chore(deps): update all non-major dependencies #40
Closed
gitea_admin
wants to merge 2 commits from
renovate/all-minor-patch into main
pull from: renovate/all-minor-patch
merge into: :main
:main
:renovate/prometheus-29.x
:renovate/traefik-41.x
:renovate/aws-6.x
:renovate/google-8.x
:fm/launchpad-forte-cli
:renovate/grafana-10.x
:renovate/kubernetes-monorepo
:feature/forte-prod
:fix/drop-duplicate-keycloak-secret
:feature/dns01
:feat/forte-drop-infra
:feature/ppusher
:feature/chibisafe
:hotfix/backup
:feature/vault-migration
:feature/hashicorp-vault
:feature/homepage
:feature/argocd-rbac
:feature/argocd-tls
:feature/multi-cloud
:feature/karpor
:feature/backstage
:feature/ai-review
:gitea-pages
:feature/gitea-docs
:feature/multicluster
:feature/secret-syncing
:feature/smtp
No Reviewers
Dismiss Review
Are you sure you want to dismiss this review?
Milestone
No items
No Milestone
Assignees
aslak.ege (Aslak Ege)
danijel.simeunovic (Danijel Simeunovic)
edvard.unsvag (Edvard Unsvåg)
ellina.ivleva (Ellina Ivleva)
gitea_admin
henrik.farstad
jorgen.stensrud (Jørgen Stensrud)
kristoffer.kopperud (Kristoffer Markus Kopperud)
ola.skarphol
oystein.roti (Øystein Roti)
peter.froystad
petter.schultz (Petter Schultz)
ragnhild.hande (Ragnhild Aaraas Hånde)
Thomas-Mannsverk-Eliassen (Thomas Mannsverk Eliassen)
thomas.solbjor (Thomas Solbjor)
Clear assignees
No Assignees
danijel.simeunovic
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Forte/launchpad#40
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
0.0.5→0.1.22.34.24→2.35.11v1.14.0→v1.21.212.6.0→12.7.01.25.4→1.27.3latest→0.12.08.0.0→8.15.00.29.0→0.32.00.33.1→0.35.11.33.2→1.36.33.18.4→3.20.20.30.0→0.38.45.7.0→5.8.11.14.3→1.19.07.0.0→7.3.0v0.64.0→v0.77.01.42.0→1.43.21.11.6→1.12.528.9.0→28.16.01.29.0→1.51.03.6.7→3.7.1028.0.0→28.3.03.29.0→3.36.00.36.4→0.46.2Release Notes
gitea/helm-actions (actions)
v0.1.2Compare Source
What's Changed
Contributors
New Contributors
Full Changelog: v0.1.1...v0.1.2
v0.1.1Compare Source
What's Changed
Contributors
Full Changelog: v0.1.0...v0.1.1
v0.1.0Compare Source
What's Changed
Contributors
Full Changelog: v0.0.5...v0.1.0
cert-manager/cert-manager (cert-manager)
v1.21.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.2 fixes controller and webhook panics, data races, ACME renewal and HTTP-01 solver bugs, and a Gateway API dnsNames bug. It stops the ACME and Vault issuers copying untrusted HTTP response bodies into status conditions and Events, and tightens ambient AWS credential use for namespaced Vault Issuers. It also updates Go and several dependencies to fix reported security vulnerabilities.
All users should upgrade.
Changes by Kind
Bug or Regression
replacesfield was being populated for the wrong issuer on issuer changes (#9236, @hjoshi123)spec.vault.servercould be copied into the Vault Issuer's Ready condition and its Kubernetes Events. Such responses now report only the HTTP status code, and Vault's own error messages are truncated before being persisted. (#9262, @FelixPhipps)Challenge.status.reason, preventing disclosure of internal response contents reachable via redirects. The response is still available in the controller's debug logs. (#9232, @FelixPhipps)vaultissuer no longer authenticates to Vault using the cert-manager controller's ambient AWS credentials for AWS IAM auth on a namespacedIssuer, unless ambient credentials are explicitly enabled via--issuer-ambient-credentials.ClusterIssuerand explicitserviceAccountRef(IRSA) configurations are unaffected. (#9231, @FelixPhipps)Other (Cleanup or Flake)
google.golang.org/grpcto v1.83.2 to fix reported security vulnerabilities (#9255, #9317)golang.org/x/cryptoto v0.56.0 to fix reported security vulnerabilities (#9265)v1.21.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.21.1 fixes a controller panic for Certificates with
spec.renewal.policy: Disabled, a regression in 1.21.0 which caused log spam and dropped Secret informer events, Issuers and ClusterIssuers getting stuck atReady=False(InvalidSolver) when a referenced ACME DNS-01 solver Secret is created after the Issuer, and the commented Gateway API example in the Helm chart values. It also updates several dependencies to fix reported security vulnerabilities.All users should upgrade.
Changes by Kind
Bug or Regression
gatewayAPI.enabledinstead of the invalidgatewayAPI.enable. (#9012, @mateenali66)Other (Cleanup or Flake)
golang.org/x/textto v0.40.0 to fix a reported security vulnerability (#9039, @wallrj-cyberark)google.golang.org/grpcto v1.82.1 to fix a reported security vulnerability (#9063)github.com/google/cel-goto v0.29.0 to fix a reported security vulnerability (#9072)go.opentelemetry.io/otelto v1.44.0 to fix a reported security vulnerability (#9073)v1.21.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.21 brings ACME Renewal Information (ARI) support, AWS IAM authentication for the Vault issuer, several security hardening changes, and continued improvements to Gateway API integration and cainjector. There are three breaking changes related to Helm chart RBAC and metrics values — review them carefully before upgrading.
Known Issues
renewal.policy: Disabled: the new Certificate renewal policies feature (#8258) causes a nil pointer dereference panic in the trigger controller whenever a Certificate'sspec.renewal.policyis set toDisabled—pki.RenewalTime()returns(nil, nil)for that policy, but the caller unconditionally dereferences the result. This crashes the controller process (crash-loop) for any cluster with such a Certificate. Workaround: do not setrenewal.policy: Disabledon any Certificate until this is fixed; remove the field (or set a different policy) from any Certificate that already has it, and restart the controller if it is currently crash-looping. See #9031 for details.filteredEventHandlertype assertion failures ("OnAdd missing Object","OnUpdate missing ObjectOld","OnDelete missing Object") for every non-cert-manager-labelled Secret event, multiplied by 7 certificate sub-controllers. This is cosmetic only — the affected controllers only need events from cert-manager-labelled Secrets (which arrive via the typed informer); the metadata informer events were always filtered out by predicates in previous versions. Issuer and ClusterIssuer controllers are not affected. See #8994 for details.Ready: False, Reason: InvalidSolverand never self-correct: new eager validation of ACME solver Secrets (#8255) means an Issuer/ClusterIssuer referencing a solver Secret (e.g. a DNS01 provider credential) that doesn't exist yet will correctly reportReady: False, but creating the missing Secret afterwards does not trigger re-reconciliation — the controller's Secret-watch logic was never updated to recognise solver Secrets. It will only recover on the next 10-hour informer resync, a change to the Issuer/ClusterIssuer's own spec, or a controller restart. Workaround: after creating the missing Secret, make a trivial edit to the Issuer/ClusterIssuer spec (or delete and recreate it) to force reconciliation. See #9036 for details and a fix proposal.Major Themes
Default
tokenrequestRBAC removed from Helm chartThe Helm chart no longer creates a default
RoleandRoleBindinggranting the cert-manager controller permission to create tokens for its own ServiceAccount (serviceaccounts/token: create). No documented workflow requires this RBAC — the Route53 docs section that motivated it was removed in 2024.If you use
serviceAccountRef.namepointing at the controller ServiceAccount, you must now either create your ownRole/RoleBindinggrantingserviceaccounts/token: create, or migrate to a dedicated ServiceAccount (recommended — see the Vault or Route53 documentation).Restrict Challenge and Order RBAC in
cert-manager-editClusterRoleThe
cert-manager-editaggregate ClusterRole no longer grantscreateforchallenges.acme.cert-manager.ioorcreate,patch,updatefororders.acme.cert-manager.io(GHSA-8rvj-mm4h-c258). These resources are internal to cert-manager's ACME workflow. Challengepatchandupdateare retained because users may need them to remove stuck finalizers.This change was already shipped in v1.20.3 and v1.19.6, so if you are running one of those versions this will not be a breaking change. If you have tooling that creates Challenge or Order resources directly, you will need to grant those permissions explicitly.
Metrics port name and path Helm values removed
The Helm values
prometheus.servicemonitor.targetPort,prometheus.servicemonitor.path, andprometheus.podmonitor.pathhave been removed. The controller Service metrics port has been renamed fromtcp-prometheus-servicemonitortohttp-metrics. Because the Helm values schema usesadditionalProperties: false, users who still have any of the removed keys in their values overrides will see a schema validation error on upgrade — remove them before upgrading. (#8952)ACME and Certificate Management
ACMEUseARIfeature gate. When enabled, cert-manager queries the ACME server'srenewalInfoendpoint for the recommended renewal window, allowing servers like Let's Encrypt to proactively prompt renewal during mass revocations or CA key rollovers. (#8798)waitInsteadOfSelfChecksolver option: skip cert-manager's own self-check and instead wait a configured duration before asking the ACME server to validate. An escape hatch for split-horizon DNS and NAT hairpin environments. See configuration details. (#8858)renewalPoliciesfield on the Certificate API provides more expressive control over renewal scheduling, complementingrenewBeforeandrenewBeforePercentage. (#8258)--certificate-request-maximum-backoff-durationflag (default: 32 hours) caps the exponential backoff for failed CertificateRequests, useful for environments with scheduled CA maintenance windows. (#8893)Gateway API and cainjector
acme.cert-manager.io/http01-parentreffallback: "true"annotation causes cert-manager to use the parent Gateway for solver HTTPRoutes instead of the ListenerSet, enabling TLS-only ListenerSets to use a shared HTTP listener for ACME challenges. (#8749)cert-manager.io/ignore-tls-listenersannotation: exclude specific Gateway TLS listeners from certificate management. (#8727)enableGatewayAPIconfiguration restructure:enableGatewayAPIandenableGatewayAPIListenerSetare deprecated in favor ofgatewayAPI.enabled/gatewayAPI.enableListenerSet. The old fields continue to work. (#8732)CAInjectorMergingpromoted to GA: unconditionally enabled; will be removed in a future release. (#8583)ServerSideApplyfeature gate is deprecated. (#8692)--ignore-namespacesflag: skip specified namespaces when watching Secrets for injection. (#8614)Deployment and Observability
AuthFailedIssuer condition reason distinguishes bad credentials from transient errors. PANW NGTS is now supported as a Venafi backend. (#8808, #8779)runtimeClassNamesupport: configurable for cert-manager components and ACME HTTP01 solver pods. (#8791, #8976)startupapicheck.ttlSecondsAfterFinished: opt-in automatic cleanup of the startupapicheck Job. (#8523)--acme-http01-solver-extra-labels: propagateglobal.commonLabelsto dynamically-created ACME HTTP01 solver resources. (#8761)Notable Bug Fixes
renewBeforePercentage: Certificates with durations longer than approximately 3 years were incorrectly rejected or assigned incorrect renewal times. (#8947)..path segments, preventingpath.Joinfrom silently resolving relative segments. (#8930)Community
As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.
A special thanks to:
for their contributions, comments and support!
Also, thanks to the cert-manager maintainer team for their help in this release:
And finally, thanks to the cert-manager steering committee for their feedback in this release cycle:
Changes since v1.20.0
Feature
AuthFailedIssuer condition reason to distinguish bad credentials from transient infrastructure errors. (#8808, @FelixPhipps)certificateRequestMaximumBackoffDurationcontroller configuration option to cap retry backoff time for failed CertificateRequests. Configurable via config file,--certificate-request-maximum-backoff-durationCLI flag, or Helm valueconfig.certificateRequestMaximumBackoffDuration. Defaults to 32 hours for backward compatibility. (#8893, @lunarwhite)waitInsteadOfSelfCheckfield to ACME HTTP01 and DNS01 solvers so cert-manager can skip its own self-check and ask the ACME server to validate after a configured wait. (#8858, @wallrj)runtimeClassNamesupport for cert-manager components and ACME HTTP01 solver pods. (#8791, @jsoref)runtimeClassNamesupport for ACME HTTP01 solver pods via theacmesolver.runtimeClassNameHelm value. (#8976, @erikgb)--acme-http01-solver-extra-labels, allowing Helm'sglobal.commonLabelsto propagate to all dynamically-created ACME HTTP01 solver resources (Pods, Services, Ingresses, or Gateway API HTTPRoutes). (#8761, @lunarwhite)startupapicheck.ttlSecondsAfterFinishedHelm value to enable automatic cleanup of the startupapicheck Job via the Kubernetes TTL-after-finished controller. (#8523, @dap0am)cert-manager.io/ignore-tls-listenersannotation for ignoring gwapi listeners. (#8727, @hjoshi123)--ignore-namespaceswas added to the cainjector binary. It can be used to filter out namespaces from being watched for secrets to use for injectables. (#8614, @figaw)cert-manager.io/alt-names,cert-manager.io/ip-sansto Certificates generated from ingress like objects in cert-shim controllers. (#8927, @jabbrwcky)acme.cert-manager.io/http01-parentreffallback: "true"causes cert-manager to use the parent Gateway as the solver HTTPRoute parentRef instead of the ListenerSet. This enables TLS-only ListenerSets to rely on a shared Gateway HTTP listener for ACME challenges. (#8749, @apkatsikas)Bug or Regression
RoleandRoleBindinggranting the cert-manager controller ServiceAccount permission to create tokens for itself (serviceaccounts/token: create). This RBAC was added in v1.16 (#7213) but no documented workflow requires it, and the motivating Route53 docs section was removed in Oct 2024. If you rely onserviceAccountRef.namepointing at the controller ServiceAccount (an undocumented pattern), you must now create your ownRoleandRoleBindinggrantingserviceaccounts/token: createon that ServiceAccount, or migrate to one of the documented patterns (IRSA ambient, or a dedicated ServiceAccount with its own RBAC). (#8931, @wallrj-cyberark)renewBeforePercentagecalculations that caused Certificates with durations longer than approximately 3 years to be incorrectly rejected by validation or assigned incorrect renewal times. (#8947, @ThatsMrTalbot)parentRefbug when both issuer config and annotations are present. (#8619, @hjoshi123)e2e-setup-samplewebhookinstallation to use the samplewebhook image repository and tag from the saved image tarball manifest. (#8821, @wallrj)webhook.configandwebhook.volumesare defined. (#8664, @jnohlgard)createand Ordercreate/patch/updatefrom the cert-manager-edit aggregate ClusterRole to prevent direct manipulation of these internal resources (GHSA-8rvj-mm4h-c258). (#8958, @wallrj-cyberark)..path segments inspec.vault.pathand auth mount path fields, preventingpath.Joinfrom silently resolving relative segments before constructing the Vault API request. (#8930, @wallrj-cyberark)Other (Cleanup or Flake)
prometheus.servicemonitor.targetPort,prometheus.servicemonitor.path, andprometheus.podmonitor.path. The metrics path is always/metricsand the target port is alwayshttp-metrics. Rename the controller service metrics port fromtcp-prometheus-servicemonitortohttp-metricsfor consistency with other workloads. Users must remove these keys from their value overrides before upgrading. (#8952, @erikgb)enableGatewayAPIandenableGatewayAPIListenerSetfields onControllerConfigurationare deprecated and moved into thegatewayAPIsub-struct asgatewayAPI.enabledandgatewayAPI.enableListenerSet. The old fields continue to work. (#8732, @ThatsMrTalbot)v1.20.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release updates Go and several dependencies to fix reported security vulnerabilities, and fixes a bug where ingress-shim removed the applyset label from cached Ingress and Gateway objects.
All users should upgrade.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
golang.org/x/netto v0.58.0,golang.org/x/textto v0.41.0 andgolang.org/x/cryptoto v0.55.0 to fix CVE-2026-46600, CVE-2026-56852 and CVE-2026-56854 (#9040, @wallrj-cyberark)google.golang.org/grpcto v1.83.2 to fix CVE-2026-84304, CVE-2026-84445, CVE-2026-84303 and one further advisory (#9062, #9257, #9316)github.com/google/cel-goto v0.30.0 to fix a reported vulnerability (#9070, #9186)software.sslmate.com/src/go-pkcs12to v0.7.2 to fix a reported vulnerability (#8988)golang.org/x/mod,go.opentelemetry.io/otelandgo.etcd.io/etcd/client/pkg/v3to versions flagged by security scanners (#9143, #9071, #9185)metadata.jsonwith cosign so the publish step can verify its authenticity (#9090, @FelixPhipps)v1.20.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release fixes a security issue (
GHSA-8rvj-mm4h-c258, HIGH) where the defaultcert-manager-editaggregate ClusterRole granted namespace users permission to create ACMEChallengeandOrderresources directly. A user who could create aChallengereferencing aClusterIssuercould supply attacker-controlled solver configuration while cert-manager loaded credentials from theClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones,dnsNames,matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.This release also removes the issuer owner reference from Challenges which was blocking Challenge garbage collection, and updates Go to fix reported CVEs.
All users should upgrade.
Changes by Kind
Bug or Regression
createand Ordercreate,patch,updateverbs from thecert-manager-editaggregate ClusterRole (GHSA-8rvj-mm4h-c258). (#8940, @wallrj-cyberark)Other (Cleanup or Flake)
v1.26.4to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 (#8926, @wallrj-cyberark)v1.20.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.20.2 fixes invalid YAML generated in the Helm chart when both
webhook.configand
webhook.volumesare defined, and bumps Go to 1.26.2 along with dependenciesto address reported vulnerabilities.
Changes by Kind
Bug or Regression
webhook.configandwebhook.volumesare defined. (#8665, @cert-manager-bot)Other (Cleanup or Flake)
v1.20.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.20.1 fixes an issue for OpenShift users that has to do with the finalizer RBAC, bumps gRPC to address a reported non-affecting vulnerability, and fixes a duplicate
parentRefbug when both issuer config and annotations are present (Gateway API).Bug or Regression
parentRefbug when both issuer config and annotations are present. (#8658, @hjoshi123)v1.20.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.20.0 adds alpha support for the new ListenerSet resource, adds support for Azure Private DNS; parentRefs are no longer required when using ACME with Gateway API, and OtherNames was promoted to Beta.
Changes by Kind
Feature
imagePullSecretsin thestartupapicheck-jobHelm template to enable pulling images from private registries. (#8186, @mathieu-clnk)parentRefoverride annotations on the Certificate resource. (#8518, @hjoshi123)venafi.cert-manager.io/custom-fieldsannotation on Issuer/ClusterIssuer and use it as base with override/append capabilities on Certificate level. (#8301, @k0da)acme.cert-manager.io/http01-ingress-ingressclassnameto overridehttp01.ingress.ingressClassNamefield in HTTP-01 challenge solvers. (#8244, @lunarwhite)global.nodeSelectorto helm chart to perform amergeand allow for a singlenodeSelectorto be set across all services. (#8195, @StingRayZA)XListenerSetsfeature gate (#8394, @hjoshi123)Documentation
Bug or Regression
Add full detailed DNS-01 errors to the events attached to the Challenge, for easier debugging (#8221, @wallrj-cyberark)
v1.25.5to fixCVE-2025-61727andCVE-2025-61729(#8290, @octo-sts[bot])cert-manager. Previously, it was set depending on various factors (namespace cert-manager is installed in and/or Helm release name). (#8162, @LiquidPL)Other (Cleanup or Flake)
XListenerSetsfeature gate toListenerSets(#8501, @hjoshi123)v1.19.6Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release fixes a security issue (
GHSA-8rvj-mm4h-c258, HIGH) where the defaultcert-manager-editaggregate ClusterRole granted namespace users permission to create ACMEChallengeandOrderresources directly. A user who could create aChallengereferencing aClusterIssuercould supply attacker-controlled solver configuration while cert-manager loaded credentials from theClusterIssuer's namespace, bypassing Issuer solver selectors (dnsZones,dnsNames,matchLabels). With the acme-dns provider specifically, this could disclose DNS credentials to an attacker-controlled endpoint.This release also includes Go version bumps to address reported CVEs. All users should upgrade.
Changes by Kind
Bug or Regression
createand Ordercreate,patch,updateverbs from thecert-manager-editaggregate ClusterRole (GHSA-8rvj-mm4h-c258). (#8941, @wallrj-cyberark)Other (Cleanup or Flake)
v1.25.11to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 (#8925, @wallrj-cyberark)v1.19.5Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This is a simple patch release to fix some reported vulnerabilities. All users are recommended to upgrade.
Changes by Kind
Other (Cleanup or Flake)
v1.19.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.19.4 is a simple patch release to fix some reported vulnerabilities - notably CVE-2026-24051 and CVE-2025-68121. All users should upgrade.
Changes by Kind
Bug or Regression
v1.19.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
v1.19.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We updated Go to fix some vulnerabilities in the standard library.
Changes since
v1.19.1Bug or Regression
CVE-2025-47914andCVE-2025-58181which were reported by Trivy. (#8283, @SgtCoDFish)v1.25.5to fixCVE-2025-61727andCVE-2025-61729(#8294, @wallrj-cyberark)global.nodeSelectorto helm chart to perform amergeand allow for a singlenodeSelectorto be set across all services. (#8233, @cert-manager-bot)Other (Cleanup or Flake)
golang/x/crypto(#8270, @SgtCoDFish)v1.19.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We reverted the CRD-based API defaults for
Certificate.Spec.IssuerRefandCertificateRequest.Spec.IssuerRefafter they were found to cause unexpected certificate renewals after upgrading to 1.19.0. We will try re-introducing these API defaults in cert-manager1.20.We fixed a bug that caused certificates to be re-issued unexpectedly if the
issuerRefkind or group was changed to one of the "runtime" default values.We upgraded Go to
1.25.3to address the following security vulnerabilities:CVE-2025-61724,CVE-2025-58187,CVE-2025-47912,CVE-2025-58183,CVE-2025-61723,CVE-2025-58186,CVE-2025-58185,CVE-2025-58188, andCVE-2025-61725.Changes since
v1.19.0:Bug or Regression
issuerRefof a Certificate was omitted, upgrading to1.19.xincorrectly caused the certificate to be renewed (#8175, @cert-manager-bot)v1.19.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This release focuses on expanding platform compatibility, improving deployment flexibility, enhancing observability, and addressing key reliability issues.
Changes since
v1.18.0:Feature
global.nodeSelectorto helm chart to allow for a singlenodeSelectorto be set across all services. (#7818, @StingRayZA)pathTypeExactin ACME HTTP01 Ingress challenge solvers. (#7795, @sspreitzer)applyconfigurationsallowing clients to make type-safe server-side apply requests for cert-manager resources. (#7866, @erikgb)certmanager_certificate_challenge_statusPrometheus metric. (#7736, @hjoshi123)protocolfield forrfc2136DNS01 provider (#7881, @hjoshi123)hostUsersflag to all pods. Not set by default. (#7973, @hjoshi123)--acme-http01-solver-resource-*settings. (#7972, @lunarwhite)CAInjectorMergingfeature has been promoted to BETA and is now enabled by default (#8017, @ThatsMrTalbot)certificatemetrics to the collector approach. (#7856, @hjoshi123)Bug or Regression
error waiting for authorization(#7796, @hjoshi123)class,ingressClassName,name) are specified simultaneously (#8021, @lunarwhite)global.rbac.disableHTTPChallengesRoleHelm option. (#7836, @inteon)pathlabel of core ACME client metrics and will require users to update their monitoring dashboards and alerting rules if using those metrics. (#8109, @mladen-rusev-cyberark)ingress-nginxin E2E tests to ensure compatibility (#7792, @wallrj)Other (Cleanup or Flake)
tokenrequestRoleBinding resource to improve consistency (#7761, @lunarwhite)maps.Copyfor cleaner map handling (#8092, @quantpoet)vault-client-goto the newvault/apiclient. (#8059, @armagankaratosun)v1.18.6Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.18.6 is a simple patch release to fix some reported vulnerabilities, most notably CVE-2025-68121.
NB: We didn't attempt to patch CVE-2026-24051 but that vulnerability affects macOS only, so cert-manager will be unaffected.
Changes by Kind
Bug or Regression
v1.18.5Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This release contains three bug fixes, including a fix for the MODERATE severity DoS issue in GHSA-gx3x-vq4p-mhhv. All users should upgrade to the latest release.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
v1.18.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We updated Go to fix some vulnerabilities in the standard library.
Changes since
v1.18.3Bug or Regression
CVE-2025-47914andCVE-2025-58181which were reported by Trivy. (#8282, @SgtCoDFish)v1.24.11to fixCVE-2025-61727andCVE-2025-61729(#8295, @wallrj-cyberark)Other (Cleanup or Flake)
golang/x/crypto(#8271, @SgtCoDFish)v1.18.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We fixed a bug which caused certificates to be re-issued unexpectedly, if the issuerRef kind or group was changed to one of the "runtime" default values. We increased the size limit when parsing PEM certificate chains to handle leaf certificates with large numbers of DNS named or other identities. We upgraded Go to 1.24.9 to fix various non-critical security vulnerabilities.
Changes since
v1.18.2:Bug or Regression
Other (Cleanup or Flake)
v1.18.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the
NameConstraintsfeature gate).We dropped the new
global.rbac.disableHTTPChallengesRoleHelm option due to a bug we found, this feature will be released inv1.19instead.Changes since
v1.18.1:Bug or Regression
global.rbac.disableHTTPChallengesRoleHelm option. (#7837, @cert-manager-bot)v1.18.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We have added a new feature gate
ACMEHTTP01IngressPathTypeExact, to allowingress-nginxusers to turn off the new default IngressPathType: Exactbehavior, in ACME HTTP01 Ingress challenge solvers.This change fixes the following issue: #7791
We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (
error waiting for authorization), which has been reported by multiple users, since the release of cert-managerv1.16.0.This change should fix the following issues: #7337, #7444, and #7685.
Changes since
v1.18.0:Feature
ACMEHTTP01IngressPathTypeExact, to allowingress-nginxusers to turn off the new default IngressPathType: Exactbehavior, in ACME HTTP01 Ingress challenge solvers. (#7810, @sspreitzer)Bug or Regression
error waiting for authorization. (#7801, @hjoshi123)Other (Cleanup or Flake)
#7807, @wallrj)v1.18.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.18 introduces several new features and breaking changes. Highlights include support for ACME certificate profiles, a new default for
Certificate.Spec.PrivateKey.RotationPolicynow set toAlways(breaking change), and the defaultCertificate.Spec.RevisionHistoryLimitnow set to1(potentially breaking).Known Issues
Changes since
v1.17.2:Feature
app.kubernetes.io/managed-by: cert-managerlabel to the created Let's Encrypt account keys (#7577, @terinjokes)certmanager_certificate_not_before_timestamp_seconds,certmanager_certificate_not_after_timestamp_seconds). (#7612, @solidDoWant)--extra-certificate-annotations, which sets a list of annotation keys to be copied from Ingress-like to resulting Certificate object (#7083, @k0da)issshort name for the cert-managerIssuerresource. (#7373, @SgtCoDFish)cissshort name for the cert-managerClusterIssuerresource (#7373, @SgtCoDFish)global.rbac.disableHTTPChallengesRolehelm value to disable HTTP-01 ACME challenges. This allows cert-manager to drop its permission to create pods, improving security when HTTP-01 challenges are not required. (#7666, @ali-hamza-noor)FindZoneByFqdn(#7596, @ThatsIvan)UseDomainQualifiedFinalizerfeature to GA. (#7735, @jsoref)Certificate.Spec.PrivateKey.RotationPolicychanged fromNevertoAlways. (#7723, @wallrj)Documentation
Bug or Regression
go-josedependency to addressCVE-2025-27144. (#7606, @SgtCoDFish)golang.org/x/oauth2to patchCVE-2025-22868. (#7638, @NicholasBlaskey)golang.org/x/cryptoto patchGHSA-hcg3-q754-cr77. (#7638, @NicholasBlaskey)github.com/golang-jwt/jwtto patchGHSA-mh63-6h87-95cp. (#7638, @NicholasBlaskey)ImplementationSpecifictoExactfor a reliable handling of ingress controllers and enhanced security. (#7767, @sspreitzer)--namespace=<namespace>: limit the scope of cert-manager to a single namespace and disable cluster-scoped controllers. (#7678, @tsaarni)commonNamefield; IP addresses are no longer added to the DNSsubjectAlternativeNamelist and are instead added to theipAddressesfield as expected. (#7081, @johnjcool)certmanager_certificate_renewal_timestamp_secondsmetric help text indicating that the metric is relative to expiration time, rather than Unix epoch time. (#7609, @solidDoWant)Passthroughmode. (#6986, @vehagn)golang.org/x/netfixingCVE-2025-22870. (#7619, @dependabot[bot])Other (Cleanup or Flake)
third_party/forked/acmepackage with support for the ACME profiles extension. (#7776, @wallrj)AdditionalCertificateOutputFormatsfeature to GA, making additional formats always enabled. (#7744, @erikgb)ValidateCAA. Setting this feature gate is now a no-op which does nothing but print a warning log line (#7553, @SgtCoDFish)v1.24.4(#7785, @wallrj)v1.17.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
We fixed a bug in the CSR's name constraints construction (only applies if you have enabled the
NameConstraintsfeature gate).Changes since
v1.17.3:Bug or Regression
v1.17.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23.
We have increased the ACME challenge authorization timeout to two minutes, which we hope will fix a timeout error (
error waiting for authorization), which has been reported by multiple users, in: #7337, #7444, and #7685.Changes since
v1.17.2:Bug or Regression
waiting for authorization(#7798, @hjoshi123)Other (Cleanup or Flake)
v1.17.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23 and includes various dependency updates.
Changes since
v1.17.1Bug or Regression
v1.23.8to fixCVE-2025-22871(#7701,@wallrj)go-josedependency to addressCVE-2025-27144(#7603,@SgtCoDFish)golang.org/x/netto addressCVE-2025-22870reported by Trivy (#7622,@SgtCoDFish)golang.org/x/netto fixCVE-2025-22872(#7703,@wallrj)golang.org/x/oauth2to patchCVE-2025-22868(#7692,@lentzi90)golang.org/x/cryptoto patchGHSA-hcg3-q754-cr77(#7692,@lentzi90)github.com/golang-jwt/jwtto patchGHSA-mh63-6h87-95cp(#7692,@lentzi90)v1.17.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This release is primarily intended to address a breaking change in Cloudflare's API which impacted ACME DNS-01 challenges using Cloudflare.
Many thanks to the community members who reported this issue!
Changes by Kind
Bug or Regression
v1.17.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.17.0 is a feature release with several improvements, including:
Major Themes
RSA Certificate Compliance
The United States Department of Defense published a memo in 2022 which introduced some requirements on the kinds of cryptography they require to be supported in software they use.
In effect, the memo requires that software be able to support larger RSA keys (3072-bit and 4096-bit) and hashing algorithms (SHA-384 at a minimum).
cert-manager supported large RSA keys long before the memo was published, but a quirk in implementation meant that cert-manager always used SHA-256 when signing with RSA.
In v1.17.0, cert-manager will choose a hash algorithm based on the RSA key length: 3072-bit keys will use SHA-384, and 4096-bit keys will use SHA-512. This matches similar behavior already present for ECDSA signatures.
Our expectation is that this change will have minimal impact beyond a slight increase to security and better compliance; we're not aware of Kubernetes based environments which support RSA 2048 with SHA-256 but fail with RSA 4096 and SHA-512. However, if you're using larger RSA keys, you should be aware of the change.
Easier Keystore Passwords for PKCS#12 and JKS
Specifying passwords on PKCS#12 and JKS keystores is supported in cert-manager
for compatibility reasons with software which expects or requires passwords to be set; however, these passwords are not relevant to security and never have been in cert-manager.
The initial implementation of the
keystoresfeature required these "passwords" to be stored in a Kubernetes secret, which would then be read by cert-manager when creating the keystore after a certificate was issued. This is cumbersome, especially when many passwords are set to default values such aschangeitorpassword.In cert-manager v1.17, it's now possible to set a keystore password using a literal string value inside the
Certificateresource itself, making this process much easier with no change to security.For example:
The new
passwordfield is mutually exclusive with thepasswordSecretReffield, so be sure to only set one.Feature Flag Promotions / Deprecations
cert-manager's feature flags allow for easier testing and adoption of new features with a reduced risk of breaking changes. In cert-manager v1.17, two feature gates have been promoted to "beta", and as such are now enabled by default in all installations:
NameConstraints, allowing users to specify the name constraints extension which can be helpful when creating CA certificates for private PKIUseDomainQualifiedFinalizer, which stops a Kubernetes warning from being printed in logsIn addition, we added a new feature gate:
CAInjectorMerging, which intelligently combines certificates used by theCAInjectorcomponent, making it safer to use when issuing certificates are rotated. If you're making heavy use of the CA injector, you should consider enabling this feature gate.Finally, we deprecated the
ValidateCAAfeature gate which will be removed entirely in cert-manager v1.18.0. This feature gate aimed to validate theCAADNS record during ACME issuance, but has seen low adoption and limited testing since its introduction back in 2019.Other Changes
There are many other PRs which were merged in this release cycle and we'd encourage you to read the release notes below. One PR that's worth highlighting is a change to add more structured logging information to certain log lines.
If you were previously filtering logs using
grepor similar tools (which is highly discouraged!) be aware that some log lines have changed format.Community
As always, we'd like to thank all of the community members who helped in this release cycle, including all below who merged a PR and anyone that helped by commenting on issues, testing, or getting involved in cert-manager meetings. We're lucky to have you involved.
A special thanks to:
for their contributions, comments and support!
Also, thanks to the cert-manager maintainer team for their help in this release:
And finally, thanks to the cert-manager steering committee for their feedback in this release cycle:
Changes by Kind
Feature
webhook.extraEnvallows you to set custom environment variables in the webhook Pod.Helm: New value
cainjector.extraEnvallows you to set custom environment variables in the cainjector Pod.Helm: New value
startupapicheck.extraEnvallows you to set custom environment variables in the startupapicheck Pod. (#7317, @wallrj)pki.DecodeX509CertificateSetBytesis able to parse, to enable reading larger TLS trust bundles (#7464, @SgtCoDFish)UseDomainQualifiedFinalizerfeature to Beta. (#7488, @jsoref)tplfunction on keys and values, to aid with workload identity configuration (#7501, @fcrespofastly)Documentation
--dns01-recursive-nameservers(#7367, @SgtCoDFish)enableGatewayAPIin the config example. (#7354, @puerco)Bug or Regression
podDisruptionBudget.minAvailableandpodDisruptionBudget.maxAvailablevalues. (#7343, @inteon)renewBeforePercentageto comply with its spec (#7421, @adam-sroka)enabledto be set as a value to toggle cert-manager as a dependency. (#7350, @inteon)Other (Cleanup or Flake)
ValidateCAAfeature gate is now deprecated, with removal scheduled for cert-manager 1.18. In 1.17, enabling this feature gate will print a warning. (#7491, @jsoref)Neither --kubeconfig nor --master was specifiedwarning message when the controller and the webhook services boot (#7457, @Peac36)v1.16.5Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release addresses several vulnerabilities reported by the Trivy security scanner. It is built with the latest version of Go 1.23 and includes various dependency updates.
Changes since
v1.16.4:Bug or Regression
v1.23.8to fixCVE-2025-22871(#7706,@wallrj)github.com/golang-jwt/jwt/v5tov5.2.2to fixCVE-2025-30204(#7708,@wallrj)golang.org/x/netto fixCVE-2025-22872(#7707,@wallrj)go-josedependency to addressCVE-2025-27144(#7602,@SgtCoDFish)golang.org/x/netto addressCVE-2025-22870reported by Trivy (#7623,@SgtCoDFish)v1.16.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This release is primarily intended to address a breaking change in Cloudflare's API which impacted ACME DNS-01 challenges using Cloudflare.
Many thanks to the community members who reported this issue!
Changes by Kind
Bug or Regression
v1.16.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.16.3 is a patch release mainly focused around bumping dependencies to address reported CVEs: CVE-2024-45337 and CVE-2024-45338.
We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners.
It also includes a bug fix to the new
renewBeforePercentagefield. If you were usingrenewBeforePercentage, see PR #7421 for more information.Changes
Bug
golang.org/x/netandgolang.org/x/cryptoto address CVE-2024-45337 and CVE-2024-45338 (#7485, @erikgb)renewBeforePercentageto comply with its spec (#7441, @cert-manager-bot)Other
v1.16.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release of cert-manager 1.16 makes several changes to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed.
This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project.
The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods.
Note also that since most PEM data parsed by cert-manager comes from
ConfigMaporSecretresources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data.Further information is available in https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4
In addition, the version of Go used to build cert-manager 1.16 was updated along with the base images.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
v1.16.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer.
📖 Read the complete 1.16 release notes before upgrading.
📜Changes since
v1.16.0Bug or Regression
@inteon)podDisruptionBudget.minAvailableandpodDisruptionBudget.maxAvailablevalues. (#7345,@inteon)enabledto be set as a value to toggle cert-manager as a dependency. (#7356,@inteon)v1.16.0caused cert-manager's ACME ClusterIssuer to look in the wrong namespace for resources required for the issuance (e.g. credential Secrets). This is now fixed inv1.16.1. (#7342,@inteon)v1.16.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
The cert-manager 1.16 release includes: new Helm chart features, more Prometheus metrics, memory optimizations, and various improvements and bug fixes for the ACME issuer and Venafi Issuer.
📖 Read the complete 1.16 release notes at cert-manager.io.
⚠️ Known issues
❗ Breaking changes
📖 Read the complete 1.16 release notes at cert-manager.io.
📜 Changes since v1.15.0
📖 Read the complete 1.16 release notes at cert-manager.io.
Feature
SecretRefsupport for Venafi TPP issuer CA Bundle (#7036,@sankalp-at-gh)renewBeforePercentagealternative torenewBefore(#6987,@cbroglie)@wallrj)@wallrj)@joshmue)@mindw)app.kubernetes.io/managed-by: cert-managerlabel to the cert-manager-webhook-ca Secret (#7154,@jrcichra)@ThatsMrTalbot)@Jasper-Ben)@wallrj)@wallrj)AWS_REGIONenvironment variable.Feature: The Route53 DNS solver of the ACME Issuer now uses the "ambient" region (
AWS_REGIONorAWS_DEFAULT_REGION) ifissuer.spec.acme.solvers.dns01.route53.regionis empty; regardless of the flags--issuer-ambient-credentialsand--cluster-issuer-ambient-credentials. (#7299,@wallrj)@inteon)--controllersflag only specifies disabled controllers, the default controllers are now enabled implicitly.Added
disableAutoApprovalandapproveSignerNamesHelm chart options. (#7049,@inteon)config.apiVersionandconfig.kindwithin the Helm chart. (#7126,@ThatsMrTalbot)@Guitarkalle)cainjector, by only caching the metadata of Secret resources.Reduce the load on the K8S API server when
cainjectorstarts up, by only listing the metadata of Secret resources. (#7161,@wallrj)AWS_REGIONandAWS_DEFAULT_REGIONenvironment variables, which is set by the IAM for Service Accounts (IRSA) webhook and by the Pod Identity webhook.The
issuer.spec.acme.solvers.dns01.route53.regionfield is now optional.The API documentation of the
regionfield has been updated to explain when and how the region value is used. (#7287,@wallrj)Breaking: cert-manager will no longer use the API Key authentication method which was deprecated in 20.2 and since removed in 24.1 of TPP. (#7084,
@hawksight)@aidy)webhook.extraEnv, allows you to set custom environment variables in the webhook Pod.Helm: New value
cainjector.extraEnv, allows you to set custom environment variables in the cainjector Pod.Helm: New value
startupapicheck.extraEnv, allows you to set custom environment variables in the startupapicheck Pod. (#7319,@wallrj)Bug or Regression
metadata.finalizers: "finalizer.acme.cert-manager.io": prefer a domain-qualified finalizer name to avoid accidental conflicts with other finalizer writers(#7273,@jsoref)aws-globalSTS region which is now required by thegithub.com/aws/aws-sdk-go-v2library. (#7108,@inteon)@inteon)@inteon)@wallrj)@wallrj)grpc-goto fixGHSA-xr7q-jx4m-x55m(#7164,@SgtCoDFish)go-retryablehttpdependency to fixCVE-2024-6104(#7125,@SgtCoDFish)@eplightning)endpointAdditionalPropertiesin thePodMonitortemplate of the Helm chart (#7190,@wallrj)@miguelvr)@bdols)@inteon)@inteon)KeyUsagesX.509 extension is no longer added when there are no key usages set (in accordance to RFC 5280 Section 4.2.1.3) (#7250,@inteon)github.com/Azure/azure-sdk-for-go/sdk/azidentityto addressCVE-2024-35255(#7087,@dependabot[bot])Other (Cleanup or Flake)
Removed:
(acme.)cert-manager.io/v1alpha2
(acme.)cert-manager.io/v1alpha3
(acme.)cert-manager.io/v1beta1 (#7278,
@inteon)v0.31.0removes a lot of noisyreflector.go: unable to sync list result: internal error: cannot cast object DeletedFinalStateUnknownerrors from logs. (#7237,@inteon)v1.23.2(#7324,@cert-manager-bot)v1.15.5Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager v1.15.5 contains simple dependency bumps to address reported CVEs (CVE-2024-45337 and CVE-2024-45338).
We don't believe that cert-manager is actually vulnerable; this release is instead intended to satisfy vulnerability scanners.
Changes
Bug or Regression
Other (Cleanup or Flake)
v1.15.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
This patch release of cert-manager 1.15 makes several changes to how PEM input is validated, adding maximum sizes appropriate to the type of PEM data which is being parsed.
This is to prevent an unacceptable slow-down in parsing specially crafted PEM data. The issue was found by Google's OSS-Fuzz project.
The issue is low severity; to exploit the PEM issue would require privileged access which would likely allow Denial-of-Service through other methods.
Note also that since most PEM data parsed by cert-manager comes from
ConfigMaporSecretresources which have a max size limit of approximately 1MB, it's difficult to force cert-manager to parse large amounts of PEM data.Further information is available in https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4
In addition, the version of Go used to build cert-manager 1.15 was updated along with the base images, and a Route53 bug fix was backported.
Changes by Kind
Bug or Regression
Other (Cleanup or Flake)
v1.15.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
🔗 See v1.15.0 for more information about cert-manager 1.15 and read-before-upgrade info.
📜 Changes since
v1.15.2Bug or Regression
v1.15.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
🔗 See v1.15.0 for more information about cert-manager 1.15 and read-before-upgrade info.
📜 Changes since
v1.15.1Bug or Regression
route53: explicitly set theaws-globalSTS region which is now required by thegithub.com/aws/aws-sdk-go-v2library. (#7189,@cert-manager-bot)grpc-goto fixGHSA-xr7q-jx4m-x55m(#7167,@SgtCoDFish)@cert-manager-bot)endpointAdditionalPropertiesin thePodMonitortemplate of the Helm chart (#7191,@inteon)HTTPRouteresources (#7186,@cert-manager-bot)golangfrom1.22.3to1.22.5(#7165,@github-actions)v1.15.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
🔗 See v1.15.0 for more information about cert-manager 1.15 and read-before-upgrade info.
📜 Changes since v1.15.0
Bug or Regression
Other (Cleanup or Flake)
v1.15.0Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.15 promotes several features to beta, including GatewayAPI support (
ExperimentalGatewayAPISupport), the ability to provide a subject in the Certificate that will be used literally in the CertificateSigningRequest (LiteralCertificateSubject) and the outputting of additional certificate formats (AdditionalCertificateOutputFormats).Community
Thanks again to all open-source contributors with commits in this release, including: @Pionerd, @SgtCoDFish, @ThatsMrTalbot, @andrey-dubnik, @bwaldrep, @eplightning, @erikgb, @findnature, @gplessis, @import-shiburin, @inteon, @jkroepke, @lunarwhite, @mangeshhambarde, @pwhitehead-splunk & @rodrigorfk, @wallrj.
Thanks also to the following cert-manager maintainers for their contributions during this release: @SgtCoDFish, @SpectralHiss, @ThatsMrTalbot, @hawksight, @inteon, @maelvls & @wallrj.
Equally thanks to everyone who provided feedback, helped users and raised issues on GitHub and Slack and joined our meetings!
Thanks also to the CNCF, which provides resources and support, and to the AWS open source team for being good community members and for their maintenance of the PrivateCA Issuer.
In addition, massive thanks to Venafi for contributing developer time and resources towards the continued maintenance of cert-manager projects.
Changes by Kind
Feature
--enable-gateway-apiflag to enable the integration. (#6961, @ThatsMrTalbot)For example:
cert-manager-certificaterequests-issuer-venafi/v1.15.0+(linux/amd64)+cert-manager/ef068a59008f6ed919b98a7177921ddc9e297200. (#6865, @wallrj)LiteralCertificateSubjectfeature to Beta. (#7030, @inteon)extraObjects; a list of yaml manifests which will helm will install and uninstall with the cert-manager manifests. (#6424, @gplessis)cert-manager.io/allow-direct-injectionin annotations (#6801, @jkroepke)Design
Bug or Regression
preferredChainis configured. (#6755, @import-shiburin)disableAutoApprovalandapproveSignerNamesHelm chart options. (#7054, @inteon)Other (Cleanup or Flake)
crds.keepandcrds.enabledHelm options can now be used instead of theinstallCRDsoption. (#6760, @inteon)slicesandk8s.io/apimachinery/pkg/utilpackages.Removed deprecated CSR functions which have been replaced with other functions in the
pkg/util/pkipackage. (#6730, @inteon)cmctlandkubectl cert-mangerhave been moved to the https://github.com/cert-manager/cmctl repo and will be versioned separately starting with cmctl v2.0.0 (#6663, @inteon)pkg/util/pki/ParseSubjectStringToRawDERBytesfunction. (#6994, @inteon)--controllersflag only specifies disabled controllers, the default controllers are now enabled implicitly. (#7054, @inteon)GO-2024-2824. (#6996, @github-actions[bot])v1.14.7Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
📜 Changes since v1.14.6
Bugfixes
Other (Cleanup or Flake)
v1.14.6Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
📜 Changes since v1.14.5
Other (Cleanup or Flake)
v1.14.5Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
v1.14.5fixes a bug in the DigitalOcean DNS-01 provider which could cause incorrect DNS records to be deleted when using a domain with a CNAME. Special thanks to @BobyMCbobs for reporting this issue and testing the fix!It also patches CVE-2023-45288.
📜 Changes since v1.14.4
preferredChainis configured: see 1.14 release notes for more information.Changes
Bug or Regression
v1.14.4Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.
⚠️ Known Issues
ℹ️ Documentation
Release notes
Upgrade notes
Installation instructions
🔧 Breaking changes
See Breaking changes in v1.14.0 release notes
📜 Changes since v1.14.3
Bug or Regression
cert-manager.io/allow-direct-injectionin annotations (#6809, @jetstack-bot)Other (Cleanup or Flake)
v1.14.3Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.
⚠️ Known Issues
ℹ️ Documentation
Release notes
Upgrade notes
Installation instructions
🔧 Breaking changes
See Breaking changes in v1.14.0 release notes
📜 Changes since v1.14.2
Bug or Regression
v1.14.2Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.
⚠️ Known Issues
preferredChainis configured: see release docs for more info and mitigationsℹ️ Documentation
Release notes
Upgrade notes
Installation instructions
🔧 Breaking changes
See
Breaking changesin v1.14.0 release notes📜 Changes since
v1.14.1Bug or Regression
Other (Cleanup or Flake)
v1.14.1Compare Source
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.14 brings a variety of features, security improvements and bug fixes, including: support for creating X.509 certificates with "Other Name" fields, and support for creating CA certificates with "Name Constraints" and "Authority Information Accessors" extensions.
⚠️ Known Issues (please install
v1.14.2)preferredChainis configured: see release docs for more info and mitigationsCAandSelfSignedissuers issue certificates with SANs set to non-critical even when the subject is empty. It incorrectly copies the critical field from the CSR.🔧 Breaking changes
See
Breaking changesin v1.14.0 release notesℹ️ Documentation
📜 Changes since
v1.14.0Bug or Regression
cmctl experimental installto panic. (#6706, @inteon)gitea/helm-gitea (gitea)
v12.7.0Compare Source
Features
7747a00)Maintenance
5005037)61d6d23)b6ded8d)e97e592)78276bc)2691024)8198a89)323b6bc)8498819)44d7783)go-gitea/gitea (gitea/gitea)
v1.27.3Compare Source
v1.27.2Compare Source
SECURITY
ENHANCEMENTS
BUGFIXES
${{ }}part on its own (#38754) (#38797)v1.27.1Compare Source
SECURITY
API
ENHANCEMENTS
BUGFIXES
ApproveRuns(#38653) (#38654)matrixwhen evaluating workflowifexpression (#38474) (#38557)cancelled()work in jobifevaluation (#38495) (#38497)github.eventfor scheduled runs (#38446) (#38452)MISC
v1.27.0Compare Source
BREAKING
SECURITY
FEATURES
jobs.<job_id>.continue-on-error(#38100)ActionRunAttemptto represent each execution of a run (#37119)ENHANCEMENTS
ExternalIDClaimoption for OAuth2 OIDC auth source (#37229)PERFORMANCE
c_uindex to includecreated_unixfor faster dashboard feeds (#38076)BUGFIXES
FetchTask(#38343) (#38347)form-fetch-actionto some forms, fix "fetch action" resp bug (#37305)relative-timeerror and improve global error handler (#37241)TESTING
FileInfoinTestInitKeys(#38330) (#38331)issue-commentclose test (#37880)TestResourceIndexand reduce its runtime (#37847)TestAPIRepoMigrateoffline via a local clone source (#37817)BUILD
zizmortolint-actions(#37720)nektos/actfork togitea/runner(#37557)golangci-lint fmt(#37194)DOCS
MISC
fill/strokecolors, add vars for git graph color series (#37543)delete-buttonwithlink-action(#38143)files-changed, addfree-disk-space(#37819)workflowpatternintomodules/actions(#37717)choretype in PR title lint (#37575)Permissionfield inRepositorystruct instead of anonymous embedding (#37441)olivere/elasticwith REST API client, add OpenSearch support (#37411)/assets/site-manifest.jsonendpoint (#37405)Block a userform (#37359)errorMessagehelper (#37292)tw-justify-betweenlayouts toflex-left-right(#37291)SubmitEventpolyfill (#37276)deadcodetool (#37271)v1.26.4Compare Source
SECURITY
BUGFIXES
v1.26.3Compare Source
BREAKING
SECURITY
API
BUGFIXES
workflow_callfrom workflow trigger detection (#37894) (#37899)UpdateLogfinalize idempotently (#37885) (#37892)BUILD
@playwright/testto 1.60.0 (#38144)tools/ci-tools.tsfor the PR labeler workflow (#37831)v1.26.2Compare Source
SECURITY
BUGFIXES
prioritycolor (#37417) (#37421)MISC
v1.26.1Compare Source
v1.26.0Compare Source
concurrencysyntax (#32751)ListUnadoptedRepositories(#36884)concurrencysyntax (#32751)mentionValuesasynchronously (#36739)--batch-commandapproach (#35775)elklayout support to mermaid (#36486)actions.WORKFLOW_DIRSsetting (#36619)inputborder hover effect (#36870)localStorage(#36623)X_FRAME_OPTIONSsetting fromcorstosecuritysection (#30256)DEFAULT_DELETE_BRANCH_AFTER_MERGEsetting (#36917)neveroption toPUBLIC_URL_DETECTIONconfiguration (#36785)add-matcherandremove-matcherfrom actions job logs (#36520).commit-sign-badgechildren (#36570)TestActionsCollaborativeOwner(#36657)no-contentmessage not rendering after comment edit (#36733)strictNullChecks-related issues (#35795)CrossOriginProtection(#36183)cmd/to use constructor functions. (#36962)relative-timeto render absolute dates (#36238)util.URLJoinand replace all callers with direct path concatenation (#36867)flake-utils(#35675)google/go-licenseswith custom generation (#36575)gitea-vetto usego tool(#35878)strictNullChecks(#35843)vue/require-typed-refeslint rule (#35764)codeformatfolder to tools (#35758)@ts-expect-error(#36513)lint-go-goplswith additionalgovetlinters (#36028)setup-uvto v8.0.0 (#37101)go-gitto v5.17.2 and related dependencies (#37060)golang.org/x/imageto v0.38.0 (#37054)docker-dryrun(#36379)v1.25.5Compare Source
security-checkinformational only (#36681) (#36852)grafana/helm-charts (grafana)
v8.15.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.8.0-weekly.339+dev.1...grafana-8.15.0
v8.14.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
6cd0753by @jcpunk in #3691Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.80.5...grafana-8.14.2
v8.14.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.38.3...grafana-8.14.1
v8.14.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.13.2...grafana-8.14.0
v8.13.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.5-beta.1...grafana-8.13.2
v8.13.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.4-beta.1...grafana-8.13.1
v8.13.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-1.0.2...grafana-8.13.0
v8.12.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.80.3...grafana-8.12.1
v8.12.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/cloudcost-exporter-1.0.1...grafana-8.12.0
v8.11.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.35.0...grafana-8.11.4
v8.11.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.11.2...grafana-8.11.3
v8.11.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/rollout-operator-0.25.0...grafana-8.11.2
v8.11.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-sampling-1.1.5...grafana-8.11.1
v8.11.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-operator-0.2.1-beta.1...grafana-8.11.0
v8.10.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.6.29...grafana-8.10.4
v8.10.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.10.2...grafana-8.10.3
v8.10.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.32.3...grafana-8.10.2
v8.10.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-2.0.12...grafana-8.10.1
v8.10.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.9.1...grafana-8.10.0
v8.9.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.26.0...grafana-8.9.1
v8.9.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.8.6...grafana-8.9.0
v8.8.6Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-agent-operator-0.5.1...grafana-8.8.6
v8.8.5Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.7.0-weekly.325...grafana-8.8.5
v8.8.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.24.1...grafana-8.8.4
v8.8.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.6.2...grafana-8.8.3
v8.8.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-1.16.0...grafana-8.8.2
v8.8.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.8.0...grafana-8.8.1
v8.8.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.7.1...grafana-8.8.0
v8.7.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.26.1...grafana-8.7.1
v8.7.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.26.0...grafana-8.7.0
v8.6.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.22.0...grafana-8.6.4
v8.6.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.5.0...grafana-8.6.3
v8.6.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.6.0-weekly.318...grafana-8.6.2
v8.6.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/oncall-1.13.3...grafana-8.6.1
v8.6.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-vulture-0.7.0...grafana-8.6.0
v8.5.12Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
managed-byshould not be templated by @bleggett in #3398New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.4.5...grafana-8.5.12
v8.5.11Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.5.10...grafana-8.5.11
v8.5.10Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/beyla-1.4.4...grafana-8.5.10
v8.5.9Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.6.1...grafana-8.5.9
v8.5.8Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.5.7...grafana-8.5.8
v8.5.7Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.9.2...grafana-8.5.7
v8.5.6Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.18.0...grafana-8.5.6
v8.5.5Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.18.4...grafana-8.5.5
v8.5.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/mimir-distributed-5.5.0...grafana-8.5.4
v8.5.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.9.1...grafana-8.5.3
v8.5.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.9.0...grafana-8.5.2
v8.5.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.11.0...grafana-8.5.1
v8.5.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.9...grafana-8.5.0
v8.4.9Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.10.1...grafana-8.4.9
v8.4.8Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.6.1...grafana-8.4.8
v8.4.7Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.6...grafana-8.4.7
v8.4.6Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.17.0...grafana-8.4.6
v8.4.5Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-sampling-1.0.0...grafana-8.4.5
v8.4.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.3...grafana-8.4.4
v8.4.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.4.2...grafana-8.4.3
v8.4.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.16.1...grafana-8.4.2
v8.4.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.4.4...grafana-8.4.1
v8.4.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.79.2...grafana-8.4.0
v8.3.8Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.15.3...grafana-8.3.8
v8.3.7Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-agent-operator-0.4.1...grafana-8.3.7
v8.3.6Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.3.5...grafana-8.3.6
v8.3.5Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/synthetic-monitoring-agent-0.3.0...grafana-8.3.5
v8.3.4Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/loki-distributed-0.79.1...grafana-8.3.4
v8.3.3Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.5.1...grafana-8.3.3
v8.3.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/helm-loki-6.6.5...grafana-8.3.2
v8.3.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.3.0...grafana-8.3.1
v8.3.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.13.2...grafana-8.3.0
v8.2.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.13.1...grafana-8.2.2
v8.2.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.2.0...grafana-8.2.1
v8.2.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.1.1...grafana-8.2.0
v8.1.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
Full Changelog: https://github.com/grafana/helm-charts/compare/grafana-8.1.0...grafana-8.1.1
v8.1.0Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/alloy-0.4.0...grafana-8.1.0
v8.0.2Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/k8s-monitoring-1.0.13...grafana-8.0.2
v8.0.1Compare Source
The leading tool for querying and visualizing time series and metrics.
What's Changed
folderUidoption by @Rohlik in #2956New Contributors
Full Changelog: https://github.com/grafana/helm-charts/compare/tempo-distributed-1.11.0...grafana-8.0.1
kubernetes-sigs/kind (kind)
v0.32.0This release contains critical dependency updates, bug fixes, and defaults to Kubernetes 1.36.1.
Breaking Changes
kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5kind load ...: Due to a containerd upgrade, you must upgradekindto this release or newer to usekind load ...with the newly published node images. As always, we cannot gurantee full compatibility of node images between kind releases. You can use the digests from previous releases, upgrade kind, or build your own node-images.docker.io/envoyproxy/envoy:v1.36.2) as the load balancer in multi-control-plane (HA) clusters. If you rely on custom HAProxy loadbalancer configurations or images, please note that Envoy is now used.New Features
v1beta4config format for Kubernetesv1.36.0+while maintainingv1beta3forv1.23.0up tov1.35.x, andv1beta2for older versions.extraArgs/kubeletExtraArgspatches to the list-basedv1beta4format when targetingv1beta4configs.extraArgs/kubeletExtraArgs/certSANsreliably. To overwrite or make other more precise patching, use json6902 patches.kind loadand snapshotter parsing, which is required for newer containerd versions.https://dl.k8s.io/ci/latest.txtor CI build prefixes).versionand if specified in patches will only apply patches that match the containerd config being used.Images pre-built for this release:
kindest/node:v1.36.1@sha256:3489c7674813ba5d8b1a9977baea8a6e553784dab7b84759d1014dbd78f7ebd5kindest/node:v1.35.5@sha256:ce977ae6d65918d0b58a5f8b5e940429c2ce42fa3a5619ec2bbc60b949c0ac95kindest/node:v1.34.8@sha256:02722c2dedddcfc00febf5d27fbeb9b7b2c14294c82109ff4a85d89ac9ba3256kindest/node:v1.33.12@sha256:3f5c8443c620245e4d355cfe09e96a91ead32ceaa569d3f1ca9edf0cb2fe2ff4NOTE: You must use the
@sha256digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons.Fixes
hostUsers: false(Kubernetes 1.36+).localhost:5000/...)./dev/mappermount on rootless Docker.See also:
NOTE: These node images support amd64 and arm64, both of our supported platforms. You must use the same platform as your host, for more context see #2718
Contributors
Committers for this release:
We'd also like to thank everyone who touched the codebase, filed issues, and helped the community!
v0.31.0This release contains dependency updates and defaults to Kubernetes 1.35.0.
Please take note of the breaking changes from Kubernetes 1.35, and how to prepare for future changes to move off of the deprecated kubeam v1beta3 in favor of v1beta4. We will include updated reminders for both again in subsequent releases.
Breaking Changes
The default node image is now
kindest/node:v1.35.0@sha256:452d707d4862f52530247495d180205e029056831160e22870e37e3f6c1ac31fKubernetes 1.35+ Cgroup v1
Kubernetes will be removing cgroup v1 support, and therefore kind node images at those versions will also be dropping support.
You can read more about this change in the Kubernetes release blog: https://kubernetes.io/blog/2025/12/17/kubernetes-v1-35-release/#removal-of-cgroup-v1-support
If you must use kind on cgroup v1, we recommend using an older Kubernetes release for the immediate future, but we also strongly recommend migrating to cgroup v2.
In the near future as Kubernetes support dwindles, KIND will also clean up cgroup v1 workarounds and drop support in future kind releases and images, regardless of Kubernetes version.
Most stable linux distros should be on cgroupv2 out of the box.
This is a reminder to use pinned images by digest, see the note below about images for this release.
Kubeadm Config *Future* Breaking Change
WARNING: Future kind releases will adopt kubeadm v1beta4 configuration, kubeadm v1beta4 has a breaking change to
extraArgs: https://kubernetes.io/blog/2024/08/23/kubernetes-1-31-kubeadm-v1beta4/.If you use the
kubeadmConfigPatchesfeature then you may need to prepare for this change.We recommend that you use versioned config patches that explicitly match the version required.
KIND uses kubeadm v1beta3 for Kubernetes 1.23+, and will likely use v1beta4 for Kubernetes 1.36+
The exact version is TBD pending work to fix this but expected to be 1.36.
It will definitely be an as-of-yet-unreleased Kubernetes version to avoid surprises, and it will not be on a patch-release boundary.
KIND may still work with older Kubernetes versions at v1beta2, but we no longer test or actively support these as Kubernetes only supports 1.32+ currently: https://kubernetes.io/releases/
You likely only need v1beta3 + v1beta4 patches, you can take your existing patches that work with v1beta3, explicitly set
apiVersion: kubeadm.k8s.io/v1beta3in the patch at the top level, and make another copy for v1beta4. The v1beta4 patch will need to moveextraArgsfrom a map to a list, for examples see: https://kubernetes.io/docs/reference/config-api/kubeadm-config.v1beta4/For a concrete example of kind config with kubeadm config patch targeting both v1beta3 and v1beta4, consider this simple kind config that sets verbosity of the apiserver logs:
If you only need to target a particular release, you can use one version.
If you only need to target fields that did not change between kubeadm beta versions, you can use a versionless patch, which may be more convenient, but we cannot guarantee there will be no future kubeadm config breaking changes.
New Features
Images pre-built for this release:
kindest/node:v1.35.0@sha256:452d707d4862f52530247495d180205e029056831160e22870e37e3f6c1ac31fkindest/node:v1.34.3@sha256:08497ee19eace7b4b5348db5c6a1591d7752b164530a36f855cb0f2bdcbadd48kindest/node:v1.33.7@sha256:d26ef333bdb2cbe9862a0f7c3803ecc7b4303d8cea8e814b481b09949d353040kindest/node:v1.32.11@sha256:5fc52d52a7b9574015299724bd68f183702956aa4a2116ae75a63cb574b35af8kindest/node:v1.31.14@sha256:6f86cf509dbb42767b6e79debc3f2c32e4ee01386f0489b3b2be24b0a55aac2bNOTE: You must use the
@sha256digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons.See also:
NOTE: These node images support amd64 and arm64, both of our supported platforms. You must use the same platform as your host, for more context see #2718
Fixes
Contributors
Committers for this release:
v0.30.0This is small release containing patched dependencies and Kubernetes 1.34, as well as a bugfix for Kubernetes v1.33.0+ cluster reboots.
Breaking Changes
The default node image is now
kindest/node:v1.34.0@sha256:7416a61b42b1662ca6ca89f02028ac133a309a2a30ba309614e8ec94d976dc5aNew Features
Images pre-built for this release:
kindest/node:v1.34.0@sha256:7416a61b42b1662ca6ca89f02028ac133a309a2a30ba309614e8ec94d976dc5akindest/node:v1.33.4@sha256:25a6018e48dfcaee478f4a59af81157a437f15e6e140bf103f85a2e7cd0cbbf2kindest/node:v1.32.8@sha256:abd489f042d2b644e2d033f5c2d900bc707798d075e8186cb65e3f1367a9d5a1kindest/node:v1.31.12@sha256:0f5cc49c5e73c0c2bb6e2df56e7df189240d83cf94edfa30946482eb08ec57d2NOTE: You must use the
@sha256digest to guarantee an image built for this release, until such a time as we switch to a different tagging scheme. Even then we will highly encourage digest pinning for security and reproducibility reasons.See also:
NOTE: These node images support amd64 and arm64, both of our supported platforms. You must use the same platform as your host, for more context see #2718
Fixes
Contributors
Committers for this release:
sunny0826/kubecm (kubecm)
v0.35.1: kubecm-v0.35.1Changelog
What's Changed
Full Changelog: https://github.com/sunny0826/kubecm/compare/v0.35.0...v0.35.1
v0.35.0: kubecm-v0.35.0Changelog
Others
6b96e5e: add clark42 as a contributor for code, doc, and test (#1172) (allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>)What's Changed
New Contributors
Full Changelog: https://github.com/sunny0826/kubecm/compare/v0.34.0...v0.35.0
v0.34.0: kubecm-v0.34.0What's Changed
New Contributors
Full Changelog: https://github.com/sunny0826/kubecm/compare/v0.33.3...v0.34.0
v0.33.3: kubecm-v0.33.3Changelog
Others
7cfb67b: Fixed a bug in table rendering when long strings had line breaks. (#1151) (小山羊创作 133758630+xiaoshanyangcode@users.noreply.github.com)v0.33.2: kubecm-v0.33.2Changelog
Others
ff503b3: add xiaoshanyangcode as a contributor for code (#1150) (allcontributors[bot] <46447321+allcontributors[bot]@users.noreply.github.com>)helm/helm (kubernetes-helm)
v3.20.2: Helm v3.20.2v3.20.2
Helm v3.20.2 is a security patch release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Security fixes
Chart.yamlname dot-segmentInstallation and Upgrading
Download Helm v3.20.2. The common platform binaries are here:
The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash.What's Next
Changelog
8fb76d6(George Jenkins)3a8927e(Terry Howe)v3.20.1: Helm v3.20.1Helm v3.20.1 is a patch release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Notable Changes
Installation and Upgrading
Download Helm v3.20.1. The common platform binaries are here:
This release was signed with
208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155and can be found at @scottrigby keybase account. Please use the attached signatures for verifying this release usinggpg.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash.What's Next
Changelog
a2369ca(dependabot[bot])90e1056(Pedro Tôrres)911f2e9(Pedro Tôrres)76dad33(Evans Mungai)45c12f7(Evans Mungai)26c6f19(Evans Mungai)09f5129(Evans Mungai)417deb2(Evans Mungai)5417bfa(Evans Mungai)v3.19.1: Helm v3.19.1Helm v3.19.1 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.19.1. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98Eand can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash.What's Next
Changelog
4f953c2(dependabot[bot])6801f4d(Benoit Tigeot)2f619be(Benoit Tigeot)helm pulluntar dir check with repo urls8112d47(Luna Stadler)5dff7ce(Benoit Tigeot)2dad4d2(dependabot[bot])a833710(Reinhard Nägele)2e12c81(Dirk Müller)v3.19.0: Helm v3.19.0Helm v3.19.0 is a feature release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Notable Changes
helm pullregression from 3.18 - error pulling OCI charts with --password #31230helm lintregression from Helm 3.18 - rejected JSON Schema $ref URLs that worked in 3.17.x #31166helm createadded httproute from gateway-api to create chart template #30658Installation and Upgrading
Download Helm v3.19.0. The common platform binaries are here:
This release was signed with
208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155and can be found at @scottrigby keybase account. Please use the attached signatures for verifying this release usinggpg.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash.What's Next
Changelog
3d8990f(Scott Rigby)9a54bf1(Evans Mungai)5af0f68(dependabot[bot])e485606(dependabot[bot])6355c3d(dependabot[bot])ec61f66(dependabot[bot])b278020(Isaiah Lewis)d33ac5e(Isaiah Lewis)8543709(Isaiah Lewis)89a3f90(dependabot[bot])da4c583(Terry Howe)e40b1b3(dependabot[bot])a27e9db(dependabot[bot])f13afaa(Matt Farina)039b0b1(Matt Farina)bec98a9(dependabot[bot])6d9509a(Robert Sirchia)807225e(Borys Hulii)cbbd569(dependabot[bot])5e8ff72(Terry Howe)5b5fb5b(dependabot[bot])d12538a(dependabot[bot])303f803(dependabot[bot])abcc2ed(dependabot[bot])521c67b(dependabot[bot])227c9cb(Matt Farina)4389fa6(Matt Farina)372e403(dependabot[bot])4fa5a64(dependabot[bot])6284ed8(dependabot[bot])2c55a4e(Terry Howe)a16e986(Terry Howe)cea26d8(Terry Howe)b52bb41(Terry Howe)45075cf(dependabot[bot])73a7826(dependabot[bot])733f94c(Terry Howe)fc36041(Terry Howe)cfe8cef(Matt Farina)c33215d(Benoit Tigeot)f552b67(Benoit Tigeot)a18a52e(Brandt Keller)fedf502(Jesse Simpson)fe512ba(Jesse Simpson)099a9e1(Jesse Simpson)b07ab77(Brandt Keller)c225c12(Brandt Keller)c0f3ace(Scott Rigby)dce60ad(Benoit Tigeot)cda0865(Benoit Tigeot)5d9d9a0(Benoit Tigeot)c5249c1(Matt Farina)5b0520d(dependabot[bot])afefca8(Feng Cao)8d6d27c(dependabot[bot])502c0d5(dependabot[bot])92be9ac(dependabot[bot])eb5b6d5(Feng Cao)6b15f26(Matthieu MOREL)6b5c944(Feng Cao)247bf7c(Feng Cao)9404459(Robert Sirchia)0a800e8(Gerard Nguyen)bd1b67b(Henrik Gerdes)Full Changelog: https://github.com/helm/helm/compare/v3.18.6...v3.19.0
bitnami/sealed-secrets (kubeseal)
v0.38.4v0.36.0972618ctod90359cin /docker (#1884)v0.34.087bce11to4b2a093in /docker (#1846)v0.33.1v0.32.2v0.32.1kubernetes-sigs/kustomize (kustomize)
v5.8.1Introduction
This release completes a fix for namespace propagation that occurred in v5.8.0. #6031 (comment)
Also addressed the breaking changes introduced in helm v4. #6016
fix
#5990: fix: allow empty patches files
#6016: fix: support helm v4 beside v3
#6038: Fix a failing test
#6044: Fix namespace propagation problem at v5.8.0
Dependencies
#6057: Upgrade json-patch to v4.13.0 to remove pkg/errors dependency
chore
#6065: Update kyaml to v0.21.1
#6066: Update cmd/config to v0.21.1
#6067: Update api to v0.21.1
v5.8.0IMPORTANT NOTICE: REGRESSION
Due to the new features introduced in this release, a regression has occurred in the functionality that propagates namespaces to child kustomizations.
We are currently preparing a patch release, so please refrain from making changes to this version.
#6031 (comment)
Highlights
implements to replacements value in the structured data
Now, We can edit yaml/json in yaml manifests with replacements transformer.
See #5679
For example
fix: Propagate Namespace correctly to Helm
The long-standing bug where kustomize's namespace transformer did not pass namespaces to helmCharts has been fixed.
See #5940
For example
Feature
#5679: implements to replacements value in the structured data
#5863: Add regex support for Replacement selectors
#5930: feat: add PatchArgs API type to populate patch options
fix
#5940: fix: Propagate Namespace correctly to Helm
#5971: fix: performance recession when propagating namespace to helm
#5942: fix fnplugin storagemounts validation
#5958: fix: make AbsorbAll conflict error more verbose
#5961: refactor: nested format string
#5967: Fix infinite loop in HTTP client by validating URLs before requests
#5985: fix(kyaml/yaml): minor nil safety fix for RNode.Content etc
#5991: Fix duplicate key error when adding multiple labels with --without-selector
Dependencies
#5962: chore: update dependencies from security alert
#5959: update go 1.24.6
chore
#6007: Update kyaml to v0.21.0
#6008: Update cmd/config to v0.21.0
#6009: Update api to v0.21.0
v5.7.1This release introduces code to replace the shlex library used for parsing arguments in the exec plugin.
If any existing manifests become corrupted, please file an issue. discussion: kubernetes/kubernetes#132593 (comment)
Dependencies
#5943: drop shlex dependency
Chore
#5948: Update kyaml to v0.20.1
#5949: Update cmd/config to v0.20.1
#5950: Update api to v0.20.1
prometheus-community/helm-charts (prometheus)
v28.16.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.18.0...prometheus-28.16.0
v28.15.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.16.1...prometheus-28.15.0
v28.14.1Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-operator-crds-28.0.1...prometheus-28.14.1
v28.14.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-snmp-exporter-9.13.0...prometheus-28.14.0
v28.13.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.4.3...prometheus-28.13.0
v28.12.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-82.4.1...prometheus-28.12.0
v28.11.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-node-exporter-4.52.0...prometheus-28.11.0
v28.10.1Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/kube-state-metrics-7.2.0...prometheus-28.10.1
v28.10.0Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-nginx-exporter-1.19.3...prometheus-28.10.0
v28.9.1Compare Source
Prometheus is a monitoring system and time series database.
What's Changed
Full Changelog: https://github.com/prometheus-community/helm-charts/compare/prometheus-redis-exporter-6.21.0...prometheus-28.9.1
anchore/syft (syft)
v1.51.0Added Features
Bug Fixes
<name>@unknownpackages for subpath or export-map stub package.json files [Issue #5118]Dependencies
9 dependency changes (9 updated). 2 vulnerabilities remediated.
🟢 Remediated (2)
Updated (9 packages)
v1.9.3→v1.9.4v5.9.0→v5.9.1v5.19.1→v5.19.2(🟢 remediated GHSA-hc8v-wwc9-vgxm, GHSA-qgq7-7hm3-q39j)v6.8.1→v6.8.3v1.19.0→v1.19.1v1.8.10→v1.18.11v0.5.15→v0.5.16v3.0.4→v3.0.5v1.54.0→v1.55.0(Full Changelog)
v1.50.0Added Features
Bug Fixes
Additional Changes
Dependencies
14 dependency changes (14 updated). 1 vulnerability remediated.
🟢 Remediated (1)
Updated (14 packages)
v1.31.0→v1.32.0v0.0.0-ee656c7→v0.0.0-dba9d58v1.36.0→v1.37.0v1.3.0→v1.3.3v0.24.1→v0.25.0v1.39.0→v1.43.0v0.0.0-9d38bb4→v0.0.0-afd174av0.0.0-6f92a3b→v0.0.0-afd174av1.80.0→v1.82.1(🟢 remediated GHSA-hrxh-6v49-42gf)v4.28.4→v4.29.0v4.34.4→v4.34.6v3.1.3→v3.1.4v1.73.4→v1.74.1v1.53.0→v1.54.0(Full Changelog)
v1.49.0Added Features
application/vnd.oci.image.index.v1+jsonmanifests in root OCI layout [Issue #1545] [PR #5074 @jasonpaulos]Bug Fixes
Dependencies
16 dependency changes (16 updated).
Updated (16 packages)
v0.1.0→v0.2.0v0.2.2→v0.3.0v2.3.2→v2.3.3v29.5.3+incompatible→v29.6.1+incompatiblev0.5.22→v0.5.23v1.54.2→v1.55.0v0.4.1→v0.5.0v2.3.1→v2.4.3v0.53.0→v0.54.0v0.37.0→v0.38.0v0.56.0→v0.57.0v0.21.0→v0.22.0v0.46.0→v0.47.0v0.44.0→v0.45.0v0.38.0→v0.40.0v0.47.0→v0.48.0(Full Changelog)
v1.48.0Added Features
vcpkg[Issue #2110] [PR #4081 @gabetrau].appcataloger [Issue #4010] [PR #4490 @rezmoss]Bug Fixes
mix.lockgit/path deps mislabeled as hex.pm packages with bogus PURLs [PR #5041 @Synvoya]Dependencies
9 dependency changes (8 updated, 1 added).
Updated (8 packages)
v1.3.1→v8.8.8v1.18.6→v1.19.0v0.46.0→v0.47.0v4.28.2→v4.28.4v4.34.0→v4.34.4v3.1.2→v3.1.3v1.72.3→v1.73.4v1.51.0→v1.53.0Added (1 package)
v1.0.1(Full Changelog)
v1.46.0Added Features
*.py.lock) [Issue #4949] [PR #4950 @ktopcuoglu]Bug Fixes
Dependencies
34 dependency changes (31 updated, 3 added). 5 vulnerabilities remediated.
🟢 Remediated (5)
Updated (31 packages)
v1.4.0→v1.4.1v0.2.0→v0.2.1v0.1.0→v0.1.1v0.1.0→v0.1.1v0.1.0→v0.1.1v0.1.0→v0.1.1v0.1.0→v0.1.1v0.1.0→v0.1.1v0.1.0→v0.1.1v0.5.0→v0.8.0v0.1.0→v0.2.0-rc2v0.1.0→v0.1.1v0.2.1→v0.2.2v0.4.1→v0.4.3v0.10.0→v0.11.0v2.6.0→v2.7.0v2.3.1→v2.3.2(🟢 remediated GHSA-33vj-92qq-66hc, GHSA-cvxm-645q-p574, GHSA-jpcc-p29g-p8mq, GHSA-rgh6-rfwx-v388, GHSA-xhf5-7wjv-pqxp)v29.4.3+incompatible→v29.5.3+incompatiblev0.21.6→v0.21.7v6.7.10→v6.8.1v0.0.19→v0.0.21v0.5.7→v0.6.0-rc4v2.24.0→v2.24.1v0.52.0→v0.53.0v0.36.0→v0.37.0v0.55.0→v0.56.0v0.20.0→v0.21.0v0.45.0→v0.46.0v0.43.0→v0.44.0v0.37.0→v0.38.0v0.45.0→v0.46.0Added (3 packages)
v0.7.0v0.0.0-1555304v0.0.0-ecc657c(Full Changelog)
v1.45.1Bug Fixes
(Full Changelog)
v1.44.0Added Features
Bug Fixes
(Full Changelog)
v1.43.0Added Features
Bug Fixes
Additional Changes
(Full Changelog)
v1.42.4Bug Fixes
Additional Changes
(Full Changelog)
v1.42.3Bug Fixes
Additional Changes
(Full Changelog)
v1.42.2Bug Fixes
Automatic-Module-Nameshould not be used as Maven groupId [#4611 #4642 @xnox]Additional Changes
(Full Changelog)
v1.42.1Bug Fixes
Additional Changes
(Full Changelog)
v1.41.2Bug Fixes
(Full Changelog)
v1.41.1Bug Fixes
(Full Changelog)
v1.41.0Added Features
Bug Fixes
(Full Changelog)
v1.40.1Bug Fixes
(Full Changelog)
v1.40.0Added Features
Bug Fixes
(Full Changelog)
v1.39.0Added Features
.go.buildinfosections with upx [#4411 #4480 @wagoodman]Bug Fixes
--base-path[#4410 #4478 @wagoodman](Full Changelog)
v1.38.2Bug Fixes
(Full Changelog)
v1.38.0Added Features
Bug Fixes
extrasstatements in Python PDM cataloger [#4352 @wagoodman]idorname(causing CycloneDX parser error) [#4363]Additional Changes
(Full Changelog)
v1.37.0Added Features
Bug Fixes
deinstalledstate should not be in SBOM [#3063 #4231 @rkirk-nos](Full Changelog)
v1.36.0Added Features
Bug Fixes
(Full Changelog)
v1.34.2Bug Fixes
(Full Changelog)
v1.33.0Added Features
(Full Changelog)
v1.32.0Added Features
Bug Fixes
Additional Changes
(Full Changelog)
v1.30.0Added Features
Bug Fixes
(Full Changelog)
v1.29.1Bug Fixes
(Full Changelog)
traefik/traefik-helm-chart (traefik)
v28.3.0Compare Source
Features
Bug Fixes
db4f43f](https://github.com/traefik/traefik-helm-chart/commit/db4f43f))New Contributors
Full Changelog: https://github.com/traefik/traefik-helm-chart/compare/v28.2.0...v28.3.0
v28.2.0Compare Source
⚠️ This release align to Kubernetes default (Always) for
podSecurityContext.fsGroupChangePolicy. It was OnRootMismatch in previous release of this chart. It can easily be set (back) to OnRootMismatch if needed, see EXAMPLES.Features
Bug Fixes
New Contributors
Full Changelog: https://github.com/traefik/traefik-helm-chart/compare/v28.1.0...v28.2.0
v28.1.0Compare Source
Features
Bug Fixes
Documentation
UpCloudLtd/upcloud-cli (upcloud-cli)
v3.36.0Added
all listandall purgecommands.--waitflag togateway deletecommand.guerzon/vaultwarden (vaultwarden)
v0.46.2Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.46.1...v0.46.2
v0.46.1Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.46.0...v0.46.1
v0.46.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.45.0...v0.46.0
v0.45.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.44.1...v0.45.0
v0.44.1Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.44.0...v0.44.1
v0.44.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.43.1...v0.44.0
v0.43.1Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.43.0...v0.43.1
v0.43.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.42.0...v0.43.0
v0.42.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.41.0...v0.42.0
v0.41.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.3...v0.41.0
v0.40.3Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.2...v0.40.3
v0.40.2Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.1...v0.40.2
v0.40.1Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.40.0...v0.40.1
v0.40.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.39.1...v0.40.0
v0.39.1Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.39.0...v0.39.1
v0.39.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.38.0...v0.39.0
v0.38.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.37.0...v0.38.0
v0.37.0Compare Source
vaultwarden is an unofficial Bitwarden-compatible server written in Rust
What's Changed
New Contributors
Full Changelog: https://github.com/guerzon/vaultwarden/compare/v0.36.4...v0.37.0
Configuration
📅 Schedule: (in timezone Europe/Oslo)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.
New commits pushed, approval review dismissed automatically according to repository settings
1d10a30496to69d841eb13Pull request closed