Skip to content

feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.6 - #5548

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-fluxcd-flux-manifests-2.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-fluxcd-flux-manifests-2.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 21, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
ghcr.io/fluxcd/flux-manifests minor v2.8.5 → v2.9.6 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

fluxcd/flux2 (ghcr.io/fluxcd/flux-manifests)

v2.9.6

Compare Source

Highlights

Flux v2.9.6 is a patch release that stops helm-controller from reapplying chart CRDs on every upgrade when server-side apply is enabled, and recovers HelmReleases left with a drifted Ready=Unknown condition after a failed status patch. source-controller normalizes Azure Blob listing ETags so unchanged containers are no longer re-downloaded on every reconcile, and evicts stale Helm repository index entries from the cache so repositories with frequently changing indexes no longer fail with "Cache is full". kustomize-controller extends SOPS decryption error redaction to spec.postBuild.substituteFrom values, so substituted secrets echoed back in API validation errors are masked out of status conditions and events, and adds the opt-in DisableCommitStatusEvent feature gate. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Stop reapplying chart CRDs on upgrades when using server-side apply with the default Create policy (helm-controller)
  • Recover HelmReleases stranded with a drifted Ready=Unknown condition after a failed status patch (helm-controller)
  • Ignore NotFound when deleting the HelmChart (helm-controller)
  • Normalize Azure Blob listing ETags so unchanged containers are not re-downloaded on every reconcile (source-controller)
  • Evict stale Helm repository index entries from the cache to avoid "Cache is full" errors (source-controller)
  • Extend SOPS decryption error redaction to spec.postBuild.substituteFrom values (kustomize-controller)

Improvements:

  • Add the opt-in DisableCommitStatusEvent feature gate (kustomize-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.5...v2.9.6

v2.9.5

Compare Source

Highlights

Flux v2.9.5 is a patch release that moves helm-controller and source-controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork. It hardens the handling of kubeconfig Secrets in helm-controller and kustomize-controller, which now reject kubeconfigs referencing files on the local filesystem and require credentials and certificates to be embedded inline. It also stops kustomize-controller from leaving behind the temporary directories of a previous process that exited without running its cleanup, and fixes a crash in post-build substitution where a substring expression with a negative length, e.g. ${VAR:2:-1}, panicked instead of counting back from the end of the string like Bash does. Across all controllers and the CLI, the fluxcd/pkg dependencies have been updated, bringing Kubernetes to 1.36.4. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Validate kubeconfigs from .spec.kubeConfig Secrets, rejecting local file references in certificate-authority, tokenFile, client-certificate and client-key; credentials and certificates must be embedded inline (helm-controller, kustomize-controller)
  • Purge temporary directories at startup (kustomize-controller)
  • Fix panic on negative-length substring expressions in post-build substitution (kustomize-controller, flux CLI)

Improvements:

  • Move back to upstream Helm v4.2.4, dropping the Flux fork (helm-controller, source-controller)
  • Update fluxcd/pkg dependencies, which bring Kubernetes to 1.36.4 (all controllers, flux CLI)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.4...v2.9.5

v2.9.4

Compare Source

Highlights

Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by ImageUpdateAutomation, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, Bucket error handling and GCS static authentication in source-controller. On the CLI side, flux migrate -f now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.

Note that this release contains CRD schema changes for ArtifactGenerator and ImageUpdateAutomation; both CRDs must be updated along with the controllers.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Confine tarball extraction and bound glob expansion (source-watcher)
  • Disallow force-update and deletion via refspecs (image-automation-controller)
  • Unify HTTP server request limits (notification-controller)
  • Align Helm repository index loading with upstream Helm v4 (source-controller)
  • Improve error handling in Bucket reconciliation (source-controller)
  • Pin OCI chart verification by digest (source-controller)
  • Limit GCS static authentication to service account keys (source-controller)
  • Restrict the allow-webhooks network policy to the receiver port (flux CLI)

Improvements:

  • Add support for migrating repositories to 2.9 in flux migrate -f (flux CLI)
  • Update fluxcd/pkg dependencies, which align the ECR host detection with upstream (source-controller, image-reflector-controller, flux CLI)
  • Update Bitbucket Cloud receiver guidance (notification-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.3...v2.9.4

v2.9.3

Compare Source

Highlights

Flux v2.9.3 is a patch release. It fixes empty lines vanishing from rendered Helm chart manifests, HelmReleases being marked as tested when their Helm test hooks never ran, and spec.images entries that set only some image fields discarding the remaining fields already declared for the same image in the kustomization.yaml. The latter affects both kustomize-controller and the flux build|diff kustomization commands. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix empty lines vanishing from rendered chart manifests (helm-controller)
  • Fix HasBeenTested for all corner cases, where a release could be marked as tested although its Helm test hooks never ran (helm-controller)
  • Fix a spec.images entry setting only some of the image fields discarding the remaining fields already declared for the same image in the kustomization.yaml at spec.path, e.g. overriding only newName produced an untagged image reference (kustomize-controller, flux CLI)

Improvements:

  • Update fluxcd/pkg dependencies
  • Include source-watcher in the OCI flux-manifests artifact
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.2...v2.9.3

v2.9.2

Compare Source

Highlights

Flux v2.9.2 is a patch release. The main fix addresses a regression introduced in
v2.9.1 where a Kustomization with openapi.path pointing to a URL failed to
reconcile with failed to read OpenAPI schema. This release also corrects several
CRD field descriptions that contained inaccurate or leaked content. Users are
encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix a regression where a Kustomization with openapi.path pointing to a URL failed to reconcile with failed to read OpenAPI schema (kustomize-controller)
  • Fix the HelmChart CRD description for .status.url, which pointed users at BucketStatus.Artifact instead of HelmChartStatus.Artifact (source-controller)
  • Fix the ImageRepository CRD description for .status.observedExclusionList, which referred to spec.lastScanResult instead of status.lastScanResult (image-reflector-controller)
  • Fix the ImageUpdateAutomation CRD description for .status.observedSourceRevision, which had a stray Go struct declaration leaking into it (image-automation-controller)

Improvements:

  • Update fluxcd/pkg dependencies
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.1...v2.9.2

v2.9.1

Compare Source

Highlights

Flux v2.9.1 is a patch release. The main fix, applied across all controllers, disables Flux variable substitution on the Flux CRDs by annotating them with kustomize.toolkit.fluxcd.io/substitute: disabled, so that Kustomizations with post-build substitution enabled no longer corrupt the CRD schemas when they contain ${...} sequences. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Disable Flux variable substitution on all Flux CRDs, preventing post-build substitution from corrupting CRD schemas that contain ${...} sequences (all controllers)
  • Update SOPS dependency to fix .ini file decryption (kustomize-controller)
  • Fix a dry-run error where applying a resource with a strategic merge patch could fail with <resource> is invalid (kustomize-controller)
  • Fix a breaking change in the in-memory Kustomization build (Flux CLI)

Improvements:

  • Cache the registry authorization token during Notation verification, so it is fetched once per verification instead of once per request (source-controller)
  • Update fluxcd/pkg dependencies
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.9.0...v2.9.1

v2.9.0

Compare Source

Highlights

Flux v2.9.0 is a feature release. Users are encouraged to upgrade for the best experience.

For a compressive overview of new features and API changes included in this release, please refer to the Announcing Flux 2.9 GA blog post.

Overview of the new features:

  • Flux CLI Plugin System with the Mirror and Schema plugins (flux plugin)
  • Server-Side Apply field ignore rules for fine-grained drift control (Kustomization)
  • SOPS decryption with the Age post-quantum cipher (Kustomization)
  • Kubernetes Workload Identity authentication for OpenBao and Vault (Kustomization)
  • Helm post-render strategies, including chart hooks support (HelmRelease)
  • Literal mode for Helm values references mirroring helm --set-literal (HelmRelease)
  • Allow empty kind in CEL health check expressions (Kustomization, HelmRelease)
  • Git commit signing and verification with SSH keys (GitRepository, ImageUpdateAutomation)
  • AWS CodeCommit authentication using Workload Identity (GitRepository)
  • Custom Sigstore trusted root for keyless verification in air-gapped environments (OCIRepository)
  • Path pattern directory discovery for monorepos (ArtifactGenerator)
  • Secret-less, OIDC-secured webhook Receivers (Receiver)

❤️ Big thanks to all the Flux contributors that helped us with this release!

Kubernetes compatibility

This release is compatible with the following Kubernetes versions:

Kubernetes version Minimum required
v1.34 >= 1.34.1
v1.35 >= 1.35.0
v1.36 >= 1.36.0

[!NOTE]
Note that the Flux project offers support only for the latest three minor versions of Kubernetes.
Backwards compatibility with older versions of Kubernetes and OpenShift is offered by vendors such as
ControlPlane that provide enterprise support for Flux.

OpenShift compatibility

Flux can be installed on Red Hat OpenShift cluster directly from OperatorHub using Flux Operator. The operator allows the configuration of Flux multi-tenancy lockdown, network policies, persistent storage, sharding, vertical scaling and the synchronization of the cluster state from Git repositories, OCI artifacts, and S3-compatible storage.

Upgrade procedure

⚠️ The Flux APIs image.toolkit.fluxcd.io/v1beta2 and notification.toolkit.fluxcd.io/v1beta2
have reached end-of-life and have been removed from the CRDs.

Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from older versions of Flux to v2.9.

Components changelog
CLI changelog
New Contributors

Full Changelog: fluxcd/flux2@v2.8.0...v2.9.0

v2.8.8

Compare Source

Highlights

Flux v2.8.8 is a patch release that includes CVE fixes via go-git v5.19.1 (source-controller, image-automation-controller), reliability fixes in helm-controller and source-controller, the move of Helm back to upstream v4.2.0, support for GCP sovereign cloud artifact registries, and dependency updates. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Add a configurable HTTP timeout for artifact fetching, preventing fetches that could block indefinitely and stall reconciliations (helm-controller)
  • Fix unbounded memory growth caused by a Kubernetes client transport retry wrapper accumulating on every reconcile (helm-controller)
  • Stop force-applying non-CRD objects placed under a chart's crds/ directory (helm-controller)
  • Fix the Helm test action failing to find releases with names longer than 53 characters (helm-controller)
  • Improve path handling in the source reconcilers (source-controller)
  • Support Helm semver build-metadata encoding in OCIRepository tags (source-controller)

Improvements:

  • Update go-git to v5.19.1 which fixes CVE-2026-45571 and CVE-2026-45570 (source-controller, image-automation-controller)
  • Move Helm back to upstream v4.2.0 (source-controller, helm-controller)
  • Add support for GCP sovereign cloud artifact registries (source-controller, image-reflector-controller)
  • Upgrade Kubernetes to 1.36.1 (source-controller, helm-controller)
  • Update fluxcd/pkg dependencies
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.7...v2.8.8

v2.8.7

Compare Source

Highlights

Flux v2.8.7 is a patch release that includes a bug fix in kustomize-controller, a CVE fix in source-controller and image-automation-controller via go-git v5.19.0, and dependency updates. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix management of objects annotated with kustomize.toolkit.fluxcd.io/ssa: IfNotPresent where non-namespaced resources were being deleted and recreated on each reconciliation (kustomize-controller)

Improvements:

  • Update go-git to v5.19.0 which fixes CVE-2026-45022 (source-controller, image-automation-controller)
  • Update fluxcd/pkg dependencies (source-controller, kustomize-controller, image-automation-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.6...v2.8.7

v2.8.6

Compare Source

Highlights

Flux v2.8.6 is a patch release that includes bug fixes and improvements across helm-controller, image-automation-controller, kustomize-controller, notification-controller, and source-controller. Users are encouraged to upgrade for the best experience.

ℹ️ Please follow the Upgrade Procedure for Flux v2.7+ for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

  • Fix a post-renderer conflict between overlapping hooks and templates (helm-controller)
  • Ignore force replace when server-side apply is enabled (helm-controller)
  • Fix a regression where generic providers would not forward commit status events (notification-controller)
  • Require the audience field on the GCR Receiver secret for tighter verification — will become mandatory in Flux v2.9 (notification-controller)

Improvements:

  • Introduce the MigrateAPIVersion feature gate for migrating the API version of resources in managed field entries (kustomize-controller)
  • Update go-git to v5.18.0 bringing performance improvements for Git operations (source-controller, image-automation-controller)
Components changelog
CLI changelog

Full Changelog: fluxcd/flux2@v2.8.5...v2.8.6


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 21, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: d21435c
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 21, 2026

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

@tinfoild tinfoild Bot changed the title fix(oci/flux-manifests): update v2.8.5 ➼ v2.8.6 fix(oci/flux-manifests): update v2.8.5 ➼ v2.8.7 May 12, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch 2 times, most recently from a6650a2 to e017e14 Compare May 13, 2026 17:46
@tinfoild

tinfoild Bot commented May 13, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

@tinfoild tinfoild Bot changed the title fix(oci/flux-manifests): update v2.8.5 ➼ v2.8.7 fix(oci/flux-manifests): update v2.8.5 ➼ v2.8.8 May 20, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from e017e14 to 718c0d6 Compare May 20, 2026 12:58
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from 718c0d6 to 354b312 Compare June 30, 2026 16:02
@tinfoild tinfoild Bot changed the title fix(oci/flux-manifests): update v2.8.5 ➼ v2.8.8 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.0 Jun 30, 2026
@tinfoild tinfoild Bot changed the title feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.0 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.1 Jul 7, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from 354b312 to d902416 Compare July 7, 2026 16:37
@tinfoild tinfoild Bot changed the title feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.1 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.2 Jul 13, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from d902416 to c8392d6 Compare July 13, 2026 16:40
@tinfoild tinfoild Bot changed the title feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.2 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.3 Jul 23, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from c8392d6 to 790e8f3 Compare July 23, 2026 15:58
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 04:30 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5548 — feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.3
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 1


Severity Summary

Severity Count
CRITICAL 1
HIGH 1
MEDIUM / MODERATE 3
LOW 1
UNKNOWN / NEEDS VERIFICATION 0
Total 6

Results

Package: ghcr.io/fluxcd/flux-manifests

  • Ecosystem: OCI (maps to fluxcd/flux2 — Go)
  • Old version: v2.8.5 — VULNERABLE (6 CVEs via go-git dependency)
  • New version: v2.9.3 — CLEAN

Vulnerabilities in version v2.8.5

  1. CVE-2026-45570 / GHSA-m7cr-m3pv-hgrp — Severity: CRITICAL (CVSS 9.6)

    • Description: go-git SSH transport command injection via unescaped single quotes in repository path.
    • Affected versions: go-git < 5.19.1
    • Fixed in: go-git 5.19.1 (bundled in flux2 v2.8.8+)
    • Sources: NVD, GHSA
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-45570
    • Status: ✅ Fixed in newer versions
  2. CVE-2026-45022 — Severity: HIGH (CVSS 7.5)

    • Description: go-git malformed object parsing allows commit signature bypass via ambiguous/malformed headers.
    • Affected versions: go-git < 5.19.0
    • Fixed in: go-git 5.19.0 (bundled in flux2 v2.8.7+)
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-45022
    • Status: ✅ Fixed in newer versions
  3. CVE-2026-34165 — Severity: MEDIUM (CVSS 5.0)

    • Description: go-git .idx file parsing causes asymmetric memory exhaustion (DoS).
    • Affected versions: go-git >= 5.0.0, < 5.17.1
    • Fixed in: go-git 5.17.1
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-34165
    • Status: ✅ Fixed in newer versions
  4. CVE-2026-45571 / GHSA-crhj-59gh-8x96 — Severity: MEDIUM (CVSS 5.4)

    • Description: go-git path validation issue allows writing outside checkout target.
    • Affected versions: go-git < 5.19.1
    • Fixed in: go-git 5.19.1 (bundled in flux2 v2.8.8+)
    • Sources: NVD, GHSA
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-45571
    • Status: ✅ Fixed in newer versions
  5. CVE-2026-41506 — Severity: MEDIUM (CVSS 4.7)

    • Description: go-git HTTP authentication credential leak when following redirects.
    • Affected versions: go-git < 5.18.0
    • Fixed in: go-git 5.18.0 (bundled in flux2 v2.8.6+)
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-41506
    • Status: ✅ Fixed in newer versions
  6. CVE-2026-33762 — Severity: LOW (CVSS 2.8)

    • Description: go-git index decoder format-v4 path name validation panic (DoS).
    • Affected versions: go-git < 5.17.1
    • Fixed in: go-git 5.17.1
    • Sources: NVD
    • Evidence: https://nvd.nist.gov/vuln/detail/CVE-2026-33762
    • Status: ✅ Fixed in newer versions

Vulnerabilities in version v2.9.3

No known vulnerabilities found. Uses go-git v5.19.1 which includes all fixes.

Non-applicable findings (verified and excluded)

Finding Severity Reason not applicable
CVE-2022-24817 CRITICAL Fixed in flux2 v0.29.0; both versions are >> that
CVE-2022-24877 CRITICAL Fixed in flux2 v0.29.0; both versions are >> that
CVE-2022-36049 HIGH Fixed in flux2 v0.32.0; both versions are >> that
CVE-2021-41254 HIGH Fixed in flux2 v0.18.0; both versions are >> that
CVE-2022-24878 HIGH Fixed in flux2 v0.29.0; both versions are >> that
+6 more — All go-git CVEs fixed in go-git v5.16.5 or earlier — not applicable

Changelog Security Highlights (v2.8.5 → v2.9.3)

  • v2.9.3 — Bug fixes (empty chart lines, helm test hooks, spec.images), dependency updates
  • v2.9.0 — Major feature release: CLI plugin system, SSA field ignore rules, SOPS Age post-quantum, Workload Identity for Vault, Helm post-render strategies, Git commit signing with SSH
  • v2.8.8 — go-git v5.19.1: fixes CVE-2026-45571 and CVE-2026-45570 (CRITICAL)
  • v2.8.7 — go-git v5.19.0: fixes CVE-2026-45022 (HIGH)
  • v2.8.6 — go-git v5.18.0: fixes CVE-2026-41506 (MEDIUM)

Recommendations

  • MERGE PRIORITY: CRITICAL — The old version (v2.8.5) bundles go-git v5.16.5 which exposes 1 CRITICAL (CVE-2026-45570, CVSS 9.6) and 1 HIGH (CVE-2026-45022, CVSS 7.5) vulnerability affecting source-controller and image-automation-controller. v2.9.3 bundles go-git v5.19.1 which fixes all known go-git CVEs.
  • No new vulnerabilities introduced by v2.9.3.
  • Review breaking changes in v2.9.0 release notes before merging (API version migrations, feature gates).
  • Merge this PR promptly to remediate the exposed CRITICAL SSH injection vulnerability.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from 790e8f3 to 7fa8737 Compare August 7, 2026 15:58
@tinfoild tinfoild Bot changed the title feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.3 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.4 Aug 7, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from 7fa8737 to 41e7490 Compare August 31, 2026 17:59
@tinfoild tinfoild Bot changed the title feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.4 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.5 Aug 31, 2026
@tinfoild tinfoild Bot changed the title feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.5 feat(oci/flux-manifests): update v2.8.5 ➼ v2.9.6 Oct 1, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-fluxcd-flux-manifests-2.x branch from 41e7490 to d21435c Compare October 1, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant