Skip to content

feat(oci/zigbee2mqtt): update 2.9.2 ➼ 2.14.2 - #5668

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-koenkk-zigbee2mqtt-2.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-koenkk-zigbee2mqtt-2.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented May 1, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
ghcr.io/koenkk/zigbee2mqtt minor 2.9.2 → 2.14.2 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

Koenkk/zigbee2mqtt (ghcr.io/koenkk/zigbee2mqtt)

v2.14.2

Compare Source

Bug Fixes

v2.14.1

Compare Source

Bug Fixes

v2.14.0

Compare Source

Features
Bug Fixes

v2.13.0

Compare Source

Features
  • Add clear_cache option to device remove request (#​32631) (83ab522)
  • Home Assistant: add discovery support for Tuya infrared receiver (learn mode) and emitter features (#​32625) (32506b4)
Bug Fixes

v2.12.1

Compare Source

Bug Fixes

v2.12.0

Compare Source

Features
Bug Fixes

v2.11.0

Compare Source

Features
Bug Fixes

v2.10.1

Compare Source

Bug Fixes

v2.10.0

Compare Source

Features
Bug Fixes

Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 1, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: f1658b2
Status:🚫  Build failed.

View logs

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-koenkk-zigbee2mqtt-2.x branch from d69d57b to cb97168 Compare May 2, 2026 20:18
@tinfoild

tinfoild Bot commented May 2, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/clusters/biohazard/flux Kustomization: flux-system/0-biohazard-config Kustomization: zigbee2mqtt/zigbee2mqtt-pvc

+++ kube/clusters/biohazard/flux Kustomization: flux-system/0-biohazard-config Kustomization: zigbee2mqtt/zigbee2mqtt-pvc

@@ -277,13 +277,13 @@

       RGID: '1000'
       RUID: '1000'
       SC: file
       SIZE: 1Gi
       SNAP: file
       SNAP_ACCESSMODE: ReadOnlyMany
-      VS_APP_CURRENT_VERSION: ghcr.io/koenkk/zigbee2mqtt:2.9.2@sha256:2a21bbf7a664a149024bbe1f776e3151f28ed9db15948270dcbffb89544a41f0
+      VS_APP_CURRENT_VERSION: ghcr.io/koenkk/zigbee2mqtt:2.14.2@sha256:addbfb08fcef2e4477de1535636118241e10d13e898fbe4d9faba8a4d7396311
     substituteFrom:
     - kind: Secret
       name: biohazard-vars
       optional: false
     - kind: Secret
       name: biohazard-secrets
--- kube/deploy/core/storage/volsync/template Kustomization: zigbee2mqtt/zigbee2mqtt-pvc ReplicationSource: zigbee2mqtt/zigbee2mqtt-data-r2-updates-restic

+++ kube/deploy/core/storage/volsync/template Kustomization: zigbee2mqtt/zigbee2mqtt-pvc ReplicationSource: zigbee2mqtt/zigbee2mqtt-data-r2-updates-restic

@@ -53,8 +53,8 @@

       daily: 14
       within: 7d
     storageClassName: file
     volumeSnapshotClassName: file
   sourcePVC: zigbee2mqtt-data
   trigger:
-    manual: ghcr.io/koenkk/zigbee2mqtt:2.9.2@sha256:2a21bbf7a664a149024bbe1f776e3151f28ed9db15948270dcbffb89544a41f0
+    manual: ghcr.io/koenkk/zigbee2mqtt:2.14.2@sha256:addbfb08fcef2e4477de1535636118241e10d13e898fbe4d9faba8a4d7396311
 
--- kube/deploy/core/storage/volsync/template Kustomization: zigbee2mqtt/zigbee2mqtt-pvc VolumeSnapshot: zigbee2mqtt/zigbee2mqtt-data-vb89544a41f0

+++ kube/deploy/core/storage/volsync/template Kustomization: zigbee2mqtt/zigbee2mqtt-pvc VolumeSnapshot: zigbee2mqtt/zigbee2mqtt-data-vb89544a41f0

@@ -1,16 +0,0 @@

----
-apiVersion: snapshot.storage.k8s.io/v1
-kind: VolumeSnapshot
-metadata:
-  labels:
-    app.kubernetes.io/name: zigbee2mqtt
-    kustomize.toolkit.fluxcd.io/name: zigbee2mqtt-pvc
-    kustomize.toolkit.fluxcd.io/namespace: zigbee2mqtt
-    pvc.home.arpa/volsync: 'true'
-  name: zigbee2mqtt-data-vb89544a41f0
-  namespace: zigbee2mqtt
-spec:
-  source:
-    persistentVolumeClaimName: zigbee2mqtt-data
-  volumeSnapshotClassName: file
-
--- kube/deploy/core/storage/volsync/template Kustomization: zigbee2mqtt/zigbee2mqtt-pvc VolumeSnapshot: zigbee2mqtt/zigbee2mqtt-data-v8a4d7396311

+++ kube/deploy/core/storage/volsync/template Kustomization: zigbee2mqtt/zigbee2mqtt-pvc VolumeSnapshot: zigbee2mqtt/zigbee2mqtt-data-v8a4d7396311

@@ -0,0 +1,16 @@

+---
+apiVersion: snapshot.storage.k8s.io/v1
+kind: VolumeSnapshot
+metadata:
+  labels:
+    app.kubernetes.io/name: zigbee2mqtt
+    kustomize.toolkit.fluxcd.io/name: zigbee2mqtt-pvc
+    kustomize.toolkit.fluxcd.io/namespace: zigbee2mqtt
+    pvc.home.arpa/volsync: 'true'
+  name: zigbee2mqtt-data-v8a4d7396311
+  namespace: zigbee2mqtt
+spec:
+  source:
+    persistentVolumeClaimName: zigbee2mqtt-data
+  volumeSnapshotClassName: file
+
--- kube/deploy/apps/zigbee2mqtt/app Kustomization: zigbee2mqtt/zigbee2mqtt-app HelmRelease: zigbee2mqtt/zigbee2mqtt

+++ kube/deploy/apps/zigbee2mqtt/app Kustomization: zigbee2mqtt/zigbee2mqtt-app HelmRelease: zigbee2mqtt/zigbee2mqtt

@@ -71,13 +71,13 @@

               ZIGBEE2MQTT_DATA: /config
             envFrom:
             - secretRef:
                 name: zigbee2mqtt-secrets
             image:
               repository: ghcr.io/koenkk/zigbee2mqtt
-              tag: 2.9.2@sha256:2a21bbf7a664a149024bbe1f776e3151f28ed9db15948270dcbffb89544a41f0
+              tag: 2.14.2@sha256:addbfb08fcef2e4477de1535636118241e10d13e898fbe4d9faba8a4d7396311
             probes:
               liveness:
                 enabled: true
               readiness:
                 enabled: true
               startup:

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-koenkk-zigbee2mqtt-2.x branch 2 times, most recently from fd3790f to 40de11d Compare May 2, 2026 22:18
@tinfoild

tinfoild Bot commented May 2, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: zigbee2mqtt/zigbee2mqtt Deployment: zigbee2mqtt/zigbee2mqtt

+++ HelmRelease: zigbee2mqtt/zigbee2mqtt Deployment: zigbee2mqtt/zigbee2mqtt

@@ -110,13 +110,13 @@

           value: tcp://slzb.internal:6638
         - name: ZIGBEE2MQTT_DATA
           value: /config
         envFrom:
         - secretRef:
             name: zigbee2mqtt-secrets
-        image: ghcr.io/koenkk/zigbee2mqtt:2.9.2@sha256:2a21bbf7a664a149024bbe1f776e3151f28ed9db15948270dcbffb89544a41f0
+        image: ghcr.io/koenkk/zigbee2mqtt:2.14.2@sha256:addbfb08fcef2e4477de1535636118241e10d13e898fbe4d9faba8a4d7396311
         livenessProbe:
           failureThreshold: 3
           initialDelaySeconds: 0
           periodSeconds: 10
           tcpSocket:
             port: 80

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-koenkk-zigbee2mqtt-2.x branch 18 times, most recently from 98003a3 to d409966 Compare May 5, 2026 22:26
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-koenkk-zigbee2mqtt-2.x branch from 7ad22da to bbd7660 Compare May 7, 2026 18:40
@tinfoild tinfoild Bot changed the title feat(oci/zigbee2mqtt): update 2.9.2 ➼ 2.10.0 feat(oci/zigbee2mqtt): update 2.9.2 ➼ 2.10.1 May 7, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-koenkk-zigbee2mqtt-2.x branch 25 times, most recently from a2d5d18 to 31d0fef Compare May 10, 2026 21:22
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 14:10 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5668 — feat(oci/zigbee2mqtt): update 2.9.2 ➼ 2.12.1
📦 Packages checked: 7 (zigbee2mqtt + 6 sub-dependencies)
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 9


Severity Summary

Severity Count
CRITICAL 0
HIGH 5
MEDIUM / MODERATE 3
LOW 1
UNKNOWN / NEEDS VERIFICATION 0
Total 9

Results

Package: zigbee2mqtt (ghcr.io/koenkk/zigbee2mqtt) — Docker Image

  • Ecosystem: Docker
  • Old version: 2.9.2 — CLEAN
  • New version: 2.12.1 — CLEAN

No direct CVEs found for the zigbee2mqtt image itself across all sources (NVD, GHSA, OSV.dev, CISA KEV, FortiGuard). However, it bundles several vulnerable npm sub-dependencies listed below.

Package: brace-expansion

  • Ecosystem: npm
  • Old version: 2.0.2 — VULNERABLE (2 CVEs)
  • New version: 5.0.6 — PARTIALLY FIXED (1 CVE remaining)

Vulnerabilities in version 2.0.2

  1. GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 — Severity: HIGH (CVSS 7.5)

    • DoS via exponential-time expansion of consecutive non-expanding {} groups
    • Fixed in: ≥1.1.16, ≥2.1.2, ≥5.0.7
  2. GHSA-f886-m6hf-6m8v / CVE-2026-33750 — Severity: MEDIUM (CVSS 5.4)

    • Zero-step sequence causes process hang and memory exhaustion
    • Fixed in: ≥1.1.13, ≥2.0.3, ≥3.0.2, ≥5.0.5

Vulnerabilities in version 5.0.6

  1. GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 — Severity: HIGH (CVSS 7.5)
    • DoS via exponential-time expansion of consecutive non-expanding {} groups
    • Affected versions: ≥3.0.0, <5.0.7
    • Fixed in: 5.0.7

Package: ws (WebSocket)

  • Ecosystem: npm
  • Old version: 8.20.0 — VULNERABLE (2 CVEs)
  • New version: 8.20.1 — PARTIALLY FIXED (1 CVE remaining)

Vulnerabilities in version 8.20.0

  1. GHSA-96hv-2xvq-fx4p / CVE-2026-48779 — Severity: HIGH (CVSS 7.5)

    • Memory exhaustion DoS from tiny fragments and data chunks
    • Fixed in: ≥5.2.5, ≥6.2.4, ≥7.5.11, ≥8.21.0
  2. GHSA-58qx-3vcg-4xpx / CVE-2026-45736 — Severity: MEDIUM (CVSS 3.1)

    • Uninitialized memory disclosure via websocket.close() reason argument
    • Fixed in: ≥8.20.1

Vulnerabilities in version 8.20.1

  1. GHSA-96hv-2xvq-fx4p / CVE-2026-48779 — Severity: HIGH (CVSS 7.5)
    • Memory exhaustion DoS from tiny fragments and data chunks
    • Fixed in: ≥8.21.0

Package: tmp

  • Ecosystem: npm
  • Old version: 0.2.5 — VULNERABLE (1 CVE)
  • New version: 0.2.6 — INTRODUCES NEW CVE (1 HIGH)

Vulnerabilities in version 0.2.5

  1. GHSA-ph9p-34f9-6g65 / CVE-2026-44705 — Severity: HIGH
    • Path traversal via unsanitized prefix/postfix enabling directory escape (CVSS 8.1)
    • Fixed in: ≥0.2.6

Vulnerabilities in version 0.2.6

  1. GHSA-7c78-jf6q-g5cm / CVE-2026-XXXXX — Severity: HIGH
    • Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
    • Introduced in: 0.2.6 (patch regression)

Package: js-yaml

  • Ecosystem: npm
  • Old version: 4.2.0 — VULNERABLE (1 CVE)
  • New version: 5.0.0 — INTRODUCES NEW CVEs (2 MODERATE)

Vulnerabilities in version 4.2.0

  1. GHSA-52cp-r559-cp3m / CVE-2026-59869 — Severity: HIGH (CVSS 7.5)
    • YAML merge-key chains can force quadratic CPU consumption (O(n²))
    • Affected versions: ≥4.0.0, <4.3.0

Vulnerabilities in version 5.0.0

  1. GHSA-724g-mxrg-4qvm / CVE-2026-59870 — Severity: MEDIUM (CVSS 5.4)

    • Quadratic-complexity DoS via !!omap tag in YAML11_SCHEMA (O(n²))
    • Fixed in: ≥5.2.1
  2. GHSA-g796-fgmg-93mv / CVE-2026-59868 — Severity: LOW/MODERATE (CVSS 5.4)

    • YAML merge-key chains force quadratic CPU consumption in v5.x (merge off by default)
    • Fixed in: ≥5.2.0

Package: semver

  • Ecosystem: npm
  • Old version: 7.8.4 — CLEAN
  • New version: 7.8.5 — CLEAN

No known vulnerabilities found across all sources.


Recommendations

  • ⚠️ DO NOT MERGE — This PR updates to a new version that introduces or retains HIGH-severity vulnerabilities in multiple bundled dependencies:

    • brace-expansion 5.0.6 still has CVE-2026-13149 (HIGH) — needs ≥5.0.7
    • ws 8.20.1 still has CVE-2026-48779 (HIGH) — needs ≥8.21.0
    • js-yaml 5.0.0 introduces 2 new CVEs vs the old 4.x version, and neither fix exists yet at 5.0.0
    • tmp 0.2.6 has a patch regression (new HIGH CVE introduced by the fix)
  • Recommended actions:

    1. Request zigbee2mqtt maintainers to update bundled deps: brace-expansion ≥5.0.7, ws ≥8.21.0
    2. Consider pinning js-yaml to a patched version (≥4.3.0 or wait for ≥5.2.0) instead of jumping to 5.0.0
    3. Monitor tmp for an alternative fix that doesn't introduce GHSA-7c78

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant