Skip to content

feat(oci/postgres-backup-local)!: Update 16 ➼ 18 - template - #3504

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Sep 26, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
docker.io/prodrigestivill/postgres-backup-local major 16 → 18

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 26, 2025 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: dc84cd1
Status: ✅  Deploy successful!
Preview URL: https://781453a2.jjgadgets-biohazard.pages.dev
Branch Preview URL: https://renovate-template-docker-io-oxi3.jjgadgets-biohazard.pages.dev

View logs

@tinfoild

tinfoild Bot commented Sep 26, 2025 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

@tinfoild
tinfoild Bot force-pushed the renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x branch from b9d83fa to 5639524 Compare November 24, 2025 15:41
@tinfoild
tinfoild Bot force-pushed the renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x branch from 5639524 to e14c01a Compare December 17, 2025 13:59
@tinfoild

tinfoild Bot commented Dec 17, 2025 •

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-default CronJob: pg/pg-default-postgres-dump-local

+++ kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-default CronJob: pg/pg-default-postgres-dump-local

@@ -45,13 +45,13 @@

                   name: pg-default-pguser-postgres
             - name: POSTGRES_PASSWORD
               valueFrom:
                 secretKeyRef:
                   key: password
                   name: pg-default-pguser-postgres
-            image: docker.io/prodrigestivill/postgres-backup-local:16@sha256:e7182c0dac78540405e954597fcb3f4cfa67955d5df008152ab41ce166fe6014
+            image: docker.io/prodrigestivill/postgres-backup-local:18@sha256:f70742ebe42b2277689b028d1fd15aa80f77cffa01da163cc9f85a6ff1866e7f
             imagePullPolicy: IfNotPresent
             name: postgres-backup
             resources:
               limits:
                 cpu: 1000m
                 memory: 1Gi
--- kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-home CronJob: pg/pg-home-postgres-dump-local

+++ kube/deploy/core/db/pg/clusters/template Kustomization: flux-system/1-core-db-pg-clusters-home CronJob: pg/pg-home-postgres-dump-local

@@ -45,13 +45,13 @@

                   name: pg-home-pguser-postgres
             - name: POSTGRES_PASSWORD
               valueFrom:
                 secretKeyRef:
                   key: password
                   name: pg-home-pguser-postgres
-            image: docker.io/prodrigestivill/postgres-backup-local:16@sha256:e7182c0dac78540405e954597fcb3f4cfa67955d5df008152ab41ce166fe6014
+            image: docker.io/prodrigestivill/postgres-backup-local:18@sha256:f70742ebe42b2277689b028d1fd15aa80f77cffa01da163cc9f85a6ff1866e7f
             imagePullPolicy: IfNotPresent
             name: postgres-backup
             resources:
               limits:
                 cpu: 1000m
                 memory: 1Gi
--- kube/deploy/core/db/pg/clusters/template Kustomization: authentik/authentik-db CronJob: authentik/pg-authentik-authentik-dump-local

+++ kube/deploy/core/db/pg/clusters/template Kustomization: authentik/authentik-db CronJob: authentik/pg-authentik-authentik-dump-local

@@ -46,13 +46,13 @@

                   name: pg-authentik-pguser-authentik
             - name: POSTGRES_PASSWORD
               valueFrom:
                 secretKeyRef:
                   key: password
                   name: pg-authentik-pguser-authentik
-            image: docker.io/prodrigestivill/postgres-backup-local:16@sha256:e7182c0dac78540405e954597fcb3f4cfa67955d5df008152ab41ce166fe6014
+            image: docker.io/prodrigestivill/postgres-backup-local:18@sha256:f70742ebe42b2277689b028d1fd15aa80f77cffa01da163cc9f85a6ff1866e7f
             imagePullPolicy: IfNotPresent
             name: postgres-backup
             resources:
               limits:
                 cpu: 1000m
                 memory: 1Gi

@tinfoild
tinfoild Bot force-pushed the renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x branch from e14c01a to 65a1c0a Compare January 27, 2026 02:58
@tinfoild
tinfoild Bot force-pushed the renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x branch 2 times, most recently from d294148 to f85ac42 Compare March 23, 2026 05:37
@JJGadgets JJGadgets added wontfix This will not be worked on procrastination and removed wontfix This will not be worked on labels Mar 25, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/template/docker.io-prodrigestivill-postgres-backup-local-18.x branch from f85ac42 to dc84cd1 Compare March 28, 2026 19:20
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 02:15 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #3504 — feat(oci/postgres-backup-local)!: Update 16 ➼ 18 - template
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 11 (applicable to this Docker image)


Severity Summary

Severity Count
CRITICAL 0
HIGH 10
MEDIUM / MODERATE 1
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 11

Results

Package: docker.io/prodrigestivill/postgres-backup-local

  • Ecosystem: Docker (container image)
  • Base image: postgres:16 → postgres:18 (official PostgreSQL Docker images)
  • Old version: 16 (image pushed 2025-09-26) — VULNERABLE (8 HIGH CVEs)
  • New version: 18 (image pushed 2025-09-26) — VULNERABLE (10 HIGH, 1 MEDIUM CVEs; 2 are PG18-specific)

⚠️ Context: Both tags were pushed 10 months ago. Images are frozen at old PostgreSQL minor versions (PG ~16.4, PG ~18.0) and lack all security patches released in PG 16.12–16.14 and PG 18.2–18.4.

Vulnerabilities AFFECTING BOTH versions (PostgreSQL < 16.12 / < 18.2)

  1. CVE-2026-2004 — Severity: HIGH (CVSS 8.8)

  2. CVE-2026-2005 — Severity: HIGH (CVSS 8.8)

    • Description: pgcrypto heap buffer overflow, arbitrary code execution.
    • Affected versions: < 18.2 / 17.8 / 16.12 / 15.16 / 14.21
    • Fixed in: PG 16.12 / 18.2
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-2005
    • Status: ✅ Fixed in newer versions
  3. CVE-2026-2006 — Severity: HIGH (CVSS 8.8)

    • Description: Multibyte character buffer overrun, arbitrary code execution.
    • Affected versions: < 18.2 / 17.8 / 16.12 / 15.16 / 14.21
    • Fixed in: PG 16.12 / 18.2
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-2006
    • Status: ✅ Fixed in newer versions
  4. CVE-2026-6473 — Severity: HIGH (CVSS 8.8)

  5. CVE-2026-6475 — Severity: HIGH (CVSS 8.8)

    • Description: pg_basebackup/pg_rewind symlink allows OS account hijacking.
    • Affected versions: < 18.4 / 17.10 / 16.14 / 15.18 / 14.23
    • Fixed in: PG 16.14 / 18.4
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-6475
    • Status: ✅ Fixed in newer versions
  6. CVE-2026-6477 — Severity: HIGH (CVSS 8.8)

    • Description: libpq lo_* functions stack buffer overflow via server superuser.
    • Affected versions: < 18.4 / 17.10 / 16.14 / 15.18 / 14.23
    • Fixed in: PG 16.14 / 18.4
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-6477
    • Status: ✅ Fixed in newer versions
  7. CVE-2026-6479 — Severity: HIGH (CVSS 7.5)

    • Description: SSL/GSS negotiation uncontrolled recursion → sustained DoS.
    • Affected versions: < 18.4 / 17.10 / 16.14 / 15.18 / 14.23
    • Fixed in: PG 16.14 / 18.4
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-6479
    • Status: ✅ Fixed in newer versions
  8. CVE-2026-6637 — Severity: HIGH (CVSS 8.8)

    • Description: refint module stack buffer overflow + SQL injection.
    • Affected versions: < 18.4 / 17.10 / 16.14 / 15.18 / 14.23
    • Fixed in: PG 16.14 / 18.4
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-6637
    • Status: ✅ Fixed in newer versions

Vulnerabilities UNIQUE to new version (PG18 only)

  1. CVE-2026-2007 — Severity: HIGH (CVSS 8.2) — ⚠️ NEW in PG18

  2. CVE-2026-6476 — Severity: HIGH (CVSS 7.2) — ⚠️ NEW in PG17/18

  3. CVE-2026-6575 — Severity: MEDIUM (CVSS 4.3) — ⚠️ NEW in PG18

Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2026-6472 MEDIUM 5.4 CREATE TYPE privilege escalation — affects both, applicable but
CVE-2026-6474 MEDIUM 4.3 timeofday() memory disclosure — affects both, applicable but
CVE-2026-6478 MEDIUM 6.5 MD5 timing channel — only MD5 auth, not scram-sha-256 default
CVE-2026-6638 LOW 3.7 REFRESH PUBLICATION SQL injection — affects both
+3 more — All patched in PG 16.14 / 18.4

Changelog Security Highlights

  • Both Docker images (16, 18) were last pushed 2025-09-26 and have not been rebuilt since.
  • The prodrigestivill/postgres-backup-local wrapper scripts (backup.sh, init.sh) have no known CVEs.
  • The underlying postgres:$BASETAG Docker image is the source of all identified CVEs.
  • PG 16.14 (current stable for PG16) fixes CVE-2026-6472 through CVE-2026-6638 — 10 CVEs.
  • PG 18.4 (current stable for PG18) fixes the same 10 + 1 PG18-specific CVE.
  • The backup container uses pg_dump via libpq — CVE-2026-6477 (stack buffer overflow via server superuser) is especially relevant.

Recommendations

  • ⚠️ DO NOT MERGE (current images) — The new version (18, PG18) has 10 HIGH + 1 MEDIUM CVEs vs. 8 HIGH in the old version (16, PG16). 2 CVEs are unique to PG18 (CVE-2026-2007 HIGH, CVE-2026-6476 HIGH) and do not affect the old PG16 version.
  • Action required: Rebuild both prodrigestivill/postgres-backup-local:16 and :18 from the latest postgres:16 / postgres:18 base images, then update the PR digest.
  • Alternative: Pin to a known-good digest after rebuilding. Merge only after confirming the new image digest includes PG 18.4+ fixes.
  • MERGE PRIORITY (if rebuilt): MEDIUM — After a fresh rebuild, PG18 has active upstream support and regular security patches.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants