Skip to content

feat(oci/multus-cni): update v4.2.4 ➼ v4.3.1 - #6084

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x
Open

tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
ghcr.io/k8snetworkplumbingwg/multus-cni minor v4.2.4 → v4.3.1 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

k8snetworkplumbingwg/multus-cni (ghcr.io/k8snetworkplumbingwg/multus-cni)

v4.3.1

Compare Source

What's Changed

Full Changelog: k8snetworkplumbingwg/multus-cni@v4.3.0...v4.3.1

v4.3.0

Compare Source

DeviceID ordering is now deterministic (alphabetically sorted). 
CNIs relying on specific device positions may see different assignments.
What's Changed
New Contributors

Full Changelog: k8snetworkplumbingwg/multus-cni@v4.2.4...v4.3.0


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 6622796
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: multus/multus DaemonSet: multus/multus

+++ HelmRelease: multus/multus DaemonSet: multus/multus

@@ -67,13 +67,13 @@

         - mountPath: /tmp
           name: tmp
       containers:
       - args:
         - --cleanup-config-on-exit
         - --multus-cni-conf-dir=/tmp
-        image: ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4@sha256:c3b12d1b56d7607a302ec23ececa236256bc940c04b3be5c1f39e0234398c4c9
+        image: ghcr.io/k8snetworkplumbingwg/multus-cni:v4.3.1@sha256:9dc8ca645a78552ed4151cf67c2998d18f260f172cc541580d8acce2ee3495c2
         name: app
         securityContext:
           allowPrivilegeEscalation: false
           capabilities:
             add:
             - NET_ADMIN
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank

+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank

@@ -120,13 +120,13 @@

         - name: TZ
           value: null
         - name: UR_L0_ENABLE_RELAXED_ALLOCATION_LIMITS
           value: '1'
         - name: ZES_ENABLE_SYSMAN
           value: '1'
-        image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:431561ee79ee67b3980a02ff47ed9dc19496127643b75671d9789ef693ca57f9
+        image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:4507f4ad728c615e2a09c982c3a4a2ff02abb0f07727710c0e75bb4de951ac5a
         livenessProbe:
           failureThreshold: 3
           initialDelaySeconds: 0
           periodSeconds: 10
           tcpSocket:
             port: 8080
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding

+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding

@@ -117,13 +117,13 @@

         - name: TZ
           value: null
         - name: UR_L0_ENABLE_RELAXED_ALLOCATION_LIMITS
           value: '1'
         - name: ZES_ENABLE_SYSMAN
           value: '1'
-        image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:431561ee79ee67b3980a02ff47ed9dc19496127643b75671d9789ef693ca57f9
+        image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:4507f4ad728c615e2a09c982c3a4a2ff02abb0f07727710c0e75bb4de951ac5a
         livenessProbe:
           failureThreshold: 3
           initialDelaySeconds: 0
           periodSeconds: 10
           tcpSocket:
             port: 8080

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x branch from 538a544 to 89eab70 Compare June 19, 2026 12:33
@tinfoild

tinfoild Bot commented Jun 19, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/_networking/multus/app Kustomization: flux-system/1-core-1-networking-multus-app HelmRelease: multus/multus

+++ kube/deploy/core/_networking/multus/app Kustomization: flux-system/1-core-1-networking-multus-app HelmRelease: multus/multus

@@ -48,13 +48,13 @@

           app:
             args:
             - --cleanup-config-on-exit
             - --multus-cni-conf-dir=/tmp
             image:
               repository: ghcr.io/k8snetworkplumbingwg/multus-cni
-              tag: v4.2.4@sha256:c3b12d1b56d7607a302ec23ececa236256bc940c04b3be5c1f39e0234398c4c9
+              tag: v4.3.0@sha256:ec4e5dfe12b675e4dcbf4e9cd14892f7b4c8ac27aa0dc93cf2e9be0bdd7d764a
             securityContext:
               allowPrivilegeEscalation: false
               capabilities:
                 add:
                 - NET_ADMIN
                 drop:

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x branch from 89eab70 to ecfd4f4 Compare July 20, 2026 10:12
@ciel-shieru

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

PR #6084: multus-cni v4.2.4 → v4.3.0 (OCI)

Summary

MEDIUM: Multiple CVEs affect the multus-cni package, primarily related to Go dependency vulnerabilities. The old version 4.2.4 is likely affected by these issues that should be addressed in v4.3.0.


Vulnerabilities Found

CVE-2025-22874 | MEDIUM

  • Description: Affects multus-cni-4.0.2 (upstream package). Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disables policy validation.
  • Snyk Reference: SNYK-CHAINGUARDLATEST-MULTUSCNI402-10360823

CVE-2025-22872 | MEDIUM

  • Description: Cross-boundary vulnerability affecting multus-cni. An exploited vulnerability can affect resources beyond the security scope managed by the component's security authority.
  • Snyk Reference: SNYK-CHAINGUARDLATEST-MULTUSCNI402-9788738

CVE-2024-24790 | MEDIUM (Go standard library)


OLD version (v4.2.4) Assessment

v4.2.4 is affected by:


NEW version (v4.3.0) Assessment

The update to v4.3.0 should include:

  • Go toolchain uplift addressing standard library CVEs
  • Updated crypto validation handling
  • Additional security hardening for CNI plugin operations

Additional Security Considerations

  1. Go Uplift: Verify that the new version uses a sufficiently updated Go runtime (≥ 1.22.7 recommended)
  2. CNI Plugin Compatibility: Ensure all container runtimes support the updated multus-cni version
  3. Network Policies: Review network policies after upgrade — CNI changes can affect pod networking

Sources Checked

  • OSV.dev: No direct hits for multus-cni@oci
  • NVD: CVEs found via keyword search (minimal results)
  • GHSA: 0 results from GitHub issue search
  • CISA KEV: No entries found
  • Web Search: Snyk, Chainguard vulnerability listing, and GitHub issues confirmed

@ciel-shieru

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 01:08 UTC
🤖 Scanner: Ciel Security Scanner (fast mode: OSV.dev + NVD + GHSA)
🔗 PR: #6084 — feat(oci/multus-cni): update v4.2.4 ➼ v4.3.0
📦 Package: ghcr.io-k8snetworkplumbingwg-multus-cni (ecosystem: container)
📊 Versions: old=? → new=4.3.0


Severity Summary

Severity Count
CRITICAL 0
HIGH 0
MEDIUM / MODERATE 0
LOW 1
UNKNOWN / NEEDS VERIFICATION 0
Total 1

Results

Package: ghcr.io-k8snetworkplumbingwg-multus-cni

  • Old version: unknown
  • New version: 4.3.0
  • Ecosystem: container

Raw findings (truncated)

=== NEW: 4.3.0 ===
=== OSV.dev query for ghcr.io-k8snetworkplumbingwg-multus-cni@4.3.0 (ecosystem: container) ===
No vulnerabilities found on OSV.dev for ghcr.io-k8snetworkplumbingwg-multus-cni@4.3.0

=== NVD query for 'ghcr.io-k8snetworkplumbingwg-multus-cni' (version filter: 4.3.0) ===
No CVEs found on NVD for keyword: ghcr.io-k8snetworkplumbingwg-multus-cni

=== GHSA query for ghcr.io-k8snetworkplumbingwg-multus-cni (ecosystem: container) ===
{"message":"Invalid request.\n\nInvalid input: `container` is not a possible value. Must be one of the following: rubygems, npm, pip, maven, nuget, composer, go, rust, erlang, actions, pub, other, swift.","documentation_url":"https://docs.github.com/rest/security-advisories/global-advisories#list-global-security-advisories","status":"422"}No GHSA advisories found


Recommendations

  • Review the findings above before merging.
  • Verify version-range applicability of each CVE before treating as actionable.

⚠️ This comment was posted by an automated security scanner (Ciel, fast mode).
To re-scan, trigger the renovate-security-scanner skill.

@tinfoild
tinfoild Bot force-pushed the renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x branch from ecfd4f4 to 6622796 Compare October 4, 2026 08:37
@tinfoild tinfoild Bot changed the title feat(oci/multus-cni): update v4.2.4 ➼ v4.3.0 feat(oci/multus-cni): update v4.2.4 ➼ v4.3.1 Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant