/stakater/Reloader) | patch | `2.2.12` → `2.2.14` | — | — | | [harbor.webgrip.dev/ghcr/victoriametrics/helm-charts/victoria-metrics-operator](https://github.com/VictoriaMetrics/operator) ([source](https://github.com/VictoriaMetrics/helm-charts)) | patch | `0.66.2` → `0.66.3` | — | — | | [keda](https://github.com/kedacore/keda) | patch | `2.20.0` → `2.20.2` | 2026-07-31T09:12:31.058Z | 4d | | [longhorn](https://github.com/longhorn/longhorn) ([source](https://github.com/longhorn/charts)) | patch | `1.11.2` → `1.11.3` | 2026-07-02T00:56:51.480Z | 34d | | [mirror.gcr.io/envoyproxy/gateway-helm](https://gateway.envoyproxy.io/) ([source](https://github.com/envoyproxy/gateway)) | patch | `v1.8.0` → `1.8.3` | 2026-07-22T18:58:01.651Z | 13d | | [quay.io/jetstack/charts/cert-manager](https://cert-manager.io) ([source](https://github.com/cert-manager/cert-manager)) | patch | `v1.20.2` → `v1.20.3` | — | — | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/93) for more information. 📦 **Grouped update**: confirm the group is operationally coherent before merging. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. Grouped GitOps PR: confirm the group is operationally coherent before enabling automerge. `Released` is the upstream publish time; `—` means this registry reports no timestamp, so no soak applies and the PR is eligible on the next Renovate run. Otherwise add the soak for this update type (patch 1d, minor 3d, digest 0d) to `Released` — the first hourly run after that merges it. --- ### Release Notes <details> <summary>forgejo-helm/forgejo-helm (harbor.webgrip.dev/forgejo/forgejo-helm/forgejo)</summary> ### [`v17.1.4`](https://code.forgejo.org/forgejo-helm/forgejo-helm/releases/tag/v17.1.4): 17.1.4 [Compare Source](https://code.forgejo.org/forgejo-helm/forgejo-helm/compare/v17.1.3...v17.1.4) ##### Bug Fixes - **deps:** update forgejo docker tag to v15.0.6 (main) ([#&#8203;1655](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1655)) ([ac25f50](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/ac25f5055b519374e5903afb18fed29fcbdd7696)) ##### Continuous Integration - **deps:** update dependency helm-unittest to v1.1.2 (main) ([#&#8203;1648](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1648)) ([4f80f7b](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/4f80f7b67b5b67a42e6d2d28445bf89eaaa5616b)) - **deps:** update dependency kubectl to v1.36.3 (main) ([#&#8203;1646](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1646)) ([e791b39](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/e791b392bd1aabffa8336a99a50233e476c8d67e)) - **deps:** update <https://data.forgejo.org/actions/checkout> action to v7.0.1 (main) ([#&#8203;1641](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1641)) ([0e70918](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/0e70918b09bd5c6006afd649cacdc2afaaca4595)) ##### Miscellaneous Chores - **deps:** lock file maintenance (main) ([#&#8203;1633](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1633)) ([abf6236](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/abf623694e6b5125298f4747a759a23c4d7947e0)) - **deps:** lock file maintenance (main) ([#&#8203;1653](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1653)) ([cb51de0](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/cb51de09a4b8549e98dcb1dd5ba92b8c4192e174)) - **deps:** update dependency lint-staged to v17.1.0 (main) ([#&#8203;1644](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1644)) ([a753989](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/a7539896dc85255d93fcb5dff5b9476279db23f9)) - **deps:** update dependency lint-staged to v17.1.1 (main) ([#&#8203;1649](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1649)) ([6568943](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/65689439775b4e00f20a356b2e8c71ce7bf34894)) - **deps:** update dependency lint-staged to v17.2.0 (main) ([#&#8203;1651](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1651)) ([4989a0a](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/4989a0aebdcf9c2c337ab46def7798874fcce02c)) - **deps:** update dependency markdownlint-cli to v0.49.1 (main) ([#&#8203;1640](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1640)) ([ad46777](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/ad46777f2e33817183897e36f2b6d181a677596a)) - **deps:** update dependency prettier to v3.9.6 (main) ([#&#8203;1647](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1647)) ([1048a6a](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1048a6a7712ce4a1f275e3a780c603a3d43a5006)) - **deps:** update node.js to v24.18.1 (main) ([#&#8203;1654](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1654)) ([87884dd](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/87884dd1d84615be4d7a662b16d8336a956a3cd8)) - **deps:** update pnpm to v11.12.0 (main) ([#&#8203;1636](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1636)) ([d9cfdb9](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/d9cfdb928de7b1a0d6cc74b5c278a00b3f3c1a8b)) - **deps:** update pnpm to v11.14.0 (main) ([#&#8203;1642](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1642)) ([1e069d2](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1e069d25daed4e2de2a3ed5c5327f720ee0d4224)) - **deps:** update pnpm to v11.15.0 (main) ([#&#8203;1643](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1643)) ([cd0dae2](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/cd0dae26f47d3b5469588c6e32d55ba1596b842c)) - **deps:** update pnpm to v11.15.1 (main) ([#&#8203;1645](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1645)) ([4d79ab6](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/4d79ab609ef4c49a457f18f42b624e03dd0f1462)) - **deps:** update pnpm to v11.16.0 (main) ([#&#8203;1650](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1650)) ([f6ecaa4](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/f6ecaa4864f924d7c8aaa42e014578f9630960e5)) - **deps:** update pnpm to v11.17.0 (main) ([#&#8203;1652](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1652)) ([e820d28](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/e820d28f73a5568fc05255797d9519490f673ef6)) - move renovate config ([6d4c2b5](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/6d4c2b5ba6a73e9126af7dd2ca8aab0736575878)) ### [`v17.1.3`](https://code.forgejo.org/forgejo-helm/forgejo-helm/releases/tag/v17.1.3): 17.1.3 [Compare Source](https://code.forgejo.org/forgejo-helm/forgejo-helm/compare/v17.1.2...v17.1.3) ##### Bug Fixes - **deps:** update forgejo docker tag to v15.0.5 (main) ([#&#8203;1637](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1637)) ([15132f9](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/15132f9b2e1496c3a25dfeb676220124f1ca2b8b)) ##### Tests - add v17 ([#&#8203;1625](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1625)) ([750fe72](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/750fe721c68f73e1da2bf2c8faddeb94dfbbd3b3)) ##### Continuous Integration - **deps:** update actions/setup-node action to v6.5.0 (main) ([#&#8203;1634](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1634)) ([34dfcf0](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/34dfcf09eebfeabd6cd43c844b9eb2a9634abb07)) - **deps:** update actions/setup-node action to v7 (main) ([#&#8203;1635](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1635)) ([afda30f](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/afda30fc5b899bc76c83da788373fe816ea39b63)) - **deps:** update dependency helm to v4.2.2 (main) ([#&#8203;1627](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1627)) ([1b2423b](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1b2423b18b9755bb5f7460c5550859356be36553)) - **deps:** update dependency helm to v4.2.3 (main) ([#&#8203;1628](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1628)) ([8f55a53](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/8f55a5378d64f2787f271f605648095e1c36a046)) ##### Miscellaneous Chores - **deps:** update dependency conventional-changelog to v8.1.0 (main) ([#&#8203;1631](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1631)) ([03ef331](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/03ef331f57fabc987ab0307bb0f5e2f13baf6bcd)) - **deps:** update dependency prettier to v3.9.5 (main) ([#&#8203;1630](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1630)) ([0d193d0](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/0d193d0ad68604085f0fa8e44c1e35387d345671)) - **deps:** update pnpm to v11.11.0 (main) ([#&#8203;1632](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1632)) ([ad31cd9](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/ad31cd95c2bc620026e287f98670234eb8c1cea9)) ### [`v17.1.2`](https://code.forgejo.org/forgejo-helm/forgejo-helm/releases/tag/v17.1.2): 17.1.2 [Compare Source](https://code.forgejo.org/forgejo-helm/forgejo-helm/compare/v17.1.1...v17.1.2) ##### Bug Fixes - **deps:** update forgejo docker tag to v15.0.4 (main) ([#&#8203;1624](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1624)) ([ecb885c](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/ecb885c6a312d5cb29237bf415bd9c2da9aad7a4)) - **deps:** update helm release common to v2.41.0 (main) ([#&#8203;1620](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1620)) ([187f17e](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/187f17e8300f462cfc97c61fd3d93f5327a0ba8d)) ##### Continuous Integration - **deps:** update actions/checkout to v7 (main) ([#&#8203;1602](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1602)) ([c90f2ef](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/c90f2efc16a341d909d076f8f0724971313d91d6)) - **deps:** update azure/setup-helm (main) ([#&#8203;1606](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1606)) ([4685dec](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/4685dec48f903429b976995c7ef06d8213e115dc)) - **deps:** update dependency kubectl to v1.36.2 (main) ([#&#8203;1595](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1595)) ([a98a515](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/a98a515b1de07b064b403b73f0d6b3bd46d5de13)) - **deps:** update k3s (patch) (main) (patch) ([#&#8203;1608](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1608)) ([7bb4aa8](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/7bb4aa8cbc951b8b3636689346cf7bda389a5c81)) - **deps:** update pnpm/action-setup to v6.0.9 (main) ([#&#8203;1599](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1599)) ([b3fc37e](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/b3fc37efc240ccb79fc943c12331f61c976c99e5)) - remove unsupported permissions ([986ce76](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/986ce76dc0ac661062dcb99a761db60f406bfa21)) ##### Miscellaneous Chores - changelog migration ([2a94f98](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/2a94f98b23559b5580dec3fbb7a4ff99ff303e5a)) - **deps:** update dependency conventional-changelog to v8 ([c32df8e](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/c32df8e5e62255b353b5de6ef6a9511fb0bf0594)) - **deps:** update dependency conventional-changelog to v8.0.1 (main) ([#&#8203;1622](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1622)) ([d1788e8](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/d1788e8fef4c0e709f91a4094309dfb5c01a0052)) - **deps:** update dependency conventional-changelog-conventionalcommits to v10 ([0b58a55](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/0b58a552dcbe66f74e9bbb681b322a88289ac37c)) - **deps:** update dependency conventional-changelog-conventionalcommits to v10.2.0 (main) ([#&#8203;1614](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1614)) ([1bfb3e7](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1bfb3e785c3ea05fe0a7380a257087bbd18acc62)) - **deps:** update dependency conventional-changelog-conventionalcommits to v10.2.1 (main) ([#&#8203;1623](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1623)) ([ce9fccf](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/ce9fccffd007a3929d8626cfdf471518e555eb05)) - **deps:** update dependency lint-staged to v17.0.8 (main) ([#&#8203;1605](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1605)) ([1a4df61](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1a4df617852f156d159d36685ec3257da16c2d9b)) - **deps:** update dependency markdownlint-cli to v0.49.0 (main) ([#&#8203;1603](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1603)) ([e570edd](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/e570edd42be996a4e297210430887e54cc56723f)) - **deps:** update dependency prettier to v3.8.4 (main) ([#&#8203;1594](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1594)) ([c4a8e7d](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/c4a8e7d572a3a891900a38ecf5bb57b9447a4968)) - **deps:** update dependency prettier to v3.8.5 (main) ([#&#8203;1610](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1610)) ([0cc7947](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/0cc7947e60f24a322c6c7fce8448de7f2804bb3e)) - **deps:** update dependency prettier to v3.9.0 (main) ([#&#8203;1613](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1613)) ([7a1ec24](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/7a1ec2457c1dba861ed192e83382460e38777c21)) - **deps:** update dependency prettier to v3.9.1 (main) ([#&#8203;1615](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1615)) ([a28511e](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/a28511e67d865112090c3eb6a23032cce8fa4406)) - **deps:** update dependency prettier to v3.9.3 (main) ([#&#8203;1616](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1616)) ([5ed966a](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/5ed966a8cdb2c2bb4867ffb2872e3d289fac8a72)) - **deps:** update dependency prettier to v3.9.4 (main) ([#&#8203;1619](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1619)) ([6c42482](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/6c42482b307216272d2a4da8a20f7939b42663f3)) - **deps:** update node.js to v24.17.0 (main) ([#&#8203;1600](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1600)) ([5d7415a](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/5d7415af9e95ef56ce1eb9aa3301af18b447d014)) - **deps:** update node.js to v24.18.0 (main) ([#&#8203;1607](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1607)) ([7cd7482](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/7cd74824521966086f0e4290e88a34456d2df562)) - **deps:** update pnpm to v11.10.0 (main) ([#&#8203;1621](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1621)) ([82cf8e3](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/82cf8e330b5b811cb86a3b18328bfeb841126446)) - **deps:** update pnpm to v11.5.2 (main) ([#&#8203;1591](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1591)) ([822c445](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/822c445a893148f6268711d48e56be117c9be6ff)) - **deps:** update pnpm to v11.5.3 (main) ([#&#8203;1597](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1597)) ([6e777cf](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/6e777cf7703291248f63da5c5ee00d896ae01c9c)) - **deps:** update pnpm to v11.6.0 (main) ([#&#8203;1598](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1598)) ([1355c9b](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1355c9b793ac252fbc4ce11ab2636659b61088d4)) - **deps:** update pnpm to v11.7.0 (main) ([#&#8203;1601](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1601)) ([33eba83](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/33eba836ff94b2608ef4e9aa9c846b76c2d10bd7)) - **deps:** update pnpm to v11.8.0 (main) ([#&#8203;1604](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1604)) ([1e62d7b](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/1e62d7bbdafaf3d8e9afbe89a5a125b160618e10)) - **deps:** update pnpm to v11.9.0 (main) ([#&#8203;1609](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1609)) ([5d9fc08](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/5d9fc0866a7b1ba26b2dd7bcfdb523dda467d94f)) - migrate changelog generation ([a4e21cb](https://code.forgejo.org/forgejo-helm/forgejo-helm/commits/a4e21cb365fae82ea478a120e9e8d5090933a299)) ### [`v17.1.1`](https://code.forgejo.org/forgejo-helm/forgejo-helm/releases/tag/v17.1.1): 17.1.1 [Compare Source](https://code.forgejo.org/forgejo-helm/forgejo-helm/compare/v17.1.0...v17.1.1) ##### Bug Fixes - **deps:** update forgejo docker tag to v15.0.3 (main) ([#&#8203;1592](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1592)) ([2ad473c](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/2ad473c789ed9556fd2d7d8f6df205c1085926fc)) - **deps:** update helm release common to v2.40.0 (main) ([#&#8203;1581](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1581)) ([eb3c258](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/eb3c258f70bb21f8d5095c22412ad955bd6258e4)) ##### Continuous Integration - **deps:** update dependency helm to v4.2.0 ([#&#8203;1588](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1588)) ([719cb41](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/719cb41ca3fbb8213a0ccba1e4e287af9f6c67ee)) - **deps:** update dependency helm-unittest to v1.1.1 (main) ([#&#8203;1590](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1590)) ([4c028d6](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/4c028d62c231fd427a02efe5eda3bc8373b8ba58)) - **deps:** update dependency kubectl to v1.36.1 (main) ([#&#8203;1568](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1568)) ([e474125](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/e474125230f8f111092aa9213be3a1f9a4ae64c4)) - **deps:** update <https://data.forgejo.org/actions/checkout> action to v6.0.3 (main) ([#&#8203;1586](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1586)) ([eaf17ac](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/eaf17ac219ebc78c0dd8f1ff11f97da99b1c28a4)) - **deps:** update k3s (patch) (main) (patch) ([#&#8203;1575](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1575)) ([2e2d71c](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/2e2d71c055c5ad6f67a6cf4ecde52f9f2b3a5af7)) - **deps:** update pnpm/action-setup action to v6.0.8 (main) ([#&#8203;1567](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1567)) ([607a5ab](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/607a5ab8b5a3b91e0c522d94d086969b658d783f)) ##### Miscellaneous Chores - **deps:** update dependency lint-staged to v17.0.4 (main) ([#&#8203;1569](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1569)) ([7057f2d](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/7057f2dde2106138627639dedb0c88f97ddc4545)) - **deps:** update dependency lint-staged to v17.0.5 (main) ([#&#8203;1574](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1574)) ([8342a27](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/8342a273b4cc0f1ac87f781922adaca419d8c5db)) - **deps:** update dependency lint-staged to v17.0.6 (main) ([#&#8203;1585](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1585)) ([64f1b9c](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/64f1b9c9839b0e4d251e0207c9d8a5b2fdfc0fdf)) - **deps:** update dependency lint-staged to v17.0.7 (main) ([#&#8203;1587](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1587)) ([ef2d5a4](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/ef2d5a4a7ba4a22d8dfc940c72203882b0b2f84d)) - **deps:** update dependency yaml to v2.9.0 (main) ([#&#8203;1570](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1570)) ([48d0dcb](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/48d0dcb63c6ec8431f1c2bcedea19494ba3cfa75)) - **deps:** update node.js to v24.16.0 (main) ([#&#8203;1576](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1576)) ([20c3406](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/20c340638993a22b95baaa4ee2980f9f0a21537d)) - **deps:** update pnpm to v11.1.0 (main) ([#&#8203;1571](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1571)) ([a444fa5](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/a444fa5c0e2613c9257afdb72fda1a29db8ecee9)) - **deps:** update pnpm to v11.1.1 (main) ([#&#8203;1572](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1572)) ([63c82b4](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/63c82b456edf5b560fc52c5a7437cbfba367092b)) - **deps:** update pnpm to v11.1.2 (main) ([#&#8203;1573](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1573)) ([a1a2a7c](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/a1a2a7cbdc5a38b6073175779d148b116444b69e)) - **deps:** update pnpm to v11.1.3 (main) ([#&#8203;1577](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1577)) ([aa7e6f0](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/aa7e6f08863e64e99d8ee2d66425afb5a6b6f956)) - **deps:** update pnpm to v11.2.0 (main) ([#&#8203;1578](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1578)) ([bbc6f76](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/bbc6f761772f6a520c8dff94d9361ab5a540edce)) - **deps:** update pnpm to v11.2.1 (main) ([#&#8203;1579](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1579)) ([399a817](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/399a8170744216a08a1c235094288b1e7811ba24)) - **deps:** update pnpm to v11.2.2 (main) ([#&#8203;1580](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1580)) ([a95f78a](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/a95f78a7aafcad9601e34c50ffbe126bbd83a63d)) - **deps:** update pnpm to v11.3.0 (main) ([#&#8203;1582](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1582)) ([d32d8b4](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/d32d8b436d35c4056add45e26bafd8e58fa6374d)) - **deps:** update pnpm to v11.4.0 (main) ([#&#8203;1583](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1583)) ([c8a3bb6](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/c8a3bb6492fb00b85580eff1ce33432ccabc3441)) - **deps:** update pnpm to v11.5.0 (main) ([#&#8203;1584](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1584)) ([864e4e6](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/864e4e611ba8dbb1327e6506ba2eac3f39e0bf96)) - **deps:** update pnpm to v11.5.1 (main) ([#&#8203;1589](https://code.forgejo.org/forgejo-helm/forgejo-helm/issues/1589)) ([146743e](https://code.forgejo.org/forgejo-helm/forgejo-helm/commit/146743e5aa90bfe36d8741d2f95b249da5f3921b)) </details> <details> <summary>grafana/pyroscope (harbor.webgrip.dev/ghcr/grafana/helm-charts/pyroscope)</summary> ### [`v2.0.3`](https://github.com/grafana/pyroscope/releases/tag/v2.0.3) [Compare Source](https://github.com/grafana/pyroscope/compare/v2.0.2...v2.0.3) #### Changelog - [`3715b1a`](https://github.com/grafana/pyroscope/commit/3715b1a4d334c8e9f14623a2c8e839e3894ed9c8) Add release notes for v2.0.2 ([#&#8203;5127](https://github.com/grafana/pyroscope/issues/5127)) ([#&#8203;5128](https://github.com/grafana/pyroscope/issues/5128)) - [`189eace`](https://github.com/grafana/pyroscope/commit/189eaceb765b525eda7925cbef4dbfdf29b58d7a) Security bumps and fixes for v2.0.3 ([#&#8203;5231](https://github.com/grafana/pyroscope/issues/5231)) - [`4415924`](https://github.com/grafana/pyroscope/commit/4415924a04f816767b70136de6c666c99297af6d) ci(release/v2.0): align CI pipeline to main (GATB + GAR) ([#&#8203;5234](https://github.com/grafana/pyroscope/issues/5234)) - [`a62c208`](https://github.com/grafana/pyroscope/commit/a62c208abb299ee91d5d16f99c0b7cc7e59c6cf1) docs: add v2.0.3 release notes ([#&#8203;5235](https://github.com/grafana/pyroscope/issues/5235)) ([#&#8203;5236](https://github.com/grafana/pyroscope/issues/5236)) - [`3b2704f`](https://github.com/grafana/pyroscope/commit/3b2704f7043faa4f43fe6edd5c94eb685e8a8c6b) docs: fix broken Grafana Cloud Profiles link in SDK guides ([#&#8203;5132](https://github.com/grafana/pyroscope/issues/5132)) ([#&#8203;5133](https://github.com/grafana/pyroscope/issues/5133)) As always, feedback is more than welcome, feel free to open issues/discussions. You can reach out to the team using: - [Slack](https://grafana.slack.com/archives/C049PLMV8TB) - [Github Discussions](https://github.com/grafana/pyroscope/discussions) - [Github Issues](https://github.com/grafana/pyroscope/issues) - [Mailing List](https://groups.google.com/g/pyroscope-team) #### Docker Images - [grafana/pyroscope](https://hub.docker.com/r/grafana/pyroscope/tags) ```bash docker pull grafana/pyroscope:2.0.3 ``` </details> <details> <summary>kedacore/keda (keda)</summary> ### [`v2.20.2`](https://github.com/kedacore/keda/blob/HEAD/CHANGELOG.md#v2202) [Compare Source](https://github.com/kedacore/keda/compare/v2.20.1...v2.20.2) ##### Improvements - **General**: Introduce a dedicated `HPAActive` condition on `ScaledObject` mirroring the HPA's own `ScalingActive` status, so transient HPA metric gaps no longer flip the `Ready` condition to `False` ([#&#8203;7914](https://github.com/kedacore/keda/issues/7914)) ##### Fixes - **General**: Fix concurrent map writes panic in the shared root CA `CertPool` ([#&#8203;7910](https://github.com/kedacore/keda/issues/7910)) - **General**: Fix nil pointer dereference in AWS Secret Manager `TriggerAuthentication` when `awsSecretManager.credentials` is omitted and no `awsSecretManager.podIdentity` is set ([#&#8203;7927](https://github.com/kedacore/keda/issues/7927)) - **General**: Fix nil pointer dereference in `customScalingStrategy.GetEffectiveMaxScale` when `customScalingQueueLengthDeduction` is omitted; the optional field is now treated as zero deduction instead of panicking ([#&#8203;7798](https://github.com/kedacore/keda/issues/7798)) - **General**: Fix nil pointer dereference in `GetCurrentReplicas` when a Deployment/StatefulSet/ReplicaSet is returned from the informer cache with an undefaulted `spec.replicas`; a nil value is now treated as the Kubernetes default of 1 instead of panicking ([#&#8203;7863](https://github.com/kedacore/keda/issues/7863)) - **General**: Fix `ScaledJob` CRD validation to include "default" as a valid value for `scalingStrategy.strategy` ([#&#8203;7855](https://github.com/kedacore/keda/issues/7855)) - **General**: Guard `GetCurrentReplicas` against nil `Status.ScaleTargetGVKR` to prevent operator panics under the cache race documented in ([#&#8203;4389](https://github.com/kedacore/keda/issues/4389)) / ([#&#8203;4955](https://github.com/kedacore/keda/issues/4955)) - **General**: Restore core `""` API group in events RBAC so that client-go's event broadcaster can write legacy events ([#&#8203;7922](https://github.com/kedacore/keda/issues/7922)) - **General**: Restore gRPC reconnect backoff in the metrics service client; an unset `Backoff` in `WithConnectParams` disabled backoff and caused a zero-delay reconnect loop that flooded logs when keda-operator was unreachable ([#&#8203;7856](https://github.com/kedacore/keda/issues/7856)) - **General**: Share HTTP transports across scalers to reuse connection pools and avoid re-dial storms at high ScaledObject counts ([#&#8203;7789](https://github.com/kedacore/keda/issues/7789)) - **General**: Treat negative external metric values as zero to prevent incorrect HPA scaling ([#&#8203;7880](https://github.com/kedacore/keda/issues/7880)) - **Azure Blob Storage Scaler**: Fix `globPattern` never matching when written in path-style with a leading `/`, since blob names never have one ([#&#8203;6492](https://github.com/kedacore/keda/issues/6492)) - **MongoDB Scaler**: Disconnect the client when the initial `Ping` fails so the background topology-monitoring connections opened by `mongo.Connect` are not leaked ([#&#8203;5612](https://github.com/kedacore/keda/issues/5612)) ### [`v2.20.1`](https://github.com/kedacore/keda/blob/HEAD/CHANGELOG.md#v2201) [Compare Source](https://github.com/kedacore/keda/compare/v2.20.0...v2.20.1) ##### Fixes - **General**: Fix concurrent map read/write data race in fallback `updateStatus` that caused panics when multiple triggers were scaling simultaneously ([#&#8203;7838](https://github.com/kedacore/keda/issues/7838)) - **General**: Fix `KEDAScalersStarted` "Started scalers watch" event not being emitted for ScaledJobs because it shared an events.k8s.io aggregation key with the per-scaler "scaler is built" event ([#&#8203;7820](https://github.com/kedacore/keda/pull/7820)) </details> <details> <summary>longhorn/charts (longhorn)</summary> ### [`v1.11.3`](https://github.com/longhorn/charts/releases/tag/longhorn-1.11.3) [Compare Source](https://github.com/longhorn/charts/compare/longhorn-1.11.2...longhorn-1.11.3) Longhorn is a distributed block storage system for Kubernetes. </details> <details> <summary>envoyproxy/gateway (mirror.gcr.io/envoyproxy/gateway-helm)</summary> ### [`v1.8.3`](https://github.com/envoyproxy/gateway/releases/tag/v1.8.3) [Compare Source](https://github.com/envoyproxy/gateway/compare/v1.8.3...v1.8.3) ##### Release Announcement Check out the [v1.8.3 release announcement](https://gateway.envoyproxy.io/news/releases/notes/v1.8.3) to learn more about the release. ##### What's Changed - \[release-1.8]: bump the gomod group across 1 directory with 3 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9389](https://github.com/envoyproxy/gateway/pull/9389) - \[release-1.8]: bump the gomod group across 1 directory with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9435](https://github.com/envoyproxy/gateway/pull/9435) - \[release-1.8]: bump the actions group across 1 directory with 6 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9440](https://github.com/envoyproxy/gateway/pull/9440) - \[release-1.8]: bump the actions group across 1 directory with 7 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9507](https://github.com/envoyproxy/gateway/pull/9507) - \[release-1.8]: bump the gomod group across 1 directory with 4 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9502](https://github.com/envoyproxy/gateway/pull/9502) - \[release-1.8]: bump sigs.k8s.io/mcs-api from 0.4.1 to 0.5.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9503](https://github.com/envoyproxy/gateway/pull/9503) - \[release-1.8]: bump distroless/base-nossl from `20f009e` to `86554c4` in /tools/docker/envoy-gateway by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9497](https://github.com/envoyproxy/gateway/pull/9497) - fix: reject TLS secret when certificate and private key do not match by [@&#8203;zhaohuabing](https://github.com/zhaohuabing) in [#&#8203;9487](https://github.com/envoyproxy/gateway/pull/9487) - \[release-1.8] release notes and version bump for v1.8.3 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9520](https://github.com/envoyproxy/gateway/pull/9520) - \[release-1.8] V1.8.3 cherry picks by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9540](https://github.com/envoyproxy/gateway/pull/9540) - \[release-1.8]: bump the gomod group across 1 directory with 7 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9547](https://github.com/envoyproxy/gateway/pull/9547) - \[release-1.8]: bump the actions group across 2 directories with 6 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9551](https://github.com/envoyproxy/gateway/pull/9551) - \[release-1.8] fix: update ratelimit image fallback tag in helm helpers by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9552](https://github.com/envoyproxy/gateway/pull/9552) **Full Changelog**: <https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3> ### [`v1.8.3`](https://github.com/envoyproxy/gateway/releases/tag/v1.8.3) [Compare Source](https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3) ##### Release Announcement Check out the [v1.8.3 release announcement](https://gateway.envoyproxy.io/news/releases/notes/v1.8.3) to learn more about the release. ##### What's Changed - \[release-1.8]: bump the gomod group across 1 directory with 3 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9389](https://github.com/envoyproxy/gateway/pull/9389) - \[release-1.8]: bump the gomod group across 1 directory with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9435](https://github.com/envoyproxy/gateway/pull/9435) - \[release-1.8]: bump the actions group across 1 directory with 6 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9440](https://github.com/envoyproxy/gateway/pull/9440) - \[release-1.8]: bump the actions group across 1 directory with 7 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9507](https://github.com/envoyproxy/gateway/pull/9507) - \[release-1.8]: bump the gomod group across 1 directory with 4 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9502](https://github.com/envoyproxy/gateway/pull/9502) - \[release-1.8]: bump sigs.k8s.io/mcs-api from 0.4.1 to 0.5.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9503](https://github.com/envoyproxy/gateway/pull/9503) - \[release-1.8]: bump distroless/base-nossl from `20f009e` to `86554c4` in /tools/docker/envoy-gateway by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9497](https://github.com/envoyproxy/gateway/pull/9497) - fix: reject TLS secret when certificate and private key do not match by [@&#8203;zhaohuabing](https://github.com/zhaohuabing) in [#&#8203;9487](https://github.com/envoyproxy/gateway/pull/9487) - \[release-1.8] release notes and version bump for v1.8.3 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9520](https://github.com/envoyproxy/gateway/pull/9520) - \[release-1.8] V1.8.3 cherry picks by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9540](https://github.com/envoyproxy/gateway/pull/9540) - \[release-1.8]: bump the gomod group across 1 directory with 7 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9547](https://github.com/envoyproxy/gateway/pull/9547) - \[release-1.8]: bump the actions group across 2 directories with 6 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9551](https://github.com/envoyproxy/gateway/pull/9551) - \[release-1.8] fix: update ratelimit image fallback tag in helm helpers by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9552](https://github.com/envoyproxy/gateway/pull/9552) **Full Changelog**: <https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3> ### [`v1.8.2`](https://github.com/envoyproxy/gateway/releases/tag/v1.8.2) [Compare Source](https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.2) ##### Release Announcement Check out the [v1.8.2 release announcement](https://gateway.envoyproxy.io/news/releases/notes/v1.8.2) to learn more about the release. ##### What's Changed - \[chore] bump codecov by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9264](https://github.com/envoyproxy/gateway/pull/9264) - \[release-1.8] chore: bump base image by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9263](https://github.com/envoyproxy/gateway/pull/9263) - build(deps): bump the actions group across 1 directory with 8 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9284](https://github.com/envoyproxy/gateway/pull/9284) - build(deps): bump busybox from `1487d0a` to `fd8d9aa` in /tools/docker/envoy-gateway by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9275](https://github.com/envoyproxy/gateway/pull/9275) - \[release-1.8]: bump the gomod group across 1 directory with 24 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9304](https://github.com/envoyproxy/gateway/pull/9304) - \[release-1.8]: bump helm.sh/helm/v3 from 3.21.0 to 3.21.2 in the gomod group across 1 directory by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9326](https://github.com/envoyproxy/gateway/pull/9326) - \[release-1.8]: bump actions/setup-go from 6.4.0 to 6.5.0 in /tools/github-actions/setup-deps in the actions group across 1 directory by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9330](https://github.com/envoyproxy/gateway/pull/9330) - \[release-1.8] release notes and version bump for v1.8.2 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9364](https://github.com/envoyproxy/gateway/pull/9364) - \[release-1.8] cherry-pick for v1.8.2 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9376](https://github.com/envoyproxy/gateway/pull/9376) **Full Changelog**: <https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2> ### [`v1.8.2`](https://github.com/envoyproxy/gateway/releases/tag/v1.8.2) [Compare Source](https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2) ##### Release Announcement Check out the [v1.8.2 release announcement](https://gateway.envoyproxy.io/news/releases/notes/v1.8.2) to learn more about the release. ##### What's Changed - \[chore] bump codecov by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9264](https://github.com/envoyproxy/gateway/pull/9264) - \[release-1.8] chore: bump base image by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9263](https://github.com/envoyproxy/gateway/pull/9263) - build(deps): bump the actions group across 1 directory with 8 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9284](https://github.com/envoyproxy/gateway/pull/9284) - build(deps): bump busybox from `1487d0a` to `fd8d9aa` in /tools/docker/envoy-gateway by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9275](https://github.com/envoyproxy/gateway/pull/9275) - \[release-1.8]: bump the gomod group across 1 directory with 24 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9304](https://github.com/envoyproxy/gateway/pull/9304) - \[release-1.8]: bump helm.sh/helm/v3 from 3.21.0 to 3.21.2 in the gomod group across 1 directory by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9326](https://github.com/envoyproxy/gateway/pull/9326) - \[release-1.8]: bump actions/setup-go from 6.4.0 to 6.5.0 in /tools/github-actions/setup-deps in the actions group across 1 directory by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;9330](https://github.com/envoyproxy/gateway/pull/9330) - \[release-1.8] release notes and version bump for v1.8.2 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9364](https://github.com/envoyproxy/gateway/pull/9364) - \[release-1.8] cherry-pick for v1.8.2 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9376](https://github.com/envoyproxy/gateway/pull/9376) **Full Changelog**: <https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2> ### [`v1.8.1`](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1) [Compare Source](https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.1) ##### Release Announcement Check out the [v1.8.1 release announcement](https://gateway.envoyproxy.io/news/releases/notes/v1.8.1) to learn more about the release. ##### What's Changed - \[release/v1.8] fix: add unary interceptor and fix fail-open auth in GatewayNamespaceMode ([#&#8203;8986](https://github.com/envoyproxy/gateway/issues/8986)) by [@&#8203;cnvergence](https://github.com/cnvergence) in [#&#8203;9118](https://github.com/envoyproxy/gateway/pull/9118) - \[release-1.8] bump envoy to 1.38.1 by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9168](https://github.com/envoyproxy/gateway/pull/9168) - \[release/v1.8] cherry-pick for v1.8.1 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9169](https://github.com/envoyproxy/gateway/pull/9169) - \[release-1.8] fix github SA for June release by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9172](https://github.com/envoyproxy/gateway/pull/9172) - \[release-1.8] cherry-pick release notes and version bump by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9174](https://github.com/envoyproxy/gateway/pull/9174) **Full Changelog**: <https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1> ### [`v1.8.1`](https://github.com/envoyproxy/gateway/releases/tag/v1.8.1) [Compare Source](https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1) ##### Release Announcement Check out the [v1.8.1 release announcement](https://gateway.envoyproxy.io/news/releases/notes/v1.8.1) to learn more about the release. ##### What's Changed - \[release/v1.8] fix: add unary interceptor and fix fail-open auth in GatewayNamespaceMode ([#&#8203;8986](https://github.com/envoyproxy/gateway/issues/8986)) by [@&#8203;cnvergence](https://github.com/cnvergence) in [#&#8203;9118](https://github.com/envoyproxy/gateway/pull/9118) - \[release-1.8] bump envoy to 1.38.1 by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9168](https://github.com/envoyproxy/gateway/pull/9168) - \[release/v1.8] cherry-pick for v1.8.1 by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9169](https://github.com/envoyproxy/gateway/pull/9169) - \[release-1.8] fix github SA for June release by [@&#8203;zirain](https://github.com/zirain) in [#&#8203;9172](https://github.com/envoyproxy/gateway/pull/9172) - \[release-1.8] cherry-pick release notes and version bump by [@&#8203;jukie](https://github.com/jukie) in [#&#8203;9174](https://github.com/envoyproxy/gateway/pull/9174) **Full Changelog**: <https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1> </details> <details> <summary>cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)</summary> ### [`v1.20.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.3...v1.20.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint. This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs. All users should upgrade. > \[!WARNING] > **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly. ##### Changes by Kind ##### Bug or Regression - Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8940](https://github.com/cert-manager/cert-manager/issues/8940), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8759](https://github.com/cert-manager/cert-manager/issues/8759), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Bump go to 1.26.3, other deps to fix several govulncheck issues ([#&#8203;8789](https://github.com/cert-manager/cert-manager/issues/8789), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update Go to `v1.26.4` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8926](https://github.com/cert-manager/cert-manager/issues/8926), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ### [`v1.20.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.2...v1.20.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint. This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs. All users should upgrade. > \[!WARNING] > **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly. ##### Changes by Kind ##### Bug or Regression - Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8940](https://github.com/cert-manager/cert-manager/issues/8940), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8759](https://github.com/cert-manager/cert-manager/issues/8759), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Bump go to 1.26.3, other deps to fix several govulncheck issues ([#&#8203;8789](https://github.com/cert-manager/cert-manager/issues/8789), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update Go to `v1.26.4` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8926](https://github.com/cert-manager/cert-manager/issues/8926), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJjb250YWluZXIiLCJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInJlbm92YXRlL2hlbG0iLCJ0eXBlL3BhdGNoIl19-->
fix(container): update flux controllers
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
e2e / Lint & static validation (pull_request) Successful in 1m45s
e2e / Validate Renovate config (pull_request) Successful in 2m33s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 3m13s
e2e / Flux-local render (pull_request) Successful in 6m27s
4a3235205c
| datasource | package                                                                       | from    | to      |
| ---------- | ----------------------------------------------------------------------------- | ------- | ------- |
| docker     | ghcr.io/coredns/charts/coredns                                                | 1.46.0  | 1.46.2  |
| docker     | ghcr.io/k8s-gateway/charts/k8s-gateway                                        | 3.7.1   | 3.7.2   |
| docker     | ghcr.io/kyverno/charts/kyverno                                                | 3.8.1   | 3.8.2   |
| docker     | ghcr.io/spegel-org/helm-charts/spegel                                         | 0.7.1   | 0.7.4   |
| docker     | harbor.webgrip.dev/forgejo/forgejo-helm/forgejo                               | 17.1.0  | 17.1.3  |
| docker     | harbor.webgrip.dev/ghcr/grafana/helm-charts/pyroscope                         | 2.0.2   | 2.0.3   |
| docker     | harbor.webgrip.dev/ghcr/home-operations/charts-mirror/metrics-server          | 3.13.0  | 3.13.1  |
| docker     | harbor.webgrip.dev/ghcr/opencost/charts/opencost                              | 2.5.25  | 2.5.28  |
| docker     | harbor.webgrip.dev/ghcr/prometheus-community/charts/kube-state-metrics        | 7.5.1   | 7.5.3   |
| docker     | harbor.webgrip.dev/ghcr/prometheus-community/charts/prometheus-node-exporter  | 4.55.0  | 4.55.1  |
| docker     | harbor.webgrip.dev/ghcr/prometheus-community/charts/prometheus-operator-crds  | 30.0.0  | 30.0.1  |
| docker     | harbor.webgrip.dev/ghcr/stakater/charts/reloader                              | 2.2.12  | 2.2.14  |
| docker     | harbor.webgrip.dev/ghcr/victoriametrics/helm-charts/victoria-metrics-operator | 0.66.2  | 0.66.3  |
| helm       | keda                                                                          | 2.20.0  | 2.20.1  |
| helm       | longhorn                                                                      | 1.11.2  | 1.11.3  |
| docker     | docker.io/envoyproxy/gateway-helm                                             | v1.8.0  | 1.8.3   |
| docker     | quay.io/jetstack/charts/cert-manager                                          | v1.20.2 | v1.20.3 |
renovate force-pushed renovate/patch-flux-controllers from 4a3235205c
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
e2e / Lint & static validation (pull_request) Successful in 1m45s
e2e / Validate Renovate config (pull_request) Successful in 2m33s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 3m13s
e2e / Flux-local render (pull_request) Successful in 6m27s
to 5e29730e2a
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
e2e / Lint & static validation (pull_request) Successful in 2m53s
e2e / Validate Renovate config (pull_request) Successful in 2m53s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 5m43s
e2e / Flux-local render (pull_request) Successful in 6m19s
2026-07-29 01:05:55 +00:00
Compare
renovate force-pushed renovate/patch-flux-controllers from 5e29730e2a
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
e2e / Lint & static validation (pull_request) Successful in 2m53s
e2e / Validate Renovate config (pull_request) Successful in 2m53s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 5m43s
e2e / Flux-local render (pull_request) Successful in 6m19s
to 178cf331c5
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
e2e / Validate Renovate config (pull_request) Successful in 2m51s
e2e / Lint & static validation (pull_request) Successful in 3m27s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 7m18s
e2e / Flux-local render (pull_request) Successful in 14m8s
2026-07-29 03:48:26 +00:00
Compare
renovate force-pushed renovate/patch-flux-controllers from 178cf331c5
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
e2e / Validate Renovate config (pull_request) Successful in 2m51s
e2e / Lint & static validation (pull_request) Successful in 3m27s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 7m18s
e2e / Flux-local render (pull_request) Successful in 14m8s
to 23cefb85d2
Some checks are pending
e2e / Lint & static validation (pull_request) Successful in 1m46s
e2e / Validate Renovate config (pull_request) Successful in 3m17s
renovate/stability-days Updates have not met minimum release age requirement
e2e / Kyverno Chainsaw (KinD) (pull_request) Successful in 7m39s
e2e / Flux-local render (pull_request) Successful in 10m26s
2026-07-31 01:01:20 +00:00
Compare
renovate force-pushed renovate/patch-flux-controllers from 23cefb85d2
Some checks are pending
e2e / Lint & static validation (pull_request) Successful in 1m46s
e2e / Validate Renovate config (pull_request) Successful in 3m17s
renovate/stability-days Updates have not met minimum release age requirement
e2e / Kyverno Chainsaw (KinD) (pull_request) Successful in 7m39s
e2e / Flux-local render (pull_request) Successful in 10m26s
to 5b4506bfee
Some checks failed
e2e / Lint & static validation (pull_request) Successful in 2m10s
e2e / Validate Renovate config (pull_request) Successful in 2m10s
renovate/stability-days Updates have not met minimum release age requirement
e2e / Flux-local render (pull_request) Failing after 9m38s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 12m44s
2026-07-31 13:23:33 +00:00
Compare
renovate force-pushed renovate/patch-flux-controllers from 5b4506bfee
Some checks failed
e2e / Lint & static validation (pull_request) Successful in 2m10s
e2e / Validate Renovate config (pull_request) Successful in 2m10s
renovate/stability-days Updates have not met minimum release age requirement
e2e / Flux-local render (pull_request) Failing after 9m38s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 12m44s
to 61c9dc9afe
Some checks failed
e2e / Lint & static validation (pull_request) Successful in 1m37s
e2e / Validate Renovate config (pull_request) Successful in 1m41s
renovate/stability-days Updates have met minimum release age requirement
e2e / Flux-local render (pull_request) Failing after 10m9s
e2e / Kyverno Chainsaw (KinD) (pull_request) Failing after 10m12s
2026-08-04 06:59:42 +00:00
Compare
Merge branch 'main' into renovate/patch-flux-controllers
Some checks failed
e2e / Validate Renovate config (pull_request) Successful in 1m5s
e2e / Lint & static validation (pull_request) Failing after 3m6s
e2e / Kyverno Chainsaw (KinD) (pull_request) Successful in 10m44s
e2e / Flux-local render (pull_request) Successful in 13m29s
caa514ebe2
Author
Member

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

### Edited/Blocked Notification Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. ⚠️ **Warning**: custom changes will be lost.
Merge branch 'main' into renovate/patch-flux-controllers
All checks were successful
e2e / Validate Renovate config (pull_request) Successful in 6m4s
e2e / Lint & static validation (pull_request) Successful in 7m33s
e2e / Kyverno Chainsaw (KinD) (pull_request) Successful in 14m56s
e2e / Flux-local render (pull_request) Successful in 17m10s
146359c0a2
All checks were successful
e2e / Validate Renovate config (pull_request) Successful in 6m4s
Required
Details
e2e / Lint & static validation (pull_request) Successful in 7m33s
Required
Details
e2e / Kyverno Chainsaw (KinD) (pull_request) Successful in 14m56s
Required
Details
e2e / Flux-local render (pull_request) Successful in 17m10s
Required
Details
This pull request has changes conflicting with the target branch.
  • kubernetes/apps/network/envoy-gateway/app/ocirepository.yaml
  • kubernetes/apps/observability/opencost/app/ocirepository.yaml
  • kubernetes/apps/observability/pyroscope/app/ocirepository.yaml
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/patch-flux-controllers:renovate/patch-flux-controllers
git switch renovate/patch-flux-controllers
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/homelab-cluster!448
No description provided.