Repository navigation
feat(oci/postgres-backup-local)!: Update 16 ➼ 18 - template - #3504
tinfoild[bot] wants to merge 1 commit into
Conversation
Deploying jjgadgets-biohazard with
|
| Latest commit: |
dc84cd1
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://781453a2.jjgadgets-biohazard.pages.dev |
| Branch Preview URL: | https://renovate-template-docker-io-oxi3.jjgadgets-biohazard.pages.dev |
kube/helmrelease/out00 |
b9d83fa to
5639524
Compare
5639524 to
e14c01a
Compare
kube/kustomization/out00--- kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-default CronJob: pg/pg-default-postgres-dump-local
+++ kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-default CronJob: pg/pg-default-postgres-dump-local
@@ -45,13 +45,13 @@
name: pg-default-pguser-postgres
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
key: password
name: pg-default-pguser-postgres
- image: docker.io/prodrigestivill/postgres-backup-local:16@sha256:e7182c0dac78540405e954597fcb3f4cfa67955d5df008152ab41ce166fe6014
+ image: docker.io/prodrigestivill/postgres-backup-local:18@sha256:f70742ebe42b2277689b028d1fd15aa80f77cffa01da163cc9f85a6ff1866e7f
imagePullPolicy: IfNotPresent
name: postgres-backup
resources:
limits:
cpu: 1000m
memory: 1Gi
--- kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-home CronJob: pg/pg-home-postgres-dump-local
+++ kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-home CronJob: pg/pg-home-postgres-dump-local
@@ -45,13 +45,13 @@
name: pg-home-pguser-postgres
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
key: password
name: pg-home-pguser-postgres
- image: docker.io/prodrigestivill/postgres-backup-local:16@sha256:e7182c0dac78540405e954597fcb3f4cfa67955d5df008152ab41ce166fe6014
+ image: docker.io/prodrigestivill/postgres-backup-local:18@sha256:f70742ebe42b2277689b028d1fd15aa80f77cffa01da163cc9f85a6ff1866e7f
imagePullPolicy: IfNotPresent
name: postgres-backup
resources:
limits:
cpu: 1000m
memory: 1Gi
--- kube/deploy/core/db/pg/clusters/template Kustomization: authentik/authentik-db CronJob: authentik/pg-authentik-authentik-dump-local
+++ kube/deploy/core/db/pg/clusters/template Kustomization: authentik/authentik-db CronJob: authentik/pg-authentik-authentik-dump-local
@@ -46,13 +46,13 @@
name: pg-authentik-pguser-authentik
- name: POSTGRES_PASSWORD
valueFrom:
secretKeyRef:
key: password
name: pg-authentik-pguser-authentik
- image: docker.io/prodrigestivill/postgres-backup-local:16@sha256:e7182c0dac78540405e954597fcb3f4cfa67955d5df008152ab41ce166fe6014
+ image: docker.io/prodrigestivill/postgres-backup-local:18@sha256:f70742ebe42b2277689b028d1fd15aa80f77cffa01da163cc9f85a6ff1866e7f
imagePullPolicy: IfNotPresent
name: postgres-backup
resources:
limits:
cpu: 1000m
memory: 1Gi |
e14c01a to
65a1c0a
Compare
d294148 to
f85ac42
Compare
f85ac42 to
dc84cd1
Compare
|
SECURITY VULNERABILITIES FOUND BY CIEL
Severity Summary
ResultsPackage:
|
| Finding | Severity | Reason not applicable |
|---|---|---|
| CVE-2026-6472 | MEDIUM 5.4 | CREATE TYPE privilege escalation — affects both, applicable but |
| CVE-2026-6474 | MEDIUM 4.3 | timeofday() memory disclosure — affects both, applicable but |
| CVE-2026-6478 | MEDIUM 6.5 | MD5 timing channel — only MD5 auth, not scram-sha-256 default |
| CVE-2026-6638 | LOW 3.7 | REFRESH PUBLICATION SQL injection — affects both |
| +3 more | — | All patched in PG 16.14 / 18.4 |
Changelog Security Highlights
- Both Docker images (
16,18) were last pushed 2025-09-26 and have not been rebuilt since. - The
prodrigestivill/postgres-backup-localwrapper scripts (backup.sh, init.sh) have no known CVEs. - The underlying
postgres:$BASETAGDocker image is the source of all identified CVEs. - PG 16.14 (current stable for PG16) fixes CVE-2026-6472 through CVE-2026-6638 — 10 CVEs.
- PG 18.4 (current stable for PG18) fixes the same 10 + 1 PG18-specific CVE.
- The backup container uses
pg_dumpvia libpq — CVE-2026-6477 (stack buffer overflow via server superuser) is especially relevant.
Recommendations
⚠️ DO NOT MERGE (current images) — The new version (18, PG18) has 10 HIGH + 1 MEDIUM CVEs vs. 8 HIGH in the old version (16, PG16). 2 CVEs are unique to PG18 (CVE-2026-2007 HIGH, CVE-2026-6476 HIGH) and do not affect the old PG16 version.- Action required: Rebuild both
prodrigestivill/postgres-backup-local:16and:18from the latestpostgres:16/postgres:18base images, then update the PR digest. - Alternative: Pin to a known-good digest after rebuilding. Merge only after confirming the new image digest includes PG 18.4+ fixes.
- MERGE PRIORITY (if rebuilt): MEDIUM — After a fresh rebuild, PG18 has active upstream support and regular security patches.
⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.
This PR contains the following updates:
16→18Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.