chore(deps): update all non-major dependencies #40

Closed
gitea_admin wants to merge 2 commits from renovate/all-minor-patch into main
Owner

This PR contains the following updates:

Package Type Update Change
actions (source) minor 0.0.5 → 0.1.2
awscli2 minor 2.34.24 → 2.35.11
cert-manager (source) minor v1.14.0 → v1.21.2
gitea minor 12.6.0 → 12.7.0
gitea/gitea minor 1.25.4 → 1.27.3
github-cli minor latest → 0.12.0
grafana (source) minor 8.0.0 → 8.15.0
kind minor 0.29.0 → 0.32.0
kubecm minor 0.33.1 → 0.35.1
kubectl minor 1.33.2 → 1.36.3
kubernetes-helm minor 3.18.4 → 3.20.2
kubeseal minor 0.30.0 → 0.38.4
kustomize minor 5.7.0 → 5.8.1
kyverno minor 1.14.3 → 1.19.0
loki (source) minor 7.0.0 → 7.3.0
nikitafilonov/ai-review docker minor v0.64.0 → v0.77.0
opencost minor 1.42.0 → 1.43.2
opentofu minor 1.11.6 → 1.12.5
prometheus (source) minor 28.9.0 → 28.16.0
syft minor 1.29.0 → 1.51.0
traefik minor 3.6.7 → 3.7.10
traefik (source) minor 28.0.0 → 28.3.0
upcloud-cli minor 3.29.0 → 3.36.0
vaultwarden minor 0.36.4 → 0.46.2

Release Notes

gitea/helm-actions (actions)

v0.1.2

Compare Source

What's Changed

  • feat: add per-container resource configuration for runner and DinD #​160 in #​168
  • chore(deps): update workflow dependencies (minor & patch) in #​172
  • chore(deps): update commitlint/commitlint docker tag to v21.2.0 in #​169
  • chore: bump runner in #​171
  • feat: customize init command in #​166
  • chore(deps): update lockfiles in #​167
  • chore(deps): update lockfiles in #​165
  • chore(deps): update workflow dependencies (minor & patch) in #​163
  • chore(deps): update lockfiles in #​157
  • chore(deps): update actions/checkout action to v7 in #​164
  • chore(deps): update workflow dependencies (minor & patch) in #​161
  • chore(deps): update dependency helm-unittest/helm-unittest to v1.1.1 in #​159
  • chore(deps): update commitlint/commitlint docker tag to v21.0.2 in #​158
  • chore(deps): update busybox docker tag to v1.38.0 in #​155
  • chore(deps): update lockfiles in #​156
  • chore(deps): update lockfiles in #​154
  • chore(deps): update lockfiles in #​153

Contributors

New Contributors

  • @​Arnault_LPC made their first contribution in #​168

Full Changelog: v0.1.1...v0.1.2

v0.1.1

Compare Source

What's Changed

  • chore(deps): update lockfiles in #​151
  • feat: rename any form of act runner to gitea runner or runner in #​149
  • chore(deps): update commitlint/commitlint docker tag to v21 in #​147
  • chore(deps): update workflow dependencies (minor & patch) in #​146
  • chore(deps): update lockfiles in #​141
  • chore(deps): update dependency pnpm to v11 in #​145
  • chore(deps): update commitlint/commitlint docker tag to v20.5.3 in #​140
  • chore(deps): update workflow dependencies (minor & patch) in #​138

Contributors

Full Changelog: v0.1.0...v0.1.1

v0.1.0

Compare Source

What's Changed

Contributors

Full Changelog: v0.0.5...v0.1.0

cert-manager/cert-manager (cert-manager)

v1.21.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities.

All users should upgrade.

Changes by Kind

Bug or Regression
  • ACME Issuer response bodies are no longer reflected into Issuer status conditions or Kubernetes Events. Only ACME problem documents are surfaced (bounded in length); other responses are reported by HTTP status code alone, with the full error available in the controller logs. (#​9239, @​FelixPhipps)
  • Cap ACME server response bodies at 16 MiB to guard against unbounded-body denial-of-service. (#​9222, @​FelixPhipps)
  • De-duplicate dnsNames when multiple Gateway/ListenerSet listeners share a Secret (#​9234, @​speer)
  • Fix certificate renewal windows using February 29 cron schedules across non-leap century years. (#​9240, @​wieghx)
  • Fix validating webhook panics when AdmissionReview requests omit optional fields, by routing identity, approval, and resource validation on the always-present Resource/SubResource fields and denying (rather than silently allowing) requests with an unset or mismatched resource. As a side effect, validation is now also enforced for equivalent-converted requests on non-v1 API versions, which previously could skip validation. (#​9235, @​lunarwhite)
  • Fixed HTTP-01 solver cleanup so that a solver ingress, pod or service that has already been deleted no longer fails the cleanup with a NotFound error. (#​9278, @​arpitjain099)
  • Fixed a bug where replaces field was being populated for the wrong issuer on issuer changes (#​9236, @​hjoshi123)
  • Fixed a data race in the ACME HTTP-01 self-check that could occur when custom DNS servers were configured. (#​9313, @​shashankvarma499)
  • Fixed a panic in the certificates-issuing controller when a CertificateRequest has a failure time set but no Ready condition. (#​9238, @​thc1006)
  • Fixed a race in pkg/scheduler where the cleanup of a fired timer could cancel a newer timer scheduled for the same object, silently dropping a rescheduled poll. (#​9312, @​shashankvarma499)
  • Fixed an issue where the body of a non-Vault HTTP response from spec.vault.server could be copied into the Vault Issuer's Ready condition and its Kubernetes Events. Such responses now report only the HTTP status code, and Vault's own error messages are truncated before being persisted. (#​9262, @​FelixPhipps)
  • Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects (#​9314, @​KR-Ravindra)
  • The ACME HTTP-01 self-check no longer reflects the fetched response body in Challenge.status.reason, preventing disclosure of internal response contents reachable via redirects. The response is still available in the controller's debug logs. (#​9232, @​FelixPhipps)
  • The vault issuer no longer authenticates to Vault using the cert-manager controller's ambient AWS credentials for AWS IAM auth on a namespaced Issuer, unless ambient credentials are explicitly enabled via --issuer-ambient-credentials. ClusterIssuer and explicit serviceAccountRef (IRSA) configurations are unaffected. (#​9231, @​FelixPhipps)
Other (Cleanup or Flake)
  • Upgrade Go to 1.26.6, which includes security fixes to the go command, and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages. (#​9151, @​wallrj)
  • Upgrade Go to 1.26.8. (#​9323, @​wallrj)
  • Bump google.golang.org/grpc to v1.83.2 to fix reported security vulnerabilities (#​9255, #​9317)
  • Bump golang.org/x/crypto to v0.56.0 to fix reported security vulnerabilities (#​9265)

v1.21.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.21.1 fixes a controller panic for Certificates with spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck at Ready=False (InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.

All users should upgrade.

Changes by Kind

Bug or Regression
  • Avoid controller panic if a Certificate sets spec.renewal.policy=Disabled (#​9038, @​sklirg)
  • Fix Issuer/ClusterIssuer stuck at Ready=False/InvalidSolver after a missing ACME DNS-01 solver Secret is created (#​9083, @​SebTardif)
  • Fix log spam and dropped Secret informer events for non-cert-manager Secrets, caused by a generics regression introduced in 1.21.0. (#​9037, @​wallrj-cyberark)
  • Fixed the commented Gateway API config example in the Helm chart values to use gatewayAPI.enabled instead of the invalid gatewayAPI.enable. (#​9012, @​mateenali66)
Other (Cleanup or Flake)
  • Bump golang.org/x/text to v0.40.0 to fix a reported security vulnerability (#​9039, @​wallrj-cyberark)
  • Bump google.golang.org/grpc to v1.82.1 to fix a reported security vulnerability (#​9063)
  • Bump github.com/google/cel-go to v0.29.0 to fix a reported security vulnerability (#​9072)
  • Bump go.opentelemetry.io/otel to v1.44.0 to fix a reported security vulnerability (#​9073)
  • Update distroless base images (#​9000, #​9025)

v1.21.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values — review them carefully before upgrading.

Known Issues

  • Controller crash-loops when a Certificate sets renewal.policy: Disabled: the new Certificate renewal policies feature (#​8258) causes a nil pointer dereference panic in the trigger controller whenever a Certificate's spec.renewal.policy is set to Disabled — pki.RenewalTime() returns (nil, nil) for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. Workaround: do not set renewal.policy: Disabled on any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See #​9031 for details.
  • Log spam for non-cert-manager-labelled Secret events: the typed predicates refactoring (#​8407) causes filteredEventHandler type assertion failures ("OnAdd missing Object", "OnUpdate missing ObjectOld", "OnDelete missing Object") for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. This is cosmetic only — the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See #​8994 for details.
  • Issuer/ClusterIssuer can get stuck at Ready: False, Reason: InvalidSolver and never self-correct: new eager validation of ACME solver Secrets (#​8255) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly report Ready: False, but creating the missing Secret afterwards does not trigger re-reconciliation — the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. Workaround: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See #​9036 for details and a fix proposal.

Major Themes

Default tokenrequest RBAC removed from Helm chart

⚠️ Breaking change

The Helm chart no longer creates a default Role and RoleBinding granting the cert-manager controller permission to create tokens for its own ServiceAccount (serviceaccounts/token: create). No documented workflow requires this RBAC — the Route53 docs section that motivated it was removed in 2024.

If you use serviceAccountRef.name pointing at the controller ServiceAccount, you must now either create your own Role/RoleBinding granting serviceaccounts/token: create, or migrate to a dedicated ServiceAccount (recommended — see the Vault or Route53 documentation).

Restrict Challenge and Order RBAC in cert-manager-edit ClusterRole

⚠️ Potentially breaking change

The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io (GHSA-8rvj-mm4h-c258). These resources are internal to cert-manager's ACME workflow. Challenge patch and update are retained because users may need them to remove stuck finalizers.

This change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant those permissions explicitly.

Metrics port name and path Helm values removed

⚠️ Breaking change

The Helm values prometheus.servicemonitor.targetPort, prometheus.servicemonitor.path, and prometheus.podmonitor.path have been removed. The controller Service metrics port has been renamed from tcp-prometheus-servicemonitor to http-metrics. Because the Helm values schema uses additionalProperties: false, users who still have any of the removed keys in their values overrides will see a schema validation error on upgrade — remove them before upgrading. (#​8952)

ACME and Certificate Management
  • ACME Renewal Information (ARI): experimental support for RFC 9773 behind the ACMEUseARI feature gate. When enabled, cert-manager queries the ACME server's renewalInfo endpoint for the recommended renewal window, allowing servers like Let's Encrypt to proactively prompt renewal during mass revocations or CA key rollovers. (#​8798)
  • waitInsteadOfSelfCheck solver option: skip cert-manager's own self-check and instead wait a configured duration before asking the ACME server to validate. An escape hatch for split-horizon DNS and NAT hairpin environments. See configuration details. (#​8858)
  • AWS IAM authentication for Vault: the Vault issuer now supports IRSA, EKS Pod Identity, and ambient EC2/ECS credentials, removing the need for long-lived AWS Secrets. (#​8422)
  • Certificate renewal policies: a new renewalPolicies field on the Certificate API provides more expressive control over renewal scheduling, complementing renewBefore and renewBeforePercentage. (#​8258)
  • Configurable CertificateRequest retry backoff: the new --certificate-request-maximum-backoff-duration flag (default: 32 hours) caps the exponential backoff for failed CertificateRequests, useful for environments with scheduled CA maintenance windows. (#​8893)
  • Modern2026 PKCS#12 profile: a new FIPS 140-3 compatible encoding profile using AES-256 + SHA-256 KDFs instead of legacy 3DES/RC2. (#​8841)
  • Webhook certificate renewal after system suspend: the webhook now detects missed certificate renewals after system suspend (S3/S4) or VM live migration by polling wall-clock time, recovering within one minute of resume. (#​8464)
Gateway API and cainjector
  • HTTP01 ListenerSet parentRef fallback: the acme.cert-manager.io/http01-parentreffallback: "true" annotation causes cert-manager to use the parent Gateway for solver HTTPRoutes instead of the ListenerSet, enabling TLS-only ListenerSets to use a shared HTTP listener for ACME challenges. (#​8749)
  • cert-manager.io/ignore-tls-listeners annotation: exclude specific Gateway TLS listeners from certificate management. (#​8727)
  • Additional listener protocols: configurable listener protocols beyond the default set. (#​8683)
  • enableGatewayAPI configuration restructure: enableGatewayAPI and enableGatewayAPIListenerSet are deprecated in favor of gatewayAPI.enabled / gatewayAPI.enableListenerSet. The old fields continue to work. (#​8732)
  • CAInjectorMerging promoted to GA: unconditionally enabled; will be removed in a future release. (#​8583)
  • cainjector server-side apply unconditional: the ServerSideApply feature gate is deprecated. (#​8692)
  • cainjector --ignore-namespaces flag: skip specified namespaces when watching Secrets for injection. (#​8614)
Deployment and Observability
  • Venafi OAuth token observability: a new AuthFailed Issuer condition reason distinguishes bad credentials from transient errors. PANW NGTS is now supported as a Venafi backend. (#​8808, #​8779)
  • runtimeClassName support: configurable for cert-manager components and ACME HTTP01 solver pods. (#​8791, #​8976)
  • startupapicheck.ttlSecondsAfterFinished: opt-in automatic cleanup of the startupapicheck Job. (#​8523)
  • --acme-http01-solver-extra-labels: propagate global.commonLabels to dynamically-created ACME HTTP01 solver resources. (#​8761)
Notable Bug Fixes
  • Integer overflow in renewBeforePercentage: Certificates with durations longer than approximately 3 years were incorrectly rejected or assigned incorrect renewal times. (#​8947)
  • Infinite re-issuance loop: cert-manager no longer loops when an issuer returns an already-expired certificate. (#​8610)
  • ACME transient network errors: challenges no longer permanently fail on TLS handshake timeouts, DNS resolution failures, or context cancellation during nonce fetches and authorization waits. (#​8760)
  • DNS-over-HTTPS response body cap: response body reads are now bounded at 128 KB to prevent potential OOM. (#​8803)
  • Vault path traversal: the Vault issuer webhook now rejects .. path segments, preventing path.Join from silently resolving relative segments. (#​8930)
  • DNS issuer secrets validated before ready: prevents silent misconfiguration. (#​8255)

Community

As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.

A special thanks to:

for their contributions, comments and support!

Also, thanks to the cert-manager maintainer team for their help in this release:

And finally, thanks to the cert-manager steering committee for their feedback in this release cycle:

Changes since v1.20.0

Feature
  • Add Venafi OAuth token request observability and a new AuthFailed Issuer condition reason to distinguish bad credentials from transient infrastructure errors. (#​8808, @​FelixPhipps)
  • Add certificateRequestMaximumBackoffDuration controller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file, --certificate-request-maximum-backoff-duration CLI flag, or Helm value config.certificateRequestMaximumBackoffDuration. Defaults to 32 hours for backward compatibility. (#​8893, @​lunarwhite)
  • Add an optional waitInsteadOfSelfCheck field to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. (#​8858, @​wallrj)
  • Add configurable runtimeClassName support for cert-manager components and ACME HTTP01 solver pods. (#​8791, @​jsoref)
  • Add direct configurable runtimeClassName support for ACME HTTP01 solver pods via the acmesolver.runtimeClassName Helm value. (#​8976, @​erikgb)
  • Add new controller flag --acme-http01-solver-extra-labels, allowing Helm's global.commonLabels to propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). (#​8761, @​lunarwhite)
  • Add opt-in startupapicheck.ttlSecondsAfterFinished Helm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. (#​8523, @​dap0am)
  • Added ARI support through the ACMEUseARI feature gate. (#​8798, @​hjoshi123)
  • Added AWS IAM authentication support for Vault issuer, including IRSA (IAM Roles for Service Accounts) and ambient credentials (EC2/ECS). (#​8422, @​bitloi)
  • Added cert-manager.io/ignore-tls-listeners annotation for ignoring gwapi listeners. (#​8727, @​hjoshi123)
  • Added option to specify additional listener protocols the GatewayAPI integration will consider when creating certificates. (#​8683, @​ThatsMrTalbot)
  • Adds support for the Modern2026 go-pkcs12 profile and FIPS 140-3 (#​8841, @​seanorama)
  • Cainjector: A new flag --ignore-namespaces was added to the cainjector binary. It can be used to filter out namespaces from being watched for secrets to use for injectables. (#​8614, @​figaw)
  • Disabled client side rate-limiting if AP&F is enabled. (#​8757, @​hjoshi123)
  • Extend the Venafi/CyberArk integration to also support PANW NGTS. (#​8779, @​FelixPhipps)
  • Adding certificate renewal policies (#​8258, @​hjoshi123)
  • Make cainjector use SSA unconditionally and deprecate the ServerSideApply feature gate (#​8692, @​erikgb)
  • Processed annotations cert-manager.io/alt-names, cert-manager.io/ip-sans to Certificates generated from ingress like objects in cert-shim controllers. (#​8927, @​jabbrwcky)
  • Promote the CAInjectorMerging feature gate to GA (#​8583, @​Copilot)
  • When using ACME HTTP-01 with a ListenerSet, setting the annotation acme.cert-manager.io/http01-parentreffallback: "true" causes cert-manager to use the parent Gateway as the solver HTTPRoute parentRef instead of the ListenerSet. This enables TLS-only ListenerSets to rely on a shared Gateway HTTP listener for ACME challenges. (#​8749, @​apkatsikas)
Bug or Regression
  • BREAKING: The Helm chart no longer ships a default Role and RoleBinding granting the cert-manager controller ServiceAccount permission to create tokens for itself (serviceaccounts/token: create). This RBAC was added in v1.16 (#​7213) but no documented workflow requires it, and the motivating Route53 docs section was removed in Oct 2024. If you rely on serviceAccountRef.name pointing at the controller ServiceAccount (an undocumented pattern), you must now create your own Role and RoleBinding granting serviceaccounts/token: create on that ServiceAccount, or migrate to one of the documented patterns (IRSA ambient, or a dedicated ServiceAccount with its own RBAC). (#​8931, @​wallrj-cyberark)
  • ACME challenges no longer terminally fail on transient network errors (TLS handshake timeouts, DNS failures, context cancellation) during nonce fetches and authorization waits. The challenge controller returns the error and lets the workqueue retry with backoff. (#​8760, @​texasich)
  • Add dns issuer secrets validation before marking it as ready (#​8255, @​Peac36)
  • Add missing issuer finalizer RBAC to the order controller to support owner references (#​8654, @​erikgb)
  • ClusterIssuer metrics collector now correctly respects the enabled-controllers configuration, avoiding a redundant startup when only operating within a namespace. (#​8822, @​lunarwhite)
  • Fix Venafi TPP issuer setup and signing regression on master: restore authentication of the vcert connector in the client constructor, which was removed in #​8808. (#​8843, @​wallrj-cyberark)
  • Fix a performance issue in the certificateRequestApproval webhook where CertificateRequests referencing a GroupKind whose CRD is not yet installed would trigger repeated API server discovery queries on every admission request. Negative results are now cached for 30 seconds. (#​8651, @​mateenali66)
  • Fix webhook serving certificate not being renewed after system suspend. (#​8464, @​Peac36)
  • Fixed a rare panic in the trigger controller when a Certificate is deleted from the informer cache while a reconcile is in progress (e.g. during namespace teardown). (#​8962, @​hjoshi123)
  • Fixed an integer overflow in renewBeforePercentage calculations that caused Certificates with durations longer than approximately 3 years to be incorrectly rejected by validation or assigned incorrect renewal times. (#​8947, @​ThatsMrTalbot)
  • Fixed duplicate parentRef bug when both issuer config and annotations are present. (#​8619, @​hjoshi123)
  • Fixed infinite re-issuance loop when issuer returns an already expired certificate (#​8610, @​onurmicoogullari)
  • Fixed local e2e-setup-samplewebhook installation to use the samplewebhook image repository and tag from the saved image tarball manifest. (#​8821, @​wallrj)
  • Fixed potential OOM in DNS-over-HTTPS client by bounding response body read with io.LimitReader (128 KB cap). (#​8803, @​SebTardif)
  • Fixed validation of timezone-prefixed renewal window cron specs without a schedule. (#​8813, @​immanuwell)
  • Helm chart bugfix: rename image helper to avoid umbrella chart conflicts (#​8753, @​FelixPhipps)
  • Helm: Fix invalid YAML generated when both webhook.config and webhook.volumes are defined. (#​8664, @​jnohlgard)
  • Remove ACME Challenge create and Order create/patch/update from the cert-manager-edit aggregate ClusterRole to prevent direct manipulation of these internal resources (GHSA-8rvj-mm4h-c258). (#​8958, @​wallrj-cyberark)
  • Remove issuer owner reference from challenges blocking challenge garbage collection (#​8743, @​erikgb)
  • Update logic to identify and preserve the secret matching nextPrivateKeySecretName (#​8577, @​putongyong)
  • Vault Issuer webhook validation now rejects .. path segments in spec.vault.path and auth mount path fields, preventing path.Join from silently resolving relative segments before constructing the Vault API request. (#​8930, @​wallrj-cyberark)
Other (Cleanup or Flake)
  • API cleanup: removed deprecated ObjectReference (#​8625, @​inteon)
  • Remove Helm values prometheus.servicemonitor.targetPort, prometheus.servicemonitor.path, and prometheus.podmonitor.path. The metrics path is always /metrics and the target port is always http-metrics. Rename the controller service metrics port from tcp-prometheus-servicemonitor to http-metrics for consistency with other workloads. Users must remove these keys from their value overrides before upgrading. (#​8952, @​erikgb)
  • The enableGatewayAPI and enableGatewayAPIListenerSet fields on ControllerConfiguration are deprecated and moved into the gatewayAPI sub-struct as gatewayAPI.enabled and gatewayAPI.enableListenerSet. The old fields continue to work. (#​8732, @​ThatsMrTalbot)
  • Update base images to Debian 13 (#​8849, @​ltwongaa)

v1.20.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release updates Go and several dependencies to fix reported security vulnerabilities, and fixes a bug where ingress-shim removed the applyset label from cached Ingress and Gateway objects.

All users should upgrade.

[!NOTE]
Security scanners still report three golang.org/x/crypto findings. None of them affects cert-manager and we do not plan to fix them in the 1.20 line.

  • CVE-2026-56855 and CVE-2026-78662 are deadlocks in the golang.org/x/crypto/ssh connection multiplexer, triggered by a malicious SSH peer after a connection is established. cert-manager never opens an SSH connection. Only the controller links the ssh package, through vcert, which uses it to format a public key. The fix, golang.org/x/crypto v0.56.0, requires Go language version 1.26, which we will not adopt in a patch release. govulncheck confirms the vulnerable functions are not called.
  • GO-2026-5932 marks golang.org/x/crypto/openpgp as unmaintained. cert-manager does not import that package and there is no fixed version.

cert-manager 1.21 already uses golang.org/x/crypto v0.56.0, so upgrade to 1.21 if you need a clean scan.

Changes by Kind

Bug or Regression
  • Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects (#​9315, @​KR-Ravindra)
Other (Cleanup or Flake)

v1.20.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.

All users should upgrade.

[!WARNING]
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.

Changes by Kind

Bug or Regression
Other (Cleanup or Flake)

v1.20.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.2 fixes invalid YAML generated in the Helm chart when both webhook.config
and webhook.volumes are defined, and bumps Go to 1.26.2 along with dependencies
to address reported vulnerabilities.

Changes by Kind

Bug or Regression
Other (Cleanup or Flake)

v1.20.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.1 fixes an issue for OpenShift users that has to do with the finalizer RBAC, bumps gRPC to address a reported non-affecting vulnerability, and fixes a duplicate parentRef bug when both issuer config and annotations are present (Gateway API).

Bug or Regression
  • Fixed duplicate parentRef bug when both issuer config and annotations are present. (#​8658, @​hjoshi123)
  • Add missing issuer finalizer RBAC to the order controller to support owner references. This was preventing OpenShift users from being able to upgrade to v1.20.0. (#​8655, @​erikgb)
  • Bump google.golang.org/grpc to fix vulnerability reported by scanners. This isn't a vulnerability that affects cert-manager, but we are bumping it because it is reported by scanners. (#​8657, @​erikgb)

v1.20.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta.

Changes by Kind

Feature
  • Added a set of flags to permit setting NetworkPolicy across all deployed containers. Remove redundant global IP ranges from example policies. (#​8370, @​jcpunk)
  • Added selectable fields to custom resource definitions for .spec.issuerRef.{group, kind, name} (#​8256, @​tareksha)
  • Added support for specifying imagePullSecrets in the startupapicheck-job Helm template to enable pulling images from private registries. (#​8186, @​mathieu-clnk)
  • Added 'extraContainers' helm chart value, allowing the deployment of arbitrary sidecar containers within the cert-manager operator pod. This can be used to support, for e.g., AWS IAM Roles Anywhere for Route53 DNS01 verification. (#​8355, @​dancmeyers)
  • Added parentRef override annotations on the Certificate resource. (#​8518, @​hjoshi123)
  • Added support for azure private zones for dns01 issuer. (#​8494, @​hjoshi123)
  • Added support for configuring PEM decoding size limits, allowing operators to handle larger certificates and keys. (#​7642, @​robertlestak)
  • Added support for unhealthyPodEvictionPolicy in PodDisruptionBudget (#​7728, @​jcpunk)
  • For Venafi provider, read venafi.cert-manager.io/custom-fields annotation on Issuer/ClusterIssuer and use it as base with override/append capabilities on Certificate level. (#​8301, @​k0da)
  • Improve error message when CA issuers are misconfigured to use a clashing secret name (#​8374, @​majiayu000)
  • Introduce a new Ingress annotation acme.cert-manager.io/http01-ingress-ingressclassname to override http01.ingress.ingressClassName field in HTTP-01 challenge solvers. (#​8244, @​lunarwhite)
  • Update global.nodeSelector to helm chart to perform a merge and allow for a single nodeSelector to be set across all services. (#​8195, @​StingRayZA)
  • Vault issuers will now include the Vault server address as one of the default audiences on generated service account tokens. (#​8228, @​terinjokes)
  • Added experimental XListenerSets feature gate (#​8394, @​hjoshi123)
Documentation
Bug or Regression
  • Adds logs for cases when acme server returns us a fatal error in the order controller (#​8199, @​Peac36)
  • Fixed an issue where kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed (#​8160, @​inteon)
  • Changes to the Duration and RenewBefore annotations on ingress and gateway-api resources will now trigger certificate updates. (#​8232, @​eleanor-merry)
  • Fix an issue where ACME challenge TXT records are not cleaned up when there are many resource records in CloudDNS. (#​8456, @​tkna)
  • Fix unregulated retries with the DigitalOcean DNS-01 solver
    Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging (#​8221, @​wallrj-cyberark)
  • Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. (#​8403, @​calm329)
  • Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. (#​8424, @​SlashNephy)
  • Fixed the HTTP-01 Gateway solver creating invalid HTTPRoutes by not setting spec.hostnames when the challenge DNSName is an IP address. (#​8443, @​alviss7)
  • Revert API defaults for issuer reference kind and group introduced in 0.19.0 (#​8173, @​erikgb)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#​8469, @​SgtCoDFish)
  • Update Go to v1.25.5 to fix CVE-2025-61727 and CVE-2025-61729 (#​8290, @​octo-sts[bot])
  • When Prometheus monitoring is enabled, the metrics label is now set to the intended value of cert-manager. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). (#​8162, @​LiquidPL)
Other (Cleanup or Flake)

v1.19.6

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release fixes a security issue (GHSA-8rvj-mm4h-c258, HIGH) where the default cert-manager-edit aggregate ClusterRole granted namespace users permission to create ACME Challenge and Order resources directly. A user who could create a Challenge referencing a ClusterIssuer could supply attacker-controlled solver configuration while cert-manager loaded credentials from the ClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones, dnsNames, matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.

This release also includes Go version bumps to address reported CVEs. All users should upgrade.

[!WARNING]
Potentially breaking change: The cert-manager-edit aggregate ClusterRole no longer grants create for challenges.acme.cert-manager.io or create, patch, update for orders.acme.cert-manager.io. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly.

Changes by Kind

Bug or Regression
Other (Cleanup or Flake)

v1.19.5

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade.

Changes by Kind

Other (Cleanup or Flake)

v1.19.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade.

Changes by Kind

Bug or Regression

v1.19.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.

Changes by Kind

Bug or Regression
  • Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. (#​8415, @​cert-manager-bot)
  • Fixed an issue where HTTP-01 challenges failed when the Host header contained an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. (#​8436, @​cert-manager-bot)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#​8468, @​SgtCoDFish)
Other (Cleanup or Flake)

v1.19.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We updated Go to fix some vulnerabilities in the standard library.

📖 Read the full 1.19 release notes on the cert-manager.io website before upgrading.

Changes since v1.19.1

Bug or Regression
  • Address false positive vulnerabilities CVE-2025-47914 and CVE-2025-58181 which were reported by Trivy. (#​8283, @​SgtCoDFish)
  • Update Go to v1.25.5 to fix CVE-2025-61727 and CVE-2025-61729 (#​8294, @​wallrj-cyberark)
  • Update global.nodeSelector to helm chart to perform a merge and allow for a single nodeSelector to be set across all services. (#​8233, @​cert-manager-bot)
Other (Cleanup or Flake)

v1.19.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We reverted the CRD-based API defaults for Certificate.Spec.IssuerRef and CertificateRequest.Spec.IssuerRef after they were found to cause unexpected certificate renewals after upgrading to 1.19.0. We will try re-introducing these API defaults in cert-manager 1.20.
We fixed a bug that caused certificates to be re-issued unexpectedly if the issuerRef kind or group was changed to one of the "runtime" default values.
We upgraded Go to 1.25.3 to address the following security vulnerabilities: CVE-2025-61724, CVE-2025-58187, CVE-2025-47912, CVE-2025-58183, CVE-2025-61723, CVE-2025-58186, CVE-2025-58185, CVE-2025-58188, and CVE-2025-61725.

📖 Read the full 1.19 release notes on the cert-manager.io website before upgrading.

Changes since v1.19.0:

Bug or Regression
  • BUGFIX: in case kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed (#​8175, @​cert-manager-bot)
  • Bump Go to 1.25.3 to fix a backwards incompatible change to the validation of DNS names in X.509 SAN fields which prevented the use of DNS names with a trailing dot (#​8177, @​wallrj-cyberark)
  • Revert API defaults for issuer reference kind and group introduced in 0.19.0 (#​8178, @​cert-manager-bot)

v1.19.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

⚠️ Known issues: The following known issues are fixed in v1.19.1:

This release focuses on expanding platform compatibility, improving deployment flexibility, enhancing observability, and addressing key reliability issues.

📖 Read the full release notes at cert-manager.io: https://cert-manager.io/docs/releases/release-notes/release-notes-1.19

Changes since v1.18.0:

Feature

  • Add IPv6 rules to the default network policy (#​7726, @​jcpunk)
  • Add global.nodeSelector to helm chart to allow for a single nodeSelector to be set across all services. (#​7818, @​StingRayZA)
  • Add a feature gate to default to Ingress pathType Exact in ACME HTTP01 Ingress challenge solvers. (#​7795, @​sspreitzer)
  • Add generated applyconfigurations allowing clients to make type-safe server-side apply requests for cert-manager resources. (#​7866, @​erikgb)
  • Added API defaults to issuer references group (cert-manager.io) and kind (Issuer). (#​7414, @​erikgb)
  • Added certmanager_certificate_challenge_status Prometheus metric. (#​7736, @​hjoshi123)
  • Added protocol field for rfc2136 DNS01 provider (#​7881, @​hjoshi123)
  • Added experimental field hostUsers flag to all pods. Not set by default. (#​7973, @​hjoshi123)
  • Support configurable resource requests and limits for ACME HTTP01 solver pods through ClusterIssuer and Issuer specifications, allowing granular resource management that overrides global --acme-http01-solver-resource-* settings. (#​7972, @​lunarwhite)
  • The CAInjectorMerging feature has been promoted to BETA and is now enabled by default (#​8017, @​ThatsMrTalbot)
  • The controller, webhook and ca-injector now log their version and git commit on startup for easier debugging and support. (#​8072, @​prasad89)
  • Updated certificate metrics to the collector approach. (#​7856, @​hjoshi123)

Bug or Regression

  • ACME: Increased challenge authorization timeout to 2 minutes to fix error waiting for authorization (#​7796, @​hjoshi123)
  • BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints (#​7816, @​kinolaev)
  • Enforced ACME HTTP-01 solver validation to properly reject configurations when multiple ingress options (class, ingressClassName, name) are specified simultaneously (#​8021, @​lunarwhite)
  • Increase maximum sizes of PEM certificates and chains which can be parsed in cert-manager, to handle leaf certificates with large numbers of DNS names or other identities (#​7961, @​SgtCoDFish)
  • Reverted adding the global.rbac.disableHTTPChallengesRole Helm option. (#​7836, @​inteon)
  • This change removes the path label of core ACME client metrics and will require users to update their monitoring dashboards and alerting rules if using those metrics. (#​8109, @​mladen-rusev-cyberark)
  • Use the latest version of ingress-nginx in E2E tests to ensure compatibility (#​7792, @​wallrj)

Other (Cleanup or Flake)

  • Helm: Fix naming template of tokenrequest RoleBinding resource to improve consistency (#​7761, @​lunarwhite)
  • Improve error messages when certificates, CRLs or private keys fail admission due to malformed or missing PEM data (#​7928, @​SgtCoDFish)
  • Major upgrade of Akamai SDK. NOTE: The new version has not been fully tested end-to-end due to the lack of cloud infrastructure. (#​8003, @​hjoshi123)
  • Update kind images to include the Kubernetes 1.33 node image (#​7786, @​wallrj)
  • Use maps.Copy for cleaner map handling (#​8092, @​quantpoet)
  • Vault: Migrate Vault E2E add-on tests from deprecated vault-client-go to the new vault/api client. (#​8059, @​armagankaratosun)

v1.18.6

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.18.6 is a simple patch release to fix some reported vulnerabilities, most notably CVE-2025-68121.

NB: We didn't attempt to patch CVE-2026-24051 but that vulnerability affects macOS only, so cert-manager will be unaffected.

Changes by Kind

Bug or Regression

v1.18.5

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.

Changes by Kind

Bug or Regression
  • Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. (#​8414, @​cert-manager-bot)
  • Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. (#​8437, @​cert-manager-bot)
  • Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. (#​8467, @​SgtCoDFish)
Other (Cleanup or Flake)

v1.18.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We updated Go to fix some vulnerabilities in the standard library.

📖 Read the full 1.18 release notes on the cert-manager.io website before upgrading.

Changes since v1.18.3

Bug or Regression
Other (Cleanup or Flake)

v1.18.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We fixed a bug which caused certificates to be re-issued unexpectedly, if the issuerRef kind or group was changed to one of the "runtime" default values. We increased the size limit when parsing PEM certificate chains to handle leaf certificates with large numbers of DNS named or other identities. We upgraded Go to 1.24.9 to fix various non-critical security vulnerabilities.

📖 Read the full 1.18 release notes on the cert-manager.io website before upgrading.

Changes since v1.18.2:

Bug or Regression
  • BUGFIX: in case kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed (#​8174, @​cert-manager-bot)
  • Bump Go to 1.24.9. Fixes the following vulnerabilities: CVE-2025-61724, CVE-2025-58187, CVE-2025-47912, CVE-2025-58183, CVE-2025-61723, CVE-2025-58186, CVE-2025-58185, CVE-2025-58188, CVE-2025-61725 (#​8176, @​wallrj-cyberark)
  • Increase maximum sizes of PEM certificates and chains which can be parsed in cert-manager, to handle leaf certificates with large numbers of DNS names or other identities (#​7966, @​cert-manager-bot)
Other (Cleanup or Flake)

v1.18.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the NameConstraints feature gate).
We dropped the new global.rbac.disableHTTPChallengesRole Helm option due to a bug we found, this feature will be released in v1.19 instead.

Changes since v1.18.1:

Bug or Regression

v1.18.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We have added a new feature gate ACMEHTTP01IngressPathTypeExact, to allow ingress-nginx users to turn off the new default Ingress PathType: Exact behavior, in ACME HTTP01 Ingress challenge solvers.
This change fixes the following issue: #​7791

We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (error waiting for authorization), which has been reported by multiple users, since the release of cert-manager v1.16.0.
This change should fix the following issues: #​7337, #​7444, and #​7685.

ℹ️ Be sure to review all new features and changes below, and read the full release notes carefully before upgrading.

Changes since v1.18.0:

Feature
  • Added a new feature gate ACMEHTTP01IngressPathTypeExact, to allow ingress-nginx users to turn off the new default Ingress PathType: Exact behavior, in ACME HTTP01 Ingress challenge solvers. (#7810, @​sspreitzer)
Bug or Regression
  • ACME: Increased challenge authorization timeout to 2 minutes to fix error waiting for authorization. (#7801, @​hjoshi123)
Other (Cleanup or Flake)
  • Use the latest version of ingress-nginx in E2E tests to ensure compatibility (#7807, @​wallrj)

v1.18.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.18 introduces several new features and breaking changes. Highlights include support for ACME certificate profiles, a new default for Certificate.Spec.PrivateKey.RotationPolicy now set to Always (breaking change), and the default Certificate.Spec.RevisionHistoryLimit now set to 1 (potentially breaking).

ℹ️ Be sure to review all new features and changes below, and read the full release notes carefully before upgrading.

Known Issues
  • ACME HTTP01 challenge paths are rejected by the ingress-nginx validating webhook (#​7791)

Changes since v1.17.2:

Feature
  • Add config to the Vault issuer to allow the server-name to be specified when validating the certificates the Vault server presents. (#​7663, @​ThatsMrTalbot)
  • Added app.kubernetes.io/managed-by: cert-manager label to the created Let's Encrypt account keys (#​7577, @​terinjokes)
  • Added certificate issuance and expiration time metrics (certmanager_certificate_not_before_timestamp_seconds, certmanager_certificate_not_after_timestamp_seconds). (#​7612, @​solidDoWant)
  • Added ingress-shim option: --extra-certificate-annotations, which sets a list of annotation keys to be copied from Ingress-like to resulting Certificate object (#​7083, @​k0da)
  • Added the iss short name for the cert-manager Issuer resource. (#​7373, @​SgtCoDFish)
  • Added the ciss short name for the cert-manager ClusterIssuer resource (#​7373, @​SgtCoDFish)
  • Adds the global.rbac.disableHTTPChallengesRole helm value to disable HTTP-01 ACME challenges. This allows cert-manager to drop its permission to create pods, improving security when HTTP-01 challenges are not required. (#​7666, @​ali-hamza-noor)
  • Allow customizing signature algorithm (#​7591, @​tareksha)
  • Cache the full DNS response and handle TTL expiration in FindZoneByFqdn (#​7596, @​ThatsIvan)
  • Cert-manager now uses a local fork of the golang.org/x/crypto/acme package (#​7752, @​wallrj)
  • Add support for ACME profiles extension. (#​7777, @​wallrj)
  • Promote the UseDomainQualifiedFinalizer feature to GA. (#​7735, @​jsoref)
  • Switched service/servicemon definitions to use port names instead of numbers. (#​7727, @​jcpunk)
  • The default value of Certificate.Spec.PrivateKey.RotationPolicy changed from Never to Always. (#​7723, @​wallrj)
  • Potentially breaking: Set the default revisionHistoryLimit to 1 for the CertificateRequest revisions (#​7758, @​ali-hamza-noor)
Documentation
Bug or Regression
  • Bump go-jose dependency to address CVE-2025-27144. (#​7606, @​SgtCoDFish)
  • Bump golang.org/x/oauth2 to patch CVE-2025-22868. (#​7638, @​NicholasBlaskey)
  • Bump golang.org/x/crypto to patch GHSA-hcg3-q754-cr77. (#​7638, @​NicholasBlaskey)
  • Bump github.com/golang-jwt/jwt to patch GHSA-mh63-6h87-95cp. (#​7638, @​NicholasBlaskey)
  • Change of the Kubernetes Ingress pathType from ImplementationSpecific to Exact for a reliable handling of ingress controllers and enhanced security. (#​7767, @​sspreitzer)
  • Fix AWS Route53 error detection for not-found errors during deletion of DNS records. (#​7690, @​wallrj)
  • Fix behavior when running with --namespace=<namespace>: limit the scope of cert-manager to a single namespace and disable cluster-scoped controllers. (#​7678, @​tsaarni)
  • Fix handling of certificates with IP addresses in the commonName field; IP addresses are no longer added to the DNS subjectAlternativeName list and are instead added to the ipAddresses field as expected. (#​7081, @​johnjcool)
  • Fix issuing of certificates via DNS01 challenges on Cloudflare after a breaking change to the Cloudflare API (#​7549, @​LukeCarrier)
  • Fixed the certmanager_certificate_renewal_timestamp_seconds metric help text indicating that the metric is relative to expiration time, rather than Unix epoch time. (#​7609, @​solidDoWant)
  • Fixing the service account template to incorporate boolean values for the annotations. (#​7698, @​ali-hamza-noor)
  • Quote nodeSelector values in Helm Chart (#​7579, @​tobiasbp)
  • Skip Gateway TLS listeners in Passthrough mode. (#​6986, @​vehagn)
  • Upgrade golang.org/x/net fixing CVE-2025-22870. (#​7619, @​dependabot[bot])
Other (Cleanup or Flake)
  • ACME E2E Tests: Upgraded Pebble to v2.7.0 and modified the ACME tests to match latest Pebble behaviour. (#​7771, @​wallrj)
  • Patch the third_party/forked/acme package with support for the ACME profiles extension. (#​7776, @​wallrj)
  • Promote the AdditionalCertificateOutputFormats feature to GA, making additional formats always enabled. (#​7744, @​erikgb)
  • Remove deprecated feature gate ValidateCAA. Setting this feature gate is now a no-op which does nothing but print a warning log line (#​7553, @​SgtCoDFish)
  • Update kind images to include the Kubernetes 1.33 node image (#​7787, @​cert-manager-bot)
  • Upgrade Go to v1.24.4 (#​7785, @​wallrj)
  • Use slices.Contains to simplify code (#​7753, @​cuinix)

v1.17.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the NameConstraints feature gate).

Changes since v1.17.3:

Bug or Regression
  • BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints (#​7832, @​cert-manager-bot)

v1.17.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23.

We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (error waiting for authorization), which has been reported by multiple users, in: #​7337, #​7444, and #​7685.

ℹ️ Be sure to review all new features and changes below, and read the full release notes carefully before upgrading.

Changes since v1.17.2:

Bug or Regression
  • Bump Go to 1.23.10 to fix GO-2025-3749, GO-2025-3750, and GO-2025-3751 (#​7799, @​wallrj)
  • ACME: Increased challenge authorization timeout to 2 minutes to fix error waiting for authorization (#​7798, @​hjoshi123)
Other (Cleanup or Flake)
  • Use the latest version of ingress-nginx in E2E tests to ensure compatibility (#​7808, @​wallrj)

v1.17.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23 and includes various dependency updates.

📖 Read the full cert-manager 1.17 release notes, before installing or upgrading.

Changes since v1.17.1

Bug or Regression

v1.17.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release is primarily intended to address a breaking change in Cloudflare's API which impacted ACME DNS-01 challenges using Cloudflare.

Many thanks to the community members who reported this issue!

Changes by Kind

Bug or Regression
  • ❗ Fix issuing of certificates via DNS01 challenges on Cloudflare after a breaking change to the Cloudflare API (#​7565, @​LukeCarrier)
  • Bump go to 1.23.6 to address CVE-2025-22866 reported by Trivy (#​7563, @​SgtCoDFish

v1.17.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.17.0 is a feature release with several improvements, including:

  • A helpful compliance change to RSA signatures on certificates
  • An easier way to specify passwords for PKCS#12 and JKS keystores
  • A few feature flag promotions (and a deprecation)
  • Dependency bumps and other smaller improvements

Major Themes

RSA Certificate Compliance

The United States Department of Defense published a memo in 2022 which introduced some requirements on the kinds of cryptography they require to be supported in software they use.

In effect, the memo requires that software be able to support larger RSA keys (3072-bit and 4096-bit) and hashing algorithms (SHA-384 at a minimum).

cert-manager supported large RSA keys long before the memo was published, but a quirk in implementation meant that cert-manager always used SHA-256 when signing with RSA.

In v1.17.0, cert-manager will choose a hash algorithm based on the RSA key length: 3072-bit keys will use SHA-384, and 4096-bit keys will use SHA-512. This matches similar behavior already present for ECDSA signatures.

Our expectation is that this change will have minimal impact beyond a slight increase to security and better compliance; we're not aware of Kubernetes based environments which support RSA 2048 with SHA-256 but fail with RSA 4096 and SHA-512. However, if you're using larger RSA keys, you should be aware of the change.

Easier Keystore Passwords for PKCS#12 and JKS

Specifying passwords on PKCS#12 and JKS keystores is supported in cert-manager
for compatibility reasons with software which expects or requires passwords to be set; however, these passwords are not relevant to security and never have been in cert-manager.

The initial implementation of the keystores feature required these "passwords" to be stored in a Kubernetes secret, which would then be read by cert-manager when creating the keystore after a certificate was issued. This is cumbersome, especially when many passwords are set to default values such as changeit or password.

In cert-manager v1.17, it's now possible to set a keystore password using a literal string value inside the Certificate resource itself, making this process much easier with no change to security.

For example:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: my-cert-password
spec:
  secretName: my-cert-password
  issuerRef:
    name: my-issuer
    kind: ClusterIssuer
  keystores:
    jks:
      create: true
      password: "abc123"
    pkcs12:
      create: true
      password: "password"
  dnsNames:
  - example.com

The new password field is mutually exclusive with the passwordSecretRef field, so be sure to only set one.

Feature Flag Promotions / Deprecations

cert-manager's feature flags allow for easier testing and adoption of new features with a reduced risk of breaking changes. In cert-manager v1.17, two feature gates have been promoted to "beta", and as such are now enabled by default in all installations:

  • NameConstraints, allowing users to specify the name constraints extension which can be helpful when creating CA certificates for private PKI
  • UseDomainQualifiedFinalizer, which stops a Kubernetes warning from being printed in logs

In addition, we added a new feature gate: CAInjectorMerging, which intelligently combines certificates used by the CAInjector component, making it safer to use when issuing certificates are rotated. If you're making heavy use of the CA injector, you should consider enabling this feature gate.

Finally, we deprecated the ValidateCAA feature gate which will be removed entirely in cert-manager v1.18.0. This feature gate aimed to validate the CAA DNS record during ACME issuance, but has seen low adoption and limited testing since its introduction back in 2019.

Other Changes

There are many other PRs which were merged in this release cycle and we'd encourage you to read the release notes below. One PR that's worth highlighting is a change to add more structured logging information to certain log lines.

If you were previously filtering logs using grep or similar tools (which is highly discouraged!) be aware that some log lines have changed format.

Community

As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.

A special thanks to:

for their contributions, comments and support!

Also, thanks to the cert-manager maintainer team for their help in this release:

And finally, thanks to the cert-manager steering committee for their feedback in this release cycle:

Changes by Kind

Feature
  • Potentially BREAKING: The CA and SelfSigned issuers now use SHA-512 when signing with RSA keys 4096 bits and above, and SHA-384 when signing with RSA keys 3072 bits and above. If you were previously using a larger RSA key as a CA, be sure to check that your systems support the new hash algorithms. (#​7368, @​SgtCoDFish)
  • Add CAInjectorMerging feature gate to the ca-injector, enabling this will change the behaviour of the ca-injector to merge in new CA certificates instead of outright replacing the existing one. (#​7469, @​ThatsMrTalbot)
  • Added image pull secrets to deployments when service accounts aren't created (#​7411, @​TheHenrick)
  • Added the ability to customize client ID when using username/password authentication for Venafi client (#​7484, @​ilyesAj)
  • Helm: New value webhook.extraEnv allows you to set custom environment variables in the webhook Pod.
    Helm: New value cainjector.extraEnv allows you to set custom environment variables in the cainjector Pod.
    Helm: New value startupapicheck.extraEnv allows you to set custom environment variables in the startupapicheck Pod. (#​7317, @​wallrj)
  • Increase the amount of PEM data pki.DecodeX509CertificateSetBytes is able to parse, to enable reading larger TLS trust bundles (#​7464, @​SgtCoDFish)
  • New configuration option tenantID for the AzureDNS provider when using managed identities with service principals. This enhancement allows users to specify the tenant ID when using managed identities, offering better flexibility in multi-tenant environments. (#​7376, @​jochenrichter)
  • Promote the UseDomainQualifiedFinalizer feature to Beta. (#​7488, @​jsoref)
  • Allow JKS/PKCS12 keystore passwords to be set as literal values in Certificate resources, mutually exclusive with the existing passwordSecretRef field (#​6657, @​rquinio1A)
  • Allow templating ServiceAccount annotations by running the built-in Helm tpl function on keys and values, to aid with workload identity configuration (#​7501, @​fcrespofastly)
  • Promote CA NameConstraints feature gate to Beta (enabled by default) (#​7494, @​tanujd11)
Documentation
Bug or Regression
  • BUGFIX: A change in v1.16.0 caused cert-manager's ACME ClusterIssuer to look in the wrong namespace for resources required for the issuance (eg. credential Secrets). This is now fixed in v1.16.1+ and v1.17.0+ (#​7339, @​inteon)
  • BUGFIX: Helm will now accept percentages for the podDisruptionBudget.minAvailable and podDisruptionBudget.maxAvailable values. (#​7343, @​inteon)
  • Fix ACME HTTP-01 solver for IPv6 endpoints (#​7391, @​Peac36)
  • Fix the behavior of renewBeforePercentage to comply with its spec (#​7421, @​adam-sroka)
  • Helm: allow enabled to be set as a value to toggle cert-manager as a dependency. (#​7350, @​inteon)
  • SECURITY (low risk): Limit maximum allowed PEM size to prevent potential DoS in cert-manager controller from attacker-controlled PEM. See GHSA-r4pg-vg54-wxx4 (#​7400, @​SgtCoDFish)
  • The Certificate object will no longer create CertificateRequest or Secret objects while being deleted (#​7361, @​ThatsMrTalbot)
  • The issuer will now more quickly retry when its linked Secret is updated to fix an issue that caused a high back-off timeout. (#​7455, @​inteon)
  • Upgrades Venafi vCert library fixing a bug which caused the RSA 3072 bit key size for TPP certificate enrollment to not work. (#​7498, @​inteon)
Other (Cleanup or Flake)
  • ⚠️ Potentially BREAKING: Log messages that were not structured have now been replaced with structured logs. If you were matching on specific log strings, this could break your setup. (#​7461, @​inteon)
  • DEPRECATION: The ValidateCAA feature gate is now deprecated, with removal scheduled for cert-manager 1.18. In 1.17, enabling this feature gate will print a warning. (#​7491, @​jsoref)
  • Remove Neither --kubeconfig nor --master was specified warning message when the controller and the webhook services boot (#​7457, @​Peac36)
  • Move 'live' DNS tests into a separate package to contain test flakiness and improve developer UX (#​7530, @​SgtCoDFish)

v1.16.5

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23 and includes various dependency updates.

📖 Read the full cert-manager 1.16 release notes, before installing or upgrading.

Changes since v1.16.4:

Bug or Regression

v1.16.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This release is primarily intended to address a breaking change in Cloudflare's API which impacted ACME DNS-01 challenges using Cloudflare.

Many thanks to the community members who reported this issue!

Changes by Kind

Bug or Regression

v1.16.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.16.3 is a patch release mainly focused around bumping dependencies to address reported CVEs: CVE-2024-45337 and CVE-2024-45338.

We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners.

It also includes a bug fix to the new renewBeforePercentage field. If you were using renewBeforePercentage, see PR #​7421 for more information.

Changes

Bug
Other

v1.16.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release of cert-manager 1.16 makes several changes to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed.

This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project.

The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods.

Note also that since most PEM data parsed by cert-manager comes from ConfigMap or Secret resources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data.

Further information is available in https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4

In addition, the version of Go used to build cert-manager 1.16 was updated along with the base images.

Changes by Kind

Bug or Regression
  • Set a maximum size for PEM inputs which cert-manager will accept to remove possibility of taking a long time to process an input (#​7401, @​SgtCoDFish)
Other (Cleanup or Flake)

v1.16.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer.

📖 Read the complete 1.16 release notes before upgrading.

📜Changes since v1.16.0

Bug or Regression
  • BUGFIX: Helm schema validation: the new schema validation was too strict for the "global" section. Since the global section is shared across all charts and sub-charts, we must also allow unknown fields. (#​7348, @inteon)
  • BUGFIX: Helm will now accept percentages for the podDisruptionBudget.minAvailable and podDisruptionBudget.maxAvailable values. (#​7345, @inteon)
  • Helm: allow enabled to be set as a value to toggle cert-manager as a dependency. (#​7356, @inteon)
  • BUGFIX: A change in v1.16.0 caused cert-manager's ACME ClusterIssuer to look in the wrong namespace for resources required for the issuance (e.g. credential Secrets). This is now fixed in v1.16.1. (#​7342, @inteon)

v1.16.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer.

📖 Read the complete 1.16 release notes at cert-manager.io.

⚠️ Known issues

  1. Helm Chart: JSON schema prevents the chart being used as a sub-chart on Rancher RKE.
  2. ACME DNS01 ClusterIssuer fail while loading credentials from Secret resources.

❗ Breaking changes

  1. Helm schema validation may reject your existing Helm values files if they contain typos or unrecognized fields.
  2. Venafi Issuer may fail to renew certificates if the requested duration conflicts with the CA’s minimum or maximum policy settings in Venafi.
  3. Venafi Issuer may fail to renew Certificates if the issuer has been configured for TPP with username-password authentication.

📖 Read the complete 1.16 release notes at cert-manager.io.

📜 Changes since v1.15.0

📖 Read the complete 1.16 release notes at cert-manager.io.

Feature
  • Add SecretRef support for Venafi TPP issuer CA Bundle (#​7036, @sankalp-at-gh)
  • Add renewBeforePercentage alternative to renewBefore (#​6987, @cbroglie)
  • Add a metrics server to the cainjector (#​7194, @wallrj)
  • Add a metrics server to the webhook (#​7182, @wallrj)
  • Add client certificate auth method for Vault issuer (#​4330, @joshmue)
  • Add process and go runtime metrics for controller (#​6966, @mindw)
  • Added app.kubernetes.io/managed-by: cert-manager label to the cert-manager-webhook-ca Secret (#​7154, @jrcichra)
  • Allow the user to specify a Pod template when using GatewayAPI HTTP01 solver, this mirrors the behavior when using the Ingress HTTP01 solver. (#​7211, @ThatsMrTalbot)
  • Create token request RBAC for the cert-manager ServiceAccount by default (#​7213, @Jasper-Ben)
  • Feature: Append cert-manager user-agent string to all AWS API requests, including IMDS and STS requests. (#​7295, @wallrj)
  • Feature: Log AWS SDK warnings and API requests at cert-manager debug level to help debug AWS Route53 problems in the field. (#​7292, @wallrj)
  • Feature: The Route53 DNS solver of the ACME Issuer will now use regional STS endpoints computed from the region that is supplied in the Issuer spec or in the AWS_REGION environment variable.
    Feature: The Route53 DNS solver of the ACME Issuer now uses the "ambient" region (AWS_REGION or AWS_DEFAULT_REGION) if issuer.spec.acme.solvers.dns01.route53.region is empty; regardless of the flags --issuer-ambient-credentials and --cluster-issuer-ambient-credentials. (#​7299, @wallrj)
  • Helm: adds JSON schema validation for the Helm values. (#​7069, @inteon)
  • If the --controllers flag only specifies disabled controllers, the default controllers are now enabled implicitly.
    Added disableAutoApproval and approveSignerNames Helm chart options. (#​7049, @inteon)
  • Make it easier to configure cert-manager using Helm by defaulting config.apiVersion and config.kind within the Helm chart. (#​7126, @ThatsMrTalbot)
  • Now passes down specified duration to Venafi client instead of using the CA default only. (#​7104, @Guitarkalle)
  • Reduce the memory usage of cainjector, by only caching the metadata of Secret resources.
    Reduce the load on the K8S API server when cainjector starts up, by only listing the metadata of Secret resources. (#​7161, @wallrj)
  • The Route53 DNS01 solver of the ACME Issuer can now detect the AWS region from the AWS_REGION and AWS_DEFAULT_REGION environment variables, which is set by the IAM for Service Accounts (IRSA) webhook and by the Pod Identity webhook.
    The issuer.spec.acme.solvers.dns01.route53.region field is now optional.
    The API documentation of the region field has been updated to explain when and how the region value is used. (#​7287, @wallrj)
  • Venafi TPP issuer can now be used with a username & password combination with OAuth. Fixes #​4653.
    Breaking: cert-manager will no longer use the API Key authentication method which was deprecated in 20.2 and since removed in 24.1 of TPP. (#​7084, @hawksight)
  • You can now configure the pod security context of HTTP-01 solver pods. (#​5373, @aidy)
  • Helm: New value webhook.extraEnv, allows you to set custom environment variables in the webhook Pod.
    Helm: New value cainjector.extraEnv, allows you to set custom environment variables in the cainjector Pod.
    Helm: New value startupapicheck.extraEnv, allows you to set custom environment variables in the startupapicheck Pod. (#​7319, @wallrj)
Bug or Regression
  • Adds support (behind a flag) to use a domain qualified finalizer. If the feature is enabled (which is not by default), it should prevent Kubernetes from reporting: metadata.finalizers: "finalizer.acme.cert-manager.io": prefer a domain-qualified finalizer name to avoid accidental conflicts with other finalizer writers (#​7273, @jsoref)
  • BUGFIX Route53: explicitly set the aws-global STS region which is now required by the github.com/aws/aws-sdk-go-v2 library. (#​7108, @inteon)
  • BUGFIX: fix issue that caused Vault issuer to not retry signing when an error was encountered. (#​7105, @inteon)
  • BUGFIX: the dynamic certificate source used by the webhook TLS server failed to detect a root CA approaching expiration, due to a calculation error. This will cause the webhook TLS server to fail renewing its CA certificate. Please upgrade before the expiration of this CA certificate is reached. (#​7230, @inteon)
  • Bugfix: Prevent aggressive Route53 retries caused by IRSA authentication failures by removing the Amazon Request ID from errors wrapped by the default credential cache. (#​7291, @wallrj)
  • Bugfix: Prevent aggressive Route53 retries caused by STS authentication failures by removing the Amazon Request ID from STS errors. (#​7259, @wallrj)
  • Bump grpc-go to fix GHSA-xr7q-jx4m-x55m (#​7164, @SgtCoDFish)
  • Bump the go-retryablehttp dependency to fix CVE-2024-6104 (#​7125, @SgtCoDFish)
  • Fix Azure DNS causing panics whenever authentication error happens (#​7177, @eplightning)
  • Fix incorrect indentation of endpointAdditionalProperties in the PodMonitor template of the Helm chart (#​7190, @wallrj)
  • Fixes ACME HTTP01 challenge behavior when using Gateway API to prevent unbounded creation of HTTPRoute resources (#​7178, @miguelvr)
  • Handle errors arising from challenges missing from the ACME server (#​7202, @bdols)
  • Helm BUGFIX: the cainjector ConfigMap was not mounted in the cainjector deployment. (#​7052, @inteon)
  • Improve the startupapicheck: validate that the validating and mutating webhooks are doing their job. (#​7057, @inteon)
  • The KeyUsages X.509 extension is no longer added when there are no key usages set (in accordance to RFC 5280 Section 4.2.1.3) (#​7250, @inteon)
  • Update github.com/Azure/azure-sdk-for-go/sdk/azidentity to address CVE-2024-35255 (#​7087, @dependabot[bot])
Other (Cleanup or Flake)
  • Old API versions were removed from the codebase.
    Removed:
    (acme.)cert-manager.io/v1alpha2
    (acme.)cert-manager.io/v1alpha3
    (acme.)cert-manager.io/v1beta1 (#​7278, @inteon)
  • Upgrading to client-go v0.31.0 removes a lot of noisy reflector.go: unable to sync list result: internal error: cannot cast object DeletedFinalStateUnknown errors from logs. (#​7237, @inteon)
  • Bump Go to v1.23.2 (#​7324, @cert-manager-bot)

v1.15.5

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager v1.15.5 contains simple dependency bumps to address reported CVEs (CVE-2024-45337 and CVE-2024-45338).

We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners.

Changes

Bug or Regression
  • Bump golang.org/x/net to address CVE-2024-45337 and CVE-2024-45338 (#​7496, @​wallrj)
Other (Cleanup or Flake)

v1.15.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

This patch release of cert-manager 1.15 makes several changes to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed.

This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project.

The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods.

Note also that since most PEM data parsed by cert-manager comes from ConfigMap or Secret resources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data.

Further information is available in https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4

In addition, the version of Go used to build cert-manager 1.15 was updated along with the base images, and a Route53 bug fix was backported.

Changes by Kind

Bug or Regression
  • Bugfix: Prevent aggressive Route53 retries caused by STS authentication failures by removing the Amazon Request ID from STS errors. (#​7261, @​cert-manager-bot)
  • Set a maximum size for PEM inputs which cert-manager will accept to remove possibility of taking a long time to process an input (#​7402, @​SgtCoDFish)
Other (Cleanup or Flake)

v1.15.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

🔗 See v1.15.0 for more information about cert-manager 1.15 and read-before-upgrade info.

📜 Changes since v1.15.2

Bug or Regression
  • BUGFIX: the dynamic certificate source used by the webhook TLS server failed to detect a root CA approaching expiration, due to a calculation error. This will cause the webhook TLS server to fail renewing its CA certificate. Please upgrade before the expiration of this CA certificate is reached. (#​7232, @​cert-manager-bot)

v1.15.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

🔗 See v1.15.0 for more information about cert-manager 1.15 and read-before-upgrade info.

📜 Changes since v1.15.1

Bug or Regression

v1.15.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

🔗 See v1.15.0 for more information about cert-manager 1.15 and read-before-upgrade info.

📜 Changes since v1.15.0

Bug or Regression
  • BUGFIX: fix issue that caused Vault issuer to not retry signing when an error was encountered. (#​7111, @​inteon)
Other (Cleanup or Flake)

v1.15.0

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.15 promotes several features to beta, including GatewayAPI support (ExperimentalGatewayAPISupport), the ability to provide a subject in the Certificate that will be used literally in the CertificateSigningRequest (LiteralCertificateSubject) and the outputting of additional certificate formats (AdditionalCertificateOutputFormats).

[!NOTE]

The cmctl binary have been moved to https://github.com/cert-manager/cmctl/releases.
For the startupapicheck Job you should update references to point at quay.io/jetstack/cert-manager-startupapicheck

[!NOTE]

From this release, the Helm chart will no longer uninstall the CRDs when the chart is uninstalled. If you want the CRDs to be removed on uninstall use crds.keep=false when installing the Helm chart.

Community

Thanks again to all open-source contributors with commits in this release, including: @​Pionerd, @​SgtCoDFish, @​ThatsMrTalbot, @​andrey-dubnik, @​bwaldrep, @​eplightning, @​erikgb, @​findnature, @​gplessis, @​import-shiburin, @​inteon, @​jkroepke, @​lunarwhite, @​mangeshhambarde, @​pwhitehead-splunk & @​rodrigorfk, @​wallrj.

Thanks also to the following cert-manager maintainers for their contributions during this release: @​SgtCoDFish, @​SpectralHiss, @​ThatsMrTalbot, @​hawksight, @​inteon, @​maelvls & @​wallrj.

Equally thanks to everyone who provided feedback, helped users and raised issues on GitHub and Slack and joined our meetings!

Thanks also to the CNCF, which provides resources and support, and to the AWS open source team for being good community members and for their maintenance of the PrivateCA Issuer.

In addition, massive thanks to Venafi for contributing developer time and resources towards the continued maintenance of cert-manager projects.

Changes by Kind

Feature
  • GatewayAPI support has graduated to Beta. Add the --enable-gateway-api flag to enable the integration. (#​6961, @​ThatsMrTalbot)
  • Add support to specify a custom key alias in a JKS Keystore (#​6807, @​bwaldrep)
  • Add the ability to communicate with Vault via mTLS when strict client certificates is enabled at Vault server side (#​6614, @​rodrigorfk)
  • Added option to provide additional audiences in the service account auth section for vault (#​6718, @​andrey-dubnik)
  • Venafi Issuer now sends a cert-manager HTTP User-Agent header in all Venafi Rest API requests.
    For example: cert-manager-certificaterequests-issuer-venafi/v1.15.0+(linux/amd64)+cert-manager/ef068a59008f6ed919b98a7177921ddc9e297200. (#​6865, @​wallrj)
  • Add hint to validation error message to help users of external issuers more easily fix the issue if they specify a Kind but forget the Group (#​6913, @​SgtCoDFish)
  • Add support for numeric OID types in LiteralSubject. Eg. "1.2.3.4=String Value" (#​6775, @​inteon)
  • Promote the LiteralCertificateSubject feature to Beta. (#​7030, @​inteon)
  • Promoted the AdditionalCertificateOutputFormats feature gate to Beta (enabled by default). (#​6970, @​erikgb)
  • The Helm chart now allows you to supply extraObjects; a list of yaml manifests which will helm will install and uninstall with the cert-manager manifests. (#​6424, @​gplessis)
  • Update the Route53 provider to support fetching credentials using AssumeRoleWithWebIdentity (#​6878, @​pwhitehead-splunk)
  • Helm can now add optional hostAliases to cert-manager Pod to allow the DNS self-check to pass in custom scenarios. (#​6456, @​Pionerd)
  • Added a new Ingress annotation for copying specific Ingress annotations to Certificate's secretTemplate (#​6839, @​mangeshhambarde)
  • Added option to define additional token audiences for the Vault Kubernetes auth (#​6744, @​andrey-dubnik)
  • Allow cert-manager.io/allow-direct-injection in annotations (#​6801, @​jkroepke)
Design
Bug or Regression
  • BUGFIX: Fixes issue with JSON-logging, where only a subset of the log messages were output as JSON. (#​6779, @​inteon)
  • BUGFIX: JKS and PKCS12 stores now contain the full set of CAs specified by an issuer (#​6806, @​bwaldrep)
  • BUGFIX: cainjector leaderelection flag/config option defaults are missing (#​6816, @​inteon)
  • BUGFIX: cert-manager issuers incorrectly copied the critical flag from the CSR instead of re-calculating that field themselves. (#​6724, @​inteon)
  • Breaking Change: Fixed unintended certificate chain is used if preferredChain is configured. (#​6755, @​import-shiburin)
  • Bugfix: LiteralSubjects with a #= value can result in memory issues due to faulty BER parser (github.com/go-asn1-ber/asn1-ber). (#​6770, @​inteon)
  • DigitalOcean: Ensure that only TXT records are considered for deletion when cleaning up after an ACME challenge (#​6875, @​SgtCoDFish)
  • Fix backwards incompatible removal of default prometheus Service resource. (#​6699, @​inteon)
  • Fix broken cainjector image value in Helm chart (#​6692, @​SgtCoDFish)
  • Helm: Fix a bug in the logic that differentiates between 0 and an empty value. (#​6713, @​inteon)
  • Make sure the Azure SDK error messages are stable. (#​6676, @​inteon)
  • When using the literalSubject on a Certificate, the webhook validation for the common name now also points to the literalSubject. (#​6767, @​lunarwhite)
  • Bump golang.org/x/net to fix CVE-2023-45288 (#​6929, @​SgtCoDFish)
  • Fix ACME issuer being stuck waiting for DNS propagation when using Azure DNS with multiple instances issuing for the same FQDN (#​6351, @​eplightning)
  • Fix cainjector ConfigMap not mounted in the cainjector deployment. (#​7055, @​inteon)
  • Added disableAutoApproval and approveSignerNames Helm chart options. (#​7054, @​inteon)
Other (Cleanup or Flake)
  • ⚠️ Possibly breaking: Helm will now keep the CRDs when you uninstall cert-manager by default to prevent accidental data loss. (#​6760, @​inteon)
  • New crds.keep and crds.enabled Helm options can now be used instead of the installCRDs option. (#​6760, @​inteon)
  • Bump base images (#​6840, @​inteon)
  • Bump github.com/go-jose/go-jose to v3.0.3 to fix CVE-2024-28180 (#​6854, @​wallrj)
  • Removed deprecated util functions that have been replaced by the slices and k8s.io/apimachinery/pkg/util packages.
    Removed deprecated CSR functions which have been replaced with other functions in the pkg/util/pki package. (#​6730, @​inteon)
  • Upgrade go to 1.21.8: fixes CVE-2024-24783 (#​6823, @​inteon)
  • Upgrade go to latest version 1.22.1 (#​6831, @​inteon)
  • Upgrade google.golang.org/protobuf: fixing GO-2024-2611 (#​6827, @​inteon)
  • cmctl and kubectl cert-manger have been moved to the https://github.com/cert-manager/cmctl repo and will be versioned separately starting with cmctl v2.0.0 (#​6663, @​inteon)
  • Graduate the 'DisallowInsecureCSRUsageDefinition' feature gate to GA. (part 2) (#​6963, @​inteon)
  • Remove deprecated pkg/util/pki/ParseSubjectStringToRawDERBytes function. (#​6994, @​inteon)
  • Upgrade Kind to v0.23.0 and update supported node image digests (#​7020, @​github-actions[bot])
  • If the --controllers flag only specifies disabled controllers, the default controllers are now enabled implicitly. (#​7054, @​inteon)
  • Upgrade to Go 1.22.3, fixing GO-2024-2824. (#​6996, @​github-actions[bot])

v1.14.7

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

📜 Changes since v1.14.6

Bugfixes
Other (Cleanup or Flake)

v1.14.6

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

📜 Changes since v1.14.5

Other (Cleanup or Flake)

v1.14.5

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

v1.14.5 fixes a bug in the DigitalOcean DNS-01 provider which could cause incorrect DNS records to be deleted when using a domain with a CNAME. Special thanks to @​BobyMCbobs for reporting this issue and testing the fix!

It also patches CVE-2023-45288.

📜 Changes since v1.14.4

  • ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see 1.14 release notes for more information.

Changes

Bug or Regression

v1.14.4

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.

⚠️ Known Issues
  • ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see release docs for more info and mitigations
ℹ️ Documentation

Release notes
Upgrade notes
Installation instructions

🔧 Breaking changes

See Breaking changes in v1.14.0 release notes

📜 Changes since v1.14.3
Bug or Regression
Other (Cleanup or Flake)

v1.14.3

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.

⚠️ Known Issues
  • ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see release docs for more info and mitigations
  • cainjector leaderelection is incorrectly disabled by default because the flag/ config option defaults are missing (#​6819)
ℹ️ Documentation

Release notes
Upgrade notes
Installation instructions

🔧 Breaking changes

See Breaking changes in v1.14.0 release notes

📜 Changes since v1.14.2
Bug or Regression
  • BUGFIX: Fixes issue with JSON-logging, where only a subset of the log messages were output as JSON. (#​6781, @​jetstack-bot)
  • BUGFIX: LiteralSubjects with a #= value can result in memory issues due to faulty BER parser (github.com/go-asn1-ber/asn1-ber). (#​6774, @​jetstack-bot)

v1.14.2

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.

⚠️ Known Issues
  • ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see release docs for more info and mitigations
  • Logging-format json sometimes writes plaintext messages (see #​6768). FIXED in v1.14.3
ℹ️ Documentation

Release notes
Upgrade notes
Installation instructions

🔧 Breaking changes

See Breaking changes in v1.14.0 release notes

📜 Changes since v1.14.1
Bug or Regression
  • BUGFIX: cert-manager CA and SelfSigned issuers incorrectly copied the critical flag from the CSR instead of re-calculating that field themselves. (#​6727, @​jetstack-bot)
  • Helm: Fix a bug in the logic that differentiates between 0 and an empty value. (#​6729, @​jetstack-bot)
Other (Cleanup or Flake)

v1.14.1

Compare Source

cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.

cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.

⚠️ This version has known issues. Please install v1.14.2 instead.

⚠️ Known Issues (please install v1.14.2)
  • ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see release docs for more info and mitigations
  • In cert-manager v1.14.0 and v1.14.1, the CA and SelfSigned issuers issue certificates with SANs set to non-critical even when the subject is empty. It incorrectly copies the critical field from the CSR.
🔧 Breaking changes

See Breaking changes in v1.14.0 release notes

ℹ️ Documentation
📜 Changes since v1.14.0
Bug or Regression
  • Fix broken cainjector image value in Helm chart (#​6693, @​SgtCoDFish)
  • Fix bug in cmctl namespace detection which prevented it being used as a startupapicheck image in namespaces other than cert-manager. (#​6706, @​inteon)
  • Fix bug in cmctl which caused cmctl experimental install to panic. (#​6706, @​inteon)
gitea/helm-gitea (gitea)

v12.7.0

Compare Source

Features
Maintenance
go-gitea/gitea (gitea/gitea)

v1.27.3

Compare Source

v1.27.2

Compare Source

v1.27.1

Compare Source

v1.27.0

Compare Source

  • BREAKING

    • Feat(actions)!: improve support for reusable workflows (#​37478)
    • Use Content-Security-Policy: script nonce (#​37232)
  • SECURITY

    • Fix: various security fixes (#​38406) (#​38426)
    • Fix(security): harden access checks and migration validation (#​38324) (#​38400)
    • Fix: enforce public-only token scope and harden push options / locale parsing (#​38323) (#​38399)
    • Fix(pull): re-evaluate review official flag on target branch change (#​38319) (#​38402)
    • Fix(api): stop leaking private repo metadata after access revocation (#​38321) (#​38390)
    • Fix(lfs): require proof of possession for cross-repo objects (#​38322) (#​38389)
    • Fix(mirror): disable HTTP redirects on pull mirror sync (#​38320) (#​38367)
    • Fix(release): validate web attachment renames against allowed types (#​38314) (#​38328)
    • Fix(release): gate draft release attachments on web download endpoints (#​38318) (#​38325)
    • Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 [security] (#​37786)
    • Fix(oauth): restrict introspection to the token's client (#​38042)
    • Fix(api): don't expose private org membership via public_members (#​38145)
    • Fix(actions): deny fork-PR cross-repo access via collaborative owner (#​38214)
    • Fix(migrations): prevent path traversal in repository restore (#​38215)
    • Feat(security): set X-Content-Type-Options: nosniff by default (#​37354)
  • FEATURES

    • Feat(actions): add workflow status badge modal (#​38196)
    • Feat(actions): support owner-level and global scoped workflows (#​38154)
    • Feat(api): support ref suffixes in compare (#​38148)
    • Feat(actions): implement jobs.<job_id>.continue-on-error (#​38100)
    • Feat(actions): show run status on browser tab favicon (#​38071)
    • Feat(api): add token introspection and self-deletion endpoint (#​37995)
    • Feat(repo): split repository creation limit into user and org scopes (#​37872)
    • Feat(actions): bulk delete, disable and enable runners in admin UI (#​37869)
    • Feat(actions): List workflows that were executed once but got removed from the default branch (#​37835)
    • Feat(org): add team visibility so org members can discover teams (#​37680)
    • Feat: add raw diff/patch endpoint for repository comparisons (#​37632)
    • Feat(oauth): Support AWS Cognito OAuth2 provider (#​37607)
    • Feat: Add avatar stacks (#​37594)
    • Feat(actions): add job summaries (GITHUB_STEP_SUMMARY) (#​37500)
    • Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support (#​37433)
    • Support for Custom URI Schemes in OAuth2 Redirect URIs (#​37356)
    • Feat(orgs): Add search bar for organization members tab page (#​37347)
    • Feat(api): Add assignees APIs (#​37330)
    • Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow_id}/runs (#​37196)
    • Introduce ActionRunAttempt to represent each execution of a run (#​37119)
    • Serve OpenAPI 3.0 spec at /openapi.v1.json (#​37038)
    • Add project column picker to issue and pull request sidebar (#​37037)
    • Allow multiple projects per issue and pull requests (#​36784)
    • Add bulk repository deletion for organizations (#​36763)
    • Add API endpoint to reply to pull request review comments (#​36683)
    • Feat: Add bypass allowlist for branch protection (#​36514)
    • Feat(ui): add "follow rename" to file commit history list (#​34994)
    • Feat(ssh): auto generate additional ssh keys (#​33974)
  • ENHANCEMENTS

    • Enhance(actions): only create filtered-out workflow commit status for required contexts (#​38371) (#​38385)
    • Enhance: allow builtin default git config options to be overridden (#​38172)
    • Enhance: allow MathML core elements (#​38034)
    • Feat(api): add q parameter to list branches API for server-side filtering (#​37982)
    • Enhance(markup): improve issue title rendering (#​37908)
    • Enhance(actions): set descriptive browser tab title on run view (#​37870)
    • Enhance(actions): show workflow name from YAML instead of filename (#​37833)
    • Feat(actions): add before/after to PR synchronize event payload (#​37827)
    • Enhance(actions): add branch filters to run list (#​37826)
    • Enhance(actions): Make Summary UI more beautiful with more infos (#​37824)
    • Feat: add copy button to action step header, improve other copy buttons (#​37744)
    • Feat(web): also display PR counts in repo list (#​37739)
    • Fix(icon): use repo-forked icon to display forks count (#​37731)
    • Feat(api): add sort and order query parameters to job list endpoints (#​37672)
    • Feat(api): add last_sync to repository API (#​37566)
    • Enhance: Adjust Workflow Graph styling (#​37497)
    • Improve code editor text selection and clean up lint enablement (#​37474)
    • Add mirror auth updates to repo edit API and settings (#​37468)
    • Feat: Add default PR branch update style setting (#​37410)
    • Fix inconsistent disabled styling on logged-out repo header buttons (#​37406)
    • Allow fast-forward-only merge when signed commits are required (#​37335)
    • Enhance styling in actions page (#​37323)
    • Add ExternalIDClaim option for OAuth2 OIDC auth source (#​37229)
    • Fix: improve actions status icons and texts (#​37206)
    • Make Markdown fenced code block work with more syntaxes (#​37154)
    • Fix: Sort action run jobs by JobID and Name with matrix examples (#​37046)
    • Add pagination and search box to org teams list (#​37245)
    • Workflow Artifact Info Hover (#​37100)
    • Feat(editor): broaden language detection in web code editor (#​37619)
  • PERFORMANCE

    • Perf(actions): debounce runner heartbeat writes and throttle task picks (#​38281) (#​38368)
    • Perf(web): sort the action_run query by a repo-scoped index when possible (#​38155)
    • Perf: Various performance regression fixes (#​38078)
    • Perf: extend action c_u index to include created_unix for faster dashboard feeds (#​38076)
    • Batch-load related data in actions run, job, and task API endpoints (#​37032)
  • BUGFIXES

    • Fix(util): reject invalid characters between time-estimate units (#​38416) (#​38423)
    • Fix: represent a deleted assignee team as a Ghost team (#​38413) (#​38419)
    • Fix(turnstile): route CAPTCHA verification through the configured proxy (#​38412) (#​38420)
    • Fix: refresh pull request merge box when the commit status is pending (#​38410) (#​38411)
    • Fix: actions task state concurrent update (#​38405) (#​38409)
    • Fix(actions): keep workflow run trailing on one row with long branch names (#​38382) (#​38403)
    • Fix(web): use locale-aware date formatting for contribution calendar tooltips (#​38398) (#​38401)
    • Fix: co-author detection (#​38392) (#​38397)
    • Fix: incorrect co-author detection on commit page (#​38386) (#​38387)
    • Fix(ui): restore commits table column widths (#​38379) (#​38383)
    • Fix: golang html template url escaping (#​38363) (#​38369)
    • Fix: minio init check (#​38355) (#​38361)
    • Fix: org project view assignee list (#​38357) (#​38360)
    • Fix(actions): release claimed task if context is cancelled during FetchTask (#​38343) (#​38347)
    • Fix(actions): make runner list pagination order deterministic (#​38313) (#​38327)
    • Fix: Improve since/until when counting commits for X-Total-Count (#​38243) (#​38304)
    • Fix(actions): prevent chevron overlap with log text when timestamps are enabled (#​38227) (#​38307)
    • Fix(workflows): branch protection status checks fail when workflow uses on: paths filter (#​38237) (#​38302)
    • Fix(oauth2): persist linkAccountData during auto-link 2FA flow (#​38274) (#​38295)
    • Fix(actions): allow Actions bot to push to protected branches (#​38284) (#​38293)
    • Fix(actions): include all aggregable run statuses in status filter (#​38280) (#​38287)
    • Fix(archiver): use serializable repo-archive queue payload (#​38273) (#​38283)
    • Fix: update npm dependencies, fix misc issues (#​38257)
    • Fix(api): respect since/until when counting commits for X-Total-Count (#​38204)
    • Fix: codemirror regressions (#​38248)
    • Fix(api): support HEAD requests on all API GET endpoints (#​38245)
    • Fix(actions): Cleanup workflow status badge code (#​38241)
    • Fix(web): Correctly align the "disabled" label on larger workflow names (#​38240)
    • Fix(actions): don't swallow HTML entities into linkified URLs (#​38239)
    • Fix(packages): accept npm "repository" and "bin" in string form (#​38236)
    • Fix(actions): fix 500 error when canceling a canceling task (#​38223)
    • Fix(deps): update module golang.org/x/image to v0.43.0 [security] (#​38219)
    • Fix(mssql): convert legacy DATETIME columns to DATETIME2 (#​38216)
    • Fix(api): deny private org member enumeration via /members (#​38213)
    • Fix(actions): ensure all waiting jobs get runners in large workflows (#​38200)
    • Fix(deps): update go dependencies (#​38194)
    • Fix(deps): update npm dependencies (#​38193)
    • Fix(cli): default must-change-password to false for bot users (#​38175)
    • Fix(actions): show run index in run view and fix summary graph height (#​38165)
    • Fix: csp (#​38162)
    • Fix(deps): update npm dependencies (#​38123)
    • Fix(mssql): expand legacy issue and comment long-text columns (#​38120)
    • Fix(packages): validate debian distribution and component names (#​38116)
    • Fix(packages): validate module version in goproxy ParsePackage (#​38104)
    • Fix(deps): update dependency esbuild to v0.28.1 [security] (#​38097)
    • Fix: git push hook post receive (#​38089)
    • Fix(ui): prevent commit status popup overflowing its row (#​38081)
    • Fix: validate gem name in rubygems parseMetadataFile (#​38061)
    • Fix: commit display name (#​38057)
    • Fix: csp regressions (#​38047)
    • Fix: api error message (#​38031)
    • Fix(deps): update npm dependencies (#​38029)
    • Fix: pgsql lint (#​38022)
    • Fix(indexer): fix assignee filters in issue search (#​38021)
    • Fix: various dropdown problems (#​38020)
    • Fix: refactor git error handling and make archive streaming handle non-existing commit id (#​38007)
    • Fix: raise git required version to 2.13 (#​37996)
    • Fix: remove "no-transfrom" from the cache-control header (#​37985)
    • Fix(deps): update module github.com/google/go-github/v87 to v88 (#​37971)
    • Fix: use committer time where ever possible as default (#​37969)
    • Fix(deps): update npm dependencies, remove nolyfill (#​37968)
    • Fix(deps): update go dependencies (#​37967)
    • Fix(pull): preserve squash message trailers and additional commit messages (#​37954)
    • Fix(deps): update module golang.org/x/image to v0.41.0 [security] (#​37904)
    • Fix: support ##[command] log prefix in action run UI (#​37882)
    • Fix(deps): update module github.com/google/go-github/v86 to v87 (#​37845)
    • Fix(deps): update npm dependencies (#​37844)
    • Fix(deps): update go dependencies (#​37841)
    • Fix(frontend): resolve Vite assets by manifest source path (#​37836)
    • Fix(locales): Replace hardcoded strings (#​37788)
    • Fix(packages): render markdown links relative to linked repo (#​37676)
    • Fix: persist mirror repository metadata (#​37519)
    • Fix cmd tests by mocking builtin paths (#​37369)
    • Add form-fetch-action to some forms, fix "fetch action" resp bug (#​37305)
    • Feat: execute post run cleanup when workflow is cancelled (#​37275)
    • Fix relative-time error and improve global error handler (#​37241)
    • Refactor flash message and remove SanitizeHTML template func (#​37179)
    • Fix Repository transferring page (#​37277)
  • TESTING

    • Test(e2e): fix race in pdf file render test (#​38380) (#​38381)
    • Test: compare key file contents instead of FileInfo in TestInitKeys (#​38330) (#​38331)
    • Test: speed up two tests (#​37905)
    • Test: Fix random failure test (#​37887)
    • Test: fix flaky issue-comment close test (#​37880)
    • Test: enable WAL for sqlite integration tests (#​37861)
    • Test: fix flaky TestResourceIndex and reduce its runtime (#​37847)
    • Test: run TestAPIRepoMigrate offline via a local clone source (#​37817)
    • Ci: shard tests and reduce redundant work (#​37618)
    • Test(e2e): run playwright via container (#​37300)
    • Remove external service dependencies in migration tests (#​36866)
    • Refactor: only reset a database table when the table's data was changed (#​37573)
  • BUILD

    • Refactor: use modernc sqlite driver as default (#​37562)
    • Fix(actions): authenticate snapcraft before nightly remote build (#​38252)
    • Ci: cap Elasticsearch heap in db-tests (#​37816)
    • Build(snap): publish nightly version to snapcraft via actions (#​37814)
    • Ci: split pgsql shards into plain jobs, dedupe setup actions (#​37802)
    • Ci: narrow files-changed frontend filter (#​37749)
    • Ci: add zizmor to lint-actions (#​37720)
    • Chore: clean up "contrib" dir (#​37690)
    • Fix: snap build (main branch) (#​37685)
    • Ci: Also lint json5 files (#​37659)
    • Build: update pnpm to v11 (#​37591)
    • Refactor(deps): migrate from nektos/act fork to gitea/runner (#​37557)
    • Update go js py dependencies (#​37525)
    • Ci: lint PR titles with commitlint (#​37498)
    • Chore: upgrade Go version in devcontainer image to 1.26 (#​37374)
    • Update GitHub Actions to latest major versions (#​37313)
    • Update go js dependencies (#​37312)
    • Fail vite build on rolldown warnings via NODE_ENV=test (#​37270)
    • Replace custom Go formatter with golangci-lint fmt (#​37194)
    • Integrate renovate bot for all dependency updates (#​37050)
    • Build(sign): move to sigstore (#​38250)
  • DOCS

    • Docs: update changelog for 1.26.3 & 1.26.4 (#​38178)
    • Update 1.26.1 changelog in main (#​37442)
    • Docs: fix duplicated word in foreachref doc comment (#​38161)
    • Docs: Clarify criteria for becoming a merger (#​38113)
    • Docs: Publish TOC Election Result 2026 (#​38111)
    • Docs: mark openapi3 as autogenerated in attributes (#​37963)
    • Docs: add development setup guide (#​37960)
  • MISC

    • Refactor: lint bare fill/stroke colors, add vars for git graph color series (#​37543)
    • Remove htmx (#​37224)
    • Refactor htmx and fetch-action related code (#​37186)
    • Revert(sign): restore gpg (#​38251)
    • Refactor: replace legacy delete-button with link-action (#​38143)
    • Refactor(actions): read runner capabilities from proto field (#​38068)
    • Refactor(api): clarify APIError message usage and fix legacy lint error (#​38012)
    • Refactor: Use db.Get[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record (#​37977)
    • Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 (#​37866)
    • Fix(deps): update go dependencies (#​37851)
    • Ci: Fix sync PR labels from the conventional-commit title (#​37784) (#​37825)
    • Ci: tweak files-changed, add free-disk-space (#​37819)
    • Fix(deps): update module golang.org/x/crypto to v0.52.0 [security] (#​37806)
    • Test(e2e): add comment, release, star, PR and fork tests (#​37800)
    • Chore: simplify issue and pull request templates (#​37799)
    • Chore: Update giteabot to fix failure when backport (#​37789)
    • Fix(api): handle partial failures in push mirror synchronization gracefully (#​37782)
    • Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 (#​37771)
    • Ci: split giteabot workflow (#​37770)
    • Fix(deps): update npm dependencies (#​37768)
    • Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go (#​37764)
    • Fix(deps): update module google.golang.org/grpc to v1.81.1 (#​37762)
    • Ci: fix cache-related issues (#​37761)
    • Chore: fix tests (#​37760)
    • Fix(deps): update module github.com/google/go-github/v85 to v86 (#​37754)
    • Fix(deps): update npm dependencies (#​37753)
    • Fix(deps): update go dependencies (#​37752)
    • Chore(deps): update action dependencies (#​37751)
    • Fix(markup): wrap indented code blocks for the code-copy button (#​37748)
    • Chore(db): introduce db.Session and db.EngineMigration interfaces (#​37746)
    • Refactor(glob): use strings.Builder for regexp compilation (#​37730)
    • Chore(doctor): remove four obsolete doctor check implementations (#​37728)
    • Refactor(org): simplify owner-team org repo creation logic (#​37727)
    • Refactor: move workflowpattern into modules/actions (#​37717)
    • Chore: clean up tests (#​37715)
    • Style: misc UI fixes (#​37691)
    • Ci: add shellcheck linter (#​37682)
    • Fix: catch and fix more lint problems (#​37674)
    • Fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test (#​37662)
    • Fix(deps): update npm dependencies (#​37647)
    • Ci(renovate): update Go import paths on major bumps (#​37641)
    • Fix(deps): update go dependencies (major) (#​37639)
    • Chore(deps): update action dependencies (major) (#​37638)
    • Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 (#​37637)
    • Fix(deps): update npm dependencies (#​37636)
    • Refactor(log): replace log.Critical with log.Error (#​37624)
    • Build(deps): bump fast-uri from 3.1.0 to 3.1.2 (#​37616)
    • Chore(deps): update action dependencies (#​37603)
    • Ci: allow chore type in PR title lint (#​37575)
    • Ci: increase renovate frequency and fix RENOVATE_ALLOWED_POST_UPGRADE_COMMANDS (#​37565)
    • Docs: fix 4 typos in CHANGELOG.md (#​37549)
    • Fix(deps): update go dependencies (#​37541)
    • Chore(deps): update action dependencies (#​37540)
    • Refactor pull request view (6) (#​37522)
    • Fix: redirect early CLI console logger to stderr (#​37507)
    • Refactor "flex-list" to "flex-divided-list" (#​37505)
    • Refactor compare diff/pull page (1) (#​37481)
    • Refactor pull request view (4) (#​37451)
    • Refactor: use named Permission field in Repository struct instead of anonymous embedding (#​37441)
    • Replace olivere/elastic with REST API client, add OpenSearch support (#​37411)
    • Refactor: serve site manifest via /assets/site-manifest.json endpoint (#​37405)
    • Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites (#​37364)
    • Update Block a user form (#​37359)
    • Move review request functions to a standalone file (#​37358)
    • Enable strict TypeScript, add errorMessage helper (#​37292)
    • Refactor frontend tw-justify-between layouts to flex-left-right (#​37291)
    • Update Nix flake (#​37284)
    • Remove SubmitEvent polyfill (#​37276)
    • Remove dead code identified by deadcode tool (#​37271)
    • Upgrade go-git to v5.18.0 (#​37268)
    • Don't add useless labels which will bother changelog generation (#​37267)
    • Move heatmap to first-party code (#​37262)
    • Tests/integration: simplify code (#​37249)
    • Remove error returns from crypto random helpers and callers (#​37240)
    • Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries (#​37210)
    • Refactor "htmx" to "fetch action" (#​37208)
    • Update go js py dependencies (#​37204)
    • Add comment for the design of "user activity time" (#​37195)
    • Remove outdated RunUser logic (#​37180)
    • Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files (#​37150)
    • Update javascript dependencies (#​37142)
    • Update go dependencies (#​37141)
    • Frontport changelog of v1.26.0-rc0 (#​37138)
    • Extend issue context popup beyond markdown content (#​36908)

v1.26.4

Compare Source

v1.26.3

Compare Source

v1.26.2

Compare Source

  • SECURITY

    • fix(permissions): Fix reading permission (#​37769)
    • fix(actions): make artifact signature payloads unambiguous (#​37707)
    • fix: Unify public-only token filtering in API queries and repo access checks (#​37118)
    • fix: Add missed token scope checking (#​37735)
    • fix(oauth): bind token exchanges to the original client request (#​37704)
    • fix(oauth): strengthen PKCE validation and refresh token replay protection (#​37706)
    • fix(web): enforce token scopes on raw, media, and attachment downloads (#​37698)
    • fix(security): enforce wiki git writes and LFS token access at request time (#​37695)
    • feat(api): encrypt AWS creds (#​37679)
    • fix(deps): update dependency mermaid to v11.15.0 [security], add e2e test
    • fix(packages): Add label for private and internal package and fix composor package source permission check (#​37610)
    • fix(git): Fix smart http request scope bug (#​37583)
    • Fix basic auth bug (#​37503)
    • Fix allow maintainer edit permission check (#​37479) (#​37484)
    • Fix URL sanitization to handle schemeless credentials (#​37440) (#​37471)
    • Fix attachment Content-Security-Policy (#​37455) (#​37464)
    • chore(deps): bump go-git/go-git/v5 to 5.19.0 (#​37608)
  • BUGFIXES

    • fix(pull): handle empty pull request files view to allow reviews (#​37783)
    • fix(markup): make RenderString never fail (#​37779)
    • fix: add natural sort to sortTreeViewNodes (#​37772)
    • fix: package creation unique conflict (#​37774)
    • fix!: add DEFAULT_TITLE_SOURCE setting for pull request title default behavior (#​37465)
    • fix: Allow direct commits for unprotected files with push restrictions (#​37657)
    • fix(actions): wrong assumption that run id always >= job id (#​37737)
    • fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register (#​37564) (#​37588)
    • fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState (#​37692)
    • fix(repo): /generate must sync the branch table for the new repo (#​37693)
    • build: Fix snap build (1.26)
    • fix(actions): run TransferLogs on UpdateLog{Rows:[], NoMore:true} (#​37631)
    • fix show correct mergebase
    • fix: make clone URL respect public URL detection setting (#​37615)
    • fix: "run as root" check (#​37622)
    • chore(deps): update dependency go to v1.26.3 (#​37601)
    • Compare dropdown fails when selecting branch with no common merge-base (#​37470)
    • fix: treat email addresses case-insensitively (#​37600)
    • fix(actions): fix blank lines after ::endgroup:: (#​37597)
    • fix(actions): report individual step status in workflow job API response (#​37592)
    • fix: Invalid UTF-8 commit messages in JSON API responses (#​37542)
    • fix: use consistent GetUser family functions (#​37553)
    • fix(api): return 409 message instead of empty JSON for wrong commit id (#​37572)
    • fix(actions): prevent panic when workflow contains null jobs (#​37570)
    • Make ServeSetHeaders default to download attachment if filename exists (#​37552) (#​37555)
    • Fix(actions): validate workflow param to prevent 500 error (#​37546) (#​37554)
    • Don't unblock run-level-concurrency-blocked runs in the resolver (#​37461) (#​37538)
    • Fix(packages): use file names for generic web downloads (#​37514) (#​37520)
    • Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once (#​37512) (#​37516)
    • Fix update branch protection order (#​37508) (#​37513)
    • Fix mCaptcha broken after Vite migration (#​37492) (#​37509)
    • Fix review submission from single-commit PR view (#​37475) (#​37485)
    • Fix scheduled action panic with null event payload (#​37459) (#​37466)
    • Make GetPossibleUserByID can handle deleted user (#​37430) (#​37431)
    • Remove excessive quote from terraform instructions (#​37424) (#​37426)
    • Fix color regressions, add priority color (#​37417) (#​37421)
  • MISC

v1.26.1

Compare Source

v1.26.0

Compare Source

  • BREAKING
    • Correct swagger annotations for enums, status codes, and notification state (#​37030)
    • Remove GET API registration-token (#​36801)
    • Support Actions concurrency syntax (#​32751)
    • Make PUBLIC_URL_DETECTION default to "auto" (#​36955)
  • SECURITY
    • Bound PageSize in ListUnadoptedRepositories (#​36884)
  • FEATURES
    • Support Actions concurrency syntax (#​32751)
    • Add terraform state registry (#​36710)
    • Instance-wide (global) info banner and maintenance mode (#​36571)
    • Support rendering OpenAPI spec (#​36449)
    • Add keyboard shortcuts for repository file and code search (#​36416)
    • Add support for archive-upload rpc (#​36391)
    • Add ability to download subpath archive (#​36371)
    • Add workflow dependencies visualization (#​26062) (#​36248) & Restyle Workflow Graph (#​36912)
    • Automatic generation of release notes (#​35977)
    • Add "Go to file", "Delete Directory" to repo file list page (#​35911)
    • Introduce "config edit-ini" sub command to help maintaining INI config file (#​35735)
    • Add button to re-run failed jobs in Actions (#​36924)
    • Support actions and reusable workflows from private repos (#​32562)
    • Add summary to action runs view (#​36883)
    • Add user badges (#​36752)
    • Add configurable permissions for Actions automatic tokens (#​36173)
    • Add per-runner "Disable/Pause" (#​36776)
    • Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) (#​36786)
  • PERFORMANCE
    • WorkflowDispatch API optionally return runid (#​36706)
    • Add render cache for SVG icons (#​36863)
    • Load mentionValues asynchronously (#​36739)
    • Lazy-load some Vue components, fix heatmap chunk loading on every page (#​36719)
    • Load heatmap data asynchronously (#​36622)
    • Use prev/next pagination for user profile activities page to speed up (#​36642)
    • Refactor cat-file batch operations and support --batch-command approach (#​35775)
    • Use merge tree to detect conflicts when possible (#​36400)
  • ENHANCEMENTS
    • Implement logout redirection for reverse proxy auth setups (#​36085) (#​37171)
    • Adds option to force update new branch in contents routes (#​35592)
    • Add viewer controller for mermaid (zoom, drag) (#​36557)
    • Add code editor setting dropdowns (#​36534)
    • Add elk layout support to mermaid (#​36486)
    • Add resolve/unresolve review comment API endpoints (#​36441)
    • Allow configuring default PR base branch (fixes #​36412) (#​36425)
    • Add support for RPM Errata (updateinfo.xml) (#​37125)
    • Require additional user confirmation for making repo private (#​36959)
    • Add actions.WORKFLOW_DIRS setting (#​36619)
    • Avoid opening new tab when downloading actions logs (#​36740)
    • Implements OIDC RP-Initiated Logout (#​36724)
    • Show workflow link (#​37070)
    • Desaturate dark theme background colors (#​37056)
    • Refactor "org teams" page and help new users to "add member" to an org (#​37051)
    • Add webhook name field to improve webhook identification (#​37025) (#​37040)
    • Make task list checkboxes clickable in the preview tab (#​37010)
    • Improve severity labels in Actions logs and tweak colors (#​36993)
    • Linkify URLs in Actions workflow logs (#​36986)
    • Allow text selection on checkbox labels (#​36970)
    • Support dark/light theme images in markdown (#​36922)
    • Enable native dark mode for swagger-ui (#​36899)
    • Rework checkbox styling, remove input border hover effect (#​36870)
    • Refactor storage content-type handling of ServeDirectURL (#​36804)
    • Use "Enable Gravatar" but not "Disable" (#​36771)
    • Use case-insensitive matching for Git error "Not a valid object name" (#​36728)
    • Add "Copy Source" to markup comment menu (#​36726)
    • Change image transparency grid to CSS (#​36711)
    • Add "Run" prefix for unnamed action steps (#​36624)
    • Persist actions log time display settings in localStorage (#​36623)
    • Use first commit title for multi-commit PRs and fix auto-focus title field (#​36606)
    • Improve BuildCaseInsensitiveLike with lowercase (#​36598)
    • Improve diff highlighting (#​36583)
    • Exclude cancelled runs from failure-only email notifications (#​36569)
    • Use full-file highlighting for diff sections (#​36561)
    • Color command/error logs in Actions log (#​36538)
    • Add paging headers (#​36521)
    • Improve timeline entries for WIP prefix changes in pull requests (#​36518)
    • Add FOLDER_ICON_THEME configuration option (#​36496)
    • Normalize guessed languages for code highlighting (#​36450)
    • Add chunked transfer encoding support for LFS uploads (#​36380)
    • Indicate when only optional checks failed (#​36367)
    • Add 'allow_maintainer_edit' API option for creating a pull request (#​36283)
    • Support closing keywords with URL references (#​36221)
    • Improve diff file headers (#​36215)
    • Fix and enhance comment editor monospace toggle (#​36181)
    • Add git.DIFF_RENAME_SIMILARITY_THRESHOLD option (#​36164)
    • Add matching pair insertion to markdown textarea (#​36121)
    • Add sorting/filtering to admin user search API endpoint (#​36112)
    • Allow action user have read permission in public repo like other user (#​36095)
    • Disable matchBrackets in monaco (#​36089)
    • Use GitHub-style commit message for squash merge (#​35987)
    • Make composer registry support tar.gz and tar.bz2 and fix bugs (#​35958)
    • Add GITEA_PR_INDEX env variable to githooks (#​35938)
    • Add proper error message if session provider can not be created (#​35520)
    • Add button to copy file name in PR files (#​35509)
    • Move X_FRAME_OPTIONS setting from cors to security section (#​30256)
    • Add placeholder content for empty content page (#​37114)
    • Add DEFAULT_DELETE_BRANCH_AFTER_MERGE setting (#​36917)
    • Redirect to the only OAuth2 provider when no other login methods and fix various problems (#​36901)
    • Add admin badge to navbar avatar (#​36790)
    • Add never option to PUBLIC_URL_DETECTION configuration (#​36785)
    • Add background and run count to actions list page (#​36707)
    • Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" (#​36654)
    • Add support for in_progress event in workflow_run webhook (#​36979)
    • Report commit status for pull_request_review events (#​36589)
    • Render merged pull request title as such in dashboard feed (#​36479)
    • Feature to be able to filter project boards by milestones (#​36321)
    • Use user id in noreply emails (#​36550)
    • Enable pagination on GiteaDownloader.getIssueReactions() (#​36549)
    • Remove striped tables in UI (#​36509)
    • Improve control char rendering and escape button styling (#​37094)
    • Support legacy run/job index-based URLs and refactor migration 326 (#​37008)
    • Add date to "No Contributions" tooltip (#​36190)
    • Show edit page confirmation dialog on tree view file change (#​36130)
    • Mention proc-receive in text for dashboard.resync_all_hooks func (#​35991)
    • Reuse selectable style for wiki (#​35990)
    • Support blue yellow colorblind theme (#​35910)
    • Support selecting theme on the footer (#​35741)
    • Improve online runner check (#​35722)
    • Add quick approve button on PR page (#​35678)
    • Enable commenting on expanded lines in PR diffs (#​35662)
    • Print PR-Title into tooltip for actions (#​35579)
    • Use explicit, stronger defaults for newly generated repo signing keys for Debian (#​36236)
    • Improve the compare page (#​36261)
    • Unify repo names in system notices (#​36491)
    • Move package settings to package instead of being tied to version (#​37026)
    • Add Actions API rerun endpoints for runs and jobs (#​36768)
    • Add branch_count to repository API (#​35351) (#​36743)
    • Add created_by filter to SearchIssues (#​36670)
    • Allow admins to rename non-local users (#​35970)
    • Support updating branch via API (#​35951)
    • Add an option to automatically verify SSH keys from LDAP (#​35927)
    • Make "update file" API can create a new file when SHA is not set (#​35738)
    • Update issue.go with labels documentation (labels content, not ids) (#​35522)
    • Expose content_version for optimistic locking on issue and PR edits (#​37035)
    • Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests (#​36982)
  • BUGFIXES
    • Frontend iframe renderer framework: 3D models, OpenAPI (#​37233) (#​37273)
    • Fix CODEOWNERS absolute path matching. (#​37244) (#​37264)
    • Swift registry metadata: preserve more JSON fields and accept empty metadata (#​37254) (#​37261)
    • Fix user ssh key exporting and tests (#​37256) (#​37258)
    • Fix team member avatar size and add tooltip (#​37253)
    • Fix commit title rendering in action run and blame (#​37243) (#​37251)
    • Fix corrupted JSON caused by goccy library (#​37214) (#​37220)
    • Add test for "fetch redirect", add CSS value validation for external render (#​37207) (#​37216)
    • Fix incorrect concurrency check (#​37205) (#​37215)
    • Fix handle missing base branch in PR commits API (#​37193) (#​37203)
    • Fix encoding for Matrix Webhooks (#​37190) (#​37201)
    • Fix handle fork-only commits in compare API (#​37185) (#​37199)
    • Indicate form field readonly via background, fix RunUser config (#​37175, #​37180) (#​37178)
    • Report structurally invalid workflows to users (#​37116) (#​37164)
    • Fix API not persisting pull request unit config when has_pull_requests is not set (#​36718)
    • Rename CSS variables and improve colorblind themes (#​36353)
    • Hide add-matcher and remove-matcher from actions job logs (#​36520)
    • Prevent navigation keys from triggering actions during IME composition (#​36540)
    • Fix vertical alignment of .commit-sign-badge children (#​36570)
    • Fix duplicate startup warnings in admin panel (#​36641)
    • Fix CODEOWNERS review request attribution using comment metadata (#​36348)
    • Fix HTML tags appearing in wiki table of contents (#​36284)
    • Fix various bugs (#​37096)
    • Fix various legacy problems (#​37092)
    • Fix RPM Registry 404 when package name contains 'package' (#​37087)
    • Merge some standalone Vite entries into index.js (#​37085)
    • Fix various problems (#​37077)
    • Fix issue label deletion with Actions tokens (#​37013)
    • Hide delete branch or tag buttons in mirror or archived repositories. (#​37006)
    • Fix org contact email not clearable once set (#​36975)
    • Fix a bug when forking a repository in an organization (#​36950)
    • Preserve sort order of exclusive labels from template repo (#​36931)
    • Make container registry support Apple Container (basic auth) (#​36920)
    • Fix the wrong push commits in the pull request when force push (#​36914)
    • Add class "list-header-filters" to the div for projects (#​36889)
    • Fix dbfs error handling (#​36844)
    • Fix incorrect viewed files counter if reverted change was viewed (#​36819)
    • Refactor avatar package, support default avatar fallback (#​36788)
    • Fix README symlink resolution in subdirectories like .github (#​36775)
    • Fix CSS stacking context issue in actions log (#​36749)
    • Add gpg signing for merge rebase and update by rebase (#​36701)
    • Delete non-exist branch should return 404 (#​36694)
    • Fix TestActionsCollaborativeOwner (#​36657)
    • Fix multi-arch Docker build SIGILL by splitting frontend stage (#​36646)
    • Fix linguist-detectable attribute being ignored for configuration files (#​36640)
    • Fix state desync in ComboMarkdownEditor (#​36625)
    • Unify DEFAULT_SHOW_FULL_NAME output in templates and dropdown (#​36597)
    • Pull Request Pusher should be the author of the merge (#​36581)
    • Fix various version parsing problems (#​36553)
    • Fix highlight diff result (#​36539)
    • Fix mirror sync parser and fix mirror messages (#​36504)
    • Fix bug when list pull request commits (#​36485)
    • Fix various bugs (#​36446)
    • Fix issue filter menu layout (#​36426)
    • Restrict branch naming when new change matches with protection rules (#​36405)
    • Fix link/origin referrer and login redirect (#​36279)
    • Generate IDs for HTML headings without id attribute (#​36233)
    • Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug (#​36160)
    • Fix issue close timeline icon (#​36138)
    • Fix diff blob excerpt expansion (#​35922)
    • Fix external render (#​35727)
    • Fix review request webhook bug (#​35339) (#​35723)
    • Fix shutdown waitgroup panic (#​35676)
    • Cleanup ActionRun creation (#​35624)
    • Fix possible bug when migrating issues/pull requests (#​33487)
    • Various fixes (#​36697)
    • Apply notify/register mail flags during install load (#​37120)
    • Repair duration display for bad stopped timestamps (#​37121)
    • Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade (#​36930)
    • Fix various trivial problems (#​36921)
    • Fix various trivial problems (#​36953)
    • Fix NuGet package upload error handling (#​37074)
    • Fix CodeQL code scanning alerts (#​36858)
    • Refactor issue sidebar and fix various problems (#​37045)
    • Fix various problems (#​37029)
    • Fix relative-time RangeError (#​37021)
    • Fix chroma lexer mapping (#​36629)
    • Fix typos and grammar in English locale (#​36751)
    • Fix milestone/project text overflow in issue sidebar (#​36741)
    • Fix no-content message not rendering after comment edit (#​36733)
    • Fix theme loading in development (#​36605)
    • Fix workflow run jobs API returning null steps (#​36603)
    • Fix timeline event layout overflow with long content (#​36595)
    • Fix minor UI issues in runner edit page (#​36590)
    • Fix incorrect vendored detections (#​36508)
    • Fix editorconfig not respected in PR Conversation view (#​36492)
    • Don't create self-references in merged PRs (#​36490)
    • Fix potential incorrect runID in run status update (#​36437)
    • Fix file-tree ui error when adding files to repo without commits (#​36312)
    • Improve image captcha contrast for dark mode (#​36265)
    • Fix panic in blame view when a file has only a single commit (#​36230)
    • Fix spelling error in migrate-storage cmd utility (#​36226)
    • Fix code highlighting on blame page (#​36157)
    • Fix nilnil in onedev downloader (#​36154)
    • Fix actions lint (#​36029)
    • Fix oauth2 session gob register (#​36017)
    • Fix Arch repo pacman.conf snippet (#​35825)
    • Fix a number of strictNullChecks-related issues (#​35795)
    • Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data (#​36861)
    • Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission (#​36384)
    • Update message severity colors, fix navbar double border (#​37019)
    • Inline and lazy-load EasyMDE CSS, fix border colors (#​36714)
    • Closed milestones with no issues now show as 100% completed (#​36220)
    • Add test for ExtendCommentTreePathLength migration and fix bugs (#​35791)
    • Only turn links to current instance into hash links (#​36237)
    • Fix typos in code comments: doesnt, dont, wont (#​36890)
  • REFACTOR
    • Clean up and improve non-gitea js error filter (#​37148) (#​37155)
    • Always show owner/repo name in compare page dropdowns (#​37172) (#​37200)
    • Remove dead CSS rules (#​37173) (#​37177)
    • Replace Monaco with CodeMirror (#​36764)
    • Replace CSRF cookie with CrossOriginProtection (#​36183)
    • Replace index with id in actions routes (#​36842)
    • Remove unnecessary function parameter (#​35765)
    • Move jobparser from act repository to Gitea (#​36699)
    • Refactor compare router param parse (#​36105)
    • Optimize 'refreshAccesses' to perform update without removing then adding (#​35702)
    • Clean up checkbox cursor styles (#​37016)
    • Remove undocumented support of signing key in the repository git configuration file (#​36143)
    • Switch cmd/ to use constructor functions. (#​36962)
    • Use relative-time to render absolute dates (#​36238)
    • Some refactors about GetMergeBase (#​36186)
    • Some small refactors (#​36163)
    • Use gitRepo as parameter instead of repopath when invoking sign functions (#​36162)
    • Move blame to gitrepo (#​36161)
    • Move some functions to gitrepo package to reduce RepoPath reference directly (#​36126)
    • Use gitrepo's clone and push when possible (#​36093)
    • Remove mermaid margin workaround (#​35732)
    • Move some functions to gitrepo package (#​35543)
    • Move GetDiverging functions to gitrepo (#​35524)
    • Use global lock instead of status pool for cron lock (#​35507)
    • Use explicit mux instead of DefaultServeMux (#​36276)
    • Use gitrepo's push function (#​36245)
    • Pass request context to generateAdditionalHeadersForIssue (#​36274)
    • Move assign project when creating pull request to the same database transaction (#​36244)
    • Move catfile batch to a sub package of git module (#​36232)
    • Use gitrepo.Repository instead of wikipath (#​35398)
    • Use experimental go json v2 library (#​35392)
    • Refactor template render (#​36438)
    • Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine (#​36434)
    • Refactor text utility classes to Tailwind CSS (#​36703)
    • Refactor git command stdio pipe (#​36422)
    • Refactor git command context & pipeline (#​36406)
    • Refactor git command stdio pipe (#​36393)
    • Remove unused functions (#​36672)
    • Refactor Actions Token Access (#​35688)
    • Move commit related functions to gitrepo package (#​35600)
    • Move archive function to repo_model and gitrepo (#​35514)
    • Move some functions to gitrepo package (#​35503)
    • Use git model to detect whether branch exist instead of gitrepo method (#​35459)
    • Some refactor for repo path (#​36251)
    • Extract helper functions from SearchIssues (#​36158)
    • Refactor merge conan and container auth preserve actions taskID (#​36560)
    • Refactor Nuget Auth to reuse Basic Auth Token Validation (#​36558)
    • Refactor ActionsTaskID (#​36503)
    • Refactor auth middleware (#​36848)
    • Refactor code render and render control chars (#​37078)
    • Clean up AppURL, remove legacy origin-url webcomponent (#​37090)
    • Remove util.URLJoin and replace all callers with direct path concatenation (#​36867)
    • Replace legacy tw-flex utility classes with flex-text-block/inline (#​36778)
    • Mark unused&immature activitypub as "not implemented" (#​36789)
  • TESTING
    • Add e2e tests for server push events (#​36879)
    • Rework e2e tests (#​36634)
    • Add e2e reaction test, improve accessibility, enable parallel testing (#​37081)
    • Increase e2e test timeouts on CI to fix flaky tests (#​37053)
  • BUILD
    • Upgrade go-git to v5.18.0 (#​37269)
    • Replace rollup-plugin-license with rolldown-license-plugin (#​37130) (#​37158)
    • Bump min go version to 1.26.2 (#​37139) (#​37143)
    • Convert locale files from ini to json format (#​35489)
    • Bump golangci-lint to 2.7.2, enable modernize stringsbuilder (#​36180)
    • Port away from flake-utils (#​35675)
    • Remove nolint (#​36252)
    • Update the Unlicense copy to latest version (#​36636)
    • Update to go 1.26.0 and golangci-lint 2.9.0 (#​36588)
    • Replace google/go-licenses with custom generation (#​36575)
    • Update go dependencies (#​36548)
    • Bump appleboy/git-push-action from 1.0.0 to 1.2.0 (#​36306)
    • Remove fomantic form module (#​36222)
    • Bump setup-node to v6, re-enable cache (#​36207)
    • Bump crowdin/github-action from 1 to 2 (#​36204)
    • Revert "Bump alpine to 3.23 (#​36185)" (#​36202)
    • Update chroma to v2.21.1 (#​36201)
    • Bump astral-sh/setup-uv from 6 to 7 (#​36198)
    • Bump docker/build-push-action from 5 to 6 (#​36197)
    • Bump aws-actions/configure-aws-credentials from 4 to 5 (#​36196)
    • Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 (#​36195)
    • Add JSON linting (#​36192)
    • Enable dependabot for actions (#​36191)
    • Bump alpine to 3.23 (#​36185)
    • Update chroma to v2.21.0 (#​36171)
    • Update JS deps and eslint enhancements (#​36147)
    • Update JS deps (#​36091)
    • update golangci-lint to v2.7.0 (#​36079)
    • Update JS deps, fix deprecations (#​36040)
    • Update JS deps (#​35978)
    • Add toolchain directive to go.mod (#​35901)
    • Move gitea-vet to use go tool (#​35878)
    • Update to go 1.25.4 (#​35877)
    • Enable TypeScript strictNullChecks (#​35843)
    • Enable vue/require-typed-ref eslint rule (#​35764)
    • Update JS dependencies (#​35759)
    • Move codeformat folder to tools (#​35758)
    • Update dependencies (#​35733)
    • Bump happy-dom from 20.0.0 to 20.0.2 (#​35677)
    • Bump setup-go to v6 (#​35660)
    • Update JS deps, misc tweaks (#​35643)
    • Bump happy-dom from 19.0.2 to 20.0.0 (#​35625)
    • Use bundled version of spectral (#​35573)
    • Update JS and PY deps (#​35565)
    • Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 (#​35557)
    • Migrate from webpack to vite (#​37002)
    • Update JS dependencies and misc tweaks (#​37064)
    • Update to eslint 10 (#​36925)
    • Optimize Docker build with dependency layer caching (#​36864)
    • Update JS deps (#​36850)
    • Update tool dependencies and fix new lint issues (#​36702)
    • Remove redundant linter rules (#​36658)
    • Move Fomantic dropdown CSS to custom module (#​36530)
    • Remove and forbid @ts-expect-error (#​36513)
    • Refactor git command stderr handling (#​36402)
    • Enable gocheckcompilerdirectives linter (#​36156)
    • Replace lint-go-gopls with additional govet linters (#​36028)
    • Update golangci-lint to v2.6.0 (#​35801)
    • Misc tool tweaks (#​35734)
    • Add cache to container build (#​35697)
    • Upgrade vite (#​37126)
    • Update setup-uv to v8.0.0 (#​37101)
    • Upgrade go-git to v5.17.2 and related dependencies (#​37060)
    • Raise minimum Node.js version to 22.18.0 (#​37058)
    • Upgrade golang.org/x/image to v0.38.0 (#​37054)
    • Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style (#​36876)
    • Enable eslint concurrency (#​36878)
    • Vendor relative-time-element as local web component (#​36853)
    • Update material-icon-theme v5.32.0 (#​36832)
    • Update Go dependencies (#​36781)
    • Upgrade minimatch (#​36760)
    • Remove i18n backport tool at the moment because of translation format changed (#​36643)
    • Update emoji data for Unicode 16 (#​36596)
    • Update JS dependencies, adjust webpack config, misc fixes (#​36431)
    • Update material-icon-theme to v5.31.0 (#​36427)
    • Update JS and PY deps (#​36383)
    • Bump alpine to 3.23, add platforms to docker-dryrun (#​36379)
    • Update JS deps (#​36354)
    • Update goldmark to v1.7.16 (#​36343)
    • Update chroma to v2.22.0 (#​36342)
  • DOCS
    • Update AI Contribution Policy (#​37022)
    • Update AGENTS.md with additional guidelines (#​37018)
    • Add missing cron tasks to example ini (#​37012)
    • Add AI Contribution Policy to CONTRIBUTING.md (#​36651)
    • Minor punctuation improvement in CONTRIBUTING.md (#​36291)
    • Add documentation for markdown anchor post-processing (#​36443)
  • MISC

v1.25.5

Compare Source

grafana/helm-charts (grafana)

v8.15.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.8.0-weekly.339+dev.1...grafana-8.15.0

v8.14.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.80.5...grafana-8.14.2

v8.14.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Explicitly drop all unused capabilities for init-chown-data and set readonlyRootFilesystem by @​jcpunk in #​3684

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.38.3...grafana-8.14.1

v8.14.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.13.2...grafana-8.14.0

v8.13.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.5-beta.1...grafana-8.13.2

v8.13.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.4-beta.1...grafana-8.13.1

v8.13.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-1.0.2...grafana-8.13.0

v8.12.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Image Pull Secrets for the Image Renderer deployment not set in values.yaml by @​RaphSku in #​3653

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.80.3...grafana-8.12.1

v8.12.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] feat: add possibility to set env var RESOURCE_NAME using grafana-helm chart values by @​CarstenSon in #​3649

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/cloudcost-exporter-1.0.1...grafana-8.12.0

v8.11.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Add initContainers only if .Values.persistence.enabled and .Values.initChownData.enabled are true by @​baurmatt in #​3590

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.35.0...grafana-8.11.4

v8.11.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.11.2...grafana-8.11.3

v8.11.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Document limitation of alert's rule_version_record_limit to avoid DB saturation by @​benoittgt in #​3629

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/rollout-operator-0.25.0...grafana-8.11.2

v8.11.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Process sidecar configmap/secret label and labelValue with tpl by @​a-abella in #​3585

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-sampling-1.1.5...grafana-8.11.1

v8.11.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.1-beta.1...grafana-8.11.0

v8.10.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.6.29...grafana-8.10.4

v8.10.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.10.2...grafana-8.10.3

v8.10.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.32.3...grafana-8.10.2

v8.10.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-2.0.12...grafana-8.10.1

v8.10.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] feat: add shareProcessNamespace option to restart Grafana on LDAP config changes by @​jiayuchen888 in #​3569

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.9.1...grafana-8.10.0

v8.9.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.26.0...grafana-8.9.1

v8.9.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.8.6...grafana-8.9.0

v8.8.6

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-agent-operator-0.5.1...grafana-8.8.6

v8.8.5

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.7.0-weekly.325...grafana-8.8.5

v8.8.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.24.1...grafana-8.8.4

v8.8.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.6.2...grafana-8.8.3

v8.8.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-1.16.0...grafana-8.8.2

v8.8.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Fix "Error: Failed to launch the browser process!\nchrome_crashpad_handler: --database is required" with "image-renderer" by @​muffl0n in #​3487

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.8.0...grafana-8.8.1

v8.8.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.7.1...grafana-8.8.0

v8.7.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.26.1...grafana-8.7.1

v8.7.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.26.0...grafana-8.7.0

v8.6.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Add configuration options for the number of retries done by the sidecar by @​cbos in #​3454

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.22.0...grafana-8.6.4

v8.6.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.5.0...grafana-8.6.3

v8.6.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.6.0-weekly.318...grafana-8.6.2

v8.6.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/oncall-1.13.3...grafana-8.6.1

v8.6.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-vulture-0.7.0...grafana-8.6.0

v8.5.12

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.4.5...grafana-8.5.12

v8.5.11

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.5.10...grafana-8.5.11

v8.5.10

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.4.4...grafana-8.5.10

v8.5.9

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.6.1...grafana-8.5.9

v8.5.8

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.5.7...grafana-8.5.8

v8.5.7

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.9.2...grafana-8.5.7

v8.5.6

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.18.0...grafana-8.5.6

v8.5.5

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.18.4...grafana-8.5.5

v8.5.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.5.0...grafana-8.5.4

v8.5.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.9.1...grafana-8.5.3

v8.5.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.9.0...grafana-8.5.2

v8.5.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.11.0...grafana-8.5.1

v8.5.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.9...grafana-8.5.0

v8.4.9

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.10.1...grafana-8.4.9

v8.4.8

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] fixed url link for persistent volume claim in values.yaml by @​usmangt in #​2881

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.6.1...grafana-8.4.8

v8.4.7

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.6...grafana-8.4.7

v8.4.6

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.17.0...grafana-8.4.6

v8.4.5

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-sampling-1.0.0...grafana-8.4.5

v8.4.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.3...grafana-8.4.4

v8.4.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.2...grafana-8.4.3

v8.4.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.16.1...grafana-8.4.2

v8.4.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.4.4...grafana-8.4.1

v8.4.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] add value to make extraConfigmapMounts and extraSecretMounts optional by @​tibuntu in #​3250

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.79.2...grafana-8.4.0

v8.3.8

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.15.3...grafana-8.3.8

v8.3.7

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-agent-operator-0.4.1...grafana-8.3.7

v8.3.6

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.3.5...grafana-8.3.6

v8.3.5

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/synthetic-monitoring-agent-0.3.0...grafana-8.3.5

v8.3.4

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.79.1...grafana-8.3.4

v8.3.3

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.5.1...grafana-8.3.3

v8.3.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.6.5...grafana-8.3.2

v8.3.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

  • [grafana] Add support for envValueFrom in datasources container and fix typo in dashboards container config by @​rgaduput in #​3187

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.3.0...grafana-8.3.1

v8.3.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.13.2...grafana-8.3.0

v8.2.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.13.1...grafana-8.2.2

v8.2.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.2.0...grafana-8.2.1

v8.2.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.1.1...grafana-8.2.0

v8.1.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.1.0...grafana-8.1.1

v8.1.0

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.4.0...grafana-8.1.0

v8.0.2

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.0.13...grafana-8.0.2

v8.0.1

Compare Source

The leading tool for querying and visualizing time series and metrics.

What's Changed

New Contributors

Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.11.0...grafana-8.0.1

kubernetes-sigs/kind (kind)

v0.32.0

This release contains critical dependency updates, bug fixes, and defaults to Kubernetes 1.36.1.

Breaking Changes

  • The default node image is now kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5
  • New node images requiring upgrading kind to kind load ...: Due to a containerd upgrade, you must upgrade kind to this release or newer to use kind load ... with the newly published node images. As always, we cannot gurantee full compatibility of node images between kind releases. You can use the digests from previous releases, upgrade kind, or build your own node-images.
  • kubeadm v1beta4 config format is now used for Kubernetes 1.36.0+ If you are using versioned config patches, you must update to target v1beta4. Unversioned patches kind will attempt to convert as needed (more below in New Features). This change is required for Kubernetes 1.37+ which drops kubeadm v1beta3 config.
  • Adoption of Envoy for Load Balancing in multi-control-plane node clusters: HAProxy has been replaced by Envoy (docker.io/envoyproxy/envoy:v1.36.2) as the load balancer in multi-control-plane (HA) clusters. If you rely on custom HAProxy loadbalancer configurations or images, please note that Envoy is now used.
  • cgroup v1 warning: A warning is now printed if cgroup v1 is detected on the host. Kubernetes has deprecated support for cgroup v1, and at some point in the future KIND releases / node-images will also drop support for cgroup v1.

New Features

  • kubeadm v1beta4 configuration support: KIND now uses the v1beta4 config format for Kubernetes v1.36.0+ while maintaining v1beta3 for v1.23.0 up to v1.35.x, and v1beta2 for older versions.
  • Custom Merging & Version-Awareness for Kubeadm Config Patches:
    • KIND now automatically translates old-style map-based extraArgs / kubeletExtraArgs patches to the list-based v1beta4 format when targeting v1beta4 configs.
    • Config patches now append to extraArgs / kubeletExtraArgs / certSANs reliably. To overwrite or make other more precise patching, use json6902 patches.
  • Support for containerd config v4 format: Enabled support for containerd's config v4 format in kind load and snapshotter parsing, which is required for newer containerd versions.
  • Building Node Images from CI Artifacts: Added support to build node images from Kubernetes CI artifacts (resolving endpoints like https://dl.k8s.io/ci/latest.txt or CI build prefixes).
  • Support for containerd version-aware containerd config patching: Like kubeadmConfigPatches, containerd config patching is now aware of version and if specified in patches will only apply patches that match the containerd config being used.
  • Assorted dependency updates.

Images pre-built for this release:

  • v1.36.1: kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5
  • v1.35.5: kindest/node:v1.35.5@sha256:ce977ae6d65918d0b58a5f8b5e940429c2ce42fa3a5619ec2bbc60b949c0ac95
  • v1.34.8: kindest/node:v1.34.8@sha256:02722c2dedddcfc00febf5d27fbeb9b7b2c14294c82109ff4a85d89ac9ba3256
  • v1.33.12: kindest/node:v1.33.12@sha256:3f5c8443c620245e4d355cfe09e96a91ead32ceaa569d3f1ca9edf0cb2fe2ff4

NOTE: You must use the @sha256 digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons.

Fixes

  • Fix permission error when creating pods with hostUsers: false (Kubernetes 1.36+).
  • Handle registry ports correctly in image normalization logic (e.g., registry running on ports like localhost:5000/...).
  • Handle empty port mapping listen addresses correctly (defaults to wildcard address).
  • Skip /dev/mapper mount on rootless Docker.
  • Assorted documentation fixes and improvements.

See also:

NOTE: These node images support amd64 and arm64, both of our supported platforms. You must use the same platform as your host, for more context see #​2718

Contributors

Committers for this release:

We'd also like to thank everyone who touched the codebase, filed issues, and helped the community!

v0.31.0

This release contains dependency updates and defaults to Kubernetes 1.35.0.

Please take note of the breaking changes from Kubernetes 1.35, and how to prepare for future changes to move off of the deprecated kubeam v1beta3 in favor of v1beta4. We will include updated reminders for both again in subsequent releases.

Breaking Changes

The default node image is now kindest/node:v1.35.0@sha256:452d707d4862f52530247495d180205e029056831160e22870e37e3f6c1ac31f

Kubernetes 1.35+ Cgroup v1

Kubernetes will be removing cgroup v1 support, and therefore kind node images at those versions will also be dropping support.

You can read more about this change in the Kubernetes release blog: https://kubernetes.io/blog/2025/12/17/kubernetes-v1-35-release/#removal-of-cgroup-v1-support

If you must use kind on cgroup v1, we recommend using an older Kubernetes release for the immediate future, but we also strongly recommend migrating to cgroup v2.

In the near future as Kubernetes support dwindles, KIND will also clean up cgroup v1 workarounds and drop support in future kind releases and images, regardless of Kubernetes version.

Most stable linux distros should be on cgroupv2 out of the box.

This is a reminder to use pinned images by digest, see the note below about images for this release.

Kubeadm Config *Future* Breaking Change

WARNING: Future kind releases will adopt kubeadm v1beta4 configuration, kubeadm v1beta4 has a breaking change to extraArgs: https://kubernetes.io/blog/2024/08/23/kubernetes-1-31-kubeadm-v1beta4/.

If you use the kubeadmConfigPatches feature then you may need to prepare for this change.
We recommend that you use versioned config patches that explicitly match the version required.

KIND uses kubeadm v1beta3 for Kubernetes 1.23+, and will likely use v1beta4 for Kubernetes 1.36+
The exact version is TBD pending work to fix this but expected to be 1.36.
It will definitely be an as-of-yet-unreleased Kubernetes version to avoid surprises, and it will not be on a patch-release boundary.

KIND may still work with older Kubernetes versions at v1beta2, but we no longer test or actively support these as Kubernetes only supports 1.32+ currently: https://kubernetes.io/releases/

You likely only need v1beta3 + v1beta4 patches, you can take your existing patches that work with v1beta3, explicitly set apiVersion: kubeadm.k8s.io/v1beta3 in the patch at the top level, and make another copy for v1beta4. The v1beta4 patch will need to move extraArgs from a map to a list, for examples see: https://kubernetes.io/docs/reference/config-api/kubeadm-config.v1beta4/

For a concrete example of kind config with kubeadm config patch targeting both v1beta3 and v1beta4, consider this simple kind config that sets verbosity of the apiserver logs:

kind: Cluster
apiVersion: kind.x-k8s.io/v1alpha4
kubeadmConfigPatches:

# patch for v1beta3 (1.23 ...)
- |
  kind: ClusterConfiguration
  apiVersion: kubeadm.k8s.io/v1beta3
  apiServer:
    extraArgs:
      "v": "4"

# patch for v1beta4 (future)
- |
  kind: ClusterConfiguration
  apiVersion: kubeadm.k8s.io/v1beta4
  apiServer:
    extraArgs:
      - name: "v"
        value: "4"

If you only need to target a particular release, you can use one version.

If you only need to target fields that did not change between kubeadm beta versions, you can use a versionless patch, which may be more convenient, but we cannot guarantee there will be no future kubeadm config breaking changes.

New Features

  • Assorted unspecified dependency updates

Images pre-built for this release:

  • v1.35.0: kindest/node:v1.35.0@sha256:452d707d4862f52530247495d180205e029056831160e22870e37e3f6c1ac31f
  • v1.34.3: kindest/node:v1.34.3@sha256:08497ee19eace7b4b5348db5c6a1591d7752b164530a36f855cb0f2bdcbadd48
  • v1.33.7: kindest/node:v1.33.7@sha256:d26ef333bdb2cbe9862a0f7c3803ecc7b4303d8cea8e814b481b09949d353040
  • v1.32.11: kindest/node:v1.32.11@sha256:5fc52d52a7b9574015299724bd68f183702956aa4a2116ae75a63cb574b35af8
  • v1.31.14: kindest/node:v1.31.14@sha256:6f86cf509dbb42767b6e79debc3f2c32e4ee01386f0489b3b2be24b0a55aac2b

NOTE: You must use the @sha256 digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons.

See also:

NOTE: These node images support amd64 and arm64, both of our supported platforms. You must use the same platform as your host, for more context see #​2718

Fixes

  • Detect additional edge case with ipv6 support on the host
  • Make development / release scripts GOTOOLCHAIN aware

Contributors

Committers for this release:

v0.30.0

This is small release containing patched dependencies and Kubernetes 1.34, as well as a bugfix for Kubernetes v1.33.0+ cluster reboots.

Breaking Changes

The default node image is now kindest/node:v1.34.0@sha256:7416a61b42b1662ca6ca89f02028ac133a309a2a30ba309614e8ec94d976dc5a

New Features

  • Updated to containerd 2.1.4

Images pre-built for this release:

  • v1.34.0: kindest/node:v1.34.0@sha256:7416a61b42b1662ca6ca89f02028ac133a309a2a30ba309614e8ec94d976dc5a
  • v1.33.4: kindest/node:v1.33.4@sha256:25a6018e48dfcaee478f4a59af81157a437f15e6e140bf103f85a2e7cd0cbbf2
  • v1.32.8: kindest/node:v1.32.8@sha256:abd489f042d2b644e2d033f5c2d900bc707798d075e8186cb65e3f1367a9d5a1
  • v1.31.12: kindest/node:v1.31.12@sha256:0f5cc49c5e73c0c2bb6e2df56e7df189240d83cf94edfa30946482eb08ec57d2

NOTE: You must use the @sha256 digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons.

See also:

NOTE: These node images support amd64 and arm64, both of our supported platforms. You must use the same platform as your host, for more context see #​2718

Fixes

  • Fix an issue with rebooting v1.33.0+ clusters #​3941
  • Add priority class system-critical to kindnetd
  • Fix HA control-plane loadbalancer for podman #​3962
  • Fix node-image builds with relative source paths

Contributors

Committers for this release:

sunny0826/kubecm (kubecm)

v0.35.1: kubecm-v0.35.1

Changelog

What's Changed

Full Changelog: https://github.com/sunny0826/kubecm/compare/v0.35.0...v0.35.1

v0.35.0: kubecm-v0.35.0

Changelog

Others
  • 6b96e5e: add clark42 as a contributor for code, doc, and test (#​1172) (allcontributors[bot] <46447321+allcontributors[bot]@​users.noreply.github.com>)

What's Changed

New Contributors

Full Changelog: https://github.com/sunny0826/kubecm/compare/v0.34.0...v0.35.0

v0.34.0: kubecm-v0.34.0

What's Changed

New Contributors

Full Changelog: https://github.com/sunny0826/kubecm/compare/v0.33.3...v0.34.0

v0.33.3: kubecm-v0.33.3

Changelog

Others

v0.33.2: kubecm-v0.33.2

Changelog

Others
  • ff503b3: add xiaoshanyangcode as a contributor for code (#​1150) (allcontributors[bot] <46447321+allcontributors[bot]@​users.noreply.github.com>)
helm/helm (kubernetes-helm)

v3.20.2: Helm v3.20.2

v3.20.2

Helm v3.20.2 is a security patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Security fixes

  • GHSA-hr2v-4r36-88hr Helm Chart extraction output directory collapse via Chart.yaml name dot-segment

Installation and Upgrading

Download Helm v3.20.2. The common platform binaries are here:

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.1.5 and 3.20.3 are the next patch (bug fix) releases and will be on April 8, 2026
  • 4.2.0 and 3.21.0 are the next minor (feature) releases and will be on May 13, 2026

Changelog

  • fix: Chart dot-name path bug 8fb76d6 (George Jenkins)
  • fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow 3a8927e (Terry Howe)

v3.20.1: Helm v3.20.1

Helm v3.20.1 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Notable Changes

  • Backport of #​31644: Fixed a bug where user-provided nil value was not preserved when chart has an empty map or no default for a key
  • Backport of #​31601: Fixed a bug where OCI references with tag+digest failed with "invalid byte" error

Installation and Upgrading

Download Helm v3.20.1. The common platform binaries are here:

This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @​scottrigby keybase account. Please use the attached signatures for verifying this release using gpg.

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.2.0 and 3.21.0 are the next minor releases and will be on May 13, 2026
  • 4.1.4 and 3.20.2 are the next patch releases and will be on April 8, 2026

Changelog

  • chore(deps): bump the k8s-io group with 7 updates a2369ca (dependabot[bot])
  • add image index test 90e1056 (Pedro Tôrres)
  • fix pulling charts from OCI indices 911f2e9 (Pedro Tôrres)
  • Remove refactorring changes from coalesce_test.go 76dad33 (Evans Mungai)
  • Fix import 45c12f7 (Evans Mungai)
  • Update pkg/chart/common/util/coalesce_test.go 26c6f19 (Evans Mungai)
  • Fix lint warning 09f5129 (Evans Mungai)
  • Preserve nil values in chart already 417deb2 (Evans Mungai)
  • fix(values): preserve nil values when chart default is empty map 5417bfa (Evans Mungai)

v3.19.1: Helm v3.19.1

Helm v3.19.1 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Installation and Upgrading

Download Helm v3.19.1. The common platform binaries are here:

This release was signed with 672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E and can be found at @​mattfarina keybase account. Please use the attached signatures for verifying this release using gpg.

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.0.0 is the next major release and will be on November 12, 2025
  • 3.19.2 and 4.0.01 are the next patch releases and will be on December 10, 2025
  • 3.20.0 and 4.1.0 is the next minor releases and will be on January 21, 2026

Changelog

  • chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 4f953c2 (dependabot[bot])
  • jsonschema: warn and ignore unresolved URN $ref to match v3.18.4 6801f4d (Benoit Tigeot)
  • Avoid "panic: interface conversion: interface {} is nil" 2f619be (Benoit Tigeot)
  • Fix helm pull untar dir check with repo urls 8112d47 (Luna Stadler)
  • Fix deprecation warning 5dff7ce (Benoit Tigeot)
  • chore(deps): bump github.com/spf13/pflag from 1.0.7 to 1.0.10 2dad4d2 (dependabot[bot])
  • Add timeout flag to repo add and update flags a833710 (Reinhard Nägele)
  • chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.43.0 2e12c81 (Dirk Müller)

v3.19.0: Helm v3.19.0

Helm v3.19.0 is a feature release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Notable Changes

  • Fixed a helm pull regression from 3.18 - error pulling OCI charts with --password #​31230
  • Fixed a helm lint regression from Helm 3.18 - rejected JSON Schema $ref URLs that worked in 3.17.x #​31166
  • Fixed go mod tidy #​31154
  • Fixed k8s version parsing not matching original #​31091
  • Fixed charts failing when using a redirect registry #​31087
  • Fixed missing debug logging for OCI transport
  • Fixed broken legacy docker support for login #​30941
  • Fixed bugs from the move to ORAS v2
  • Fixed processing all hook deletions on failure #​30673
  • Feature for helm create added httproute from gateway-api to create chart template #​30658

Installation and Upgrading

Download Helm v3.19.0. The common platform binaries are here:

This release was signed with 208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155 and can be found at @​scottrigby keybase account. Please use the attached signatures for verifying this release using gpg.

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 3.19.1 will contain only bug fixes.
  • 3.20.0 is the next feature release.

Changelog

  • bump version to v3.19.0 3d8990f (Scott Rigby)
  • fix: use username and password if provided 9a54bf1 (Evans Mungai)
  • chore(deps): bump the k8s-io group with 7 updates 5af0f68 (dependabot[bot])
  • chore(deps): bump github.com/spf13/cobra from 1.9.1 to 1.10.1 e485606 (dependabot[bot])
  • chore(deps): bump github.com/stretchr/testify from 1.11.0 to 1.11.1 6355c3d (dependabot[bot])
  • chore(deps): bump github.com/stretchr/testify from 1.10.0 to 1.11.0 ec61f66 (dependabot[bot])
  • fix(helm-lint): fmt b278020 (Isaiah Lewis)
  • fix(helm-lint): Add TLSClientConfig d33ac5e (Isaiah Lewis)
  • fix(helm-lint): Add HTTP/HTTPS URL support for json schema references 8543709 (Isaiah Lewis)
  • chore(deps): bump the k8s-io group with 7 updates 89a3f90 (dependabot[bot])
  • fix: go mod tidy for v3 da4c583 (Terry Howe)
  • chore(deps): bump golang.org/x/crypto from 0.40.0 to 0.41.0 e40b1b3 (dependabot[bot])
  • chore(deps): bump golang.org/x/term from 0.33.0 to 0.34.0 a27e9db (dependabot[bot])
  • fix Chart.yaml handling f13afaa (Matt Farina)
  • Handle messy index files 039b0b1 (Matt Farina)
  • chore(deps): bump github.com/containerd/containerd from 1.7.27 to 1.7.28 bec98a9 (dependabot[bot])
  • json schema fix 6d9509a (Robert Sirchia)
  • fix: k8s version parsing to match original 807225e (Borys Hulii)
  • chore(deps): bump sigs.k8s.io/yaml from 1.5.0 to 1.6.0 cbbd569 (dependabot[bot])
  • Do not explicitly set SNI in HTTPGetter 5e8ff72 (Terry Howe)
  • chore(deps): bump github.com/spf13/pflag from 1.0.6 to 1.0.7 5b5fb5b (dependabot[bot])
  • chore(deps): bump the k8s-io group with 7 updates d12538a (dependabot[bot])
  • chore(deps): bump golang.org/x/crypto from 0.39.0 to 0.40.0 303f803 (dependabot[bot])
  • chore(deps): bump golang.org/x/term from 0.32.0 to 0.33.0 abcc2ed (dependabot[bot])
  • chore(deps): bump golang.org/x/text from 0.26.0 to 0.27.0 521c67b (dependabot[bot])
  • Disabling linter due to unknown issue 227c9cb (Matt Farina)
  • Updating link handling 4389fa6 (Matt Farina)
  • Bump github.com/Masterminds/semver/v3 from 3.3.0 to 3.3.1 372e403 (dependabot[bot])
  • build(deps): bump the k8s-io group with 7 updates 4fa5a64 (dependabot[bot])
  • build(deps): bump sigs.k8s.io/yaml from 1.4.0 to 1.5.0 6284ed8 (dependabot[bot])
  • fix: user username password for login 2c55a4e (Terry Howe)
  • Update pkg/registry/transport.go a16e986 (Terry Howe)
  • Update pkg/registry/transport.go cea26d8 (Terry Howe)
  • fix: add debug logging to oci transport b52bb41 (Terry Howe)
  • build(deps): bump golang.org/x/crypto from 0.38.0 to 0.39.0 45075cf (dependabot[bot])
  • build(deps): bump golang.org/x/text from 0.25.0 to 0.26.0 73a7826 (dependabot[bot])
  • fix: legacy docker support broken for login 733f94c (Terry Howe)
  • fix: plugin installer test with no Internet fc36041 (Terry Howe)
  • Handle an empty registry config file. cfe8cef (Matt Farina)
  • Prevent fetching newReference again as we have in calling method c33215d (Benoit Tigeot)
  • Prevent failure when resolving version tags in oras memory store f552b67 (Benoit Tigeot)
  • fix(client): skipnode utilization for PreCopy a18a52e (Brandt Keller)
  • test: Skip instead of returning early. looks more intentional fedf502 (Jesse Simpson)
  • test: tests repo stripping functionality fe512ba (Jesse Simpson)
  • test: include tests for Login based on different protocol prefixes 099a9e1 (Jesse Simpson)
  • fix(client): layers now returns manifest - remove duplicate from descriptors b07ab77 (Brandt Keller)
  • fix(client): return nil on non-allowed media types c225c12 (Brandt Keller)
  • Fix 3.18.0 regression: registry login with scheme c0f3ace (Scott Rigby)
  • Update pkg/plugin/plugin.go dce60ad (Benoit Tigeot)
  • Update pkg/plugin/plugin.go cda0865 (Benoit Tigeot)
  • Wait for Helm v4 before raising when platformCommand and Command are set 5d9d9a0 (Benoit Tigeot)
  • Revert "fix (helm) : toToml` renders int as float [ backport to v3 ]" c5249c1 (Matt Farina)
  • build(deps): bump the k8s-io group with 7 updates 5b0520d (dependabot[bot])
  • chore: update generalization warning message afefca8 (Feng Cao)
  • build(deps): bump oras.land/oras-go/v2 from 2.5.0 to 2.6.0 8d6d27c (dependabot[bot])
  • build(deps): bump the k8s-io group with 7 updates 502c0d5 (dependabot[bot])
  • build(deps): bump golang.org/x/crypto from 0.37.0 to 0.38.0 92be9ac (dependabot[bot])
  • fix: move warning to top of block eb5b6d5 (Feng Cao)
  • fix: govulncheck workflow 6b15f26 (Matthieu MOREL)
  • fix: replace fmt warning with slog 6b5c944 (Feng Cao)
  • fix: add warning when ignore repo flag 247bf7c (Feng Cao)
  • bump version to v3.18.0 9404459 (Robert Sirchia)
  • backport #​30673 to dev-v3 0a800e8 (Gerard Nguyen)
  • feat: add httproute from gateway-api to create chart template bd1b67b (Henrik Gerdes)

Full Changelog: https://github.com/helm/helm/compare/v3.18.6...v3.19.0

bitnami/sealed-secrets (kubeseal)

v0.38.4

  • Incomplete release for credentials problems

v0.36.0

  • [Security] Preserve scope during Sealed Secret rotation (#​1886)
  • [Security] Throw an error in case of inconsistencies in the Sealed Secrets (#​1885)
  • Bump distroless/static from 972618c to d90359c in /docker (#​1884)
  • Set up OCI GH to release helm chart (#​1883)

v0.34.0

  • Add kseal to README (#​1852))
  • Bump golang version to the latest available 1.24 (#​1854)
  • Bump k8s.io/code-generator from 0.34.2 to 0.34.3 (#​1850)
  • Bump k8s.io/client-go from 0.34.2 to 0.34.3 (#​1848)
  • Bump github.com/onsi/ginkgo/v2 from 2.27.2 to 2.27.3 (#​1843)
  • Bump distroless/static from 87bce11 to 4b2a093 in /docker (#​1846)
  • Bump github.com/onsi/gomega from 1.38.2 to 1.38.3 (#​1844)
  • Bump golang.org/x/crypto from 0.45.0 to 0.46.0 (#​1845)
  • Make controllers kubeclient QPS & Burst configurable. (#​1834)
  • use default method to watch for key secrets (#​1831)
  • Bump golang.org/x/crypto from 0.44.0 to 0.45.0 in the go_modules group across 1 directory (#​1840)
  • Bump k8s.io/code-generator from 0.34.1 to 0.34.2 (#​1839)
  • Bump golang.org/x/crypto from 0.43.0 to 0.44.0 (#​1835)
  • Bump k8s.io/client-go from 0.34.1 to 0.34.2 (#​1837)

v0.33.1

  • Release done to fix missing helm chart code.

v0.32.2

  • Fix controller yaml (#​1811)
  • Bump k8s.io/code-generator from 0.33.4 to 0.34.1 (#​1809)

v0.32.1

kubernetes-sigs/kustomize (kustomize)

v5.8.1

Introduction

This release completes a fix for namespace propagation that occurred in v5.8.0. #​6031 (comment)
Also addressed the breaking changes introduced in helm v4. #​6016

fix

#​5990: fix: allow empty patches files
#​6016: fix: support helm v4 beside v3
#​6038: Fix a failing test
#​6044: Fix namespace propagation problem at v5.8.0

Dependencies

#​6057: Upgrade json-patch to v4.13.0 to remove pkg/errors dependency

chore

#​6065: Update kyaml to v0.21.1
#​6066: Update cmd/config to v0.21.1
#​6067: Update api to v0.21.1

v5.8.0

IMPORTANT NOTICE: REGRESSION

Due to the new features introduced in this release, a regression has occurred in the functionality that propagates namespaces to child kustomizations.
We are currently preparing a patch release, so please refrain from making changes to this version.

#​6031 (comment)

Highlights

implements to replacements value in the structured data

Now, We can edit yaml/json in yaml manifests with replacements transformer.
See #​5679

For example

## source
apiVersion: v1
kind: ConfigMap
metadata:
  name: source-configmap
data:
  HOSTNAME: www.example.com
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: target-configmap
data:
  config.json: |-
    {"config": {
      "id": "42",
      "hostname": "REPLACE_TARGET_HOSTNAME"
    }}

## replacement
replacements:
- source:
    kind: ConfigMap
    name: source-configmap
    fieldPath: data.HOSTNAME
  targets:
  - select:
      kind: ConfigMap
      name: target-configmap
    fieldPaths:
    - data.config\.json.config.hostname
fix: Propagate Namespace correctly to Helm

The long-standing bug where kustomize's namespace transformer did not pass namespaces to helmCharts has been fixed.
See #​5940

For example

## define namespace
namespace: any-namespace

helmCharts:
- name: minecraft
  repo: https://kubernetes-charts.storage.googleapis.com
  version: v1.2.0
  # namespace: any-namespace   ## propagates without additional namespace specific
  valuesFile: values.yaml

Feature

#​5679: implements to replacements value in the structured data
#​5863: Add regex support for Replacement selectors
#​5930: feat: add PatchArgs API type to populate patch options

fix

#​5940: fix: Propagate Namespace correctly to Helm
#​5971: fix: performance recession when propagating namespace to helm
#​5942: fix fnplugin storagemounts validation
#​5958: fix: make AbsorbAll conflict error more verbose
#​5961: refactor: nested format string
#​5967: Fix infinite loop in HTTP client by validating URLs before requests
#​5985: fix(kyaml/yaml): minor nil safety fix for RNode.Content etc
#​5991: Fix duplicate key error when adding multiple labels with --without-selector

Dependencies

#​5962: chore: update dependencies from security alert
#​5959: update go 1.24.6

chore

#​6007: Update kyaml to v0.21.0
#​6008: Update cmd/config to v0.21.0
#​6009: Update api to v0.21.0

v5.7.1

This release introduces code to replace the shlex library used for parsing arguments in the exec plugin.
If any existing manifests become corrupted, please file an issue. discussion: kubernetes/kubernetes#132593 (comment)

Dependencies

#​5943: drop shlex dependency

Chore

#​5948: Update kyaml to v0.20.1
#​5949: Update cmd/config to v0.20.1
#​5950: Update api to v0.20.1

prometheus-community/helm-charts (prometheus)

v28.16.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

  • [prometheus] Update Helm release prometheus-node-exporter to 4.53.* by @​renovate[bot] in #​6814

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.18.0...prometheus-28.16.0

v28.15.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.16.1...prometheus-28.15.0

v28.14.1

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

  • [prometheus] Update quay.io/prometheus-operator/prometheus-config-reloader Docker tag to v0.90.1 by @​renovate[bot] in #​6786

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-operator-crds-28.0.1...prometheus-28.14.1

v28.14.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-snmp-exporter-9.13.0...prometheus-28.14.0

v28.13.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.4.3...prometheus-28.13.0

v28.12.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

  • [prometheus] Update Helm release prometheus-node-exporter to 4.52.* by @​renovate[bot] in #​6685

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.4.1...prometheus-28.12.0

v28.11.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-node-exporter-4.52.0...prometheus-28.11.0

v28.10.1

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

  • [prometheus] Update quay.io/oauth2-proxy/oauth2-proxy Docker tag to v7.14.3 by @​renovate[bot] in #​6678

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-state-metrics-7.2.0...prometheus-28.10.1

v28.10.0

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-nginx-exporter-1.19.3...prometheus-28.10.0

v28.9.1

Compare Source

Prometheus is a monitoring system and time series database.

What's Changed

Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-redis-exporter-6.21.0...prometheus-28.9.1

anchore/syft (syft)

v1.51.0

Added Features
Bug Fixes
  • Cleanup snap temporary directories [PR #​5117 @​spiffcs]
  • add correct CPE vendor/product candidates for Git for Windows PE binary [PR #​5156 @​westonsteimel]
  • javascript-package-cataloger creates phantom <name>@unknown packages for subpath or export-map stub package.json files [Issue #​5118]
  • Syft generates incorrect PURLs for legacy JARs missing Maven metadata, causing Grype false negatives [Issue #​4598] [PR #​5146 @​ankit090701]
  • When scanning an image, syft only reports one file per set of hardlinks, leading to wrong SPDX packageVerificationCode [Issue #​5019] [PR #​5029 @​wagoodman]
  • Support deno binary latest and some old versions [Issue #​5057] [PR #​5084 @​ychampion]
  • Update install methods in README.md [Issue #​3198]
Dependencies

9 dependency changes (9 updated). 2 vulnerabilities remediated.

🟢 Remediated (2)

Updated (9 packages)
  • github.com/diskfs/go-diskfs v1.9.3 → v1.9.4
  • github.com/go-git/go-billy/v5 v5.9.0 → v5.9.1
  • github.com/go-git/go-git/v5 v5.19.1 → v5.19.2 (🟢 remediated GHSA-hc8v-wwc9-vgxm, GHSA-qgq7-7hm3-q39j)
  • github.com/jedib0t/go-pretty/v6 v6.8.1 → v6.8.3
  • github.com/klauspost/compress v1.19.0 → v1.19.1
  • github.com/magiconair/properties v1.8.10 → v1.18.11
  • github.com/ulikunitz/xz v0.5.15 → v0.5.16
  • go.yaml.in/yaml/v3 v3.0.4 → v3.0.5
  • modernc.org/sqlite v1.54.0 → v1.55.0

(Full Changelog)

v1.50.0

Added Features
Bug Fixes
Additional Changes
Dependencies

14 dependency changes (14 updated). 1 vulnerability remediated.

🟢 Remediated (1)

Updated (14 packages)
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0 → v1.32.0
  • github.com/cncf/xds/go v0.0.0-ee656c7 → v0.0.0-dba9d58
  • github.com/envoyproxy/go-control-plane/envoy v1.36.0 → v1.37.0
  • github.com/envoyproxy/protoc-gen-validate v1.3.0 → v1.3.3
  • github.com/gpustack/gguf-parser-go v0.24.1 → v0.25.0
  • go.opentelemetry.io/contrib/detectors/gcp v1.39.0 → v1.43.0
  • google.golang.org/genproto/googleapis/api v0.0.0-9d38bb4 → v0.0.0-afd174a
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6f92a3b → v0.0.0-afd174a
  • google.golang.org/grpc v1.80.0 → v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)
  • modernc.org/cc/v4 v4.28.4 → v4.29.0
  • modernc.org/ccgo/v4 v4.34.4 → v4.34.6
  • modernc.org/gc/v3 v3.1.3 → v3.1.4
  • modernc.org/libc v1.73.4 → v1.74.1
  • modernc.org/sqlite v1.53.0 → v1.54.0

(Full Changelog)

v1.49.0

Added Features
Bug Fixes
Dependencies

16 dependency changes (16 updated).

Updated (16 packages)
  • github.com/anchore/go-rpmdb v0.1.0 → v0.2.0
  • github.com/anchore/stereoscope v0.2.2 → v0.3.0
  • github.com/containerd/containerd/v2 v2.3.2 → v2.3.3
  • github.com/docker/cli v29.5.3+incompatible → v29.6.1+incompatible
  • github.com/gkampitakis/go-snaps v0.5.22 → v0.5.23
  • github.com/moby/moby/api v1.54.2 → v1.55.0
  • github.com/moby/moby/client v0.4.1 → v0.5.0
  • github.com/pelletier/go-toml/v2 v2.3.1 → v2.4.3
  • golang.org/x/crypto v0.53.0 → v0.54.0
  • golang.org/x/mod v0.37.0 → v0.38.0
  • golang.org/x/net v0.56.0 → v0.57.0
  • golang.org/x/sync v0.21.0 → v0.22.0
  • golang.org/x/sys v0.46.0 → v0.47.0
  • golang.org/x/term v0.44.0 → v0.45.0
  • golang.org/x/text v0.38.0 → v0.40.0
  • golang.org/x/tools v0.47.0 → v0.48.0

(Full Changelog)

v1.48.0

Added Features
Bug Fixes
Dependencies

9 dependency changes (8 updated, 1 added).

Updated (8 packages)
  • github.com/bmatcuk/doublestar v1.3.1 → v8.8.8
  • github.com/klauspost/compress v1.18.6 → v1.19.0
  • golang.org/x/tools v0.46.0 → v0.47.0
  • modernc.org/cc/v4 v4.28.2 → v4.28.4
  • modernc.org/ccgo/v4 v4.34.0 → v4.34.4
  • modernc.org/gc/v3 v3.1.2 → v3.1.3
  • modernc.org/libc v1.72.3 → v1.73.4
  • modernc.org/sqlite v1.51.0 → v1.53.0
Added (1 package)
  • howett.net/plist v1.0.1

(Full Changelog)

v1.46.0

Added Features
Bug Fixes
Dependencies

34 dependency changes (31 updated, 3 added). 5 vulnerabilities remediated.

🟢 Remediated (5)

Updated (31 packages)
  • github.com/ProtonMail/go-crypto v1.4.0 → v1.4.1
  • github.com/anchore/bubbly v0.2.0 → v0.2.1
  • github.com/anchore/clio v0.1.0 → v0.1.1
  • github.com/anchore/fangs v0.1.0 → v0.1.1
  • github.com/anchore/go-collections v0.1.0 → v0.1.1
  • github.com/anchore/go-homedir v0.1.0 → v0.1.1
  • github.com/anchore/go-logger v0.1.0 → v0.1.1
  • github.com/anchore/go-lzo v0.1.0 → v0.1.1
  • github.com/anchore/go-macholibre v0.1.0 → v0.1.1
  • github.com/anchore/go-make v0.5.0 → v0.8.0
  • github.com/anchore/go-struct-converter v0.1.0 → v0.2.0-rc2
  • github.com/anchore/go-sync v0.1.0 → v0.1.1
  • github.com/anchore/stereoscope v0.2.1 → v0.2.2
  • github.com/charmbracelet/colorprofile v0.4.1 → v0.4.3
  • github.com/clipperhouse/displaywidth v0.10.0 → v0.11.0
  • github.com/clipperhouse/uax29/v2 v2.6.0 → v2.7.0
  • github.com/containerd/containerd/v2 v2.3.1 → v2.3.2 (🟢 remediated GHSA-33vj-92qq-66hc, GHSA-cvxm-645q-p574, GHSA-jpcc-p29g-p8mq, GHSA-rgh6-rfwx-v388, GHSA-xhf5-7wjv-pqxp)
  • github.com/docker/cli v29.4.3+incompatible → v29.5.3+incompatible
  • github.com/google/go-containerregistry v0.21.6 → v0.21.7
  • github.com/jedib0t/go-pretty/v6 v6.7.10 → v6.8.1
  • github.com/mattn/go-runewidth v0.0.19 → v0.0.21
  • github.com/spdx/tools-golang v0.5.7 → v0.6.0-rc4
  • github.com/sylabs/sif/v2 v2.24.0 → v2.24.1
  • golang.org/x/crypto v0.52.0 → v0.53.0
  • golang.org/x/mod v0.36.0 → v0.37.0
  • golang.org/x/net v0.55.0 → v0.56.0
  • golang.org/x/sync v0.20.0 → v0.21.0
  • golang.org/x/sys v0.45.0 → v0.46.0
  • golang.org/x/term v0.43.0 → v0.44.0
  • golang.org/x/text v0.37.0 → v0.38.0
  • golang.org/x/tools v0.45.0 → v0.46.0
Added (3 packages)
  • github.com/piprate/json-gold v0.7.0
  • github.com/pquerna/cachecontrol v0.0.0-1555304
  • github.com/tailscale/hujson v0.0.0-ecc657c

(Full Changelog)

v1.45.1

Bug Fixes

(Full Changelog)

v1.44.0

Added Features
Bug Fixes

(Full Changelog)

v1.43.0

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v1.42.4

Bug Fixes
Additional Changes

(Full Changelog)

v1.42.3

Bug Fixes
  • Missing secondary evidence for .NET dependency in ghcr.io/open-telemetry/demo:2.0.0-accounting image [#​4652]
Additional Changes

(Full Changelog)

v1.42.2

Bug Fixes
Additional Changes

(Full Changelog)

v1.42.1

Bug Fixes
  • Use redhat as namespace for hummingbird rpms [#​4615 @​scoheb]
  • False Positive: Emacs snap package version CVE-2024-39331 [#​4485]
Additional Changes

(Full Changelog)

v1.41.2

Bug Fixes

(Full Changelog)

v1.41.1

Bug Fixes

(Full Changelog)

v1.41.0

Added Features
Bug Fixes

(Full Changelog)

v1.40.1

[!Important]
This release bumps github.com/containerd/containerd to v2, which will cause compiler errors if used alongside other dependencies that use v1 of containerd. See anchore/stereoscope#495 for a detailed discussion.

Bug Fixes

(Full Changelog)

v1.40.0

Added Features
Bug Fixes

(Full Changelog)

v1.39.0

Added Features
Bug Fixes

(Full Changelog)

v1.38.2

Bug Fixes

(Full Changelog)

v1.38.0

Added Features
Bug Fixes
  • Support extras statements in Python PDM cataloger [#​4352 @​wagoodman]
  • Preserve --from argument order [#​4350 @​wagoodman]
  • SBOM generated by Syft 1.28 contains license elements missing id or name (causing CycloneDX parser error) [#​4363]
  • empty PURL output in dependency snapshot format breaks sbom-action [#​4311]
  • Interface includes constraint elements, can only be used in type parameters [#​4346]
  • Upgrade github.com/nwaples/rardecode@​v1.1.3 to 2.2.1 [#​4338]
  • Upgrade to Golang 1.25.4 [#​4341]
Additional Changes

(Full Changelog)

v1.37.0

Added Features
Bug Fixes

(Full Changelog)

v1.36.0

Added Features
Bug Fixes

(Full Changelog)

v1.34.2

Bug Fixes

(Full Changelog)

v1.33.0

Added Features

(Full Changelog)

v1.32.0

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v1.30.0

Added Features
Bug Fixes

(Full Changelog)

v1.29.1

Bug Fixes

(Full Changelog)

traefik/traefik-helm-chart (traefik)

v28.3.0

Compare Source

Features
  • allow setting permanent on redirectTo (1b454e9)
  • deps: update traefik docker tag to v3.0.2
Bug Fixes

New Contributors

Full Changelog: https://github.com/traefik/traefik-helm-chart/compare/v28.2.0...v28.3.0

v28.2.0

Compare Source

⚠️ This release align to Kubernetes default (Always) for podSecurityContext.fsGroupChangePolicy. It was OnRootMismatch in previous release of this chart. It can easily be set (back) to OnRootMismatch if needed, see EXAMPLES.

Features
Bug Fixes
  • IngressClass: provides annotation on IngressRoutes when it's enabled (f5de0c3)

New Contributors

Full Changelog: https://github.com/traefik/traefik-helm-chart/compare/v28.1.0...v28.2.0

v28.1.0

Compare Source

Features
  • Traefik Hub: add initial support for API Gateway (dc5c68d)
  • Traefik Hub: use Traefik Proxy otlp config (a910db4)
Bug Fixes
  • Traefik Hub: refine support (60d210d)
  • Traefik Hub: do not deploy mutating webhook when enabling only API Gateway (cb2a98d)
Documentation
  • example: Update Digital Ocean PROXY Protocol (9850319)
  • 📚️ improve UPGRADING section (54ec665)
UpCloudLtd/upcloud-cli (upcloud-cli)

v3.36.0

Added
  • Support gateway resources in all list and all purge commands.
  • Add --wait flag to gateway delete command.
guerzon/vaultwarden (vaultwarden)

v0.46.2

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.46.1...v0.46.2

v0.46.1

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.46.0...v0.46.1

v0.46.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.45.0...v0.46.0

v0.45.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.44.1...v0.45.0

v0.44.1

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.44.0...v0.44.1

v0.44.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.43.1...v0.44.0

v0.43.1

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.43.0...v0.43.1

v0.43.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.42.0...v0.43.0

v0.42.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.41.0...v0.42.0

v0.41.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.3...v0.41.0

v0.40.3

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.2...v0.40.3

v0.40.2

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.1...v0.40.2

v0.40.1

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.0...v0.40.1

v0.40.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.39.1...v0.40.0

v0.39.1

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.39.0...v0.39.1

v0.39.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.38.0...v0.39.0

v0.38.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.37.0...v0.38.0

v0.37.0

Compare Source

vaultwarden is an unofficial Bitwarden-compatible server written in Rust

What's Changed

New Contributors

Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.36.4...v0.37.0


Configuration

📅 Schedule: (in timezone Europe/Oslo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions](https://gitea.com/) ([source](https://gitea.com/gitea/helm-actions)) | | minor | `0.0.5` → `0.1.2` | | [awscli2](https://aws.amazon.com/cli/) | | minor | `2.34.24` → `2.35.11` | | [cert-manager](https://cert-manager.io) ([source](https://github.com/cert-manager/cert-manager)) | | minor | `v1.14.0` → `v1.21.2` | | [gitea](https://gitea.com/gitea/helm-gitea) | | minor | `12.6.0` → `12.7.0` | | [gitea/gitea](https://github.com/go-gitea/gitea) | | minor | `1.25.4` → `1.27.3` | | [github-cli](https://cli.github.com/) | | minor | `latest` → `0.12.0` | | [grafana](https://grafana.com) ([source](https://github.com/grafana/helm-charts)) | | minor | `8.0.0` → `8.15.0` | | [kind](https://github.com/kubernetes-sigs/kind) | | minor | `0.29.0` → `0.32.0` | | [kubecm](https://github.com/sunny0826/kubecm) | | minor | `0.33.1` → `0.35.1` | | [kubectl](https://github.com/kubernetes/kubectl) | | minor | `1.33.2` → `1.36.3` | | [kubernetes-helm](https://github.com/helm/helm) | | minor | `3.18.4` → `3.20.2` | | [kubeseal](https://github.com/bitnami/sealed-secrets) | | minor | `0.30.0` → `0.38.4` | | [kustomize](https://github.com/kubernetes-sigs/kustomize) | | minor | `5.7.0` → `5.8.1` | | [kyverno](https://kyverno.io/) | | minor | `1.14.3` → `1.19.0` | | [loki](https://grafana.github.io/helm-charts) ([source](https://github.com/grafana/helm-charts)) | | minor | `7.0.0` → `7.3.0` | | nikitafilonov/ai-review | docker | minor | `v0.64.0` → `v0.77.0` | | [opencost](https://github.com/opencost/opencost-helm-chart) | | minor | `1.42.0` → `1.43.2` | | [opentofu](https://opentofu.org/) | | minor | `1.11.6` → `1.12.5` | | [prometheus](https://prometheus.io/) ([source](https://github.com/prometheus-community/helm-charts)) | | minor | `28.9.0` → `28.16.0` | | [syft](https://github.com/anchore/syft) | | minor | `1.29.0` → `1.51.0` | | [traefik](https://traefik.io) | | minor | `3.6.7` → `3.7.10` | | [traefik](https://traefik.io/) ([source](https://github.com/traefik/traefik-helm-chart)) | | minor | `28.0.0` → `28.3.0` | | [upcloud-cli](https://github.com/UpCloudLtd/upcloud-cli) | | minor | `3.29.0` → `3.36.0` | | [vaultwarden](https://github.com/guerzon/vaultwarden) | | minor | `0.36.4` → `0.46.2` | --- ### Release Notes <details> <summary>gitea/helm-actions (actions)</summary> ### [`v0.1.2`](https://gitea.com/gitea/helm-actions/releases/tag/v0.1.2) [Compare Source](https://gitea.com/gitea/helm-actions/compare/v0.1.1...v0.1.2) #### What's Changed - feat: add per-container resource configuration for runner and DinD [#&#8203;160](https://github.com/gitea/helm-actions/issues/160) in [#&#8203;168](https://gitea.com/gitea/helm-actions/pulls/168) - chore(deps): update workflow dependencies (minor & patch) in [#&#8203;172](https://gitea.com/gitea/helm-actions/pulls/172) - chore(deps): update commitlint/commitlint docker tag to v21.2.0 in [#&#8203;169](https://gitea.com/gitea/helm-actions/pulls/169) - chore: bump runner in [#&#8203;171](https://gitea.com/gitea/helm-actions/pulls/171) - feat: customize init command in [#&#8203;166](https://gitea.com/gitea/helm-actions/pulls/166) - chore(deps): update lockfiles in [#&#8203;167](https://gitea.com/gitea/helm-actions/pulls/167) - chore(deps): update lockfiles in [#&#8203;165](https://gitea.com/gitea/helm-actions/pulls/165) - chore(deps): update workflow dependencies (minor & patch) in [#&#8203;163](https://gitea.com/gitea/helm-actions/pulls/163) - chore(deps): update lockfiles in [#&#8203;157](https://gitea.com/gitea/helm-actions/pulls/157) - chore(deps): update actions/checkout action to v7 in [#&#8203;164](https://gitea.com/gitea/helm-actions/pulls/164) - chore(deps): update workflow dependencies (minor & patch) in [#&#8203;161](https://gitea.com/gitea/helm-actions/pulls/161) - chore(deps): update dependency helm-unittest/helm-unittest to v1.1.1 in [#&#8203;159](https://gitea.com/gitea/helm-actions/pulls/159) - chore(deps): update commitlint/commitlint docker tag to v21.0.2 in [#&#8203;158](https://gitea.com/gitea/helm-actions/pulls/158) - chore(deps): update busybox docker tag to v1.38.0 in [#&#8203;155](https://gitea.com/gitea/helm-actions/pulls/155) - chore(deps): update lockfiles in [#&#8203;156](https://gitea.com/gitea/helm-actions/pulls/156) - chore(deps): update lockfiles in [#&#8203;154](https://gitea.com/gitea/helm-actions/pulls/154) - chore(deps): update lockfiles in [#&#8203;153](https://gitea.com/gitea/helm-actions/pulls/153) #### Contributors - @&#8203;Arnault\_LPC - [@&#8203;renovate-bot](https://github.com/renovate-bot) - [@&#8203;DaanSelen](https://github.com/DaanSelen) #### New Contributors - @&#8203;Arnault\_LPC made their first contribution in [#&#8203;168](https://gitea.com/gitea/helm-actions/pulls/168) **Full Changelog**: [v0.1.1...v0.1.2](https://gitea.com/gitea/helm-actions/compare/v0.1.1...v0.1.2) ### [`v0.1.1`](https://gitea.com/gitea/helm-actions/releases/tag/v0.1.1) [Compare Source](https://gitea.com/gitea/helm-actions/compare/v0.1.0...v0.1.1) #### What's Changed - chore(deps): update lockfiles in [#&#8203;151](https://gitea.com/gitea/helm-actions/pulls/151) - feat: rename any form of act runner to gitea runner or runner in [#&#8203;149](https://gitea.com/gitea/helm-actions/pulls/149) - chore(deps): update commitlint/commitlint docker tag to v21 in [#&#8203;147](https://gitea.com/gitea/helm-actions/pulls/147) - chore(deps): update workflow dependencies (minor & patch) in [#&#8203;146](https://gitea.com/gitea/helm-actions/pulls/146) - chore(deps): update lockfiles in [#&#8203;141](https://gitea.com/gitea/helm-actions/pulls/141) - chore(deps): update dependency pnpm to v11 in [#&#8203;145](https://gitea.com/gitea/helm-actions/pulls/145) - chore(deps): update commitlint/commitlint docker tag to v20.5.3 in [#&#8203;140](https://gitea.com/gitea/helm-actions/pulls/140) - chore(deps): update workflow dependencies (minor & patch) in [#&#8203;138](https://gitea.com/gitea/helm-actions/pulls/138) #### Contributors - [@&#8203;renovate-bot](https://github.com/renovate-bot) - [@&#8203;DaanSelen](https://github.com/DaanSelen) **Full Changelog**: [v0.1.0...v0.1.1](https://gitea.com/gitea/helm-actions/compare/v0.1.0...v0.1.1) ### [`v0.1.0`](https://gitea.com/gitea/helm-actions/releases/tag/v0.1.0) [Compare Source](https://gitea.com/gitea/helm-actions/compare/v0.0.5...v0.1.0) #### What's Changed - chore(deps): update lockfiles in [#&#8203;131](https://gitea.com/gitea/helm-actions/pulls/131) - chore(deps): update lockfiles in [#&#8203;130](https://gitea.com/gitea/helm-actions/pulls/130) - chore(deps): update alpine/helm docker tag to v4.1.4 in [#&#8203;128](https://gitea.com/gitea/helm-actions/pulls/128) - chore(deps): update pnpm/action-setup action to v6 in [#&#8203;129](https://gitea.com/gitea/helm-actions/pulls/129) - fix: <https://gitea.com/gitea/helm-actions/issues/132> #### Contributors - [@&#8203;renovate-bot](https://github.com/renovate-bot) **Full Changelog**: [v0.0.5...v0.1.0](https://gitea.com/gitea/helm-actions/compare/v0.0.5...v0.1.0) </details> <details> <summary>cert-manager/cert-manager (cert-manager)</summary> ### [`v1.21.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.21.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.21.1...v1.21.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities. All users should upgrade. #### Changes by Kind ##### Bug or Regression - ACME Issuer response bodies are no longer reflected into Issuer status conditions or Kubernetes Events. Only ACME problem documents are surfaced (bounded in length); other responses are reported by HTTP status code alone, with the full error available in the controller logs. ([#&#8203;9239](https://github.com/cert-manager/cert-manager/issues/9239), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - Cap ACME server response bodies at 16 MiB to guard against unbounded-body denial-of-service. ([#&#8203;9222](https://github.com/cert-manager/cert-manager/issues/9222), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - De-duplicate dnsNames when multiple Gateway/ListenerSet listeners share a Secret ([#&#8203;9234](https://github.com/cert-manager/cert-manager/issues/9234), [@&#8203;speer](https://github.com/speer)) - Fix certificate renewal windows using February 29 cron schedules across non-leap century years. ([#&#8203;9240](https://github.com/cert-manager/cert-manager/issues/9240), [@&#8203;wieghx](https://github.com/wieghx)) - Fix validating webhook panics when AdmissionReview requests omit optional fields, by routing identity, approval, and resource validation on the always-present Resource/SubResource fields and denying (rather than silently allowing) requests with an unset or mismatched resource. As a side effect, validation is now also enforced for equivalent-converted requests on non-v1 API versions, which previously could skip validation. ([#&#8203;9235](https://github.com/cert-manager/cert-manager/issues/9235), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Fixed HTTP-01 solver cleanup so that a solver ingress, pod or service that has already been deleted no longer fails the cleanup with a NotFound error. ([#&#8203;9278](https://github.com/cert-manager/cert-manager/issues/9278), [@&#8203;arpitjain099](https://github.com/arpitjain099)) - Fixed a bug where `replaces` field was being populated for the wrong issuer on issuer changes ([#&#8203;9236](https://github.com/cert-manager/cert-manager/issues/9236), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Fixed a data race in the ACME HTTP-01 self-check that could occur when custom DNS servers were configured. ([#&#8203;9313](https://github.com/cert-manager/cert-manager/issues/9313), [@&#8203;shashankvarma499](https://github.com/shashankvarma499)) - Fixed a panic in the certificates-issuing controller when a CertificateRequest has a failure time set but no Ready condition. ([#&#8203;9238](https://github.com/cert-manager/cert-manager/issues/9238), [@&#8203;thc1006](https://github.com/thc1006)) - Fixed a race in pkg/scheduler where the cleanup of a fired timer could cancel a newer timer scheduled for the same object, silently dropping a rescheduled poll. ([#&#8203;9312](https://github.com/cert-manager/cert-manager/issues/9312), [@&#8203;shashankvarma499](https://github.com/shashankvarma499)) - Fixed an issue where the body of a non-Vault HTTP response from `spec.vault.server` could be copied into the Vault Issuer's Ready condition and its Kubernetes Events. Such responses now report only the HTTP status code, and Vault's own error messages are truncated before being persisted. ([#&#8203;9262](https://github.com/cert-manager/cert-manager/issues/9262), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects ([#&#8203;9314](https://github.com/cert-manager/cert-manager/issues/9314), [@&#8203;KR-Ravindra](https://github.com/KR-Ravindra)) - The ACME HTTP-01 self-check no longer reflects the fetched response body in `Challenge.status.reason`, preventing disclosure of internal response contents reachable via redirects. The response is still available in the controller's debug logs. ([#&#8203;9232](https://github.com/cert-manager/cert-manager/issues/9232), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - The `vault` issuer no longer authenticates to Vault using the cert-manager controller's ambient AWS credentials for AWS IAM auth on a namespaced `Issuer`, unless ambient credentials are explicitly enabled via `--issuer-ambient-credentials`. `ClusterIssuer` and explicit `serviceAccountRef` (IRSA) configurations are unaffected. ([#&#8203;9231](https://github.com/cert-manager/cert-manager/issues/9231), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) ##### Other (Cleanup or Flake) - Upgrade Go to 1.26.6, which includes security fixes to the go command, and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages. ([#&#8203;9151](https://github.com/cert-manager/cert-manager/issues/9151), [@&#8203;wallrj](https://github.com/wallrj)) - Upgrade Go to 1.26.8. ([#&#8203;9323](https://github.com/cert-manager/cert-manager/issues/9323), [@&#8203;wallrj](https://github.com/wallrj)) - Bump `google.golang.org/grpc` to v1.83.2 to fix reported security vulnerabilities ([#&#8203;9255](https://github.com/cert-manager/cert-manager/issues/9255), [#&#8203;9317](https://github.com/cert-manager/cert-manager/issues/9317)) - Bump `golang.org/x/crypto` to v0.56.0 to fix reported security vulnerabilities ([#&#8203;9265](https://github.com/cert-manager/cert-manager/issues/9265)) ### [`v1.21.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.21.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.21.0...v1.21.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.21.1 fixes a controller panic for Certificates with `spec.renewal.policy: Disabled`, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck at `Ready=False` (`InvalidSolver`) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities. All users should upgrade. #### Changes by Kind ##### Bug or Regression - Avoid controller panic if a Certificate sets spec.renewal.policy=Disabled ([#&#8203;9038](https://github.com/cert-manager/cert-manager/issues/9038), [@&#8203;sklirg](https://github.com/sklirg)) - Fix Issuer/ClusterIssuer stuck at Ready=False/InvalidSolver after a missing ACME DNS-01 solver Secret is created ([#&#8203;9083](https://github.com/cert-manager/cert-manager/issues/9083), [@&#8203;SebTardif](https://github.com/SebTardif)) - Fix log spam and dropped Secret informer events for non-cert-manager Secrets, caused by a generics regression introduced in 1.21.0. ([#&#8203;9037](https://github.com/cert-manager/cert-manager/issues/9037), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Fixed the commented Gateway API config example in the Helm chart values to use `gatewayAPI.enabled` instead of the invalid `gatewayAPI.enable`. ([#&#8203;9012](https://github.com/cert-manager/cert-manager/issues/9012), [@&#8203;mateenali66](https://github.com/mateenali66)) ##### Other (Cleanup or Flake) - Bump `golang.org/x/text` to v0.40.0 to fix a reported security vulnerability ([#&#8203;9039](https://github.com/cert-manager/cert-manager/issues/9039), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Bump `google.golang.org/grpc` to v1.82.1 to fix a reported security vulnerability ([#&#8203;9063](https://github.com/cert-manager/cert-manager/issues/9063)) - Bump `github.com/google/cel-go` to v0.29.0 to fix a reported security vulnerability ([#&#8203;9072](https://github.com/cert-manager/cert-manager/issues/9072)) - Bump `go.opentelemetry.io/otel` to v1.44.0 to fix a reported security vulnerability ([#&#8203;9073](https://github.com/cert-manager/cert-manager/issues/9073)) - Update distroless base images ([#&#8203;9000](https://github.com/cert-manager/cert-manager/issues/9000), [#&#8203;9025](https://github.com/cert-manager/cert-manager/issues/9025)) ### [`v1.21.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.21.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.4...v1.21.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values — review them carefully before upgrading. #### Known Issues - **Controller crash-loops when a Certificate sets `renewal.policy: Disabled`**: the new Certificate renewal policies feature ([#&#8203;8258](https://github.com/cert-manager/cert-manager/issues/8258)) causes a nil pointer dereference panic in the trigger controller whenever a Certificate's `spec.renewal.policy` is set to `Disabled` — `pki.RenewalTime()` returns `(nil, nil)` for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. **Workaround**: do not set `renewal.policy: Disabled` on any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See [#&#8203;9031](https://github.com/cert-manager/cert-manager/issues/9031) for details. - **Log spam for non-cert-manager-labelled Secret events**: the typed predicates refactoring ([#&#8203;8407](https://github.com/cert-manager/cert-manager/issues/8407)) causes `filteredEventHandler` type assertion failures (`"OnAdd missing Object"`, `"OnUpdate missing ObjectOld"`, `"OnDelete missing Object"`) for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. **This is cosmetic only** — the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See [#&#8203;8994](https://github.com/cert-manager/cert-manager/issues/8994) for details. - **Issuer/ClusterIssuer can get stuck at `Ready: False, Reason: InvalidSolver` and never self-correct**: new eager validation of ACME solver Secrets ([#&#8203;8255](https://github.com/cert-manager/cert-manager/issues/8255)) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly report `Ready: False`, but creating the missing Secret afterwards does not trigger re-reconciliation — the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. **Workaround**: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See [#&#8203;9036](https://github.com/cert-manager/cert-manager/issues/9036) for details and a fix proposal. #### Major Themes ##### Default `tokenrequest` RBAC removed from Helm chart > ⚠️ Breaking change The Helm chart no longer creates a default `Role` and `RoleBinding` granting the cert-manager controller permission to create tokens for its own ServiceAccount (`serviceaccounts/token: create`). No documented workflow requires this RBAC — the Route53 docs section that motivated it was removed in 2024. If you use `serviceAccountRef.name` pointing at the controller ServiceAccount, you must now either create your own `Role`/`RoleBinding` granting `serviceaccounts/token: create`, or migrate to a dedicated ServiceAccount (recommended — see the [Vault](https://cert-manager.io/docs/configuration/vault/) or [Route53](https://cert-manager.io/docs/configuration/acme/dns01/route53/) documentation). ##### Restrict Challenge and Order RBAC in `cert-manager-edit` ClusterRole > ⚠️ Potentially breaking change The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io` ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). These resources are internal to cert-manager's ACME workflow. Challenge `patch` and `update` are retained because users may need them to remove stuck finalizers. This change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant those permissions explicitly. ##### Metrics port name and path Helm values removed > ⚠️ Breaking change The Helm values `prometheus.servicemonitor.targetPort`, `prometheus.servicemonitor.path`, and `prometheus.podmonitor.path` have been removed. The controller Service metrics port has been renamed from `tcp-prometheus-servicemonitor` to `http-metrics`. Because the Helm values schema uses `additionalProperties: false`, users who still have any of the removed keys in their values overrides will see a schema validation error on upgrade — remove them before upgrading. ([#&#8203;8952](https://github.com/cert-manager/cert-manager/issues/8952)) ##### ACME and Certificate Management - **ACME Renewal Information (ARI)**: experimental support for [RFC 9773](https://www.rfc-editor.org/rfc/rfc9773) behind the `ACMEUseARI` feature gate. When enabled, cert-manager queries the ACME server's `renewalInfo` endpoint for the recommended renewal window, allowing servers like Let's Encrypt to proactively prompt renewal during mass revocations or CA key rollovers. ([#&#8203;8798](https://github.com/cert-manager/cert-manager/issues/8798)) - **`waitInsteadOfSelfCheck` solver option**: skip cert-manager's own self-check and instead wait a configured duration before asking the ACME server to validate. An escape hatch for split-horizon DNS and NAT hairpin environments. See [configuration details](https://cert-manager.io/docs/configuration/acme/#skip-the-self-check-with-waitinsteadofselfcheck). ([#&#8203;8858](https://github.com/cert-manager/cert-manager/issues/8858)) - **AWS IAM authentication for Vault**: the Vault issuer now supports IRSA, EKS Pod Identity, and ambient EC2/ECS credentials, removing the need for long-lived AWS Secrets. ([#&#8203;8422](https://github.com/cert-manager/cert-manager/issues/8422)) - **Certificate renewal policies**: a new `renewalPolicies` field on the Certificate API provides more expressive control over renewal scheduling, complementing `renewBefore` and `renewBeforePercentage`. ([#&#8203;8258](https://github.com/cert-manager/cert-manager/issues/8258)) - **Configurable CertificateRequest retry backoff**: the new `--certificate-request-maximum-backoff-duration` flag (default: 32 hours) caps the exponential backoff for failed CertificateRequests, useful for environments with scheduled CA maintenance windows. ([#&#8203;8893](https://github.com/cert-manager/cert-manager/issues/8893)) - **Modern2026 [PKCS#12](https://github.com/PKCS/cert-manager/issues/12) profile**: a new FIPS 140-3 compatible encoding profile using AES-256 + SHA-256 KDFs instead of legacy 3DES/RC2. ([#&#8203;8841](https://github.com/cert-manager/cert-manager/issues/8841)) - **Webhook certificate renewal after system suspend**: the webhook now detects missed certificate renewals after system suspend (S3/S4) or VM live migration by polling wall-clock time, recovering within one minute of resume. ([#&#8203;8464](https://github.com/cert-manager/cert-manager/issues/8464)) ##### Gateway API and cainjector - **HTTP01 ListenerSet parentRef fallback**: the `acme.cert-manager.io/http01-parentreffallback: "true"` annotation causes cert-manager to use the parent Gateway for solver HTTPRoutes instead of the ListenerSet, enabling TLS-only ListenerSets to use a shared HTTP listener for ACME challenges. ([#&#8203;8749](https://github.com/cert-manager/cert-manager/issues/8749)) - **`cert-manager.io/ignore-tls-listeners` annotation**: exclude specific Gateway TLS listeners from certificate management. ([#&#8203;8727](https://github.com/cert-manager/cert-manager/issues/8727)) - **Additional listener protocols**: configurable listener protocols beyond the default set. ([#&#8203;8683](https://github.com/cert-manager/cert-manager/issues/8683)) - **`enableGatewayAPI` configuration restructure**: `enableGatewayAPI` and `enableGatewayAPIListenerSet` are deprecated in favor of `gatewayAPI.enabled` / `gatewayAPI.enableListenerSet`. The old fields continue to work. ([#&#8203;8732](https://github.com/cert-manager/cert-manager/issues/8732)) - **`CAInjectorMerging` promoted to GA**: unconditionally enabled; will be removed in a future release. ([#&#8203;8583](https://github.com/cert-manager/cert-manager/issues/8583)) - **cainjector server-side apply unconditional**: the `ServerSideApply` feature gate is deprecated. ([#&#8203;8692](https://github.com/cert-manager/cert-manager/issues/8692)) - **cainjector `--ignore-namespaces` flag**: skip specified namespaces when watching Secrets for injection. ([#&#8203;8614](https://github.com/cert-manager/cert-manager/issues/8614)) ##### Deployment and Observability - **Venafi OAuth token observability**: a new `AuthFailed` Issuer condition reason distinguishes bad credentials from transient errors. PANW NGTS is now supported as a Venafi backend. ([#&#8203;8808](https://github.com/cert-manager/cert-manager/issues/8808), [#&#8203;8779](https://github.com/cert-manager/cert-manager/issues/8779)) - **`runtimeClassName` support**: configurable for cert-manager components and ACME HTTP01 solver pods. ([#&#8203;8791](https://github.com/cert-manager/cert-manager/issues/8791), [#&#8203;8976](https://github.com/cert-manager/cert-manager/issues/8976)) - **`startupapicheck.ttlSecondsAfterFinished`**: opt-in automatic cleanup of the startupapicheck Job. ([#&#8203;8523](https://github.com/cert-manager/cert-manager/issues/8523)) - **`--acme-http01-solver-extra-labels`**: propagate `global.commonLabels` to dynamically-created ACME HTTP01 solver resources. ([#&#8203;8761](https://github.com/cert-manager/cert-manager/issues/8761)) ##### Notable Bug Fixes - **Integer overflow in `renewBeforePercentage`**: Certificates with durations longer than approximately 3 years were incorrectly rejected or assigned incorrect renewal times. ([#&#8203;8947](https://github.com/cert-manager/cert-manager/issues/8947)) - **Infinite re-issuance loop**: cert-manager no longer loops when an issuer returns an already-expired certificate. ([#&#8203;8610](https://github.com/cert-manager/cert-manager/issues/8610)) - **ACME transient network errors**: challenges no longer permanently fail on TLS handshake timeouts, DNS resolution failures, or context cancellation during nonce fetches and authorization waits. ([#&#8203;8760](https://github.com/cert-manager/cert-manager/issues/8760)) - **DNS-over-HTTPS response body cap**: response body reads are now bounded at 128 KB to prevent potential OOM. ([#&#8203;8803](https://github.com/cert-manager/cert-manager/issues/8803)) - **Vault path traversal**: the Vault issuer webhook now rejects `..` path segments, preventing `path.Join` from silently resolving relative segments. ([#&#8203;8930](https://github.com/cert-manager/cert-manager/issues/8930)) - **DNS issuer secrets validated before ready**: prevents silent misconfiguration. ([#&#8203;8255](https://github.com/cert-manager/cert-manager/issues/8255)) #### Community As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved. A special thanks to: - [@&#8203;Copilot](https://github.com/Copilot) - [@&#8203;FelixPhipps](https://github.com/FelixPhipps) - [@&#8203;Peac36](https://github.com/Peac36) - [@&#8203;SebTardif](https://github.com/SebTardif) - [@&#8203;apkatsikas](https://github.com/apkatsikas) - [@&#8203;bitloi](https://github.com/bitloi) - [@&#8203;dap0am](https://github.com/dap0am) - [@&#8203;figaw](https://github.com/figaw) - [@&#8203;immanuwell](https://github.com/immanuwell) - [@&#8203;jabbrwcky](https://github.com/jabbrwcky) - [@&#8203;jnohlgard](https://github.com/jnohlgard) - [@&#8203;jsoref](https://github.com/jsoref) - [@&#8203;ltwongaa](https://github.com/ltwongaa) - [@&#8203;lunarwhite](https://github.com/lunarwhite) - [@&#8203;mateenali66](https://github.com/mateenali66) - [@&#8203;onurmicoogullari](https://github.com/onurmicoogullari) - [@&#8203;putongyong](https://github.com/putongyong) - [@&#8203;seanorama](https://github.com/seanorama) - [@&#8203;texasich](https://github.com/texasich) for their contributions, comments and support! Also, thanks to the cert-manager maintainer team for their help in this release: - [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish) - [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot) - [@&#8203;erikgb](https://github.com/erikgb) - [@&#8203;hjoshi123](https://github.com/hjoshi123) - [@&#8203;inteon](https://github.com/inteon) - [@&#8203;maelvls](https://github.com/maelvls) - [@&#8203;munnerz](https://github.com/munnerz) - [@&#8203;wallrj](https://github.com/wallrj) - [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark) And finally, thanks to the cert-manager steering committee for their feedback in this release cycle: - [@&#8203;FlorianLiebhart](https://github.com/FlorianLiebhart) - [@&#8203;TrilokGeer](https://github.com/TrilokGeer) - [@&#8203;ianarsenault](https://github.com/ianarsenault) - [@&#8203;ssyno](https://github.com/ssyno) #### Changes since v1.20.0 ##### Feature - Add Venafi OAuth token request observability and a new `AuthFailed` Issuer condition reason to distinguish bad credentials from transient infrastructure errors. ([#&#8203;8808](https://github.com/cert-manager/cert-manager/issues/8808), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - Add `certificateRequestMaximumBackoffDuration` controller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file, `--certificate-request-maximum-backoff-duration` CLI flag, or Helm value `config.certificateRequestMaximumBackoffDuration`. Defaults to 32 hours for backward compatibility. ([#&#8203;8893](https://github.com/cert-manager/cert-manager/issues/8893), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Add an optional `waitInsteadOfSelfCheck` field to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. ([#&#8203;8858](https://github.com/cert-manager/cert-manager/issues/8858), [@&#8203;wallrj](https://github.com/wallrj)) - Add configurable `runtimeClassName` support for cert-manager components and ACME HTTP01 solver pods. ([#&#8203;8791](https://github.com/cert-manager/cert-manager/issues/8791), [@&#8203;jsoref](https://github.com/jsoref)) - Add direct configurable `runtimeClassName` support for ACME HTTP01 solver pods via the `acmesolver.runtimeClassName` Helm value. ([#&#8203;8976](https://github.com/cert-manager/cert-manager/issues/8976), [@&#8203;erikgb](https://github.com/erikgb)) - Add new controller flag `--acme-http01-solver-extra-labels`, allowing Helm's `global.commonLabels` to propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). ([#&#8203;8761](https://github.com/cert-manager/cert-manager/issues/8761), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Add opt-in `startupapicheck.ttlSecondsAfterFinished` Helm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. ([#&#8203;8523](https://github.com/cert-manager/cert-manager/issues/8523), [@&#8203;dap0am](https://github.com/dap0am)) - Added ARI support through the ACMEUseARI feature gate. ([#&#8203;8798](https://github.com/cert-manager/cert-manager/issues/8798), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Added AWS IAM authentication support for Vault issuer, including IRSA (IAM Roles for Service Accounts) and ambient credentials (EC2/ECS). ([#&#8203;8422](https://github.com/cert-manager/cert-manager/issues/8422), [@&#8203;bitloi](https://github.com/bitloi)) - Added `cert-manager.io/ignore-tls-listeners` annotation for ignoring gwapi listeners. ([#&#8203;8727](https://github.com/cert-manager/cert-manager/issues/8727), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Added option to specify additional listener protocols the GatewayAPI integration will consider when creating certificates. ([#&#8203;8683](https://github.com/cert-manager/cert-manager/issues/8683), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Adds support for the Modern2026 go-pkcs12 profile and FIPS 140-3 ([#&#8203;8841](https://github.com/cert-manager/cert-manager/issues/8841), [@&#8203;seanorama](https://github.com/seanorama)) - Cainjector: A new flag `--ignore-namespaces` was added to the cainjector binary. It can be used to filter out namespaces from being watched for secrets to use for injectables. ([#&#8203;8614](https://github.com/cert-manager/cert-manager/issues/8614), [@&#8203;figaw](https://github.com/figaw)) - Disabled client side rate-limiting if AP\&F is enabled. ([#&#8203;8757](https://github.com/cert-manager/cert-manager/issues/8757), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Extend the Venafi/CyberArk integration to also support PANW NGTS. ([#&#8203;8779](https://github.com/cert-manager/cert-manager/issues/8779), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - Adding certificate renewal policies ([#&#8203;8258](https://github.com/cert-manager/cert-manager/issues/8258), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Make cainjector use SSA unconditionally and deprecate the ServerSideApply feature gate ([#&#8203;8692](https://github.com/cert-manager/cert-manager/issues/8692), [@&#8203;erikgb](https://github.com/erikgb)) - Processed annotations `cert-manager.io/alt-names`, `cert-manager.io/ip-sans` to Certificates generated from ingress like objects in cert-shim controllers. ([#&#8203;8927](https://github.com/cert-manager/cert-manager/issues/8927), [@&#8203;jabbrwcky](https://github.com/jabbrwcky)) - Promote the CAInjectorMerging feature gate to GA ([#&#8203;8583](https://github.com/cert-manager/cert-manager/issues/8583), [@&#8203;Copilot](https://github.com/Copilot)) - When using ACME HTTP-01 with a ListenerSet, setting the annotation `acme.cert-manager.io/http01-parentreffallback: "true"` causes cert-manager to use the parent Gateway as the solver HTTPRoute parentRef instead of the ListenerSet. This enables TLS-only ListenerSets to rely on a shared Gateway HTTP listener for ACME challenges. ([#&#8203;8749](https://github.com/cert-manager/cert-manager/issues/8749), [@&#8203;apkatsikas](https://github.com/apkatsikas)) ##### Bug or Regression - **BREAKING**: The Helm chart no longer ships a default `Role` and `RoleBinding` granting the cert-manager controller ServiceAccount permission to create tokens for itself (`serviceaccounts/token: create`). This RBAC was added in v1.16 ([#&#8203;7213](https://github.com/cert-manager/cert-manager/issues/7213)) but no documented workflow requires it, and the motivating Route53 docs section was removed in Oct 2024. If you rely on `serviceAccountRef.name` pointing at the controller ServiceAccount (an undocumented pattern), you must now create your own `Role` and `RoleBinding` granting `serviceaccounts/token: create` on that ServiceAccount, or migrate to one of the documented patterns (IRSA ambient, or a dedicated ServiceAccount with its own RBAC). ([#&#8203;8931](https://github.com/cert-manager/cert-manager/issues/8931), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - ACME challenges no longer terminally fail on transient network errors (TLS handshake timeouts, DNS failures, context cancellation) during nonce fetches and authorization waits. The challenge controller returns the error and lets the workqueue retry with backoff. ([#&#8203;8760](https://github.com/cert-manager/cert-manager/issues/8760), [@&#8203;texasich](https://github.com/texasich)) - Add dns issuer secrets validation before marking it as ready ([#&#8203;8255](https://github.com/cert-manager/cert-manager/issues/8255), [@&#8203;Peac36](https://github.com/Peac36)) - Add missing issuer finalizer RBAC to the order controller to support owner references ([#&#8203;8654](https://github.com/cert-manager/cert-manager/issues/8654), [@&#8203;erikgb](https://github.com/erikgb)) - ClusterIssuer metrics collector now correctly respects the enabled-controllers configuration, avoiding a redundant startup when only operating within a namespace. ([#&#8203;8822](https://github.com/cert-manager/cert-manager/issues/8822), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Fix Venafi TPP issuer setup and signing regression on master: restore authentication of the vcert connector in the client constructor, which was removed in [#&#8203;8808](https://github.com/cert-manager/cert-manager/issues/8808). ([#&#8203;8843](https://github.com/cert-manager/cert-manager/issues/8843), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Fix a performance issue in the certificateRequestApproval webhook where CertificateRequests referencing a GroupKind whose CRD is not yet installed would trigger repeated API server discovery queries on every admission request. Negative results are now cached for 30 seconds. ([#&#8203;8651](https://github.com/cert-manager/cert-manager/issues/8651), [@&#8203;mateenali66](https://github.com/mateenali66)) - Fix webhook serving certificate not being renewed after system suspend. ([#&#8203;8464](https://github.com/cert-manager/cert-manager/issues/8464), [@&#8203;Peac36](https://github.com/Peac36)) - Fixed a rare panic in the trigger controller when a Certificate is deleted from the informer cache while a reconcile is in progress (e.g. during namespace teardown). ([#&#8203;8962](https://github.com/cert-manager/cert-manager/issues/8962), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Fixed an integer overflow in `renewBeforePercentage` calculations that caused Certificates with durations longer than approximately 3 years to be incorrectly rejected by validation or assigned incorrect renewal times. ([#&#8203;8947](https://github.com/cert-manager/cert-manager/issues/8947), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Fixed duplicate `parentRef` bug when both issuer config and annotations are present. ([#&#8203;8619](https://github.com/cert-manager/cert-manager/issues/8619), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Fixed infinite re-issuance loop when issuer returns an already expired certificate ([#&#8203;8610](https://github.com/cert-manager/cert-manager/issues/8610), [@&#8203;onurmicoogullari](https://github.com/onurmicoogullari)) - Fixed local `e2e-setup-samplewebhook` installation to use the samplewebhook image repository and tag from the saved image tarball manifest. ([#&#8203;8821](https://github.com/cert-manager/cert-manager/issues/8821), [@&#8203;wallrj](https://github.com/wallrj)) - Fixed potential OOM in DNS-over-HTTPS client by bounding response body read with io.LimitReader (128 KB cap). ([#&#8203;8803](https://github.com/cert-manager/cert-manager/issues/8803), [@&#8203;SebTardif](https://github.com/SebTardif)) - Fixed validation of timezone-prefixed renewal window cron specs without a schedule. ([#&#8203;8813](https://github.com/cert-manager/cert-manager/issues/8813), [@&#8203;immanuwell](https://github.com/immanuwell)) - Helm chart bugfix: rename image helper to avoid umbrella chart conflicts ([#&#8203;8753](https://github.com/cert-manager/cert-manager/issues/8753), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) - Helm: Fix invalid YAML generated when both `webhook.config` and `webhook.volumes` are defined. ([#&#8203;8664](https://github.com/cert-manager/cert-manager/issues/8664), [@&#8203;jnohlgard](https://github.com/jnohlgard)) - Remove ACME Challenge `create` and Order `create`/`patch`/`update` from the cert-manager-edit aggregate ClusterRole to prevent direct manipulation of these internal resources (GHSA-8rvj-mm4h-c258). ([#&#8203;8958](https://github.com/cert-manager/cert-manager/issues/8958), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8743](https://github.com/cert-manager/cert-manager/issues/8743), [@&#8203;erikgb](https://github.com/erikgb)) - Update logic to identify and preserve the secret matching nextPrivateKeySecretName ([#&#8203;8577](https://github.com/cert-manager/cert-manager/issues/8577), [@&#8203;putongyong](https://github.com/putongyong)) - Vault Issuer webhook validation now rejects `..` path segments in `spec.vault.path` and auth mount path fields, preventing `path.Join` from silently resolving relative segments before constructing the Vault API request. ([#&#8203;8930](https://github.com/cert-manager/cert-manager/issues/8930), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ##### Other (Cleanup or Flake) - API cleanup: removed deprecated ObjectReference ([#&#8203;8625](https://github.com/cert-manager/cert-manager/issues/8625), [@&#8203;inteon](https://github.com/inteon)) - Remove Helm values `prometheus.servicemonitor.targetPort`, `prometheus.servicemonitor.path`, and `prometheus.podmonitor.path`. The metrics path is always `/metrics` and the target port is always `http-metrics`. Rename the controller service metrics port from `tcp-prometheus-servicemonitor` to `http-metrics` for consistency with other workloads. Users must remove these keys from their value overrides before upgrading. ([#&#8203;8952](https://github.com/cert-manager/cert-manager/issues/8952), [@&#8203;erikgb](https://github.com/erikgb)) - The `enableGatewayAPI` and `enableGatewayAPIListenerSet` fields on `ControllerConfiguration` are deprecated and moved into the `gatewayAPI` sub-struct as `gatewayAPI.enabled` and `gatewayAPI.enableListenerSet`. The old fields continue to work. ([#&#8203;8732](https://github.com/cert-manager/cert-manager/issues/8732), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Update base images to Debian 13 ([#&#8203;8849](https://github.com/cert-manager/cert-manager/issues/8849), [@&#8203;ltwongaa](https://github.com/ltwongaa)) ### [`v1.20.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.3...v1.20.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release updates Go and several dependencies to fix reported security vulnerabilities, and fixes a bug where ingress-shim removed the applyset label from cached Ingress and Gateway objects. All users should upgrade. > \[!NOTE] > **Security scanners still report three `golang.org/x/crypto` findings.** None of them affects cert-manager and we do not plan to fix them in the 1.20 line. > > - [CVE-2026-56855](https://nvd.nist.gov/vuln/detail/CVE-2026-56855) and [CVE-2026-78662](https://nvd.nist.gov/vuln/detail/CVE-2026-78662) are deadlocks in the `golang.org/x/crypto/ssh` connection multiplexer, triggered by a malicious SSH peer after a connection is established. cert-manager never opens an SSH connection. Only the controller links the `ssh` package, through `vcert`, which uses it to format a public key. The fix, `golang.org/x/crypto` v0.56.0, requires Go language version 1.26, which we will not adopt in a patch release. `govulncheck` confirms the vulnerable functions are not called. > - [GO-2026-5932](https://pkg.go.dev/vuln/GO-2026-5932) marks `golang.org/x/crypto/openpgp` as unmaintained. cert-manager does not import that package and there is no fixed version. > > cert-manager 1.21 already uses `golang.org/x/crypto` v0.56.0, so upgrade to 1.21 if you need a clean scan. #### Changes by Kind ##### Bug or Regression - Ingress-shim no longer removes the applyset label from cached Ingress and Gateway objects ([#&#8203;9315](https://github.com/cert-manager/cert-manager/issues/9315), [@&#8203;KR-Ravindra](https://github.com/KR-Ravindra)) ##### Other (Cleanup or Flake) - Update Go to 1.26.5 and then 1.26.6, which include security fixes to the go command, and the crypto/tls, encoding/asn1, encoding/xml, html/template, net, net/http, and net/url packages ([#&#8203;8995](https://github.com/cert-manager/cert-manager/issues/8995), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark); [#&#8203;9152](https://github.com/cert-manager/cert-manager/issues/9152), [@&#8203;wallrj](https://github.com/wallrj)) - Bump `golang.org/x/net` to v0.58.0, `golang.org/x/text` to v0.41.0 and `golang.org/x/crypto` to v0.55.0 to fix [CVE-2026-46600](https://nvd.nist.gov/vuln/detail/CVE-2026-46600), [CVE-2026-56852](https://nvd.nist.gov/vuln/detail/CVE-2026-56852) and [CVE-2026-56854](https://nvd.nist.gov/vuln/detail/CVE-2026-56854) ([#&#8203;9040](https://github.com/cert-manager/cert-manager/issues/9040), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Bump `google.golang.org/grpc` to v1.83.2 to fix [CVE-2026-84304](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc), [CVE-2026-84445](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj), [CVE-2026-84303](https://nvd.nist.gov/vuln/detail/CVE-2026-84303) and [one further advisory](https://github.com/advisories/GHSA-hrxh-6v49-42gf) ([#&#8203;9062](https://github.com/cert-manager/cert-manager/issues/9062), [#&#8203;9257](https://github.com/cert-manager/cert-manager/issues/9257), [#&#8203;9316](https://github.com/cert-manager/cert-manager/issues/9316)) - Bump `github.com/google/cel-go` to v0.30.0 to fix [a reported vulnerability](https://github.com/advisories/GHSA-gcjh-h69q-9w9g) ([#&#8203;9070](https://github.com/cert-manager/cert-manager/issues/9070), [#&#8203;9186](https://github.com/cert-manager/cert-manager/issues/9186)) - Bump `software.sslmate.com/src/go-pkcs12` to v0.7.2 to fix [a reported vulnerability](https://github.com/advisories/GHSA-mpwr-8vm7-h73f) ([#&#8203;8988](https://github.com/cert-manager/cert-manager/issues/8988)) - Bump `golang.org/x/mod`, `go.opentelemetry.io/otel` and `go.etcd.io/etcd/client/pkg/v3` to versions flagged by security scanners ([#&#8203;9143](https://github.com/cert-manager/cert-manager/issues/9143), [#&#8203;9071](https://github.com/cert-manager/cert-manager/issues/9071), [#&#8203;9185](https://github.com/cert-manager/cert-manager/issues/9185)) - Update the distroless base images ([#&#8203;8991](https://github.com/cert-manager/cert-manager/issues/8991), [#&#8203;9024](https://github.com/cert-manager/cert-manager/issues/9024), [#&#8203;9055](https://github.com/cert-manager/cert-manager/issues/9055), [#&#8203;9325](https://github.com/cert-manager/cert-manager/issues/9325)) - The release staging process now signs `metadata.json` with cosign so the publish step can verify its authenticity ([#&#8203;9090](https://github.com/cert-manager/cert-manager/issues/9090), [@&#8203;FelixPhipps](https://github.com/FelixPhipps)) ### [`v1.20.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.2...v1.20.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint. This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs. All users should upgrade. > \[!WARNING] > **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly. #### Changes by Kind ##### Bug or Regression - Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8940](https://github.com/cert-manager/cert-manager/issues/8940), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Remove issuer owner reference from challenges blocking challenge garbage collection ([#&#8203;8759](https://github.com/cert-manager/cert-manager/issues/8759), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Bump go to 1.26.3, other deps to fix several govulncheck issues ([#&#8203;8789](https://github.com/cert-manager/cert-manager/issues/8789), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update Go to `v1.26.4` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8926](https://github.com/cert-manager/cert-manager/issues/8926), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ### [`v1.20.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.1...v1.20.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.20.2 fixes invalid YAML generated in the Helm chart when both `webhook.config` and `webhook.volumes` are defined, and bumps Go to 1.26.2 along with dependencies to address reported vulnerabilities. #### Changes by Kind ##### Bug or Regression - Helm: Fix invalid YAML generated when both `webhook.config` and `webhook.volumes` are defined. ([#&#8203;8665](https://github.com/cert-manager/cert-manager/issues/8665), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Bump go dependencies with reported vulnerabilities ([#&#8203;8704](https://github.com/cert-manager/cert-manager/issues/8704), [@&#8203;erikgb](https://github.com/erikgb)) - Bump go to 1.26.2 ([#&#8203;8703](https://github.com/cert-manager/cert-manager/issues/8703), [@&#8203;erikgb](https://github.com/erikgb)) ### [`v1.20.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.20.0...v1.20.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.20.1 fixes an issue for OpenShift users that has to do with the finalizer RBAC, bumps gRPC to address a reported non-affecting vulnerability, and fixes a duplicate `parentRef` bug when both issuer config and annotations are present (Gateway API). ##### Bug or Regression - Fixed duplicate `parentRef` bug when both issuer config and annotations are present. ([#&#8203;8658](https://github.com/cert-manager/cert-manager/issues/8658), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Add missing issuer finalizer RBAC to the order controller to support owner references. This was preventing OpenShift users from being able to upgrade to v1.20.0. ([#&#8203;8655](https://github.com/cert-manager/cert-manager/issues/8655), [@&#8203;erikgb](https://github.com/erikgb)) - Bump google.golang.org/grpc to fix vulnerability reported by scanners. This isn't a vulnerability that affects cert-manager, but we are bumping it because it is reported by scanners. ([#&#8203;8657](https://github.com/cert-manager/cert-manager/issues/8657), [@&#8203;erikgb](https://github.com/erikgb)) ### [`v1.20.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.20.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.6...v1.20.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta. #### Changes by Kind ##### Feature - Added a set of flags to permit setting NetworkPolicy across all deployed containers. Remove redundant global IP ranges from example policies. ([#&#8203;8370](https://github.com/cert-manager/cert-manager/issues/8370), [@&#8203;jcpunk](https://github.com/jcpunk)) - Added selectable fields to custom resource definitions for .spec.issuerRef.{group, kind, name} ([#&#8203;8256](https://github.com/cert-manager/cert-manager/issues/8256), [@&#8203;tareksha](https://github.com/tareksha)) - Added support for specifying `imagePullSecrets` in the `startupapicheck-job` Helm template to enable pulling images from private registries. ([#&#8203;8186](https://github.com/cert-manager/cert-manager/issues/8186), [@&#8203;mathieu-clnk](https://github.com/mathieu-clnk)) - Added 'extraContainers' helm chart value, allowing the deployment of arbitrary sidecar containers within the cert-manager operator pod. This can be used to support, for e.g., AWS IAM Roles Anywhere for Route53 DNS01 verification. ([#&#8203;8355](https://github.com/cert-manager/cert-manager/issues/8355), [@&#8203;dancmeyers](https://github.com/dancmeyers)) - Added `parentRef` override annotations on the Certificate resource. ([#&#8203;8518](https://github.com/cert-manager/cert-manager/issues/8518), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Added support for azure private zones for dns01 issuer. ([#&#8203;8494](https://github.com/cert-manager/cert-manager/issues/8494), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Added support for configuring PEM decoding size limits, allowing operators to handle larger certificates and keys. ([#&#8203;7642](https://github.com/cert-manager/cert-manager/issues/7642), [@&#8203;robertlestak](https://github.com/robertlestak)) - Added support for unhealthyPodEvictionPolicy in PodDisruptionBudget ([#&#8203;7728](https://github.com/cert-manager/cert-manager/issues/7728), [@&#8203;jcpunk](https://github.com/jcpunk)) - For Venafi provider, read `venafi.cert-manager.io/custom-fields` annotation on Issuer/ClusterIssuer and use it as base with override/append capabilities on Certificate level. ([#&#8203;8301](https://github.com/cert-manager/cert-manager/issues/8301), [@&#8203;k0da](https://github.com/k0da)) - Improve error message when CA issuers are misconfigured to use a clashing secret name ([#&#8203;8374](https://github.com/cert-manager/cert-manager/issues/8374), [@&#8203;majiayu000](https://github.com/majiayu000)) - Introduce a new Ingress annotation `acme.cert-manager.io/http01-ingress-ingressclassname` to override `http01.ingress.ingressClassName` field in HTTP-01 challenge solvers. ([#&#8203;8244](https://github.com/cert-manager/cert-manager/issues/8244), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Update `global.nodeSelector` to helm chart to perform a `merge` and allow for a single `nodeSelector` to be set across all services. ([#&#8203;8195](https://github.com/cert-manager/cert-manager/issues/8195), [@&#8203;StingRayZA](https://github.com/StingRayZA)) - Vault issuers will now include the Vault server address as one of the default audiences on generated service account tokens. ([#&#8203;8228](https://github.com/cert-manager/cert-manager/issues/8228), [@&#8203;terinjokes](https://github.com/terinjokes)) - Added experimental `XListenerSets` feature gate ([#&#8203;8394](https://github.com/cert-manager/cert-manager/issues/8394), [@&#8203;hjoshi123](https://github.com/hjoshi123)) ##### Documentation - Add GWAPI documentation to NOTES.TXT in helm chart ([#&#8203;8353](https://github.com/cert-manager/cert-manager/issues/8353), [@&#8203;jaxels10](https://github.com/jaxels10)) ##### Bug or Regression - Adds logs for cases when acme server returns us a fatal error in the order controller ([#&#8203;8199](https://github.com/cert-manager/cert-manager/issues/8199), [@&#8203;Peac36](https://github.com/Peac36)) - Fixed an issue where kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed ([#&#8203;8160](https://github.com/cert-manager/cert-manager/issues/8160), [@&#8203;inteon](https://github.com/inteon)) - Changes to the Duration and RenewBefore annotations on ingress and gateway-api resources will now trigger certificate updates. ([#&#8203;8232](https://github.com/cert-manager/cert-manager/issues/8232), [@&#8203;eleanor-merry](https://github.com/eleanor-merry)) - Fix an issue where ACME challenge TXT records are not cleaned up when there are many resource records in CloudDNS. ([#&#8203;8456](https://github.com/cert-manager/cert-manager/issues/8456), [@&#8203;tkna](https://github.com/tkna)) - Fix unregulated retries with the DigitalOcean DNS-01 solver Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging ([#&#8203;8221](https://github.com/cert-manager/cert-manager/issues/8221), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8403](https://github.com/cert-manager/cert-manager/issues/8403), [@&#8203;calm329](https://github.com/calm329)) - Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8424](https://github.com/cert-manager/cert-manager/issues/8424), [@&#8203;SlashNephy](https://github.com/SlashNephy)) - Fixed the HTTP-01 Gateway solver creating invalid HTTPRoutes by not setting spec.hostnames when the challenge DNSName is an IP address. ([#&#8203;8443](https://github.com/cert-manager/cert-manager/issues/8443), [@&#8203;alviss7](https://github.com/alviss7)) - Revert API defaults for issuer reference kind and group introduced in 0.19.0 ([#&#8203;8173](https://github.com/cert-manager/cert-manager/issues/8173), [@&#8203;erikgb](https://github.com/erikgb)) - Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8469](https://github.com/cert-manager/cert-manager/issues/8469), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update Go to `v1.25.5` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8290](https://github.com/cert-manager/cert-manager/issues/8290), [@&#8203;octo-sts](https://github.com/octo-sts)\[bot]) - When Prometheus monitoring is enabled, the metrics label is now set to the intended value of `cert-manager`. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). ([#&#8203;8162](https://github.com/cert-manager/cert-manager/issues/8162), [@&#8203;LiquidPL](https://github.com/LiquidPL)) ##### Other (Cleanup or Flake) - Promoted the OtherNames feature to Beta and enabled it by default ([#&#8203;8288](https://github.com/cert-manager/cert-manager/issues/8288), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Promoting `XListenerSets` feature gate to `ListenerSets` ([#&#8203;8501](https://github.com/cert-manager/cert-manager/issues/8501), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Rebranding of the Venafi Issuer to CyberArk ([#&#8203;8215](https://github.com/cert-manager/cert-manager/issues/8215), [@&#8203;iossifbenbassat123](https://github.com/iossifbenbassat123)) - Switched to SSA for challenge finalizer updates ([#&#8203;8519](https://github.com/cert-manager/cert-manager/issues/8519), [@&#8203;inteon](https://github.com/inteon)) - The default container user (UID) is now 65532 (previously 1000) and the default container group (GID) is now 65532 (previously 0) ([#&#8203;8408](https://github.com/cert-manager/cert-manager/issues/8408), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - The feature-gate DefaultPrivateKeyRotationPolicyAlways moved from Beta to GA and can no longer be disabled. ([#&#8203;8287](https://github.com/cert-manager/cert-manager/issues/8287), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Update cert-manager's ACME client, forked from golang/x/crypto ([#&#8203;8268](https://github.com/cert-manager/cert-manager/issues/8268), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Use the latest version of Kyverno (1.16.2) in the best-practice installation tests ([#&#8203;8389](https://github.com/cert-manager/cert-manager/issues/8389), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - We stopped testing with Coutour due to it not supporting the new XListenerSet resource, and moved to kgateway. ([#&#8203;8426](https://github.com/cert-manager/cert-manager/issues/8426), [@&#8203;hjoshi123](https://github.com/hjoshi123)) ### [`v1.19.6`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.6) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.5...v1.19.6) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release fixes a security issue ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258), HIGH) where the default `cert-manager-edit` aggregate ClusterRole granted namespace users permission to create ACME `Challenge` and `Order` resources directly. A user who could create a `Challenge` referencing a `ClusterIssuer` could supply attacker-controlled solver configuration while cert-manager loaded credentials from the `ClusterIssuer`'s namespace, bypassing Issuer solver selectors (`dnsZones`, `dnsNames`, `matchLabels`). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint. This release also includes Go version bumps to address reported CVEs. All users should upgrade. > \[!WARNING] > **Potentially breaking change:** The `cert-manager-edit` aggregate ClusterRole no longer grants `create` for `challenges.acme.cert-manager.io` or `create`, `patch`, `update` for `orders.acme.cert-manager.io`. These resources are internal to cert-manager's ACME workflow and are not intended to be created or modified directly by users. If you have tooling or workflows that create Challenge or Order resources directly (outside of the normal Certificate → CertificateRequest → Order → Challenge flow), you will need to grant those permissions explicitly. #### Changes by Kind ##### Bug or Regression - Security (HIGH): Remove Challenge `create` and Order `create`, `patch`, `update` verbs from the `cert-manager-edit` aggregate ClusterRole ([`GHSA-8rvj-mm4h-c258`](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-8rvj-mm4h-c258)). ([#&#8203;8941](https://github.com/cert-manager/cert-manager/pull/8941), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ##### Other (Cleanup or Flake) - Update Go to `v1.25.11` to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 ([#&#8203;8925](https://github.com/cert-manager/cert-manager/pull/8925), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Upgrade Go to 1.25.10 to fix reported vulnerabilities, along with other dependency bumps ([#&#8203;8788](https://github.com/cert-manager/cert-manager/pull/8788), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.19.5`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.5) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.4...v1.19.5) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade. #### Changes by Kind ##### Other (Cleanup or Flake) - Bump go dependencies with reported vulnerabilities ([#&#8203;8706](https://github.com/cert-manager/cert-manager/pull/8706), [@&#8203;erikgb](https://github.com/erikgb)) - Bump go to 1.25.8 to address several reported vulnerabilities ([#&#8203;8628](https://github.com/cert-manager/cert-manager/pull/8628), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Bump go to 1.25.9 ([#&#8203;8705](https://github.com/cert-manager/cert-manager/pull/8705), [@&#8203;erikgb](https://github.com/erikgb)) ### [`v1.19.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.3...v1.19.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade. #### Changes by Kind ##### Bug or Regression - Bump go to address CVE-2025-68121 ([#&#8203;8526](https://github.com/cert-manager/cert-manager/issues/8526), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Bump otel SDK to address GO-2026-4394 ([#&#8203;8531](https://github.com/cert-manager/cert-manager/issues/8531), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.19.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.2...v1.19.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release. #### Changes by Kind ##### Bug or Regression - Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8415](https://github.com/cert-manager/cert-manager/issues/8415), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Fixed an issue where HTTP-01 challenges failed when the Host header contained an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8436](https://github.com/cert-manager/cert-manager/issues/8436), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8468](https://github.com/cert-manager/cert-manager/issues/8468), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ##### Other (Cleanup or Flake) - Bump go to 1.25.6 ([#&#8203;8459](https://github.com/cert-manager/cert-manager/issues/8459), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.19.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.1...v1.19.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We updated Go to fix some vulnerabilities in the standard library. > 📖 Read the [full 1.19 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19) on the cert-manager.io website before upgrading. #### Changes since `v1.19.1` ##### Bug or Regression - Address false positive vulnerabilities `CVE-2025-47914` and `CVE-2025-58181` which were reported by Trivy. ([#&#8203;8283](https://github.com/cert-manager/cert-manager/issues/8283), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update Go to `v1.25.5` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8294](https://github.com/cert-manager/cert-manager/issues/8294), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Update `global.nodeSelector` to helm chart to perform a `merge` and allow for a single `nodeSelector` to be set across all services. ([#&#8203;8233](https://github.com/cert-manager/cert-manager/issues/8233), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Update cert-manager's ACME client, forked from `golang/x/crypto` ([#&#8203;8270](https://github.com/cert-manager/cert-manager/issues/8270), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Updated Debian 12 distroless base images ([#&#8203;8326](https://github.com/cert-manager/cert-manager/issues/8326), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ### [`v1.19.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.19.0...v1.19.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We reverted the CRD-based API defaults for `Certificate.Spec.IssuerRef` and `CertificateRequest.Spec.IssuerRef` after they were found to cause unexpected certificate renewals after upgrading to 1.19.0. We will try re-introducing these API defaults in cert-manager `1.20`. We fixed a bug that caused certificates to be re-issued unexpectedly if the `issuerRef` kind or group was changed to one of the "runtime" default values. We upgraded Go to `1.25.3` to address the following security vulnerabilities: `CVE-2025-61724`, `CVE-2025-58187`, `CVE-2025-47912`, `CVE-2025-58183`, `CVE-2025-61723`, `CVE-2025-58186`, `CVE-2025-58185`, `CVE-2025-58188`, and `CVE-2025-61725`. > 📖 Read the [full 1.19 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.19) on the cert-manager.io website before upgrading. Changes since `v1.19.0`: ##### Bug or Regression - BUGFIX: in case kind or group in the `issuerRef` of a Certificate was omitted, upgrading to `1.19.x` incorrectly caused the certificate to be renewed ([#&#8203;8175](https://github.com/cert-manager/cert-manager/issues/8175), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Bump Go to 1.25.3 to fix a backwards incompatible change to the validation of DNS names in X.509 SAN fields which prevented the use of DNS names with a trailing dot ([#&#8203;8177](https://github.com/cert-manager/cert-manager/issues/8177), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Revert API defaults for issuer reference kind and group introduced in 0.19.0 ([#&#8203;8178](https://github.com/cert-manager/cert-manager/issues/8178), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ### [`v1.19.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.6...v1.19.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. > ⚠️ **Known issues**: The following known issues are fixed in [v1.19.1](https://github.com/cert-manager/cert-manager/releases/tag/v1.19.1): > > - [Unexpected certificate renewal after upgrading to 1.19.0](https://github.com/cert-manager/cert-manager/issues/8158) This release focuses on expanding platform compatibility, improving deployment flexibility, enhancing observability, and addressing key reliability issues. > 📖 Read the full release notes at cert-manager.io: <https://cert-manager.io/docs/releases/release-notes/release-notes-1.19> Changes since `v1.18.0`: #### Feature - Add IPv6 rules to the default network policy ([#&#8203;7726](https://github.com/cert-manager/cert-manager/issues/7726), [@&#8203;jcpunk](https://github.com/jcpunk)) - Add `global.nodeSelector` to helm chart to allow for a single `nodeSelector` to be set across all services. ([#&#8203;7818](https://github.com/cert-manager/cert-manager/issues/7818), [@&#8203;StingRayZA](https://github.com/StingRayZA)) - Add a feature gate to default to Ingress `pathType` `Exact` in ACME HTTP01 Ingress challenge solvers. ([#&#8203;7795](https://github.com/cert-manager/cert-manager/issues/7795), [@&#8203;sspreitzer](https://github.com/sspreitzer)) - Add generated `applyconfigurations` allowing clients to make type-safe server-side apply requests for cert-manager resources. ([#&#8203;7866](https://github.com/cert-manager/cert-manager/issues/7866), [@&#8203;erikgb](https://github.com/erikgb)) - Added API defaults to issuer references group (cert-manager.io) and kind (Issuer). ([#&#8203;7414](https://github.com/cert-manager/cert-manager/issues/7414), [@&#8203;erikgb](https://github.com/erikgb)) - Added `certmanager_certificate_challenge_status` Prometheus metric. ([#&#8203;7736](https://github.com/cert-manager/cert-manager/issues/7736), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Added `protocol` field for `rfc2136` DNS01 provider ([#&#8203;7881](https://github.com/cert-manager/cert-manager/issues/7881), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Added experimental field `hostUsers` flag to all pods. Not set by default. ([#&#8203;7973](https://github.com/cert-manager/cert-manager/issues/7973), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Support configurable resource requests and limits for ACME HTTP01 solver pods through ClusterIssuer and Issuer specifications, allowing granular resource management that overrides global `--acme-http01-solver-resource-*` settings. ([#&#8203;7972](https://github.com/cert-manager/cert-manager/issues/7972), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - The `CAInjectorMerging` feature has been promoted to BETA and is now enabled by default ([#&#8203;8017](https://github.com/cert-manager/cert-manager/issues/8017), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - The controller, webhook and ca-injector now log their version and git commit on startup for easier debugging and support. ([#&#8203;8072](https://github.com/cert-manager/cert-manager/issues/8072), [@&#8203;prasad89](https://github.com/prasad89)) - Updated `certificate` metrics to the collector approach. ([#&#8203;7856](https://github.com/cert-manager/cert-manager/issues/7856), [@&#8203;hjoshi123](https://github.com/hjoshi123)) #### Bug or Regression - ACME: Increased challenge authorization timeout to 2 minutes to fix `error waiting for authorization` ([#&#8203;7796](https://github.com/cert-manager/cert-manager/issues/7796), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints ([#&#8203;7816](https://github.com/cert-manager/cert-manager/issues/7816), [@&#8203;kinolaev](https://github.com/kinolaev)) - Enforced ACME HTTP-01 solver validation to properly reject configurations when multiple ingress options (`class`, `ingressClassName`, `name`) are specified simultaneously ([#&#8203;8021](https://github.com/cert-manager/cert-manager/issues/8021), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Increase maximum sizes of PEM certificates and chains which can be parsed in cert-manager, to handle leaf certificates with large numbers of DNS names or other identities ([#&#8203;7961](https://github.com/cert-manager/cert-manager/issues/7961), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Reverted adding the `global.rbac.disableHTTPChallengesRole` Helm option. ([#&#8203;7836](https://github.com/cert-manager/cert-manager/issues/7836), [@&#8203;inteon](https://github.com/inteon)) - This change removes the `path` label of core ACME client metrics and will require users to update their monitoring dashboards and alerting rules if using those metrics. ([#&#8203;8109](https://github.com/cert-manager/cert-manager/issues/8109), [@&#8203;mladen-rusev-cyberark](https://github.com/mladen-rusev-cyberark)) - Use the latest version of `ingress-nginx` in E2E tests to ensure compatibility ([#&#8203;7792](https://github.com/cert-manager/cert-manager/issues/7792), [@&#8203;wallrj](https://github.com/wallrj)) #### Other (Cleanup or Flake) - Helm: Fix naming template of `tokenrequest` RoleBinding resource to improve consistency ([#&#8203;7761](https://github.com/cert-manager/cert-manager/issues/7761), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Improve error messages when certificates, CRLs or private keys fail admission due to malformed or missing PEM data ([#&#8203;7928](https://github.com/cert-manager/cert-manager/issues/7928), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Major upgrade of Akamai SDK. NOTE: The new version has not been fully tested end-to-end due to the lack of cloud infrastructure. ([#&#8203;8003](https://github.com/cert-manager/cert-manager/issues/8003), [@&#8203;hjoshi123](https://github.com/hjoshi123)) - Update kind images to include the Kubernetes 1.33 node image ([#&#8203;7786](https://github.com/cert-manager/cert-manager/issues/7786), [@&#8203;wallrj](https://github.com/wallrj)) - Use `maps.Copy` for cleaner map handling ([#&#8203;8092](https://github.com/cert-manager/cert-manager/issues/8092), [@&#8203;quantpoet](https://github.com/quantpoet)) - Vault: Migrate Vault E2E add-on tests from deprecated `vault-client-go` to the new `vault/api` client. ([#&#8203;8059](https://github.com/cert-manager/cert-manager/issues/8059), [@&#8203;armagankaratosun](https://github.com/armagankaratosun)) ### [`v1.18.6`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.6) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.5...v1.18.6) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.18.6 is a simple patch release to fix some reported vulnerabilities, most notably [CVE-2025-68121](https://nvd.nist.gov/vuln/detail/CVE-2025-68121). NB: We didn't attempt to patch [CVE-2026-24051](https://nvd.nist.gov/vuln/detail/CVE-2026-24051) but that vulnerability affects macOS only, so cert-manager will be unaffected. #### Changes by Kind ##### Bug or Regression - Bump Go to address CVE-2025-68121 ([#&#8203;8525](https://github.com/cert-manager/cert-manager/issues/8525), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.18.5`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.5) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.4...v1.18.5) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release. #### Changes by Kind ##### Bug or Regression - Fixed an infinite re-issuance loop that could occur when an issuer returns a certificate with a public key that doesn't match the CSR. The issuing controller now validates the certificate before storing it and fails with backoff on mismatch. ([#&#8203;8414](https://github.com/cert-manager/cert-manager/issues/8414), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Fixed an issue where HTTP-01 challenges failed when the Host header contains an IPv6 address. This means that users can now issue IP address certificates for IPv6 address subjects. ([#&#8203;8437](https://github.com/cert-manager/cert-manager/issues/8437), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Security (MODERATE): Fix a potential panic in the cert-manager controller when a DNS response in an unexpected order was cached. If an attacker was able to modify DNS responses (or if they controlled the DNS server) it was possible to cause denial of service for the cert-manager controller. ([#&#8203;8467](https://github.com/cert-manager/cert-manager/issues/8467), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ##### Other (Cleanup or Flake) - Bump go to 1.24.12 ([#&#8203;8460](https://github.com/cert-manager/cert-manager/issues/8460), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.18.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.3...v1.18.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We updated Go to fix some vulnerabilities in the standard library. > 📖 Read the [full 1.18 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.18) on the cert-manager.io website before upgrading. #### Changes since `v1.18.3` ##### Bug or Regression - Address false positive vulnerabilities `CVE-2025-47914` and `CVE-2025-58181` which were reported by Trivy. ([#&#8203;8282](https://github.com/cert-manager/cert-manager/issues/8282), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update Go to `v1.24.11` to fix `CVE-2025-61727` and `CVE-2025-61729` ([#&#8203;8295](https://github.com/cert-manager/cert-manager/issues/8295), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ##### Other (Cleanup or Flake) - Update cert-manager's ACME client, forked from `golang/x/crypto` ([#&#8203;8271](https://github.com/cert-manager/cert-manager/issues/8271), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Updated Debian 12 distroless base images ([#&#8203;8328](https://github.com/cert-manager/cert-manager/issues/8328), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) ### [`v1.18.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.2...v1.18.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We fixed a bug which caused certificates to be re-issued unexpectedly, if the issuerRef kind or group was changed to one of the "runtime" default values. We increased the size limit when parsing PEM certificate chains to handle leaf certificates with large numbers of DNS named or other identities. We upgraded Go to 1.24.9 to fix various non-critical security vulnerabilities. > 📖 Read the [full 1.18 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.18) on the cert-manager.io website before upgrading. Changes since `v1.18.2`: ##### Bug or Regression - BUGFIX: in case kind or group in the issuerRef of a Certificate was omitted, upgrading to 1.19.x incorrectly caused the certificate to be renewed ([#&#8203;8174](https://github.com/cert-manager/cert-manager/issues/8174), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Bump Go to 1.24.9. Fixes the following vulnerabilities: CVE-2025-61724, CVE-2025-58187, CVE-2025-47912, CVE-2025-58183, CVE-2025-61723, CVE-2025-58186, CVE-2025-58185, CVE-2025-58188, CVE-2025-61725 ([#&#8203;8176](https://github.com/cert-manager/cert-manager/issues/8176), [@&#8203;wallrj-cyberark](https://github.com/wallrj-cyberark)) - Increase maximum sizes of PEM certificates and chains which can be parsed in cert-manager, to handle leaf certificates with large numbers of DNS names or other identities ([#&#8203;7966](https://github.com/cert-manager/cert-manager/issues/7966), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Improve error messages when certificates, CRLs or private keys fail admission due to malformed or missing PEM data ([#&#8203;7964](https://github.com/cert-manager/cert-manager/issues/7964), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Upgrades Go to v1.24.6 ([#&#8203;7974](https://github.com/cert-manager/cert-manager/issues/7974), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.18.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.1...v1.18.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the `NameConstraints` feature gate). We dropped the new `global.rbac.disableHTTPChallengesRole` Helm option due to a bug we found, this feature will be released in `v1.19` instead. Changes since `v1.18.1`: ##### Bug or Regression - BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints ([#&#8203;7833](https://github.com/cert-manager/cert-manager/issues/7833), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Reverted adding the `global.rbac.disableHTTPChallengesRole` Helm option. ([#&#8203;7837](https://github.com/cert-manager/cert-manager/issues/7837), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ### [`v1.18.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.18.0...v1.18.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We have added a new feature gate `ACMEHTTP01IngressPathTypeExact`, to allow `ingress-nginx` users to turn off the new default Ingress `PathType: Exact` behavior, in ACME HTTP01 Ingress challenge solvers. This change fixes the following issue: [#&#8203;7791](https://github.com/cert-manager/cert-manager/issues/7791) We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (`error waiting for authorization`), which has been reported by multiple users, since the release of cert-manager `v1.16.0`. This change should fix the following issues: [#&#8203;7337](https://github.com/cert-manager/cert-manager/issues/7337), [#&#8203;7444](https://github.com/cert-manager/cert-manager/issues/7444), and [#&#8203;7685](https://github.com/cert-manager/cert-manager/issues/7685). > ℹ️ Be sure to review all new features and changes below, and read the [full release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.18) carefully before upgrading. Changes since `v1.18.0`: ##### Feature - Added a new feature gate `ACMEHTTP01IngressPathTypeExact`, to allow `ingress-nginx` users to turn off the new default Ingress `PathType: Exact` behavior, in ACME HTTP01 Ingress challenge solvers. ([`#7810`](https://github.com/cert-manager/cert-manager/pull/7810), [@&#8203;sspreitzer](https://github.com/sspreitzer)) ##### Bug or Regression - ACME: Increased challenge authorization timeout to 2 minutes to fix `error waiting for authorization`. ([`#7801`](https://github.com/cert-manager/cert-manager/pull/7801), [@&#8203;hjoshi123](https://github.com/hjoshi123)) ##### Other (Cleanup or Flake) - Use the latest version of ingress-nginx in E2E tests to ensure compatibility ([`#7807`](https://github.com/cert-manager/cert-manager/pull/7807), [@&#8203;wallrj](https://github.com/wallrj)) ### [`v1.18.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.18.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.17.4...v1.18.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.18 introduces several new features and breaking changes. Highlights include support for ACME certificate profiles, a new default for `Certificate.Spec.PrivateKey.RotationPolicy` now set to `Always` (breaking change), and the default `Certificate.Spec.RevisionHistoryLimit` now set to `1` (potentially breaking). > ℹ️ Be sure to review all new features and changes below, and read the [full release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.18) carefully before upgrading. ##### Known Issues - ACME HTTP01 challenge paths are rejected by the ingress-nginx validating webhook ([#&#8203;7791](https://github.com/cert-manager/cert-manager/issues/7791)) Changes since `v1.17.2`: ##### Feature - Add config to the Vault issuer to allow the server-name to be specified when validating the certificates the Vault server presents. ([#&#8203;7663](https://github.com/cert-manager/cert-manager/issues/7663), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Added `app.kubernetes.io/managed-by: cert-manager` label to the created Let's Encrypt account keys ([#&#8203;7577](https://github.com/cert-manager/cert-manager/issues/7577), [@&#8203;terinjokes](https://github.com/terinjokes)) - Added certificate issuance and expiration time metrics (`certmanager_certificate_not_before_timestamp_seconds`, `certmanager_certificate_not_after_timestamp_seconds`). ([#&#8203;7612](https://github.com/cert-manager/cert-manager/issues/7612), [@&#8203;solidDoWant](https://github.com/solidDoWant)) - Added ingress-shim option: `--extra-certificate-annotations`, which sets a list of annotation keys to be copied from Ingress-like to resulting Certificate object ([#&#8203;7083](https://github.com/cert-manager/cert-manager/issues/7083), [@&#8203;k0da](https://github.com/k0da)) - Added the `iss` short name for the cert-manager `Issuer` resource. ([#&#8203;7373](https://github.com/cert-manager/cert-manager/issues/7373), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Added the `ciss` short name for the cert-manager `ClusterIssuer` resource ([#&#8203;7373](https://github.com/cert-manager/cert-manager/issues/7373), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Adds the `global.rbac.disableHTTPChallengesRole` helm value to disable HTTP-01 ACME challenges. This allows cert-manager to drop its permission to create pods, improving security when HTTP-01 challenges are not required. ([#&#8203;7666](https://github.com/cert-manager/cert-manager/issues/7666), [@&#8203;ali-hamza-noor](https://github.com/ali-hamza-noor)) - Allow customizing signature algorithm ([#&#8203;7591](https://github.com/cert-manager/cert-manager/issues/7591), [@&#8203;tareksha](https://github.com/tareksha)) - Cache the full DNS response and handle TTL expiration in `FindZoneByFqdn` ([#&#8203;7596](https://github.com/cert-manager/cert-manager/issues/7596), [@&#8203;ThatsIvan](https://github.com/ThatsIvan)) - Cert-manager now uses a local fork of the golang.org/x/crypto/acme package ([#&#8203;7752](https://github.com/cert-manager/cert-manager/issues/7752), [@&#8203;wallrj](https://github.com/wallrj)) - Add support for [ACME profiles extension](https://datatracker.ietf.org/doc/draft-aaron-acme-profiles/). ([#&#8203;7777](https://github.com/cert-manager/cert-manager/issues/7777), [@&#8203;wallrj](https://github.com/wallrj)) - Promote the `UseDomainQualifiedFinalizer` feature to GA. ([#&#8203;7735](https://github.com/cert-manager/cert-manager/issues/7735), [@&#8203;jsoref](https://github.com/jsoref)) - Switched service/servicemon definitions to use port names instead of numbers. ([#&#8203;7727](https://github.com/cert-manager/cert-manager/issues/7727), [@&#8203;jcpunk](https://github.com/jcpunk)) - The default value of `Certificate.Spec.PrivateKey.RotationPolicy` changed from `Never` to `Always`. ([#&#8203;7723](https://github.com/cert-manager/cert-manager/issues/7723), [@&#8203;wallrj](https://github.com/wallrj)) - Potentially breaking: Set the default revisionHistoryLimit to 1 for the CertificateRequest revisions ([#&#8203;7758](https://github.com/cert-manager/cert-manager/issues/7758), [@&#8203;ali-hamza-noor](https://github.com/ali-hamza-noor)) ##### Documentation - Fix some comments ([#&#8203;7620](https://github.com/cert-manager/cert-manager/issues/7620), [@&#8203;teslaedison](https://github.com/teslaedison)) ##### Bug or Regression - Bump `go-jose` dependency to address `CVE-2025-27144`. ([#&#8203;7606](https://github.com/cert-manager/cert-manager/issues/7606), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Bump `golang.org/x/oauth2` to patch `CVE-2025-22868`. ([#&#8203;7638](https://github.com/cert-manager/cert-manager/issues/7638), [@&#8203;NicholasBlaskey](https://github.com/NicholasBlaskey)) - Bump `golang.org/x/crypto` to patch `GHSA-hcg3-q754-cr77`. ([#&#8203;7638](https://github.com/cert-manager/cert-manager/issues/7638), [@&#8203;NicholasBlaskey](https://github.com/NicholasBlaskey)) - Bump `github.com/golang-jwt/jwt` to patch `GHSA-mh63-6h87-95cp`. ([#&#8203;7638](https://github.com/cert-manager/cert-manager/issues/7638), [@&#8203;NicholasBlaskey](https://github.com/NicholasBlaskey)) - Change of the Kubernetes Ingress pathType from `ImplementationSpecific` to `Exact` for a reliable handling of ingress controllers and enhanced security. ([#&#8203;7767](https://github.com/cert-manager/cert-manager/issues/7767), [@&#8203;sspreitzer](https://github.com/sspreitzer)) - Fix AWS Route53 error detection for not-found errors during deletion of DNS records. ([#&#8203;7690](https://github.com/cert-manager/cert-manager/issues/7690), [@&#8203;wallrj](https://github.com/wallrj)) - Fix behavior when running with `--namespace=<namespace>`: limit the scope of cert-manager to a single namespace and disable cluster-scoped controllers. ([#&#8203;7678](https://github.com/cert-manager/cert-manager/issues/7678), [@&#8203;tsaarni](https://github.com/tsaarni)) - Fix handling of certificates with IP addresses in the `commonName` field; IP addresses are no longer added to the DNS `subjectAlternativeName` list and are instead added to the `ipAddresses` field as expected. ([#&#8203;7081](https://github.com/cert-manager/cert-manager/issues/7081), [@&#8203;johnjcool](https://github.com/johnjcool)) - Fix issuing of certificates via DNS01 challenges on Cloudflare after a breaking change to the Cloudflare API ([#&#8203;7549](https://github.com/cert-manager/cert-manager/issues/7549), [@&#8203;LukeCarrier](https://github.com/LukeCarrier)) - Fixed the `certmanager_certificate_renewal_timestamp_seconds` metric help text indicating that the metric is relative to expiration time, rather than Unix epoch time. ([#&#8203;7609](https://github.com/cert-manager/cert-manager/issues/7609), [@&#8203;solidDoWant](https://github.com/solidDoWant)) - Fixing the service account template to incorporate boolean values for the annotations. ([#&#8203;7698](https://github.com/cert-manager/cert-manager/issues/7698), [@&#8203;ali-hamza-noor](https://github.com/ali-hamza-noor)) - Quote nodeSelector values in Helm Chart ([#&#8203;7579](https://github.com/cert-manager/cert-manager/issues/7579), [@&#8203;tobiasbp](https://github.com/tobiasbp)) - Skip Gateway TLS listeners in `Passthrough` mode. ([#&#8203;6986](https://github.com/cert-manager/cert-manager/issues/6986), [@&#8203;vehagn](https://github.com/vehagn)) - Upgrade `golang.org/x/net` fixing `CVE-2025-22870`. ([#&#8203;7619](https://github.com/cert-manager/cert-manager/issues/7619), [@&#8203;dependabot](https://github.com/dependabot)\[bot]) ##### Other (Cleanup or Flake) - ACME E2E Tests: Upgraded Pebble to v2.7.0 and modified the ACME tests to match latest Pebble behaviour. ([#&#8203;7771](https://github.com/cert-manager/cert-manager/issues/7771), [@&#8203;wallrj](https://github.com/wallrj)) - Patch the `third_party/forked/acme` package with support for the ACME profiles extension. ([#&#8203;7776](https://github.com/cert-manager/cert-manager/issues/7776), [@&#8203;wallrj](https://github.com/wallrj)) - Promote the `AdditionalCertificateOutputFormats` feature to GA, making additional formats always enabled. ([#&#8203;7744](https://github.com/cert-manager/cert-manager/issues/7744), [@&#8203;erikgb](https://github.com/erikgb)) - Remove deprecated feature gate `ValidateCAA`. Setting this feature gate is now a no-op which does nothing but print a warning log line ([#&#8203;7553](https://github.com/cert-manager/cert-manager/issues/7553), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update kind images to include the Kubernetes 1.33 node image ([#&#8203;7787](https://github.com/cert-manager/cert-manager/issues/7787), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Upgrade Go to `v1.24.4` ([#&#8203;7785](https://github.com/cert-manager/cert-manager/issues/7785), [@&#8203;wallrj](https://github.com/wallrj)) - Use slices.Contains to simplify code ([#&#8203;7753](https://github.com/cert-manager/cert-manager/issues/7753), [@&#8203;cuinix](https://github.com/cuinix)) ### [`v1.17.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.17.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.17.3...v1.17.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the `NameConstraints` feature gate). Changes since `v1.17.3`: ##### Bug or Regression - BUGFIX: permitted URI domains were incorrectly used to set the excluded URI domains in the CSR's name constraints ([#&#8203;7832](https://github.com/cert-manager/cert-manager/issues/7832), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ### [`v1.17.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.17.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.17.2...v1.17.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23. We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (`error waiting for authorization`), which has been reported by multiple users, in: [#&#8203;7337](https://github.com/cert-manager/cert-manager/issues/7337), [#&#8203;7444](https://github.com/cert-manager/cert-manager/issues/7444), and [#&#8203;7685](https://github.com/cert-manager/cert-manager/issues/7685). > ℹ️ Be sure to review all new features and changes below, and read the [full release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.17) carefully before upgrading. Changes since `v1.17.2`: ##### Bug or Regression - Bump Go to 1.23.10 to fix GO-2025-3749, GO-2025-3750, and GO-2025-3751 ([#&#8203;7799](https://github.com/cert-manager/cert-manager/issues/7799), [@&#8203;wallrj](https://github.com/wallrj)) - ACME: Increased challenge authorization timeout to 2 minutes to fix error `waiting for authorization` ([#&#8203;7798](https://github.com/cert-manager/cert-manager/issues/7798), [@&#8203;hjoshi123](https://github.com/hjoshi123)) ##### Other (Cleanup or Flake) - Use the latest version of ingress-nginx in E2E tests to ensure compatibility ([#&#8203;7808](https://github.com/cert-manager/cert-manager/issues/7808), [@&#8203;wallrj](https://github.com/wallrj)) ### [`v1.17.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.17.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.17.1...v1.17.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23 and includes various dependency updates. > 📖 Read the full [cert-manager 1.17 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.17), before installing or upgrading. #### Changes since `v1.17.1` ##### Bug or Regression - Bump Go to `v1.23.8` to fix `CVE-2025-22871` ([#&#8203;7701](https://github.com/cert-manager/cert-manager/pull/7701), [`@wallrj`](https://github.com/wallrj)) - Bump `go-jose` dependency to address `CVE-2025-27144` ([#&#8203;7603](https://github.com/cert-manager/cert-manager/pull/7603), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) - Bump `golang.org/x/net` to address `CVE-2025-22870` reported by Trivy ([#&#8203;7622](https://github.com/cert-manager/cert-manager/pull/7622), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) - Bump `golang.org/x/net` to fix `CVE-2025-22872` ([#&#8203;7703](https://github.com/cert-manager/cert-manager/pull/7703), [`@wallrj`](https://github.com/wallrj)) - Bump `golang.org/x/oauth2` to patch `CVE-2025-22868` ([#&#8203;7692](https://github.com/cert-manager/cert-manager/pull/7692), [`@lentzi90`](https://github.com/lentzi90)) - Bump `golang.org/x/crypto` to patch `GHSA-hcg3-q754-cr77` ([#&#8203;7692](https://github.com/cert-manager/cert-manager/pull/7692), [`@lentzi90`](https://github.com/lentzi90)) - Bump `github.com/golang-jwt/jwt` to patch `GHSA-mh63-6h87-95cp` ([#&#8203;7692](https://github.com/cert-manager/cert-manager/pull/7692), [`@lentzi90`](https://github.com/lentzi90)) ### [`v1.17.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.17.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.17.0...v1.17.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This release is primarily intended to address [a breaking change in Cloudflare's API](https://github.com/cert-manager/cert-manager/issues/7540) which impacted ACME DNS-01 challenges using Cloudflare. Many thanks to the community members who reported this issue! #### Changes by Kind ##### Bug or Regression - ❗ Fix issuing of certificates via DNS01 challenges on Cloudflare after a breaking change to the Cloudflare API ([#&#8203;7565](https://github.com/cert-manager/cert-manager/issues/7565), [@&#8203;LukeCarrier](https://github.com/LukeCarrier)) - Bump go to 1.23.6 to address CVE-2025-22866 reported by Trivy ([#&#8203;7563](https://github.com/cert-manager/cert-manager/issues/7563), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish) ### [`v1.17.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.17.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.16.5...v1.17.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.17.0 is a feature release with several improvements, including: - A helpful compliance change to RSA signatures on certificates - An easier way to specify passwords for [PKCS#12](https://github.com/PKCS/cert-manager/issues/12) and JKS keystores - A few feature flag promotions (and a deprecation) - Dependency bumps and other smaller improvements #### Major Themes ##### RSA Certificate Compliance The United States Department of Defense published [a memo](https://dl.dod.cyber.mil/wp-content/uploads/pki-pke/pdf/unclass-memo_dodcryptoalgorithms.pdf) in 2022 which introduced some requirements on the kinds of cryptography they require to be supported in software they use. In effect, the memo requires that software be able to support larger RSA keys (3072-bit and 4096-bit) and hashing algorithms (SHA-384 at a minimum). cert-manager supported large RSA keys long before the memo was published, but a quirk in implementation meant that cert-manager always used SHA-256 when signing with RSA. In v1.17.0, cert-manager will choose a hash algorithm based on the RSA key length: 3072-bit keys will use SHA-384, and 4096-bit keys will use SHA-512. This matches similar behavior already present for ECDSA signatures. Our expectation is that this change will have minimal impact beyond a slight increase to security and better compliance; we're not aware of Kubernetes based environments which support RSA 2048 with SHA-256 but fail with RSA 4096 and SHA-512. However, if you're using larger RSA keys, you should be aware of the change. ##### Easier Keystore Passwords for [PKCS#12](https://github.com/PKCS/cert-manager/issues/12) and JKS Specifying passwords on [PKCS#12](https://github.com/PKCS/cert-manager/issues/12) and JKS keystores is supported in cert-manager for compatibility reasons with software which expects or requires passwords to be set; however, these passwords are [not relevant to security](https://cert-manager.io/docs/faq/#why-are-passwords-on-jks-or-pkcs12-files-not-helpful) and never have been in cert-manager. The initial implementation of the `keystores` feature required these "passwords" to be stored in a Kubernetes secret, which would then be read by cert-manager when creating the keystore after a certificate was issued. This is cumbersome, especially when many passwords are set to default values such as `changeit` or `password`. In cert-manager v1.17, it's now possible to set a keystore password using a literal string value inside the `Certificate` resource itself, making this process much easier with no change to security. For example: ```yaml apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: my-cert-password spec: secretName: my-cert-password issuerRef: name: my-issuer kind: ClusterIssuer keystores: jks: create: true password: "abc123" pkcs12: create: true password: "password" dnsNames: - example.com ``` The new `password` field is mutually exclusive with the `passwordSecretRef` field, so be sure to only set one. ##### Feature Flag Promotions / Deprecations cert-manager's feature flags allow for easier testing and adoption of new features with a reduced risk of breaking changes. In cert-manager v1.17, two feature gates have been promoted to "beta", and as such are now enabled by default in all installations: - `NameConstraints`, allowing users to specify the name constraints extension which can be helpful when creating CA certificates for private PKI - `UseDomainQualifiedFinalizer`, which stops a Kubernetes warning from being printed in logs In addition, we added a new feature gate: `CAInjectorMerging`, which intelligently combines certificates used by the [`CAInjector`](../../concepts/ca-injector.md) component, making it safer to use when issuing certificates are rotated. If you're making heavy use of the CA injector, you should consider enabling this feature gate. Finally, we deprecated the `ValidateCAA` feature gate which will be removed entirely in cert-manager v1.18.0. This feature gate aimed to validate the `CAA` DNS record during ACME issuance, but has seen low adoption and limited testing since its introduction back in 2019. ##### Other Changes There are many other PRs which were merged in this release cycle and we'd encourage you to read the release notes below. One PR that's worth highlighting is a change to add more structured logging information to certain log lines. If you were previously filtering logs using `grep` or similar tools (which is highly discouraged!) be aware that some log lines have changed format. #### Community As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved. A special thanks to: - [@&#8203;hawksight](https://github.com/hawksight) - [@&#8203;aidy](https://github.com/aidy) - [@&#8203;bashlion](https://github.com/bashlion) - [@&#8203;7ing](https://github.com/7ing) - [@&#8203;fadecore](https://github.com/fadecore) - [@&#8203;schedin](https://github.com/schedin) - [@&#8203;jkroepke](https://github.com/jkroepke) - [@&#8203;sdarwin](https://github.com/sdarwin) for their contributions, comments and support! Also, thanks to the cert-manager maintainer team for their help in this release: - [@&#8203;inteon](https://github.com/inteon) - [@&#8203;erikgb](https://github.com/erikgb) - [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish) - [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot) - [@&#8203;munnerz](https://github.com/munnerz) - [@&#8203;maelvls](https://github.com/maelvls) And finally, thanks to the cert-manager steering committee for their feedback in this release cycle: - [@&#8203;FlorianLiebhart](https://github.com/FlorianLiebhart) - [@&#8203;ssyno](https://github.com/ssyno) - [@&#8203;ianarsenault](https://github.com/ianarsenault) - [@&#8203;TrilokGeer](https://github.com/TrilokGeer) #### Changes by Kind ##### Feature - Potentially BREAKING: The CA and SelfSigned issuers now use SHA-512 when signing with RSA keys 4096 bits and above, and SHA-384 when signing with RSA keys 3072 bits and above. If you were previously using a larger RSA key as a CA, be sure to check that your systems support the new hash algorithms. ([#&#8203;7368](https://github.com/cert-manager/cert-manager/issues/7368), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Add CAInjectorMerging feature gate to the ca-injector, enabling this will change the behaviour of the ca-injector to merge in new CA certificates instead of outright replacing the existing one. ([#&#8203;7469](https://github.com/cert-manager/cert-manager/issues/7469), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Added image pull secrets to deployments when service accounts aren't created ([#&#8203;7411](https://github.com/cert-manager/cert-manager/issues/7411), [@&#8203;TheHenrick](https://github.com/TheHenrick)) - Added the ability to customize client ID when using username/password authentication for Venafi client ([#&#8203;7484](https://github.com/cert-manager/cert-manager/issues/7484), [@&#8203;ilyesAj](https://github.com/ilyesAj)) - Helm: New value `webhook.extraEnv` allows you to set custom environment variables in the webhook Pod. Helm: New value `cainjector.extraEnv` allows you to set custom environment variables in the cainjector Pod. Helm: New value `startupapicheck.extraEnv` allows you to set custom environment variables in the startupapicheck Pod. ([#&#8203;7317](https://github.com/cert-manager/cert-manager/issues/7317), [@&#8203;wallrj](https://github.com/wallrj)) - Increase the amount of PEM data `pki.DecodeX509CertificateSetBytes` is able to parse, to enable reading larger TLS trust bundles ([#&#8203;7464](https://github.com/cert-manager/cert-manager/issues/7464), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - New configuration option tenantID for the AzureDNS provider when using managed identities with service principals. This enhancement allows users to specify the tenant ID when using managed identities, offering better flexibility in multi-tenant environments. ([#&#8203;7376](https://github.com/cert-manager/cert-manager/issues/7376), [@&#8203;jochenrichter](https://github.com/jochenrichter)) - Promote the `UseDomainQualifiedFinalizer` feature to Beta. ([#&#8203;7488](https://github.com/cert-manager/cert-manager/issues/7488), [@&#8203;jsoref](https://github.com/jsoref)) - Allow JKS/PKCS12 keystore passwords to be set as literal values in Certificate resources, mutually exclusive with the existing passwordSecretRef field ([#&#8203;6657](https://github.com/cert-manager/cert-manager/issues/6657), [@&#8203;rquinio1A](https://github.com/rquinio1A)) - Allow templating ServiceAccount annotations by running the built-in Helm `tpl` function on keys and values, to aid with workload identity configuration ([#&#8203;7501](https://github.com/cert-manager/cert-manager/issues/7501), [@&#8203;fcrespofastly](https://github.com/fcrespofastly)) - Promote CA NameConstraints feature gate to Beta (enabled by default) ([#&#8203;7494](https://github.com/cert-manager/cert-manager/issues/7494), [@&#8203;tanujd11](https://github.com/tanujd11)) ##### Documentation - Add example for IPv6 in `--dns01-recursive-nameservers` ([#&#8203;7367](https://github.com/cert-manager/cert-manager/issues/7367), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Updated the chart documentation to show `enableGatewayAPI` in the config example. ([#&#8203;7354](https://github.com/cert-manager/cert-manager/issues/7354), [@&#8203;puerco](https://github.com/puerco)) ##### Bug or Regression - BUGFIX: A change in v1.16.0 caused cert-manager's ACME ClusterIssuer to look in the wrong namespace for resources required for the issuance (eg. credential Secrets). This is now fixed in v1.16.1+ and v1.17.0+ ([#&#8203;7339](https://github.com/cert-manager/cert-manager/issues/7339), [@&#8203;inteon](https://github.com/inteon)) - BUGFIX: Helm will now accept percentages for the `podDisruptionBudget.minAvailable` and `podDisruptionBudget.maxAvailable` values. ([#&#8203;7343](https://github.com/cert-manager/cert-manager/issues/7343), [@&#8203;inteon](https://github.com/inteon)) - Fix ACME HTTP-01 solver for IPv6 endpoints ([#&#8203;7391](https://github.com/cert-manager/cert-manager/issues/7391), [@&#8203;Peac36](https://github.com/Peac36)) - Fix the behavior of `renewBeforePercentage` to comply with its spec ([#&#8203;7421](https://github.com/cert-manager/cert-manager/issues/7421), [@&#8203;adam-sroka](https://github.com/adam-sroka)) - Helm: allow `enabled` to be set as a value to toggle cert-manager as a dependency. ([#&#8203;7350](https://github.com/cert-manager/cert-manager/issues/7350), [@&#8203;inteon](https://github.com/inteon)) - SECURITY (low risk): Limit maximum allowed PEM size to prevent potential DoS in cert-manager controller from attacker-controlled PEM. See [GHSA-r4pg-vg54-wxx4](https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4) ([#&#8203;7400](https://github.com/cert-manager/cert-manager/issues/7400), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - The Certificate object will no longer create CertificateRequest or Secret objects while being deleted ([#&#8203;7361](https://github.com/cert-manager/cert-manager/issues/7361), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - The issuer will now more quickly retry when its linked Secret is updated to fix an issue that caused a high back-off timeout. ([#&#8203;7455](https://github.com/cert-manager/cert-manager/issues/7455), [@&#8203;inteon](https://github.com/inteon)) - Upgrades Venafi vCert library fixing a bug which caused the RSA 3072 bit key size for TPP certificate enrollment to not work. ([#&#8203;7498](https://github.com/cert-manager/cert-manager/issues/7498), [@&#8203;inteon](https://github.com/inteon)) ##### Other (Cleanup or Flake) - ⚠️ Potentially BREAKING: Log messages that were not structured have now been replaced with structured logs. If you were matching on specific log strings, this could break your setup. ([#&#8203;7461](https://github.com/cert-manager/cert-manager/issues/7461), [@&#8203;inteon](https://github.com/inteon)) - DEPRECATION: The `ValidateCAA` feature gate is now deprecated, with removal scheduled for cert-manager 1.18. In 1.17, enabling this feature gate will print a warning. ([#&#8203;7491](https://github.com/cert-manager/cert-manager/issues/7491), [@&#8203;jsoref](https://github.com/jsoref)) - Remove `Neither --kubeconfig nor --master was specified` warning message when the controller and the webhook services boot ([#&#8203;7457](https://github.com/cert-manager/cert-manager/issues/7457), [@&#8203;Peac36](https://github.com/Peac36)) - Move 'live' DNS tests into a separate package to contain test flakiness and improve developer UX ([#&#8203;7530](https://github.com/cert-manager/cert-manager/issues/7530), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.16.5`](https://github.com/cert-manager/cert-manager/releases/tag/v1.16.5) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.16.4...v1.16.5) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23 and includes various dependency updates. > 📖 Read the full [cert-manager 1.16 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.16), before installing or upgrading. #### Changes since `v1.16.4`: ##### Bug or Regression - Bump Go to `v1.23.8` to fix `CVE-2025-22871` ([#&#8203;7706](https://github.com/cert-manager/cert-manager/pull/7706), [`@wallrj`](https://github.com/wallrj)) - Bump `github.com/golang-jwt/jwt/v5` to `v5.2.2` to fix `CVE-2025-30204` ([#&#8203;7708](https://github.com/cert-manager/cert-manager/pull/7708), [`@wallrj`](https://github.com/wallrj)) - Bump `golang.org/x/net` to fix `CVE-2025-22872` ([#&#8203;7707](https://github.com/cert-manager/cert-manager/pull/7707), [`@wallrj`](https://github.com/wallrj)) - Bump `go-jose` dependency to address `CVE-2025-27144` ([#&#8203;7602](https://github.com/cert-manager/cert-manager/pull/7602), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) - Bump `golang.org/x/net` to address `CVE-2025-22870` reported by Trivy ([#&#8203;7623](https://github.com/cert-manager/cert-manager/pull/7623), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) ### [`v1.16.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.16.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.16.3...v1.16.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This release is primarily intended to address [a breaking change in Cloudflare's API](https://github.com/cert-manager/cert-manager/issues/7540) which impacted ACME DNS-01 challenges using Cloudflare. Many thanks to the community members who reported this issue! #### Changes by Kind ##### Bug or Regression - ❗ Fix issuing of certificates via DNS01 challenges on Cloudflare after a breaking change to the Cloudflare API ([#&#8203;7566](https://github.com/cert-manager/cert-manager/issues/7566), [@&#8203;LukeCarrier](https://github.com/LukeCarrier)) - Bump go to 1.23.6 to address CVE-2025-22866 reported by Trivy ([#&#8203;7562](https://github.com/cert-manager/cert-manager/issues/7562), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Update go to 1.23.5 ([#&#8203;7533](https://github.com/cert-manager/cert-manager/issues/7533), [@&#8203;tareksha](https://github.com/tareksha)) ### [`v1.16.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.16.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.16.2...v1.16.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. v1.16.3 is a patch release mainly focused around bumping dependencies to address reported CVEs: CVE-2024-45337 and CVE-2024-45338. We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners. It also includes a bug fix to the new `renewBeforePercentage` field. If you were using `renewBeforePercentage`, see PR [#&#8203;7421](https://github.com/cert-manager/cert-manager/issues/7421) for more information. #### Changes ##### Bug - Bump `golang.org/x/net` and `golang.org/x/crypto` to address CVE-2024-45337 and CVE-2024-45338 ([#&#8203;7485](https://github.com/cert-manager/cert-manager/issues/7485), [@&#8203;erikgb](https://github.com/erikgb)) - Fix the behaviour of `renewBeforePercentage` to comply with its spec ([#&#8203;7441](https://github.com/cert-manager/cert-manager/issues/7441), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other - Bump go to 1.23.4 ([#&#8203;7489](https://github.com/cert-manager/cert-manager/issues/7489), [@&#8203;erikgb](https://github.com/erikgb)) - Bump base images to latest available ([#&#8203;7508](https://github.com/cert-manager/cert-manager/issues/7508), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.16.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.16.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.16.1...v1.16.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release of cert-manager 1.16 makes [several changes](https://github.com/cert-manager/cert-manager/pull/7401) to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed. This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project. The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods. Note also that since most PEM data parsed by cert-manager comes from `ConfigMap` or `Secret` resources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data. Further information is available in <https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4> In addition, the version of Go used to build cert-manager 1.16 was updated along with the base images. #### Changes by Kind ##### Bug or Regression - Set a maximum size for PEM inputs which cert-manager will accept to remove possibility of taking a long time to process an input ([#&#8203;7401](https://github.com/cert-manager/cert-manager/issues/7401), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ##### Other (Cleanup or Flake) - Bump go to 1.23.3 and bump base images to latest available ([#&#8203;7431](https://github.com/cert-manager/cert-manager/issues/7431), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.16.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.16.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.16.0...v1.16.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer. 📖 Read the [complete 1.16 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.16) before upgrading. #### 📜Changes since `v1.16.0` ##### Bug or Regression - BUGFIX: Helm schema validation: the new schema validation was too strict for the "global" section. Since the global section is shared across all charts and sub-charts, we must also allow unknown fields. ([#&#8203;7348](https://github.com/cert-manager/cert-manager/pull/7348), [`@inteon`](https://github.com/inteon)) - BUGFIX: Helm will now accept percentages for the `podDisruptionBudget.minAvailable` and `podDisruptionBudget.maxAvailable` values. ([#&#8203;7345](https://github.com/cert-manager/cert-manager/pull/7345), [`@inteon`](https://github.com/inteon)) - Helm: allow `enabled` to be set as a value to toggle cert-manager as a dependency. ([#&#8203;7356](https://github.com/cert-manager/cert-manager/pull/7356), [`@inteon`](https://github.com/inteon)) - BUGFIX: A change in `v1.16.0` caused cert-manager's ACME ClusterIssuer to look in the wrong namespace for resources required for the issuance (e.g. credential Secrets). This is now fixed in `v1.16.1`. ([#&#8203;7342](https://github.com/cert-manager/cert-manager/pull/7342), [`@inteon`](https://github.com/inteon)) ### [`v1.16.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.16.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.15.5...v1.16.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer. 📖 Read the [complete 1.16 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.16) at cert-manager.io. #### ⚠️ Known issues 1. [Helm Chart: JSON schema prevents the chart being used as a sub-chart on Rancher RKE](https://github.com/cert-manager/cert-manager/issues/7329). 2. [ACME DNS01 **ClusterIssuer** fail while loading credentials from Secret resources](https://github.com/cert-manager/cert-manager/issues/7331). #### ❗ Breaking changes 1. Helm schema validation may reject your existing Helm values files if they contain typos or unrecognized fields. 2. Venafi Issuer may fail to renew certificates if the requested duration conflicts with the CA’s minimum or maximum policy settings in Venafi. 3. Venafi Issuer may fail to renew Certificates if the issuer has been configured for TPP with username-password authentication. 📖 Read the [complete 1.16 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.16) at cert-manager.io. #### 📜 Changes since v1.15.0 📖 Read the [complete 1.16 release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.16) at cert-manager.io. ##### Feature - Add `SecretRef` support for Venafi TPP issuer CA Bundle ([#&#8203;7036](https://github.com/cert-manager/cert-manager/pull/7036), [`@sankalp-at-gh`](https://github.com/sankalp-at-gh)) - Add `renewBeforePercentage` alternative to `renewBefore` ([#&#8203;6987](https://github.com/cert-manager/cert-manager/pull/6987), [`@cbroglie`](https://github.com/cbroglie)) - Add a metrics server to the cainjector ([#&#8203;7194](https://github.com/cert-manager/cert-manager/pull/7194), [`@wallrj`](https://github.com/wallrj)) - Add a metrics server to the webhook ([#&#8203;7182](https://github.com/cert-manager/cert-manager/pull/7182), [`@wallrj`](https://github.com/wallrj)) - Add client certificate auth method for Vault issuer ([#&#8203;4330](https://github.com/cert-manager/cert-manager/pull/4330), [`@joshmue`](https://github.com/joshmue)) - Add process and go runtime metrics for controller ([#&#8203;6966](https://github.com/cert-manager/cert-manager/pull/6966), [`@mindw`](https://github.com/mindw)) - Added `app.kubernetes.io/managed-by: cert-manager` label to the cert-manager-webhook-ca Secret ([#&#8203;7154](https://github.com/cert-manager/cert-manager/pull/7154), [`@jrcichra`](https://github.com/jrcichra)) - Allow the user to specify a Pod template when using GatewayAPI HTTP01 solver, this mirrors the behavior when using the Ingress HTTP01 solver. ([#&#8203;7211](https://github.com/cert-manager/cert-manager/pull/7211), [`@ThatsMrTalbot`](https://github.com/ThatsMrTalbot)) - Create token request RBAC for the cert-manager ServiceAccount by default ([#&#8203;7213](https://github.com/cert-manager/cert-manager/pull/7213), [`@Jasper-Ben`](https://github.com/Jasper-Ben)) - Feature: Append cert-manager user-agent string to all AWS API requests, including IMDS and STS requests. ([#&#8203;7295](https://github.com/cert-manager/cert-manager/pull/7295), [`@wallrj`](https://github.com/wallrj)) - Feature: Log AWS SDK warnings and API requests at cert-manager debug level to help debug AWS Route53 problems in the field. ([#&#8203;7292](https://github.com/cert-manager/cert-manager/pull/7292), [`@wallrj`](https://github.com/wallrj)) - Feature: The Route53 DNS solver of the ACME Issuer will now use regional STS endpoints computed from the region that is supplied in the Issuer spec or in the `AWS_REGION` environment variable. Feature: The Route53 DNS solver of the ACME Issuer now uses the "ambient" region (`AWS_REGION` or `AWS_DEFAULT_REGION`) if `issuer.spec.acme.solvers.dns01.route53.region` is empty; regardless of the flags `--issuer-ambient-credentials` and `--cluster-issuer-ambient-credentials`. ([#&#8203;7299](https://github.com/cert-manager/cert-manager/pull/7299), [`@wallrj`](https://github.com/wallrj)) - Helm: adds JSON schema validation for the Helm values. ([#&#8203;7069](https://github.com/cert-manager/cert-manager/pull/7069), [`@inteon`](https://github.com/inteon)) - If the `--controllers` flag only specifies disabled controllers, the default controllers are now enabled implicitly. Added `disableAutoApproval` and `approveSignerNames` Helm chart options. ([#&#8203;7049](https://github.com/cert-manager/cert-manager/pull/7049), [`@inteon`](https://github.com/inteon)) - Make it easier to configure cert-manager using Helm by defaulting `config.apiVersion` and `config.kind` within the Helm chart. ([#&#8203;7126](https://github.com/cert-manager/cert-manager/pull/7126), [`@ThatsMrTalbot`](https://github.com/ThatsMrTalbot)) - Now passes down specified duration to Venafi client instead of using the CA default only. ([#&#8203;7104](https://github.com/cert-manager/cert-manager/pull/7104), [`@Guitarkalle`](https://github.com/Guitarkalle)) - Reduce the memory usage of `cainjector`, by only caching the metadata of Secret resources. Reduce the load on the K8S API server when `cainjector` starts up, by only listing the metadata of Secret resources. ([#&#8203;7161](https://github.com/cert-manager/cert-manager/pull/7161), [`@wallrj`](https://github.com/wallrj)) - The Route53 DNS01 solver of the ACME Issuer can now detect the AWS region from the `AWS_REGION` and `AWS_DEFAULT_REGION` environment variables, which is set by the IAM for Service Accounts (IRSA) webhook and by the Pod Identity webhook. The `issuer.spec.acme.solvers.dns01.route53.region` field is now optional. The API documentation of the `region` field has been updated to explain when and how the region value is used. ([#&#8203;7287](https://github.com/cert-manager/cert-manager/pull/7287), [`@wallrj`](https://github.com/wallrj)) - Venafi TPP issuer can now be used with a username & password combination with OAuth. Fixes [#&#8203;4653](https://github.com/cert-manager/cert-manager/issues/4653). Breaking: cert-manager will no longer use the API Key authentication method which was deprecated in 20.2 and since removed in 24.1 of TPP. ([#&#8203;7084](https://github.com/cert-manager/cert-manager/pull/7084), [`@hawksight`](https://github.com/hawksight)) - You can now configure the pod security context of HTTP-01 solver pods. ([#&#8203;5373](https://github.com/cert-manager/cert-manager/pull/5373), [`@aidy`](https://github.com/aidy)) - Helm: New value `webhook.extraEnv`, allows you to set custom environment variables in the webhook Pod. Helm: New value `cainjector.extraEnv`, allows you to set custom environment variables in the cainjector Pod. Helm: New value `startupapicheck.extraEnv`, allows you to set custom environment variables in the startupapicheck Pod. ([#&#8203;7319](https://github.com/cert-manager/cert-manager/pull/7319), [`@wallrj`](https://github.com/wallrj)) ##### Bug or Regression - Adds support (behind a flag) to use a domain qualified finalizer. If the feature is enabled (which is not by default), it should prevent Kubernetes from reporting: `metadata.finalizers: "finalizer.acme.cert-manager.io": prefer a domain-qualified finalizer name to avoid accidental conflicts with other finalizer writers` ([#&#8203;7273](https://github.com/cert-manager/cert-manager/pull/7273), [`@jsoref`](https://github.com/jsoref)) - BUGFIX Route53: explicitly set the `aws-global` STS region which is now required by the `github.com/aws/aws-sdk-go-v2` library. ([#&#8203;7108](https://github.com/cert-manager/cert-manager/pull/7108), [`@inteon`](https://github.com/inteon)) - BUGFIX: fix issue that caused Vault issuer to not retry signing when an error was encountered. ([#&#8203;7105](https://github.com/cert-manager/cert-manager/pull/7105), [`@inteon`](https://github.com/inteon)) - BUGFIX: the dynamic certificate source used by the webhook TLS server failed to detect a root CA approaching expiration, due to a calculation error. This will cause the webhook TLS server to fail renewing its CA certificate. Please upgrade before the expiration of this CA certificate is reached. ([#&#8203;7230](https://github.com/cert-manager/cert-manager/pull/7230), [`@inteon`](https://github.com/inteon)) - Bugfix: Prevent aggressive Route53 retries caused by IRSA authentication failures by removing the Amazon Request ID from errors wrapped by the default credential cache. ([#&#8203;7291](https://github.com/cert-manager/cert-manager/pull/7291), [`@wallrj`](https://github.com/wallrj)) - Bugfix: Prevent aggressive Route53 retries caused by STS authentication failures by removing the Amazon Request ID from STS errors. ([#&#8203;7259](https://github.com/cert-manager/cert-manager/pull/7259), [`@wallrj`](https://github.com/wallrj)) - Bump `grpc-go` to fix `GHSA-xr7q-jx4m-x55m` ([#&#8203;7164](https://github.com/cert-manager/cert-manager/pull/7164), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) - Bump the `go-retryablehttp` dependency to fix `CVE-2024-6104` ([#&#8203;7125](https://github.com/cert-manager/cert-manager/pull/7125), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) - Fix Azure DNS causing panics whenever authentication error happens ([#&#8203;7177](https://github.com/cert-manager/cert-manager/pull/7177), [`@eplightning`](https://github.com/eplightning)) - Fix incorrect indentation of `endpointAdditionalProperties` in the `PodMonitor` template of the Helm chart ([#&#8203;7190](https://github.com/cert-manager/cert-manager/pull/7190), [`@wallrj`](https://github.com/wallrj)) - Fixes ACME HTTP01 challenge behavior when using Gateway API to prevent unbounded creation of HTTPRoute resources ([#&#8203;7178](https://github.com/cert-manager/cert-manager/pull/7178), [`@miguelvr`](https://github.com/miguelvr)) - Handle errors arising from challenges missing from the ACME server ([#&#8203;7202](https://github.com/cert-manager/cert-manager/pull/7202), [`@bdols`](https://github.com/bdols)) - Helm BUGFIX: the cainjector ConfigMap was not mounted in the cainjector deployment. ([#&#8203;7052](https://github.com/cert-manager/cert-manager/pull/7052), [`@inteon`](https://github.com/inteon)) - Improve the startupapicheck: validate that the validating and mutating webhooks are doing their job. ([#&#8203;7057](https://github.com/cert-manager/cert-manager/pull/7057), [`@inteon`](https://github.com/inteon)) - The `KeyUsages` X.509 extension is no longer added when there are no key usages set (in accordance to RFC 5280 Section 4.2.1.3) ([#&#8203;7250](https://github.com/cert-manager/cert-manager/pull/7250), [`@inteon`](https://github.com/inteon)) - Update `github.com/Azure/azure-sdk-for-go/sdk/azidentity` to address `CVE-2024-35255` ([#&#8203;7087](https://github.com/cert-manager/cert-manager/pull/7087), [`@dependabot[bot]`](https://github.com/apps/dependabot)) ##### Other (Cleanup or Flake) - Old API versions were removed from the codebase. Removed: (acme.)cert-manager.io/v1alpha2 (acme.)cert-manager.io/v1alpha3 (acme.)cert-manager.io/v1beta1 ([#&#8203;7278](https://github.com/cert-manager/cert-manager/pull/7278), [`@inteon`](https://github.com/inteon)) - Upgrading to client-go `v0.31.0` removes a lot of noisy `reflector.go: unable to sync list result: internal error: cannot cast object DeletedFinalStateUnknown` errors from logs. ([#&#8203;7237](https://github.com/cert-manager/cert-manager/pull/7237), [`@inteon`](https://github.com/inteon)) - Bump Go to `v1.23.2` ([#&#8203;7324](https://github.com/cert-manager/cert-manager/pull/7324), [`@cert-manager-bot`](https://github.com/cert-manager-bot)) ### [`v1.15.5`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.5) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.15.4...v1.15.5) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager v1.15.5 contains simple dependency bumps to address reported CVEs (CVE-2024-45337 and CVE-2024-45338). We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners. #### Changes ##### Bug or Regression - Bump golang.org/x/net to address CVE-2024-45337 and CVE-2024-45338 ([#&#8203;7496](https://github.com/cert-manager/cert-manager/issues/7496), [@&#8203;wallrj](https://github.com/wallrj)) ##### Other (Cleanup or Flake) - Bump to go 1.22.10 ([#&#8203;7507](https://github.com/cert-manager/cert-manager/issues/7507), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.15.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.15.3...v1.15.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. This patch release of cert-manager 1.15 makes [several changes](https://github.com/cert-manager/cert-manager/pull/7403) to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed. This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project. The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods. Note also that since most PEM data parsed by cert-manager comes from `ConfigMap` or `Secret` resources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data. Further information is available in <https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4> In addition, the version of Go used to build cert-manager 1.15 was updated along with the base images, and a Route53 bug fix was backported. #### Changes by Kind ##### Bug or Regression - Bugfix: Prevent aggressive Route53 retries caused by STS authentication failures by removing the Amazon Request ID from STS errors. ([#&#8203;7261](https://github.com/cert-manager/cert-manager/pull/7261), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Set a maximum size for PEM inputs which cert-manager will accept to remove possibility of taking a long time to process an input ([#&#8203;7402](https://github.com/cert-manager/cert-manager/pull/7402), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ##### Other (Cleanup or Flake) - Bump go to 1.22.9 ([#&#8203;7424](https://github.com/cert-manager/cert-manager/pull/7424), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Upgrade Go to 1.22.8, the latest available patch release ([#&#8203;7406](https://github.com/cert-manager/cert-manager/pull/7406), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.15.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.15.2...v1.15.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. **🔗 [See v1.15.0](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.0) for more information about cert-manager 1.15 and read-before-upgrade info.** #### 📜 Changes since [`v1.15.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.2) ##### Bug or Regression - BUGFIX: the dynamic certificate source used by the webhook TLS server failed to detect a root CA approaching expiration, due to a calculation error. This will cause the webhook TLS server to fail renewing its CA certificate. Please upgrade before the expiration of this CA certificate is reached. ([#&#8203;7232](https://github.com/cert-manager/cert-manager/issues/7232), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ### [`v1.15.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.15.1...v1.15.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. **🔗 [See v1.15.0](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.0) for more information about cert-manager 1.15 and read-before-upgrade info.** #### 📜 Changes since [`v1.15.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.1) ##### Bug or Regression - BUGFIX `route53`: explicitly set the `aws-global` STS region which is now required by the `github.com/aws/aws-sdk-go-v2` library. ([#&#8203;7189](https://github.com/cert-manager/cert-manager/pull/7189), [`@cert-manager-bot`](https://github.com/cert-manager-bot)) - Bump `grpc-go` to fix `GHSA-xr7q-jx4m-x55m` ([#&#8203;7167](https://github.com/cert-manager/cert-manager/pull/7167), [`@SgtCoDFish`](https://github.com/SgtCoDFish)) - Fix Azure DNS causing panics whenever authentication error happens ([#&#8203;7188](https://github.com/cert-manager/cert-manager/pull/7188), [`@cert-manager-bot`](https://github.com/cert-manager-bot)) - Fix incorrect value and indentation of `endpointAdditionalProperties` in the `PodMonitor` template of the Helm chart ([#&#8203;7191](https://github.com/cert-manager/cert-manager/pull/7191), [`@inteon`](https://github.com/inteon)) - Fixes ACME HTTP01 challenge behavior when using Gateway API to prevent unbounded creation of `HTTPRoute` resources ([#&#8203;7186](https://github.com/cert-manager/cert-manager/pull/7186), [`@cert-manager-bot`](https://github.com/cert-manager-bot)) - Upgrade `golang` from `1.22.3` to `1.22.5` ([#&#8203;7165](https://github.com/cert-manager/cert-manager/pull/7165), [`@github-actions`](https://github.com/github-actions)) ### [`v1.15.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.15.0...v1.15.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. **🔗 [See v1.15.0](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.0) for more information about cert-manager 1.15 and read-before-upgrade info.** #### 📜 Changes since [v1.15.0](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.0) ##### Bug or Regression - BUGFIX: fix issue that caused Vault issuer to not retry signing when an error was encountered. ([#&#8203;7111](https://github.com/cert-manager/cert-manager/issues/7111), [@&#8203;inteon](https://github.com/inteon)) ##### Other (Cleanup or Flake) - Update github.com/Azure/azure-sdk-for-go/sdk/azidentity to address CVE-2024-35255 ([#&#8203;7092](https://github.com/cert-manager/cert-manager/issues/7092), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Bump the go-retryablehttp dependency to fix CVE-2024-6104 ([#&#8203;7130](https://github.com/cert-manager/cert-manager/issues/7130), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.15.0`](https://github.com/cert-manager/cert-manager/releases/tag/v1.15.0) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.7...v1.15.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.15 promotes several features to beta, including GatewayAPI support (`ExperimentalGatewayAPISupport`), the ability to provide a subject in the Certificate that will be used literally in the CertificateSigningRequest (`LiteralCertificateSubject`) and the outputting of additional certificate formats (`AdditionalCertificateOutputFormats`). > \[!NOTE] > > The `cmctl` binary have been moved to <https://github.com/cert-manager/cmctl/releases>. > For the startupapicheck Job you should update references to point at `quay.io/jetstack/cert-manager-startupapicheck` > \[!NOTE] > > From this release, the Helm chart will no longer uninstall the CRDs when the chart is uninstalled. If you want the CRDs to be removed on uninstall use `crds.keep=false` when installing the Helm chart. #### Community Thanks again to all open-source contributors with commits in this release, including: [@&#8203;Pionerd](https://github.com/Pionerd), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot), [@&#8203;andrey-dubnik](https://github.com/andrey-dubnik), [@&#8203;bwaldrep](https://github.com/bwaldrep), [@&#8203;eplightning](https://github.com/eplightning), [@&#8203;erikgb](https://github.com/erikgb), [@&#8203;findnature](https://github.com/findnature), [@&#8203;gplessis](https://github.com/gplessis), [@&#8203;import-shiburin](https://github.com/import-shiburin), [@&#8203;inteon](https://github.com/inteon), [@&#8203;jkroepke](https://github.com/jkroepke), [@&#8203;lunarwhite](https://github.com/lunarwhite), [@&#8203;mangeshhambarde](https://github.com/mangeshhambarde), [@&#8203;pwhitehead-splunk](https://github.com/pwhitehead-splunk) & [@&#8203;rodrigorfk](https://github.com/rodrigorfk), [@&#8203;wallrj](https://github.com/wallrj). Thanks also to the following cert-manager maintainers for their contributions during this release: [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish), [@&#8203;SpectralHiss](https://github.com/SpectralHiss), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot), [@&#8203;hawksight](https://github.com/hawksight), [@&#8203;inteon](https://github.com/inteon), [@&#8203;maelvls](https://github.com/maelvls) & [@&#8203;wallrj](https://github.com/wallrj). Equally thanks to everyone who provided feedback, helped users and raised issues on GitHub and Slack and joined our meetings! Thanks also to the CNCF, which provides resources and support, and to the AWS open source team for being good community members and for their maintenance of the PrivateCA Issuer. In addition, massive thanks to Venafi for contributing developer time and resources towards the continued maintenance of cert-manager projects. #### Changes by Kind ##### Feature - GatewayAPI support has graduated to Beta. Add the `--enable-gateway-api` flag to enable the integration. ([#&#8203;6961](https://github.com/cert-manager/cert-manager/issues/6961), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) - Add support to specify a custom key alias in a JKS Keystore ([#&#8203;6807](https://github.com/cert-manager/cert-manager/issues/6807), [@&#8203;bwaldrep](https://github.com/bwaldrep)) - Add the ability to communicate with Vault via mTLS when strict client certificates is enabled at Vault server side ([#&#8203;6614](https://github.com/cert-manager/cert-manager/issues/6614), [@&#8203;rodrigorfk](https://github.com/rodrigorfk)) - Added option to provide additional audiences in the service account auth section for vault ([#&#8203;6718](https://github.com/cert-manager/cert-manager/issues/6718), [@&#8203;andrey-dubnik](https://github.com/andrey-dubnik)) - Venafi Issuer now sends a cert-manager HTTP User-Agent header in all Venafi Rest API requests. For example: `cert-manager-certificaterequests-issuer-venafi/v1.15.0+(linux/amd64)+cert-manager/ef068a59008f6ed919b98a7177921ddc9e297200`. ([#&#8203;6865](https://github.com/cert-manager/cert-manager/issues/6865), [@&#8203;wallrj](https://github.com/wallrj)) - Add hint to validation error message to help users of external issuers more easily fix the issue if they specify a Kind but forget the Group ([#&#8203;6913](https://github.com/cert-manager/cert-manager/issues/6913), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Add support for numeric OID types in LiteralSubject. Eg. "1.2.3.4=String Value" ([#&#8203;6775](https://github.com/cert-manager/cert-manager/issues/6775), [@&#8203;inteon](https://github.com/inteon)) - Promote the `LiteralCertificateSubject` feature to Beta. ([#&#8203;7030](https://github.com/cert-manager/cert-manager/issues/7030), [@&#8203;inteon](https://github.com/inteon)) - Promoted the AdditionalCertificateOutputFormats feature gate to Beta (enabled by default). ([#&#8203;6970](https://github.com/cert-manager/cert-manager/issues/6970), [@&#8203;erikgb](https://github.com/erikgb)) - The Helm chart now allows you to supply `extraObjects`; a list of yaml manifests which will helm will install and uninstall with the cert-manager manifests. ([#&#8203;6424](https://github.com/cert-manager/cert-manager/issues/6424), [@&#8203;gplessis](https://github.com/gplessis)) - Update the Route53 provider to support fetching credentials using AssumeRoleWithWebIdentity ([#&#8203;6878](https://github.com/cert-manager/cert-manager/issues/6878), [@&#8203;pwhitehead-splunk](https://github.com/pwhitehead-splunk)) - Helm can now add optional hostAliases to cert-manager Pod to allow the DNS self-check to pass in custom scenarios. ([#&#8203;6456](https://github.com/cert-manager/cert-manager/issues/6456), [@&#8203;Pionerd](https://github.com/Pionerd)) - Added a new Ingress annotation for copying specific Ingress annotations to Certificate's secretTemplate ([#&#8203;6839](https://github.com/cert-manager/cert-manager/issues/6839), [@&#8203;mangeshhambarde](https://github.com/mangeshhambarde)) - Added option to define additional token audiences for the Vault Kubernetes auth ([#&#8203;6744](https://github.com/cert-manager/cert-manager/issues/6744), [@&#8203;andrey-dubnik](https://github.com/andrey-dubnik)) - Allow `cert-manager.io/allow-direct-injection` in annotations ([#&#8203;6801](https://github.com/cert-manager/cert-manager/issues/6801), [@&#8203;jkroepke](https://github.com/jkroepke)) ##### Design - Remove repetitive words ([#&#8203;6949](https://github.com/cert-manager/cert-manager/issues/6949), [@&#8203;findnature](https://github.com/findnature)) ##### Bug or Regression - BUGFIX: Fixes issue with JSON-logging, where only a subset of the log messages were output as JSON. ([#&#8203;6779](https://github.com/cert-manager/cert-manager/issues/6779), [@&#8203;inteon](https://github.com/inteon)) - BUGFIX: JKS and PKCS12 stores now contain the full set of CAs specified by an issuer ([#&#8203;6806](https://github.com/cert-manager/cert-manager/issues/6806), [@&#8203;bwaldrep](https://github.com/bwaldrep)) - BUGFIX: cainjector leaderelection flag/config option defaults are missing ([#&#8203;6816](https://github.com/cert-manager/cert-manager/issues/6816), [@&#8203;inteon](https://github.com/inteon)) - BUGFIX: cert-manager issuers incorrectly copied the critical flag from the CSR instead of re-calculating that field themselves. ([#&#8203;6724](https://github.com/cert-manager/cert-manager/issues/6724), [@&#8203;inteon](https://github.com/inteon)) - Breaking Change: Fixed unintended certificate chain is used if `preferredChain` is configured. ([#&#8203;6755](https://github.com/cert-manager/cert-manager/issues/6755), [@&#8203;import-shiburin](https://github.com/import-shiburin)) - Bugfix: LiteralSubjects with a #= value can result in memory issues due to faulty BER parser (github.com/go-asn1-ber/asn1-ber). ([#&#8203;6770](https://github.com/cert-manager/cert-manager/issues/6770), [@&#8203;inteon](https://github.com/inteon)) - DigitalOcean: Ensure that only TXT records are considered for deletion when cleaning up after an ACME challenge ([#&#8203;6875](https://github.com/cert-manager/cert-manager/issues/6875), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Fix backwards incompatible removal of default prometheus Service resource. ([#&#8203;6699](https://github.com/cert-manager/cert-manager/issues/6699), [@&#8203;inteon](https://github.com/inteon)) - Fix broken cainjector image value in Helm chart ([#&#8203;6692](https://github.com/cert-manager/cert-manager/issues/6692), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Helm: Fix a bug in the logic that differentiates between 0 and an empty value. ([#&#8203;6713](https://github.com/cert-manager/cert-manager/issues/6713), [@&#8203;inteon](https://github.com/inteon)) - Make sure the Azure SDK error messages are stable. ([#&#8203;6676](https://github.com/cert-manager/cert-manager/issues/6676), [@&#8203;inteon](https://github.com/inteon)) - When using the literalSubject on a Certificate, the webhook validation for the common name now also points to the literalSubject. ([#&#8203;6767](https://github.com/cert-manager/cert-manager/issues/6767), [@&#8203;lunarwhite](https://github.com/lunarwhite)) - Bump golang.org/x/net to fix CVE-2023-45288 ([#&#8203;6929](https://github.com/cert-manager/cert-manager/issues/6929), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Fix ACME issuer being stuck waiting for DNS propagation when using Azure DNS with multiple instances issuing for the same FQDN ([#&#8203;6351](https://github.com/cert-manager/cert-manager/issues/6351), [@&#8203;eplightning](https://github.com/eplightning)) - Fix cainjector ConfigMap not mounted in the cainjector deployment. ([#&#8203;7055](https://github.com/cert-manager/cert-manager/issues/7055), [@&#8203;inteon](https://github.com/inteon)) - Added `disableAutoApproval` and `approveSignerNames` Helm chart options. ([#&#8203;7054](https://github.com/cert-manager/cert-manager/issues/7054), [@&#8203;inteon](https://github.com/inteon)) ##### Other (Cleanup or Flake) - ⚠️ Possibly breaking: Helm will now keep the CRDs when you uninstall cert-manager by default to prevent accidental data loss. ([#&#8203;6760](https://github.com/cert-manager/cert-manager/issues/6760), [@&#8203;inteon](https://github.com/inteon)) - New `crds.keep` and `crds.enabled` Helm options can now be used instead of the `installCRDs` option. ([#&#8203;6760](https://github.com/cert-manager/cert-manager/issues/6760), [@&#8203;inteon](https://github.com/inteon)) - Bump base images ([#&#8203;6840](https://github.com/cert-manager/cert-manager/issues/6840), [@&#8203;inteon](https://github.com/inteon)) - Bump github.com/go-jose/go-jose to v3.0.3 to fix CVE-2024-28180 ([#&#8203;6854](https://github.com/cert-manager/cert-manager/issues/6854), [@&#8203;wallrj](https://github.com/wallrj)) - Removed deprecated util functions that have been replaced by the `slices` and `k8s.io/apimachinery/pkg/util` packages. Removed deprecated CSR functions which have been replaced with other functions in the `pkg/util/pki` package. ([#&#8203;6730](https://github.com/cert-manager/cert-manager/issues/6730), [@&#8203;inteon](https://github.com/inteon)) - Upgrade go to 1.21.8: fixes CVE-2024-24783 ([#&#8203;6823](https://github.com/cert-manager/cert-manager/issues/6823), [@&#8203;inteon](https://github.com/inteon)) - Upgrade go to latest version 1.22.1 ([#&#8203;6831](https://github.com/cert-manager/cert-manager/issues/6831), [@&#8203;inteon](https://github.com/inteon)) - Upgrade google.golang.org/protobuf: fixing GO-2024-2611 ([#&#8203;6827](https://github.com/cert-manager/cert-manager/issues/6827), [@&#8203;inteon](https://github.com/inteon)) - `cmctl` and `kubectl cert-manger` have been moved to the <https://github.com/cert-manager/cmctl> repo and will be versioned separately starting with cmctl v2.0.0 ([#&#8203;6663](https://github.com/cert-manager/cert-manager/issues/6663), [@&#8203;inteon](https://github.com/inteon)) - Graduate the 'DisallowInsecureCSRUsageDefinition' feature gate to GA. (part 2) ([#&#8203;6963](https://github.com/cert-manager/cert-manager/issues/6963), [@&#8203;inteon](https://github.com/inteon)) - Remove deprecated `pkg/util/pki/ParseSubjectStringToRawDERBytes` function. ([#&#8203;6994](https://github.com/cert-manager/cert-manager/issues/6994), [@&#8203;inteon](https://github.com/inteon)) - Upgrade Kind to v0.23.0 and update supported node image digests ([#&#8203;7020](https://github.com/cert-manager/cert-manager/issues/7020), [@&#8203;github-actions](https://github.com/github-actions)\[bot]) - If the `--controllers` flag only specifies disabled controllers, the default controllers are now enabled implicitly. ([#&#8203;7054](https://github.com/cert-manager/cert-manager/issues/7054), [@&#8203;inteon](https://github.com/inteon)) - Upgrade to Go 1.22.3, fixing `GO-2024-2824`. ([#&#8203;6996](https://github.com/cert-manager/cert-manager/issues/6996), [@&#8203;github-actions](https://github.com/github-actions)\[bot]) ### [`v1.14.7`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.7) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.6...v1.14.7) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. #### 📜 Changes since [v1.14.6](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.6) ##### Bugfixes - BUGFIX: fix issue that caused Vault issuer to not retry signing when an error was encountered. ([#&#8203;7113](https://github.com/cert-manager/cert-manager/issues/7113), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) ##### Other (Cleanup or Flake) - Update github.com/Azure/azure-sdk-for-go/sdk/azidentity to address CVE-2024-35255 ([#&#8203;7093](https://github.com/cert-manager/cert-manager/issues/7093), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) ### [`v1.14.6`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.6) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.5...v1.14.6) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. #### 📜 Changes since [v1.14.5](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.5) ##### Other (Cleanup or Flake) - Upgrade Go to 1.21.10, fixing GO-2024-2824 (<https://github.com/advisories/GHSA-2jwv-jmq4-4j3r>). ([#&#8203;7008](https://github.com/cert-manager/cert-manager/issues/7008), [@&#8203;inteon](https://github.com/inteon)) - Helm: the cainjector ConfigMap was not mounted in the cainjector deployment. ([#&#8203;7053](https://github.com/cert-manager/cert-manager/issues/7053), [@&#8203;cert-manager-bot](https://github.com/cert-manager-bot)) - Updated Go to 1.21.11 bringing in security fixes for archive/zip and net/netip. ([#&#8203;7076](https://github.com/cert-manager/cert-manager/issues/7076), [@&#8203;ThatsMrTalbot](https://github.com/ThatsMrTalbot)) ### [`v1.14.5`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.5) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.4...v1.14.5) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. `v1.14.5` fixes a bug in the DigitalOcean DNS-01 provider which could cause incorrect DNS records to be deleted when using a domain with a CNAME. Special thanks to [@&#8203;BobyMCbobs](https://github.com/BobyMCbobs) for reporting this issue and testing the fix! It also patches CVE-2023-45288. #### 📜 Changes since [v1.14.4](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.4) - ACME Issuer (Let's Encrypt): wrong certificate chain may be used if `preferredChain` is configured: see [1.14 release notes](./release-notes-1.14.md#known-issues) for more information. #### Changes ##### Bug or Regression - DigitalOcean: Ensure that only TXT records are considered for deletion when cleaning up after an ACME challenge ([#&#8203;6893](https://github.com/cert-manager/cert-manager/issues/6893) , [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Bump golang.org/x/net to address [CVE-2023-45288](https://nvd.nist.gov/vuln/detail/CVE-2023-45288) ([#&#8203;6931](https://github.com/cert-manager/cert-manager/issues/6931) , [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) ### [`v1.14.4`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.4) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.3...v1.14.4) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions. ##### ⚠️ Known Issues - ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see [release docs](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14/#acme-issuer-lets-encrypt-wrong-certificate-chain-may-be-used-if-preferredchain-is-configured---6755-6757) for more info and mitigations ##### ℹ️ Documentation [Release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14) [Upgrade notes](https://cert-manager.io/docs/releases/upgrading/upgrading-1.13-1.14) [Installation instructions](https://cert-manager.io/docs/installation/) ##### 🔧 Breaking changes See Breaking changes in [v1.14.0 release notes](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.0) ##### 📜 Changes since v1.14.3 ##### Bug or Regression - Allow `cert-manager.io/allow-direct-injection` in annotations ([#&#8203;6809](https://github.com/cert-manager/cert-manager/issues/6809), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) - BUGFIX: JKS and PKCS12 stores now contain the full set of CAs specified by an issuer ([#&#8203;6812](https://github.com/cert-manager/cert-manager/issues/6812), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) - BUGFIX: cainjector leaderelection flag/ config option defaults are missing ([#&#8203;6819](https://github.com/cert-manager/cert-manager/issues/6819), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) ##### Other (Cleanup or Flake) - Bump base images. ([#&#8203;6842](https://github.com/cert-manager/cert-manager/issues/6842), [@&#8203;inteon](https://github.com/inteon)) - Upgrade Helm: fix CVE-2024-26147 alert ([#&#8203;6834](https://github.com/cert-manager/cert-manager/issues/6834), [@&#8203;inteon](https://github.com/inteon)) - Upgrade go to 1.21.8: fixes CVE-2024-24783 ([#&#8203;6825](https://github.com/cert-manager/cert-manager/issues/6825), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) - Upgrade google.golang.org/protobuf: fixing GO-2024-2611 ([#&#8203;6829](https://github.com/cert-manager/cert-manager/issues/6829), [@&#8203;inteon](https://github.com/inteon)) ### [`v1.14.3`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.3) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.2...v1.14.3) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions. ##### ⚠️ Known Issues - ACME Issuer (Let's Encrypt): wrong certificate chain may be used if preferredChain is configured: see [release docs](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14/#acme-issuer-lets-encrypt-wrong-certificate-chain-may-be-used-if-preferredchain-is-configured---6755-6757) for more info and mitigations - cainjector leaderelection is incorrectly disabled by default because the flag/ config option defaults are missing ([#&#8203;6819](https://github.com/cert-manager/cert-manager/pull/6819)) ##### ℹ️ Documentation [Release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14) [Upgrade notes](https://cert-manager.io/docs/releases/upgrading/upgrading-1.13-1.14) [Installation instructions](https://cert-manager.io/docs/installation/) ##### 🔧 Breaking changes See Breaking changes in [v1.14.0 release notes](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.0) ##### 📜 Changes since v1.14.2 ##### Bug or Regression - BUGFIX: Fixes issue with JSON-logging, where only a subset of the log messages were output as JSON. ([#&#8203;6781](https://github.com/cert-manager/cert-manager/issues/6781), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) - BUGFIX: LiteralSubjects with a #= value can result in memory issues due to faulty BER parser (github.com/go-asn1-ber/asn1-ber). ([#&#8203;6774](https://github.com/cert-manager/cert-manager/issues/6774), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) ### [`v1.14.2`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.2) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.1...v1.14.2) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions. ##### ⚠️ Known Issues - ACME Issuer (Let's Encrypt): wrong certificate chain may be used if `preferredChain` is configured: see [release docs](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14/#acme-issuer-lets-encrypt-wrong-certificate-chain-may-be-used-if-preferredchain-is-configured---6755-6757) for more info and mitigations - Logging-format json sometimes writes plaintext messages (see [#&#8203;6768](https://github.com/cert-manager/cert-manager/issues/6768)). FIXED in v1.14.3 ##### ℹ️ Documentation [Release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14) [Upgrade notes](https://cert-manager.io/docs/releases/upgrading/upgrading-1.13-1.14) [Installation instructions](https://cert-manager.io/docs/installation/) ##### 🔧 Breaking changes See `Breaking changes` in [v1.14.0 release notes](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.0) ##### 📜 Changes since `v1.14.1` ##### Bug or Regression - BUGFIX: cert-manager CA and SelfSigned issuers incorrectly copied the critical flag from the CSR instead of re-calculating that field themselves. ([#&#8203;6727](https://github.com/cert-manager/cert-manager/issues/6727), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) - Helm: Fix a bug in the logic that differentiates between 0 and an empty value. ([#&#8203;6729](https://github.com/cert-manager/cert-manager/issues/6729), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) ##### Other (Cleanup or Flake) - Bump golang to 1.21.7 ([#&#8203;6735](https://github.com/cert-manager/cert-manager/issues/6735), [@&#8203;jetstack-bot](https://github.com/jetstack-bot)) ### [`v1.14.1`](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.1) [Compare Source](https://github.com/cert-manager/cert-manager/compare/v1.14.0...v1.14.1) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions. > ⚠️ This version has known issues. Please install `v1.14.2` instead. ##### ⚠️ Known Issues (please install `v1.14.2`) - ACME Issuer (Let's Encrypt): wrong certificate chain may be used if `preferredChain` is configured: see [release docs](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14/#acme-issuer-lets-encrypt-wrong-certificate-chain-may-be-used-if-preferredchain-is-configured---6755-6757) for more info and mitigations - In cert-manager v1.14.0 and v1.14.1, the `CA` and `SelfSigned` issuers issue certificates with SANs set to non-critical even when the subject is empty. It incorrectly copies the critical field from the CSR. ##### 🔧 Breaking changes See `Breaking changes` in [v1.14.0 release notes](https://github.com/cert-manager/cert-manager/releases/tag/v1.14.0) ##### ℹ️ Documentation - [Release notes](https://cert-manager.io/docs/releases/release-notes/release-notes-1.14) - [Upgrade notes](https://cert-manager.io/docs/releases/upgrading/upgrading-1.13-1.14) - [Installation instructions](https://cert-manager.io/docs/installation/) ##### 📜 Changes since `v1.14.0` ##### Bug or Regression - Fix broken cainjector image value in Helm chart ([#&#8203;6693](https://github.com/cert-manager/cert-manager/pull/6693), [@&#8203;SgtCoDFish](https://github.com/SgtCoDFish)) - Fix bug in cmctl namespace detection which prevented it being used as a startupapicheck image in namespaces other than cert-manager. ([#&#8203;6706](https://github.com/cert-manager/cert-manager/pull/6706), [@&#8203;inteon](https://github.com/inteon)) - Fix bug in cmctl which caused `cmctl experimental install` to panic. ([#&#8203;6706](https://github.com/cert-manager/cert-manager/pull/6706), [@&#8203;inteon](https://github.com/inteon)) </details> <details> <summary>gitea/helm-gitea (gitea)</summary> ### [`v12.7.0`](https://gitea.com/gitea/helm-gitea/releases/tag/v12.7.0) [Compare Source](https://gitea.com/gitea/helm-gitea/compare/v12.6.0...v12.7.0) ##### Features - add Gateway API support ([#&#8203;1073](https://github.com/gitea/helm-gitea/issues/1073)) ([`7747a00`](https://github.com/gitea/helm-gitea/commit/7747a00)) ##### Maintenance - **deps:** update alpine/helm docker tag to v3.21.3 ([#&#8203;1096](https://github.com/gitea/helm-gitea/issues/1096)) ([`5005037`](https://github.com/gitea/helm-gitea/commit/5005037)) - **deps:** update to 1.27.0 ([#&#8203;1095](https://github.com/gitea/helm-gitea/issues/1095)) ([`61d6d23`](https://github.com/gitea/helm-gitea/commit/61d6d23)) - **deps:** update workflow dependencies (minor & patch) ([#&#8203;1094](https://github.com/gitea/helm-gitea/issues/1094)) ([`b6ded8d`](https://github.com/gitea/helm-gitea/commit/b6ded8d)) - **deps:** update gitea version to 1.26.4 ([#&#8203;1093](https://github.com/gitea/helm-gitea/issues/1093)) ([`e97e592`](https://github.com/gitea/helm-gitea/commit/e97e592)) - **deps:** update workflow dependencies (minor & patch) ([#&#8203;1092](https://github.com/gitea/helm-gitea/issues/1092)) ([`78276bc`](https://github.com/gitea/helm-gitea/commit/78276bc)) - **deps:** update dependency helm-unittest/helm-unittest to v1.1.1 ([#&#8203;1090](https://github.com/gitea/helm-gitea/issues/1090)) ([`2691024`](https://github.com/gitea/helm-gitea/commit/2691024)) - **deps:** update lockfiles ([#&#8203;1087](https://github.com/gitea/helm-gitea/issues/1087)) ([`8198a89`](https://github.com/gitea/helm-gitea/commit/8198a89)) - **deps:** update dependency go-gitea/gitea to v1.26.2 ([#&#8203;1084](https://github.com/gitea/helm-gitea/issues/1084)) ([`323b6bc`](https://github.com/gitea/helm-gitea/commit/323b6bc)) - **deps:** update lockfiles ([#&#8203;1082](https://github.com/gitea/helm-gitea/issues/1082)) ([`8498819`](https://github.com/gitea/helm-gitea/commit/8498819)) - **deps:** update workflow dependencies (minor & patch) ([#&#8203;1080](https://github.com/gitea/helm-gitea/issues/1080)) ([`44d7783`](https://github.com/gitea/helm-gitea/commit/44d7783)) </details> <details> <summary>go-gitea/gitea (gitea/gitea)</summary> ### [`v1.27.3`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1273---2026-08-29) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.2...v1.27.3) - SECURITY - fix(packages): restrict/limited/token-scope access ([#&#8203;39041](https://github.com/go-gitea/gitea/issues/39041), [#&#8203;39043](https://github.com/go-gitea/gitea/issues/39043), [#&#8203;39044](https://github.com/go-gitea/gitea/issues/39044), [#&#8203;39047](https://github.com/go-gitea/gitea/issues/39047), [#&#8203;39046](https://github.com/go-gitea/gitea/issues/39046)) ([#&#8203;39058](https://github.com/go-gitea/gitea/issues/39058)) - fix(attachments): enforce owning repository path ([#&#8203;39048](https://github.com/go-gitea/gitea/issues/39048)) ([#&#8203;39077](https://github.com/go-gitea/gitea/issues/39077)) - fix(markup): enforce same-repository issue access ([#&#8203;39045](https://github.com/go-gitea/gitea/issues/39045)) ([#&#8203;39054](https://github.com/go-gitea/gitea/issues/39054)) - fix(actions): verify raw artifact signatures first ([#&#8203;39049](https://github.com/go-gitea/gitea/issues/39049)) ([#&#8203;39053](https://github.com/go-gitea/gitea/issues/39053)) - fix(api): hide limited users from restricted viewers ([#&#8203;39004](https://github.com/go-gitea/gitea/issues/39004)) ([#&#8203;39039](https://github.com/go-gitea/gitea/issues/39039)) - fix(repo): limit gitignore template selections ([#&#8203;39027](https://github.com/go-gitea/gitea/issues/39027)) ([#&#8203;39040](https://github.com/go-gitea/gitea/issues/39040)) - fix(migrations): cancel GitLab version probes ([#&#8203;39023](https://github.com/go-gitea/gitea/issues/39023)) ([#&#8203;39035](https://github.com/go-gitea/gitea/issues/39035)) - fix(packages): limit Swift package manifests ([#&#8203;39025](https://github.com/go-gitea/gitea/issues/39025)) ([#&#8203;39032](https://github.com/go-gitea/gitea/issues/39032)) - fix(migrations): bound OneDev version responses ([#&#8203;39024](https://github.com/go-gitea/gitea/issues/39024)) ([#&#8203;39033](https://github.com/go-gitea/gitea/issues/39033)) - fix(packages): limit Maven checksum uploads ([#&#8203;39028](https://github.com/go-gitea/gitea/issues/39028)) ([#&#8203;39031](https://github.com/go-gitea/gitea/issues/39031)) - fix(packages): bound Alpine metadata entries ([#&#8203;39026](https://github.com/go-gitea/gitea/issues/39026)) ([#&#8203;39029](https://github.com/go-gitea/gitea/issues/39029)) - fix(actions): enforce fork pull request trust boundaries ([#&#8203;39005](https://github.com/go-gitea/gitea/issues/39005)) ([#&#8203;39018](https://github.com/go-gitea/gitea/issues/39018)) - fix(git): restrict hook permissions ([#&#8203;39008](https://github.com/go-gitea/gitea/issues/39008)) ([#&#8203;39016](https://github.com/go-gitea/gitea/issues/39016)) - fix(api): enforce repository creation token authorization ([#&#8203;39007](https://github.com/go-gitea/gitea/issues/39007)) ([#&#8203;39014](https://github.com/go-gitea/gitea/issues/39014)) - fix(api): enforce public-only scope for compare heads ([#&#8203;39006](https://github.com/go-gitea/gitea/issues/39006)) ([#&#8203;39013](https://github.com/go-gitea/gitea/issues/39013)) - fix(repo): hide repositories of hidden owners ([#&#8203;39009](https://github.com/go-gitea/gitea/issues/39009)) ([#&#8203;39012](https://github.com/go-gitea/gitea/issues/39012)) - fix: avoid enumerating every public repository in issue search ([#&#8203;38992](https://github.com/go-gitea/gitea/issues/38992)) ([#&#8203;39000](https://github.com/go-gitea/gitea/issues/39000)) - refactor: private endpoints ([#&#8203;38964](https://github.com/go-gitea/gitea/issues/38964)) ([#&#8203;38965](https://github.com/go-gitea/gitea/issues/38965)) - ENHANCEMENTS - enhance: add permalinks to pull request reviews ([#&#8203;38849](https://github.com/go-gitea/gitea/issues/38849)) ([#&#8203;39036](https://github.com/go-gitea/gitea/issues/39036)) - BUGFIXES - fix: add missing query parameters on runner list page ([#&#8203;39163](https://github.com/go-gitea/gitea/issues/39163)) - fix(actions): keep step-level continue-on-error expressions unevaluated ([#&#8203;39141](https://github.com/go-gitea/gitea/issues/39141)) ([#&#8203;39148](https://github.com/go-gitea/gitea/issues/39148)) - fix(packages): preserve SemVer prerelease identifiers in Swift Registry ([#&#8203;39156](https://github.com/go-gitea/gitea/issues/39156)) ([#&#8203;39158](https://github.com/go-gitea/gitea/issues/39158)) - fix(repo): prevent MarkAsBrokenEmpty when repository is being migrated ([#&#8203;39091](https://github.com/go-gitea/gitea/issues/39091)) ([#&#8203;39092](https://github.com/go-gitea/gitea/issues/39092)) - fix(asymkey): do not verify OpenPGP signatures with an SSH instance key ([#&#8203;39073](https://github.com/go-gitea/gitea/issues/39073)) ([#&#8203;39086](https://github.com/go-gitea/gitea/issues/39086)) - fix(pull): keep the merged state in sync with git ([#&#8203;39062](https://github.com/go-gitea/gitea/issues/39062)) ([#&#8203;39118](https://github.com/go-gitea/gitea/issues/39118)) - fix(pull): name the head repository in default compare links ([#&#8203;39075](https://github.com/go-gitea/gitea/issues/39075)) ([#&#8203;39079](https://github.com/go-gitea/gitea/issues/39079)) - fix(git): parse co-author trailers that are not RFC 5322 addresses ([#&#8203;39076](https://github.com/go-gitea/gitea/issues/39076)) ([#&#8203;39081](https://github.com/go-gitea/gitea/issues/39081)) - fix(actions): show "Complete job" logs when the last step is skipped ([#&#8203;38939](https://github.com/go-gitea/gitea/issues/38939)) ([#&#8203;39003](https://github.com/go-gitea/gitea/issues/39003)) - fix(actions): Fix how jobs in matrixes are grouped ([#&#8203;38980](https://github.com/go-gitea/gitea/issues/38980)) ([#&#8203;38998](https://github.com/go-gitea/gitea/issues/38998)) - fix: resolve YAML anchors and aliases in Actions workflows ([#&#8203;38984](https://github.com/go-gitea/gitea/issues/38984)) ([#&#8203;38996](https://github.com/go-gitea/gitea/issues/38996)) - fix: honor environment variables during install ([#&#8203;38974](https://github.com/go-gitea/gitea/issues/38974)) ([#&#8203;38976](https://github.com/go-gitea/gitea/issues/38976)) - fix: grant limited-org unit read access to authenticated non-members ([#&#8203;38871](https://github.com/go-gitea/gitea/issues/38871)) ([#&#8203;38963](https://github.com/go-gitea/gitea/issues/38963)) - fix: allow anonymous theme switching when REQUIRE\_SIGNIN\_VIEW is set ([#&#8203;38956](https://github.com/go-gitea/gitea/issues/38956)) ([#&#8203;38961](https://github.com/go-gitea/gitea/issues/38961)) - fix(actions): drop wrapper span around the action status icon ([#&#8203;38957](https://github.com/go-gitea/gitea/issues/38957)) ([#&#8203;38959](https://github.com/go-gitea/gitea/issues/38959)) - fix(issues): sort scoped labels by exclusive order in dropdowns ([#&#8203;38893](https://github.com/go-gitea/gitea/issues/38893)) ([#&#8203;38954](https://github.com/go-gitea/gitea/issues/38954)) - fix(indexer): correct bleve indexer token filters ([#&#8203;38853](https://github.com/go-gitea/gitea/issues/38853)) ([#&#8203;38951](https://github.com/go-gitea/gitea/issues/38951)) - fix: make "login\_name" field optional for API edit user ([#&#8203;38917](https://github.com/go-gitea/gitea/issues/38917)) ([#&#8203;38945](https://github.com/go-gitea/gitea/issues/38945)) - fix(actions): reject non-mapping matrix include/exclude ([#&#8203;38933](https://github.com/go-gitea/gitea/issues/38933)) - fix(ui): respect FEED\_PAGING\_NUM on the dashboard feed ([#&#8203;38935](https://github.com/go-gitea/gitea/issues/38935)) ([#&#8203;38936](https://github.com/go-gitea/gitea/issues/38936)) - MISC - chore: repo compare link ([#&#8203;39088](https://github.com/go-gitea/gitea/issues/39088)) ([#&#8203;39119](https://github.com/go-gitea/gitea/issues/39119)) - ci: remove AWS S3 uploads from release workflows ([#&#8203;38928](https://github.com/go-gitea/gitea/issues/38928)) ([#&#8203;38929](https://github.com/go-gitea/gitea/issues/38929)) - chore: Pre-register a builtin OAuth2 application for the official Gitea mobile app ([#&#8203;38880](https://github.com/go-gitea/gitea/issues/38880)) ([#&#8203;38922](https://github.com/go-gitea/gitea/issues/38922)) ### [`v1.27.2`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1272---2026-08-14) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.1...v1.27.2) - SECURITY - Fix: update collaborator access mode and httpsign ([#&#8203;38894](https://github.com/go-gitea/gitea/issues/38894), [#&#8203;38862](https://github.com/go-gitea/gitea/issues/38862)) ([#&#8203;38895](https://github.com/go-gitea/gitea/issues/38895)) - Refactor: external render ([#&#8203;38885](https://github.com/go-gitea/gitea/issues/38885)) ([#&#8203;38898](https://github.com/go-gitea/gitea/issues/38898)) - Fix(actions): resolve pull\_request\_target reusable workflows at the base commit ([#&#8203;38886](https://github.com/go-gitea/gitea/issues/38886)) ([#&#8203;38897](https://github.com/go-gitea/gitea/issues/38897)) - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/issues/38864)) ([#&#8203;38869](https://github.com/go-gitea/gitea/issues/38869)) - Fix(deps): update dependency mermaid to v11.16.1 ([#&#8203;38816](https://github.com/go-gitea/gitea/issues/38816)) - Fix(auth): set WebAuthn user verification per request ([#&#8203;38805](https://github.com/go-gitea/gitea/issues/38805)) ([#&#8203;38810](https://github.com/go-gitea/gitea/issues/38810)) - Fix: render highlight language ([#&#8203;38793](https://github.com/go-gitea/gitea/issues/38793)) ([#&#8203;38795](https://github.com/go-gitea/gitea/issues/38795)) - ENHANCEMENTS - enhance: add missing npm package metadata properties ([#&#8203;38826](https://github.com/go-gitea/gitea/issues/38826)) ([#&#8203;38831](https://github.com/go-gitea/gitea/issues/38831)) - BUGFIXES - fix(actions): keep github.event.inputs as strings for workflow\_dispatch ([#&#8203;38899](https://github.com/go-gitea/gitea/issues/38899)) ([#&#8203;38908](https://github.com/go-gitea/gitea/issues/38908)) - fix(actions): let a rerun of selected jobs read the previous attempt's artifacts ([#&#8203;38857](https://github.com/go-gitea/gitea/issues/38857)) ([#&#8203;38901](https://github.com/go-gitea/gitea/issues/38901)) - fix(lfs): accept successful transfer responses ([#&#8203;38866](https://github.com/go-gitea/gitea/issues/38866)) ([#&#8203;38875](https://github.com/go-gitea/gitea/issues/38875)) - fix(packages): ignore nested Package.swift ([#&#8203;38788](https://github.com/go-gitea/gitea/issues/38788)) ([#&#8203;38836](https://github.com/go-gitea/gitea/issues/38836)) - fix: drop newline-bearing member names in arch ParsePackage ([#&#8203;38102](https://github.com/go-gitea/gitea/issues/38102)) ([#&#8203;38830](https://github.com/go-gitea/gitea/issues/38830)) - fix(storage): fix Azure Blob dump failing with file does not exist ([#&#8203;38814](https://github.com/go-gitea/gitea/issues/38814)) ([#&#8203;38828](https://github.com/go-gitea/gitea/issues/38828)) - fix(migration): migration deletion returned json redirection ([#&#8203;38796](https://github.com/go-gitea/gitea/issues/38796)) ([#&#8203;38825](https://github.com/go-gitea/gitea/issues/38825)) - fix(ui): change underlines to default browser style ([#&#8203;38819](https://github.com/go-gitea/gitea/issues/38819)) ([#&#8203;38823](https://github.com/go-gitea/gitea/issues/38823)) - fix(actions): allow cancelling runs without running jobs ([#&#8203;35842](https://github.com/go-gitea/gitea/issues/35842)) ([#&#8203;38812](https://github.com/go-gitea/gitea/issues/38812)) - fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/issues/38754)) ([#&#8203;38797](https://github.com/go-gitea/gitea/issues/38797)) - fix(actions): write an action task report in one transaction ([#&#8203;38792](https://github.com/go-gitea/gitea/issues/38792)) ([#&#8203;38794](https://github.com/go-gitea/gitea/issues/38794)) - fix: markup link ([#&#8203;38764](https://github.com/go-gitea/gitea/issues/38764)) ([#&#8203;38765](https://github.com/go-gitea/gitea/issues/38765)) - fix: set a minio part size when the content size is unknown ([#&#8203;38753](https://github.com/go-gitea/gitea/issues/38753)) ([#&#8203;38755](https://github.com/go-gitea/gitea/issues/38755)) - fix: bad path escape in subpath archive download ([#&#8203;38749](https://github.com/go-gitea/gitea/issues/38749)) ([#&#8203;38750](https://github.com/go-gitea/gitea/issues/38750)) - fix: remove the pull merge box from UI when the refreshed page doesn't contain it ([#&#8203;38742](https://github.com/go-gitea/gitea/issues/38742)) ([#&#8203;38744](https://github.com/go-gitea/gitea/issues/38744)) - fix(markdown): fix double strikethough on code ([#&#8203;38707](https://github.com/go-gitea/gitea/issues/38707)) ([#&#8203;38729](https://github.com/go-gitea/gitea/issues/38729)) - fix(lfs): failed upload deletes a concurrent upload's meta object ([#&#8203;38693](https://github.com/go-gitea/gitea/issues/38693)) ([#&#8203;38722](https://github.com/go-gitea/gitea/issues/38722)) - fix: correct full url when using sub-path ([#&#8203;38712](https://github.com/go-gitea/gitea/issues/38712)) ([#&#8203;38716](https://github.com/go-gitea/gitea/issues/38716)) - fix: avoid markup render panic ([#&#8203;38698](https://github.com/go-gitea/gitea/issues/38698)) ([#&#8203;38703](https://github.com/go-gitea/gitea/issues/38703)) - fix(ui): too many participants shown in commit avatar stacks ([#&#8203;38689](https://github.com/go-gitea/gitea/issues/38689)) ([#&#8203;38700](https://github.com/go-gitea/gitea/issues/38700)) - fix: support HEAD requests on Alpine registry APKINDEX.tar.gz ([#&#8203;38686](https://github.com/go-gitea/gitea/issues/38686)) ([#&#8203;38688](https://github.com/go-gitea/gitea/issues/38688)) - fix(migrations): use all configured GitHub tokens ([#&#8203;38841](https://github.com/go-gitea/gitea/issues/38841)) ([#&#8203;38846](https://github.com/go-gitea/gitea/issues/38846)) ### [`v1.27.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1271---2026-07-27) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.0...v1.27.1) - SECURITY - Fix: orgmode render include path ([#&#8203;38642](https://github.com/go-gitea/gitea/issues/38642)) ([#&#8203;38645](https://github.com/go-gitea/gitea/issues/38645)) - Fix: git patch apply ([#&#8203;38637](https://github.com/go-gitea/gitea/issues/38637)) ([#&#8203;38638](https://github.com/go-gitea/gitea/issues/38638)) - Fix(oauth2): enforce mandatory 2FA policy on OAuth2 authorize/grant endpoints ([#&#8203;38591](https://github.com/go-gitea/gitea/issues/38591)) ([#&#8203;38606](https://github.com/go-gitea/gitea/issues/38606)) - API - fix(api): align Swagger schemas for UserSettings and TopicListResponse ([#&#8203;38590](https://github.com/go-gitea/gitea/issues/38590)) ([#&#8203;38592](https://github.com/go-gitea/gitea/issues/38592)) - ENHANCEMENTS - enhance: improve diff contrast in light and dark themes ([#&#8203;37477](https://github.com/go-gitea/gitea/issues/37477)) ([#&#8203;38574](https://github.com/go-gitea/gitea/issues/38574)) - BUGFIXES - fix: skip OIDC end-session after password login for OAuth2 users ([#&#8203;38439](https://github.com/go-gitea/gitea/issues/38439)) ([#&#8203;38666](https://github.com/go-gitea/gitea/issues/38666)) - fix: make Actions log parser support multiple line message encoding ([#&#8203;38659](https://github.com/go-gitea/gitea/issues/38659)) ([#&#8203;38664](https://github.com/go-gitea/gitea/issues/38664)) - fix(actions): use base branch ref for pull\_request\_target context ([#&#8203;38636](https://github.com/go-gitea/gitea/issues/38636)) ([#&#8203;38657](https://github.com/go-gitea/gitea/issues/38657)) - fix(actions): skip already-approved runs in `ApproveRuns` ([#&#8203;38653](https://github.com/go-gitea/gitea/issues/38653)) ([#&#8203;38654](https://github.com/go-gitea/gitea/issues/38654)) - fix: orgmode render include path ([#&#8203;38642](https://github.com/go-gitea/gitea/issues/38642)) ([#&#8203;38645](https://github.com/go-gitea/gitea/issues/38645)) - fix(actions): cancel tasks immediately when the runner stopped reporting ([#&#8203;38616](https://github.com/go-gitea/gitea/issues/38616)) ([#&#8203;38644](https://github.com/go-gitea/gitea/issues/38644)) - fix(issues): fix label bulk-load key and reduce log noise in LoadLabel ([#&#8203;38632](https://github.com/go-gitea/gitea/issues/38632)) ([#&#8203;38643](https://github.com/go-gitea/gitea/issues/38643)) - fix(actions): improve runner list status sorting, labels and task job links ([#&#8203;38586](https://github.com/go-gitea/gitea/issues/38586)) ([#&#8203;38633](https://github.com/go-gitea/gitea/issues/38633)) - fix(actions): correctness and hardening fixes ([#&#8203;38518](https://github.com/go-gitea/gitea/issues/38518)) ([#&#8203;38631](https://github.com/go-gitea/gitea/issues/38631)) - fix(repo): prevent double-write redirect collisions on dependency errors, fix ui ([#&#8203;38627](https://github.com/go-gitea/gitea/issues/38627)) ([#&#8203;38628](https://github.com/go-gitea/gitea/issues/38628)) - fix: delete repo-scoped rows of seven more tables when deleting a repository ([#&#8203;38534](https://github.com/go-gitea/gitea/issues/38534)) ([#&#8203;38618](https://github.com/go-gitea/gitea/issues/38618)) - fix(webhook): remove slack channel name check ([#&#8203;38608](https://github.com/go-gitea/gitea/issues/38608)) ([#&#8203;38612](https://github.com/go-gitea/gitea/issues/38612)) - fix: download dropdown menu clipped on the branches page ([#&#8203;38604](https://github.com/go-gitea/gitea/issues/38604)) ([#&#8203;38609](https://github.com/go-gitea/gitea/issues/38609)) - fix(project): prevent database mutations on invalid MoveIssues payload ([#&#8203;38600](https://github.com/go-gitea/gitea/issues/38600)) ([#&#8203;38602](https://github.com/go-gitea/gitea/issues/38602)) - fix(actions): make SingleWorkflow\.Marshal round-trip multi-line run blocks (stop silent job stranding) ([#&#8203;38520](https://github.com/go-gitea/gitea/issues/38520)) ([#&#8203;38599](https://github.com/go-gitea/gitea/issues/38599)) - fix(file-tree): handle submodule links and missing view container ([#&#8203;38033](https://github.com/go-gitea/gitea/issues/38033)) ([#&#8203;38589](https://github.com/go-gitea/gitea/issues/38589)) - fix(actions): fail unexpandable reusable workflow callers and decouple the job emitter's cross-run processing ([#&#8203;38565](https://github.com/go-gitea/gitea/issues/38565)) ([#&#8203;38587](https://github.com/go-gitea/gitea/issues/38587)) - fix: keep serving valid ACME cert when renewal fails at startup ([#&#8203;38554](https://github.com/go-gitea/gitea/issues/38554)) ([#&#8203;38583](https://github.com/go-gitea/gitea/issues/38583)) - fix: branch protection user list ([#&#8203;38570](https://github.com/go-gitea/gitea/issues/38570)) ([#&#8203;38584](https://github.com/go-gitea/gitea/issues/38584)) - fix(pulls): respect diff.orderFile in diff file tree ([#&#8203;38566](https://github.com/go-gitea/gitea/issues/38566)) ([#&#8203;38578](https://github.com/go-gitea/gitea/issues/38578)) - fix(issue): make issue action (issue list batch operation) elements have correct attributes ([#&#8203;38575](https://github.com/go-gitea/gitea/issues/38575)) ([#&#8203;38580](https://github.com/go-gitea/gitea/issues/38580)) - fix(actions): support `matrix` when evaluating workflow `if` expression ([#&#8203;38474](https://github.com/go-gitea/gitea/issues/38474)) ([#&#8203;38557](https://github.com/go-gitea/gitea/issues/38557)) - fix(actions): align status icon span for Safari rendering ([#&#8203;38558](https://github.com/go-gitea/gitea/issues/38558)) ([#&#8203;38562](https://github.com/go-gitea/gitea/issues/38562)) - fix: revert git clone http redirection forbidden ([#&#8203;38530](https://github.com/go-gitea/gitea/issues/38530)) ([#&#8203;38545](https://github.com/go-gitea/gitea/issues/38545)) - fix: clean up orphaned user-keyed tables in deleteUser ([#&#8203;38511](https://github.com/go-gitea/gitea/issues/38511)) ([#&#8203;38514](https://github.com/go-gitea/gitea/issues/38514)) - fix(actions): coerce workflow\_dispatch boolean inputs to native types ([#&#8203;38472](https://github.com/go-gitea/gitea/issues/38472)) ([#&#8203;38521](https://github.com/go-gitea/gitea/issues/38521)) - fix: make the merge box button red if some checks fail ([#&#8203;38508](https://github.com/go-gitea/gitea/issues/38508)) ([#&#8203;38516](https://github.com/go-gitea/gitea/issues/38516)) - fix(pull): sign the commit when updating a branch by merge ([#&#8203;38441](https://github.com/go-gitea/gitea/issues/38441)) ([#&#8203;38499](https://github.com/go-gitea/gitea/issues/38499)) - fix: make commit message merge correctly ([#&#8203;38490](https://github.com/go-gitea/gitea/issues/38490)) ([#&#8203;38502](https://github.com/go-gitea/gitea/issues/38502)) - fix(actions): explain why a blocked or waiting job has not started ([#&#8203;38476](https://github.com/go-gitea/gitea/issues/38476)) ([#&#8203;38498](https://github.com/go-gitea/gitea/issues/38498)) - fix(actions): make `cancelled()` work in job `if` evaluation ([#&#8203;38495](https://github.com/go-gitea/gitea/issues/38495)) ([#&#8203;38497](https://github.com/go-gitea/gitea/issues/38497)) - fix(actions): show retention info on hover for expired artifacts ([#&#8203;38477](https://github.com/go-gitea/gitea/issues/38477)) ([#&#8203;38493](https://github.com/go-gitea/gitea/issues/38493)) - fix(actions): group reusable-workflow matrix legs in the workflow graph ([#&#8203;38475](https://github.com/go-gitea/gitea/issues/38475)) ([#&#8203;38492](https://github.com/go-gitea/gitea/issues/38492)) - fix: full file highlighting for git diff with CR char ([#&#8203;38484](https://github.com/go-gitea/gitea/issues/38484)) ([#&#8203;38491](https://github.com/go-gitea/gitea/issues/38491)) - fix(packages): serve noarch Alpine index for any requested architecture ([#&#8203;38479](https://github.com/go-gitea/gitea/issues/38479)) ([#&#8203;38486](https://github.com/go-gitea/gitea/issues/38486)) - fix: 500 error when updating user visibility ([#&#8203;38480](https://github.com/go-gitea/gitea/issues/38480)) ([#&#8203;38483](https://github.com/go-gitea/gitea/issues/38483)) - fix(actions): make job list item fully clickable ([#&#8203;38462](https://github.com/go-gitea/gitea/issues/38462)) ([#&#8203;38471](https://github.com/go-gitea/gitea/issues/38471)) - fix: mail template for push event ([#&#8203;38467](https://github.com/go-gitea/gitea/issues/38467)) ([#&#8203;38468](https://github.com/go-gitea/gitea/issues/38468)) - fix: make "test push webhook" always work ([#&#8203;38425](https://github.com/go-gitea/gitea/issues/38425)) ([#&#8203;38455](https://github.com/go-gitea/gitea/issues/38455)) - fix(actions): prevent bulk actions from affecting all runners ([#&#8203;38453](https://github.com/go-gitea/gitea/issues/38453)) ([#&#8203;38457](https://github.com/go-gitea/gitea/issues/38457)) - fix(org): align follow button and wrap description ([#&#8203;38448](https://github.com/go-gitea/gitea/issues/38448)) ([#&#8203;38454](https://github.com/go-gitea/gitea/issues/38454)) - fix(actions): populate `github.event` for scheduled runs ([#&#8203;38446](https://github.com/go-gitea/gitea/issues/38446)) ([#&#8203;38452](https://github.com/go-gitea/gitea/issues/38452)) - MISC - refactor: git patch apply ([#&#8203;38637](https://github.com/go-gitea/gitea/issues/38637)) ([#&#8203;38638](https://github.com/go-gitea/gitea/issues/38638)) ### [`v1.27.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1270---2026-07-13) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.4...v1.27.0) - BREAKING - Feat(actions)!: improve support for reusable workflows ([#&#8203;37478](https://github.com/go-gitea/gitea/issues/37478)) - Use Content-Security-Policy: script nonce ([#&#8203;37232](https://github.com/go-gitea/gitea/issues/37232)) - SECURITY - Fix: various security fixes ([#&#8203;38406](https://github.com/go-gitea/gitea/issues/38406)) ([#&#8203;38426](https://github.com/go-gitea/gitea/issues/38426)) - Fix(security): harden access checks and migration validation ([#&#8203;38324](https://github.com/go-gitea/gitea/issues/38324)) ([#&#8203;38400](https://github.com/go-gitea/gitea/issues/38400)) - Fix: enforce public-only token scope and harden push options / locale parsing ([#&#8203;38323](https://github.com/go-gitea/gitea/issues/38323)) ([#&#8203;38399](https://github.com/go-gitea/gitea/issues/38399)) - Fix(pull): re-evaluate review official flag on target branch change ([#&#8203;38319](https://github.com/go-gitea/gitea/issues/38319)) ([#&#8203;38402](https://github.com/go-gitea/gitea/issues/38402)) - Fix(api): stop leaking private repo metadata after access revocation ([#&#8203;38321](https://github.com/go-gitea/gitea/issues/38321)) ([#&#8203;38390](https://github.com/go-gitea/gitea/issues/38390)) - Fix(lfs): require proof of possession for cross-repo objects ([#&#8203;38322](https://github.com/go-gitea/gitea/issues/38322)) ([#&#8203;38389](https://github.com/go-gitea/gitea/issues/38389)) - Fix(mirror): disable HTTP redirects on pull mirror sync ([#&#8203;38320](https://github.com/go-gitea/gitea/issues/38320)) ([#&#8203;38367](https://github.com/go-gitea/gitea/issues/38367)) - Fix(release): validate web attachment renames against allowed types ([#&#8203;38314](https://github.com/go-gitea/gitea/issues/38314)) ([#&#8203;38328](https://github.com/go-gitea/gitea/issues/38328)) - Fix(release): gate draft release attachments on web download endpoints ([#&#8203;38318](https://github.com/go-gitea/gitea/issues/38318)) ([#&#8203;38325](https://github.com/go-gitea/gitea/issues/38325)) - Fix(deps): update module github.com/go-git/go-git/v5 to v5.19.1 \[security] ([#&#8203;37786](https://github.com/go-gitea/gitea/issues/37786)) - Fix(oauth): restrict introspection to the token's client ([#&#8203;38042](https://github.com/go-gitea/gitea/issues/38042)) - Fix(api): don't expose private org membership via public\_members ([#&#8203;38145](https://github.com/go-gitea/gitea/issues/38145)) - Fix(actions): deny fork-PR cross-repo access via collaborative owner ([#&#8203;38214](https://github.com/go-gitea/gitea/issues/38214)) - Fix(migrations): prevent path traversal in repository restore ([#&#8203;38215](https://github.com/go-gitea/gitea/issues/38215)) - Feat(security): set X-Content-Type-Options: nosniff by default ([#&#8203;37354](https://github.com/go-gitea/gitea/issues/37354)) - FEATURES - Feat(actions): add workflow status badge modal ([#&#8203;38196](https://github.com/go-gitea/gitea/issues/38196)) - Feat(actions): support owner-level and global scoped workflows ([#&#8203;38154](https://github.com/go-gitea/gitea/issues/38154)) - Feat(api): support ref suffixes in compare ([#&#8203;38148](https://github.com/go-gitea/gitea/issues/38148)) - Feat(actions): implement `jobs.<job_id>.continue-on-error` ([#&#8203;38100](https://github.com/go-gitea/gitea/issues/38100)) - Feat(actions): show run status on browser tab favicon ([#&#8203;38071](https://github.com/go-gitea/gitea/issues/38071)) - Feat(api): add token introspection and self-deletion endpoint ([#&#8203;37995](https://github.com/go-gitea/gitea/issues/37995)) - Feat(repo): split repository creation limit into user and org scopes ([#&#8203;37872](https://github.com/go-gitea/gitea/issues/37872)) - Feat(actions): bulk delete, disable and enable runners in admin UI ([#&#8203;37869](https://github.com/go-gitea/gitea/issues/37869)) - Feat(actions): List workflows that were executed once but got removed from the default branch ([#&#8203;37835](https://github.com/go-gitea/gitea/issues/37835)) - Feat(org): add team visibility so org members can discover teams ([#&#8203;37680](https://github.com/go-gitea/gitea/issues/37680)) - Feat: add raw diff/patch endpoint for repository comparisons ([#&#8203;37632](https://github.com/go-gitea/gitea/issues/37632)) - Feat(oauth): Support AWS Cognito OAuth2 provider ([#&#8203;37607](https://github.com/go-gitea/gitea/issues/37607)) - Feat: Add avatar stacks ([#&#8203;37594](https://github.com/go-gitea/gitea/issues/37594)) - Feat(actions): add job summaries (GITHUB\_STEP\_SUMMARY) ([#&#8203;37500](https://github.com/go-gitea/gitea/issues/37500)) - Feat(web): Add Jupyter Notebook (.ipynb) Rendering Support ([#&#8203;37433](https://github.com/go-gitea/gitea/issues/37433)) - Support for Custom URI Schemes in OAuth2 Redirect URIs ([#&#8203;37356](https://github.com/go-gitea/gitea/issues/37356)) - Feat(orgs): Add search bar for organization members tab page ([#&#8203;37347](https://github.com/go-gitea/gitea/issues/37347)) - Feat(api): Add assignees APIs ([#&#8203;37330](https://github.com/go-gitea/gitea/issues/37330)) - Feat(api): Add GET /repos/{owner}/{repo}/actions/workflows/{workflow\_id}/runs ([#&#8203;37196](https://github.com/go-gitea/gitea/issues/37196)) - Introduce `ActionRunAttempt` to represent each execution of a run ([#&#8203;37119](https://github.com/go-gitea/gitea/issues/37119)) - Serve OpenAPI 3.0 spec at /openapi.v1.json ([#&#8203;37038](https://github.com/go-gitea/gitea/issues/37038)) - Add project column picker to issue and pull request sidebar ([#&#8203;37037](https://github.com/go-gitea/gitea/issues/37037)) - Allow multiple projects per issue and pull requests ([#&#8203;36784](https://github.com/go-gitea/gitea/issues/36784)) - Add bulk repository deletion for organizations ([#&#8203;36763](https://github.com/go-gitea/gitea/issues/36763)) - Add API endpoint to reply to pull request review comments ([#&#8203;36683](https://github.com/go-gitea/gitea/issues/36683)) - Feat: Add bypass allowlist for branch protection ([#&#8203;36514](https://github.com/go-gitea/gitea/issues/36514)) - Feat(ui): add "follow rename" to file commit history list ([#&#8203;34994](https://github.com/go-gitea/gitea/issues/34994)) - Feat(ssh): auto generate additional ssh keys ([#&#8203;33974](https://github.com/go-gitea/gitea/issues/33974)) - ENHANCEMENTS - Enhance(actions): only create filtered-out workflow commit status for required contexts ([#&#8203;38371](https://github.com/go-gitea/gitea/issues/38371)) ([#&#8203;38385](https://github.com/go-gitea/gitea/issues/38385)) - Enhance: allow builtin default git config options to be overridden ([#&#8203;38172](https://github.com/go-gitea/gitea/issues/38172)) - Enhance: allow MathML core elements ([#&#8203;38034](https://github.com/go-gitea/gitea/issues/38034)) - Feat(api): add q parameter to list branches API for server-side filtering ([#&#8203;37982](https://github.com/go-gitea/gitea/issues/37982)) - Enhance(markup): improve issue title rendering ([#&#8203;37908](https://github.com/go-gitea/gitea/issues/37908)) - Enhance(actions): set descriptive browser tab title on run view ([#&#8203;37870](https://github.com/go-gitea/gitea/issues/37870)) - Enhance(actions): show workflow name from YAML instead of filename ([#&#8203;37833](https://github.com/go-gitea/gitea/issues/37833)) - Feat(actions): add before/after to PR synchronize event payload ([#&#8203;37827](https://github.com/go-gitea/gitea/issues/37827)) - Enhance(actions): add branch filters to run list ([#&#8203;37826](https://github.com/go-gitea/gitea/issues/37826)) - Enhance(actions): Make Summary UI more beautiful with more infos ([#&#8203;37824](https://github.com/go-gitea/gitea/issues/37824)) - Feat: add copy button to action step header, improve other copy buttons ([#&#8203;37744](https://github.com/go-gitea/gitea/issues/37744)) - Feat(web): also display PR counts in repo list ([#&#8203;37739](https://github.com/go-gitea/gitea/issues/37739)) - Fix(icon): use repo-forked icon to display forks count ([#&#8203;37731](https://github.com/go-gitea/gitea/issues/37731)) - Feat(api): add sort and order query parameters to job list endpoints ([#&#8203;37672](https://github.com/go-gitea/gitea/issues/37672)) - Feat(api): add last\_sync to repository API ([#&#8203;37566](https://github.com/go-gitea/gitea/issues/37566)) - Enhance: Adjust Workflow Graph styling ([#&#8203;37497](https://github.com/go-gitea/gitea/issues/37497)) - Improve code editor text selection and clean up lint enablement ([#&#8203;37474](https://github.com/go-gitea/gitea/issues/37474)) - Add mirror auth updates to repo edit API and settings ([#&#8203;37468](https://github.com/go-gitea/gitea/issues/37468)) - Feat: Add default PR branch update style setting ([#&#8203;37410](https://github.com/go-gitea/gitea/issues/37410)) - Fix inconsistent disabled styling on logged-out repo header buttons ([#&#8203;37406](https://github.com/go-gitea/gitea/issues/37406)) - Allow fast-forward-only merge when signed commits are required ([#&#8203;37335](https://github.com/go-gitea/gitea/issues/37335)) - Enhance styling in actions page ([#&#8203;37323](https://github.com/go-gitea/gitea/issues/37323)) - Add `ExternalIDClaim` option for OAuth2 OIDC auth source ([#&#8203;37229](https://github.com/go-gitea/gitea/issues/37229)) - Fix: improve actions status icons and texts ([#&#8203;37206](https://github.com/go-gitea/gitea/issues/37206)) - Make Markdown fenced code block work with more syntaxes ([#&#8203;37154](https://github.com/go-gitea/gitea/issues/37154)) - Fix: Sort action run jobs by JobID and Name with matrix examples ([#&#8203;37046](https://github.com/go-gitea/gitea/issues/37046)) - Add pagination and search box to org teams list ([#&#8203;37245](https://github.com/go-gitea/gitea/issues/37245)) - Workflow Artifact Info Hover ([#&#8203;37100](https://github.com/go-gitea/gitea/issues/37100)) - Feat(editor): broaden language detection in web code editor ([#&#8203;37619](https://github.com/go-gitea/gitea/issues/37619)) - PERFORMANCE - Perf(actions): debounce runner heartbeat writes and throttle task picks ([#&#8203;38281](https://github.com/go-gitea/gitea/issues/38281)) ([#&#8203;38368](https://github.com/go-gitea/gitea/issues/38368)) - Perf(web): sort the action\_run query by a repo-scoped index when possible ([#&#8203;38155](https://github.com/go-gitea/gitea/issues/38155)) - Perf: Various performance regression fixes ([#&#8203;38078](https://github.com/go-gitea/gitea/issues/38078)) - Perf: extend action `c_u` index to include `created_unix` for faster dashboard feeds ([#&#8203;38076](https://github.com/go-gitea/gitea/issues/38076)) - Batch-load related data in actions run, job, and task API endpoints ([#&#8203;37032](https://github.com/go-gitea/gitea/issues/37032)) - BUGFIXES - Fix(util): reject invalid characters between time-estimate units ([#&#8203;38416](https://github.com/go-gitea/gitea/issues/38416)) ([#&#8203;38423](https://github.com/go-gitea/gitea/issues/38423)) - Fix: represent a deleted assignee team as a Ghost team ([#&#8203;38413](https://github.com/go-gitea/gitea/issues/38413)) ([#&#8203;38419](https://github.com/go-gitea/gitea/issues/38419)) - Fix(turnstile): route CAPTCHA verification through the configured proxy ([#&#8203;38412](https://github.com/go-gitea/gitea/issues/38412)) ([#&#8203;38420](https://github.com/go-gitea/gitea/issues/38420)) - Fix: refresh pull request merge box when the commit status is pending ([#&#8203;38410](https://github.com/go-gitea/gitea/issues/38410)) ([#&#8203;38411](https://github.com/go-gitea/gitea/issues/38411)) - Fix: actions task state concurrent update ([#&#8203;38405](https://github.com/go-gitea/gitea/issues/38405)) ([#&#8203;38409](https://github.com/go-gitea/gitea/issues/38409)) - Fix(actions): keep workflow run trailing on one row with long branch names ([#&#8203;38382](https://github.com/go-gitea/gitea/issues/38382)) ([#&#8203;38403](https://github.com/go-gitea/gitea/issues/38403)) - Fix(web): use locale-aware date formatting for contribution calendar tooltips ([#&#8203;38398](https://github.com/go-gitea/gitea/issues/38398)) ([#&#8203;38401](https://github.com/go-gitea/gitea/issues/38401)) - Fix: co-author detection ([#&#8203;38392](https://github.com/go-gitea/gitea/issues/38392)) ([#&#8203;38397](https://github.com/go-gitea/gitea/issues/38397)) - Fix: incorrect co-author detection on commit page ([#&#8203;38386](https://github.com/go-gitea/gitea/issues/38386)) ([#&#8203;38387](https://github.com/go-gitea/gitea/issues/38387)) - Fix(ui): restore commits table column widths ([#&#8203;38379](https://github.com/go-gitea/gitea/issues/38379)) ([#&#8203;38383](https://github.com/go-gitea/gitea/issues/38383)) - Fix: golang html template url escaping ([#&#8203;38363](https://github.com/go-gitea/gitea/issues/38363)) ([#&#8203;38369](https://github.com/go-gitea/gitea/issues/38369)) - Fix: minio init check ([#&#8203;38355](https://github.com/go-gitea/gitea/issues/38355)) ([#&#8203;38361](https://github.com/go-gitea/gitea/issues/38361)) - Fix: org project view assignee list ([#&#8203;38357](https://github.com/go-gitea/gitea/issues/38357)) ([#&#8203;38360](https://github.com/go-gitea/gitea/issues/38360)) - Fix(actions): release claimed task if context is cancelled during `FetchTask` ([#&#8203;38343](https://github.com/go-gitea/gitea/issues/38343)) ([#&#8203;38347](https://github.com/go-gitea/gitea/issues/38347)) - Fix(actions): make runner list pagination order deterministic ([#&#8203;38313](https://github.com/go-gitea/gitea/issues/38313)) ([#&#8203;38327](https://github.com/go-gitea/gitea/issues/38327)) - Fix: Improve since/until when counting commits for X-Total-Count ([#&#8203;38243](https://github.com/go-gitea/gitea/issues/38243)) ([#&#8203;38304](https://github.com/go-gitea/gitea/issues/38304)) - Fix(actions): prevent chevron overlap with log text when timestamps are enabled ([#&#8203;38227](https://github.com/go-gitea/gitea/issues/38227)) ([#&#8203;38307](https://github.com/go-gitea/gitea/issues/38307)) - Fix(workflows): branch protection status checks fail when workflow uses on: paths filter ([#&#8203;38237](https://github.com/go-gitea/gitea/issues/38237)) ([#&#8203;38302](https://github.com/go-gitea/gitea/issues/38302)) - Fix(oauth2): persist linkAccountData during auto-link 2FA flow ([#&#8203;38274](https://github.com/go-gitea/gitea/issues/38274)) ([#&#8203;38295](https://github.com/go-gitea/gitea/issues/38295)) - Fix(actions): allow Actions bot to push to protected branches ([#&#8203;38284](https://github.com/go-gitea/gitea/issues/38284)) ([#&#8203;38293](https://github.com/go-gitea/gitea/issues/38293)) - Fix(actions): include all aggregable run statuses in status filter ([#&#8203;38280](https://github.com/go-gitea/gitea/issues/38280)) ([#&#8203;38287](https://github.com/go-gitea/gitea/issues/38287)) - Fix(archiver): use serializable repo-archive queue payload ([#&#8203;38273](https://github.com/go-gitea/gitea/issues/38273)) ([#&#8203;38283](https://github.com/go-gitea/gitea/issues/38283)) - Fix: update npm dependencies, fix misc issues ([#&#8203;38257](https://github.com/go-gitea/gitea/issues/38257)) - Fix(api): respect since/until when counting commits for X-Total-Count ([#&#8203;38204](https://github.com/go-gitea/gitea/issues/38204)) - Fix: codemirror regressions ([#&#8203;38248](https://github.com/go-gitea/gitea/issues/38248)) - Fix(api): support HEAD requests on all API GET endpoints ([#&#8203;38245](https://github.com/go-gitea/gitea/issues/38245)) - Fix(actions): Cleanup workflow status badge code ([#&#8203;38241](https://github.com/go-gitea/gitea/issues/38241)) - Fix(web): Correctly align the "disabled" label on larger workflow names ([#&#8203;38240](https://github.com/go-gitea/gitea/issues/38240)) - Fix(actions): don't swallow HTML entities into linkified URLs ([#&#8203;38239](https://github.com/go-gitea/gitea/issues/38239)) - Fix(packages): accept npm "repository" and "bin" in string form ([#&#8203;38236](https://github.com/go-gitea/gitea/issues/38236)) - Fix(actions): fix 500 error when canceling a canceling task ([#&#8203;38223](https://github.com/go-gitea/gitea/issues/38223)) - Fix(deps): update module golang.org/x/image to v0.43.0 \[security] ([#&#8203;38219](https://github.com/go-gitea/gitea/issues/38219)) - Fix(mssql): convert legacy DATETIME columns to DATETIME2 ([#&#8203;38216](https://github.com/go-gitea/gitea/issues/38216)) - Fix(api): deny private org member enumeration via /members ([#&#8203;38213](https://github.com/go-gitea/gitea/issues/38213)) - Fix(actions): ensure all waiting jobs get runners in large workflows ([#&#8203;38200](https://github.com/go-gitea/gitea/issues/38200)) - Fix(deps): update go dependencies ([#&#8203;38194](https://github.com/go-gitea/gitea/issues/38194)) - Fix(deps): update npm dependencies ([#&#8203;38193](https://github.com/go-gitea/gitea/issues/38193)) - Fix(cli): default must-change-password to false for bot users ([#&#8203;38175](https://github.com/go-gitea/gitea/issues/38175)) - Fix(actions): show run index in run view and fix summary graph height ([#&#8203;38165](https://github.com/go-gitea/gitea/issues/38165)) - Fix: csp ([#&#8203;38162](https://github.com/go-gitea/gitea/issues/38162)) - Fix(deps): update npm dependencies ([#&#8203;38123](https://github.com/go-gitea/gitea/issues/38123)) - Fix(mssql): expand legacy issue and comment long-text columns ([#&#8203;38120](https://github.com/go-gitea/gitea/issues/38120)) - Fix(packages): validate debian distribution and component names ([#&#8203;38116](https://github.com/go-gitea/gitea/issues/38116)) - Fix(packages): validate module version in goproxy ParsePackage ([#&#8203;38104](https://github.com/go-gitea/gitea/issues/38104)) - Fix(deps): update dependency esbuild to v0.28.1 \[security] ([#&#8203;38097](https://github.com/go-gitea/gitea/issues/38097)) - Fix: git push hook post receive ([#&#8203;38089](https://github.com/go-gitea/gitea/issues/38089)) - Fix(ui): prevent commit status popup overflowing its row ([#&#8203;38081](https://github.com/go-gitea/gitea/issues/38081)) - Fix: validate gem name in rubygems parseMetadataFile ([#&#8203;38061](https://github.com/go-gitea/gitea/issues/38061)) - Fix: commit display name ([#&#8203;38057](https://github.com/go-gitea/gitea/issues/38057)) - Fix: csp regressions ([#&#8203;38047](https://github.com/go-gitea/gitea/issues/38047)) - Fix: api error message ([#&#8203;38031](https://github.com/go-gitea/gitea/issues/38031)) - Fix(deps): update npm dependencies ([#&#8203;38029](https://github.com/go-gitea/gitea/issues/38029)) - Fix: pgsql lint ([#&#8203;38022](https://github.com/go-gitea/gitea/issues/38022)) - Fix(indexer): fix assignee filters in issue search ([#&#8203;38021](https://github.com/go-gitea/gitea/issues/38021)) - Fix: various dropdown problems ([#&#8203;38020](https://github.com/go-gitea/gitea/issues/38020)) - Fix: refactor git error handling and make archive streaming handle non-existing commit id ([#&#8203;38007](https://github.com/go-gitea/gitea/issues/38007)) - Fix: raise git required version to 2.13 ([#&#8203;37996](https://github.com/go-gitea/gitea/issues/37996)) - Fix: remove "no-transfrom" from the cache-control header ([#&#8203;37985](https://github.com/go-gitea/gitea/issues/37985)) - Fix(deps): update module github.com/google/go-github/v87 to v88 ([#&#8203;37971](https://github.com/go-gitea/gitea/issues/37971)) - Fix: use committer time where ever possible as default ([#&#8203;37969](https://github.com/go-gitea/gitea/issues/37969)) - Fix(deps): update npm dependencies, remove nolyfill ([#&#8203;37968](https://github.com/go-gitea/gitea/issues/37968)) - Fix(deps): update go dependencies ([#&#8203;37967](https://github.com/go-gitea/gitea/issues/37967)) - Fix(pull): preserve squash message trailers and additional commit messages ([#&#8203;37954](https://github.com/go-gitea/gitea/issues/37954)) - Fix(deps): update module golang.org/x/image to v0.41.0 \[security] ([#&#8203;37904](https://github.com/go-gitea/gitea/issues/37904)) - Fix: support ##\[command] log prefix in action run UI ([#&#8203;37882](https://github.com/go-gitea/gitea/issues/37882)) - Fix(deps): update module github.com/google/go-github/v86 to v87 ([#&#8203;37845](https://github.com/go-gitea/gitea/issues/37845)) - Fix(deps): update npm dependencies ([#&#8203;37844](https://github.com/go-gitea/gitea/issues/37844)) - Fix(deps): update go dependencies ([#&#8203;37841](https://github.com/go-gitea/gitea/issues/37841)) - Fix(frontend): resolve Vite assets by manifest source path ([#&#8203;37836](https://github.com/go-gitea/gitea/issues/37836)) - Fix(locales): Replace hardcoded strings ([#&#8203;37788](https://github.com/go-gitea/gitea/issues/37788)) - Fix(packages): render markdown links relative to linked repo ([#&#8203;37676](https://github.com/go-gitea/gitea/issues/37676)) - Fix: persist mirror repository metadata ([#&#8203;37519](https://github.com/go-gitea/gitea/issues/37519)) - Fix cmd tests by mocking builtin paths ([#&#8203;37369](https://github.com/go-gitea/gitea/issues/37369)) - Add `form-fetch-action` to some forms, fix "fetch action" resp bug ([#&#8203;37305](https://github.com/go-gitea/gitea/issues/37305)) - Feat: execute post run cleanup when workflow is cancelled ([#&#8203;37275](https://github.com/go-gitea/gitea/issues/37275)) - Fix `relative-time` error and improve global error handler ([#&#8203;37241](https://github.com/go-gitea/gitea/issues/37241)) - Refactor flash message and remove SanitizeHTML template func ([#&#8203;37179](https://github.com/go-gitea/gitea/issues/37179)) - Fix Repository transferring page ([#&#8203;37277](https://github.com/go-gitea/gitea/issues/37277)) - TESTING - Test(e2e): fix race in pdf file render test ([#&#8203;38380](https://github.com/go-gitea/gitea/issues/38380)) ([#&#8203;38381](https://github.com/go-gitea/gitea/issues/38381)) - Test: compare key file contents instead of `FileInfo` in `TestInitKeys` ([#&#8203;38330](https://github.com/go-gitea/gitea/issues/38330)) ([#&#8203;38331](https://github.com/go-gitea/gitea/issues/38331)) - Test: speed up two tests ([#&#8203;37905](https://github.com/go-gitea/gitea/issues/37905)) - Test: Fix random failure test ([#&#8203;37887](https://github.com/go-gitea/gitea/issues/37887)) - Test: fix flaky `issue-comment` close test ([#&#8203;37880](https://github.com/go-gitea/gitea/issues/37880)) - Test: enable WAL for sqlite integration tests ([#&#8203;37861](https://github.com/go-gitea/gitea/issues/37861)) - Test: fix flaky `TestResourceIndex` and reduce its runtime ([#&#8203;37847](https://github.com/go-gitea/gitea/issues/37847)) - Test: run `TestAPIRepoMigrate` offline via a local clone source ([#&#8203;37817](https://github.com/go-gitea/gitea/issues/37817)) - Ci: shard tests and reduce redundant work ([#&#8203;37618](https://github.com/go-gitea/gitea/issues/37618)) - Test(e2e): run playwright via container ([#&#8203;37300](https://github.com/go-gitea/gitea/issues/37300)) - Remove external service dependencies in migration tests ([#&#8203;36866](https://github.com/go-gitea/gitea/issues/36866)) - Refactor: only reset a database table when the table's data was changed ([#&#8203;37573](https://github.com/go-gitea/gitea/issues/37573)) - BUILD - Refactor: use modernc sqlite driver as default ([#&#8203;37562](https://github.com/go-gitea/gitea/issues/37562)) - Fix(actions): authenticate snapcraft before nightly remote build ([#&#8203;38252](https://github.com/go-gitea/gitea/issues/38252)) - Ci: cap Elasticsearch heap in db-tests ([#&#8203;37816](https://github.com/go-gitea/gitea/issues/37816)) - Build(snap): publish nightly version to snapcraft via actions ([#&#8203;37814](https://github.com/go-gitea/gitea/issues/37814)) - Ci: split pgsql shards into plain jobs, dedupe setup actions ([#&#8203;37802](https://github.com/go-gitea/gitea/issues/37802)) - Ci: narrow files-changed frontend filter ([#&#8203;37749](https://github.com/go-gitea/gitea/issues/37749)) - Ci: add `zizmor` to `lint-actions` ([#&#8203;37720](https://github.com/go-gitea/gitea/issues/37720)) - Chore: clean up "contrib" dir ([#&#8203;37690](https://github.com/go-gitea/gitea/issues/37690)) - Fix: snap build (main branch) ([#&#8203;37685](https://github.com/go-gitea/gitea/issues/37685)) - Ci: Also lint json5 files ([#&#8203;37659](https://github.com/go-gitea/gitea/issues/37659)) - Build: update pnpm to v11 ([#&#8203;37591](https://github.com/go-gitea/gitea/issues/37591)) - Refactor(deps): migrate from `nektos/act` fork to `gitea/runner` ([#&#8203;37557](https://github.com/go-gitea/gitea/issues/37557)) - Update go js py dependencies ([#&#8203;37525](https://github.com/go-gitea/gitea/issues/37525)) - Ci: lint PR titles with commitlint ([#&#8203;37498](https://github.com/go-gitea/gitea/issues/37498)) - Chore: upgrade Go version in devcontainer image to 1.26 ([#&#8203;37374](https://github.com/go-gitea/gitea/issues/37374)) - Update GitHub Actions to latest major versions ([#&#8203;37313](https://github.com/go-gitea/gitea/issues/37313)) - Update go js dependencies ([#&#8203;37312](https://github.com/go-gitea/gitea/issues/37312)) - Fail vite build on rolldown warnings via NODE\_ENV=test ([#&#8203;37270](https://github.com/go-gitea/gitea/issues/37270)) - Replace custom Go formatter with `golangci-lint fmt` ([#&#8203;37194](https://github.com/go-gitea/gitea/issues/37194)) - Integrate renovate bot for all dependency updates ([#&#8203;37050](https://github.com/go-gitea/gitea/issues/37050)) - Build(sign): move to sigstore ([#&#8203;38250](https://github.com/go-gitea/gitea/issues/38250)) - DOCS - Docs: update changelog for 1.26.3 & 1.26.4 ([#&#8203;38178](https://github.com/go-gitea/gitea/issues/38178)) - Update 1.26.1 changelog in main ([#&#8203;37442](https://github.com/go-gitea/gitea/issues/37442)) - Docs: fix duplicated word in foreachref doc comment ([#&#8203;38161](https://github.com/go-gitea/gitea/issues/38161)) - Docs: Clarify criteria for becoming a merger ([#&#8203;38113](https://github.com/go-gitea/gitea/issues/38113)) - Docs: Publish TOC Election Result 2026 ([#&#8203;38111](https://github.com/go-gitea/gitea/issues/38111)) - Docs: mark openapi3 as autogenerated in attributes ([#&#8203;37963](https://github.com/go-gitea/gitea/issues/37963)) - Docs: add development setup guide ([#&#8203;37960](https://github.com/go-gitea/gitea/issues/37960)) - MISC - Refactor: lint bare `fill`/`stroke` colors, add vars for git graph color series ([#&#8203;37543](https://github.com/go-gitea/gitea/issues/37543)) - Remove htmx ([#&#8203;37224](https://github.com/go-gitea/gitea/issues/37224)) - Refactor htmx and fetch-action related code ([#&#8203;37186](https://github.com/go-gitea/gitea/issues/37186)) - Revert(sign): restore gpg ([#&#8203;38251](https://github.com/go-gitea/gitea/issues/38251)) - Refactor: replace legacy `delete-button` with `link-action` ([#&#8203;38143](https://github.com/go-gitea/gitea/issues/38143)) - Refactor(actions): read runner capabilities from proto field ([#&#8203;38068](https://github.com/go-gitea/gitea/issues/38068)) - Refactor(api): clarify APIError message usage and fix legacy lint error ([#&#8203;38012](https://github.com/go-gitea/gitea/issues/38012)) - Refactor: Use db.Get\[] instead of db.GetEngine(ctx).Get(bean) to avoid zero value fetching wrong database record ([#&#8203;37977](https://github.com/go-gitea/gitea/issues/37977)) - Enhance: Migrate remaining gopkg.in/yaml.v3 usages to go.yaml.in/yaml/v4 ([#&#8203;37866](https://github.com/go-gitea/gitea/issues/37866)) - Fix(deps): update go dependencies ([#&#8203;37851](https://github.com/go-gitea/gitea/issues/37851)) - Ci: Fix sync PR labels from the conventional-commit title ([#&#8203;37784](https://github.com/go-gitea/gitea/issues/37784)) ([#&#8203;37825](https://github.com/go-gitea/gitea/issues/37825)) - Ci: tweak `files-changed`, add `free-disk-space` ([#&#8203;37819](https://github.com/go-gitea/gitea/issues/37819)) - Fix(deps): update module golang.org/x/crypto to v0.52.0 \[security] ([#&#8203;37806](https://github.com/go-gitea/gitea/issues/37806)) - Test(e2e): add comment, release, star, PR and fork tests ([#&#8203;37800](https://github.com/go-gitea/gitea/issues/37800)) - Chore: simplify issue and pull request templates ([#&#8203;37799](https://github.com/go-gitea/gitea/issues/37799)) - Chore: Update giteabot to fix failure when backport ([#&#8203;37789](https://github.com/go-gitea/gitea/issues/37789)) - Fix(api): handle partial failures in push mirror synchronization gracefully ([#&#8203;37782](https://github.com/go-gitea/gitea/issues/37782)) - Fix(deps): update module gitlab.com/gitlab-org/api/client-go/v2 to v2.26.0 ([#&#8203;37771](https://github.com/go-gitea/gitea/issues/37771)) - Ci: split giteabot workflow ([#&#8203;37770](https://github.com/go-gitea/gitea/issues/37770)) - Fix(deps): update npm dependencies ([#&#8203;37768](https://github.com/go-gitea/gitea/issues/37768)) - Refactor(waitgroup): replace Add/Done goroutines with WaitGroup.Go ([#&#8203;37764](https://github.com/go-gitea/gitea/issues/37764)) - Fix(deps): update module google.golang.org/grpc to v1.81.1 ([#&#8203;37762](https://github.com/go-gitea/gitea/issues/37762)) - Ci: fix cache-related issues ([#&#8203;37761](https://github.com/go-gitea/gitea/issues/37761)) - Chore: fix tests ([#&#8203;37760](https://github.com/go-gitea/gitea/issues/37760)) - Fix(deps): update module github.com/google/go-github/v85 to v86 ([#&#8203;37754](https://github.com/go-gitea/gitea/issues/37754)) - Fix(deps): update npm dependencies ([#&#8203;37753](https://github.com/go-gitea/gitea/issues/37753)) - Fix(deps): update go dependencies ([#&#8203;37752](https://github.com/go-gitea/gitea/issues/37752)) - Chore(deps): update action dependencies ([#&#8203;37751](https://github.com/go-gitea/gitea/issues/37751)) - Fix(markup): wrap indented code blocks for the code-copy button ([#&#8203;37748](https://github.com/go-gitea/gitea/issues/37748)) - Chore(db): introduce db.Session and db.EngineMigration interfaces ([#&#8203;37746](https://github.com/go-gitea/gitea/issues/37746)) - Refactor(glob): use strings.Builder for regexp compilation ([#&#8203;37730](https://github.com/go-gitea/gitea/issues/37730)) - Chore(doctor): remove four obsolete doctor check implementations ([#&#8203;37728](https://github.com/go-gitea/gitea/issues/37728)) - Refactor(org): simplify owner-team org repo creation logic ([#&#8203;37727](https://github.com/go-gitea/gitea/issues/37727)) - Refactor: move `workflowpattern` into `modules/actions` ([#&#8203;37717](https://github.com/go-gitea/gitea/issues/37717)) - Chore: clean up tests ([#&#8203;37715](https://github.com/go-gitea/gitea/issues/37715)) - Style: misc UI fixes ([#&#8203;37691](https://github.com/go-gitea/gitea/issues/37691)) - Ci: add shellcheck linter ([#&#8203;37682](https://github.com/go-gitea/gitea/issues/37682)) - Fix: catch and fix more lint problems ([#&#8203;37674](https://github.com/go-gitea/gitea/issues/37674)) - Fix(deps): update dependency mermaid to v11.15.0 \[security], add e2e test ([#&#8203;37662](https://github.com/go-gitea/gitea/issues/37662)) - Fix(deps): update npm dependencies ([#&#8203;37647](https://github.com/go-gitea/gitea/issues/37647)) - Ci(renovate): update Go import paths on major bumps ([#&#8203;37641](https://github.com/go-gitea/gitea/issues/37641)) - Fix(deps): update go dependencies (major) ([#&#8203;37639](https://github.com/go-gitea/gitea/issues/37639)) - Chore(deps): update action dependencies (major) ([#&#8203;37638](https://github.com/go-gitea/gitea/issues/37638)) - Fix(deps): update module code.gitea.io/sdk/gitea to v0.25.0 ([#&#8203;37637](https://github.com/go-gitea/gitea/issues/37637)) - Fix(deps): update npm dependencies ([#&#8203;37636](https://github.com/go-gitea/gitea/issues/37636)) - Refactor(log): replace log.Critical with log.Error ([#&#8203;37624](https://github.com/go-gitea/gitea/issues/37624)) - Build(deps): bump fast-uri from 3.1.0 to 3.1.2 ([#&#8203;37616](https://github.com/go-gitea/gitea/issues/37616)) - Chore(deps): update action dependencies ([#&#8203;37603](https://github.com/go-gitea/gitea/issues/37603)) - Ci: allow `chore` type in PR title lint ([#&#8203;37575](https://github.com/go-gitea/gitea/issues/37575)) - Ci: increase renovate frequency and fix RENOVATE\_ALLOWED\_POST\_UPGRADE\_COMMANDS ([#&#8203;37565](https://github.com/go-gitea/gitea/issues/37565)) - Docs: fix 4 typos in CHANGELOG.md ([#&#8203;37549](https://github.com/go-gitea/gitea/issues/37549)) - Fix(deps): update go dependencies ([#&#8203;37541](https://github.com/go-gitea/gitea/issues/37541)) - Chore(deps): update action dependencies ([#&#8203;37540](https://github.com/go-gitea/gitea/issues/37540)) - Refactor pull request view (6) ([#&#8203;37522](https://github.com/go-gitea/gitea/issues/37522)) - Fix: redirect early CLI console logger to stderr ([#&#8203;37507](https://github.com/go-gitea/gitea/issues/37507)) - Refactor "flex-list" to "flex-divided-list" ([#&#8203;37505](https://github.com/go-gitea/gitea/issues/37505)) - Refactor compare diff/pull page (1) ([#&#8203;37481](https://github.com/go-gitea/gitea/issues/37481)) - Refactor pull request view (4) ([#&#8203;37451](https://github.com/go-gitea/gitea/issues/37451)) - Refactor: use named `Permission` field in `Repository` struct instead of anonymous embedding ([#&#8203;37441](https://github.com/go-gitea/gitea/issues/37441)) - Replace `olivere/elastic` with REST API client, add OpenSearch support ([#&#8203;37411](https://github.com/go-gitea/gitea/issues/37411)) - Refactor: serve site manifest via `/assets/site-manifest.json` endpoint ([#&#8203;37405](https://github.com/go-gitea/gitea/issues/37405)) - Remove IsValidExternalURL/IsAPIURL and use IsValidURL at call sites ([#&#8203;37364](https://github.com/go-gitea/gitea/issues/37364)) - Update `Block a user` form ([#&#8203;37359](https://github.com/go-gitea/gitea/issues/37359)) - Move review request functions to a standalone file ([#&#8203;37358](https://github.com/go-gitea/gitea/issues/37358)) - Enable strict TypeScript, add `errorMessage` helper ([#&#8203;37292](https://github.com/go-gitea/gitea/issues/37292)) - Refactor frontend `tw-justify-between` layouts to `flex-left-right` ([#&#8203;37291](https://github.com/go-gitea/gitea/issues/37291)) - Update Nix flake ([#&#8203;37284](https://github.com/go-gitea/gitea/issues/37284)) - Remove `SubmitEvent` polyfill ([#&#8203;37276](https://github.com/go-gitea/gitea/issues/37276)) - Remove dead code identified by `deadcode` tool ([#&#8203;37271](https://github.com/go-gitea/gitea/issues/37271)) - Upgrade go-git to v5.18.0 ([#&#8203;37268](https://github.com/go-gitea/gitea/issues/37268)) - Don't add useless labels which will bother changelog generation ([#&#8203;37267](https://github.com/go-gitea/gitea/issues/37267)) - Move heatmap to first-party code ([#&#8203;37262](https://github.com/go-gitea/gitea/issues/37262)) - Tests/integration: simplify code ([#&#8203;37249](https://github.com/go-gitea/gitea/issues/37249)) - Remove error returns from crypto random helpers and callers ([#&#8203;37240](https://github.com/go-gitea/gitea/issues/37240)) - Refactor: simplify ParseCatFileTreeLine and catBatchParseTreeEntries ([#&#8203;37210](https://github.com/go-gitea/gitea/issues/37210)) - Refactor "htmx" to "fetch action" ([#&#8203;37208](https://github.com/go-gitea/gitea/issues/37208)) - Update go js py dependencies ([#&#8203;37204](https://github.com/go-gitea/gitea/issues/37204)) - Add comment for the design of "user activity time" ([#&#8203;37195](https://github.com/go-gitea/gitea/issues/37195)) - Remove outdated RunUser logic ([#&#8203;37180](https://github.com/go-gitea/gitea/issues/37180)) - Models/fixtures: add "DO NOT add more test data" comment to all yml fixture files ([#&#8203;37150](https://github.com/go-gitea/gitea/issues/37150)) - Update javascript dependencies ([#&#8203;37142](https://github.com/go-gitea/gitea/issues/37142)) - Update go dependencies ([#&#8203;37141](https://github.com/go-gitea/gitea/issues/37141)) - Frontport changelog of v1.26.0-rc0 ([#&#8203;37138](https://github.com/go-gitea/gitea/issues/37138)) - Extend issue context popup beyond markdown content ([#&#8203;36908](https://github.com/go-gitea/gitea/issues/36908)) ### [`v1.26.4`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1264---2026-06-21) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.3...v1.26.4) - SECURITY - fix(auth): do not auto-reactivate disabled users on OAuth2 callback ([#&#8203;38009](https://github.com/go-gitea/gitea/issues/38009)) ([#&#8203;38183](https://github.com/go-gitea/gitea/issues/38183)) - BUGFIXES - fix: walk git log context error handling ([#&#8203;38182](https://github.com/go-gitea/gitea/issues/38182)) ([#&#8203;38185](https://github.com/go-gitea/gitea/issues/38185)) ### [`v1.26.3`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1263---2026-06-18) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.2...v1.26.3) - BREAKING - fix(actions)!: require merged PR to bypass fork PR approval gate ([#&#8203;38010](https://github.com/go-gitea/gitea/issues/38010)) ([#&#8203;38041](https://github.com/go-gitea/gitea/issues/38041)) - SECURITY - fix(hostmatcher): patch incorrect private list ([#&#8203;38170](https://github.com/go-gitea/gitea/issues/38170)) ([#&#8203;38173](https://github.com/go-gitea/gitea/issues/38173)) - fix: Various security fixes ([#&#8203;38103](https://github.com/go-gitea/gitea/issues/38103)) ([#&#8203;38151](https://github.com/go-gitea/gitea/issues/38151)) - fix: Various sec fixes ([#&#8203;38108](https://github.com/go-gitea/gitea/issues/38108)) ([#&#8203;38147](https://github.com/go-gitea/gitea/issues/38147)) - fix: allow git clone of private repos with anonymous code access ([#&#8203;38074](https://github.com/go-gitea/gitea/issues/38074)) ([#&#8203;38146](https://github.com/go-gitea/gitea/issues/38146)) - fix(auth): ignore stale OIDC external login links to organizations ([#&#8203;37875](https://github.com/go-gitea/gitea/issues/37875)) ([#&#8203;38141](https://github.com/go-gitea/gitea/issues/38141)) - fix(hostmatcher): block reserved IP ranges from external/private filters ([#&#8203;38039](https://github.com/go-gitea/gitea/issues/38039)) ([#&#8203;38059](https://github.com/go-gitea/gitea/issues/38059)) - fix(lfs): require Code-unit access for cross-repo LFS object reuse ([#&#8203;38006](https://github.com/go-gitea/gitea/issues/38006)) ([#&#8203;38050](https://github.com/go-gitea/gitea/issues/38050)) - fix(lfs): reject unknown SSH LFS sub-verbs to prevent auth bypass ([#&#8203;38008](https://github.com/go-gitea/gitea/issues/38008)) ([#&#8203;38015](https://github.com/go-gitea/gitea/issues/38015)) - fix: bound CODEOWNERS regex match time ([#&#8203;38011](https://github.com/go-gitea/gitea/issues/38011)) ([#&#8203;38025](https://github.com/go-gitea/gitea/issues/38025)) - fix: bound debian ParseControlFile to a single control stanza ([#&#8203;38044](https://github.com/go-gitea/gitea/issues/38044)) ([#&#8203;38055](https://github.com/go-gitea/gitea/issues/38055)) - fix(deps): update module golang.org/x/net to v0.55.0 \[security] ([#&#8203;37813](https://github.com/go-gitea/gitea/issues/37813)) ([#&#8203;37829](https://github.com/go-gitea/gitea/issues/37829)) - API - feat(api): add Link header in ListForks ([#&#8203;38052](https://github.com/go-gitea/gitea/issues/38052)) ([#&#8203;38063](https://github.com/go-gitea/gitea/issues/38063)) - BUGFIXES - fix: Fix the panic when ssh remote lfs endpoint parsing failure ([#&#8203;38026](https://github.com/go-gitea/gitea/issues/38026)) ([#&#8203;38158](https://github.com/go-gitea/gitea/issues/38158)) - fix(api): nil pointer panic when filtering tracked times by a non-existent user ([#&#8203;38112](https://github.com/go-gitea/gitea/issues/38112)) ([#&#8203;38115](https://github.com/go-gitea/gitea/issues/38115)) - fix: keep literal "false" value displayed in workflow\_dispatch choice dropdowns ([#&#8203;38080](https://github.com/go-gitea/gitea/issues/38080)) ([#&#8203;38096](https://github.com/go-gitea/gitea/issues/38096)) - fix: parse HEAD ref ([#&#8203;38119](https://github.com/go-gitea/gitea/issues/38119)) - fix: git cmd ([#&#8203;38084](https://github.com/go-gitea/gitea/issues/38084)) ([#&#8203;38087](https://github.com/go-gitea/gitea/issues/38087)) - fix(releases): generate notes for initial tag ([#&#8203;37697](https://github.com/go-gitea/gitea/issues/37697)) ([#&#8203;37986](https://github.com/go-gitea/gitea/issues/37986)) - fix(actions): return 404 when job log blob is missing ([#&#8203;38003](https://github.com/go-gitea/gitea/issues/38003)) ([#&#8203;38004](https://github.com/go-gitea/gitea/issues/38004)) - fix(actions): exclude `workflow_call` from workflow trigger detection ([#&#8203;37894](https://github.com/go-gitea/gitea/issues/37894)) ([#&#8203;37899](https://github.com/go-gitea/gitea/issues/37899)) - fix(actions): keep action run title clickable when commit subject is a URL ([#&#8203;37867](https://github.com/go-gitea/gitea/issues/37867)) ([#&#8203;37898](https://github.com/go-gitea/gitea/issues/37898)) - fix(actions): reject workflow\_dispatch for workflows without that trigger ([#&#8203;37660](https://github.com/go-gitea/gitea/issues/37660)) ([#&#8203;37895](https://github.com/go-gitea/gitea/issues/37895)) - fix(actions): ack re-sent `UpdateLog` finalize idempotently ([#&#8203;37885](https://github.com/go-gitea/gitea/issues/37885)) ([#&#8203;37892](https://github.com/go-gitea/gitea/issues/37892)) - fix: http content file render ([#&#8203;37850](https://github.com/go-gitea/gitea/issues/37850)) ([#&#8203;37856](https://github.com/go-gitea/gitea/issues/37856)) - fix(issues): clear stale ReviewTypeRequest when submitting pending review ([#&#8203;37809](https://github.com/go-gitea/gitea/issues/37809)) ([#&#8203;37815](https://github.com/go-gitea/gitea/issues/37815)) - fix: Fix issue target branch selection for non-collaborators ([#&#8203;36916](https://github.com/go-gitea/gitea/issues/36916)) ([#&#8203;38164](https://github.com/go-gitea/gitea/issues/38164)) - BUILD - fix(deps): update `@playwright/test` to 1.60.0 ([#&#8203;38144](https://github.com/go-gitea/gitea/issues/38144)) - ci: add `tools/ci-tools.ts` for the PR labeler workflow ([#&#8203;37831](https://github.com/go-gitea/gitea/issues/37831)) - fix(build): swagger css import ([#&#8203;37801](https://github.com/go-gitea/gitea/issues/37801)) ([#&#8203;37803](https://github.com/go-gitea/gitea/issues/37803)) ### [`v1.26.2`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1262---2026-05-20) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.1...v1.26.2) - SECURITY - fix(permissions): Fix reading permission ([#&#8203;37769](https://github.com/go-gitea/gitea/issues/37769)) - fix(actions): make artifact signature payloads unambiguous ([#&#8203;37707](https://github.com/go-gitea/gitea/issues/37707)) - fix: Unify public-only token filtering in API queries and repo access checks ([#&#8203;37118](https://github.com/go-gitea/gitea/issues/37118)) - fix: Add missed token scope checking ([#&#8203;37735](https://github.com/go-gitea/gitea/issues/37735)) - fix(oauth): bind token exchanges to the original client request ([#&#8203;37704](https://github.com/go-gitea/gitea/issues/37704)) - fix(oauth): strengthen PKCE validation and refresh token replay protection ([#&#8203;37706](https://github.com/go-gitea/gitea/issues/37706)) - fix(web): enforce token scopes on raw, media, and attachment downloads ([#&#8203;37698](https://github.com/go-gitea/gitea/issues/37698)) - fix(security): enforce wiki git writes and LFS token access at request time ([#&#8203;37695](https://github.com/go-gitea/gitea/issues/37695)) - feat(api): encrypt AWS creds ([#&#8203;37679](https://github.com/go-gitea/gitea/issues/37679)) - fix(deps): update dependency mermaid to v11.15.0 \[security], add e2e test - fix(packages): Add label for private and internal package and fix composor package source permission check ([#&#8203;37610](https://github.com/go-gitea/gitea/issues/37610)) - fix(git): Fix smart http request scope bug ([#&#8203;37583](https://github.com/go-gitea/gitea/issues/37583)) - Fix basic auth bug ([#&#8203;37503](https://github.com/go-gitea/gitea/issues/37503)) - Fix allow maintainer edit permission check ([#&#8203;37479](https://github.com/go-gitea/gitea/issues/37479)) ([#&#8203;37484](https://github.com/go-gitea/gitea/issues/37484)) - Fix URL sanitization to handle schemeless credentials ([#&#8203;37440](https://github.com/go-gitea/gitea/issues/37440)) ([#&#8203;37471](https://github.com/go-gitea/gitea/issues/37471)) - Fix attachment Content-Security-Policy ([#&#8203;37455](https://github.com/go-gitea/gitea/issues/37455)) ([#&#8203;37464](https://github.com/go-gitea/gitea/issues/37464)) - chore(deps): bump go-git/go-git/v5 to 5.19.0 ([#&#8203;37608](https://github.com/go-gitea/gitea/issues/37608)) - BUGFIXES - fix(pull): handle empty pull request files view to allow reviews ([#&#8203;37783](https://github.com/go-gitea/gitea/issues/37783)) - fix(markup): make RenderString never fail ([#&#8203;37779](https://github.com/go-gitea/gitea/issues/37779)) - fix: add natural sort to sortTreeViewNodes ([#&#8203;37772](https://github.com/go-gitea/gitea/issues/37772)) - fix: package creation unique conflict ([#&#8203;37774](https://github.com/go-gitea/gitea/issues/37774)) - fix!: add DEFAULT\_TITLE\_SOURCE setting for pull request title default behavior ([#&#8203;37465](https://github.com/go-gitea/gitea/issues/37465)) - fix: Allow direct commits for unprotected files with push restrictions ([#&#8203;37657](https://github.com/go-gitea/gitea/issues/37657)) - fix(actions): wrong assumption that run id always >= job id ([#&#8203;37737](https://github.com/go-gitea/gitea/issues/37737)) - fix(auth): set User-Agent on avatar fetch and sync avatar on link-account register ([#&#8203;37564](https://github.com/go-gitea/gitea/issues/37564)) ([#&#8203;37588](https://github.com/go-gitea/gitea/issues/37588)) - fix(actions): deadlock between PrepareRunAndInsert and UpdateTaskByState ([#&#8203;37692](https://github.com/go-gitea/gitea/issues/37692)) - fix(repo): /generate must sync the branch table for the new repo ([#&#8203;37693](https://github.com/go-gitea/gitea/issues/37693)) - build: Fix snap build (1.26) - fix(actions): run TransferLogs on UpdateLog{Rows:\[], NoMore:true} ([#&#8203;37631](https://github.com/go-gitea/gitea/issues/37631)) - fix show correct mergebase - fix: make clone URL respect public URL detection setting ([#&#8203;37615](https://github.com/go-gitea/gitea/issues/37615)) - fix: "run as root" check ([#&#8203;37622](https://github.com/go-gitea/gitea/issues/37622)) - chore(deps): update dependency go to v1.26.3 ([#&#8203;37601](https://github.com/go-gitea/gitea/issues/37601)) - Compare dropdown fails when selecting branch with no common merge-base ([#&#8203;37470](https://github.com/go-gitea/gitea/issues/37470)) - fix: treat email addresses case-insensitively ([#&#8203;37600](https://github.com/go-gitea/gitea/issues/37600)) - fix(actions): fix blank lines after ::endgroup:: ([#&#8203;37597](https://github.com/go-gitea/gitea/issues/37597)) - fix(actions): report individual step status in workflow job API response ([#&#8203;37592](https://github.com/go-gitea/gitea/issues/37592)) - fix: Invalid UTF-8 commit messages in JSON API responses ([#&#8203;37542](https://github.com/go-gitea/gitea/issues/37542)) - fix: use consistent GetUser family functions ([#&#8203;37553](https://github.com/go-gitea/gitea/issues/37553)) - fix(api): return 409 message instead of empty JSON for wrong commit id ([#&#8203;37572](https://github.com/go-gitea/gitea/issues/37572)) - fix(actions): prevent panic when workflow contains null jobs ([#&#8203;37570](https://github.com/go-gitea/gitea/issues/37570)) - Make ServeSetHeaders default to download attachment if filename exists ([#&#8203;37552](https://github.com/go-gitea/gitea/issues/37552)) ([#&#8203;37555](https://github.com/go-gitea/gitea/issues/37555)) - Fix(actions): validate workflow param to prevent 500 error ([#&#8203;37546](https://github.com/go-gitea/gitea/issues/37546)) ([#&#8203;37554](https://github.com/go-gitea/gitea/issues/37554)) - Don't unblock run-level-concurrency-blocked runs in the resolver ([#&#8203;37461](https://github.com/go-gitea/gitea/issues/37461)) ([#&#8203;37538](https://github.com/go-gitea/gitea/issues/37538)) - Fix(packages): use file names for generic web downloads ([#&#8203;37514](https://github.com/go-gitea/gitea/issues/37514)) ([#&#8203;37520](https://github.com/go-gitea/gitea/issues/37520)) - Fix merge autodetect can't close other PRs but only the last one when multiple PRs are pushed at once ([#&#8203;37512](https://github.com/go-gitea/gitea/issues/37512)) ([#&#8203;37516](https://github.com/go-gitea/gitea/issues/37516)) - Fix update branch protection order ([#&#8203;37508](https://github.com/go-gitea/gitea/issues/37508)) ([#&#8203;37513](https://github.com/go-gitea/gitea/issues/37513)) - Fix mCaptcha broken after Vite migration ([#&#8203;37492](https://github.com/go-gitea/gitea/issues/37492)) ([#&#8203;37509](https://github.com/go-gitea/gitea/issues/37509)) - Fix review submission from single-commit PR view ([#&#8203;37475](https://github.com/go-gitea/gitea/issues/37475)) ([#&#8203;37485](https://github.com/go-gitea/gitea/issues/37485)) - Fix scheduled action panic with null event payload ([#&#8203;37459](https://github.com/go-gitea/gitea/issues/37459)) ([#&#8203;37466](https://github.com/go-gitea/gitea/issues/37466)) - Make GetPossibleUserByID can handle deleted user ([#&#8203;37430](https://github.com/go-gitea/gitea/issues/37430)) ([#&#8203;37431](https://github.com/go-gitea/gitea/issues/37431)) - Remove excessive quote from terraform instructions ([#&#8203;37424](https://github.com/go-gitea/gitea/issues/37424)) ([#&#8203;37426](https://github.com/go-gitea/gitea/issues/37426)) - Fix color regressions, add `priority` color ([#&#8203;37417](https://github.com/go-gitea/gitea/issues/37417)) ([#&#8203;37421](https://github.com/go-gitea/gitea/issues/37421)) - MISC - Add CurrentURL template variable back ([#&#8203;37444](https://github.com/go-gitea/gitea/issues/37444)) ([#&#8203;37449](https://github.com/go-gitea/gitea/issues/37449)) ### [`v1.26.1`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1261---2026-04-21) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.26.0...v1.26.1) - BUGFIXES - Add event.schedule context for schedule actions task ([#&#8203;37320](https://github.com/go-gitea/gitea/issues/37320)) ([#&#8203;37348](https://github.com/go-gitea/gitea/issues/37348)) - Fix an issue where changing an organization's visibility caused problems when users had forked its repositories. ([#&#8203;37324](https://github.com/go-gitea/gitea/issues/37324)) ([#&#8203;37344](https://github.com/go-gitea/gitea/issues/37344)) - Use modern "git update-index --cacheinfo" syntax to support more file names ([#&#8203;37338](https://github.com/go-gitea/gitea/issues/37338)) ([#&#8203;37343](https://github.com/go-gitea/gitea/issues/37343)) - Fix URL related escaping for oauth2 ([#&#8203;37334](https://github.com/go-gitea/gitea/issues/37334)) ([#&#8203;37340](https://github.com/go-gitea/gitea/issues/37340)) - When the requested arch rpm is missing fall back to noarch ([#&#8203;37236](https://github.com/go-gitea/gitea/issues/37236)) ([#&#8203;37339](https://github.com/go-gitea/gitea/issues/37339)) - Fix actions concurrency groups cross-branch leak ([#&#8203;37311](https://github.com/go-gitea/gitea/issues/37311)) ([#&#8203;37331](https://github.com/go-gitea/gitea/issues/37331)) - Fix bug when accessing user badges ([#&#8203;37321](https://github.com/go-gitea/gitea/issues/37321)) ([#&#8203;37329](https://github.com/go-gitea/gitea/issues/37329)) - Fix AppFullLink ([#&#8203;37325](https://github.com/go-gitea/gitea/issues/37325)) ([#&#8203;37328](https://github.com/go-gitea/gitea/issues/37328)) - Fix container auth for public instance ([#&#8203;37290](https://github.com/go-gitea/gitea/issues/37290)) ([#&#8203;37294](https://github.com/go-gitea/gitea/issues/37294)) - Enhance GetActionWorkflow to support fallback references ([#&#8203;37189](https://github.com/go-gitea/gitea/issues/37189)) ([#&#8203;37283](https://github.com/go-gitea/gitea/issues/37283)) - Fix vite manifest update masking build errors ([#&#8203;37279](https://github.com/go-gitea/gitea/issues/37279)) ([#&#8203;37310](https://github.com/go-gitea/gitea/issues/37310)) - Fix Mermaid diagrams failing when node labels contain line breaks ([#&#8203;37296](https://github.com/go-gitea/gitea/issues/37296)) ([#&#8203;37299](https://github.com/go-gitea/gitea/issues/37299)) - Use TriggerEvent instead of Event in workflow runs API response for scheduled runs ([#&#8203;37288](https://github.com/go-gitea/gitea/issues/37288)) [#&#8203;37360](https://github.com/go-gitea/gitea/issues/37360) - Add URL to Learn more about blocking a user. ([#&#8203;37355](https://github.com/go-gitea/gitea/issues/37355)) [#&#8203;37367](https://github.com/go-gitea/gitea/issues/37367) - Fix button layout shift when collapsing file tree in editor ([#&#8203;37363](https://github.com/go-gitea/gitea/issues/37363)) [#&#8203;37375](https://github.com/go-gitea/gitea/issues/37375) - Fix org team assignee/reviewer lookups for team member permissions ([#&#8203;37365](https://github.com/go-gitea/gitea/issues/37365)) [#&#8203;37391](https://github.com/go-gitea/gitea/issues/37391) - Fix repo init README EOL ([#&#8203;37388](https://github.com/go-gitea/gitea/issues/37388)) [#&#8203;37399](https://github.com/go-gitea/gitea/issues/37399) - Fix: dump with default zip type produces uncompressed zip ([#&#8203;37401](https://github.com/go-gitea/gitea/issues/37401)) [#&#8203;37402](https://github.com/go-gitea/gitea/issues/37402) ### [`v1.26.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1260---2026-04-17) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.5...v1.26.0) - BREAKING - Correct swagger annotations for enums, status codes, and notification state ([#&#8203;37030](https://github.com/go-gitea/gitea/issues/37030)) - Remove GET API registration-token ([#&#8203;36801](https://github.com/go-gitea/gitea/issues/36801)) - Support Actions `concurrency` syntax ([#&#8203;32751](https://github.com/go-gitea/gitea/issues/32751)) - Make PUBLIC\_URL\_DETECTION default to "auto" ([#&#8203;36955](https://github.com/go-gitea/gitea/issues/36955)) - SECURITY - Bound PageSize in `ListUnadoptedRepositories` ([#&#8203;36884](https://github.com/go-gitea/gitea/issues/36884)) - FEATURES - Support Actions `concurrency` syntax ([#&#8203;32751](https://github.com/go-gitea/gitea/issues/32751)) - Add terraform state registry ([#&#8203;36710](https://github.com/go-gitea/gitea/issues/36710)) - Instance-wide (global) info banner and maintenance mode ([#&#8203;36571](https://github.com/go-gitea/gitea/issues/36571)) - Support rendering OpenAPI spec ([#&#8203;36449](https://github.com/go-gitea/gitea/issues/36449)) - Add keyboard shortcuts for repository file and code search ([#&#8203;36416](https://github.com/go-gitea/gitea/issues/36416)) - Add support for archive-upload rpc ([#&#8203;36391](https://github.com/go-gitea/gitea/issues/36391)) - Add ability to download subpath archive ([#&#8203;36371](https://github.com/go-gitea/gitea/issues/36371)) - Add workflow dependencies visualization ([#&#8203;26062](https://github.com/go-gitea/gitea/issues/26062)) ([#&#8203;36248](https://github.com/go-gitea/gitea/issues/36248)) & Restyle Workflow Graph ([#&#8203;36912](https://github.com/go-gitea/gitea/issues/36912)) - Automatic generation of release notes ([#&#8203;35977](https://github.com/go-gitea/gitea/issues/35977)) - Add "Go to file", "Delete Directory" to repo file list page ([#&#8203;35911](https://github.com/go-gitea/gitea/issues/35911)) - Introduce "config edit-ini" sub command to help maintaining INI config file ([#&#8203;35735](https://github.com/go-gitea/gitea/issues/35735)) - Add button to re-run failed jobs in Actions ([#&#8203;36924](https://github.com/go-gitea/gitea/issues/36924)) - Support actions and reusable workflows from private repos ([#&#8203;32562](https://github.com/go-gitea/gitea/issues/32562)) - Add summary to action runs view ([#&#8203;36883](https://github.com/go-gitea/gitea/issues/36883)) - Add user badges ([#&#8203;36752](https://github.com/go-gitea/gitea/issues/36752)) - Add configurable permissions for Actions automatic tokens ([#&#8203;36173](https://github.com/go-gitea/gitea/issues/36173)) - Add per-runner "Disable/Pause" ([#&#8203;36776](https://github.com/go-gitea/gitea/issues/36776)) - Feature non-zipped actions artifacts (action v7 / nodejs / npm v6.2.0) ([#&#8203;36786](https://github.com/go-gitea/gitea/issues/36786)) - PERFORMANCE - WorkflowDispatch API optionally return runid ([#&#8203;36706](https://github.com/go-gitea/gitea/issues/36706)) - Add render cache for SVG icons ([#&#8203;36863](https://github.com/go-gitea/gitea/issues/36863)) - Load `mentionValues` asynchronously ([#&#8203;36739](https://github.com/go-gitea/gitea/issues/36739)) - Lazy-load some Vue components, fix heatmap chunk loading on every page ([#&#8203;36719](https://github.com/go-gitea/gitea/issues/36719)) - Load heatmap data asynchronously ([#&#8203;36622](https://github.com/go-gitea/gitea/issues/36622)) - Use prev/next pagination for user profile activities page to speed up ([#&#8203;36642](https://github.com/go-gitea/gitea/issues/36642)) - Refactor cat-file batch operations and support `--batch-command` approach ([#&#8203;35775](https://github.com/go-gitea/gitea/issues/35775)) - Use merge tree to detect conflicts when possible ([#&#8203;36400](https://github.com/go-gitea/gitea/issues/36400)) - ENHANCEMENTS - Implement logout redirection for reverse proxy auth setups ([#&#8203;36085](https://github.com/go-gitea/gitea/issues/36085)) ([#&#8203;37171](https://github.com/go-gitea/gitea/issues/37171)) - Adds option to force update new branch in contents routes ([#&#8203;35592](https://github.com/go-gitea/gitea/issues/35592)) - Add viewer controller for mermaid (zoom, drag) ([#&#8203;36557](https://github.com/go-gitea/gitea/issues/36557)) - Add code editor setting dropdowns ([#&#8203;36534](https://github.com/go-gitea/gitea/issues/36534)) - Add `elk` layout support to mermaid ([#&#8203;36486](https://github.com/go-gitea/gitea/issues/36486)) - Add resolve/unresolve review comment API endpoints ([#&#8203;36441](https://github.com/go-gitea/gitea/issues/36441)) - Allow configuring default PR base branch (fixes [#&#8203;36412](https://github.com/go-gitea/gitea/issues/36412)) ([#&#8203;36425](https://github.com/go-gitea/gitea/issues/36425)) - Add support for RPM Errata (updateinfo.xml) ([#&#8203;37125](https://github.com/go-gitea/gitea/issues/37125)) - Require additional user confirmation for making repo private ([#&#8203;36959](https://github.com/go-gitea/gitea/issues/36959)) - Add `actions.WORKFLOW_DIRS` setting ([#&#8203;36619](https://github.com/go-gitea/gitea/issues/36619)) - Avoid opening new tab when downloading actions logs ([#&#8203;36740](https://github.com/go-gitea/gitea/issues/36740)) - Implements OIDC RP-Initiated Logout ([#&#8203;36724](https://github.com/go-gitea/gitea/issues/36724)) - Show workflow link ([#&#8203;37070](https://github.com/go-gitea/gitea/issues/37070)) - Desaturate dark theme background colors ([#&#8203;37056](https://github.com/go-gitea/gitea/issues/37056)) - Refactor "org teams" page and help new users to "add member" to an org ([#&#8203;37051](https://github.com/go-gitea/gitea/issues/37051)) - Add webhook name field to improve webhook identification ([#&#8203;37025](https://github.com/go-gitea/gitea/issues/37025)) ([#&#8203;37040](https://github.com/go-gitea/gitea/issues/37040)) - Make task list checkboxes clickable in the preview tab ([#&#8203;37010](https://github.com/go-gitea/gitea/issues/37010)) - Improve severity labels in Actions logs and tweak colors ([#&#8203;36993](https://github.com/go-gitea/gitea/issues/36993)) - Linkify URLs in Actions workflow logs ([#&#8203;36986](https://github.com/go-gitea/gitea/issues/36986)) - Allow text selection on checkbox labels ([#&#8203;36970](https://github.com/go-gitea/gitea/issues/36970)) - Support dark/light theme images in markdown ([#&#8203;36922](https://github.com/go-gitea/gitea/issues/36922)) - Enable native dark mode for swagger-ui ([#&#8203;36899](https://github.com/go-gitea/gitea/issues/36899)) - Rework checkbox styling, remove `input` border hover effect ([#&#8203;36870](https://github.com/go-gitea/gitea/issues/36870)) - Refactor storage content-type handling of ServeDirectURL ([#&#8203;36804](https://github.com/go-gitea/gitea/issues/36804)) - Use "Enable Gravatar" but not "Disable" ([#&#8203;36771](https://github.com/go-gitea/gitea/issues/36771)) - Use case-insensitive matching for Git error "Not a valid object name" ([#&#8203;36728](https://github.com/go-gitea/gitea/issues/36728)) - Add "Copy Source" to markup comment menu ([#&#8203;36726](https://github.com/go-gitea/gitea/issues/36726)) - Change image transparency grid to CSS ([#&#8203;36711](https://github.com/go-gitea/gitea/issues/36711)) - Add "Run" prefix for unnamed action steps ([#&#8203;36624](https://github.com/go-gitea/gitea/issues/36624)) - Persist actions log time display settings in `localStorage` ([#&#8203;36623](https://github.com/go-gitea/gitea/issues/36623)) - Use first commit title for multi-commit PRs and fix auto-focus title field ([#&#8203;36606](https://github.com/go-gitea/gitea/issues/36606)) - Improve BuildCaseInsensitiveLike with lowercase ([#&#8203;36598](https://github.com/go-gitea/gitea/issues/36598)) - Improve diff highlighting ([#&#8203;36583](https://github.com/go-gitea/gitea/issues/36583)) - Exclude cancelled runs from failure-only email notifications ([#&#8203;36569](https://github.com/go-gitea/gitea/issues/36569)) - Use full-file highlighting for diff sections ([#&#8203;36561](https://github.com/go-gitea/gitea/issues/36561)) - Color command/error logs in Actions log ([#&#8203;36538](https://github.com/go-gitea/gitea/issues/36538)) - Add paging headers ([#&#8203;36521](https://github.com/go-gitea/gitea/issues/36521)) - Improve timeline entries for WIP prefix changes in pull requests ([#&#8203;36518](https://github.com/go-gitea/gitea/issues/36518)) - Add FOLDER\_ICON\_THEME configuration option ([#&#8203;36496](https://github.com/go-gitea/gitea/issues/36496)) - Normalize guessed languages for code highlighting ([#&#8203;36450](https://github.com/go-gitea/gitea/issues/36450)) - Add chunked transfer encoding support for LFS uploads ([#&#8203;36380](https://github.com/go-gitea/gitea/issues/36380)) - Indicate when only optional checks failed ([#&#8203;36367](https://github.com/go-gitea/gitea/issues/36367)) - Add 'allow\_maintainer\_edit' API option for creating a pull request ([#&#8203;36283](https://github.com/go-gitea/gitea/issues/36283)) - Support closing keywords with URL references ([#&#8203;36221](https://github.com/go-gitea/gitea/issues/36221)) - Improve diff file headers ([#&#8203;36215](https://github.com/go-gitea/gitea/issues/36215)) - Fix and enhance comment editor monospace toggle ([#&#8203;36181](https://github.com/go-gitea/gitea/issues/36181)) - Add git.DIFF\_RENAME\_SIMILARITY\_THRESHOLD option ([#&#8203;36164](https://github.com/go-gitea/gitea/issues/36164)) - Add matching pair insertion to markdown textarea ([#&#8203;36121](https://github.com/go-gitea/gitea/issues/36121)) - Add sorting/filtering to admin user search API endpoint ([#&#8203;36112](https://github.com/go-gitea/gitea/issues/36112)) - Allow action user have read permission in public repo like other user ([#&#8203;36095](https://github.com/go-gitea/gitea/issues/36095)) - Disable matchBrackets in monaco ([#&#8203;36089](https://github.com/go-gitea/gitea/issues/36089)) - Use GitHub-style commit message for squash merge ([#&#8203;35987](https://github.com/go-gitea/gitea/issues/35987)) - Make composer registry support tar.gz and tar.bz2 and fix bugs ([#&#8203;35958](https://github.com/go-gitea/gitea/issues/35958)) - Add GITEA\_PR\_INDEX env variable to githooks ([#&#8203;35938](https://github.com/go-gitea/gitea/issues/35938)) - Add proper error message if session provider can not be created ([#&#8203;35520](https://github.com/go-gitea/gitea/issues/35520)) - Add button to copy file name in PR files ([#&#8203;35509](https://github.com/go-gitea/gitea/issues/35509)) - Move `X_FRAME_OPTIONS` setting from `cors` to `security` section ([#&#8203;30256](https://github.com/go-gitea/gitea/issues/30256)) - Add placeholder content for empty content page ([#&#8203;37114](https://github.com/go-gitea/gitea/issues/37114)) - Add `DEFAULT_DELETE_BRANCH_AFTER_MERGE` setting ([#&#8203;36917](https://github.com/go-gitea/gitea/issues/36917)) - Redirect to the only OAuth2 provider when no other login methods and fix various problems ([#&#8203;36901](https://github.com/go-gitea/gitea/issues/36901)) - Add admin badge to navbar avatar ([#&#8203;36790](https://github.com/go-gitea/gitea/issues/36790)) - Add `never` option to `PUBLIC_URL_DETECTION` configuration ([#&#8203;36785](https://github.com/go-gitea/gitea/issues/36785)) - Add background and run count to actions list page ([#&#8203;36707](https://github.com/go-gitea/gitea/issues/36707)) - Add icon to buttons "Close with Comment", "Close Pull Request", "Close Issue" ([#&#8203;36654](https://github.com/go-gitea/gitea/issues/36654)) - Add support for in\_progress event in workflow\_run webhook ([#&#8203;36979](https://github.com/go-gitea/gitea/issues/36979)) - Report commit status for pull\_request\_review events ([#&#8203;36589](https://github.com/go-gitea/gitea/issues/36589)) - Render merged pull request title as such in dashboard feed ([#&#8203;36479](https://github.com/go-gitea/gitea/issues/36479)) - Feature to be able to filter project boards by milestones ([#&#8203;36321](https://github.com/go-gitea/gitea/issues/36321)) - Use user id in noreply emails ([#&#8203;36550](https://github.com/go-gitea/gitea/issues/36550)) - Enable pagination on GiteaDownloader.getIssueReactions() ([#&#8203;36549](https://github.com/go-gitea/gitea/issues/36549)) - Remove striped tables in UI ([#&#8203;36509](https://github.com/go-gitea/gitea/issues/36509)) - Improve control char rendering and escape button styling ([#&#8203;37094](https://github.com/go-gitea/gitea/issues/37094)) - Support legacy run/job index-based URLs and refactor migration 326 ([#&#8203;37008](https://github.com/go-gitea/gitea/issues/37008)) - Add date to "No Contributions" tooltip ([#&#8203;36190](https://github.com/go-gitea/gitea/issues/36190)) - Show edit page confirmation dialog on tree view file change ([#&#8203;36130](https://github.com/go-gitea/gitea/issues/36130)) - Mention proc-receive in text for dashboard.resync\_all\_hooks func ([#&#8203;35991](https://github.com/go-gitea/gitea/issues/35991)) - Reuse selectable style for wiki ([#&#8203;35990](https://github.com/go-gitea/gitea/issues/35990)) - Support blue yellow colorblind theme ([#&#8203;35910](https://github.com/go-gitea/gitea/issues/35910)) - Support selecting theme on the footer ([#&#8203;35741](https://github.com/go-gitea/gitea/issues/35741)) - Improve online runner check ([#&#8203;35722](https://github.com/go-gitea/gitea/issues/35722)) - Add quick approve button on PR page ([#&#8203;35678](https://github.com/go-gitea/gitea/issues/35678)) - Enable commenting on expanded lines in PR diffs ([#&#8203;35662](https://github.com/go-gitea/gitea/issues/35662)) - Print PR-Title into tooltip for actions ([#&#8203;35579](https://github.com/go-gitea/gitea/issues/35579)) - Use explicit, stronger defaults for newly generated repo signing keys for Debian ([#&#8203;36236](https://github.com/go-gitea/gitea/issues/36236)) - Improve the compare page ([#&#8203;36261](https://github.com/go-gitea/gitea/issues/36261)) - Unify repo names in system notices ([#&#8203;36491](https://github.com/go-gitea/gitea/issues/36491)) - Move package settings to package instead of being tied to version ([#&#8203;37026](https://github.com/go-gitea/gitea/issues/37026)) - Add Actions API rerun endpoints for runs and jobs ([#&#8203;36768](https://github.com/go-gitea/gitea/issues/36768)) - Add branch\_count to repository API ([#&#8203;35351](https://github.com/go-gitea/gitea/issues/35351)) ([#&#8203;36743](https://github.com/go-gitea/gitea/issues/36743)) - Add created\_by filter to SearchIssues ([#&#8203;36670](https://github.com/go-gitea/gitea/issues/36670)) - Allow admins to rename non-local users ([#&#8203;35970](https://github.com/go-gitea/gitea/issues/35970)) - Support updating branch via API ([#&#8203;35951](https://github.com/go-gitea/gitea/issues/35951)) - Add an option to automatically verify SSH keys from LDAP ([#&#8203;35927](https://github.com/go-gitea/gitea/issues/35927)) - Make "update file" API can create a new file when SHA is not set ([#&#8203;35738](https://github.com/go-gitea/gitea/issues/35738)) - Update issue.go with labels documentation (labels content, not ids) ([#&#8203;35522](https://github.com/go-gitea/gitea/issues/35522)) - Expose content\_version for optimistic locking on issue and PR edits ([#&#8203;37035](https://github.com/go-gitea/gitea/issues/37035)) - Pass ServeHeaderOptions by value instead of pointer, fine tune httplib tests ([#&#8203;36982](https://github.com/go-gitea/gitea/issues/36982)) - BUGFIXES - Frontend iframe renderer framework: 3D models, OpenAPI ([#&#8203;37233](https://github.com/go-gitea/gitea/issues/37233)) ([#&#8203;37273](https://github.com/go-gitea/gitea/issues/37273)) - Fix CODEOWNERS absolute path matching. ([#&#8203;37244](https://github.com/go-gitea/gitea/issues/37244)) ([#&#8203;37264](https://github.com/go-gitea/gitea/issues/37264)) - Swift registry metadata: preserve more JSON fields and accept empty metadata ([#&#8203;37254](https://github.com/go-gitea/gitea/issues/37254)) ([#&#8203;37261](https://github.com/go-gitea/gitea/issues/37261)) - Fix user ssh key exporting and tests ([#&#8203;37256](https://github.com/go-gitea/gitea/issues/37256)) ([#&#8203;37258](https://github.com/go-gitea/gitea/issues/37258)) - Fix team member avatar size and add tooltip ([#&#8203;37253](https://github.com/go-gitea/gitea/issues/37253)) - Fix commit title rendering in action run and blame ([#&#8203;37243](https://github.com/go-gitea/gitea/issues/37243)) ([#&#8203;37251](https://github.com/go-gitea/gitea/issues/37251)) - Fix corrupted JSON caused by goccy library ([#&#8203;37214](https://github.com/go-gitea/gitea/issues/37214)) ([#&#8203;37220](https://github.com/go-gitea/gitea/issues/37220)) - Add test for "fetch redirect", add CSS value validation for external render ([#&#8203;37207](https://github.com/go-gitea/gitea/issues/37207)) ([#&#8203;37216](https://github.com/go-gitea/gitea/issues/37216)) - Fix incorrect concurrency check ([#&#8203;37205](https://github.com/go-gitea/gitea/issues/37205)) ([#&#8203;37215](https://github.com/go-gitea/gitea/issues/37215)) - Fix handle missing base branch in PR commits API ([#&#8203;37193](https://github.com/go-gitea/gitea/issues/37193)) ([#&#8203;37203](https://github.com/go-gitea/gitea/issues/37203)) - Fix encoding for Matrix Webhooks ([#&#8203;37190](https://github.com/go-gitea/gitea/issues/37190)) ([#&#8203;37201](https://github.com/go-gitea/gitea/issues/37201)) - Fix handle fork-only commits in compare API ([#&#8203;37185](https://github.com/go-gitea/gitea/issues/37185)) ([#&#8203;37199](https://github.com/go-gitea/gitea/issues/37199)) - Indicate form field readonly via background, fix RunUser config ([#&#8203;37175](https://github.com/go-gitea/gitea/issues/37175), [#&#8203;37180](https://github.com/go-gitea/gitea/issues/37180)) ([#&#8203;37178](https://github.com/go-gitea/gitea/issues/37178)) - Report structurally invalid workflows to users ([#&#8203;37116](https://github.com/go-gitea/gitea/issues/37116)) ([#&#8203;37164](https://github.com/go-gitea/gitea/issues/37164)) - Fix API not persisting pull request unit config when has\_pull\_requests is not set ([#&#8203;36718](https://github.com/go-gitea/gitea/issues/36718)) - Rename CSS variables and improve colorblind themes ([#&#8203;36353](https://github.com/go-gitea/gitea/issues/36353)) - Hide `add-matcher` and `remove-matcher` from actions job logs ([#&#8203;36520](https://github.com/go-gitea/gitea/issues/36520)) - Prevent navigation keys from triggering actions during IME composition ([#&#8203;36540](https://github.com/go-gitea/gitea/issues/36540)) - Fix vertical alignment of `.commit-sign-badge` children ([#&#8203;36570](https://github.com/go-gitea/gitea/issues/36570)) - Fix duplicate startup warnings in admin panel ([#&#8203;36641](https://github.com/go-gitea/gitea/issues/36641)) - Fix CODEOWNERS review request attribution using comment metadata ([#&#8203;36348](https://github.com/go-gitea/gitea/issues/36348)) - Fix HTML tags appearing in wiki table of contents ([#&#8203;36284](https://github.com/go-gitea/gitea/issues/36284)) - Fix various bugs ([#&#8203;37096](https://github.com/go-gitea/gitea/issues/37096)) - Fix various legacy problems ([#&#8203;37092](https://github.com/go-gitea/gitea/issues/37092)) - Fix RPM Registry 404 when package name contains 'package' ([#&#8203;37087](https://github.com/go-gitea/gitea/issues/37087)) - Merge some standalone Vite entries into index.js ([#&#8203;37085](https://github.com/go-gitea/gitea/issues/37085)) - Fix various problems ([#&#8203;37077](https://github.com/go-gitea/gitea/issues/37077)) - Fix issue label deletion with Actions tokens ([#&#8203;37013](https://github.com/go-gitea/gitea/issues/37013)) - Hide delete branch or tag buttons in mirror or archived repositories. ([#&#8203;37006](https://github.com/go-gitea/gitea/issues/37006)) - Fix org contact email not clearable once set ([#&#8203;36975](https://github.com/go-gitea/gitea/issues/36975)) - Fix a bug when forking a repository in an organization ([#&#8203;36950](https://github.com/go-gitea/gitea/issues/36950)) - Preserve sort order of exclusive labels from template repo ([#&#8203;36931](https://github.com/go-gitea/gitea/issues/36931)) - Make container registry support Apple Container (basic auth) ([#&#8203;36920](https://github.com/go-gitea/gitea/issues/36920)) - Fix the wrong push commits in the pull request when force push ([#&#8203;36914](https://github.com/go-gitea/gitea/issues/36914)) - Add class "list-header-filters" to the div for projects ([#&#8203;36889](https://github.com/go-gitea/gitea/issues/36889)) - Fix dbfs error handling ([#&#8203;36844](https://github.com/go-gitea/gitea/issues/36844)) - Fix incorrect viewed files counter if reverted change was viewed ([#&#8203;36819](https://github.com/go-gitea/gitea/issues/36819)) - Refactor avatar package, support default avatar fallback ([#&#8203;36788](https://github.com/go-gitea/gitea/issues/36788)) - Fix README symlink resolution in subdirectories like .github ([#&#8203;36775](https://github.com/go-gitea/gitea/issues/36775)) - Fix CSS stacking context issue in actions log ([#&#8203;36749](https://github.com/go-gitea/gitea/issues/36749)) - Add gpg signing for merge rebase and update by rebase ([#&#8203;36701](https://github.com/go-gitea/gitea/issues/36701)) - Delete non-exist branch should return 404 ([#&#8203;36694](https://github.com/go-gitea/gitea/issues/36694)) - Fix `TestActionsCollaborativeOwner` ([#&#8203;36657](https://github.com/go-gitea/gitea/issues/36657)) - Fix multi-arch Docker build SIGILL by splitting frontend stage ([#&#8203;36646](https://github.com/go-gitea/gitea/issues/36646)) - Fix linguist-detectable attribute being ignored for configuration files ([#&#8203;36640](https://github.com/go-gitea/gitea/issues/36640)) - Fix state desync in ComboMarkdownEditor ([#&#8203;36625](https://github.com/go-gitea/gitea/issues/36625)) - Unify DEFAULT\_SHOW\_FULL\_NAME output in templates and dropdown ([#&#8203;36597](https://github.com/go-gitea/gitea/issues/36597)) - Pull Request Pusher should be the author of the merge ([#&#8203;36581](https://github.com/go-gitea/gitea/issues/36581)) - Fix various version parsing problems ([#&#8203;36553](https://github.com/go-gitea/gitea/issues/36553)) - Fix highlight diff result ([#&#8203;36539](https://github.com/go-gitea/gitea/issues/36539)) - Fix mirror sync parser and fix mirror messages ([#&#8203;36504](https://github.com/go-gitea/gitea/issues/36504)) - Fix bug when list pull request commits ([#&#8203;36485](https://github.com/go-gitea/gitea/issues/36485)) - Fix various bugs ([#&#8203;36446](https://github.com/go-gitea/gitea/issues/36446)) - Fix issue filter menu layout ([#&#8203;36426](https://github.com/go-gitea/gitea/issues/36426)) - Restrict branch naming when new change matches with protection rules ([#&#8203;36405](https://github.com/go-gitea/gitea/issues/36405)) - Fix link/origin referrer and login redirect ([#&#8203;36279](https://github.com/go-gitea/gitea/issues/36279)) - Generate IDs for HTML headings without id attribute ([#&#8203;36233](https://github.com/go-gitea/gitea/issues/36233)) - Use a migration test instead of a wrong test which populated the meta test repositories and fix a migration bug ([#&#8203;36160](https://github.com/go-gitea/gitea/issues/36160)) - Fix issue close timeline icon ([#&#8203;36138](https://github.com/go-gitea/gitea/issues/36138)) - Fix diff blob excerpt expansion ([#&#8203;35922](https://github.com/go-gitea/gitea/issues/35922)) - Fix external render ([#&#8203;35727](https://github.com/go-gitea/gitea/issues/35727)) - Fix review request webhook bug ([#&#8203;35339](https://github.com/go-gitea/gitea/issues/35339)) ([#&#8203;35723](https://github.com/go-gitea/gitea/issues/35723)) - Fix shutdown waitgroup panic ([#&#8203;35676](https://github.com/go-gitea/gitea/issues/35676)) - Cleanup ActionRun creation ([#&#8203;35624](https://github.com/go-gitea/gitea/issues/35624)) - Fix possible bug when migrating issues/pull requests ([#&#8203;33487](https://github.com/go-gitea/gitea/issues/33487)) - Various fixes ([#&#8203;36697](https://github.com/go-gitea/gitea/issues/36697)) - Apply notify/register mail flags during install load ([#&#8203;37120](https://github.com/go-gitea/gitea/issues/37120)) - Repair duration display for bad stopped timestamps ([#&#8203;37121](https://github.com/go-gitea/gitea/issues/37121)) - Fix(upgrade.sh): use HTTPS for GPG key import and restore SELinux context after upgrade ([#&#8203;36930](https://github.com/go-gitea/gitea/issues/36930)) - Fix various trivial problems ([#&#8203;36921](https://github.com/go-gitea/gitea/issues/36921)) - Fix various trivial problems ([#&#8203;36953](https://github.com/go-gitea/gitea/issues/36953)) - Fix NuGet package upload error handling ([#&#8203;37074](https://github.com/go-gitea/gitea/issues/37074)) - Fix CodeQL code scanning alerts ([#&#8203;36858](https://github.com/go-gitea/gitea/issues/36858)) - Refactor issue sidebar and fix various problems ([#&#8203;37045](https://github.com/go-gitea/gitea/issues/37045)) - Fix various problems ([#&#8203;37029](https://github.com/go-gitea/gitea/issues/37029)) - Fix relative-time RangeError ([#&#8203;37021](https://github.com/go-gitea/gitea/issues/37021)) - Fix chroma lexer mapping ([#&#8203;36629](https://github.com/go-gitea/gitea/issues/36629)) - Fix typos and grammar in English locale ([#&#8203;36751](https://github.com/go-gitea/gitea/issues/36751)) - Fix milestone/project text overflow in issue sidebar ([#&#8203;36741](https://github.com/go-gitea/gitea/issues/36741)) - Fix `no-content` message not rendering after comment edit ([#&#8203;36733](https://github.com/go-gitea/gitea/issues/36733)) - Fix theme loading in development ([#&#8203;36605](https://github.com/go-gitea/gitea/issues/36605)) - Fix workflow run jobs API returning null steps ([#&#8203;36603](https://github.com/go-gitea/gitea/issues/36603)) - Fix timeline event layout overflow with long content ([#&#8203;36595](https://github.com/go-gitea/gitea/issues/36595)) - Fix minor UI issues in runner edit page ([#&#8203;36590](https://github.com/go-gitea/gitea/issues/36590)) - Fix incorrect vendored detections ([#&#8203;36508](https://github.com/go-gitea/gitea/issues/36508)) - Fix editorconfig not respected in PR Conversation view ([#&#8203;36492](https://github.com/go-gitea/gitea/issues/36492)) - Don't create self-references in merged PRs ([#&#8203;36490](https://github.com/go-gitea/gitea/issues/36490)) - Fix potential incorrect runID in run status update ([#&#8203;36437](https://github.com/go-gitea/gitea/issues/36437)) - Fix file-tree ui error when adding files to repo without commits ([#&#8203;36312](https://github.com/go-gitea/gitea/issues/36312)) - Improve image captcha contrast for dark mode ([#&#8203;36265](https://github.com/go-gitea/gitea/issues/36265)) - Fix panic in blame view when a file has only a single commit ([#&#8203;36230](https://github.com/go-gitea/gitea/issues/36230)) - Fix spelling error in migrate-storage cmd utility ([#&#8203;36226](https://github.com/go-gitea/gitea/issues/36226)) - Fix code highlighting on blame page ([#&#8203;36157](https://github.com/go-gitea/gitea/issues/36157)) - Fix nilnil in onedev downloader ([#&#8203;36154](https://github.com/go-gitea/gitea/issues/36154)) - Fix actions lint ([#&#8203;36029](https://github.com/go-gitea/gitea/issues/36029)) - Fix oauth2 session gob register ([#&#8203;36017](https://github.com/go-gitea/gitea/issues/36017)) - Fix Arch repo pacman.conf snippet ([#&#8203;35825](https://github.com/go-gitea/gitea/issues/35825)) - Fix a number of `strictNullChecks`-related issues ([#&#8203;35795](https://github.com/go-gitea/gitea/issues/35795)) - Fix URLJoin, markup render link reoslving, sign-in/up/linkaccount page common data ([#&#8203;36861](https://github.com/go-gitea/gitea/issues/36861)) - Hide delete directory button for mirror or archive repository and disable the menu item if user have no permission ([#&#8203;36384](https://github.com/go-gitea/gitea/issues/36384)) - Update message severity colors, fix navbar double border ([#&#8203;37019](https://github.com/go-gitea/gitea/issues/37019)) - Inline and lazy-load EasyMDE CSS, fix border colors ([#&#8203;36714](https://github.com/go-gitea/gitea/issues/36714)) - Closed milestones with no issues now show as 100% completed ([#&#8203;36220](https://github.com/go-gitea/gitea/issues/36220)) - Add test for ExtendCommentTreePathLength migration and fix bugs ([#&#8203;35791](https://github.com/go-gitea/gitea/issues/35791)) - Only turn links to current instance into hash links ([#&#8203;36237](https://github.com/go-gitea/gitea/issues/36237)) - Fix typos in code comments: doesnt, dont, wont ([#&#8203;36890](https://github.com/go-gitea/gitea/issues/36890)) - REFACTOR - Clean up and improve non-gitea js error filter ([#&#8203;37148](https://github.com/go-gitea/gitea/issues/37148)) ([#&#8203;37155](https://github.com/go-gitea/gitea/issues/37155)) - Always show owner/repo name in compare page dropdowns ([#&#8203;37172](https://github.com/go-gitea/gitea/issues/37172)) ([#&#8203;37200](https://github.com/go-gitea/gitea/issues/37200)) - Remove dead CSS rules ([#&#8203;37173](https://github.com/go-gitea/gitea/issues/37173)) ([#&#8203;37177](https://github.com/go-gitea/gitea/issues/37177)) - Replace Monaco with CodeMirror ([#&#8203;36764](https://github.com/go-gitea/gitea/issues/36764)) - Replace CSRF cookie with `CrossOriginProtection` ([#&#8203;36183](https://github.com/go-gitea/gitea/issues/36183)) - Replace index with id in actions routes ([#&#8203;36842](https://github.com/go-gitea/gitea/issues/36842)) - Remove unnecessary function parameter ([#&#8203;35765](https://github.com/go-gitea/gitea/issues/35765)) - Move jobparser from act repository to Gitea ([#&#8203;36699](https://github.com/go-gitea/gitea/issues/36699)) - Refactor compare router param parse ([#&#8203;36105](https://github.com/go-gitea/gitea/issues/36105)) - Optimize 'refreshAccesses' to perform update without removing then adding ([#&#8203;35702](https://github.com/go-gitea/gitea/issues/35702)) - Clean up checkbox cursor styles ([#&#8203;37016](https://github.com/go-gitea/gitea/issues/37016)) - Remove undocumented support of signing key in the repository git configuration file ([#&#8203;36143](https://github.com/go-gitea/gitea/issues/36143)) - Switch `cmd/` to use constructor functions. ([#&#8203;36962](https://github.com/go-gitea/gitea/issues/36962)) - Use `relative-time` to render absolute dates ([#&#8203;36238](https://github.com/go-gitea/gitea/issues/36238)) - Some refactors about GetMergeBase ([#&#8203;36186](https://github.com/go-gitea/gitea/issues/36186)) - Some small refactors ([#&#8203;36163](https://github.com/go-gitea/gitea/issues/36163)) - Use gitRepo as parameter instead of repopath when invoking sign functions ([#&#8203;36162](https://github.com/go-gitea/gitea/issues/36162)) - Move blame to gitrepo ([#&#8203;36161](https://github.com/go-gitea/gitea/issues/36161)) - Move some functions to gitrepo package to reduce RepoPath reference directly ([#&#8203;36126](https://github.com/go-gitea/gitea/issues/36126)) - Use gitrepo's clone and push when possible ([#&#8203;36093](https://github.com/go-gitea/gitea/issues/36093)) - Remove mermaid margin workaround ([#&#8203;35732](https://github.com/go-gitea/gitea/issues/35732)) - Move some functions to gitrepo package ([#&#8203;35543](https://github.com/go-gitea/gitea/issues/35543)) - Move GetDiverging functions to gitrepo ([#&#8203;35524](https://github.com/go-gitea/gitea/issues/35524)) - Use global lock instead of status pool for cron lock ([#&#8203;35507](https://github.com/go-gitea/gitea/issues/35507)) - Use explicit mux instead of DefaultServeMux ([#&#8203;36276](https://github.com/go-gitea/gitea/issues/36276)) - Use gitrepo's push function ([#&#8203;36245](https://github.com/go-gitea/gitea/issues/36245)) - Pass request context to generateAdditionalHeadersForIssue ([#&#8203;36274](https://github.com/go-gitea/gitea/issues/36274)) - Move assign project when creating pull request to the same database transaction ([#&#8203;36244](https://github.com/go-gitea/gitea/issues/36244)) - Move catfile batch to a sub package of git module ([#&#8203;36232](https://github.com/go-gitea/gitea/issues/36232)) - Use gitrepo.Repository instead of wikipath ([#&#8203;35398](https://github.com/go-gitea/gitea/issues/35398)) - Use experimental go json v2 library ([#&#8203;35392](https://github.com/go-gitea/gitea/issues/35392)) - Refactor template render ([#&#8203;36438](https://github.com/go-gitea/gitea/issues/36438)) - Refactor GetRepoRawDiffForFile to avoid unnecessary pipe or goroutine ([#&#8203;36434](https://github.com/go-gitea/gitea/issues/36434)) - Refactor text utility classes to Tailwind CSS ([#&#8203;36703](https://github.com/go-gitea/gitea/issues/36703)) - Refactor git command stdio pipe ([#&#8203;36422](https://github.com/go-gitea/gitea/issues/36422)) - Refactor git command context & pipeline ([#&#8203;36406](https://github.com/go-gitea/gitea/issues/36406)) - Refactor git command stdio pipe ([#&#8203;36393](https://github.com/go-gitea/gitea/issues/36393)) - Remove unused functions ([#&#8203;36672](https://github.com/go-gitea/gitea/issues/36672)) - Refactor Actions Token Access ([#&#8203;35688](https://github.com/go-gitea/gitea/issues/35688)) - Move commit related functions to gitrepo package ([#&#8203;35600](https://github.com/go-gitea/gitea/issues/35600)) - Move archive function to repo\_model and gitrepo ([#&#8203;35514](https://github.com/go-gitea/gitea/issues/35514)) - Move some functions to gitrepo package ([#&#8203;35503](https://github.com/go-gitea/gitea/issues/35503)) - Use git model to detect whether branch exist instead of gitrepo method ([#&#8203;35459](https://github.com/go-gitea/gitea/issues/35459)) - Some refactor for repo path ([#&#8203;36251](https://github.com/go-gitea/gitea/issues/36251)) - Extract helper functions from SearchIssues ([#&#8203;36158](https://github.com/go-gitea/gitea/issues/36158)) - Refactor merge conan and container auth preserve actions taskID ([#&#8203;36560](https://github.com/go-gitea/gitea/issues/36560)) - Refactor Nuget Auth to reuse Basic Auth Token Validation ([#&#8203;36558](https://github.com/go-gitea/gitea/issues/36558)) - Refactor ActionsTaskID ([#&#8203;36503](https://github.com/go-gitea/gitea/issues/36503)) - Refactor auth middleware ([#&#8203;36848](https://github.com/go-gitea/gitea/issues/36848)) - Refactor code render and render control chars ([#&#8203;37078](https://github.com/go-gitea/gitea/issues/37078)) - Clean up AppURL, remove legacy origin-url webcomponent ([#&#8203;37090](https://github.com/go-gitea/gitea/issues/37090)) - Remove `util.URLJoin` and replace all callers with direct path concatenation ([#&#8203;36867](https://github.com/go-gitea/gitea/issues/36867)) - Replace legacy tw-flex utility classes with flex-text-block/inline ([#&#8203;36778](https://github.com/go-gitea/gitea/issues/36778)) - Mark unused\&immature activitypub as "not implemented" ([#&#8203;36789](https://github.com/go-gitea/gitea/issues/36789)) - TESTING - Add e2e tests for server push events ([#&#8203;36879](https://github.com/go-gitea/gitea/issues/36879)) - Rework e2e tests ([#&#8203;36634](https://github.com/go-gitea/gitea/issues/36634)) - Add e2e reaction test, improve accessibility, enable parallel testing ([#&#8203;37081](https://github.com/go-gitea/gitea/issues/37081)) - Increase e2e test timeouts on CI to fix flaky tests ([#&#8203;37053](https://github.com/go-gitea/gitea/issues/37053)) - BUILD - Upgrade go-git to v5.18.0 ([#&#8203;37269](https://github.com/go-gitea/gitea/issues/37269)) - Replace rollup-plugin-license with rolldown-license-plugin ([#&#8203;37130](https://github.com/go-gitea/gitea/issues/37130)) ([#&#8203;37158](https://github.com/go-gitea/gitea/issues/37158)) - Bump min go version to 1.26.2 ([#&#8203;37139](https://github.com/go-gitea/gitea/issues/37139)) ([#&#8203;37143](https://github.com/go-gitea/gitea/issues/37143)) - Convert locale files from ini to json format ([#&#8203;35489](https://github.com/go-gitea/gitea/issues/35489)) - Bump golangci-lint to 2.7.2, enable modernize stringsbuilder ([#&#8203;36180](https://github.com/go-gitea/gitea/issues/36180)) - Port away from `flake-utils` ([#&#8203;35675](https://github.com/go-gitea/gitea/issues/35675)) - Remove nolint ([#&#8203;36252](https://github.com/go-gitea/gitea/issues/36252)) - Update the Unlicense copy to latest version ([#&#8203;36636](https://github.com/go-gitea/gitea/issues/36636)) - Update to go 1.26.0 and golangci-lint 2.9.0 ([#&#8203;36588](https://github.com/go-gitea/gitea/issues/36588)) - Replace `google/go-licenses` with custom generation ([#&#8203;36575](https://github.com/go-gitea/gitea/issues/36575)) - Update go dependencies ([#&#8203;36548](https://github.com/go-gitea/gitea/issues/36548)) - Bump appleboy/git-push-action from 1.0.0 to 1.2.0 ([#&#8203;36306](https://github.com/go-gitea/gitea/issues/36306)) - Remove fomantic form module ([#&#8203;36222](https://github.com/go-gitea/gitea/issues/36222)) - Bump setup-node to v6, re-enable cache ([#&#8203;36207](https://github.com/go-gitea/gitea/issues/36207)) - Bump crowdin/github-action from 1 to 2 ([#&#8203;36204](https://github.com/go-gitea/gitea/issues/36204)) - Revert "Bump alpine to 3.23 ([#&#8203;36185](https://github.com/go-gitea/gitea/issues/36185))" ([#&#8203;36202](https://github.com/go-gitea/gitea/issues/36202)) - Update chroma to v2.21.1 ([#&#8203;36201](https://github.com/go-gitea/gitea/issues/36201)) - Bump astral-sh/setup-uv from 6 to 7 ([#&#8203;36198](https://github.com/go-gitea/gitea/issues/36198)) - Bump docker/build-push-action from 5 to 6 ([#&#8203;36197](https://github.com/go-gitea/gitea/issues/36197)) - Bump aws-actions/configure-aws-credentials from 4 to 5 ([#&#8203;36196](https://github.com/go-gitea/gitea/issues/36196)) - Bump dev-hanz-ops/install-gh-cli-action from 0.1.0 to 0.2.1 ([#&#8203;36195](https://github.com/go-gitea/gitea/issues/36195)) - Add JSON linting ([#&#8203;36192](https://github.com/go-gitea/gitea/issues/36192)) - Enable dependabot for actions ([#&#8203;36191](https://github.com/go-gitea/gitea/issues/36191)) - Bump alpine to 3.23 ([#&#8203;36185](https://github.com/go-gitea/gitea/issues/36185)) - Update chroma to v2.21.0 ([#&#8203;36171](https://github.com/go-gitea/gitea/issues/36171)) - Update JS deps and eslint enhancements ([#&#8203;36147](https://github.com/go-gitea/gitea/issues/36147)) - Update JS deps ([#&#8203;36091](https://github.com/go-gitea/gitea/issues/36091)) - update golangci-lint to v2.7.0 ([#&#8203;36079](https://github.com/go-gitea/gitea/issues/36079)) - Update JS deps, fix deprecations ([#&#8203;36040](https://github.com/go-gitea/gitea/issues/36040)) - Update JS deps ([#&#8203;35978](https://github.com/go-gitea/gitea/issues/35978)) - Add toolchain directive to go.mod ([#&#8203;35901](https://github.com/go-gitea/gitea/issues/35901)) - Move `gitea-vet` to use `go tool` ([#&#8203;35878](https://github.com/go-gitea/gitea/issues/35878)) - Update to go 1.25.4 ([#&#8203;35877](https://github.com/go-gitea/gitea/issues/35877)) - Enable TypeScript `strictNullChecks` ([#&#8203;35843](https://github.com/go-gitea/gitea/issues/35843)) - Enable `vue/require-typed-ref` eslint rule ([#&#8203;35764](https://github.com/go-gitea/gitea/issues/35764)) - Update JS dependencies ([#&#8203;35759](https://github.com/go-gitea/gitea/issues/35759)) - Move `codeformat` folder to tools ([#&#8203;35758](https://github.com/go-gitea/gitea/issues/35758)) - Update dependencies ([#&#8203;35733](https://github.com/go-gitea/gitea/issues/35733)) - Bump happy-dom from 20.0.0 to 20.0.2 ([#&#8203;35677](https://github.com/go-gitea/gitea/issues/35677)) - Bump setup-go to v6 ([#&#8203;35660](https://github.com/go-gitea/gitea/issues/35660)) - Update JS deps, misc tweaks ([#&#8203;35643](https://github.com/go-gitea/gitea/issues/35643)) - Bump happy-dom from 19.0.2 to 20.0.0 ([#&#8203;35625](https://github.com/go-gitea/gitea/issues/35625)) - Use bundled version of spectral ([#&#8203;35573](https://github.com/go-gitea/gitea/issues/35573)) - Update JS and PY deps ([#&#8203;35565](https://github.com/go-gitea/gitea/issues/35565)) - Bump github.com/wneessen/go-mail from 0.6.2 to 0.7.1 ([#&#8203;35557](https://github.com/go-gitea/gitea/issues/35557)) - Migrate from webpack to vite ([#&#8203;37002](https://github.com/go-gitea/gitea/issues/37002)) - Update JS dependencies and misc tweaks ([#&#8203;37064](https://github.com/go-gitea/gitea/issues/37064)) - Update to eslint 10 ([#&#8203;36925](https://github.com/go-gitea/gitea/issues/36925)) - Optimize Docker build with dependency layer caching ([#&#8203;36864](https://github.com/go-gitea/gitea/issues/36864)) - Update JS deps ([#&#8203;36850](https://github.com/go-gitea/gitea/issues/36850)) - Update tool dependencies and fix new lint issues ([#&#8203;36702](https://github.com/go-gitea/gitea/issues/36702)) - Remove redundant linter rules ([#&#8203;36658](https://github.com/go-gitea/gitea/issues/36658)) - Move Fomantic dropdown CSS to custom module ([#&#8203;36530](https://github.com/go-gitea/gitea/issues/36530)) - Remove and forbid `@ts-expect-error` ([#&#8203;36513](https://github.com/go-gitea/gitea/issues/36513)) - Refactor git command stderr handling ([#&#8203;36402](https://github.com/go-gitea/gitea/issues/36402)) - Enable gocheckcompilerdirectives linter ([#&#8203;36156](https://github.com/go-gitea/gitea/issues/36156)) - Replace `lint-go-gopls` with additional `govet` linters ([#&#8203;36028](https://github.com/go-gitea/gitea/issues/36028)) - Update golangci-lint to v2.6.0 ([#&#8203;35801](https://github.com/go-gitea/gitea/issues/35801)) - Misc tool tweaks ([#&#8203;35734](https://github.com/go-gitea/gitea/issues/35734)) - Add cache to container build ([#&#8203;35697](https://github.com/go-gitea/gitea/issues/35697)) - Upgrade vite ([#&#8203;37126](https://github.com/go-gitea/gitea/issues/37126)) - Update `setup-uv` to v8.0.0 ([#&#8203;37101](https://github.com/go-gitea/gitea/issues/37101)) - Upgrade `go-git` to v5.17.2 and related dependencies ([#&#8203;37060](https://github.com/go-gitea/gitea/issues/37060)) - Raise minimum Node.js version to 22.18.0 ([#&#8203;37058](https://github.com/go-gitea/gitea/issues/37058)) - Upgrade `golang.org/x/image` to v0.38.0 ([#&#8203;37054](https://github.com/go-gitea/gitea/issues/37054)) - Update minimum go version to 1.26.1, golangci-lint to 2.11.2, fix test style ([#&#8203;36876](https://github.com/go-gitea/gitea/issues/36876)) - Enable eslint concurrency ([#&#8203;36878](https://github.com/go-gitea/gitea/issues/36878)) - Vendor relative-time-element as local web component ([#&#8203;36853](https://github.com/go-gitea/gitea/issues/36853)) - Update material-icon-theme v5.32.0 ([#&#8203;36832](https://github.com/go-gitea/gitea/issues/36832)) - Update Go dependencies ([#&#8203;36781](https://github.com/go-gitea/gitea/issues/36781)) - Upgrade minimatch ([#&#8203;36760](https://github.com/go-gitea/gitea/issues/36760)) - Remove i18n backport tool at the moment because of translation format changed ([#&#8203;36643](https://github.com/go-gitea/gitea/issues/36643)) - Update emoji data for Unicode 16 ([#&#8203;36596](https://github.com/go-gitea/gitea/issues/36596)) - Update JS dependencies, adjust webpack config, misc fixes ([#&#8203;36431](https://github.com/go-gitea/gitea/issues/36431)) - Update material-icon-theme to v5.31.0 ([#&#8203;36427](https://github.com/go-gitea/gitea/issues/36427)) - Update JS and PY deps ([#&#8203;36383](https://github.com/go-gitea/gitea/issues/36383)) - Bump alpine to 3.23, add platforms to `docker-dryrun` ([#&#8203;36379](https://github.com/go-gitea/gitea/issues/36379)) - Update JS deps ([#&#8203;36354](https://github.com/go-gitea/gitea/issues/36354)) - Update goldmark to v1.7.16 ([#&#8203;36343](https://github.com/go-gitea/gitea/issues/36343)) - Update chroma to v2.22.0 ([#&#8203;36342](https://github.com/go-gitea/gitea/issues/36342)) - DOCS - Update AI Contribution Policy ([#&#8203;37022](https://github.com/go-gitea/gitea/issues/37022)) - Update AGENTS.md with additional guidelines ([#&#8203;37018](https://github.com/go-gitea/gitea/issues/37018)) - Add missing cron tasks to example ini ([#&#8203;37012](https://github.com/go-gitea/gitea/issues/37012)) - Add AI Contribution Policy to CONTRIBUTING.md ([#&#8203;36651](https://github.com/go-gitea/gitea/issues/36651)) - Minor punctuation improvement in CONTRIBUTING.md ([#&#8203;36291](https://github.com/go-gitea/gitea/issues/36291)) - Add documentation for markdown anchor post-processing ([#&#8203;36443](https://github.com/go-gitea/gitea/issues/36443)) - MISC - Correct spelling ([#&#8203;36783](https://github.com/go-gitea/gitea/issues/36783)) - Update Nix flake ([#&#8203;37110](https://github.com/go-gitea/gitea/issues/37110)) - Update Nix flake ([#&#8203;37024](https://github.com/go-gitea/gitea/issues/37024)) - Add valid github scopes ([#&#8203;36977](https://github.com/go-gitea/gitea/issues/36977)) - Update Nix flake ([#&#8203;36943](https://github.com/go-gitea/gitea/issues/36943)) - Update Nix flake ([#&#8203;36902](https://github.com/go-gitea/gitea/issues/36902)) - Update Nix flake ([#&#8203;36857](https://github.com/go-gitea/gitea/issues/36857)) - Update Nix flake ([#&#8203;36787](https://github.com/go-gitea/gitea/issues/36787)) ### [`v1.25.5`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#1255---2026-03-10) [Compare Source](https://github.com/go-gitea/gitea/compare/v1.25.4...v1.25.5) - SECURITY - Toolchain Update to Go 1.25.6 ([#&#8203;36480](https://github.com/go-gitea/gitea/issues/36480)) ([#&#8203;36487](https://github.com/go-gitea/gitea/issues/36487)) - Adjust the toolchain version ([#&#8203;36537](https://github.com/go-gitea/gitea/issues/36537)) ([#&#8203;36542](https://github.com/go-gitea/gitea/issues/36542)) - Update toolchain to 1.25.8 for v1.25 ([#&#8203;36888](https://github.com/go-gitea/gitea/issues/36888)) - Prevent redirect bypasses via backslash-encoded paths ([#&#8203;36660](https://github.com/go-gitea/gitea/issues/36660)) ([#&#8203;36716](https://github.com/go-gitea/gitea/issues/36716)) - Fix get release draft permission check ([#&#8203;36659](https://github.com/go-gitea/gitea/issues/36659)) ([#&#8203;36715](https://github.com/go-gitea/gitea/issues/36715)) - Fix a bug user could change another user's primary email ([#&#8203;36586](https://github.com/go-gitea/gitea/issues/36586)) ([#&#8203;36607](https://github.com/go-gitea/gitea/issues/36607)) - Fix OAuth2 authorization code expiry and reuse handling ([#&#8203;36797](https://github.com/go-gitea/gitea/issues/36797)) ([#&#8203;36851](https://github.com/go-gitea/gitea/issues/36851)) - Add validation constraints for repository creation fields ([#&#8203;36671](https://github.com/go-gitea/gitea/issues/36671)) ([#&#8203;36757](https://github.com/go-gitea/gitea/issues/36757)) - Fix bug to check whether user can update pull request branch or rebase branch ([#&#8203;36465](https://github.com/go-gitea/gitea/issues/36465)) ([#&#8203;36838](https://github.com/go-gitea/gitea/issues/36838)) - Add migration http transport for push/sync mirror lfs ([#&#8203;36665](https://github.com/go-gitea/gitea/issues/36665)) ([#&#8203;36691](https://github.com/go-gitea/gitea/issues/36691)) - Fix track time list permission check ([#&#8203;36662](https://github.com/go-gitea/gitea/issues/36662)) ([#&#8203;36744](https://github.com/go-gitea/gitea/issues/36744)) - Fix track time issue id ([#&#8203;36664](https://github.com/go-gitea/gitea/issues/36664)) ([#&#8203;36689](https://github.com/go-gitea/gitea/issues/36689)) - Fix path resolving ([#&#8203;36734](https://github.com/go-gitea/gitea/issues/36734)) ([#&#8203;36746](https://github.com/go-gitea/gitea/issues/36746)) - Fix dump release asset bug ([#&#8203;36799](https://github.com/go-gitea/gitea/issues/36799)) ([#&#8203;36839](https://github.com/go-gitea/gitea/issues/36839)) - Fix org permission API visibility checks for hidden members and private orgs ([#&#8203;36798](https://github.com/go-gitea/gitea/issues/36798)) ([#&#8203;36841](https://github.com/go-gitea/gitea/issues/36841)) - Fix forwarded proto handling for public URL detection ([#&#8203;36810](https://github.com/go-gitea/gitea/issues/36810)) ([#&#8203;36836](https://github.com/go-gitea/gitea/issues/36836)) - Add a git grep search timeout ([#&#8203;36809](https://github.com/go-gitea/gitea/issues/36809)) ([#&#8203;36835](https://github.com/go-gitea/gitea/issues/36835)) - Fix oauth2 s256 ([#&#8203;36462](https://github.com/go-gitea/gitea/issues/36462)) ([#&#8203;36477](https://github.com/go-gitea/gitea/issues/36477)) - ENHANCEMENTS - Make `security-check` informational only ([#&#8203;36681](https://github.com/go-gitea/gitea/issues/36681)) ([#&#8203;36852](https://github.com/go-gitea/gitea/issues/36852)) - Upgrade to github.com/cloudflare/circl 1.6.3, svgo 4.0.1, markdownlint-cli 0.48.0 ([#&#8203;36840](https://github.com/go-gitea/gitea/issues/36840)) - Add some validation on values provided to USER\_DISABLED\_FEATURES and EXTERNAL\_USER\_DISABLED\_FEATURES ([#&#8203;36688](https://github.com/go-gitea/gitea/issues/36688)) ([#&#8203;36692](https://github.com/go-gitea/gitea/issues/36692)) - Upgrade gogit to 5.16.5 ([#&#8203;36687](https://github.com/go-gitea/gitea/issues/36687)) - Add wrap to runner label list ([#&#8203;36565](https://github.com/go-gitea/gitea/issues/36565)) ([#&#8203;36574](https://github.com/go-gitea/gitea/issues/36574)) - Add dnf5 command for Fedora in RPM package instructions ([#&#8203;36527](https://github.com/go-gitea/gitea/issues/36527)) ([#&#8203;36572](https://github.com/go-gitea/gitea/issues/36572)) - Allow scroll propagation outside code editor ([#&#8203;36502](https://github.com/go-gitea/gitea/issues/36502)) ([#&#8203;36510](https://github.com/go-gitea/gitea/issues/36510)) - BUGFIXES - Fix non-admins unable to automerge PRs from forks ([#&#8203;36833](https://github.com/go-gitea/gitea/issues/36833)) ([#&#8203;36843](https://github.com/go-gitea/gitea/issues/36843)) - Fix bug when pushing mirror with wiki ([#&#8203;36795](https://github.com/go-gitea/gitea/issues/36795)) ([#&#8203;36807](https://github.com/go-gitea/gitea/issues/36807)) - Fix artifacts v4 backend upload problems ([#&#8203;36805](https://github.com/go-gitea/gitea/issues/36805)) ([#&#8203;36834](https://github.com/go-gitea/gitea/issues/36834)) - Fix CRAN package version validation to allow more than 4 version components ([#&#8203;36813](https://github.com/go-gitea/gitea/issues/36813)) ([#&#8203;36821](https://github.com/go-gitea/gitea/issues/36821)) - Fix force push time-line commit comments of pull request ([#&#8203;36653](https://github.com/go-gitea/gitea/issues/36653)) ([#&#8203;36717](https://github.com/go-gitea/gitea/issues/36717)) - Fix SVG height calculation in diff viewer ([#&#8203;36748](https://github.com/go-gitea/gitea/issues/36748)) ([#&#8203;36750](https://github.com/go-gitea/gitea/issues/36750)) - Fix push time bug ([#&#8203;36693](https://github.com/go-gitea/gitea/issues/36693)) ([#&#8203;36713](https://github.com/go-gitea/gitea/issues/36713)) - Fix bug the protected branch rule name is conflicted with renamed branch name ([#&#8203;36650](https://github.com/go-gitea/gitea/issues/36650)) ([#&#8203;36661](https://github.com/go-gitea/gitea/issues/36661)) - Fix bug when do LFS GC ([#&#8203;36500](https://github.com/go-gitea/gitea/issues/36500)) ([#&#8203;36608](https://github.com/go-gitea/gitea/issues/36608)) - Fix focus lost bugs in the Monaco editor ([#&#8203;36609](https://github.com/go-gitea/gitea/issues/36609)) - Reprocess htmx content after loading more files ([#&#8203;36568](https://github.com/go-gitea/gitea/issues/36568)) ([#&#8203;36577](https://github.com/go-gitea/gitea/issues/36577)) - Fix assignee sidebar links and empty placeholder ([#&#8203;36559](https://github.com/go-gitea/gitea/issues/36559)) ([#&#8203;36563](https://github.com/go-gitea/gitea/issues/36563)) - Fix issues filter dropdown showing empty label scope section ([#&#8203;36535](https://github.com/go-gitea/gitea/issues/36535)) ([#&#8203;36544](https://github.com/go-gitea/gitea/issues/36544)) - Fix various mermaid bugs ([#&#8203;36547](https://github.com/go-gitea/gitea/issues/36547)) ([#&#8203;36552](https://github.com/go-gitea/gitea/issues/36552)) - Fix data race when uploading container blobs concurrently ([#&#8203;36524](https://github.com/go-gitea/gitea/issues/36524)) ([#&#8203;36526](https://github.com/go-gitea/gitea/issues/36526)) - Correct spacing between username and bot label ([#&#8203;36473](https://github.com/go-gitea/gitea/issues/36473)) ([#&#8203;36484](https://github.com/go-gitea/gitea/issues/36484)) </details> <details> <summary>grafana/helm-charts (grafana)</summary> ### [`v8.15.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.15.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.14.2...grafana-8.15.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Allow users to override curl short options by [@&#8203;blag](https://github.com/blag) in [#&#8203;3625](https://github.com/grafana/helm-charts/pull/3625) #### New Contributors - [@&#8203;blag](https://github.com/blag) made their first contribution in [#&#8203;3625](https://github.com/grafana/helm-charts/pull/3625) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/mimir-distributed-5.8.0-weekly.339+dev.1...grafana-8.15.0> ### [`v8.14.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.14.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.14.1...grafana-8.14.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Revert initChownData readOnlyRootFilesystem - [`6cd0753`](https://github.com/grafana/helm-charts/commit/6cd0753) by [@&#8203;jcpunk](https://github.com/jcpunk) in [#&#8203;3691](https://github.com/grafana/helm-charts/pull/3691) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/loki-distributed-0.80.5...grafana-8.14.2> ### [`v8.14.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.14.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.14.0...grafana-8.14.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Explicitly drop all unused capabilities for init-chown-data and set readonlyRootFilesystem by [@&#8203;jcpunk](https://github.com/jcpunk) in [#&#8203;3684](https://github.com/grafana/helm-charts/pull/3684) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.38.3...grafana-8.14.1> ### [`v8.14.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.14.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.13.2...grafana-8.14.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Add volumeName field to statefulset template by [@&#8203;hyukjuns](https://github.com/hyukjuns) in [#&#8203;3675](https://github.com/grafana/helm-charts/pull/3675) #### New Contributors - [@&#8203;hyukjuns](https://github.com/hyukjuns) made their first contribution in [#&#8203;3675](https://github.com/grafana/helm-charts/pull/3675) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.13.2...grafana-8.14.0> ### [`v8.13.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.13.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.13.1...grafana-8.13.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - Github actions: harden workflows by [@&#8203;alexweav](https://github.com/alexweav) in [#&#8203;3674](https://github.com/grafana/helm-charts/pull/3674) - \[grafana] Add support for custom script and extra mounts in Grafana sidecar by [@&#8203;refucktor](https://github.com/refucktor) in [#&#8203;3669](https://github.com/grafana/helm-charts/pull/3669) #### New Contributors - [@&#8203;alexweav](https://github.com/alexweav) made their first contribution in [#&#8203;3674](https://github.com/grafana/helm-charts/pull/3674) - [@&#8203;refucktor](https://github.com/refucktor) made their first contribution in [#&#8203;3669](https://github.com/grafana/helm-charts/pull/3669) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.5-beta.1...grafana-8.13.2> ### [`v8.13.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.13.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.13.0...grafana-8.13.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana to 11.6.1 by [@&#8203;mhoyer](https://github.com/mhoyer) in [#&#8203;3667](https://github.com/grafana/helm-charts/pull/3667) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.4-beta.1...grafana-8.13.1> ### [`v8.13.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.13.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.12.1...grafana-8.13.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana to 11.6.0-security-01 by [@&#8203;fredlahde](https://github.com/fredlahde) in [#&#8203;3663](https://github.com/grafana/helm-charts/pull/3663) #### New Contributors - [@&#8203;fredlahde](https://github.com/fredlahde) made their first contribution in [#&#8203;3663](https://github.com/grafana/helm-charts/pull/3663) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-1.0.2...grafana-8.13.0> ### [`v8.12.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.12.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.12.0...grafana-8.12.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Image Pull Secrets for the Image Renderer deployment not set in values.yaml by [@&#8203;RaphSku](https://github.com/RaphSku) in [#&#8203;3653](https://github.com/grafana/helm-charts/pull/3653) #### New Contributors - [@&#8203;RaphSku](https://github.com/RaphSku) made their first contribution in [#&#8203;3653](https://github.com/grafana/helm-charts/pull/3653) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/loki-distributed-0.80.3...grafana-8.12.1> ### [`v8.12.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.12.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.11.4...grafana-8.12.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] feat: add possibility to set env var RESOURCE\_NAME using grafana-helm chart values by [@&#8203;CarstenSon](https://github.com/CarstenSon) in [#&#8203;3649](https://github.com/grafana/helm-charts/pull/3649) #### New Contributors - [@&#8203;CarstenSon](https://github.com/CarstenSon) made their first contribution in [#&#8203;3649](https://github.com/grafana/helm-charts/pull/3649) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/cloudcost-exporter-1.0.1...grafana-8.12.0> ### [`v8.11.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.11.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.11.3...grafana-8.11.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Add initContainers only if .Values.persistence.enabled and .Values.initChownData.enabled are true by [@&#8203;baurmatt](https://github.com/baurmatt) in [#&#8203;3590](https://github.com/grafana/helm-charts/pull/3590) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.35.0...grafana-8.11.4> ### [`v8.11.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.11.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.11.2...grafana-8.11.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] fix extra spaces in extra objects to fix templating by [@&#8203;QuentinBisson](https://github.com/QuentinBisson) in [#&#8203;3635](https://github.com/grafana/helm-charts/pull/3635) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.11.2...grafana-8.11.3> ### [`v8.11.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.11.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.11.1...grafana-8.11.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Document limitation of alert's rule\_version\_record\_limit to avoid DB saturation by [@&#8203;benoittgt](https://github.com/benoittgt) in [#&#8203;3629](https://github.com/grafana/helm-charts/pull/3629) #### New Contributors - [@&#8203;benoittgt](https://github.com/benoittgt) made their first contribution in [#&#8203;3629](https://github.com/grafana/helm-charts/pull/3629) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/rollout-operator-0.25.0...grafana-8.11.2> ### [`v8.11.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.11.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.11.0...grafana-8.11.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Process sidecar configmap/secret label and labelValue with tpl by [@&#8203;a-abella](https://github.com/a-abella) in [#&#8203;3585](https://github.com/grafana/helm-charts/pull/3585) #### New Contributors - [@&#8203;a-abella](https://github.com/a-abella) made their first contribution in [#&#8203;3585](https://github.com/grafana/helm-charts/pull/3585) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-sampling-1.1.5...grafana-8.11.1> ### [`v8.11.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.11.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.10.4...grafana-8.11.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana version to 11.6.0 by [@&#8203;tobiasamft](https://github.com/tobiasamft) in [#&#8203;3621](https://github.com/grafana/helm-charts/pull/3621) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.1-beta.1...grafana-8.11.0> ### [`v8.10.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.10.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.10.3...grafana-8.10.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] adds extraObjects as strings support by [@&#8203;marshallford](https://github.com/marshallford) in [#&#8203;3602](https://github.com/grafana/helm-charts/pull/3602) #### New Contributors - [@&#8203;marshallford](https://github.com/marshallford) made their first contribution in [#&#8203;3602](https://github.com/grafana/helm-charts/pull/3602) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.6.29...grafana-8.10.4> ### [`v8.10.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.10.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.10.2...grafana-8.10.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Make containerSecurityContext of testFramework configurable by [@&#8203;baurmatt](https://github.com/baurmatt) in [#&#8203;3591](https://github.com/grafana/helm-charts/pull/3591) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.10.2...grafana-8.10.3> ### [`v8.10.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.10.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.10.1...grafana-8.10.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Fix HPA scaleTargetRef condition logic by [@&#8203;Ryan-Brice](https://github.com/Ryan-Brice) in [#&#8203;3587](https://github.com/grafana/helm-charts/pull/3587) #### New Contributors - [@&#8203;Ryan-Brice](https://github.com/Ryan-Brice) made their first contribution in [#&#8203;3587](https://github.com/grafana/helm-charts/pull/3587) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.32.3...grafana-8.10.2> ### [`v8.10.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.10.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.10.0...grafana-8.10.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update to version 11.5.2 by [@&#8203;terop](https://github.com/terop) in [#&#8203;3575](https://github.com/grafana/helm-charts/pull/3575) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/k8s-monitoring-2.0.12...grafana-8.10.1> ### [`v8.10.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.10.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.9.1...grafana-8.10.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] feat: add shareProcessNamespace option to restart Grafana on LDAP config changes by [@&#8203;jiayuchen888](https://github.com/jiayuchen888) in [#&#8203;3569](https://github.com/grafana/helm-charts/pull/3569) #### New Contributors - [@&#8203;jiayuchen888](https://github.com/jiayuchen888) made their first contribution in [#&#8203;3569](https://github.com/grafana/helm-charts/pull/3569) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.9.1...grafana-8.10.0> ### [`v8.9.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.9.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.9.0...grafana-8.9.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] chore: bump k8s-sidecar to 1.30.0 by [@&#8203;tberreis](https://github.com/tberreis) in [#&#8203;3565](https://github.com/grafana/helm-charts/pull/3565) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.26.0...grafana-8.9.1> ### [`v8.9.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.9.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.6...grafana-8.9.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update to version 11.5.1 by [@&#8203;terop](https://github.com/terop) in [#&#8203;3554](https://github.com/grafana/helm-charts/pull/3554) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.8.6...grafana-8.9.0> ### [`v8.8.6`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.6) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.5...grafana-8.8.6) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update to version 11.4.1 by [@&#8203;mhoyer](https://github.com/mhoyer) in [#&#8203;3553](https://github.com/grafana/helm-charts/pull/3553) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-agent-operator-0.5.1...grafana-8.8.6> ### [`v8.8.5`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.5) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.4...grafana-8.8.5) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update downloadDashboards image to latest curl release by [@&#8203;marcofranssen](https://github.com/marcofranssen) in [#&#8203;3534](https://github.com/grafana/helm-charts/pull/3534) #### New Contributors - [@&#8203;marcofranssen](https://github.com/marcofranssen) made their first contribution in [#&#8203;3534](https://github.com/grafana/helm-charts/pull/3534) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/mimir-distributed-5.7.0-weekly.325...grafana-8.8.5> ### [`v8.8.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.3...grafana-8.8.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Fix session affinity bug by [@&#8203;Aza1250](https://github.com/Aza1250) in [#&#8203;3529](https://github.com/grafana/helm-charts/pull/3529) #### New Contributors - [@&#8203;Aza1250](https://github.com/Aza1250) made their first contribution in [#&#8203;3529](https://github.com/grafana/helm-charts/pull/3529) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.24.1...grafana-8.8.4> ### [`v8.8.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.2...grafana-8.8.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] add session affinity config by [@&#8203;KyriosGN0](https://github.com/KyriosGN0) in [#&#8203;3524](https://github.com/grafana/helm-charts/pull/3524) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/beyla-1.6.2...grafana-8.8.3> ### [`v8.8.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.1...grafana-8.8.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Expose basicAuth property for ServiceMonitor by [@&#8203;jkroepke](https://github.com/jkroepke) in [#&#8203;3432](https://github.com/grafana/helm-charts/pull/3432) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-1.16.0...grafana-8.8.2> ### [`v8.8.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.8.0...grafana-8.8.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Fix "Error: Failed to launch the browser process!\nchrome\_crashpad\_handler: --database is required" with "image-renderer" by [@&#8203;muffl0n](https://github.com/muffl0n) in [#&#8203;3487](https://github.com/grafana/helm-charts/pull/3487) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.8.0...grafana-8.8.1> ### [`v8.8.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.8.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.7.1...grafana-8.8.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] feat(grafana): Introduce profiling container port by [@&#8203;simonswine](https://github.com/simonswine) in [#&#8203;3472](https://github.com/grafana/helm-charts/pull/3472) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.7.1...grafana-8.8.0> ### [`v8.7.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.7.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.7.0...grafana-8.7.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] fix: don't automount default serviceAccount by [@&#8203;cwrau](https://github.com/cwrau) in [#&#8203;3302](https://github.com/grafana/helm-charts/pull/3302) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.26.1...grafana-8.7.1> ### [`v8.7.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.7.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.6.4...grafana-8.7.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update to version 11.4.0 by [@&#8203;terop](https://github.com/terop) in [#&#8203;3475](https://github.com/grafana/helm-charts/pull/3475) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.26.0...grafana-8.7.0> ### [`v8.6.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.6.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.6.3...grafana-8.6.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Add configuration options for the number of retries done by the sidecar by [@&#8203;cbos](https://github.com/cbos) in [#&#8203;3454](https://github.com/grafana/helm-charts/pull/3454) #### New Contributors - [@&#8203;cbos](https://github.com/cbos) made their first contribution in [#&#8203;3454](https://github.com/grafana/helm-charts/pull/3454) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.22.0...grafana-8.6.4> ### [`v8.6.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.6.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.6.2...grafana-8.6.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] values.yaml: update alerting examples and ref by [@&#8203;michaelruigrok](https://github.com/michaelruigrok) in [#&#8203;3450](https://github.com/grafana/helm-charts/pull/3450) #### New Contributors - [@&#8203;michaelruigrok](https://github.com/michaelruigrok) made their first contribution in [#&#8203;3450](https://github.com/grafana/helm-charts/pull/3450) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/beyla-1.5.0...grafana-8.6.3> ### [`v8.6.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.6.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.6.1...grafana-8.6.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Updated pod labels to include all labels by [@&#8203;jimmybchopps](https://github.com/jimmybchopps) in [#&#8203;3423](https://github.com/grafana/helm-charts/pull/3423) #### New Contributors - [@&#8203;jimmybchopps](https://github.com/jimmybchopps) made their first contribution in [#&#8203;3423](https://github.com/grafana/helm-charts/pull/3423) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/mimir-distributed-5.6.0-weekly.318...grafana-8.6.2> ### [`v8.6.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.6.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.6.0...grafana-8.6.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana version to 11.3.1 by [@&#8203;tobiasamft](https://github.com/tobiasamft) in [#&#8203;3435](https://github.com/grafana/helm-charts/pull/3435) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/oncall-1.13.3...grafana-8.6.1> ### [`v8.6.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.6.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.12...grafana-8.6.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Implement Gateway API by [@&#8203;jkroepke](https://github.com/jkroepke) in [#&#8203;3400](https://github.com/grafana/helm-charts/pull/3400) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-vulture-0.7.0...grafana-8.6.0> ### [`v8.5.12`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.12) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.11...grafana-8.5.12) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] `managed-by` should not be templated by [@&#8203;bleggett](https://github.com/bleggett) in [#&#8203;3398](https://github.com/grafana/helm-charts/pull/3398) #### New Contributors - [@&#8203;bleggett](https://github.com/bleggett) made their first contribution in [#&#8203;3398](https://github.com/grafana/helm-charts/pull/3398) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/beyla-1.4.5...grafana-8.5.12> ### [`v8.5.11`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.11) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.10...grafana-8.5.11) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Make the Helm hook type for the testFramework configurable by [@&#8203;baileymjensen](https://github.com/baileymjensen) in [#&#8203;3388](https://github.com/grafana/helm-charts/pull/3388) #### New Contributors - [@&#8203;baileymjensen](https://github.com/baileymjensen) made their first contribution in [#&#8203;3388](https://github.com/grafana/helm-charts/pull/3388) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.5.10...grafana-8.5.11> ### [`v8.5.10`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.10) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.9...grafana-8.5.10) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] FIX: yaml indentation in README.md by [@&#8203;b-o-g-d-a-n](https://github.com/b-o-g-d-a-n) in [#&#8203;3382](https://github.com/grafana/helm-charts/pull/3382) #### New Contributors - [@&#8203;b-o-g-d-a-n](https://github.com/b-o-g-d-a-n) made their first contribution in [#&#8203;3382](https://github.com/grafana/helm-charts/pull/3382) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/beyla-1.4.4...grafana-8.5.10> ### [`v8.5.9`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.9) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.8...grafana-8.5.9) The leading tool for querying and visualizing time series and metrics. #### What's Changed - Add missing permissions in update-helm-repo workflow by [@&#8203;narqo](https://github.com/narqo) in [#&#8203;3383](https://github.com/grafana/helm-charts/pull/3383) - \[grafana] Bump Grafana appVersion to v11.3.0 by [@&#8203;anders-elastisys](https://github.com/anders-elastisys) in [#&#8203;3386](https://github.com/grafana/helm-charts/pull/3386) #### New Contributors - [@&#8203;anders-elastisys](https://github.com/anders-elastisys) made their first contribution in [#&#8203;3386](https://github.com/grafana/helm-charts/pull/3386) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.6.1...grafana-8.5.9> ### [`v8.5.8`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.8) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.7...grafana-8.5.8) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] add extraMounts to plugins sidecar by [@&#8203;coutug](https://github.com/coutug) in [#&#8203;3355](https://github.com/grafana/helm-charts/pull/3355) #### New Contributors - [@&#8203;coutug](https://github.com/coutug) made their first contribution in [#&#8203;3355](https://github.com/grafana/helm-charts/pull/3355) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.5.7...grafana-8.5.8> ### [`v8.5.7`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.7) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.6...grafana-8.5.7) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] use release with security fix for CVE-2024-9264 by [@&#8203;kubicgruenfeld](https://github.com/kubicgruenfeld) in [#&#8203;3369](https://github.com/grafana/helm-charts/pull/3369) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-0.9.2...grafana-8.5.7> ### [`v8.5.6`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.6) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.5...grafana-8.5.6) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] correct array formatting for grafana.ini by [@&#8203;nathwill](https://github.com/nathwill) in [#&#8203;3352](https://github.com/grafana/helm-charts/pull/3352) #### New Contributors - [@&#8203;nathwill](https://github.com/nathwill) made their first contribution in [#&#8203;3352](https://github.com/grafana/helm-charts/pull/3352) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.18.0...grafana-8.5.6> ### [`v8.5.5`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.5) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.4...grafana-8.5.5) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Replicas could be 0 [#&#8203;3337](https://github.com/grafana/helm-charts/issues/3337) by [@&#8203;ramon951](https://github.com/ramon951) in [#&#8203;3343](https://github.com/grafana/helm-charts/pull/3343) #### New Contributors - [@&#8203;ramon951](https://github.com/ramon951) made their first contribution in [#&#8203;3343](https://github.com/grafana/helm-charts/pull/3343) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.18.4...grafana-8.5.5> ### [`v8.5.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.3...grafana-8.5.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] chore: bump k8s-sidecar to 1.28.0 by [@&#8203;mlflr](https://github.com/mlflr) in [#&#8203;3348](https://github.com/grafana/helm-charts/pull/3348) #### New Contributors - [@&#8203;mlflr](https://github.com/mlflr) made their first contribution in [#&#8203;3348](https://github.com/grafana/helm-charts/pull/3348) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/mimir-distributed-5.5.0...grafana-8.5.4> ### [`v8.5.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.2...grafana-8.5.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana to version 11.2.2 by [@&#8203;terop](https://github.com/terop) in [#&#8203;3356](https://github.com/grafana/helm-charts/pull/3356) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-0.9.1...grafana-8.5.3> ### [`v8.5.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.1...grafana-8.5.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana to version 11.2.1 by [@&#8203;terop](https://github.com/terop) in [#&#8203;3335](https://github.com/grafana/helm-charts/pull/3335) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-0.9.0...grafana-8.5.2> ### [`v8.5.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.5.0...grafana-8.5.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update to 11.2.0 by [@&#8203;LarsStegman](https://github.com/LarsStegman) in [#&#8203;3299](https://github.com/grafana/helm-charts/pull/3299) #### New Contributors - [@&#8203;LarsStegman](https://github.com/LarsStegman) made their first contribution in [#&#8203;3299](https://github.com/grafana/helm-charts/pull/3299) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.11.0...grafana-8.5.1> ### [`v8.5.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.5.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.9...grafana-8.5.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Support for overriding the server and call back urls by [@&#8203;dig-whois](https://github.com/dig-whois) in [#&#8203;3292](https://github.com/grafana/helm-charts/pull/3292) #### New Contributors - [@&#8203;dig-whois](https://github.com/dig-whois) made their first contribution in [#&#8203;3292](https://github.com/grafana/helm-charts/pull/3292) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.4.9...grafana-8.5.0> ### [`v8.4.9`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.9) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.8...grafana-8.4.9) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana version to 11.1.5 by [@&#8203;tobiasamft](https://github.com/tobiasamft) in [#&#8203;3293](https://github.com/grafana/helm-charts/pull/3293) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.10.1...grafana-8.4.9> ### [`v8.4.8`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.8) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.7...grafana-8.4.8) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] fixed url link for persistent volume claim in values.yaml by [@&#8203;usmangt](https://github.com/usmangt) in [#&#8203;2881](https://github.com/grafana/helm-charts/pull/2881) #### New Contributors - [@&#8203;usmangt](https://github.com/usmangt) made their first contribution in [#&#8203;2881](https://github.com/grafana/helm-charts/pull/2881) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-0.6.1...grafana-8.4.8> ### [`v8.4.7`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.7) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.6...grafana-8.4.7) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update README.md by [@&#8203;NWilkieTechno](https://github.com/NWilkieTechno) in [#&#8203;3285](https://github.com/grafana/helm-charts/pull/3285) #### New Contributors - [@&#8203;NWilkieTechno](https://github.com/NWilkieTechno) made their first contribution in [#&#8203;3285](https://github.com/grafana/helm-charts/pull/3285) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.4.6...grafana-8.4.7> ### [`v8.4.6`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.6) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.5...grafana-8.4.6) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Typo in readme docs by [@&#8203;paulburlumi](https://github.com/paulburlumi) in [#&#8203;3277](https://github.com/grafana/helm-charts/pull/3277) #### New Contributors - [@&#8203;paulburlumi](https://github.com/paulburlumi) made their first contribution in [#&#8203;3277](https://github.com/grafana/helm-charts/pull/3277) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.17.0...grafana-8.4.6> ### [`v8.4.5`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.5) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.4...grafana-8.4.5) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana version to 11.1.4 by [@&#8203;tobiasamft](https://github.com/tobiasamft) in [#&#8203;3274](https://github.com/grafana/helm-charts/pull/3274) #### New Contributors - [@&#8203;tobiasamft](https://github.com/tobiasamft) made their first contribution in [#&#8203;3274](https://github.com/grafana/helm-charts/pull/3274) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-sampling-1.0.0...grafana-8.4.5> ### [`v8.4.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.3...grafana-8.4.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] tpl for host in grafana.ini by [@&#8203;nanori](https://github.com/nanori) in [#&#8203;3127](https://github.com/grafana/helm-charts/pull/3127) #### New Contributors - [@&#8203;nanori](https://github.com/nanori) made their first contribution in [#&#8203;3127](https://github.com/grafana/helm-charts/pull/3127) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.4.3...grafana-8.4.4> ### [`v8.4.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.2...grafana-8.4.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Truncate label values - max 64 characters by [@&#8203;uristernik](https://github.com/uristernik) in [#&#8203;3108](https://github.com/grafana/helm-charts/pull/3108) #### New Contributors - [@&#8203;uristernik](https://github.com/uristernik) made their first contribution in [#&#8203;3108](https://github.com/grafana/helm-charts/pull/3108) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.4.2...grafana-8.4.3> ### [`v8.4.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.1...grafana-8.4.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Removed dashboard labels from dashboard-json-configmap by [@&#8203;nwsteenberg](https://github.com/nwsteenberg) in [#&#8203;3215](https://github.com/grafana/helm-charts/pull/3215) #### New Contributors - [@&#8203;nwsteenberg](https://github.com/nwsteenberg) made their first contribution in [#&#8203;3215](https://github.com/grafana/helm-charts/pull/3215) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.16.1...grafana-8.4.2> ### [`v8.4.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.4.0...grafana-8.4.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update appVersion to 11.1.3 by [@&#8203;terop](https://github.com/terop) in [#&#8203;3253](https://github.com/grafana/helm-charts/pull/3253) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.4.4...grafana-8.4.1> ### [`v8.4.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.4.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.8...grafana-8.4.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] add value to make extraConfigmapMounts and extraSecretMounts optional by [@&#8203;tibuntu](https://github.com/tibuntu) in [#&#8203;3250](https://github.com/grafana/helm-charts/pull/3250) #### New Contributors - [@&#8203;tibuntu](https://github.com/tibuntu) made their first contribution in [#&#8203;3250](https://github.com/grafana/helm-charts/pull/3250) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/loki-distributed-0.79.2...grafana-8.4.0> ### [`v8.3.8`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.8) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.7...grafana-8.3.8) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Helm test annotations to new format by [@&#8203;ibakshay](https://github.com/ibakshay) in [#&#8203;3251](https://github.com/grafana/helm-charts/pull/3251) #### New Contributors - [@&#8203;ibakshay](https://github.com/ibakshay) made their first contribution in [#&#8203;3251](https://github.com/grafana/helm-charts/pull/3251) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.15.3...grafana-8.3.8> ### [`v8.3.7`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.7) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.6...grafana-8.3.7) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] fix: do not create pvc manually when useStatefulSet by [@&#8203;fengxsong](https://github.com/fengxsong) in [#&#8203;3244](https://github.com/grafana/helm-charts/pull/3244) #### New Contributors - [@&#8203;fengxsong](https://github.com/fengxsong) made their first contribution in [#&#8203;3244](https://github.com/grafana/helm-charts/pull/3244) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-agent-operator-0.4.1...grafana-8.3.7> ### [`v8.3.6`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.6) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.5...grafana-8.3.6) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] chore: update k8s-sidecar to 1.27.4 by [@&#8203;KyriosGN0](https://github.com/KyriosGN0) in [#&#8203;3232](https://github.com/grafana/helm-charts/pull/3232) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.3.5...grafana-8.3.6> ### [`v8.3.5`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.5) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.4...grafana-8.3.5) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] fix: Add missing version, kind to volumeClaimTemplates by [@&#8203;Nickmman](https://github.com/Nickmman) in [#&#8203;3037](https://github.com/grafana/helm-charts/pull/3037) #### New Contributors - [@&#8203;Nickmman](https://github.com/Nickmman) made their first contribution in [#&#8203;3037](https://github.com/grafana/helm-charts/pull/3037) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/synthetic-monitoring-agent-0.3.0...grafana-8.3.5> ### [`v8.3.4`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.4) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.3...grafana-8.3.4) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] TYPO by [@&#8203;mattclegg](https://github.com/mattclegg) in [#&#8203;3166](https://github.com/grafana/helm-charts/pull/3166) #### New Contributors - [@&#8203;mattclegg](https://github.com/mattclegg) made their first contribution in [#&#8203;3166](https://github.com/grafana/helm-charts/pull/3166) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/loki-distributed-0.79.1...grafana-8.3.4> ### [`v8.3.3`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.3) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.2...grafana-8.3.3) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Fixed image renderer network policy namespace selector by [@&#8203;elliotcourant](https://github.com/elliotcourant) in [#&#8203;3227](https://github.com/grafana/helm-charts/pull/3227) #### New Contributors - [@&#8203;elliotcourant](https://github.com/elliotcourant) made their first contribution in [#&#8203;3227](https://github.com/grafana/helm-charts/pull/3227) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-0.5.1...grafana-8.3.3> ### [`v8.3.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.1...grafana-8.3.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Clarify documentation for serviceMonitor.enabled by [@&#8203;oliviermichaelis](https://github.com/oliviermichaelis) in [#&#8203;3209](https://github.com/grafana/helm-charts/pull/3209) #### New Contributors - [@&#8203;oliviermichaelis](https://github.com/oliviermichaelis) made their first contribution in [#&#8203;3209](https://github.com/grafana/helm-charts/pull/3209) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/helm-loki-6.6.5...grafana-8.3.2> ### [`v8.3.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.3.0...grafana-8.3.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Add support for envValueFrom in datasources container and fix typo in dashboards container config by [@&#8203;rgaduput](https://github.com/rgaduput) in [#&#8203;3187](https://github.com/grafana/helm-charts/pull/3187) #### New Contributors - [@&#8203;rgaduput](https://github.com/rgaduput) made their first contribution in [#&#8203;3187](https://github.com/grafana/helm-charts/pull/3187) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.3.0...grafana-8.3.1> ### [`v8.3.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.3.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.2.2...grafana-8.3.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Add support for extra volumes for Grafana Image Renderer by [@&#8203;bradleypettit](https://github.com/bradleypettit) in [#&#8203;3178](https://github.com/grafana/helm-charts/pull/3178) #### New Contributors - [@&#8203;bradleypettit](https://github.com/bradleypettit) made their first contribution in [#&#8203;3178](https://github.com/grafana/helm-charts/pull/3178) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.13.2...grafana-8.3.0> ### [`v8.2.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.2.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.2.1...grafana-8.2.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Introduce toggle for volumeName lookup by [@&#8203;jkroepke](https://github.com/jkroepke) in [#&#8203;3163](https://github.com/grafana/helm-charts/pull/3163) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.13.1...grafana-8.2.2> ### [`v8.2.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.2.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.2.0...grafana-8.2.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Update Grafana to 11.1.0 by [@&#8203;sboulkour](https://github.com/sboulkour) in [#&#8203;3191](https://github.com/grafana/helm-charts/pull/3191) #### New Contributors - [@&#8203;sboulkour](https://github.com/sboulkour) made their first contribution in [#&#8203;3191](https://github.com/grafana/helm-charts/pull/3191) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.2.0...grafana-8.2.1> ### [`v8.2.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.2.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.1.1...grafana-8.2.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] add support for dual stack clusters by [@&#8203;M0NsTeRRR](https://github.com/M0NsTeRRR) in [#&#8203;3066](https://github.com/grafana/helm-charts/pull/3066) #### New Contributors - [@&#8203;M0NsTeRRR](https://github.com/M0NsTeRRR) made their first contribution in [#&#8203;3066](https://github.com/grafana/helm-charts/pull/3066) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.1.1...grafana-8.2.0> ### [`v8.1.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.1.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.1.0...grafana-8.1.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Adding jkroepke as maintainer by [@&#8203;jkroepke](https://github.com/jkroepke) in [#&#8203;3179](https://github.com/grafana/helm-charts/pull/3179) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/grafana-8.1.0...grafana-8.1.1> ### [`v8.1.0`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.1.0) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.0.2...grafana-8.1.0) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] feat:Allow hiding persistence warning by [@&#8203;nikolaik](https://github.com/nikolaik) in [#&#8203;3013](https://github.com/grafana/helm-charts/pull/3013) #### New Contributors - [@&#8203;nikolaik](https://github.com/nikolaik) made their first contribution in [#&#8203;3013](https://github.com/grafana/helm-charts/pull/3013) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/alloy-0.4.0...grafana-8.1.0> ### [`v8.0.2`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.0.2) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.0.1...grafana-8.0.2) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] Adding configmap annotation by [@&#8203;jmiszczak83](https://github.com/jmiszczak83) in [#&#8203;3064](https://github.com/grafana/helm-charts/pull/3064) #### New Contributors - [@&#8203;jmiszczak83](https://github.com/jmiszczak83) made their first contribution in [#&#8203;3064](https://github.com/grafana/helm-charts/pull/3064) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.0.13...grafana-8.0.2> ### [`v8.0.1`](https://github.com/grafana/helm-charts/releases/tag/grafana-8.0.1) [Compare Source](https://github.com/grafana/helm-charts/compare/grafana-8.0.0...grafana-8.0.1) The leading tool for querying and visualizing time series and metrics. #### What's Changed - \[grafana] conf(grafana): Add `folderUid` option by [@&#8203;Rohlik](https://github.com/Rohlik) in [#&#8203;2956](https://github.com/grafana/helm-charts/pull/2956) #### New Contributors - [@&#8203;Rohlik](https://github.com/Rohlik) made their first contribution in [#&#8203;2956](https://github.com/grafana/helm-charts/pull/2956) **Full Changelog**: <https://github.com/grafana/helm-charts/compare/tempo-distributed-1.11.0...grafana-8.0.1> </details> <details> <summary>kubernetes-sigs/kind (kind)</summary> ### [`v0.32.0`](https://github.com/kubernetes-sigs/kind/releases/tag/v0.32.0) This release contains critical dependency updates, bug fixes, and defaults to Kubernetes 1.36.1. ### Breaking Changes - **The default node image is now `kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5`** - **New node images requiring upgrading kind to `kind load ...`**: Due to a containerd upgrade, you must upgrade `kind` to this release or newer to use `kind load ...` with the newly published node images. As always, we cannot gurantee full compatibility of node images between kind releases. You can use the digests from previous releases, upgrade kind, or build your own node-images. - **kubeadm v1beta4 config format is now used for Kubernetes 1.36.0+** If you are using versioned config patches, you must update to target v1beta4. Unversioned patches kind will attempt to convert as needed (more below in New Features). This change is required for Kubernetes 1.37+ which drops kubeadm v1beta3 config. - **Adoption of Envoy for Load Balancing in multi-control-plane node clusters:** HAProxy has been replaced by Envoy (`docker.io/envoyproxy/envoy:v1.36.2`) as the load balancer in multi-control-plane (HA) clusters. If you rely on custom HAProxy loadbalancer configurations or images, please note that Envoy is now used. - **cgroup v1 warning:** A warning is now printed if cgroup v1 is detected on the host. Kubernetes [has deprecated support for cgroup v1](https://github.com/kubernetes/enhancements/issues/5573), and at some point in the future KIND releases / node-images will also drop support for cgroup v1. ### New Features - **kubeadm v1beta4 configuration support:** KIND now uses the `v1beta4` config format for Kubernetes `v1.36.0+` while maintaining `v1beta3` for `v1.23.0` up to `v1.35.x`, and `v1beta2` for older versions. - **Custom Merging & Version-Awareness for Kubeadm Config Patches:** - KIND now automatically translates old-style map-based `extraArgs` / `kubeletExtraArgs` patches to the list-based `v1beta4` format when targeting `v1beta4` configs. - Config patches now append to `extraArgs` / `kubeletExtraArgs` / `certSANs` reliably. To overwrite or make other more precise patching, use json6902 patches. - **Support for containerd config v4 format:** Enabled support for containerd's config v4 format in `kind load` and snapshotter parsing, which is required for newer containerd versions. - **Building Node Images from CI Artifacts:** Added support to build node images from Kubernetes CI artifacts (resolving endpoints like `https://dl.k8s.io/ci/latest.txt` or CI build prefixes). - **Support for containerd version-aware containerd config patching:** Like kubeadmConfigPatches, containerd config patching is now aware of `version` and if specified in patches will only apply patches that match the containerd config being used. - Assorted dependency updates. Images pre-built for this release: - v1.36.1: `kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5` - v1.35.5: `kindest/node:v1.35.5@sha256:ce977ae6d65918d0b58a5f8b5e940429c2ce42fa3a5619ec2bbc60b949c0ac95` - v1.34.8: `kindest/node:v1.34.8@sha256:02722c2dedddcfc00febf5d27fbeb9b7b2c14294c82109ff4a85d89ac9ba3256` - v1.33.12: `kindest/node:v1.33.12@sha256:3f5c8443c620245e4d355cfe09e96a91ead32ceaa569d3f1ca9edf0cb2fe2ff4` **NOTE**: You *must* use the `@sha256` digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons. ### Fixes - Fix permission error when creating pods with `hostUsers: false` (Kubernetes 1.36+). - Handle registry ports correctly in image normalization logic (e.g., registry running on ports like `localhost:5000/...`). - Handle empty port mapping listen addresses correctly (defaults to wildcard address). - Skip `/dev/mapper` mount on rootless Docker. - Assorted documentation fixes and improvements. See also: - <https://kind.sigs.k8s.io/docs/user/quick-start/#creating-a-cluster> - <https://kind.sigs.k8s.io/docs/user/quick-start/#building-images> NOTE: These node images support amd64 and arm64, both of our supported platforms. **You must use the same platform as your host,** for more context see [#&#8203;2718](https://github.com/kubernetes-sigs/kind/issues/2718) ### Contributors Committers for this release: - [@&#8203;AnjaliMishra1st](https://github.com/AnjaliMishra1st) - [@&#8203;aojea](https://github.com/aojea) - [@&#8203;BenTheElder](https://github.com/BenTheElder) - [@&#8203;dependabot](https://github.com/dependabot)\[bot] - [@&#8203;dims](https://github.com/dims) - [@&#8203;egypcio](https://github.com/egypcio) - [@&#8203;george-angel](https://github.com/george-angel) - [@&#8203;immanuwell](https://github.com/immanuwell) - [@&#8203;k8s-ci-robot](https://github.com/k8s-ci-robot) - [@&#8203;rjbrown57](https://github.com/rjbrown57) - [@&#8203;shwetha-s-poojary](https://github.com/shwetha-s-poojary) - [@&#8203;stmcginnis](https://github.com/stmcginnis) - [@&#8203;tmchow](https://github.com/tmchow) - [@&#8203;yesdeepakverma](https://github.com/yesdeepakverma) We'd also like to thank everyone who touched the codebase, filed issues, and helped the community! ### [`v0.31.0`](https://github.com/kubernetes-sigs/kind/releases/tag/v0.31.0) This release contains dependency updates and defaults to Kubernetes 1.35.0. Please take note of the breaking changes from Kubernetes 1.35, and how to prepare for **future** changes to move off of the deprecated kubeam v1beta3 in favor of v1beta4. We will include updated reminders for both again in subsequent releases. <h1 id="breaking-changes">Breaking Changes</h1> The default node image is now `kindest/node:v1.35.0@sha256:452d707d4862f52530247495d180205e029056831160e22870e37e3f6c1ac31f` <h2 id="kubernetes-cgroupv1">Kubernetes 1.35+ Cgroup v1</h2> Kubernetes [will be removing cgroup v1 support](https://kubernetes.io/blog/2025/12/17/kubernetes-v1-35-release/#removal-of-cgroup-v1-support), and therefore kind node images at those versions will also be dropping support. You can read more about this change in the Kubernetes release blog: <https://kubernetes.io/blog/2025/12/17/kubernetes-v1-35-release/#removal-of-cgroup-v1-support> If you must use kind on cgroup v1, we recommend using an older Kubernetes release for the immediate future, but we also strongly recommend migrating to cgroup v2. In the near future as Kubernetes support dwindles, KIND will also clean up cgroup v1 workarounds and drop support in future kind releases and images, regardless of Kubernetes version. Most stable linux distros should be on cgroupv2 out of the box. This is a reminder to use pinned images by digest, see the note below about images for this release. <h2 id="kubeadm-config">Kubeadm Config *Future* Breaking Change</h2> **WARNING**: Future kind releases will [adopt kubeadm v1beta4](https://github.com/kubernetes-sigs/kind/issues/3847) configuration, [kubeadm](https://github.com/kubernetes/kubeadm) v1beta4 has a breaking change to `extraArgs`: <https://kubernetes.io/blog/2024/08/23/kubernetes-1-31-kubeadm-v1beta4/>. If you use the `kubeadmConfigPatches` feature then you may need to prepare for this change. We recommend that you use versioned config patches that explicitly match the version required. KIND uses kubeadm v1beta3 for Kubernetes 1.23+, and will likely use v1beta4 for Kubernetes 1.36+ The exact version is TBD pending work to fix this but expected to be 1.36. It will definitely be an as-of-yet-unreleased Kubernetes version to avoid surprises, and it will not be on a patch-release boundary. KIND *may* still work with older Kubernetes versions at v1beta2, but we no longer test or actively support these as Kubernetes only supports 1.32+ currently: <https://kubernetes.io/releases/> You likely only need v1beta3 + v1beta4 patches, you can take your existing patches that work with v1beta3, explicitly set `apiVersion: kubeadm.k8s.io/v1beta3` in the patch at the top level, and make another copy for v1beta4. The v1beta4 patch will need to move `extraArgs` from a map to a list, for examples see: <https://kubernetes.io/docs/reference/config-api/kubeadm-config.v1beta4/> For a concrete example of kind config with kubeadm config patch targeting both v1beta3 and v1beta4, consider this simple kind config that sets verbosity of the apiserver logs: ```yaml kind: Cluster apiVersion: kind.x-k8s.io/v1alpha4 kubeadmConfigPatches: # patch for v1beta3 (1.23 ...) - | kind: ClusterConfiguration apiVersion: kubeadm.k8s.io/v1beta3 apiServer: extraArgs: "v": "4" # patch for v1beta4 (future) - | kind: ClusterConfiguration apiVersion: kubeadm.k8s.io/v1beta4 apiServer: extraArgs: - name: "v" value: "4" ``` If you only need to target a particular release, you can use one version. If you only need to target fields that did not change between kubeadm beta versions, you can use a versionless patch, which may be more convenient, but we cannot guarantee there will be no future kubeadm config breaking changes. <h1 id="new-features">New Features</h1> - Assorted unspecified dependency updates Images pre-built for this release: - v1.35.0: `kindest/node:v1.35.0@sha256:452d707d4862f52530247495d180205e029056831160e22870e37e3f6c1ac31f` - v1.34.3: `kindest/node:v1.34.3@sha256:08497ee19eace7b4b5348db5c6a1591d7752b164530a36f855cb0f2bdcbadd48` - v1.33.7: `kindest/node:v1.33.7@sha256:d26ef333bdb2cbe9862a0f7c3803ecc7b4303d8cea8e814b481b09949d353040` - v1.32.11: `kindest/node:v1.32.11@sha256:5fc52d52a7b9574015299724bd68f183702956aa4a2116ae75a63cb574b35af8` - v1.31.14: `kindest/node:v1.31.14@sha256:6f86cf509dbb42767b6e79debc3f2c32e4ee01386f0489b3b2be24b0a55aac2b` **NOTE**: You *must* use the `@sha256` digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons. See also: - <https://kind.sigs.k8s.io/docs/user/quick-start/#creating-a-cluster> - <https://kind.sigs.k8s.io/docs/user/quick-start/#building-images> NOTE: These node images support amd64 and arm64, both of our supported platforms. **You must use the same platform as your host,** for more context see [#&#8203;2718](https://github.com/kubernetes-sigs/kind/issues/2718) <h1 id="fixes">Fixes</h1> - Detect additional edge case with ipv6 support on the host - Make development / release scripts GOTOOLCHAIN aware <h1 id="contributors">Contributors</h1> Committers for this release: - [@&#8203;AkihiroSuda](https://github.com/AkihiroSuda) - [@&#8203;adambkaplan](https://github.com/adambkaplan) - [@&#8203;afbjorklund](https://github.com/afbjorklund) - [@&#8203;aoxn](https://github.com/aoxn) - [@&#8203;BenTheElder](https://github.com/BenTheElder) - [@&#8203;dependabot](https://github.com/dependabot)\[bot] - [@&#8203;k8s-ci-robot](https://github.com/k8s-ci-robot) - [@&#8203;kalexmills](https://github.com/kalexmills) - [@&#8203;kishen-v](https://github.com/kishen-v) - [@&#8203;mikejoh](https://github.com/mikejoh) - [@&#8203;rayowang](https://github.com/rayowang) - [@&#8203;shahar1](https://github.com/shahar1) - [@&#8203;stmcginnis](https://github.com/stmcginnis) ### [`v0.30.0`](https://github.com/kubernetes-sigs/kind/releases/tag/v0.30.0) This is small release containing patched dependencies and Kubernetes 1.34, as well as a bugfix for Kubernetes v1.33.0+ cluster reboots. <h1 id="breaking-changes">Breaking Changes</h1> The default node image is now `kindest/node:v1.34.0@sha256:7416a61b42b1662ca6ca89f02028ac133a309a2a30ba309614e8ec94d976dc5a` <h1 id="new-features">New Features</h1> - Updated to containerd 2.1.4 Images pre-built for this release: - v1.34.0: `kindest/node:v1.34.0@sha256:7416a61b42b1662ca6ca89f02028ac133a309a2a30ba309614e8ec94d976dc5a` - v1.33.4: `kindest/node:v1.33.4@sha256:25a6018e48dfcaee478f4a59af81157a437f15e6e140bf103f85a2e7cd0cbbf2` - v1.32.8: `kindest/node:v1.32.8@sha256:abd489f042d2b644e2d033f5c2d900bc707798d075e8186cb65e3f1367a9d5a1` - v1.31.12: `kindest/node:v1.31.12@sha256:0f5cc49c5e73c0c2bb6e2df56e7df189240d83cf94edfa30946482eb08ec57d2` **NOTE**: You *must* use the `@sha256` digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons. See also: - <https://kind.sigs.k8s.io/docs/user/quick-start/#creating-a-cluster> - <https://kind.sigs.k8s.io/docs/user/quick-start/#building-images> NOTE: These node images support amd64 and arm64, both of our supported platforms. **You must use the same platform as your host,** for more context see [#&#8203;2718](https://github.com/kubernetes-sigs/kind/issues/2718) <h1 id="fixes">Fixes</h1> - Fix an issue with rebooting v1.33.0+ clusters [#&#8203;3941](https://github.com/kubernetes-sigs/kind/issues/3941) - Add priority class system-critical to kindnetd - Fix HA control-plane loadbalancer for podman [#&#8203;3962](https://github.com/kubernetes-sigs/kind/pull/3962) - Fix node-image builds with relative source paths <h1 id="contributors">Contributors</h1> Committers for this release: - [@&#8203;BenTheElder](https://github.com/BenTheElder) - [@&#8203;dims](https://github.com/dims) - [@&#8203;k8s-ci-robot](https://github.com/k8s-ci-robot) - [@&#8203;oduludo](https://github.com/oduludo) - [@&#8203;stmcginnis](https://github.com/stmcginnis) - [@&#8203;tchap](https://github.com/tchap) - [@&#8203;tom1299](https://github.com/tom1299) </details> <details> <summary>sunny0826/kubecm (kubecm)</summary> ### [`v0.35.1`](https://github.com/sunny0826/kubecm/releases/tag/v0.35.1): kubecm-v0.35.1 #### Changelog #### What's Changed - docs: add Registry to README highlights and sidebar by [@&#8203;clark42](https://github.com/clark42) in [#&#8203;1173](https://github.com/sunny0826/kubecm/pull/1173) - fix(namespace): handle missing or empty current-context gracefully by [@&#8203;clark42](https://github.com/clark42) in [#&#8203;1174](https://github.com/sunny0826/kubecm/pull/1174) - feat(registry): add User concept, cluster/user separation by [@&#8203;clark42](https://github.com/clark42) in [#&#8203;1175](https://github.com/sunny0826/kubecm/pull/1175) - chore(deps): bump rajatjindal/krew-release-bot from 0.0.50 to 0.0.51 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1180](https://github.com/sunny0826/kubecm/pull/1180) **Full Changelog**: <https://github.com/sunny0826/kubecm/compare/v0.35.0...v0.35.1> ### [`v0.35.0`](https://github.com/sunny0826/kubecm/releases/tag/v0.35.0): kubecm-v0.35.0 #### Changelog ##### Others - [`6b96e5e`](https://github.com/sunny0826/kubecm/commit/6b96e5e27edff1b6a5daadb467115c9d46409ad1): add clark42 as a contributor for code, doc, and test ([#&#8203;1172](https://github.com/sunny0826/kubecm/issues/1172)) (allcontributors\[bot] <46447321+allcontributors\[bot][@&#8203;users](https://github.com/users).noreply.github.com>) #### What's Changed - feat(cloud): add AWS profile and credential chain support for EKS by [@&#8203;clark42](https://github.com/clark42) in [#&#8203;1170](https://github.com/sunny0826/kubecm/pull/1170) - chore(deps): bump goreleaser/goreleaser-action from 6 to 7 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1168](https://github.com/sunny0826/kubecm/pull/1168) - chore(deps): bump rajatjindal/krew-release-bot from 0.0.47 to 0.0.50 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1169](https://github.com/sunny0826/kubecm/pull/1169) - feat(registry): add Git-backed kubeconfig distribution system by [@&#8203;clark42](https://github.com/clark42) in [#&#8203;1171](https://github.com/sunny0826/kubecm/pull/1171) - add clark42 as a contributor for code, doc, and test by [@&#8203;allcontributors](https://github.com/allcontributors)\[bot] in [#&#8203;1172](https://github.com/sunny0826/kubecm/pull/1172) #### New Contributors - [@&#8203;clark42](https://github.com/clark42) made their first contribution in [#&#8203;1170](https://github.com/sunny0826/kubecm/pull/1170) **Full Changelog**: <https://github.com/sunny0826/kubecm/compare/v0.34.0...v0.35.0> ### [`v0.34.0`](https://github.com/sunny0826/kubecm/releases/tag/v0.34.0): kubecm-v0.34.0 #### What's Changed - feat: support multiple kubeconfig files at os env $KUBECONFIG by [@&#8203;sk31337](https://github.com/sk31337) in [#&#8203;1153](https://github.com/sunny0826/kubecm/pull/1153) - add sk31337 as a contributor for code by [@&#8203;allcontributors](https://github.com/allcontributors)\[bot] in [#&#8203;1155](https://github.com/sunny0826/kubecm/pull/1155) - chore(deps): bump golang.org/x/crypto from 0.36.0 to 0.45.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1154](https://github.com/sunny0826/kubecm/pull/1154) - chore(deps): bump actions/checkout from 5 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1157](https://github.com/sunny0826/kubecm/pull/1157) - chore(deps): bump dawidd6/action-homebrew-bump-formula from 5 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1158](https://github.com/sunny0826/kubecm/pull/1158) - feat(list): add flags to shorten or hide server column in list command by [@&#8203;sunny0826](https://github.com/sunny0826) in [#&#8203;1161](https://github.com/sunny0826/kubecm/pull/1161) - chore(deps): bump dawidd6/action-homebrew-bump-formula from 6 to 7 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1162](https://github.com/sunny0826/kubecm/pull/1162) - chore(deps): bump codecov/codecov-action from 5.5.1 to 5.5.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1163](https://github.com/sunny0826/kubecm/pull/1163) - Add e2e test framework for kubecm by [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;1164](https://github.com/sunny0826/kubecm/pull/1164) #### New Contributors - [@&#8203;sk31337](https://github.com/sk31337) made their first contribution in [#&#8203;1153](https://github.com/sunny0826/kubecm/pull/1153) - [@&#8203;Copilot](https://github.com/Copilot) made their first contribution in [#&#8203;1164](https://github.com/sunny0826/kubecm/pull/1164) **Full Changelog**: <https://github.com/sunny0826/kubecm/compare/v0.33.3...v0.34.0> ### [`v0.33.3`](https://github.com/sunny0826/kubecm/releases/tag/v0.33.3): kubecm-v0.33.3 #### Changelog ##### Others - [`7cfb67b`](https://github.com/sunny0826/kubecm/commit/7cfb67b92239b5c2c3a71a0f3876fb25864cbda4): Fixed a bug in table rendering when long strings had line breaks. ([#&#8203;1151](https://github.com/sunny0826/kubecm/issues/1151)) (小山羊创作 <133758630+xiaoshanyangcode@users.noreply.github.com>) ### [`v0.33.2`](https://github.com/sunny0826/kubecm/releases/tag/v0.33.2): kubecm-v0.33.2 #### Changelog ##### Others - [`ff503b3`](https://github.com/sunny0826/kubecm/commit/ff503b3559f9882d1ad8df0b39a80bc01a99922e): add xiaoshanyangcode as a contributor for code ([#&#8203;1150](https://github.com/sunny0826/kubecm/issues/1150)) (allcontributors\[bot] <46447321+allcontributors\[bot][@&#8203;users](https://github.com/users).noreply.github.com>) </details> <details> <summary>helm/helm (kubernetes-helm)</summary> ### [`v3.20.2`](https://github.com/helm/helm/releases/tag/v3.20.2): Helm v3.20.2 #### v3.20.2 Helm v3.20.2 is a security patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! - Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com): - for questions and just to hang out - for discussing PRs, code, and bugs - Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622) - Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0) #### Security fixes - [GHSA-hr2v-4r36-88hr](https://github.com/helm/helm/security/advisories/GHSA-hr2v-4r36-88hr) Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment #### Installation and Upgrading Download Helm v3.20.2. The common platform binaries are here: - [MacOS amd64](https://get.helm.sh/helm-v3.20.2-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-darwin-amd64.tar.gz.sha256sum) / 7de04301f28b902a74f6286ed941cadc86ee5e6a9086a18f2ccf1f548e99d618) - [MacOS arm64](https://get.helm.sh/helm-v3.20.2-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-darwin-arm64.tar.gz.sha256sum) / 139c794c22f16b579d08ddd3008c8038b9bb2814f35b5bcca91f50a1f458978d) - [Linux amd64](https://get.helm.sh/helm-v3.20.2-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-amd64.tar.gz.sha256sum) / 258e830a9e613c8a7a302d6059b4bb3b9758f2f3e1bb8ea0d707ce10a9a72fea) - [Linux arm](https://get.helm.sh/helm-v3.20.2-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-arm.tar.gz.sha256sum) / a8a614c740399ff1ef32bcea6be6e4523f17e3376f9cf55c192cc48c8f2d1f19) - [Linux arm64](https://get.helm.sh/helm-v3.20.2-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-arm64.tar.gz.sha256sum) / 5ea2d6bc2cda3f8edf985e028809f5a9278f404fb8ab24044de9b7cb9b79a691) - [Linux i386](https://get.helm.sh/helm-v3.20.2-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-386.tar.gz.sha256sum) / 88e4c1834307cdbc9f3b80920e1a383e4ba50bb488fb0be1b1fbd4918bb6ae73) - [Linux ppc64le](https://get.helm.sh/helm-v3.20.2-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-ppc64le.tar.gz.sha256sum) / 98bb26a2f3c0b0c1a50db3181dff192554e0c204a07427d98d6b01e259f23cbe) - [Linux s390x](https://get.helm.sh/helm-v3.20.2-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-s390x.tar.gz.sha256sum) / 584dd77ef8096d6ef939a1822f72840e749fc8311b2b13ae94df5f786862a56b) - [Linux riscv64](https://get.helm.sh/helm-v3.20.2-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.2-linux-riscv64.tar.gz.sha256sum) / 957391d0710d72678acd09959b5dc77888cd007a78a4b99944d3b2fc7e1895ca) - [Windows amd64](https://get.helm.sh/helm-v3.20.2-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v3.20.2-windows-amd64.zip.sha256sum) / 24e8e5b71bab4ee17e6f989931ecf4fb144f9916cbe9990c0b6b2ec7b925c454) - [Windows arm64](https://get.helm.sh/helm-v3.20.2-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v3.20.2-windows-arm64.zip.sha256sum) / 7c940a73a6882f50b69aec3282549da4a49917669db18fc503db930fb74b9789) The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3) on any system with `bash`. #### What's Next - 4.1.5 and 3.20.3 are the next patch (bug fix) releases and will be on April 8, 2026 - 4.2.0 and 3.21.0 are the next minor (feature) releases and will be on May 13, 2026 #### Changelog - fix: Chart dot-name path bug [`8fb76d6`](https://github.com/helm/helm/commit/8fb76d6ab555577e98e23b7500009537a471feee) (George Jenkins) - fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow [`3a8927e`](https://github.com/helm/helm/commit/3a8927e275c50cecde273872dad2a5576bd46375) (Terry Howe) ### [`v3.20.1`](https://github.com/helm/helm/releases/tag/v3.20.1): Helm v3.20.1 Helm v3.20.1 is a patch release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! - Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com): - for questions and just to hang out - for discussing PRs, code, and bugs - Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622) - Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0) #### Notable Changes - Backport of [#&#8203;31644](https://github.com/helm/helm/issues/31644): Fixed a bug where user-provided nil value was not preserved when chart has an empty map or no default for a key - Backport of [#&#8203;31601](https://github.com/helm/helm/issues/31601): Fixed a bug where OCI references with tag+digest failed with "invalid byte" error #### Installation and Upgrading Download Helm v3.20.1. The common platform binaries are here: - [MacOS amd64](https://get.helm.sh/helm-v3.20.1-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-darwin-amd64.tar.gz.sha256sum) / 580515b544d5c966edc6f782c9ae88e21a9e10c786a7d6c5fd4b52613f321076) - [MacOS arm64](https://get.helm.sh/helm-v3.20.1-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-darwin-arm64.tar.gz.sha256sum) / 75cc96ac3fe8b8b9928eb051e55698e98d1e026967b6bffe4f0f3c538a551b65) - [Linux amd64](https://get.helm.sh/helm-v3.20.1-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-amd64.tar.gz.sha256sum) / 0165ee4a2db012cc657381001e593e981f42aa5707acdd50658326790c9d0dc3) - [Linux arm](https://get.helm.sh/helm-v3.20.1-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-arm.tar.gz.sha256sum) / 758375df78fb8f91f4056244bda539710a73be79284b24b4bdad68384348ca33) - [Linux arm64](https://get.helm.sh/helm-v3.20.1-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-arm64.tar.gz.sha256sum) / 56b9d1b0e0efbb739be6e68a37860ace8ec9c7d3e6424e3b55d4c459bc3a0401) - [Linux i386](https://get.helm.sh/helm-v3.20.1-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-386.tar.gz.sha256sum) / 22b350307d5e5897b3a14f096cb6b2212cc03c22ba29ab7b4ee3e64ab9f3f190) - [Linux ppc64le](https://get.helm.sh/helm-v3.20.1-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-ppc64le.tar.gz.sha256sum) / 77b7d9bc62b209c044b873bc773055c5c0d17ef055e54c683f33209ebbe8883c) - [Linux s390x](https://get.helm.sh/helm-v3.20.1-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-s390x.tar.gz.sha256sum) / 3c43d45149a425c7bf15ba3653ddee13e7b1a4dd6d4534397b6f317f83c51b58) - [Linux riscv64](https://get.helm.sh/helm-v3.20.1-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.20.1-linux-riscv64.tar.gz.sha256sum) / 0eeae246112b4780e61651f9fbe6d778eebf8c8eccca590139b97d167d1b8aeb) - [Windows amd64](https://get.helm.sh/helm-v3.20.1-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v3.20.1-windows-amd64.zip.sha256sum) / 16d5256f4c2cde0745acb922ba88b7759dfced4bf547b99381084211f81c8629) - [Windows arm64](https://get.helm.sh/helm-v3.20.1-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v3.20.1-windows-arm64.zip.sha256sum) / 2aac2b87e92c32d44aa81c6412286d9db7e43b22b4c8ac112b68cf69185429bd) This release was signed with `208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155` and can be found at [@&#8203;scottrigby](https://github.com/scottrigby) [keybase account](https://keybase.io/r6by). Please use the attached signatures for verifying this release using `gpg`. The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3) on any system with `bash`. #### What's Next - 4.2.0 and 3.21.0 are the next minor releases and will be on May 13, 2026 - 4.1.4 and 3.20.2 are the next patch releases and will be on April 8, 2026 #### Changelog - chore(deps): bump the k8s-io group with 7 updates [`a2369ca`](https://github.com/helm/helm/commit/a2369ca71c0ef633bf6e4fccd66d634eb379b371) (dependabot\[bot]) - add image index test [`90e1056`](https://github.com/helm/helm/commit/90e10564f7ae746a153f3a03006e7061a54ad490) (Pedro Tôrres) - fix pulling charts from OCI indices [`911f2e9`](https://github.com/helm/helm/commit/911f2e908ae40b01ca95b857e94b8894043f64fd) (Pedro Tôrres) - Remove refactorring changes from coalesce\_test.go [`76dad33`](https://github.com/helm/helm/commit/76dad33fb1a2b6451920429b4f5f2dd575ea71bb) (Evans Mungai) - Fix import [`45c12f7`](https://github.com/helm/helm/commit/45c12f71407b6054a37d3e425d5293ee79a1ab37) (Evans Mungai) - Update pkg/chart/common/util/coalesce\_test.go [`26c6f19`](https://github.com/helm/helm/commit/26c6f19f967941dbe53bfb5e52d419b3b3e46075) (Evans Mungai) - Fix lint warning [`09f5129`](https://github.com/helm/helm/commit/09f5129d49a14c9336cea6f33adf5f52889915ef) (Evans Mungai) - Preserve nil values in chart already [`417deb2`](https://github.com/helm/helm/commit/417deb2b6b7504357b0f580b76f5eed1bb8a5270) (Evans Mungai) - fix(values): preserve nil values when chart default is empty map [`5417bfa`](https://github.com/helm/helm/commit/5417bfaa84871feae9c8171f192e2f9796475054) (Evans Mungai) ### [`v3.19.1`](https://github.com/helm/helm/releases/tag/v3.19.1): Helm v3.19.1 Helm v3.19.1 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! - Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com): - for questions and just to hang out - for discussing PRs, code, and bugs - Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622) - Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0) #### Installation and Upgrading Download Helm v3.19.1. The common platform binaries are here: - [MacOS amd64](https://get.helm.sh/helm-v3.19.1-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-darwin-amd64.tar.gz.sha256sum) / 567f50c5855c45e85ecfa50846bf30adad5d68e1d35ff216866b4897e91bcb80) - [MacOS arm64](https://get.helm.sh/helm-v3.19.1-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-darwin-arm64.tar.gz.sha256sum) / 080f320cfc4ee3816fd6c8f73820f4b3d941b10f709e69bf9afd78f8f8e7c92a) - [Linux amd64](https://get.helm.sh/helm-v3.19.1-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-amd64.tar.gz.sha256sum) / 966bed9b1e0dda11268f59bd7268c3cd3e308b37b070546e1d78a02526ff63f2) - [Linux arm](https://get.helm.sh/helm-v3.19.1-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-arm.tar.gz.sha256sum) / cd21c7ee767b4138e13ca856f102732cae7270c1bbe6d080a3d98153953550ac) - [Linux arm64](https://get.helm.sh/helm-v3.19.1-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-arm64.tar.gz.sha256sum) / ceed150305a1d1ef4a37923a7f66931a6807c34a38ea487fa8340e102dd2c7f7) - [Linux i386](https://get.helm.sh/helm-v3.19.1-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-386.tar.gz.sha256sum) / be3b70efa7b0ddaddd60d94ef0a37b69e22a5ee05efbec579729cdaacc2e7c5e) - [Linux ppc64le](https://get.helm.sh/helm-v3.19.1-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-ppc64le.tar.gz.sha256sum) / acb8a92d873cc2ae2dd44593d88a0bc3a78eb7abd6b3784c3fced9e005401018) - [Linux s390x](https://get.helm.sh/helm-v3.19.1-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-s390x.tar.gz.sha256sum) / 279dcdeaa9f3b42c8558e6e1815466852a80bd373f9a9e83ae7f724ff2cda17f) - [Linux riscv64](https://get.helm.sh/helm-v3.19.1-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.1-linux-riscv64.tar.gz.sha256sum) / ed0a8b03c2163157a948a67702d1884f4936575f9be953c673748b41bd2a9881) - [Windows amd64](https://get.helm.sh/helm-v3.19.1-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v3.19.1-windows-amd64.zip.sha256sum) / 3fd3ab4a47364c04c51e0e7387e0598aa2c8c43dd535128665aa43e695cec11e) - [Windows arm64](https://get.helm.sh/helm-v3.19.1-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v3.19.1-windows-arm64.zip.sha256sum) / 361b04b599ada09be194461cd0347db20276849c22f57adc697963d57a515c6a) This release was signed with `672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E ` and can be found at [@&#8203;mattfarina](https://github.com/mattfarina) [keybase account](https://keybase.io/mattfarina). Please use the attached signatures for verifying this release using `gpg`. The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3) on any system with `bash`. #### What's Next - 4.0.0 is the next major release and will be on November 12, 2025 - 3.19.2 and 4.0.01 are the next patch releases and will be on December 10, 2025 - 3.20.0 and 4.1.0 is the next minor releases and will be on January 21, 2026 #### Changelog - chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 [`4f953c2`](https://github.com/helm/helm/commit/4f953c223ba21103268e0b664c64240bc69fced7) (dependabot\[bot]) - jsonschema: warn and ignore unresolved URN $ref to match v3.18.4 [`6801f4d`](https://github.com/helm/helm/commit/6801f4d6b3c97a146e21034a34b3d098d0013931) (Benoit Tigeot) - Avoid "panic: interface conversion: interface {} is nil" [`2f619be`](https://github.com/helm/helm/commit/2f619be224790e7b2447b10faa3b965701177e40) (Benoit Tigeot) - Fix `helm pull` untar dir check with repo urls [`8112d47`](https://github.com/helm/helm/commit/8112d47cbba491a70d84005e5a88bd0e72ef5040) (Luna Stadler) - Fix deprecation warning [`5dff7ce`](https://github.com/helm/helm/commit/5dff7ce71b53828d36121f81ac59cf389b811ebc) (Benoit Tigeot) - chore(deps): bump github.com/spf13/pflag from 1.0.7 to 1.0.10 [`2dad4d2`](https://github.com/helm/helm/commit/2dad4d27fa39e658bfb87c9f61f3aea09669536a) (dependabot\[bot]) - Add timeout flag to repo add and update flags [`a833710`](https://github.com/helm/helm/commit/a8337106b434584b600d2b51c191610dde34fc53) (Reinhard Nägele) - chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.43.0 [`2e12c81`](https://github.com/helm/helm/commit/2e12c81d2aa702e31340582d9f9f7fe05d2700b4) (Dirk Müller) ### [`v3.19.0`](https://github.com/helm/helm/releases/tag/v3.19.0): Helm v3.19.0 Helm v3.19.0 is a feature release. Users are encouraged to upgrade for the best experience. The community keeps growing, and we'd love to see you there! - Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com): - for questions and just to hang out - for discussing PRs, code, and bugs - Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622) - Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0) #### Notable Changes - Fixed a `helm pull` regression from 3.18 - error pulling OCI charts with --password [#&#8203;31230](https://github.com/helm/helm/issues/31230) - Fixed a `helm lint` regression from Helm 3.18 - rejected JSON Schema $ref URLs that worked in 3.17.x [#&#8203;31166](https://github.com/helm/helm/issues/31166) - Fixed go mod tidy [#&#8203;31154](https://github.com/helm/helm/issues/31154) - Fixed k8s version parsing not matching original [#&#8203;31091](https://github.com/helm/helm/issues/31091) - Fixed charts failing when using a redirect registry [#&#8203;31087](https://github.com/helm/helm/issues/31087) - Fixed missing debug logging for OCI transport - Fixed broken legacy docker support for login [#&#8203;30941](https://github.com/helm/helm/issues/30941) - Fixed bugs from the move to ORAS v2 - Fixed processing all hook deletions on failure [#&#8203;30673](https://github.com/helm/helm/issues/30673) - Feature for `helm create` added httproute from gateway-api to create chart template [#&#8203;30658](https://github.com/helm/helm/issues/30658) #### Installation and Upgrading Download Helm v3.19.0. The common platform binaries are here: - [MacOS amd64](https://get.helm.sh/helm-v3.19.0-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-darwin-amd64.tar.gz.sha256sum) / 09a108c0abda42e45af172be65c49125354bf7cd178dbe10435e94540e49c7b9) - [MacOS arm64](https://get.helm.sh/helm-v3.19.0-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-darwin-arm64.tar.gz.sha256sum) / 31513e1193da4eb4ae042eb5f98ef9aca7890cfa136f4707c8d4f70e2115bef6) - [Linux amd64](https://get.helm.sh/helm-v3.19.0-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-amd64.tar.gz.sha256sum) / a7f81ce08007091b86d8bd696eb4d86b8d0f2e1b9f6c714be62f82f96a594496) - [Linux arm](https://get.helm.sh/helm-v3.19.0-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-arm.tar.gz.sha256sum) / 8708367b8e8bed9bdf8429bb57536e4223cdca96245dffc205cb0cb670b151f4) - [Linux arm64](https://get.helm.sh/helm-v3.19.0-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-arm64.tar.gz.sha256sum) / 440cf7add0aee27ebc93fada965523c1dc2e0ab340d4348da2215737fc0d76ad) - [Linux i386](https://get.helm.sh/helm-v3.19.0-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-386.tar.gz.sha256sum) / ca0329cd1b09267e7c63c563e32462265949c31512b537dd6615d0b5190040fc) - [Linux ppc64le](https://get.helm.sh/helm-v3.19.0-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-ppc64le.tar.gz.sha256sum) / f57ea04d7fa62cc3e90a831eb67edb1400c810df6083875bee3a7c195a795ce4) - [Linux s390x](https://get.helm.sh/helm-v3.19.0-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-s390x.tar.gz.sha256sum) / 0dff2f249f71690e3b420ebb5efc573eb26a51b4a614c4391c8c7fa3e47863f2) - [Linux riscv64](https://get.helm.sh/helm-v3.19.0-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v3.19.0-linux-riscv64.tar.gz.sha256sum) / 978af545a3d72a253ce1d4c03c9febb509a239a48b2581107e548883ab61a227) - [Windows amd64](https://get.helm.sh/helm-v3.19.0-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v3.19.0-windows-amd64.zip.sha256sum) / 6488630c2e5d5945ed990fa02fd9e99f9c6792cdbcd79eb264b6cfb90179d2d1) - [Windows arm64](https://get.helm.sh/helm-v3.19.0-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v3.19.0-windows-arm64.zip.sha256sum) / 488f7530a1776da1b46b14e988bf305c9d7419c78e7e73aeb92f198a41c9ef6b) This release was signed with `208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155` and can be found at [@&#8203;scottrigby](https://github.com/scottrigby) [keybase account](https://keybase.io/r6by). Please use the attached signatures for verifying this release using `gpg`. The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3) on any system with `bash`. #### What's Next - 3.19.1 will contain only bug fixes. - 3.20.0 is the next feature release. #### Changelog - bump version to v3.19.0 [`3d8990f`](https://github.com/helm/helm/commit/3d8990f0836691f0229297773f3524598f46bda6) (Scott Rigby) - fix: use username and password if provided [`9a54bf1`](https://github.com/helm/helm/commit/9a54bf1df6245232aff6235ebc5da7616f06afa7) (Evans Mungai) - chore(deps): bump the k8s-io group with 7 updates [`5af0f68`](https://github.com/helm/helm/commit/5af0f68365132bf40d6da38eac87cb94d113b5c3) (dependabot\[bot]) - chore(deps): bump github.com/spf13/cobra from 1.9.1 to 1.10.1 [`e485606`](https://github.com/helm/helm/commit/e485606fa6c637f9d33c85d449f5add15fa75f64) (dependabot\[bot]) - chore(deps): bump github.com/stretchr/testify from 1.11.0 to 1.11.1 [`6355c3d`](https://github.com/helm/helm/commit/6355c3de11a76acc934348b2b2365c795327517b) (dependabot\[bot]) - chore(deps): bump github.com/stretchr/testify from 1.10.0 to 1.11.0 [`ec61f66`](https://github.com/helm/helm/commit/ec61f666994ca6572278ff05a45850606d18f12d) (dependabot\[bot]) - fix(helm-lint): fmt [`b278020`](https://github.com/helm/helm/commit/b27802031110bcfcaf0b685f7f3efda8a309ce8c) (Isaiah Lewis) - fix(helm-lint): Add TLSClientConfig [`d33ac5e`](https://github.com/helm/helm/commit/d33ac5e44b4eb884d67141b00753817b091054ca) (Isaiah Lewis) - fix(helm-lint): Add HTTP/HTTPS URL support for json schema references [`8543709`](https://github.com/helm/helm/commit/854370978eb4664ed75e1918df733ecf1503e904) (Isaiah Lewis) - chore(deps): bump the k8s-io group with 7 updates [`89a3f90`](https://github.com/helm/helm/commit/89a3f90e7545857edbfbb7d46af1796f0fee7097) (dependabot\[bot]) - fix: go mod tidy for v3 [`da4c583`](https://github.com/helm/helm/commit/da4c583145cf4de6a291e81b499ba53785739c2b) (Terry Howe) - chore(deps): bump golang.org/x/crypto from 0.40.0 to 0.41.0 [`e40b1b3`](https://github.com/helm/helm/commit/e40b1b3b367cae275d823eadcfcef43729e16260) (dependabot\[bot]) - chore(deps): bump golang.org/x/term from 0.33.0 to 0.34.0 [`a27e9db`](https://github.com/helm/helm/commit/a27e9db724540bc53b066dff7d80d075a9fa86d8) (dependabot\[bot]) - fix Chart.yaml handling [`f13afaa`](https://github.com/helm/helm/commit/f13afaacd6f8f9dca4ad914d87fabbe129692eda) (Matt Farina) - Handle messy index files [`039b0b1`](https://github.com/helm/helm/commit/039b0b18d3c83c9aa3a80da67f3cf1c2d965a598) (Matt Farina) - chore(deps): bump github.com/containerd/containerd from 1.7.27 to 1.7.28 [`bec98a9`](https://github.com/helm/helm/commit/bec98a91aa1f810220f4fd2a7f06b155afe68970) (dependabot\[bot]) - json schema fix [`6d9509a`](https://github.com/helm/helm/commit/6d9509aadcfb44aaaa6fc6528443815343a551b4) (Robert Sirchia) - fix: k8s version parsing to match original [`807225e`](https://github.com/helm/helm/commit/807225ed62b2901fcbaf56923111d9d7f9204a59) (Borys Hulii) - chore(deps): bump sigs.k8s.io/yaml from 1.5.0 to 1.6.0 [`cbbd569`](https://github.com/helm/helm/commit/cbbd569aba384d6bf04328645d8befd8555c7879) (dependabot\[bot]) - Do not explicitly set SNI in HTTPGetter [`5e8ff72`](https://github.com/helm/helm/commit/5e8ff72b71fab9bda848bc2c980b2139401e1057) (Terry Howe) - chore(deps): bump github.com/spf13/pflag from 1.0.6 to 1.0.7 [`5b5fb5b`](https://github.com/helm/helm/commit/5b5fb5b6832fd210e6dfeda01ef91d6eea73abe4) (dependabot\[bot]) - chore(deps): bump the k8s-io group with 7 updates [`d12538a`](https://github.com/helm/helm/commit/d12538a23df05acb027f319766dde19a90f0c78a) (dependabot\[bot]) - chore(deps): bump golang.org/x/crypto from 0.39.0 to 0.40.0 [`303f803`](https://github.com/helm/helm/commit/303f8031bdfbd18fa8630def8199957fa4784a20) (dependabot\[bot]) - chore(deps): bump golang.org/x/term from 0.32.0 to 0.33.0 [`abcc2ed`](https://github.com/helm/helm/commit/abcc2edc2722406928df731dfac8981032d7831a) (dependabot\[bot]) - chore(deps): bump golang.org/x/text from 0.26.0 to 0.27.0 [`521c67b`](https://github.com/helm/helm/commit/521c67b3588a37ccb1e19fc90130813587015291) (dependabot\[bot]) - Disabling linter due to unknown issue [`227c9cb`](https://github.com/helm/helm/commit/227c9cb6b6c4ba190fa4064c0dba91f8a3106b79) (Matt Farina) - Updating link handling [`4389fa6`](https://github.com/helm/helm/commit/4389fa639a4d8e6836fa8df9bb70dd69c2820c12) (Matt Farina) - Bump github.com/Masterminds/semver/v3 from 3.3.0 to 3.3.1 [`372e403`](https://github.com/helm/helm/commit/372e40376a15568ba1d9920beb9ab4fe91b90a55) (dependabot\[bot]) - build(deps): bump the k8s-io group with 7 updates [`4fa5a64`](https://github.com/helm/helm/commit/4fa5a64127532cb9e69986f584aef491f36a925b) (dependabot\[bot]) - build(deps): bump sigs.k8s.io/yaml from 1.4.0 to 1.5.0 [`6284ed8`](https://github.com/helm/helm/commit/6284ed853892c95b87d08a08d64199af63ed3e13) (dependabot\[bot]) - fix: user username password for login [`2c55a4e`](https://github.com/helm/helm/commit/2c55a4e8ce483fe1a03d7afa46a89e26852bc3c5) (Terry Howe) - Update pkg/registry/transport.go [`a16e986`](https://github.com/helm/helm/commit/a16e986d4e184b4e065968c5f5c30198a12d880e) (Terry Howe) - Update pkg/registry/transport.go [`cea26d8`](https://github.com/helm/helm/commit/cea26d8bcac27f888ebb43a8ac8fe87f5851d380) (Terry Howe) - fix: add debug logging to oci transport [`b52bb41`](https://github.com/helm/helm/commit/b52bb41484bca2eab616aed83aa922cbb5ef1e3b) (Terry Howe) - build(deps): bump golang.org/x/crypto from 0.38.0 to 0.39.0 [`45075cf`](https://github.com/helm/helm/commit/45075cf9434456c8d1cd59a6355265e958b71b2f) (dependabot\[bot]) - build(deps): bump golang.org/x/text from 0.25.0 to 0.26.0 [`73a7826`](https://github.com/helm/helm/commit/73a78263956bf738008e158afb8d641acbb8f3b9) (dependabot\[bot]) - fix: legacy docker support broken for login [`733f94c`](https://github.com/helm/helm/commit/733f94c86a98f2fc4a12eba510e26615d4b8aa59) (Terry Howe) - fix: plugin installer test with no Internet [`fc36041`](https://github.com/helm/helm/commit/fc360417024f4734e5b7356385512a08a31c743e) (Terry Howe) - Handle an empty registry config file. [`cfe8cef`](https://github.com/helm/helm/commit/cfe8cef46f04f36ca33e8696573e243d14e17e79) (Matt Farina) - Prevent fetching newReference again as we have in calling method [`c33215d`](https://github.com/helm/helm/commit/c33215d765e291bc9321984d4f60a0182c738938) (Benoit Tigeot) - Prevent failure when resolving version tags in oras memory store [`f552b67`](https://github.com/helm/helm/commit/f552b672305a420b54a725185f98e34e51fbd7ba) (Benoit Tigeot) - fix(client): skipnode utilization for PreCopy [`a18a52e`](https://github.com/helm/helm/commit/a18a52e8982b399101f7f20e2473de8514e85226) (Brandt Keller) - test: Skip instead of returning early. looks more intentional [`fedf502`](https://github.com/helm/helm/commit/fedf5024d60bcb4efce9cf7f6f1b7bca642a66eb) (Jesse Simpson) - test: tests repo stripping functionality [`fe512ba`](https://github.com/helm/helm/commit/fe512bae439b5271dd7d2cdb75fadf3c39abd800) (Jesse Simpson) - test: include tests for Login based on different protocol prefixes [`099a9e1`](https://github.com/helm/helm/commit/099a9e18f30db9c90a3a5e52b2af6dd630a6d757) (Jesse Simpson) - fix(client): layers now returns manifest - remove duplicate from descriptors [`b07ab77`](https://github.com/helm/helm/commit/b07ab77da3a2d20508b8e775981e233a81d4c753) (Brandt Keller) - fix(client): return nil on non-allowed media types [`c225c12`](https://github.com/helm/helm/commit/c225c124ac76eedc3ca6e013df40da8d2c50650d) (Brandt Keller) - Fix 3.18.0 regression: registry login with scheme [`c0f3ace`](https://github.com/helm/helm/commit/c0f3ace52d974b7465f33079bbf54ed961f875f1) (Scott Rigby) - Update pkg/plugin/plugin.go [`dce60ad`](https://github.com/helm/helm/commit/dce60adb5141695b9deab023dbfa25bba681d8fa) (Benoit Tigeot) - Update pkg/plugin/plugin.go [`cda0865`](https://github.com/helm/helm/commit/cda0865d64a4deec682fd044aa4412eb9ab643db) (Benoit Tigeot) - Wait for Helm v4 before raising when platformCommand and Command are set [`5d9d9a0`](https://github.com/helm/helm/commit/5d9d9a0fb8c1700c5aa9051e3768dcdabfed642d) (Benoit Tigeot) - Revert "fix (helm) : toToml\` renders int as float \[ backport to v3 ]" [`c5249c1`](https://github.com/helm/helm/commit/c5249c1f8d83d44081afee41efeac3ee36d6e9bc) (Matt Farina) - build(deps): bump the k8s-io group with 7 updates [`5b0520d`](https://github.com/helm/helm/commit/5b0520d6b323b291546cb6fbc4dc0f76b570a6eb) (dependabot\[bot]) - chore: update generalization warning message [`afefca8`](https://github.com/helm/helm/commit/afefca8b2dcb3c220e24075e8dabf0cffd170daf) (Feng Cao) - build(deps): bump oras.land/oras-go/v2 from 2.5.0 to 2.6.0 [`8d6d27c`](https://github.com/helm/helm/commit/8d6d27c26aad581c3da61f7e67786949c9201fcd) (dependabot\[bot]) - build(deps): bump the k8s-io group with 7 updates [`502c0d5`](https://github.com/helm/helm/commit/502c0d5f5b8563be076de69be85f8e0add11b69c) (dependabot\[bot]) - build(deps): bump golang.org/x/crypto from 0.37.0 to 0.38.0 [`92be9ac`](https://github.com/helm/helm/commit/92be9ac0c8abab27efd740be6a671d6e8dd535fd) (dependabot\[bot]) - fix: move warning to top of block [`eb5b6d5`](https://github.com/helm/helm/commit/eb5b6d50474842db17330b11e0db70077e1c4510) (Feng Cao) - fix: govulncheck workflow [`6b15f26`](https://github.com/helm/helm/commit/6b15f26bd45c2856b36bdf3e8c32b44595e4580f) (Matthieu MOREL) - fix: replace fmt warning with slog [`6b5c944`](https://github.com/helm/helm/commit/6b5c94475db950a981523344029f0a7c620a2e32) (Feng Cao) - fix: add warning when ignore repo flag [`247bf7c`](https://github.com/helm/helm/commit/247bf7c2e0c591554b6cfd4c2f62cb2700b034ee) (Feng Cao) - bump version to v3.18.0 [`9404459`](https://github.com/helm/helm/commit/94044595c79ddf1311a4cd3df0353fe62a7ed633) (Robert Sirchia) - backport [#&#8203;30673](https://github.com/helm/helm/issues/30673) to dev-v3 [`0a800e8`](https://github.com/helm/helm/commit/0a800e84b033ae03fc31a46215378ac7761cb9c5) (Gerard Nguyen) - feat: add httproute from gateway-api to create chart template [`bd1b67b`](https://github.com/helm/helm/commit/bd1b67b082122ad1264d07c5d28bbc4c4171b826) (Henrik Gerdes) **Full Changelog**: <https://github.com/helm/helm/compare/v3.18.6...v3.19.0> </details> <details> <summary>bitnami/sealed-secrets (kubeseal)</summary> ### [`v0.38.4`](https://github.com/bitnami/sealed-secrets/blob/HEAD/RELEASE-NOTES.md#v0384) - Incomplete release for credentials problems ### [`v0.36.0`](https://github.com/bitnami/sealed-secrets/blob/HEAD/RELEASE-NOTES.md#v0360) - \[Security] Preserve scope during Sealed Secret rotation ([#&#8203;1886](https://github.com/bitnami/sealed-secrets/pull/1886)) - \[Security] Throw an error in case of inconsistencies in the Sealed Secrets ([#&#8203;1885](https://github.com/bitnami/sealed-secrets/pull/1885)) - Bump distroless/static from `972618c` to `d90359c` in /docker ([#&#8203;1884](https://github.com/bitnami/sealed-secrets/pull/1884)) - Set up OCI GH to release helm chart ([#&#8203;1883](https://github.com/bitnami/sealed-secrets/pull/1883)) ### [`v0.34.0`](https://github.com/bitnami/sealed-secrets/blob/HEAD/RELEASE-NOTES.md#v0340) - Add kseal to README ([#&#8203;1852)](https://github.com/bitnami/sealed-secrets/pull/1852)) - Bump golang version to the latest available 1.24 ([#&#8203;1854](https://github.com/bitnami/sealed-secrets/pull/1854)) - Bump k8s.io/code-generator from 0.34.2 to 0.34.3 ([#&#8203;1850](https://github.com/bitnami/sealed-secrets/pull/1850)) - Bump k8s.io/client-go from 0.34.2 to 0.34.3 ([#&#8203;1848](https://github.com/bitnami/sealed-secrets/pull/1848)) - Bump github.com/onsi/ginkgo/v2 from 2.27.2 to 2.27.3 ([#&#8203;1843](https://github.com/bitnami/sealed-secrets/pull/1843)) - Bump distroless/static from `87bce11` to `4b2a093` in /docker ([#&#8203;1846](https://github.com/bitnami/sealed-secrets/pull/1846)) - Bump github.com/onsi/gomega from 1.38.2 to 1.38.3 ([#&#8203;1844](https://github.com/bitnami/sealed-secrets/pull/1844)) - Bump golang.org/x/crypto from 0.45.0 to 0.46.0 ([#&#8203;1845](https://github.com/bitnami/sealed-secrets/pull/1845)) - Make controllers kubeclient QPS & Burst configurable. ([#&#8203;1834](https://github.com/bitnami/sealed-secrets/pull/1834)) - use default method to watch for key secrets ([#&#8203;1831](https://github.com/bitnami/sealed-secrets/pull/1831)) - Bump golang.org/x/crypto from 0.44.0 to 0.45.0 in the go\_modules group across 1 directory ([#&#8203;1840](https://github.com/bitnami/sealed-secrets/pull/1840)) - Bump k8s.io/code-generator from 0.34.1 to 0.34.2 ([#&#8203;1839](https://github.com/bitnami/sealed-secrets/pull/1839)) - Bump golang.org/x/crypto from 0.43.0 to 0.44.0 ([#&#8203;1835](https://github.com/bitnami/sealed-secrets/pull/1835)) - Bump k8s.io/client-go from 0.34.1 to 0.34.2 ([#&#8203;1837](https://github.com/bitnami/sealed-secrets/pull/1837)) ### [`v0.33.1`](https://github.com/bitnami/sealed-secrets/blob/HEAD/RELEASE-NOTES.md#v0331) - Release done to fix missing helm chart code. ### [`v0.32.2`](https://github.com/bitnami/sealed-secrets/blob/HEAD/RELEASE-NOTES.md#v0322) - Fix controller yaml ([#&#8203;1811](https://github.com/bitnami/sealed-secrets/pull/1811)) - Bump k8s.io/code-generator from 0.33.4 to 0.34.1 ([#&#8203;1809](https://github.com/bitnami/sealed-secrets/pull/1809)) ### [`v0.32.1`](https://github.com/bitnami/sealed-secrets/blob/HEAD/RELEASE-NOTES.md#v0321) - Bump distroless version ([#&#8203;1804](https://github.com/bitnami/sealed-secrets/pull/1804)) </details> <details> <summary>kubernetes-sigs/kustomize (kustomize)</summary> ### [`v5.8.1`](https://github.com/kubernetes-sigs/kustomize/releases/tag/kustomize/v5.8.1) #### Introduction This release completes a fix for namespace propagation that occurred in v5.8.0. [#&#8203;6031 (comment)](https://github.com/kubernetes-sigs/kustomize/issues/6031#issuecomment-3594321206) Also addressed the breaking changes introduced in helm v4. [#&#8203;6016](https://github.com/kubernetes-sigs/kustomize/issues/6016) #### fix [#&#8203;5990](https://github.com/kubernetes-sigs/kustomize/issues/5990): fix: allow empty patches files [#&#8203;6016](https://github.com/kubernetes-sigs/kustomize/issues/6016): fix: support helm v4 beside v3 [#&#8203;6038](https://github.com/kubernetes-sigs/kustomize/issues/6038): Fix a failing test [#&#8203;6044](https://github.com/kubernetes-sigs/kustomize/issues/6044): Fix namespace propagation problem at v5.8.0 #### Dependencies [#&#8203;6057](https://github.com/kubernetes-sigs/kustomize/issues/6057): Upgrade json-patch to v4.13.0 to remove pkg/errors dependency #### chore [#&#8203;6065](https://github.com/kubernetes-sigs/kustomize/issues/6065): Update kyaml to v0.21.1 [#&#8203;6066](https://github.com/kubernetes-sigs/kustomize/issues/6066): Update cmd/config to v0.21.1 [#&#8203;6067](https://github.com/kubernetes-sigs/kustomize/issues/6067): Update api to v0.21.1 ### [`v5.8.0`](https://github.com/kubernetes-sigs/kustomize/releases/tag/kustomize/v5.8.0) ### IMPORTANT NOTICE: REGRESSION Due to the new features introduced in this release, a regression has occurred in the functionality that propagates namespaces to child kustomizations. We are currently preparing a patch release, so please refrain from making changes to this version. [#&#8203;6031 (comment)](https://github.com/kubernetes-sigs/kustomize/issues/6031#issuecomment-3594321206) ### Highlights ##### implements to replacements value in the structured data Now, We can edit yaml/json in yaml manifests with replacements transformer. See [#&#8203;5679](https://github.com/kubernetes-sigs/kustomize/issues/5679) ##### For example ```yaml ## source apiVersion: v1 kind: ConfigMap metadata: name: source-configmap data: HOSTNAME: www.example.com --- apiVersion: v1 kind: ConfigMap metadata: name: target-configmap data: config.json: |- {"config": { "id": "42", "hostname": "REPLACE_TARGET_HOSTNAME" }} ``` ```yaml ## replacement replacements: - source: kind: ConfigMap name: source-configmap fieldPath: data.HOSTNAME targets: - select: kind: ConfigMap name: target-configmap fieldPaths: - data.config\.json.config.hostname ``` ##### fix: Propagate Namespace correctly to Helm The long-standing bug where kustomize's namespace transformer did not pass namespaces to helmCharts has been fixed. See [#&#8203;5940](https://github.com/kubernetes-sigs/kustomize/issues/5940) ##### For example ```yaml ## define namespace namespace: any-namespace helmCharts: - name: minecraft repo: https://kubernetes-charts.storage.googleapis.com version: v1.2.0 # namespace: any-namespace ## propagates without additional namespace specific valuesFile: values.yaml ``` #### Feature [#&#8203;5679](https://github.com/kubernetes-sigs/kustomize/issues/5679): implements to replacements value in the structured data [#&#8203;5863](https://github.com/kubernetes-sigs/kustomize/issues/5863): Add regex support for Replacement selectors [#&#8203;5930](https://github.com/kubernetes-sigs/kustomize/issues/5930): feat: add PatchArgs API type to populate patch options #### fix [#&#8203;5940](https://github.com/kubernetes-sigs/kustomize/issues/5940): fix: Propagate Namespace correctly to Helm [#&#8203;5971](https://github.com/kubernetes-sigs/kustomize/issues/5971): fix: performance recession when propagating namespace to helm [#&#8203;5942](https://github.com/kubernetes-sigs/kustomize/issues/5942): fix fnplugin storagemounts validation [#&#8203;5958](https://github.com/kubernetes-sigs/kustomize/issues/5958): fix: make AbsorbAll conflict error more verbose [#&#8203;5961](https://github.com/kubernetes-sigs/kustomize/issues/5961): refactor: nested format string [#&#8203;5967](https://github.com/kubernetes-sigs/kustomize/issues/5967): Fix infinite loop in HTTP client by validating URLs before requests [#&#8203;5985](https://github.com/kubernetes-sigs/kustomize/issues/5985): fix(kyaml/yaml): minor nil safety fix for RNode.Content etc [#&#8203;5991](https://github.com/kubernetes-sigs/kustomize/issues/5991): Fix duplicate key error when adding multiple labels with --without-selector #### Dependencies [#&#8203;5962](https://github.com/kubernetes-sigs/kustomize/issues/5962): chore: update dependencies from security alert [#&#8203;5959](https://github.com/kubernetes-sigs/kustomize/issues/5959): update go 1.24.6 #### chore [#&#8203;6007](https://github.com/kubernetes-sigs/kustomize/issues/6007): Update kyaml to v0.21.0 [#&#8203;6008](https://github.com/kubernetes-sigs/kustomize/issues/6008): Update cmd/config to v0.21.0 [#&#8203;6009](https://github.com/kubernetes-sigs/kustomize/issues/6009): Update api to v0.21.0 ### [`v5.7.1`](https://github.com/kubernetes-sigs/kustomize/releases/tag/kustomize/v5.7.1) This release introduces code to replace the shlex library used for parsing arguments in the exec plugin. If any existing manifests become corrupted, please file an issue. discussion: [kubernetes/kubernetes#132593 (comment)](https://github.com/kubernetes/kubernetes/pull/132593#discussion_r2178116543) #### Dependencies [#&#8203;5943](https://github.com/kubernetes-sigs/kustomize/issues/5943): drop shlex dependency #### Chore [#&#8203;5948](https://github.com/kubernetes-sigs/kustomize/issues/5948): Update kyaml to v0.20.1 [#&#8203;5949](https://github.com/kubernetes-sigs/kustomize/issues/5949): Update cmd/config to v0.20.1 [#&#8203;5950](https://github.com/kubernetes-sigs/kustomize/issues/5950): Update api to v0.20.1 </details> <details> <summary>prometheus-community/helm-charts (prometheus)</summary> ### [`v28.16.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.16.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.15.0...prometheus-28.16.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update Helm release prometheus-node-exporter to 4.53.\* by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6814](https://github.com/prometheus-community/helm-charts/pull/6814) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.18.0...prometheus-28.16.0> ### [`v28.15.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.15.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.14.1...prometheus-28.15.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update dependency prometheus/prometheus to v3.11.0 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6802](https://github.com/prometheus-community/helm-charts/pull/6802) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.16.1...prometheus-28.15.0> ### [`v28.14.1`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.14.1) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.14.0...prometheus-28.14.1) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update quay.io/prometheus-operator/prometheus-config-reloader Docker tag to v0.90.1 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6786](https://github.com/prometheus-community/helm-charts/pull/6786) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/prometheus-operator-crds-28.0.1...prometheus-28.14.1> ### [`v28.14.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.14.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.13.0...prometheus-28.14.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update prometheus dependency non-major updates by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6751](https://github.com/prometheus-community/helm-charts/pull/6751) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/prometheus-snmp-exporter-9.13.0...prometheus-28.14.0> ### [`v28.13.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.13.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.12.0...prometheus-28.13.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Add value to use distroless image variant by [@&#8203;erpel](https://github.com/erpel) in [#&#8203;6677](https://github.com/prometheus-community/helm-charts/pull/6677) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.4.3...prometheus-28.13.0> ### [`v28.12.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.12.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.11.0...prometheus-28.12.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update Helm release prometheus-node-exporter to 4.52.\* by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6685](https://github.com/prometheus-community/helm-charts/pull/6685) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.4.1...prometheus-28.12.0> ### [`v28.11.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.11.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.10.1...prometheus-28.11.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update Helm release kube-state-metrics to 7.2.\* by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6683](https://github.com/prometheus-community/helm-charts/pull/6683) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/prometheus-node-exporter-4.52.0...prometheus-28.11.0> ### [`v28.10.1`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.10.1) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.10.0...prometheus-28.10.1) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update quay.io/oauth2-proxy/oauth2-proxy Docker tag to v7.14.3 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6678](https://github.com/prometheus-community/helm-charts/pull/6678) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/kube-state-metrics-7.2.0...prometheus-28.10.1> ### [`v28.10.0`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.10.0) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.9.1...prometheus-28.10.0) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] Update dependency prometheus/prometheus to v3.10.0 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;6676](https://github.com/prometheus-community/helm-charts/pull/6676) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/prometheus-nginx-exporter-1.19.3...prometheus-28.10.0> ### [`v28.9.1`](https://github.com/prometheus-community/helm-charts/releases/tag/prometheus-28.9.1) [Compare Source](https://github.com/prometheus-community/helm-charts/compare/prometheus-28.9.0...prometheus-28.9.1) Prometheus is a monitoring system and time series database. #### What's Changed - \[prometheus] harden NOTES when deps absent by [@&#8203;firasmosbehi](https://github.com/firasmosbehi) in [#&#8203;6558](https://github.com/prometheus-community/helm-charts/pull/6558) **Full Changelog**: <https://github.com/prometheus-community/helm-charts/compare/prometheus-redis-exporter-6.21.0...prometheus-28.9.1> </details> <details> <summary>anchore/syft (syft)</summary> ### [`v1.51.0`](https://github.com/anchore/syft/releases/tag/v1.51.0) ##### Added Features - detect native Go FIPS 140 mode in binaries \[PR [#&#8203;5155](https://github.com/anchore/syft/pull/5155) [@&#8203;gunnypatel](https://github.com/gunnypatel)] - add extended-stdlib scope and module patterns for symbol capture \[PR [#&#8203;5154](https://github.com/anchore/syft/pull/5154) [@&#8203;wagoodman](https://github.com/wagoodman)] ##### Bug Fixes - Cleanup snap temporary directories \[PR [#&#8203;5117](https://github.com/anchore/syft/pull/5117) [@&#8203;spiffcs](https://github.com/spiffcs)] - add correct CPE vendor/product candidates for Git for Windows PE binary \[PR [#&#8203;5156](https://github.com/anchore/syft/pull/5156) [@&#8203;westonsteimel](https://github.com/westonsteimel)] - javascript-package-cataloger creates phantom `<name>@unknown` packages for subpath or export-map stub package.json files \[Issue [#&#8203;5118](https://github.com/anchore/syft/issues/5118)] - Syft generates incorrect PURLs for legacy JARs missing Maven metadata, causing Grype false negatives \[Issue [#&#8203;4598](https://github.com/anchore/syft/issues/4598)] \[PR [#&#8203;5146](https://github.com/anchore/syft/pull/5146) [@&#8203;ankit090701](https://github.com/ankit090701)] - When scanning an image, syft only reports one file per set of hardlinks, leading to wrong SPDX packageVerificationCode \[Issue [#&#8203;5019](https://github.com/anchore/syft/issues/5019)] \[PR [#&#8203;5029](https://github.com/anchore/syft/pull/5029) [@&#8203;wagoodman](https://github.com/wagoodman)] - Support deno binary latest and some old versions \[Issue [#&#8203;5057](https://github.com/anchore/syft/issues/5057)] \[PR [#&#8203;5084](https://github.com/anchore/syft/pull/5084) [@&#8203;ychampion](https://github.com/ychampion)] - Update install methods in README.md \[Issue [#&#8203;3198](https://github.com/anchore/syft/issues/3198)] ##### Dependencies 9 dependency changes (9 updated). 2 vulnerabilities remediated. **🟢 Remediated (2)** - [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm) (High) — github.com/go-git/go-git/v5 - [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j) (Medium) — github.com/go-git/go-git/v5 <details> <summary>Updated (9 packages)</summary> - github.com/diskfs/go-diskfs `v1.9.3` → `v1.9.4` - github.com/go-git/go-billy/v5 `v5.9.0` → `v5.9.1` - github.com/go-git/go-git/v5 `v5.19.1` → `v5.19.2` **(🟢 remediated [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm), [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j))** - github.com/jedib0t/go-pretty/v6 `v6.8.1` → `v6.8.3` - github.com/klauspost/compress `v1.19.0` → `v1.19.1` - github.com/magiconair/properties `v1.8.10` → `v1.18.11` - github.com/ulikunitz/xz `v0.5.15` → `v0.5.16` - go.yaml.in/yaml/v3 `v3.0.4` → `v3.0.5` - modernc.org/sqlite `v1.54.0` → `v1.55.0` </details> **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.50.0...v1.51.0)** ### [`v1.50.0`](https://github.com/anchore/syft/releases/tag/v1.50.0) ##### Added Features - Add bun binary classifier \[PR [#&#8203;5103](https://github.com/anchore/syft/pull/5103) [@&#8203;rezmoss](https://github.com/rezmoss)] ##### Bug Fixes - Fix Cargo PURLs for local workspace packages \[PR [#&#8203;5105](https://github.com/anchore/syft/pull/5105) [@&#8203;3nesdeniz](https://github.com/3nesdeniz)] - Decode golang symbols \[PR [#&#8203;5089](https://github.com/anchore/syft/pull/5089) [@&#8203;wagoodman](https://github.com/wagoodman)] - CPE vendor field incorrectly includes publisher URL for SUSE RPM packages \[Issue [#&#8203;5073](https://github.com/anchore/syft/issues/5073)] \[PR [#&#8203;5081](https://github.com/anchore/syft/pull/5081) [@&#8203;Eljees](https://github.com/Eljees)] - apk-db-cataloger silently drops the entire APK catalog when one installed-DB field exceeds 64 KB \[Issue [#&#8203;5094](https://github.com/anchore/syft/issues/5094)] \[PR [#&#8203;5100](https://github.com/anchore/syft/pull/5100) [@&#8203;cyphercodes](https://github.com/cyphercodes)] ##### Additional Changes - package-lock.json v1: nested dependencies entries are never cataloged (flat top-level iteration only) \[Issue [#&#8203;5101](https://github.com/anchore/syft/issues/5101)] \[PR [#&#8203;5108](https://github.com/anchore/syft/pull/5108) [@&#8203;Eljees](https://github.com/Eljees)] - consider vendored golang packages in module attribution \[PR [#&#8203;5093](https://github.com/anchore/syft/pull/5093) [@&#8203;kzantow](https://github.com/kzantow)] - Fix inverted bounds check dropping every Erlang string with a backslash \[PR [#&#8203;5110](https://github.com/anchore/syft/pull/5110) [@&#8203;arpitjain099](https://github.com/arpitjain099)] ##### Dependencies 14 dependency changes (14 updated). 1 vulnerability remediated. **🟢 Remediated (1)** - [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc <details> <summary>Updated (14 packages)</summary> - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0` - github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58` - github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0` - github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3` - github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0` - go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0` - google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a` - google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a` - google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))** - modernc.org/cc/v4 `v4.28.4` → `v4.29.0` - modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6` - modernc.org/gc/v3 `v3.1.3` → `v3.1.4` - modernc.org/libc `v1.73.4` → `v1.74.1` - modernc.org/sqlite `v1.53.0` → `v1.54.0` </details> **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.49.0...v1.50.0)** ### [`v1.49.0`](https://github.com/anchore/syft/releases/tag/v1.49.0) ##### Added Features - Support for `application/vnd.oci.image.index.v1+json` manifests in root OCI layout \[Issue [#&#8203;1545](https://github.com/anchore/syft/issues/1545)] \[PR [#&#8203;5074](https://github.com/anchore/syft/pull/5074) [@&#8203;jasonpaulos](https://github.com/jasonpaulos)] ##### Bug Fixes - Misinterpretation of Multiple replace Directives in Golang \[Issue [#&#8203;2721](https://github.com/anchore/syft/issues/2721)] \[PR [#&#8203;5069](https://github.com/anchore/syft/pull/5069) [@&#8203;ychampion](https://github.com/ychampion)] ##### Dependencies 16 dependency changes (16 updated). <details> <summary>Updated (16 packages)</summary> - github.com/anchore/go-rpmdb `v0.1.0` → `v0.2.0` - github.com/anchore/stereoscope `v0.2.2` → `v0.3.0` - github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3` - github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible` - github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23` - github.com/moby/moby/api `v1.54.2` → `v1.55.0` - github.com/moby/moby/client `v0.4.1` → `v0.5.0` - github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3` - golang.org/x/crypto `v0.53.0` → `v0.54.0` - golang.org/x/mod `v0.37.0` → `v0.38.0` - golang.org/x/net `v0.56.0` → `v0.57.0` - golang.org/x/sync `v0.21.0` → `v0.22.0` - golang.org/x/sys `v0.46.0` → `v0.47.0` - golang.org/x/term `v0.44.0` → `v0.45.0` - golang.org/x/text `v0.38.0` → `v0.40.0` - golang.org/x/tools `v0.47.0` → `v0.48.0` </details> **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.48.0...v1.49.0)** ### [`v1.48.0`](https://github.com/anchore/syft/releases/tag/v1.48.0) ##### Added Features - emit dependency relationships from mix.lock \[PR [#&#8203;4985](https://github.com/anchore/syft/pull/4985) [@&#8203;cgreeno](https://github.com/cgreeno)] - add safe tensor model type to SBOM output \[PR [#&#8203;4844](https://github.com/anchore/syft/pull/4844) [@&#8203;spiffcs](https://github.com/spiffcs)] - Capture golang binary symbols \[PR [#&#8203;4988](https://github.com/anchore/syft/pull/4988) [@&#8203;spiffcs](https://github.com/spiffcs)] - Detect Ubuntu Pro/ESM extended support \[PR [#&#8203;5028](https://github.com/anchore/syft/pull/5028) [@&#8203;wagoodman](https://github.com/wagoodman)] - Add scan duration timer to Syft \[Issue [#&#8203;4587](https://github.com/anchore/syft/issues/4587)] \[PR [#&#8203;4858](https://github.com/anchore/syft/pull/4858) [@&#8203;ChrisJr404](https://github.com/ChrisJr404)] - Support for `vcpkg` \[Issue [#&#8203;2110](https://github.com/anchore/syft/issues/2110)] \[PR [#&#8203;4081](https://github.com/anchore/syft/pull/4081) [@&#8203;gabetrau](https://github.com/gabetrau)] - Add macOS `.app` cataloger \[Issue [#&#8203;4010](https://github.com/anchore/syft/issues/4010)] \[PR [#&#8203;4490](https://github.com/anchore/syft/pull/4490) [@&#8203;rezmoss](https://github.com/rezmoss)] - Add support for Kerberos 5 library cataloging \[Issue [#&#8203;4780](https://github.com/anchore/syft/issues/4780)] \[PR [#&#8203;4781](https://github.com/anchore/syft/pull/4781) [@&#8203;nadimz](https://github.com/nadimz)] - Include date of scan in results \[Issue [#&#8203;3910](https://github.com/anchore/syft/issues/3910)] ##### Bug Fixes - use printf instead of echo to fix ANSI color output \[PR [#&#8203;4978](https://github.com/anchore/syft/pull/4978) [@&#8203;Jouini-Mohamed-Chaker](https://github.com/Jouini-Mohamed-Chaker)] - Strip peer-dep suffix from deno.lock npm keys \[PR [#&#8203;5055](https://github.com/anchore/syft/pull/5055) [@&#8203;Synvoya](https://github.com/Synvoya)] - Allow more PEP440-compliant characters in python versions \[PR [#&#8203;4964](https://github.com/anchore/syft/pull/4964) [@&#8203;kzantow](https://github.com/kzantow)] - PE case-insensitive extensions (Win32/ISO 9660 compatibility) \[PR [#&#8203;4996](https://github.com/anchore/syft/pull/4996) [@&#8203;activeobd](https://github.com/activeobd)] - Fix panic parsing a rockspec comment that ends at EOF \[PR [#&#8203;5053](https://github.com/anchore/syft/pull/5053) [@&#8203;arpitjain099](https://github.com/arpitjain099)] - Fix Debian point release detection \[PR [#&#8203;4997](https://github.com/anchore/syft/pull/4997) [@&#8203;OsamaSE](https://github.com/OsamaSE)] - Fix `mix.lock` git/path deps mislabeled as hex.pm packages with bogus PURLs \[PR [#&#8203;5041](https://github.com/anchore/syft/pull/5041) [@&#8203;Synvoya](https://github.com/Synvoya)] - npm redis client generates no CPE \[Issue [#&#8203;5011](https://github.com/anchore/syft/issues/5011)] \[PR [#&#8203;5012](https://github.com/anchore/syft/pull/5012) [@&#8203;rezmoss](https://github.com/rezmoss)] - Debug Docker images are running as nonroot user \[Issue [#&#8203;4113](https://github.com/anchore/syft/issues/4113)] \[PR [#&#8203;4608](https://github.com/anchore/syft/pull/4608) [@&#8203;spiffcs](https://github.com/spiffcs)] - libxml2 gets the wrong cpe vendor \[Issue [#&#8203;5015](https://github.com/anchore/syft/issues/5015)] \[PR [#&#8203;5016](https://github.com/anchore/syft/pull/5016) [@&#8203;rezmoss](https://github.com/rezmoss)] - wrong purl for spring-ldap-core dependency \[Issue [#&#8203;4030](https://github.com/anchore/syft/issues/4030)] \[PR [#&#8203;4908](https://github.com/anchore/syft/pull/4908) [@&#8203;jonasboos](https://github.com/jonasboos)] - Swift: CVEs missed by Grype when using Syft-generated SBOMs – missing group field breaks PURL matching \[Issue [#&#8203;3961](https://github.com/anchore/syft/issues/3961)] \[PR [#&#8203;4785](https://github.com/anchore/syft/pull/4785) [@&#8203;SAY-5](https://github.com/SAY-5)] - conanfile.txt: dependencies after a comment line in \[requires] are not detected \[Issue [#&#8203;5017](https://github.com/anchore/syft/issues/5017)] \[PR [#&#8203;5020](https://github.com/anchore/syft/pull/5020) [@&#8203;jfjrh2014](https://github.com/jfjrh2014)] - dotnet cataloger can't find packages from deps.json in linux elf single-file bundles \[Issue [#&#8203;4514](https://github.com/anchore/syft/issues/4514)] \[PR [#&#8203;4517](https://github.com/anchore/syft/pull/4517) [@&#8203;rezmoss](https://github.com/rezmoss)] - Go template sprig date functions not defined \[Issue [#&#8203;2372](https://github.com/anchore/syft/issues/2372)] \[PR [#&#8203;4644](https://github.com/anchore/syft/pull/4644) [@&#8203;sputnik-mac](https://github.com/sputnik-mac)] - CycloneDX BOM contains invalid externalReferences URL from unresolved Ruby gemspec interpolation (e.g. #{s.name}) \[Issue [#&#8203;4720](https://github.com/anchore/syft/issues/4720)] \[PR [#&#8203;4782](https://github.com/anchore/syft/pull/4782) [@&#8203;SAY-5](https://github.com/SAY-5)] ##### Dependencies 9 dependency changes (8 updated, 1 added). <details> <summary>Updated (8 packages)</summary> - github.com/bmatcuk/doublestar `v1.3.1` → `v8.8.8` - github.com/klauspost/compress `v1.18.6` → `v1.19.0` - golang.org/x/tools `v0.46.0` → `v0.47.0` - modernc.org/cc/v4 `v4.28.2` → `v4.28.4` - modernc.org/ccgo/v4 `v4.34.0` → `v4.34.4` - modernc.org/gc/v3 `v3.1.2` → `v3.1.3` - modernc.org/libc `v1.72.3` → `v1.73.4` - modernc.org/sqlite `v1.51.0` → `v1.53.0` </details> <details> <summary>Added (1 package)</summary> - howett.net/plist `v1.0.1` </details> **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.46.0...v1.47.1)** ### [`v1.46.0`](https://github.com/anchore/syft/releases/tag/v1.46.0) ##### Added Features - Add purl types to cataloger info cmd \[PR [#&#8203;4984](https://github.com/anchore/syft/pull/4984) [@&#8203;wagoodman](https://github.com/wagoodman)] - Python cataloger misses uv PEP 723 script lockfiles (`*.py.lock`) \[Issue [#&#8203;4949](https://github.com/anchore/syft/issues/4949)] \[PR [#&#8203;4950](https://github.com/anchore/syft/pull/4950) [@&#8203;ktopcuoglu](https://github.com/ktopcuoglu)] - Add bin classifier for Elastic agen \[Issue [#&#8203;4973](https://github.com/anchore/syft/issues/4973)] \[PR [#&#8203;4968](https://github.com/anchore/syft/pull/4968) [@&#8203;rezmoss](https://github.com/rezmoss)] - SPDX 3 Support \[Issue [#&#8203;4250](https://github.com/anchore/syft/issues/4250)] \[PR [#&#8203;4269](https://github.com/anchore/syft/pull/4269) [@&#8203;kzantow](https://github.com/kzantow)] - Add Deno support \[Issue [#&#8203;4417](https://github.com/anchore/syft/issues/4417)] \[PR [#&#8203;4523](https://github.com/anchore/syft/pull/4523) [@&#8203;rezmoss](https://github.com/rezmoss)] - Catalog Elastic Beats binary \[Issue [#&#8203;4961](https://github.com/anchore/syft/issues/4961)] \[PR [#&#8203;4969](https://github.com/anchore/syft/pull/4969) [@&#8203;rezmoss](https://github.com/rezmoss)] - Add binary classifiers for Elastic Beats \[Issue [#&#8203;4972](https://github.com/anchore/syft/issues/4972)] \[PR [#&#8203;4969](https://github.com/anchore/syft/pull/4969) [@&#8203;rezmoss](https://github.com/rezmoss)] - Catalog elastic-agent binary \[Issue [#&#8203;4962](https://github.com/anchore/syft/issues/4962)] - Add support for Bun lockfile (bun.lock) \[Issue [#&#8203;4617](https://github.com/anchore/syft/issues/4617)] \[PR [#&#8203;4625](https://github.com/anchore/syft/pull/4625) [@&#8203;hnnynh](https://github.com/hnnynh)] - Add .bpl file support to the PE / DLL cataloger \[Issue [#&#8203;4664](https://github.com/anchore/syft/issues/4664)] \[PR [#&#8203;4954](https://github.com/anchore/syft/pull/4954) [@&#8203;jfjrh2014](https://github.com/jfjrh2014)] ##### Bug Fixes - respect arch qualifier \[PR [#&#8203;4987](https://github.com/anchore/syft/pull/4987) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Preserve dependency edges when a compliance stub changes a package ID \[PR [#&#8203;4993](https://github.com/anchore/syft/pull/4993) [@&#8203;wagoodman](https://github.com/wagoodman)] - Support envoy binary various versions \[Issue [#&#8203;4590](https://github.com/anchore/syft/issues/4590)] \[PR [#&#8203;4605](https://github.com/anchore/syft/pull/4605) [@&#8203;rezmoss](https://github.com/rezmoss)] - .net deps.json cataloger shows phantom pkgs for reference assembly library entries \[Issue [#&#8203;4970](https://github.com/anchore/syft/issues/4970)] \[PR [#&#8203;4971](https://github.com/anchore/syft/pull/4971) [@&#8203;rezmoss](https://github.com/rezmoss)] - Syft does not extract package licenses from opkg manager \[Issue [#&#8203;4940](https://github.com/anchore/syft/issues/4940)] \[PR [#&#8203;4963](https://github.com/anchore/syft/pull/4963) [@&#8203;Dashtid](https://github.com/Dashtid)] - squashfs breaks with godisk-fs 1.8.0 \[Issue [#&#8203;4718](https://github.com/anchore/syft/issues/4718)] - requirements.txt cataloger silently drops PEP 440 local version identifiers, producing incorrect PURL \[Issue [#&#8203;4958](https://github.com/anchore/syft/issues/4958)] \[PR [#&#8203;4959](https://github.com/anchore/syft/pull/4959) [@&#8203;kzantow](https://github.com/kzantow)] ##### Dependencies 34 dependency changes (31 updated, 3 added). 5 vulnerabilities remediated. **🟢 Remediated (5)** - [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2 - [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2 - [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2 - [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2 - [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2 <details> <summary>Updated (31 packages)</summary> - github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1` - github.com/anchore/bubbly `v0.2.0` → `v0.2.1` - github.com/anchore/clio `v0.1.0` → `v0.1.1` - github.com/anchore/fangs `v0.1.0` → `v0.1.1` - github.com/anchore/go-collections `v0.1.0` → `v0.1.1` - github.com/anchore/go-homedir `v0.1.0` → `v0.1.1` - github.com/anchore/go-logger `v0.1.0` → `v0.1.1` - github.com/anchore/go-lzo `v0.1.0` → `v0.1.1` - github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1` - github.com/anchore/go-make `v0.5.0` → `v0.8.0` - github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2` - github.com/anchore/go-sync `v0.1.0` → `v0.1.1` - github.com/anchore/stereoscope `v0.2.1` → `v0.2.2` - github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3` - github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0` - github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0` - github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))** - github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible` - github.com/google/go-containerregistry `v0.21.6` → `v0.21.7` - github.com/jedib0t/go-pretty/v6 `v6.7.10` → `v6.8.1` - github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21` - github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4` - github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1` - golang.org/x/crypto `v0.52.0` → `v0.53.0` - golang.org/x/mod `v0.36.0` → `v0.37.0` - golang.org/x/net `v0.55.0` → `v0.56.0` - golang.org/x/sync `v0.20.0` → `v0.21.0` - golang.org/x/sys `v0.45.0` → `v0.46.0` - golang.org/x/term `v0.43.0` → `v0.44.0` - golang.org/x/text `v0.37.0` → `v0.38.0` - golang.org/x/tools `v0.45.0` → `v0.46.0` </details> <details> <summary>Added (3 packages)</summary> - github.com/piprate/json-gold `v0.7.0` - github.com/pquerna/cachecontrol `v0.0.0-1555304` - github.com/tailscale/hujson `v0.0.0-ecc657c` </details> **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.45.1...v1.46.0)** ### [`v1.45.1`](https://github.com/anchore/syft/releases/tag/v1.45.1) ##### Bug Fixes - bump stereoscope to pull in fix for registry client hanging \[[#&#8203;4934](https://github.com/anchore/syft/pull/4934) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.45.0...v1.45.1)** ### [`v1.44.0`](https://github.com/anchore/syft/releases/tag/v1.44.0) ##### Added Features - Add support for linux-riscv64 \[[#&#8203;4757](https://github.com/anchore/syft/pull/4757) [@&#8203;luhenry](https://github.com/luhenry)] ##### Bug Fixes - Yarn lockfile cataloguing does not handle aliases \[[#&#8203;4833](https://github.com/anchore/syft/issues/4833) [#&#8203;4836](https://github.com/anchore/syft/pull/4836) [@&#8203;cyphercodes](https://github.com/cyphercodes)] - Some snippet files are saved in the previous test directory \[[#&#8203;4829](https://github.com/anchore/syft/issues/4829) [#&#8203;4830](https://github.com/anchore/syft/pull/4830) [@&#8203;witchcraze](https://github.com/witchcraze)] - empty rockspec causes index out of range \[[#&#8203;4824](https://github.com/anchore/syft/issues/4824) [#&#8203;4827](https://github.com/anchore/syft/pull/4827) [@&#8203;aki1770-del](https://github.com/aki1770-del)] - PE cataloger shows asp.net core ref assemblies using fileversion build stamp instead of productversion \[[#&#8203;4813](https://github.com/anchore/syft/issues/4813) [#&#8203;4814](https://github.com/anchore/syft/pull/4814) [@&#8203;rezmoss](https://github.com/rezmoss)] - Syft safeCopy silently swallows archive decompression errors \[[#&#8203;4806](https://github.com/anchore/syft/issues/4806) [#&#8203;4807](https://github.com/anchore/syft/pull/4807) [@&#8203;SAY-5](https://github.com/SAY-5)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.43.0...v1.44.0)** ### [`v1.43.0`](https://github.com/anchore/syft/releases/tag/v1.43.0) ##### Added Features - added deno bin classifiers \[[#&#8203;4677](https://github.com/anchore/syft/pull/4677) [@&#8203;rezmoss](https://github.com/rezmoss)] - Support haskell old versions \[[#&#8203;3237](https://github.com/anchore/syft/issues/3237) [#&#8203;4793](https://github.com/anchore/syft/pull/4793) [@&#8203;witchcraze](https://github.com/witchcraze)] - Add support for OpenLDAP binary detection \[[#&#8203;4768](https://github.com/anchore/syft/issues/4768) [#&#8203;4755](https://github.com/anchore/syft/pull/4755) [@&#8203;nadimz](https://github.com/nadimz)] - Support erlang ols versions \[[#&#8203;3235](https://github.com/anchore/syft/issues/3235) [#&#8203;4766](https://github.com/anchore/syft/pull/4766) [@&#8203;witchcraze](https://github.com/witchcraze)] ##### Bug Fixes - improve redhat-release parsing fallback for RHEL clones \[[#&#8203;4808](https://github.com/anchore/syft/pull/4808) [@&#8203;westonsteimel](https://github.com/westonsteimel)] - fix format string in search results struct \[[#&#8203;4775](https://github.com/anchore/syft/pull/4775) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - prevent infinite recursion in Document.UnmarshalJSON with encoding/json/v2 \[[#&#8203;4748](https://github.com/anchore/syft/pull/4748) [@&#8203;benja-M-1](https://github.com/benja-M-1)] - Syft can not complete scanning golang image \[[#&#8203;4686](https://github.com/anchore/syft/issues/4686)] - javascript-package-cataloger drops entire package.json when authors/contributors/maintainers is a single string \[[#&#8203;4778](https://github.com/anchore/syft/issues/4778) [#&#8203;4779](https://github.com/anchore/syft/pull/4779) [@&#8203;yoav-orca](https://github.com/yoav-orca)] - pnpm lock file cataloger produces unstable output \[[#&#8203;4648](https://github.com/anchore/syft/issues/4648) [#&#8203;4765](https://github.com/anchore/syft/pull/4765) [@&#8203;lawrence3699](https://github.com/lawrence3699)] - Linux Kernel bzImage and zImage not cataloged by linux-kernel-cataloger \[[#&#8203;4769](https://github.com/anchore/syft/issues/4769) [#&#8203;4751](https://github.com/anchore/syft/pull/4751) [@&#8203;nadimz](https://github.com/nadimz)] - Support istio binary (pilot-discovery, pilot-agent) alpha,beta,rc,dev version \[[#&#8203;4546](https://github.com/anchore/syft/issues/4546) [#&#8203;4645](https://github.com/anchore/syft/pull/4645) [@&#8203;witchcraze](https://github.com/witchcraze)] - Scanning mounted ISO: duplicate entries \[[#&#8203;4759](https://github.com/anchore/syft/issues/4759)] ##### Additional Changes - update CPE dictionary index \[[#&#8203;4767](https://github.com/anchore/syft/pull/4767) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.42.4...v1.43.0)** ### [`v1.42.4`](https://github.com/anchore/syft/releases/tag/v1.42.4) ##### Bug Fixes - Similar Packages Should Be Aggregated \[[#&#8203;1162](https://github.com/anchore/syft/issues/1162)] - Support arangodb binary recent version \[[#&#8203;4571](https://github.com/anchore/syft/issues/4571) [#&#8203;4662](https://github.com/anchore/syft/pull/4662) [@&#8203;witchcraze](https://github.com/witchcraze)] - Support go binary various versions \[[#&#8203;4687](https://github.com/anchore/syft/issues/4687) [#&#8203;4694](https://github.com/anchore/syft/pull/4694) [@&#8203;kzantow](https://github.com/kzantow)] ##### Additional Changes - update CPE dictionary index \[[#&#8203;4745](https://github.com/anchore/syft/pull/4745) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] - update CPE dictionary index \[[#&#8203;4726](https://github.com/anchore/syft/pull/4726) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] - Add a trust boundary section \[[#&#8203;4716](https://github.com/anchore/syft/pull/4716) [@&#8203;joshbressers](https://github.com/joshbressers)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.42.3...v1.42.4)** ### [`v1.42.3`](https://github.com/anchore/syft/releases/tag/v1.42.3) ##### Bug Fixes - Missing secondary evidence for .NET dependency in ghcr.io/open-telemetry/demo:2.0.0-accounting image \[[#&#8203;4652](https://github.com/anchore/syft/issues/4652)] ##### Additional Changes - bump github.com/buger/jsonsparser to v1.1.2 \[[#&#8203;4680](https://github.com/anchore/syft/pull/4680) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - centralize temp files and prefer streaming IO \[[#&#8203;4668](https://github.com/anchore/syft/pull/4668) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.42.2...v1.42.3)** ### [`v1.42.2`](https://github.com/anchore/syft/releases/tag/v1.42.2) ##### Bug Fixes - \[BUG] Incorrect Maven PURL generation: `Automatic-Module-Name` should not be used as Maven groupId \[[#&#8203;4611](https://github.com/anchore/syft/issues/4611) [#&#8203;4642](https://github.com/anchore/syft/pull/4642) [@&#8203;xnox](https://github.com/xnox)] - Checksum is 0 for spdx files \[[#&#8203;2307](https://github.com/anchore/syft/issues/2307) [#&#8203;4620](https://github.com/anchore/syft/pull/4620) [@&#8203;ppalucha](https://github.com/ppalucha)] - Support grafana binary various versions \[[#&#8203;4559](https://github.com/anchore/syft/issues/4559) [#&#8203;4635](https://github.com/anchore/syft/pull/4635) [@&#8203;witchcraze](https://github.com/witchcraze)] ##### Additional Changes - migrate fixtures to testdata \[[#&#8203;4651](https://github.com/anchore/syft/pull/4651) [@&#8203;wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.42.1...v1.42.2)** ### [`v1.42.1`](https://github.com/anchore/syft/releases/tag/v1.42.1) ##### Bug Fixes - Use redhat as namespace for hummingbird rpms \[[#&#8203;4615](https://github.com/anchore/syft/pull/4615) [@&#8203;scoheb](https://github.com/scoheb)] - False Positive: Emacs snap package version CVE-2024-39331 \[[#&#8203;4485](https://github.com/anchore/syft/issues/4485)] ##### Additional Changes - call cleanup on tmpfile and replace some io.ReadAlls with streams \[[#&#8203;4629](https://github.com/anchore/syft/pull/4629) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - bumps go mod version to 1.25; ci takes latest patch \[[#&#8203;4628](https://github.com/anchore/syft/pull/4628) [@&#8203;spiffcs](https://github.com/spiffcs)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.42.0...v1.42.1)** ### [`v1.41.2`](https://github.com/anchore/syft/releases/tag/v1.41.2) ##### Bug Fixes - further improve go binary classifier, including windows \[[#&#8203;4593](https://github.com/anchore/syft/pull/4593) [@&#8203;kzantow](https://github.com/kzantow)] - Wrong format in license \[[#&#8203;4233](https://github.com/anchore/syft/issues/4233) [#&#8203;4588](https://github.com/anchore/syft/pull/4588) [@&#8203;spiffcs](https://github.com/spiffcs)] - Cannot detect installation of Qt6 \[[#&#8203;4467](https://github.com/anchore/syft/issues/4467) [#&#8203;4550](https://github.com/anchore/syft/pull/4550) [@&#8203;rezmoss](https://github.com/rezmoss)] - bug: Syft mis-identifies binary as deb inside a snap \[[#&#8203;4486](https://github.com/anchore/syft/issues/4486) [#&#8203;4500](https://github.com/anchore/syft/pull/4500) [@&#8203;popey](https://github.com/popey)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.41.1...v1.41.2)** ### [`v1.41.1`](https://github.com/anchore/syft/releases/tag/v1.41.1) ##### Bug Fixes - \[Bug Report] Missing some dependencies on cyclonedx formatted SBOM using syft \[[#&#8203;4562](https://github.com/anchore/syft/issues/4562) [#&#8203;4573](https://github.com/anchore/syft/pull/4573) [@&#8203;spiffcs](https://github.com/spiffcs)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.41.0...v1.41.1)** ### [`v1.41.0`](https://github.com/anchore/syft/releases/tag/v1.41.0) ##### Added Features - detect Debian version from /etc/debian\_version \[[#&#8203;4569](https://github.com/anchore/syft/pull/4569) [@&#8203;kzantow](https://github.com/kzantow)] ##### Bug Fixes - correctly report supporting evidence for binary packages \[[#&#8203;4558](https://github.com/anchore/syft/pull/4558) [@&#8203;kzantow](https://github.com/kzantow)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.40.1...v1.41.0)** ### [`v1.40.1`](https://github.com/anchore/syft/releases/tag/v1.40.1) > \[!Important] > This release bumps github.com/containerd/containerd to v2, which will cause compiler errors if used alongside other dependencies that use v1 of containerd. See [anchore/stereoscope#495](https://github.com/anchore/stereoscope/pull/495) for a detailed discussion. ##### Bug Fixes - mongodb binary not detected manual/source install \[[#&#8203;4540](https://github.com/anchore/syft/issues/4540) [#&#8203;4541](https://github.com/anchore/syft/pull/4541) [@&#8203;rezmoss](https://github.com/rezmoss)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.40.0...v1.40.1)** ### [`v1.40.0`](https://github.com/anchore/syft/releases/tag/v1.40.0) ##### Added Features - Exclude development or test dependencies for PNPM Package type \[[#&#8203;4430](https://github.com/anchore/syft/issues/4430) [#&#8203;4487](https://github.com/anchore/syft/pull/4487) [@&#8203;rezmoss](https://github.com/rezmoss)] - Catalog istio binary (pilot-discovery, pilot-agent) \[[#&#8203;4508](https://github.com/anchore/syft/issues/4508) [#&#8203;4521](https://github.com/anchore/syft/pull/4521) [@&#8203;witchcraze](https://github.com/witchcraze)] - Catalog envoy binary \[[#&#8203;4506](https://github.com/anchore/syft/issues/4506) [#&#8203;4530](https://github.com/anchore/syft/pull/4530) [@&#8203;witchcraze](https://github.com/witchcraze)] - Catalog grafana binary \[[#&#8203;4505](https://github.com/anchore/syft/issues/4505) [#&#8203;4516](https://github.com/anchore/syft/pull/4516) [@&#8203;witchcraze](https://github.com/witchcraze)] - Add a binary classifier for valkey \[[#&#8203;3400](https://github.com/anchore/syft/issues/3400) [#&#8203;4509](https://github.com/anchore/syft/pull/4509) [@&#8203;witchcraze](https://github.com/witchcraze)] ##### Bug Fixes - old bitnami images without spdx files arent getting picked up correctly in the catalog \[[#&#8203;4529](https://github.com/anchore/syft/issues/4529) [#&#8203;4532](https://github.com/anchore/syft/pull/4532) [@&#8203;rezmoss](https://github.com/rezmoss)] - wrong traefik rc versions at binary detection \[[#&#8203;3535](https://github.com/anchore/syft/issues/3535) [#&#8203;4499](https://github.com/anchore/syft/pull/4499) [@&#8203;rezmoss](https://github.com/rezmoss)] - FromPOSIX() in internals\windows\path.go assumes that all Windows root paths must have a colon terminator \[[#&#8203;4070](https://github.com/anchore/syft/issues/4070) [#&#8203;4075](https://github.com/anchore/syft/pull/4075) [@&#8203;luissantosHCIT](https://github.com/luissantosHCIT)] - binary cataloger is picking up the go version instead of the actual binary version in traefik experimental images \[[#&#8203;4498](https://github.com/anchore/syft/issues/4498) [#&#8203;4499](https://github.com/anchore/syft/pull/4499) [@&#8203;rezmoss](https://github.com/rezmoss)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.39.0...v1.40.0)** ### [`v1.39.0`](https://github.com/anchore/syft/releases/tag/v1.39.0) ##### Added Features - add support for Gemfile.next.lock \[[#&#8203;4457](https://github.com/anchore/syft/pull/4457) [@&#8203;HatiCode](https://github.com/HatiCode)] - Command output to give more information on what catalogers look for and what they can find \[[#&#8203;4155](https://github.com/anchore/syft/issues/4155) [#&#8203;4317](https://github.com/anchore/syft/pull/4317) [@&#8203;wagoodman](https://github.com/wagoodman)] - Support reading lzma compressed `.go.buildinfo` sections with upx \[[#&#8203;4411](https://github.com/anchore/syft/issues/4411) [#&#8203;4480](https://github.com/anchore/syft/pull/4480) [@&#8203;wagoodman](https://github.com/wagoodman)] - Specify specific snap revision to pull \[[#&#8203;4389](https://github.com/anchore/syft/issues/4389) [#&#8203;4439](https://github.com/anchore/syft/pull/4439) [@&#8203;VictorHuu](https://github.com/VictorHuu)] - Cannot detect embedded deps.json metadata in single-file .NET binaries \[[#&#8203;4344](https://github.com/anchore/syft/issues/4344) [#&#8203;4375](https://github.com/anchore/syft/pull/4375) [@&#8203;rezmoss](https://github.com/rezmoss)] - ELF note cataloger does not pick up OS field, but should \[[#&#8203;4384](https://github.com/anchore/syft/issues/4384) [#&#8203;4438](https://github.com/anchore/syft/pull/4438) [@&#8203;VictorHuu](https://github.com/VictorHuu)] ##### Bug Fixes - remove debug print statement in dependency parser \[[#&#8203;4412](https://github.com/anchore/syft/pull/4412) [@&#8203;cgreeno](https://github.com/cgreeno)] - dotnet-deps cataloger should skip project references with type "project" when building the sbom \[[#&#8203;4423](https://github.com/anchore/syft/issues/4423) [#&#8203;4436](https://github.com/anchore/syft/pull/4436) [@&#8203;rezmoss](https://github.com/rezmoss)] - File digests not computed when using `--base-path` \[[#&#8203;4410](https://github.com/anchore/syft/issues/4410) [#&#8203;4478](https://github.com/anchore/syft/pull/4478) [@&#8203;wagoodman](https://github.com/wagoodman)] - Syft should not define subpaths by default in PURLs \[[#&#8203;4394](https://github.com/anchore/syft/issues/4394) [#&#8203;4395](https://github.com/anchore/syft/pull/4395) [@&#8203;rezmoss](https://github.com/rezmoss)] - go: valid purl but incorrect name \[[#&#8203;1737](https://github.com/anchore/syft/issues/1737) [#&#8203;4395](https://github.com/anchore/syft/pull/4395) [@&#8203;rezmoss](https://github.com/rezmoss)] - Incorrect Go module PURL generation when module path contains /vN (e.g. /v5) \[[#&#8203;4316](https://github.com/anchore/syft/issues/4316) [#&#8203;4395](https://github.com/anchore/syft/pull/4395) [@&#8203;rezmoss](https://github.com/rezmoss)] - Failing to convert npm repository information correctly to SPDX \[[#&#8203;4362](https://github.com/anchore/syft/issues/4362) [#&#8203;4390](https://github.com/anchore/syft/pull/4390) [@&#8203;kendrickm](https://github.com/kendrickm)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.38.2...v1.39.0)** ### [`v1.38.2`](https://github.com/anchore/syft/releases/tag/v1.38.2) ##### Bug Fixes - drop cpe from gguf \[[#&#8203;4383](https://github.com/anchore/syft/pull/4383) [@&#8203;spiffcs](https://github.com/spiffcs)] - emit lua rockspec dependencies in metadata \[[#&#8203;4376](https://github.com/anchore/syft/pull/4376) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Invalid SBOMs are created when GO replace directive is used \[[#&#8203;4415](https://github.com/anchore/syft/issues/4415) [#&#8203;4419](https://github.com/anchore/syft/pull/4419) [@&#8203;VictorHuu](https://github.com/VictorHuu)] - Incorrect CPE for Vercel's Next js \[[#&#8203;4443](https://github.com/anchore/syft/issues/4443) [#&#8203;4450](https://github.com/anchore/syft/pull/4450) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - v1.38.0 generates empty sbom for tgz sources \[[#&#8203;4416](https://github.com/anchore/syft/issues/4416) [#&#8203;4421](https://github.com/anchore/syft/pull/4421) [@&#8203;VictorHuu](https://github.com/VictorHuu)] - Syft: The dependency graph does not include all Requires-Dist relationships defined in the package’s METADATA file \[[#&#8203;4401](https://github.com/anchore/syft/issues/4401) [#&#8203;4408](https://github.com/anchore/syft/pull/4408) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.38.0...v1.38.2)** ### [`v1.38.0`](https://github.com/anchore/syft/releases/tag/v1.38.0) ##### Added Features - add support for cataloging GGUF models \[[#&#8203;4184](https://github.com/anchore/syft/issues/4184) [#&#8203;4279](https://github.com/anchore/syft/pull/4279) [@&#8203;spiffcs](https://github.com/spiffcs)] - Support scanning a list of CPEs \[[#&#8203;3890](https://github.com/anchore/syft/issues/3890) [#&#8203;4207](https://github.com/anchore/syft/pull/4207) [@&#8203;chovanecadam](https://github.com/chovanecadam)] - Syft does not detect Elixir binary on system \[[#&#8203;4333](https://github.com/anchore/syft/issues/4333) [#&#8203;4334](https://github.com/anchore/syft/pull/4334) [@&#8203;rezmoss](https://github.com/rezmoss)] ##### Bug Fixes - Support `extras` statements in Python PDM cataloger \[[#&#8203;4352](https://github.com/anchore/syft/pull/4352) [@&#8203;wagoodman](https://github.com/wagoodman)] - Preserve --from argument order \[[#&#8203;4350](https://github.com/anchore/syft/pull/4350) [@&#8203;wagoodman](https://github.com/wagoodman)] - SBOM generated by Syft 1.28 contains license elements missing `id` or `name` (causing CycloneDX parser error) \[[#&#8203;4363](https://github.com/anchore/syft/issues/4363)] - empty PURL output in dependency snapshot format breaks sbom-action \[[#&#8203;4311](https://github.com/anchore/syft/issues/4311)] - Interface includes constraint elements, can only be used in type parameters \[[#&#8203;4346](https://github.com/anchore/syft/issues/4346)] - Upgrade github.com/nwaples/rardecode\@&#8203;v1.1.3 to 2.2.1 \[[#&#8203;4338](https://github.com/anchore/syft/issues/4338)] - Upgrade to Golang 1.25.4 \[[#&#8203;4341](https://github.com/anchore/syft/issues/4341)] ##### Additional Changes - migrate syft to use mholt/archives instead of anchore fork \[[#&#8203;4029](https://github.com/anchore/syft/pull/4029) [@&#8203;Rupikz](https://github.com/Rupikz)] - Add license enrichment from pypi to python packages \[[#&#8203;4295](https://github.com/anchore/syft/pull/4295) [@&#8203;timols](https://github.com/timols)] - license file search \[[#&#8203;4327](https://github.com/anchore/syft/pull/4327) [@&#8203;kzantow](https://github.com/kzantow)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.37.0...v1.38.0)** ### [`v1.37.0`](https://github.com/anchore/syft/releases/tag/v1.37.0) ##### Added Features - Refactor fileresolver to not require base path \[[#&#8203;4298](https://github.com/anchore/syft/pull/4298) [@&#8203;Rupikz](https://github.com/Rupikz)] - Describe cataloger capabilities via test observations \[[#&#8203;4318](https://github.com/anchore/syft/pull/4318) [@&#8203;wagoodman](https://github.com/wagoodman)] - Support Java resource adapter extension .far as a Java archive \[[#&#8203;4183](https://github.com/anchore/syft/issues/4183) [#&#8203;4193](https://github.com/anchore/syft/pull/4193) [@&#8203;kyounghunJang](https://github.com/kyounghunJang)] - Add Java resource adapter extension ".rar" as supported Java archive \[[#&#8203;4136](https://github.com/anchore/syft/issues/4136) [#&#8203;4137](https://github.com/anchore/syft/pull/4137) [@&#8203;thomassui](https://github.com/thomassui)] ##### Bug Fixes - fix empty PURL Github format \[[#&#8203;4312](https://github.com/anchore/syft/pull/4312) [@&#8203;rezmoss](https://github.com/rezmoss)] - Canonicalize Ghostscript CPE/PURL for ghostscript packages from PE Binaries \[[#&#8203;4308](https://github.com/anchore/syft/pull/4308) [@&#8203;kdt523](https://github.com/kdt523)] - Respect "rpmmod" PURL qualifier \[[#&#8203;4314](https://github.com/anchore/syft/pull/4314) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - fix dpkg packages that are in `deinstalled` state should not be in SBOM \[[#&#8203;3063](https://github.com/anchore/syft/issues/3063) [#&#8203;4231](https://github.com/anchore/syft/pull/4231) [@&#8203;rkirk-nos](https://github.com/rkirk-nos)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.36.0...v1.37.0)** ### [`v1.36.0`](https://github.com/anchore/syft/releases/tag/v1.36.0) ##### Added Features - Add the ability to fetch remote licenses for pnpm-lock.yaml files \[[#&#8203;4286](https://github.com/anchore/syft/pull/4286) [@&#8203;timols](https://github.com/timols)] - support universal (fat) mach-o binary files \[[#&#8203;4278](https://github.com/anchore/syft/pull/4278) [@&#8203;JoeyShapiro](https://github.com/JoeyShapiro)] - pdm support \[[#&#8203;2709](https://github.com/anchore/syft/issues/2709) [#&#8203;4234](https://github.com/anchore/syft/pull/4234) [@&#8203;paulslaby](https://github.com/paulslaby)] ##### Bug Fixes - Remove duplicate image source providers \[[#&#8203;4289](https://github.com/anchore/syft/pull/4289) [@&#8203;Rupikz](https://github.com/Rupikz)] - syft can't extract go module information from executables on Windows \[[#&#8203;4271](https://github.com/anchore/syft/issues/4271) [#&#8203;4285](https://github.com/anchore/syft/pull/4285) [@&#8203;JoeyShapiro](https://github.com/JoeyShapiro)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.34.2...v1.35.0)** ### [`v1.34.2`](https://github.com/anchore/syft/releases/tag/v1.34.2) ##### Bug Fixes - Extract zip archive with multiple entries \[[#&#8203;4283](https://github.com/anchore/syft/pull/4283) [@&#8203;Rupikz](https://github.com/Rupikz)] - panic while resolving maven properties in archive parser \[[#&#8203;4288](https://github.com/anchore/syft/issues/4288) [#&#8203;4290](https://github.com/anchore/syft/pull/4290) [@&#8203;kzantow](https://github.com/kzantow)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.34.1...v1.34.2)** ### [`v1.33.0`](https://github.com/anchore/syft/releases/tag/v1.33.0) ##### Added Features - Modify RpmDBEntry to include modularityLabel for cyclonedx \[[#&#8203;4212](https://github.com/anchore/syft/pull/4212) [@&#8203;sfc-gh-rmaj](https://github.com/sfc-gh-rmaj)] - Add locations onto packages read from Java native image SBOMs \[[#&#8203;4186](https://github.com/anchore/syft/pull/4186) [@&#8203;rudsberg](https://github.com/rudsberg)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.32.0...v1.33.0)** ### [`v1.32.0`](https://github.com/anchore/syft/releases/tag/v1.32.0) ##### Added Features - Catalog entire build list for Go projects, not just packages listed in go.mod \[[#&#8203;432](https://github.com/anchore/syft/issues/432) [#&#8203;4127](https://github.com/anchore/syft/pull/4127) [@&#8203;spiffcs](https://github.com/spiffcs)] - package.json authors keyword parsing \[[#&#8203;2250](https://github.com/anchore/syft/issues/2250) [#&#8203;4003](https://github.com/anchore/syft/pull/4003) [@&#8203;popey](https://github.com/popey)] - Conda ecosystem support (basic) \[[#&#8203;4002](https://github.com/anchore/syft/pull/4002)[@SimeonStoykovQC](https://github.com/SimeonStoykovQC)] ##### Bug Fixes - When scanning the FFmpeg binary with Syft a new package is now added \[[#&#8203;3988](https://github.com/anchore/syft/issues/3988) [#&#8203;3994](https://github.com/anchore/syft/pull/3994) [@&#8203;popey](https://github.com/popey)] - Warn loudly if SQLite driver is not present when needed \[[#&#8203;3234](https://github.com/anchore/syft/issues/3234) [#&#8203;4150](https://github.com/anchore/syft/pull/4150) [@&#8203;kzantow](https://github.com/kzantow)] ##### Additional Changes - Update dependencies to use go.yaml.in/yaml \[[#&#8203;4157](https://github.com/anchore/syft/pull/4157) [@&#8203;n-bes](https://github.com/n-bes)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.31.0...v1.32.0)** ### [`v1.30.0`](https://github.com/anchore/syft/releases/tag/v1.30.0) ##### Added Features - add binary classifier for hashicorp vault \[[#&#8203;4121](https://github.com/anchore/syft/pull/4121) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - fix: update nondeterministic Java archive cataloging and improve groupID \[[#&#8203;3521](https://github.com/anchore/syft/issues/3521) [#&#8203;4118](https://github.com/anchore/syft/pull/4118) [@&#8203;kzantow](https://github.com/kzantow)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.29.1...v1.30.0)** ### [`v1.29.1`](https://github.com/anchore/syft/releases/tag/v1.29.1) ##### Bug Fixes - Missing license information for tzdata \[[#&#8203;4102](https://github.com/anchore/syft/issues/4102)] - Improve JVM Scan Accuracy for JDK and JRE Detection \[[#&#8203;4071](https://github.com/anchore/syft/issues/4071) [#&#8203;4046](https://github.com/anchore/syft/pull/4046) [@&#8203;kzantow](https://github.com/kzantow)] - Azul JDK classified as Oracle JRE \[[#&#8203;3893](https://github.com/anchore/syft/issues/3893) [#&#8203;4046](https://github.com/anchore/syft/pull/4046) [@&#8203;kzantow](https://github.com/kzantow)] **[(Full Changelog)](https://github.com/anchore/syft/compare/v1.29.0...v1.29.1)** </details> <details> <summary>traefik/traefik-helm-chart (traefik)</summary> ### [`v28.3.0`](https://github.com/traefik/traefik-helm-chart/releases/tag/v28.3.0) [Compare Source](https://github.com/traefik/traefik-helm-chart/compare/v28.2.0...v28.3.0) ##### Features - allow setting permanent on redirectTo ([1b454e9](https://github.com/traefik/traefik-helm-chart/commit/1b454e9e071d90f18f9eb43840c57d709eb8eb86)) - **deps**: update traefik docker tag to v3.0.2 ##### Bug Fixes - **Security:** 🐛 🔒️ mount service account token on pod level (\[[`db4f43f`](https://github.com/traefik/traefik-helm-chart/commit/db4f43f)]\(<https://github.com/traefik/traefik-helm-chart/commit/> - **Traefik Hub:** remove namespace in mutating webhook ([f8f2da2](https://github.com/traefik/traefik-helm-chart/commit/f8f2da2905f8c97a9e891461d6203612d22c333c)) - **Traefik Hub:** remove obsolete CRD ([4fcec62](https://github.com/traefik/traefik-helm-chart/commit/4fcec6296bdd5b4bd18776d88fe3c82497c8b800)) - 🐛 namespaced rbac when kubernetesIngress provider is disabled ([3bb41f7](https://github.com/traefik/traefik-helm-chart/commit/3bb41f7acc77463d518c26f38371df9f6a0d9b9e)) [`db4f43f`](https://github.com/traefik/traefik-helm-chart/commit/db4f43f2cbdaad77b95c838d12f0b398bc149863))) - 🐛 add divisor: '1' to GOMAXPROCS and GOMEMLIMIT ([9ccbee2](https://github.com/traefik/traefik-helm-chart/commit/9ccbee20ec22392eeca541514a534d357a2e499b)) #### New Contributors - [@&#8203;hawkesn](https://github.com/hawkesn) made their first contribution in [#&#8203;1085](https://github.com/traefik/traefik-helm-chart/pull/1085) - [@&#8203;berlincount](https://github.com/berlincount) made their first contribution in [#&#8203;1082](https://github.com/traefik/traefik-helm-chart/pull/1082) **Full Changelog**: <https://github.com/traefik/traefik-helm-chart/compare/v28.2.0...v28.3.0> ### [`v28.2.0`](https://github.com/traefik/traefik-helm-chart/releases/tag/v28.2.0) [Compare Source](https://github.com/traefik/traefik-helm-chart/compare/v28.1.0...v28.2.0) :warning: This release align to Kubernetes default (*Always*) for `podSecurityContext.fsGroupChangePolicy`. It was *OnRootMismatch* in previous release of this chart. It can easily be set (back) to *OnRootMismatch* if needed, see [EXAMPLES](https://github.com/traefik/traefik-helm-chart/blob/master/EXAMPLES.md#use-traefik-native-lets-encrypt-integration-without-cert-manager). ##### Features - ✨ simplify values and provide more examples ([4eb71eb](https://github.com/traefik/traefik-helm-chart/commit/4eb71eb43bde454ce16e8633215551e67eff4568)) - add deletecollection right on secrets ([fb69807](https://github.com/traefik/traefik-helm-chart/commit/fb69807b609a991643a45d982a716441980955e6)) - update traefik docker tag to v3.0.1 by [@&#8203;renovate](https://github.com/renovate) in [#&#8203;1075](https://github.com/traefik/traefik-helm-chart/pull/1075) ##### Bug Fixes - **IngressClass:** provides annotation on IngressRoutes when it's enabled ([f5de0c3](https://github.com/traefik/traefik-helm-chart/commit/f5de0c3725e7ab46d22744ba8510875a2ca5fbf9)) #### New Contributors - [@&#8203;jspdown](https://github.com/jspdown) made their first contribution in [#&#8203;1077](https://github.com/traefik/traefik-helm-chart/pull/1077) **Full Changelog**: <https://github.com/traefik/traefik-helm-chart/compare/v28.1.0...v28.2.0> ### [`v28.1.0`](https://github.com/traefik/traefik-helm-chart/releases/tag/v28.1.0) [Compare Source](https://github.com/traefik/traefik-helm-chart/compare/v28.0.0...v28.1.0) ##### Features - **Traefik Hub:** add initial support for API Gateway ([dc5c68d](https://github.com/traefik/traefik-helm-chart/commit/dc5c68d584198b52cd0ac64fb17d3df1d2ccb018)) - **Traefik Hub:** use Traefik Proxy otlp config ([a910db4](https://github.com/traefik/traefik-helm-chart/commit/a910db40fc9f3889a221003ca674242a2458744c)) ##### Bug Fixes - **Traefik Hub:** refine support ([60d210d](https://github.com/traefik/traefik-helm-chart/commit/60d210de336614ff16161d3cf13d555575ace12c)) - **Traefik Hub:** do not deploy mutating webhook when enabling only API Gateway ([cb2a98d](https://github.com/traefik/traefik-helm-chart/commit/cb2a98dfc8e412ea78d317954e245148915109a7)) ##### Documentation - **example:** Update Digital Ocean PROXY Protocol ([9850319](https://github.com/traefik/traefik-helm-chart/commit/9850319029826fcb31d037fd51a6242261d400e1)) - 📚️ improve UPGRADING section ([54ec665](https://github.com/traefik/traefik-helm-chart/commit/54ec66537c2338b82d7c81f36367d17b9bc86b81)) </details> <details> <summary>UpCloudLtd/upcloud-cli (upcloud-cli)</summary> ### [`v3.36.0`](https://github.com/UpCloudLtd/upcloud-cli/blob/HEAD/CHANGELOG.md#3360---2026-07-28) ##### Added - Support gateway resources in `all list` and `all purge` commands. - Add `--wait` flag to `gateway delete` command. </details> <details> <summary>guerzon/vaultwarden (vaultwarden)</summary> ### [`v0.46.2`](https://github.com/guerzon/vaultwarden/releases/tag/v0.46.2) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.46.1...v0.46.2) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - New upstream release 1.37.3 by [@&#8203;bmm-alc](https://github.com/bmm-alc) in [#&#8203;249](https://github.com/guerzon/vaultwarden/pull/249) #### New Contributors - [@&#8203;bmm-alc](https://github.com/bmm-alc) made their first contribution in [#&#8203;249](https://github.com/guerzon/vaultwarden/pull/249) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.46.1...v0.46.2> ### [`v0.46.1`](https://github.com/guerzon/vaultwarden/releases/tag/v0.46.1) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.46.0...v0.46.1) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - New upstream release 1.37.2 by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;245](https://github.com/guerzon/vaultwarden/pull/245) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.46.0...v0.46.1> ### [`v0.46.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.46.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.45.0...v0.46.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat: add custom labels to storage PVCs by [@&#8203;guarnz](https://github.com/guarnz) in [#&#8203;239](https://github.com/guerzon/vaultwarden/pull/239) #### New Contributors - [@&#8203;guarnz](https://github.com/guarnz) made their first contribution in [#&#8203;239](https://github.com/guerzon/vaultwarden/pull/239) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.45.0...v0.46.0> ### [`v0.45.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.45.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.44.1...v0.45.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat(vaultwarden): add topologySpreadConstraints support by [@&#8203;somaz94](https://github.com/somaz94) in [#&#8203;234](https://github.com/guerzon/vaultwarden/pull/234) #### New Contributors - [@&#8203;somaz94](https://github.com/somaz94) made their first contribution in [#&#8203;234](https://github.com/guerzon/vaultwarden/pull/234) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.44.1...v0.45.0> ### [`v0.44.1`](https://github.com/guerzon/vaultwarden/releases/tag/v0.44.1) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.44.0...v0.44.1) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - Bump default Vaultwarden image version to 1.37.1 by [@&#8203;IQNeoXen](https://github.com/IQNeoXen) in [#&#8203;244](https://github.com/guerzon/vaultwarden/pull/244) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.44.0...v0.44.1> ### [`v0.44.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.44.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.43.1...v0.44.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - Bump default Vaultwarden image version to 1.37.0 by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;240](https://github.com/guerzon/vaultwarden/pull/240) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.43.1...v0.44.0> ### [`v0.43.1`](https://github.com/guerzon/vaultwarden/releases/tag/v0.43.1) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.43.0...v0.43.1) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - fix ingress additional hostnames context by [@&#8203;casinesque](https://github.com/casinesque) in [#&#8203;233](https://github.com/guerzon/vaultwarden/pull/233) #### New Contributors - [@&#8203;casinesque](https://github.com/casinesque) made their first contribution in [#&#8203;233](https://github.com/guerzon/vaultwarden/pull/233) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.43.0...v0.43.1> ### [`v0.43.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.43.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.42.0...v0.43.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat: add support for HELO\_NAME in SMTP settings by [@&#8203;OdyX](https://github.com/OdyX) in [#&#8203;219](https://github.com/guerzon/vaultwarden/pull/219) #### New Contributors - [@&#8203;OdyX](https://github.com/OdyX) made their first contribution in [#&#8203;219](https://github.com/guerzon/vaultwarden/pull/219) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.42.0...v0.43.0> ### [`v0.42.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.42.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.41.0...v0.42.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat: support HTTPS in Vaultwarden service using Rocket by [@&#8203;slavoutich](https://github.com/slavoutich) in [#&#8203;207](https://github.com/guerzon/vaultwarden/pull/207) #### New Contributors - [@&#8203;slavoutich](https://github.com/slavoutich) made their first contribution in [#&#8203;207](https://github.com/guerzon/vaultwarden/pull/207) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.41.0...v0.42.0> ### [`v0.41.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.41.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.40.3...v0.41.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat: add OCI builds by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;227](https://github.com/guerzon/vaultwarden/pull/227) - feat: add more database configs by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;228](https://github.com/guerzon/vaultwarden/pull/228) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.40.3...v0.41.0> ### [`v0.40.3`](https://github.com/guerzon/vaultwarden/releases/tag/v0.40.3) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.40.2...v0.40.3) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - fix: remove hardcoded serviceName by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;226](https://github.com/guerzon/vaultwarden/pull/226) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.40.2...v0.40.3> ### [`v0.40.2`](https://github.com/guerzon/vaultwarden/releases/tag/v0.40.2) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.40.1...v0.40.2) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - docs: update documentation on admin token by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;224](https://github.com/guerzon/vaultwarden/pull/224) - fix: remove hardcoded rocket port by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;225](https://github.com/guerzon/vaultwarden/pull/225) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.40.1...v0.40.2> ### [`v0.40.1`](https://github.com/guerzon/vaultwarden/releases/tag/v0.40.1) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.40.0...v0.40.1) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - fix: leave serviceAccount.create as true by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;223](https://github.com/guerzon/vaultwarden/pull/223) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.40.0...v0.40.1> ### [`v0.40.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.40.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.39.1...v0.40.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - fix(security): disable admin page, remove excessive rbac by [@&#8203;guerzon](https://github.com/guerzon) in [#&#8203;222](https://github.com/guerzon/vaultwarden/pull/222) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.39.1...v0.40.0> ### [`v0.39.1`](https://github.com/guerzon/vaultwarden/releases/tag/v0.39.1) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.39.0...v0.39.1) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - sso.disableSessionHandling not linked to configmap by [@&#8203;mreho](https://github.com/mreho) in [#&#8203;198](https://github.com/guerzon/vaultwarden/pull/198) #### New Contributors - [@&#8203;mreho](https://github.com/mreho) made their first contribution in [#&#8203;198](https://github.com/guerzon/vaultwarden/pull/198) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.39.0...v0.39.1> ### [`v0.39.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.39.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.38.0...v0.39.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat(httproute): support multiple named routes and httpsRedirect by [@&#8203;DevOpJadeja](https://github.com/DevOpJadeja) in [#&#8203;221](https://github.com/guerzon/vaultwarden/pull/221) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.38.0...v0.39.0> ### [`v0.38.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.38.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.37.0...v0.38.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat(hibp): allow existing secret by [@&#8203;santiagon610](https://github.com/santiagon610) in [#&#8203;218](https://github.com/guerzon/vaultwarden/pull/218) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.37.0...v0.38.0> ### [`v0.37.0`](https://github.com/guerzon/vaultwarden/releases/tag/v0.37.0) [Compare Source](https://github.com/guerzon/vaultwarden/compare/v0.36.4...v0.37.0) vaultwarden is an unofficial Bitwarden-compatible server written in Rust #### What's Changed - feat: add Kubernetes Gateway API (HTTPRoute) support by [@&#8203;DevOpJadeja](https://github.com/DevOpJadeja) in [#&#8203;217](https://github.com/guerzon/vaultwarden/pull/217) #### New Contributors - [@&#8203;DevOpJadeja](https://github.com/DevOpJadeja) made their first contribution in [#&#8203;217](https://github.com/guerzon/vaultwarden/pull/217) **Full Changelog**: <https://github.com/guerzon/vaultwarden/compare/v0.36.4...v0.37.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [x] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
danijel.simeunovic was assigned by gitea_admin 2026-09-28 00:09:07 +00:00
gitea_admin requested review from danijel.simeunovic 2026-09-28 00:09:12 +00:00
danijel.simeunovic approved these changes 2026-09-28 06:57:39 +00:00
Dismissed
danijel.simeunovic dismissed danijel.simeunovic's review 2026-09-28 22:06:08 +00:00
Reason:

New commits pushed, approval review dismissed automatically according to repository settings

danijel.simeunovic added 1 commit 2026-09-28 22:12:51 +00:00
chore(deps): update all non-major dependencies
AI Code Review / ai-review (pull_request) Has been skipped
/ test (pull_request) Successful in 20s
69d841eb13
danijel.simeunovic force-pushed renovate/all-minor-patch from 1d10a30496 to 69d841eb13 2026-09-28 22:12:51 +00:00 Compare
danijel.simeunovic approved these changes 2026-09-28 22:13:20 +00:00
danijel.simeunovic added 1 commit 2026-09-28 22:19:16 +00:00
Merge branch 'main' into renovate/all-minor-patch
AI Code Review / ai-review (pull_request) Has been skipped
/ test (pull_request) Successful in 19s
b7ea90b468

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.