fix(container): update flux controllers (patch) #448
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/homelab-cluster!448
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/patch-flux-controllers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.46.0→1.46.23.7.1→3.7.23.8.1→3.8.20.7.1→0.7.417.1.0→17.1.42.0.2→2.0.33.13.0→3.13.12.5.25→2.5.287.5.1→7.5.34.55.0→4.55.130.0.0→30.0.12.2.12→2.2.140.66.2→0.66.32.20.0→2.20.21.11.2→1.11.3v1.8.0→1.8.3v1.20.2→v1.20.3📦 Grouped update: confirm the group is operationally coherent before merging.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Grouped GitOps PR: confirm the group is operationally coherent before enabling automerge.
Releasedis the upstream publish time;—means this registry reports no timestamp, so no soak applies and the PR is eligible on the next Renovate run. Otherwise add the soak for this update type (patch 1d, minor 3d, digest 0d) toReleased— the first hourly run after that merges it.Release Notes
forgejo-helm/forgejo-helm (harbor.webgrip.dev/forgejo/forgejo-helm/forgejo)
v17.1.4: 17.1.4Compare Source
Bug Fixes
Continuous Integration
Miscellaneous Chores
v17.1.3: 17.1.3Compare Source
Bug Fixes
Tests
Continuous Integration
Miscellaneous Chores
v17.1.2: 17.1.2Compare Source
Bug Fixes
Continuous Integration
Miscellaneous Chores
v17.1.1: 17.1.1Compare Source
Bug Fixes
Continuous Integration
Miscellaneous Chores
grafana/pyroscope (harbor.webgrip.dev/ghcr/grafana/helm-charts/pyroscope)
v2.0.3Compare Source
Changelog
3715b1aAdd release notes for v2.0.2 (#5127) (#5128)189eaceSecurity bumps and fixes for v2.0.3 (#5231)4415924ci(release/v2.0): align CI pipeline to main (GATB + GAR) (#5234)a62c208docs: add v2.0.3 release notes (#5235) (#5236)3b2704fdocs: fix broken Grafana Cloud Profiles link in SDK guides (#5132) (#5133)As always, feedback is more than welcome, feel free to open issues/discussions.
You can reach out to the team using:
Docker Images
kedacore/keda (keda)
v2.20.2Compare Source
Improvements
HPAActivecondition onScaledObjectmirroring the HPA's ownScalingActivestatus, so transient HPA metric gaps no longer flip theReadycondition toFalse(#7914)Fixes
CertPool(#7910)TriggerAuthenticationwhenawsSecretManager.credentialsis omitted and noawsSecretManager.podIdentityis set (#7927)customScalingStrategy.GetEffectiveMaxScalewhencustomScalingQueueLengthDeductionis omitted; the optional field is now treated as zero deduction instead of panicking (#7798)GetCurrentReplicaswhen a Deployment/StatefulSet/ReplicaSet is returned from the informer cache with an undefaultedspec.replicas; a nil value is now treated as the Kubernetes default of 1 instead of panicking (#7863)ScaledJobCRD validation to include "default" as a valid value forscalingStrategy.strategy(#7855)GetCurrentReplicasagainst nilStatus.ScaleTargetGVKRto prevent operator panics under the cache race documented in (#4389) / (#4955)""API group in events RBAC so that client-go's event broadcaster can write legacy events (#7922)BackoffinWithConnectParamsdisabled backoff and caused a zero-delay reconnect loop that flooded logs when keda-operator was unreachable (#7856)globPatternnever matching when written in path-style with a leading/, since blob names never have one (#6492)Pingfails so the background topology-monitoring connections opened bymongo.Connectare not leaked (#5612)v2.20.1Compare Source
Fixes
updateStatusthat caused panics when multiple triggers were scaling simultaneously (#7838)KEDAScalersStarted"Started scalers watch" event not being emitted for ScaledJobs because it shared an events.k8s.io aggregation key with the per-scaler "scaler is built" event (#7820)longhorn/charts (longhorn)
v1.11.3Compare Source
Longhorn is a distributed block storage system for Kubernetes.
envoyproxy/gateway (mirror.gcr.io/envoyproxy/gateway-helm)
v1.8.3Compare Source
Release Announcement
Check out the v1.8.3 release announcement to learn more about the release.
What's Changed
20f009eto86554c4in /tools/docker/envoy-gateway by @dependabot[bot] in #9497Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3
v1.8.3Compare Source
Release Announcement
Check out the v1.8.3 release announcement to learn more about the release.
What's Changed
20f009eto86554c4in /tools/docker/envoy-gateway by @dependabot[bot] in #9497Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.2...v1.8.3
v1.8.2Compare Source
Release Announcement
Check out the v1.8.2 release announcement to learn more about the release.
What's Changed
1487d0atofd8d9aain /tools/docker/envoy-gateway by @dependabot[bot] in #9275Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2
v1.8.2Compare Source
Release Announcement
Check out the v1.8.2 release announcement to learn more about the release.
What's Changed
1487d0atofd8d9aain /tools/docker/envoy-gateway by @dependabot[bot] in #9275Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.1...v1.8.2
v1.8.1Compare Source
Release Announcement
Check out the v1.8.1 release announcement to learn more about the release.
What's Changed
Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1
v1.8.1Compare Source
Release Announcement
Check out the v1.8.1 release announcement to learn more about the release.
What's Changed
Full Changelog: https://github.com/envoyproxy/gateway/compare/v1.8.0...v1.8.1
cert-manager/cert-manager (quay.io/jetstack/charts/cert-manager)
v1.20.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release fixes a security issue (
GHSA-8rvj-mm4h-c258, HIGH) where the defaultcert-manager-editaggregate ClusterRole granted namespace users permission to create ACMEChallengeandOrderresources directly. A user who could create aChallengereferencing aClusterIssuercould supply attacker-controlled solver configuration while cert-manager loaded credentials from theClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones,dnsNames,matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.
All users should upgrade.
Changes by Kind
Bug or Regression
createand Ordercreate,patch,updateverbs from thecert-manager-editaggregate ClusterRole (GHSA-8rvj-mm4h-c258). (#8940, @wallrj-cyberark)Other (Cleanup or Flake)
v1.26.4to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 (#8926, @wallrj-cyberark)v1.20.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release fixes a security issue (
GHSA-8rvj-mm4h-c258, HIGH) where the defaultcert-manager-editaggregate ClusterRole granted namespace users permission to create ACMEChallengeandOrderresources directly. A user who could create aChallengereferencing aClusterIssuercould supply attacker-controlled solver configuration while cert-manager loaded credentials from theClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones,dnsNames,matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.
All users should upgrade.
Changes by Kind
Bug or Regression
createand Ordercreate,patch,updateverbs from thecert-manager-editaggregate ClusterRole (GHSA-8rvj-mm4h-c258). (#8940, @wallrj-cyberark)Other (Cleanup or Flake)
v1.26.4to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 (#8926, @wallrj-cyberark)Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
4a3235205c5e29730e2a5e29730e2a178cf331c5178cf331c523cefb85d223cefb85d25b4506bfee5b4506bfee61c9dc9afeEdited/Blocked Notification
Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.
You can manually request rebase by checking the rebase/retry box above.
⚠️ Warning: custom changes will be lost.
View command line instructions
Manual merge helper
Use this merge commit message when completing the merge manually.
Checkout
From your project repository, check out a new branch and test the changes.