Skip to content

feat(oci/charts/k8s-gateway): update 3.6.1 ➼ 3.7.2 - #5520

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
ghcr.io/k8s-gateway/charts/k8s-gateway minor 3.6.1 → 3.7.2 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 18, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 7e0460e
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 18, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/dns/internal/k8s-gateway/app Kustomization: flux-system/1-core-dns-internal-k8s-gateway-app OCIRepository: dns/k8s-gateway

+++ kube/deploy/core/dns/internal/k8s-gateway/app Kustomization: flux-system/1-core-dns-internal-k8s-gateway-app OCIRepository: dns/k8s-gateway

@@ -10,9 +10,9 @@

 spec:
   interval: 1h
   layerSelector:
     mediaType: application/vnd.cncf.helm.chart.content.v1.tar+gzip
     operation: copy
   ref:
-    tag: 3.6.1
+    tag: 3.7.2
   url: oci://ghcr.io/k8s-gateway/charts/k8s-gateway
 

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from f3f8c77 to 992636a Compare April 19, 2026 15:22
@tinfoild tinfoild Bot changed the title feat(oci/charts/k8s-gateway): update 3.6.1 ➼ 3.7.0 feat(oci/charts/k8s-gateway): update 3.6.1 ➼ 3.7.1 Apr 19, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from 992636a to 5dba886 Compare April 27, 2026 11:44
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from 5dba886 to 9427d77 Compare May 15, 2026 18:39
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from 9427d77 to 37bc774 Compare June 8, 2026 20:59
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from 37bc774 to 3bc06d4 Compare June 19, 2026 12:33
@tinfoild

tinfoild Bot commented Jun 19, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: dns/k8s-gateway ClusterRole: dns/k8s-gateway

+++ HelmRelease: dns/k8s-gateway ClusterRole: dns/k8s-gateway

@@ -22,12 +22,19 @@

   - services
   - namespaces
   verbs:
   - list
   - watch
 - apiGroups:
+  - discovery.k8s.io
+  resources:
+  - endpointslices
+  verbs:
+  - list
+  - watch
+- apiGroups:
   - extensions
   - networking.k8s.io
   resources:
   - ingresses
   verbs:
   - list

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from 3bc06d4 to 38592cc Compare July 6, 2026 10:25
@tinfoild tinfoild Bot changed the title feat(oci/charts/k8s-gateway): update 3.6.1 ➼ 3.7.1 feat(oci/charts/k8s-gateway): update 3.6.1 ➼ 3.7.2 Jul 6, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8s-gateway-charts-k8s-gateway-3.x branch from 38592cc to 7e0460e Compare July 20, 2026 10:12
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 04:30 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5520 — feat(oci/charts/k8s-gateway): update 3.6.1 ➼ 3.7.2
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 0


Severity Summary

Severity Count
CRITICAL 0
HIGH 0
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 0

Results

Package: ghcr.io/k8s-gateway/charts/k8s-gateway

  • Ecosystem: Helm (OCI chart)
  • Old version: 3.6.1 — CLEAN
  • New version: 3.7.2 — CLEAN

Vulnerabilities in version 3.6.1

No known vulnerabilities found.

Vulnerabilities in version 3.7.2

No known vulnerabilities found.

Source scan summary

Source Status Notes
OSV.dev ✅ Scanned No results for this package (tried Go and unqualified queries)
NVD ✅ Scanned No CVEs found for k8s-gateway / k8s_gateway
GHSA ✅ Scanned No advisories for this package (Go ecosystem)
GHSL ✅ Scanned GitHub Security Lab – no publications for this project
CISA KEV ✅ Scanned No entries for this product
FortiGuard ✅ Scanned No advisories found
CVE.org ✅ Scanned CVE.org API requires auth key; web search found no hits
Changelog ✅ Scanned See highlights below

Changelog Security Highlights (3.6.1 → 3.7.2)

  • CoreDNS dependency v1.14.2 → v1.14.4 — Several important security fixes remediated (see details below)
  • Chart 3.7.2 adds RBAC permission for discovery.k8s.io/endpointslices — opt-in endpoint resolution
  • Chart 3.7.1 bumps bundled app version to v1.8.0 (from v1.7.0)
  • Feature additions (service label selector, Node hostname DNS resolution) — non-security

The dependency bump from CoreDNS v1.14.2 (bundled with old chart) to v1.14.4 (bundled with new chart) fixes the following verified CVEs that affect the CoreDNS server embedded in k8s-gateway:

CVE Severity Fixed in Description
CVE-2026-35579 CRITICAL (9.8) 1.14.3 TSIG authentication bypass in gRPC/QUIC/DoH/DoH3 transports
CVE-2026-32934 HIGH (7.5) 1.14.3 DoQ unbounded goroutine & memory growth DoS
CVE-2026-32936 HIGH (7.5) 1.14.3 DoH GET path oversized dns= parameter DoS
CVE-2026-33190 HIGH (7.5) 1.14.3 tsig plugin bypass on non-plain-DNS transports
CVE-2026-33489 HIGH (7.5) 1.14.3 transfer plugin wrong ACL stanza selection
CVE-2026-62309 HIGH (7.5) 1.14.4 proxyproto plugin crash from 28-byte UDP datagram

Recommendations

  • MERGE PRIORITY: LOW — No known CVEs found in the k8s-gateway chart or application itself. The old version (3.6.1) is clean.
  • ⚠️ Important context: The old chart bundles CoreDNS v1.14.2 which exposes 5 HIGH/CRITICAL CVEs (fixed in v1.14.3). The new chart (3.7.2) bundles CoreDNS v1.14.4 which fixes all of these. While not direct k8s-gateway vulnerabilities, this is a strong practical reason to merge promptly depending on your CoreDNS transport configuration.
  • Verify that your deployment does not use DoQ, DoH, DoH3, gRPC, or proxyproto with CoreDNS — if it does, the upgrade is security-critical.
  • Review the feature additions in v3.7.0 (serviceLabelSelector) and v3.7.2 (endpointslice RBAC) before merging.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant