Skip to content

feat(oci/helm/app-template): update to v5.3.0 - #5682

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented May 4, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
ghcr.io/bjw-s-labs/helm/app-template minor 5.0.1 → 5.3.0 OpenSSF Scorecard
ghcr.io/bjw-s-labs/helm/app-template major 4.6.2 → 5.3.0 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 4, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4498d76
Status:🚫  Build failed.

View logs

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from a222a58 to f3aff11 Compare May 14, 2026 18:42
@tinfoild tinfoild Bot changed the title feat(oci/helm/app-template)!: Update 4.6.2 ➼ 5.0.0 feat(oci/helm/app-template)!: Update 4.6.2 ➼ 5.0.1 May 14, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch 2 times, most recently from 9908c05 to db881db Compare May 19, 2026 15:12
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch 2 times, most recently from a926808 to 3394fb3 Compare June 7, 2026 13:38
@tinfoild

tinfoild Bot commented Jun 7, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: media/copyparty Deployment: media/copyparty

+++ HelmRelease: media/copyparty Deployment: media/copyparty

@@ -14,25 +14,25 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: copyparty
       app.kubernetes.io/name: copyparty
-      app.kubernetes.io/instance: copyparty
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: copyparty
         app.kubernetes.io/name: copyparty
         ingress.home.arpa/envoy-internal: allow
         ingress.home.arpa/jjgadgets: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: copyparty
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 6969
         fsGroupChangePolicy: OnRootMismatch
         runAsGroup: 6969
         runAsNonRoot: true
--- HelmRelease: media/copyparty ServiceAccount: media/copyparty

+++ HelmRelease: media/copyparty ServiceAccount: media/copyparty

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: copyparty
+  labels:
+    app.kubernetes.io/instance: copyparty
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: copyparty
+  namespace: media
+
--- HelmRelease: continuwuity/continuwuity Deployment: continuwuity/continuwuity

+++ HelmRelease: continuwuity/continuwuity Deployment: continuwuity/continuwuity

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: continuwuity
       app.kubernetes.io/name: continuwuity
-      app.kubernetes.io/instance: continuwuity
   template:
     metadata:
       annotations:
         ipam.cilium.io/ip-pool: vpn-vlan
         ipam.cilium.io/require-pool-match: 'true'
       labels:
@@ -32,13 +32,13 @@

         egress.home.arpa/internet: allow
         egress.home.arpa/ntfy: allow
         ingress.home.arpa/envoy-external: allow
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: continuwuity
       automountServiceAccountToken: false
       runtimeClassName: kata
       securityContext:
         fsGroup: 65534
         fsGroupChangePolicy: Always
         runAsGroup: 65534
--- HelmRelease: continuwuity/continuwuity ServiceAccount: continuwuity/continuwuity

+++ HelmRelease: continuwuity/continuwuity ServiceAccount: continuwuity/continuwuity

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: continuwuity
+  labels:
+    app.kubernetes.io/instance: continuwuity
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: continuwuity
+  namespace: continuwuity
+
--- HelmRelease: cinny/cinny Deployment: cinny/cinny

+++ HelmRelease: cinny/cinny Deployment: cinny/cinny

@@ -14,24 +14,24 @@

   replicas: 2
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: cinny
       app.kubernetes.io/name: cinny
-      app.kubernetes.io/instance: cinny
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: cinny
         app.kubernetes.io/name: cinny
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: cinny
       automountServiceAccountToken: false
       runtimeClassName: kata
       securityContext:
         fsGroup: 65534
         fsGroupChangePolicy: Always
         runAsGroup: 65534
--- HelmRelease: cinny/cinny ServiceAccount: cinny/cinny

+++ HelmRelease: cinny/cinny ServiceAccount: cinny/cinny

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: cinny
+  labels:
+    app.kubernetes.io/instance: cinny
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: cinny
+  namespace: cinny
+
--- HelmRelease: code-server/code-server Deployment: code-server/code-server

+++ HelmRelease: code-server/code-server Deployment: code-server/code-server

@@ -17,14 +17,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: code-server
       app.kubernetes.io/name: code-server
-      app.kubernetes.io/instance: code-server
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: code-server
         app.kubernetes.io/name: code-server
--- HelmRelease: gotosocial/gotosocial Deployment: gotosocial/gotosocial

+++ HelmRelease: gotosocial/gotosocial Deployment: gotosocial/gotosocial

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: gotosocial
       app.kubernetes.io/name: gotosocial
-      app.kubernetes.io/instance: gotosocial
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: gotosocial
         app.kubernetes.io/name: gotosocial
@@ -29,13 +29,13 @@

         egress.home.arpa/internet: allow
         ingress.home.arpa/envoy-external: allow
         ingress.home.arpa/envoy-internal: allow
         prom.home.arpa/kps: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: gotosocial
       automountServiceAccountToken: false
       runtimeClassName: kata
       securityContext:
         fsGroup: 65534
         fsGroupChangePolicy: Always
         runAsGroup: 65534
--- HelmRelease: gotosocial/gotosocial ServiceMonitor: gotosocial/gotosocial

+++ HelmRelease: gotosocial/gotosocial ServiceMonitor: gotosocial/gotosocial

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: gotosocial
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: gotosocial
   namespace: gotosocial
 spec:
-  jobLabel: gotosocial
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - gotosocial
   selector:
     matchLabels:
       app.kubernetes.io/service: gotosocial
--- HelmRelease: gotosocial/gotosocial ServiceAccount: gotosocial/gotosocial

+++ HelmRelease: gotosocial/gotosocial ServiceAccount: gotosocial/gotosocial

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: gotosocial
+  labels:
+    app.kubernetes.io/instance: gotosocial
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: gotosocial
+  namespace: gotosocial
+
--- HelmRelease: atuin/atuin Deployment: atuin/atuin

+++ HelmRelease: atuin/atuin Deployment: atuin/atuin

@@ -14,24 +14,24 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: atuin
       app.kubernetes.io/name: atuin
-      app.kubernetes.io/instance: atuin
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: atuin
         app.kubernetes.io/name: atuin
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: atuin
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: Always
         runAsGroup: 1000
         runAsNonRoot: true
--- HelmRelease: atuin/atuin ServiceAccount: atuin/atuin

+++ HelmRelease: atuin/atuin ServiceAccount: atuin/atuin

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: atuin
+  labels:
+    app.kubernetes.io/instance: atuin
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: atuin
+  namespace: atuin
+
--- HelmRelease: insurgency-sandstorm/insurgency-sandstorm Deployment: insurgency-sandstorm/insurgency-sandstorm-app

+++ HelmRelease: insurgency-sandstorm/insurgency-sandstorm Deployment: insurgency-sandstorm/insurgency-sandstorm-app

@@ -14,25 +14,25 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: insurgency-sandstorm
       app.kubernetes.io/name: insurgency-sandstorm
-      app.kubernetes.io/instance: insurgency-sandstorm
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: insurgency-sandstorm
         app.kubernetes.io/name: insurgency-sandstorm
         dns.home.arpa/l7: 'true'
         ingress.home.arpa/world: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: insurgency-sandstorm
       automountServiceAccountToken: false
       runtimeClassName: kata
       securityContext:
         fsGroup: 1001
         fsGroupChangePolicy: Always
         runAsGroup: 1001
--- HelmRelease: insurgency-sandstorm/insurgency-sandstorm CronJob: insurgency-sandstorm/insurgency-sandstorm-download

+++ HelmRelease: insurgency-sandstorm/insurgency-sandstorm CronJob: insurgency-sandstorm/insurgency-sandstorm-download

@@ -27,13 +27,13 @@

             app.kubernetes.io/controller: download
             app.kubernetes.io/instance: insurgency-sandstorm
             app.kubernetes.io/name: insurgency-sandstorm
             egress.home.arpa/internet: allow
         spec:
           enableServiceLinks: false
-          serviceAccountName: default
+          serviceAccountName: insurgency-sandstorm
           automountServiceAccountToken: false
           securityContext:
             fsGroup: 1001
             fsGroupChangePolicy: Always
             runAsGroup: 1001
             runAsNonRoot: true
--- HelmRelease: insurgency-sandstorm/insurgency-sandstorm ServiceAccount: insurgency-sandstorm/insurgency-sandstorm

+++ HelmRelease: insurgency-sandstorm/insurgency-sandstorm ServiceAccount: insurgency-sandstorm/insurgency-sandstorm

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: insurgency-sandstorm
+  labels:
+    app.kubernetes.io/instance: insurgency-sandstorm
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: insurgency-sandstorm
+  namespace: insurgency-sandstorm
+
--- HelmRelease: cyberchef/cyberchef Deployment: cyberchef/cyberchef

+++ HelmRelease: cyberchef/cyberchef Deployment: cyberchef/cyberchef

@@ -14,24 +14,24 @@

   replicas: 2
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: cyberchef
       app.kubernetes.io/name: cyberchef
-      app.kubernetes.io/instance: cyberchef
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: cyberchef
         app.kubernetes.io/name: cyberchef
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: cyberchef
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: Always
         runAsGroup: 1000
         runAsNonRoot: true
--- HelmRelease: cyberchef/cyberchef ServiceAccount: cyberchef/cyberchef

+++ HelmRelease: cyberchef/cyberchef ServiceAccount: cyberchef/cyberchef

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: cyberchef
+  labels:
+    app.kubernetes.io/instance: cyberchef
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: cyberchef
+  namespace: cyberchef
+
--- HelmRelease: mollysocket/mollysocket Deployment: mollysocket/mollysocket

+++ HelmRelease: mollysocket/mollysocket Deployment: mollysocket/mollysocket

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: mollysocket
       app.kubernetes.io/name: mollysocket
-      app.kubernetes.io/instance: mollysocket
   template:
     metadata:
       annotations:
         ipam.cilium.io/ip-pool: vpn-vlan
         ipam.cilium.io/require-pool-match: 'true'
       labels:
@@ -30,13 +30,13 @@

         app.kubernetes.io/name: mollysocket
         egress.home.arpa/internet: allow
         egress.home.arpa/ntfy: allow
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: mollysocket
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: Always
         runAsGroup: 1000
         runAsNonRoot: true
--- HelmRelease: mollysocket/mollysocket ServiceAccount: mollysocket/mollysocket

+++ HelmRelease: mollysocket/mollysocket ServiceAccount: mollysocket/mollysocket

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: mollysocket
+  labels:
+    app.kubernetes.io/instance: mollysocket
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: mollysocket
+  namespace: mollysocket
+
--- HelmRelease: minecraft/minecraft Deployment: minecraft/minecraft

+++ HelmRelease: minecraft/minecraft Deployment: minecraft/minecraft

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: minecraft
       app.kubernetes.io/name: minecraft
-      app.kubernetes.io/instance: minecraft
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: minecraft
         app.kubernetes.io/name: minecraft
--- HelmRelease: stirling-pdf/stirling-pdf Deployment: stirling-pdf/stirling-pdf

+++ HelmRelease: stirling-pdf/stirling-pdf Deployment: stirling-pdf/stirling-pdf

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: stirling-pdf
       app.kubernetes.io/name: stirling-pdf
-      app.kubernetes.io/instance: stirling-pdf
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: stirling-pdf
         app.kubernetes.io/name: stirling-pdf
--- HelmRelease: ntfy/ntfy Deployment: ntfy/ntfy

+++ HelmRelease: ntfy/ntfy Deployment: ntfy/ntfy

@@ -14,24 +14,24 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: ntfy
       app.kubernetes.io/name: ntfy
-      app.kubernetes.io/instance: ntfy
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: ntfy
         app.kubernetes.io/name: ntfy
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: ntfy
       automountServiceAccountToken: false
       runtimeClassName: gvisor
       securityContext:
         fsGroup: 65534
         fsGroupChangePolicy: Always
         runAsGroup: 65534
--- HelmRelease: ntfy/ntfy ServiceAccount: ntfy/ntfy

+++ HelmRelease: ntfy/ntfy ServiceAccount: ntfy/ntfy

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: ntfy
+  labels:
+    app.kubernetes.io/instance: ntfy
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: ntfy
+  namespace: ntfy
+
--- HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-app

+++ HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-app

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: sit-ics-go
       app.kubernetes.io/name: sit-ics-go
-      app.kubernetes.io/instance: sit-ics-go
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: sit-ics-go
         app.kubernetes.io/name: sit-ics-go
--- HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-chromium

+++ HelmRelease: sit-ics-go/sit-ics-go Deployment: sit-ics-go/sit-ics-go-chromium

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: chromium
+      app.kubernetes.io/instance: sit-ics-go
       app.kubernetes.io/name: sit-ics-go
-      app.kubernetes.io/instance: sit-ics-go
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: chromium
         app.kubernetes.io/instance: sit-ics-go
         app.kubernetes.io/name: sit-ics-go
--- HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-app

+++ HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-app

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: mindwtr
       app.kubernetes.io/name: mindwtr
-      app.kubernetes.io/instance: mindwtr
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: mindwtr
         app.kubernetes.io/name: mindwtr
--- HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-cloud

+++ HelmRelease: mindwtr/mindwtr Deployment: mindwtr/mindwtr-cloud

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: cloud
+      app.kubernetes.io/instance: mindwtr
       app.kubernetes.io/name: mindwtr
-      app.kubernetes.io/instance: mindwtr
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: cloud
         app.kubernetes.io/instance: mindwtr
         app.kubernetes.io/name: mindwtr
--- HelmRelease: openclaw/openclaw Deployment: openclaw/openclaw

+++ HelmRelease: openclaw/openclaw Deployment: openclaw/openclaw

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: openclaw
       app.kubernetes.io/name: openclaw
-      app.kubernetes.io/instance: openclaw
   template:
     metadata:
       annotations:
         ipam.cilium.io/ip-pool: vpn-vlan
         ipam.cilium.io/require-pool-match: 'true'
       labels:
--- HelmRelease: lunar-ics/lunar-ics Deployment: lunar-ics/lunar-ics

+++ HelmRelease: lunar-ics/lunar-ics Deployment: lunar-ics/lunar-ics

@@ -14,14 +14,14 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: lunar-ics
       app.kubernetes.io/name: lunar-ics
-      app.kubernetes.io/instance: lunar-ics
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: lunar-ics
         app.kubernetes.io/name: lunar-ics
--- HelmRelease: out-of-your-element/out-of-your-element Deployment: out-of-your-element/out-of-your-element

+++ HelmRelease: out-of-your-element/out-of-your-element Deployment: out-of-your-element/out-of-your-element

@@ -14,26 +14,26 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: out-of-your-element
       app.kubernetes.io/name: out-of-your-element
-      app.kubernetes.io/instance: out-of-your-element
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: out-of-your-element
         app.kubernetes.io/name: out-of-your-element
         egress.home.arpa/internet: allow
         ingress.home.arpa/envoy-external: allow
         ingress.home.arpa/envoy-internal: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: out-of-your-element
       automountServiceAccountToken: false
       runtimeClassName: gvisor
       securityContext:
         fsGroup: 1000
         fsGroupChangePolicy: Always
         runAsGroup: 1000
--- HelmRelease: out-of-your-element/out-of-your-element ServiceAccount: out-of-your-element/out-of-your-element

+++ HelmRelease: out-of-your-element/out-of-your-element ServiceAccount: out-of-your-element/out-of-your-element

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: out-of-your-element
+  labels:
+    app.kubernetes.io/instance: out-of-your-element
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: out-of-your-element
+  namespace: out-of-your-element
+
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-app

+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-app

@@ -14,25 +14,25 @@

   replicas: 0
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: app
+      app.kubernetes.io/instance: llama-cpp
       app.kubernetes.io/name: llama-cpp
-      app.kubernetes.io/instance: llama-cpp
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: app
         app.kubernetes.io/instance: llama-cpp
         app.kubernetes.io/name: llama-cpp
         ingress.home.arpa/envoy-internal: allow
         prom.home.arpa/kps: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: llama-cpp
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 98341
         fsGroupChangePolicy: Always
         runAsGroup: 98341
         runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding

+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding

@@ -14,25 +14,25 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: embedding
+      app.kubernetes.io/instance: llama-cpp
       app.kubernetes.io/name: llama-cpp
-      app.kubernetes.io/instance: llama-cpp
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: embedding
         app.kubernetes.io/instance: llama-cpp
         app.kubernetes.io/name: llama-cpp
         ingress.home.arpa/envoy-internal: allow
         prom.home.arpa/kps: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: llama-cpp
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 98341
         fsGroupChangePolicy: Always
         runAsGroup: 98341
         runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank

+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank

@@ -14,25 +14,25 @@

   replicas: 1
   strategy:
     type: Recreate
   selector:
     matchLabels:
       app.kubernetes.io/controller: rerank
+      app.kubernetes.io/instance: llama-cpp
       app.kubernetes.io/name: llama-cpp
-      app.kubernetes.io/instance: llama-cpp
   template:
     metadata:
       labels:
         app.kubernetes.io/controller: rerank
         app.kubernetes.io/instance: llama-cpp
         app.kubernetes.io/name: llama-cpp
         ingress.home.arpa/envoy-internal: allow
         prom.home.arpa/kps: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: llama-cpp
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 98341
         fsGroupChangePolicy: Always
         runAsGroup: 98341
         runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull

+++ HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull

@@ -18,13 +18,13 @@

         app.kubernetes.io/controller: pull
         app.kubernetes.io/instance: llama-cpp
         app.kubernetes.io/name: llama-cpp
         egress.home.arpa/internet: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: llama-cpp
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 98341
         fsGroupChangePolicy: Always
         runAsGroup: 98341
         runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-embedding

+++ HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-embedding

@@ -18,13 +18,13 @@

         app.kubernetes.io/controller: pull-embedding
         app.kubernetes.io/instance: llama-cpp
         app.kubernetes.io/name: llama-cpp
         egress.home.arpa/internet: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: llama-cpp
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 98341
         fsGroupChangePolicy: Always
         runAsGroup: 98341
         runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-rerank

+++ HelmRelease: llama-cpp/llama-cpp Job: llama-cpp/llama-cpp-pull-rerank

@@ -18,13 +18,13 @@

         app.kubernetes.io/controller: pull-rerank
         app.kubernetes.io/instance: llama-cpp
         app.kubernetes.io/name: llama-cpp
         egress.home.arpa/internet: allow
     spec:
       enableServiceLinks: false
-      serviceAccountName: default
+      serviceAccountName: llama-cpp
       automountServiceAccountToken: false
       securityContext:
         fsGroup: 98341
         fsGroupChangePolicy: Always
         runAsGroup: 98341
         runAsNonRoot: true
--- HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-app

+++ HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-app

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: llama-cpp
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: llama-cpp
   namespace: llama-cpp
 spec:
-  jobLabel: llama-cpp-app
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - llama-cpp
   selector:
     matchLabels:
       app.kubernetes.io/service: llama-cpp
--- HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-embedding

+++ HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-embedding

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: llama-cpp
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: llama-cpp
   namespace: llama-cpp
 spec:
-  jobLabel: llama-cpp-embedding
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - llama-cpp
   selector:
     matchLabels:
       app.kubernetes.io/service: llama-cpp-embedding
--- HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-rerank

+++ HelmRelease: llama-cpp/llama-cpp ServiceMonitor: llama-cpp/llama-cpp-rerank

@@ -6,13 +6,13 @@

   labels:
     app.kubernetes.io/instance: llama-cpp
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: llama-cpp
   namespace: llama-cpp
 spec:
-  jobLabel: llama-cpp-rerank
+  jobLabel: app.kubernetes.io/name
   namespaceSelector:
     matchNames:
     - llama-cpp
   selector:
     matchLabels:
       app.kubernetes.io/service: llama-cpp-rerank
--- HelmRelease: llama-cpp/llama-cpp ServiceAccount: llama-cpp/llama-cpp

+++ HelmRelease: llama-cpp/llama-cpp ServiceAccount: llama-cpp/llama-cpp

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: llama-cpp
+  labels:
+    app.kubernetes.io/instance: llama-cpp
+    app.kubernetes.io/managed-by: Helm
+    app.kubernetes.io/name: llama-cpp
+  namespace: llama-cpp
+

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 3394fb3 to 455a279 Compare June 8, 2026 21:00
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 455a279 to bc0b8d5 Compare June 19, 2026 12:35
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from bc0b8d5 to d405fcb Compare June 28, 2026 12:36
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from d405fcb to 99babfa Compare July 20, 2026 10:15
@ciel-shieru

ciel-shieru commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 07:07 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5682 — feat(oci/helm/app-template)!: Update 4.6.2 ➼ 5.0.1
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 0


Severity Summary

Severity Count
CRITICAL 0
HIGH 0
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 0

Results

Package: ghcr.io/bjw-s-labs/helm/app-template

  • Ecosystem: Helm (OCI chart)
  • Old version: 4.6.2 — CLEAN
  • New version: 5.0.1 — CLEAN

Vulnerabilities in version 4.6.2

No known vulnerabilities found.

Vulnerabilities in version 5.0.1

No known vulnerabilities found.

Source scan summary

Source Status Notes
OSV.dev ✅ Scanned No results in any ecosystem
NVD ✅ Scanned No CVEs found for this chart or its upstream repo
GHSA ✅ Scanned No advisories for this package
GHSL ✅ Scanned (limited) Web search unavailable; GHSL findings typically appear via GHSA/NVD — none found
CISA KEV ✅ Scanned No entries for this product
FortiGuard ✅ Scanned No advisories related to this project
CVE.org ✅ Scanned (limited) API requires key; NVD cross-check confirmed no CVEs
Changelog ✅ Scanned See highlights below

Changelog Security Highlights (4.6.2 → 5.0.1)

  • common-5.0.0 — 🔒 automountServiceAccountToken now defaults to false (security hardening)
  • common-5.0.0 — 🔒 Unprivileged default ServiceAccount created automatically (isolation improvement)
  • common-5.0.0 — ⚠️ Breaking: rawResources restructured to use a manifest wrapper key — review affected values before merging
  • common-5.0.1 — 🐛 Fixed serviceAccountName resolution when global.nameOverride is set
  • common-5.0.1 — 🐛 Fixed namespace omission in route parentRefs

Recommendations

  • MERGE PRIORITY: LOW — No security vulnerabilities found in either version.
  • The v5.x upgrade introduces meaningful security hardening (default SA isolation, service account token auto-mount disabled by default) but requires careful review of breaking changes to rawResources configuration.
  • ⚠️ Review the 4-to-5 upgrade guide before merging to ensure breaking changes don't cause configuration regressions.
  • No new vulnerabilities introduced; the new version improves the baseline security posture.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 99babfa to 7c58d80 Compare August 24, 2026 03:10
@tinfoild tinfoild Bot changed the title feat(oci/helm/app-template)!: Update 4.6.2 ➼ 5.0.1 feat(oci/helm/app-template): update to v5.1.0 Aug 24, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 7c58d80 to 7381455 Compare September 5, 2026 07:40
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from 7381455 to acd25c4 Compare September 17, 2026 18:32
@tinfoild tinfoild Bot changed the title feat(oci/helm/app-template): update to v5.1.0 feat(oci/helm/app-template): update to v5.2.0 Sep 17, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from acd25c4 to c65199c Compare September 17, 2026 21:39
@tinfoild tinfoild Bot changed the title feat(oci/helm/app-template): update to v5.2.0 feat(oci/helm/app-template): update to v5.2.1 Sep 17, 2026
@tinfoild tinfoild Bot changed the title feat(oci/helm/app-template): update to v5.2.1 feat(oci/helm/app-template): update to v5.3.0 Oct 10, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-bjw-s-labs-helm-app-template-5.x branch from c65199c to 4498d76 Compare October 10, 2026 18:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant