Repository navigation
feat(oci/multus-cni): update v4.2.4 ➼ v4.3.1 - #6084
Open
tinfoild[bot] wants to merge 1 commit into
Open
tinfoild[bot] wants to merge 1 commit into
tinfoild[bot] wants to merge 1 commit into
Conversation
Contributor
Author
kube/helmrelease/out00--- HelmRelease: multus/multus DaemonSet: multus/multus
+++ HelmRelease: multus/multus DaemonSet: multus/multus
@@ -67,13 +67,13 @@
- mountPath: /tmp
name: tmp
containers:
- args:
- --cleanup-config-on-exit
- --multus-cni-conf-dir=/tmp
- image: ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.4@sha256:c3b12d1b56d7607a302ec23ececa236256bc940c04b3be5c1f39e0234398c4c9
+ image: ghcr.io/k8snetworkplumbingwg/multus-cni:v4.3.1@sha256:9dc8ca645a78552ed4151cf67c2998d18f260f172cc541580d8acce2ee3495c2
name: app
securityContext:
allowPrivilegeEscalation: false
capabilities:
add:
- NET_ADMIN
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank
+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-rerank
@@ -120,13 +120,13 @@
- name: TZ
value: null
- name: UR_L0_ENABLE_RELAXED_ALLOCATION_LIMITS
value: '1'
- name: ZES_ENABLE_SYSMAN
value: '1'
- image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:431561ee79ee67b3980a02ff47ed9dc19496127643b75671d9789ef693ca57f9
+ image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:4507f4ad728c615e2a09c982c3a4a2ff02abb0f07727710c0e75bb4de951ac5a
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
port: 8080
--- HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding
+++ HelmRelease: llama-cpp/llama-cpp Deployment: llama-cpp/llama-cpp-embedding
@@ -117,13 +117,13 @@
- name: TZ
value: null
- name: UR_L0_ENABLE_RELAXED_ALLOCATION_LIMITS
value: '1'
- name: ZES_ENABLE_SYSMAN
value: '1'
- image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:431561ee79ee67b3980a02ff47ed9dc19496127643b75671d9789ef693ca57f9
+ image: ghcr.io/ggml-org/llama.cpp:server-vulkan@sha256:4507f4ad728c615e2a09c982c3a4a2ff02abb0f07727710c0e75bb4de951ac5a
livenessProbe:
failureThreshold: 3
initialDelaySeconds: 0
periodSeconds: 10
tcpSocket:
port: 8080 |
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x
branch
from
June 19, 2026 12:33
538a544 to
89eab70
Compare
Contributor
Author
kube/kustomization/out00--- kube/deploy/core/_networking/multus/app Kustomization: flux-system/1-core-1-networking-multus-app HelmRelease: multus/multus
+++ kube/deploy/core/_networking/multus/app Kustomization: flux-system/1-core-1-networking-multus-app HelmRelease: multus/multus
@@ -48,13 +48,13 @@
app:
args:
- --cleanup-config-on-exit
- --multus-cni-conf-dir=/tmp
image:
repository: ghcr.io/k8snetworkplumbingwg/multus-cni
- tag: v4.2.4@sha256:c3b12d1b56d7607a302ec23ececa236256bc940c04b3be5c1f39e0234398c4c9
+ tag: v4.3.0@sha256:ec4e5dfe12b675e4dcbf4e9cd14892f7b4c8ac27aa0dc93cf2e9be0bdd7d764a
securityContext:
allowPrivilegeEscalation: false
capabilities:
add:
- NET_ADMIN
drop: |
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x
branch
from
July 20, 2026 10:12
89eab70 to
ecfd4f4
Compare
Contributor
|
SECURITY VULNERABILITIES FOUND BY CIEL PR #6084: multus-cni v4.2.4 → v4.3.0 (OCI)SummaryMEDIUM: Multiple CVEs affect the multus-cni package, primarily related to Go dependency vulnerabilities. The old version 4.2.4 is likely affected by these issues that should be addressed in v4.3.0. Vulnerabilities FoundCVE-2025-22874 | MEDIUM
CVE-2025-22872 | MEDIUM
CVE-2024-24790 | MEDIUM (Go standard library)
OLD version (v4.2.4) Assessmentv4.2.4 is affected by:
NEW version (v4.3.0) AssessmentThe update to v4.3.0 should include:
Additional Security Considerations
Sources Checked
|
Contributor
|
SECURITY VULNERABILITIES FOUND BY CIEL
Severity Summary
ResultsPackage:
|
tinfoild
Bot
force-pushed
the
renovate/ghcr.io-k8snetworkplumbingwg-multus-cni-4.x
branch
from
October 4, 2026 08:37
ecfd4f4 to
6622796
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.4→v4.3.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
k8snetworkplumbingwg/multus-cni (ghcr.io/k8snetworkplumbingwg/multus-cni)
v4.3.1Compare Source
What's Changed
Full Changelog: k8snetworkplumbingwg/multus-cni@v4.3.0...v4.3.1
v4.3.0Compare Source
What's Changed
New Contributors
Full Changelog: k8snetworkplumbingwg/multus-cni@v4.2.4...v4.3.0
Configuration
📅 Schedule: (in timezone Asia/Singapore)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR has been generated by Mend Renovate.