Skip to content

feat(oci/vector): update 0.54.0 ➼ 0.59.0 - #5570

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-vectordotdev-vector-0.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-vectordotdev-vector-0.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 22, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
ghcr.io/vectordotdev/vector (source) minor 0.54.0-distroless-libc → 0.59.0-distroless-libc OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 22, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: d753bfe
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 22, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: vector/vector Deployment: vector/vector

+++ HelmRelease: vector/vector Deployment: vector/vector

@@ -74,13 +74,13 @@

             fieldRef:
               fieldPath: spec.nodeName
         - name: PROM_HTTP
           value: '8081'
         - name: TZ
           value: null
-        image: ghcr.io/vectordotdev/vector:0.54.0-distroless-libc@sha256:2eb5350e821e77fc35a11a268e5cec4a1460134ddc75f3cb191a949739d36365
+        image: ghcr.io/vectordotdev/vector:0.59.0-distroless-libc@sha256:54a7c01056e98305fce80545ace22779035747af9e89114508330fe94f829831
         name: app
         ports:
         - containerPort: 8081
           name: metrics
         resources:
           limits:

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch from 339d173 to 660c0c8 Compare April 27, 2026 11:44
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch from 660c0c8 to f2dfbba Compare May 15, 2026 18:40
@tinfoild tinfoild Bot changed the title feat(oci/vector): update 0.54.0 ➼ 0.55.0 feat(oci/vector): update 0.54.0 ➼ 0.56.0 Jun 3, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch 2 times, most recently from 44962b5 to 942235c Compare June 8, 2026 20:59
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch from 942235c to 304a370 Compare June 19, 2026 12:34
@tinfoild tinfoild Bot changed the title feat(oci/vector): update 0.54.0 ➼ 0.56.0 feat(oci/vector): update 0.54.0 ➼ 0.57.0 Jul 14, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch 2 times, most recently from 21bdf5d to 5988b74 Compare July 20, 2026 10:13
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 05:10 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5570 — feat(oci/vector): update 0.54.0 ➼ 0.57.0
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 3


Severity Summary

Severity Count
CRITICAL 1
HIGH 2
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 3

Results

Package: ghcr.io/vectordotdev/vector

  • Ecosystem: Docker / OCI container
  • Old version: 0.54.0-distroless-libc — VULNERABLE (3 advisories)
  • New version: 0.57.0-distroless-libc — CLEAN

Vulnerabilities in version 0.54.0

  1. GHSA-6342-xwvw-c637 — Severity: CRITICAL

    • Description: Arbitrary file write in file sink via templated path traversal; untrusted event fields can write files outside intended directory, escalating to code execution (e.g., cron.d or authorized_keys).
    • Affected versions: >= 0.10.0, < 0.57.0
    • Fixed in: v0.57.0
    • Sources: GHSA
    • Evidence: GHSA-6342-xwvw-c637
    • Status: ✅ Fixed in newer versions
  2. GHSA-qp6f-fpfx-4gg6 — Severity: HIGH

    • Description: Unauthenticated denial of service in the logstash source via nested compressed frames causing stack exhaustion and decompression amplification.
    • Affected versions: >= 0.15.0, < 0.57.0
    • Fixed in: 0.57.0
    • Sources: GHSA
    • Evidence: GHSA-qp6f-fpfx-4gg6
    • Status: ✅ Fixed in newer versions
  3. GHSA-rrfg-9487-mhp6 — Severity: HIGH

    • Description: Unauthenticated denial of service in the logstash source via unbounded memory allocation triggered by a crafted compressed frame length field.
    • Affected versions: >= 0.15.0, < 0.57.0
    • Fixed in: 0.57.0
    • Sources: GHSA
    • Evidence: GHSA-rrfg-9487-mhp6
    • Status: ✅ Fixed in newer versions

Vulnerabilities in version 0.57.0

No known vulnerabilities found.

Changelog Security Highlights (0.54.0 → 0.57.0)


Recommendations

  • MERGE PRIORITY: CRITICAL — The old version (0.54.0) has 1 CRITICAL and 2 HIGH-severity vulnerabilities (arbitrary file write, unauthenticated DoS in logstash source). All three are remediated in 0.57.0. No new vulnerabilities introduced.
  • v0.57.0 is explicitly a security-focused release — merge promptly to remediate the exposed vulnerabilities.
  • Review breaking changes if you use the greptimedb_metrics/greptimedb_logs sinks (require GreptimeDB v1.x in 0.56.0) or the GraphQL API (moved to gRPC in 0.55.0).

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild tinfoild Bot changed the title feat(oci/vector): update 0.54.0 ➼ 0.57.0 feat(oci/vector): update 0.54.0 ➼ 0.58.0 Aug 26, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch from 5988b74 to d2cf4d5 Compare August 26, 2026 14:46
@tinfoild

tinfoild Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/monitoring/vector/app Kustomization: flux-system/vector-app HelmRelease: vector/vector

+++ kube/deploy/core/monitoring/vector/app Kustomization: flux-system/vector-app HelmRelease: vector/vector

@@ -59,13 +59,13 @@

                   fieldRef:
                     fieldPath: spec.nodeName
               PROM_HTTP: 8081
               TZ: null
             image:
               repository: ghcr.io/vectordotdev/vector
-              tag: 0.54.0-distroless-libc@sha256:2eb5350e821e77fc35a11a268e5cec4a1460134ddc75f3cb191a949739d36365
+              tag: 0.58.0-distroless-libc@sha256:6c93dfe2554cc7e38316d618961cd657d5271c7a7aa727e0007502b28cb82c2e
             ports:
             - containerPort: 8081
               name: metrics
             resources:
               limits:
                 cpu: '1'

@tinfoild tinfoild Bot changed the title feat(oci/vector): update 0.54.0 ➼ 0.58.0 feat(oci/vector): update 0.54.0 ➼ 0.59.0 Oct 6, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-vectordotdev-vector-0.x branch from d2cf4d5 to d753bfe Compare October 6, 2026 17:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant