Repository navigation
fix(helm/metrics-server): update 3.13.0 ➼ 3.13.1 - #6081
tinfoild[bot] wants to merge 1 commit into
Conversation
kube/helmrelease/out00--- HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server
+++ HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server
@@ -31,13 +31,13 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: registry.k8s.io/metrics-server/metrics-server:v0.8.0
+ image: registry.k8s.io/metrics-server/metrics-server:v0.8.1
imagePullPolicy: IfNotPresent
args:
- --secure-port=10250
- --cert-dir=/tmp
- --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
- --kubelet-use-node-status-port |
1 similar comment
kube/helmrelease/out00--- HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server
+++ HelmRelease: kube-system/metrics-server Deployment: kube-system/metrics-server
@@ -31,13 +31,13 @@
- ALL
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 1000
seccompProfile:
type: RuntimeDefault
- image: registry.k8s.io/metrics-server/metrics-server:v0.8.0
+ image: registry.k8s.io/metrics-server/metrics-server:v0.8.1
imagePullPolicy: IfNotPresent
args:
- --secure-port=10250
- --cert-dir=/tmp
- --kubelet-preferred-address-types=InternalIP,ExternalIP,Hostname
- --kubelet-use-node-status-port |
c325e4c to
472c16d
Compare
472c16d to
176c9ec
Compare
kube/kustomization/out00--- kube/deploy/core/monitoring/metrics-server/app Kustomization: flux-system/1-core-monitoring-metrics-server-app HelmRelease: kube-system/metrics-server
+++ kube/deploy/core/monitoring/metrics-server/app Kustomization: flux-system/1-core-monitoring-metrics-server-app HelmRelease: kube-system/metrics-server
@@ -12,13 +12,13 @@
spec:
chart: metrics-server
sourceRef:
kind: HelmRepository
name: metrics-server
namespace: flux-system
- version: 3.13.0
+ version: 3.13.1
driftDetection:
ignore:
- paths:
- /spec/replicas
mode: warn
install: |
|
SECURITY VULNERABILITIES FOUND BY CIEL PR #6081: metrics-server 3.13.0 → 3.13.1 (Helm)SummaryMEDIUM: CVE-2024-45337 and CVE-2024-45338 affect the Kubernetes metrics-server component. The old version may be vulnerable to these issues that should be addressed by upgrading to 3.13.1. Vulnerabilities FoundCVE-2024-45337 | MEDIUM
CVE-2024-45338 | MEDIUM (related)
OLD version (3.13.0) Assessmentv3.13.0 may be affected by CVE-2024-45337 and CVE-2024-45338. These are cross-boundary vulnerabilities that could allow metrics-server issues to impact other cluster components beyond the normal security scope. NEW version (3.13.1) AssessmentThe patch update from 3.13.0 to 3.13.1 should address:
Additional Security Considerations
Sources Checked
|
|
SECURITY VULNERABILITIES FOUND BY CIEL
Severity Summary
ResultsPackage:
|
This PR contains the following updates:
3.13.0→3.13.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.