Skip to content

fix(helm/reloader): update 2.2.9 ➼ 2.2.14 - #5431

Open
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/reloader-2.2.x
Open

fix(helm/reloader): update 2.2.9 ➼ 2.2.14#5431
tinfoild[bot] wants to merge 1 commit into
mainfrom
renovate/reloader-2.2.x

Conversation

@tinfoild

@tinfoild tinfoild Bot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
reloader patch 2.2.92.2.14 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Asia/Singapore)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Apr 13, 2026

Copy link
Copy Markdown

Deploying jjgadgets-biohazard with  Cloudflare Pages  Cloudflare Pages

Latest commit: 362ac67
Status:🚫  Build failed.

View logs

@tinfoild

tinfoild Bot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/reloader/app Kustomization: flux-system/1-core-reloader-app HelmRelease: reloader/reloader

+++ kube/deploy/core/reloader/app Kustomization: flux-system/1-core-reloader-app HelmRelease: reloader/reloader

@@ -12,13 +12,13 @@

     spec:
       chart: reloader
       sourceRef:
         kind: HelmRepository
         name: stakater
         namespace: flux-system
-      version: 2.2.9
+      version: 2.2.14
   driftDetection:
     ignore:
     - paths:
       - /spec/replicas
     mode: warn
   install:

@tinfoild

tinfoild Bot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor Author

kube/kustomization/out00

--- kube/deploy/core/reloader/app Kustomization: flux-system/1-core-reloader-app HelmRelease: reloader/reloader

+++ kube/deploy/core/reloader/app Kustomization: flux-system/1-core-reloader-app HelmRelease: reloader/reloader

@@ -12,13 +12,13 @@

     spec:
       chart: reloader
       sourceRef:
         kind: HelmRepository
         name: stakater
         namespace: flux-system
-      version: 2.2.9
+      version: 2.2.10
   driftDetection:
     ignore:
     - paths:
       - /spec/replicas
     mode: warn
   install:

@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from 39cfcf5 to 97cd3c2 Compare April 15, 2026 11:27
@tinfoild tinfoild Bot changed the title fix(helm/reloader): update 2.2.9 ➼ 2.2.10 fix(helm/reloader): update 2.2.9 ➼ 2.2.11 Apr 15, 2026
@tinfoild

tinfoild Bot commented Apr 15, 2026

Copy link
Copy Markdown
Contributor Author

kube/helmrelease/out00

--- HelmRelease: reloader/reloader Deployment: reloader/reloader

+++ HelmRelease: reloader/reloader Deployment: reloader/reloader

@@ -13,13 +13,13 @@

     heritage: Helm
     app.kubernetes.io/managed-by: Helm
     egress.home.arpa/apiserver: allow
     egress.home.arpa/discord: allow
     group: com.stakater.platform
     provider: stakater
-    version: v1.4.14
+    version: v1.4.19
   name: reloader
   namespace: reloader
 spec:
   replicas: 2
   revisionHistoryLimit: 2
   selector:
@@ -36,13 +36,13 @@

         heritage: Helm
         app.kubernetes.io/managed-by: Helm
         egress.home.arpa/apiserver: allow
         egress.home.arpa/discord: allow
         group: com.stakater.platform
         provider: stakater
-        version: v1.4.14
+        version: v1.4.19
     spec:
       affinity:
         podAntiAffinity:
           preferredDuringSchedulingIgnoredDuringExecution:
           - weight: 100
             podAffinityTerm:
@@ -61,13 +61,13 @@

           matchLabels:
             app.kubernetes.io/name: reloader
         maxSkew: 1
         topologyKey: kubernetes.io/hostname
         whenUnsatisfiable: DoNotSchedule
       containers:
-      - image: ghcr.io/stakater/reloader:v1.4.14
+      - image: ghcr.io/stakater/reloader:v1.4.19
         imagePullPolicy: IfNotPresent
         name: reloader
         env:
         - name: GOMAXPROCS
           valueFrom:
             resourceFieldRef:

@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch 2 times, most recently from 1fc32ef to 536dac8 Compare April 27, 2026 11:43
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from 536dac8 to 3ab45bd Compare May 15, 2026 18:38
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from 3ab45bd to f1af44b Compare May 25, 2026 09:27
@tinfoild tinfoild Bot changed the title fix(helm/reloader): update 2.2.9 ➼ 2.2.11 fix(helm/reloader): update 2.2.9 ➼ 2.2.12 May 25, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from f1af44b to 4a1461e Compare June 8, 2026 20:58
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from 4a1461e to dfa3c6b Compare June 19, 2026 12:30
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from dfa3c6b to 7177149 Compare July 1, 2026 11:10
@tinfoild tinfoild Bot changed the title fix(helm/reloader): update 2.2.9 ➼ 2.2.12 fix(helm/reloader): update 2.2.9 ➼ 2.2.13 Jul 1, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from 7177149 to 6748d82 Compare July 1, 2026 15:05
@tinfoild tinfoild Bot changed the title fix(helm/reloader): update 2.2.9 ➼ 2.2.13 fix(helm/reloader): update 2.2.9 ➼ 2.2.14 Jul 1, 2026
@tinfoild
tinfoild Bot force-pushed the renovate/reloader-2.2.x branch from 6748d82 to 362ac67 Compare July 20, 2026 10:09
@ciel-shieru

ciel-shieru commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

SECURITY VULNERABILITIES FOUND BY CIEL

📅 Scan date: 2026-07-24 03:10 UTC
🤖 Scanner: Ciel Security Scanner
🔗 PR: #5431 — fix(helm/reloader): update 2.2.9 ➼ 2.2.14
📦 Packages checked: 1
🔍 Sources: NVD, OSV.dev, GHSA, GHSL, CISA KEV, FortiGuard, CVE.org, Changelog
⚠️ Vulnerabilities found: 12


Severity Summary

Severity Count
CRITICAL 1
HIGH 4
MEDIUM / MODERATE 7
LOW 0
UNKNOWN / NEEDS VERIFICATION 0
Total 12

Results

Package: reloader (stakater/Reloader)

  • Ecosystem: Go (Helm chart — bundled app image)
  • Old version: chart 2.2.9 / app v1.4.14 / Go 1.26
  • New version: chart 2.2.14 / app v1.4.19 / Go 1.26.4

Vulnerabilities in old version (chart 2.2.9 / app v1.4.14)

The old app image was compiled with Go 1.26 which lacks security fixes from Go 1.26.1 and 1.26.2. These are Go stdlib/compiler CVEs affecting the compiled binary.

  1. CVE-2026-27143 — Severity: CRITICAL (CVSS 9.8)

  2. CVE-2026-27140 — Severity: HIGH (CVSS 8.8)

  3. CVE-2026-33810 — Severity: HIGH (CVSS 8.2)

  4. CVE-2026-32283 — Severity: HIGH (CVSS 7.5)

  5. CVE-2026-27144 — Severity: HIGH (CVSS 7.1)

  6. CVE-2026-32282 — Severity: MEDIUM (CVSS 6.4)

  7. CVE-2026-32289 — Severity: MEDIUM (CVSS 6.1)

  8. CVE-2026-32288 — Severity: MEDIUM (CVSS 5.5)

  9. CVE-2026-32280 — Severity: MEDIUM (CVSS 5.3)

  10. CVE-2026-32281 — Severity: MEDIUM (CVSS 5.3)

+4 more Go 1.26.1 CVEs (CVE-2026-27138, CVE-2026-27137, CVE-2026-27142, CVE-2026-25679) — all fixed in Go 1.26.1+.

Vulnerabilities in new version (chart 2.2.14 / app v1.4.19)

  1. CVE-2026-35469 / GHSA-pc3f-x583-g7j2 — Severity: MEDIUM (CVSS 6.5)

Changelog Security Highlights (chart 2.2.9 → 2.2.14)

  • app v1.4.16 — Go upgrade to 1.26.2 (fixes 10+ Go stdlib/compiler CVEs)
  • app v1.4.19 — go.mod updates & release script fixes; introduced spdystream v0.5.0 (CVE-2026-35469)
  • app v1.4.17 — Harden GitHub Actions workflows against cache poisoning
  • Other releases: feature additions and bug fixes, no security-specific patches

Non-applicable findings (verified and excluded)

Finding Severity Reason
CVE-2024-23656 HIGH (7.5) Dex TLS-reloader issue — false positive from keyword match
CVE-2023-40297 HIGH (7.5) Stakater Forecastle issue — different product
CLEANSTART-2026-PT11267 CRITICAL (9.8) CleanStart build of reloader-fips — not upstream

Recommendations

  • MERGE PRIORITY: CRITICAL — The old app image (v1.4.14 / Go 1.26) has 1 CRITICAL and 4 HIGH-severity CVEs in Go stdlib/compiler, all remediated in the new image (Go 1.26.4).
  • Note: The new version introduces spdystream v0.5.0 (CVE-2026-35469, MEDIUM 6.5 — SPDY frame parser OOM). This is an indirect dependency; upstream fix PR (Update module github.com/moby/spdystream to v0.5.1 [SECURITY] (master) stakater/Reloader#1173) is open. Monitor for v0.5.1+ in a future update.
  • Merge this PR promptly to remediate the CRITICAL/HIGH exposure — the spdystream issue is lower severity and can be addressed in a follow-up.

⚠️ This comment was posted by an automated security scanner (Ciel).
To re-scan, trigger the renovate-security-scanner skill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant