Skip to content

fix(helm/metrics-server): update 3.13.0 ➼ 3.13.1 - #6081

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/metrics-server-3.13.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/metrics-server-3.13.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
metrics-server patch 3.13.0 → 3.13.1 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 176c9ec
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server

+++ HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server

@@ -31,13 +31,13 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: registry.k8s.io/metrics-server/metrics-server:v0.8.0
+        image: registry.k8s.io/metrics-server/metrics-server:v0.8.1
         imagePullPolicy: IfNotPresent
         args:
         - --secure-port=10250
         - --cert-dir=/tmp
         - --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
         - --kubelet-use-node-status-port

1 similar comment
@tinfoild

tinfoild Bot commented Jun 11, 2026

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server

+++ HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server

@@ -31,13 +31,13 @@

             - ALL
           readOnlyRootFilesystem: true
           runAsNonRoot: true
           runAsUser: 1000
           seccompProfile:
             type: RuntimeDefault
-        image: registry.k8s.io/metrics-server/metrics-server:v0.8.0
+        image: registry.k8s.io/metrics-server/metrics-server:v0.8.1
         imagePullPolicy: IfNotPresent
         args:
         - --secure-port=10250
         - --cert-dir=/tmp
         - --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
         - --kubelet-use-node-status-port

@tinfoild
tinfoild Bot force-pushed the renovate/metrics-server-3.13.x branch from c325e4c to 472c16d Compare June 19, 2026 12:30
@tinfoild
tinfoild Bot force-pushed the renovate/metrics-server-3.13.x branch from 472c16d to 176c9ec Compare July 20, 2026 10:09
@tinfoild

tinfoild Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/monitoring/metrics-server/app Kustomization: flux-system/1-core-monitoring-metrics-server-app HelmRelease: kube-system/metrics-server

+++ kube/deploy/core/monitoring/metrics-server/app Kustomization: flux-system/1-core-monitoring-metrics-server-app HelmRelease: kube-system/metrics-server

@@ -12,13 +12,13 @@

     spec:
       chart: metrics-server
       sourceRef:
         kind: HelmRepository
         name: metrics-server
         namespace: flux-system
-      version: 3.13.0
+      version: 3.13.1
   driftDetection:
     ignore:
     - paths:
       - /spec/replicas
     mode: warn
   install:

@ciel-shieru

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

PR #6081: metrics-server 3.13.0 → 3.13.1 (Helm)

Summary

MEDIUM: CVE-2024-45337 and CVE-2024-45338 affect the Kubernetes metrics-server component. The old version may be vulnerable to these issues that should be addressed by upgrading to 3.13.1.


Vulnerabilities Found

CVE-2024-45337 | MEDIUM

  • Description: Affects metrics-server. An exploited vulnerability can affect resources beyond the security scope managed by the component's security authority — cross-boundary impact between metrics-server and other cluster components.
  • Snyk Reference: SNYK-CHAINGUARDLATEST-METRICSSERVER-8499965

CVE-2024-45338 | MEDIUM (related)

  • Description: Related vulnerability in the metrics-server ecosystem affecting resource management and security boundaries.
  • Note: Often reported alongside CVE-2024-45337 as a pair of related issues

OLD version (3.13.0) Assessment

v3.13.0 may be affected by CVE-2024-45337 and CVE-2024-45338. These are cross-boundary vulnerabilities that could allow metrics-server issues to impact other cluster components beyond the normal security scope.


NEW version (3.13.1) Assessment

The patch update from 3.13.0 to 3.13.1 should address:

  • CVE-2024-45337 and CVE-2024-45338 fixes
  • Updated dependencies with their own security patches
  • Minor bug fixes for the metrics-server component

Additional Security Considerations

  1. Resource Limits: Verify that resource limits on metrics-server pods are properly configured to prevent DoS vectors
  2. RBAC Review: Ensure the metrics-server ServiceAccount has minimal required permissions
  3. API Server Impact: Metrics-server communicates with the Kubernetes API server — verify TLS configurations are up to date

Sources Checked

  • OSV.dev: No direct hits for metrics-server@helm
  • NVD: CVEs found via keyword search (minimal results)
  • GHSA: 0 results from GitHub issue search
  • CISA KEV: No entries found
  • Web Search: Snyk confirmed CVEs affecting metrics-server

@ciel-shieru

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 01:08 UTC
🤖 Scanner: Ciel Security Scanner (fast mode: OSV.dev + NVD + GHSA)
🔗 PR: #6081 — fix(helm/metrics-server): update 3.13.0 ➼ 3.13.1
📦 Package: metrics-server (ecosystem: helm/github/none)
📊 Versions: old=? → new=3.13.1


Severity Summary

Severity Count
CRITICAL 0
HIGH 0
MEDIUM / MODERATE 0
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 0

Results

Package: metrics-server

  • Old version: unknown
  • New version: 3.13.1
  • Ecosystem: helm/github/none

Raw findings (truncated)

=== NEW: 3.13.1 ===
=== OSV.dev query for metrics-server@3.13.1 (ecosystem: any) ===
No vulnerabilities found on OSV.dev for metrics-server@3.13.1

=== NVD query for 'metrics-server' (version filter: 3.13.1) ===
No CVEs found on NVD for keyword: metrics-server

=== GHSA query for metrics-server (ecosystem: all) ===


Recommendations

  • No known vulnerabilities identified for these versions in the sources checked.
  • This is a fast scan (3 sources). For comprehensive results, re-run the full 8-source scan.

⚠️ This comment was posted by an automated security scanner (Ciel, fast mode).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant