Skip to content

fix(oci/charts/trust-manager): update v0.22.0 ➼ v0.22.1 - #5506

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/quay.io-jetstack-charts-trust-manager-0.22.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/quay.io-jetstack-charts-trust-manager-0.22.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 17, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
quay.io/jetstack/charts/trust-manager (source) patch v0.22.0 → v0.22.1 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

cert-manager/trust-manager (quay.io/jetstack/charts/trust-manager)

v0.22.1

Compare Source

trust-manager is the easiest way to manage security-critical TLS trust bundles in Kubernetes and OpenShift clusters.

This release is a patch release, bumping dependencies, Go version, and base images to address vulnerabilities reported by scanners.

The release also contains various non-user-facing changes, preparing for the migration from Bundle to ClusterBundle.

What's Changed
New Contributors

Full Changelog: cert-manager/trust-manager@v0.22.0...v0.22.1

v0.22.1

Compare Source

trust-manager is the easiest way to manage security-critical TLS trust bundles in Kubernetes and OpenShift clusters.

This release is a patch release, bumping dependencies, Go version, and base images to address vulnerabilities reported by scanners.

The release also contains various non-user-facing changes, preparing for the migration from Bundle to ClusterBundle.

What's Changed
New Contributors

Full Changelog: cert-manager/trust-manager@v0.22.0...v0.22.1


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 17, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 25f4370
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 17, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/tls/trust-manager/app Kustomization: trust-manager/trust-manager-app OCIRepository: trust-manager/trust-manager

+++ kube/deploy/core/tls/trust-manager/app Kustomization: trust-manager/trust-manager-app OCIRepository: trust-manager/trust-manager

@@ -12,9 +12,9 @@

 spec:
   interval: 1h
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: v0.22.0
+    tag: v0.22.1
   url: oci://quay.io/jetstack/charts/trust-manager
 

1 similar comment
@tinfoild

tinfoild Bot commented Apr 17, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/tls/trust-manager/app Kustomization: trust-manager/trust-manager-app OCIRepository: trust-manager/trust-manager

+++ kube/deploy/core/tls/trust-manager/app Kustomization: trust-manager/trust-manager-app OCIRepository: trust-manager/trust-manager

@@ -12,9 +12,9 @@

 spec:
   interval: 1h
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: v0.22.0
+    tag: v0.22.1
   url: oci://quay.io/jetstack/charts/trust-manager
 

@tinfoild
tinfoild Bot force-pushed the renovate/quay.io-jetstack-charts-trust-manager-0.22.x branch from 60a465a to 3b7f7aa Compare April 23, 2026 17:36
@tinfoild

tinfoild Bot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: trust-manager/trust-manager Deployment: trust-manager/trust-manager

+++ HelmRelease: trust-manager/trust-manager Deployment: trust-manager/trust-manager

@@ -25,13 +25,13 @@

         egress.home.arpa/apiserver: allow
     spec:
       serviceAccountName: trust-manager
       automountServiceAccountToken: true
       initContainers:
       - name: cert-manager-package-debian
-        image: quay.io/jetstack/trust-pkg-debian-bookworm:20230311-deb12u1.5
+        image: quay.io/jetstack/trust-pkg-debian-bookworm:20230311-deb12u1.6
         imagePullPolicy: IfNotPresent
         args:
         - /copyandmaybepause
         - /debian-package
         - /packages
         volumeMounts:
@@ -46,13 +46,13 @@

           readOnlyRootFilesystem: true
           runAsNonRoot: true
           seccompProfile:
             type: RuntimeDefault
       containers:
       - name: trust-manager
-        image: quay.io/jetstack/trust-manager:v0.22.0
+        image: quay.io/jetstack/trust-manager:v0.22.1
         imagePullPolicy: IfNotPresent
         ports:
         - containerPort: 6443
           name: webhook
         - containerPort: 9402
           name: metrics

@tinfoild
tinfoild Bot force-pushed the renovate/quay.io-jetstack-charts-trust-manager-0.22.x branch from 3b7f7aa to 384cc04 Compare April 27, 2026 11:43
@tinfoild
tinfoild Bot force-pushed the renovate/quay.io-jetstack-charts-trust-manager-0.22.x branch from 384cc04 to c14c344 Compare May 15, 2026 18:38
@tinfoild
tinfoild Bot force-pushed the renovate/quay.io-jetstack-charts-trust-manager-0.22.x branch from c14c344 to 883c503 Compare June 8, 2026 20:58
@tinfoild
tinfoild Bot force-pushed the renovate/quay.io-jetstack-charts-trust-manager-0.22.x branch from 883c503 to 60ebc73 Compare June 19, 2026 12:31
@tinfoild
tinfoild Bot force-pushed the renovate/quay.io-jetstack-charts-trust-manager-0.22.x branch from 60ebc73 to 25f4370 Compare July 20, 2026 10:09
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 04:17 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5506 — fix(oci/charts/trust-manager): update v0.22.0 ➼ v0.22.1
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 7


Severity Summary

Severity Count
CRITICAL 0
HIGH 4
MEDIUM / MODERATE 3
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 7

Results

Package: quay.io/jetstack/charts/trust-manager

  • Ecosystem: Go / Helm (OCI chart)
  • Source: cert-manager/trust-manager
  • Old version: v0.22.0 (Go 1.26.1) — VULNERABLE (7 Go stdlib CVEs)
  • New version: v0.22.1 (Go 1.26.2) — CLEAN

Vulnerabilities in old version v0.22.0 (Go 1.26.1)

These are Go standard library vulnerabilities affecting the trust-manager binary compiled with Go 1.26.1. All are fixed by the Go 1.26.2 bump included in v0.22.1.

  1. CVE-2026-33810 / GO-2026-4866 — Severity: HIGH (CVSS 8.2)

  2. CVE-2026-32283 / GO-2026-4870 — Severity: HIGH (CVSS 7.5)

  3. CVE-2026-32281 / GO-2026-4946 — Severity: HIGH (CVSS 7.5)

  4. CVE-2026-32280 / GO-2026-4947 — Severity: HIGH (CVSS 7.5)

  5. CVE-2026-32282 / GO-2026-4864 — Severity: MEDIUM (CVSS 6.4)

  6. CVE-2026-32289 / GO-2026-4865 — Severity: MEDIUM (CVSS 6.1)

  7. CVE-2026-32288 / GO-2026-4869 — Severity: MEDIUM (CVSS 5.5)

Vulnerabilities in new version v0.22.1 (Go 1.26.2)

No known vulnerabilities found.

Changelog Security Highlights (v0.22.0 → v0.22.1)

  • Go 1.26.2 — Bump from Go 1.26.1, fixing 7 CVEs in stdlib (crypto/x509, crypto/tls, os, archive/tar, html/template)
  • golang.org/x/crypto to v0.7.1 — Dependency security updates for go-pkcs12
  • Kubernetes Go patches — Updated to v0.35.3/v0.35.4 with dependency security fixes
  • Release explicitly states: "bumping dependencies, Go version, and base images to address vulnerabilities reported by scanners"

Source scan summary

Source Status Notes
OSV.dev ✅ Scanned Found 7 Go stdlib CVEs in old version (fixed in Go 1.26.2)
NVD ✅ Scanned Confirmed CVSS scores for all 7 CVEs (4 HIGH, 3 MEDIUM)
GHSA ✅ Scanned No advisories for trust-manager itself; CVEs tracked via Go ecosystem
GHSL ✅ Scanned No GHSL publications for this project
CISA KEV ✅ Scanned No exploited-in-wild entries for these CVEs
FortiGuard ✅ Scanned No advisories found
CVE.org ✅ Scanned CVEs confirmed via NVD references
Changelog ✅ Scanned Security patch release bumping Go 1.26.1 → 1.26.2

Recommendations

  • MERGE PRIORITY: HIGH — The old version (v0.22.0) is compiled with Go 1.26.1 which has 4 HIGH-severity CVEs (CVE-2026-33810, CVE-2026-32283, CVE-2026-32281, CVE-2026-32280) in crypto/x509 and crypto/tls — directly affecting trust-manager's core TLS trust bundle functionality. The update to v0.22.1 bumps Go to 1.26.2, fixing all 7 CVEs.
  • No new vulnerabilities introduced by the update.
  • Recommend merging promptly to remediate the exposed Go stdlib vulnerabilities, particularly the crypto/x509 auth bypass (CVE-2026-33810, CVSS 8.2).

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant