Commit Graph

39616 Commits

Author SHA1 Message Date
TrueCharts Bot
a4900d4595 chore(helm): update image docker.io/tailscale/tailscale v1.78.3 → v1.80.0 (#31657)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/tailscale/tailscale](https://tailscale.com/kb/1282/docker)
([source](https://redirect.github.com/tailscale/tailscale)) | minor |
`9d4c17a` -> `27b6a3d` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>tailscale/tailscale (docker.io/tailscale/tailscale)</summary>

###
[`v1.80.0`](https://redirect.github.com/tailscale/tailscale/releases/tag/v1.80.0)

[Compare
Source](https://redirect.github.com/tailscale/tailscale/compare/v1.78.3...v1.80.0)

Please refer to the changelog available at
[https://tailscale.com/changelog](https://tailscale.com/changelog#2025-01-30).

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2025-02-05 03:18:14 +01:00
TrueCharts Bot
ab376a348a chore(helm): update image docker.io/sonatype/nexus3 3.76.1 → 3.77.0 (#31656)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/sonatype/nexus3 | minor | `390b8ec` -> `9bc9cbb` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2025-02-05 03:17:58 +01:00
TrueCharts Bot
eeb74d8d8e chore(helm): update image docker.io/discordgsm/discord-game-server-monitor 2.17.0 → 2.18.0 (#31655)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/discordgsm/discord-game-server-monitor](https://redirect.github.com/DiscordGSM/GameServerMonitor)
| minor | `8e6a5c9` -> `85cf112` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>DiscordGSM/GameServerMonitor
(docker.io/discordgsm/discord-game-server-monitor)</summary>

###
[`v2.18.0`](https://redirect.github.com/DiscordGSM/GameServerMonitor/releases/tag/2.18.0)

[Compare
Source](https://redirect.github.com/DiscordGSM/GameServerMonitor/compare/2.17.0...2.18.0)

#### What's Changed

- Bump gunicorn from 21.2.0 to 22.0.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/90](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/90)
- Update games.csv by
[@&#8203;xLeviNx](https://redirect.github.com/xLeviNx) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/99](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/99)
- Update Translation Author by
[@&#8203;koimoee](https://redirect.github.com/koimoee) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/96](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/96)
- Set docker image's default command to run main.py by
[@&#8203;Sceptyre](https://redirect.github.com/Sceptyre) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/89](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/89)
- Bump pymongo from 4.6.2 to 4.7.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/97](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/97)
- Bump aiohttp from 3.9.3 to 3.9.5 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/91](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/91)
- Bump flask\[async] from 3.0.2 to 3.0.3 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/86](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/86)
- Update fr.json - spelling correction by
[@&#8203;noxzobax](https://redirect.github.com/noxzobax) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/103](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/103)
- Update games.csv by
[@&#8203;xLeviNx](https://redirect.github.com/xLeviNx) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/105](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/105)
- Update pt-BR.json by
[@&#8203;Mart-User](https://redirect.github.com/Mart-User) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/107](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/107)
- Satisfactory 1.0 update + opengsq by
[@&#8203;The-Padi](https://redirect.github.com/The-Padi) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/119](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/119)
- Update it.json by
[@&#8203;ricardoguimaraes2021](https://redirect.github.com/ricardoguimaraes2021)
in
[https://github.com/DiscordGSM/GameServerMonitor/pull/122](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/122)
- Adding Support for Nadeo Games (like Trackmania Nations Forever) by
[@&#8203;Hornochs](https://redirect.github.com/Hornochs) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/127](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/127)
- Palworld + opengsq Update by
[@&#8203;swesner411](https://redirect.github.com/swesner411) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/131](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/131)
- Adding Python Script to automatically add Servers to DiscordGSM by
[@&#8203;Hornochs](https://redirect.github.com/Hornochs) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/129](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/129)
- Bump docker/build-push-action from 5 to 6 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/101](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/101)
- Bump discord-py from 2.3.2 to 2.4.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/102](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/102)
- Bump pymongo from 4.7.3 to 4.8.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/104](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/104)
- Bump aiohttp from 3.9.5 to 3.11.11 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/133](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/133)
- Requirements Updates and Python 3.13 by
[@&#8203;swesner411](https://redirect.github.com/swesner411) in
[https://github.com/DiscordGSM/GameServerMonitor/pull/132](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/132)

#### New Contributors

- [@&#8203;Sceptyre](https://redirect.github.com/Sceptyre) made their
first contribution in
[https://github.com/DiscordGSM/GameServerMonitor/pull/89](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/89)
- [@&#8203;noxzobax](https://redirect.github.com/noxzobax) made their
first contribution in
[https://github.com/DiscordGSM/GameServerMonitor/pull/103](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/103)
- [@&#8203;Mart-User](https://redirect.github.com/Mart-User) made their
first contribution in
[https://github.com/DiscordGSM/GameServerMonitor/pull/107](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/107)
- [@&#8203;The-Padi](https://redirect.github.com/The-Padi) made their
first contribution in
[https://github.com/DiscordGSM/GameServerMonitor/pull/119](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/119)
- [@&#8203;Hornochs](https://redirect.github.com/Hornochs) made their
first contribution in
[https://github.com/DiscordGSM/GameServerMonitor/pull/127](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/127)
- [@&#8203;swesner411](https://redirect.github.com/swesner411) made
their first contribution in
[https://github.com/DiscordGSM/GameServerMonitor/pull/131](https://redirect.github.com/DiscordGSM/GameServerMonitor/pull/131)

**Full Changelog**:
https://github.com/DiscordGSM/GameServerMonitor/compare/2.17.0...2.18.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2025-02-05 03:17:39 +01:00
TrueCharts Bot
12c63f5c34 fix(website): update astro 5.2.3 → 5.2.5 (#31652)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [astro](https://astro.build)
([source](https://redirect.github.com/withastro/astro/tree/HEAD/packages/astro))
| dependencies | patch | [`5.2.3` ->
`5.2.5`](https://renovatebot.com/diffs/npm/astro/5.2.3/5.2.5) |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>withastro/astro (astro)</summary>

###
[`v5.2.5`](https://redirect.github.com/withastro/astro/blob/HEAD/packages/astro/CHANGELOG.md#525)

[Compare
Source](https://redirect.github.com/withastro/astro/compare/astro@5.2.4...astro@5.2.5)

##### Patch Changes

-
[#&#8203;13133](https://redirect.github.com/withastro/astro/pull/13133)
[`e76aa83`](e76aa8391e)
Thanks [@&#8203;ematipico](https://redirect.github.com/ematipico)! -
Fixes a bug where Astro was failing to build an external redirect when
the middleware was triggered

-
[#&#8203;13119](https://redirect.github.com/withastro/astro/pull/13119)
[`ac43580`](ac4358052a)
Thanks [@&#8203;Hacksore](https://redirect.github.com/Hacksore)! - Adds
extra guidance in the terminal when using the `astro add tailwind` CLI
command

Now, users are given a friendly reminder to import the stylesheet
containing their Tailwind classes into any pages where they want to use
Tailwind. Commonly, this is a shared layout component so that Tailwind
styling can be used on multiple pages.

###
[`v5.2.4`](https://redirect.github.com/withastro/astro/blob/HEAD/packages/astro/CHANGELOG.md#524)

[Compare
Source](https://redirect.github.com/withastro/astro/compare/astro@5.2.3...astro@5.2.4)

##### Patch Changes

-
[#&#8203;13130](https://redirect.github.com/withastro/astro/pull/13130)
[`b71bd10`](b71bd10989)
Thanks [@&#8203;ascorbic](https://redirect.github.com/ascorbic)! - Fixes
a bug that caused duplicate slashes inside query params to be collapsed

-
[#&#8203;13131](https://redirect.github.com/withastro/astro/pull/13131)
[`d60c742`](d60c74243f)
Thanks [@&#8203;ascorbic](https://redirect.github.com/ascorbic)! -
Ignores trailing slashes for endpoints with file extensions in the route

- Updated dependencies
\[[`b71bd10`](b71bd10989)]:
-
[@&#8203;astrojs/internal-helpers](https://redirect.github.com/astrojs/internal-helpers)[@&#8203;0](https://redirect.github.com/0).5.1

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 03:16:54 +01:00
TrueCharts Bot
1ec1f03209 chore(helm): update image docker.io/semaphoreui/semaphore v2.12.3 → v2.12.4 (#31648) 2025-02-05 03:15:46 +01:00
TrueCharts Bot
380bb5f3ea chore(helm): update image docker.io/flowiseai/flowise 2.2.4 → 2.2.5 (#31643) 2025-02-05 03:15:43 +01:00
TrueCharts Bot
39d51346df chore(helm): update image docker.io/n8nio/n8n 1.77.1 → 1.77.2 (#31645) 2025-02-05 03:15:37 +01:00
TrueCharts Bot
06c215439a chore(helm): update image docker.io/cglatot/pasta 1.6.4 → 1.6.6 (#31641) 2025-02-05 03:15:34 +01:00
TrueCharts Bot
a4a5757267 chore(helm): update image ghcr.io/stirling-tools/s-pdf 0.40.1 → 0.40.2 (#31651)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/stirling-tools/s-pdf](https://redirect.github.com/Stirling-Tools/Stirling-PDF)
| patch | `0dd4e05` -> `d44cb8b` |
|
[ghcr.io/stirling-tools/s-pdf](https://redirect.github.com/Stirling-Tools/Stirling-PDF)
| patch | `f802d90` -> `0d30644` |
|
[ghcr.io/stirling-tools/s-pdf](https://redirect.github.com/Stirling-Tools/Stirling-PDF)
| patch | `1a4352b` -> `4f8ac53` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Stirling-Tools/Stirling-PDF
(ghcr.io/stirling-tools/s-pdf)</summary>

###
[`v0.40.2`](https://redirect.github.com/Stirling-Tools/Stirling-PDF/releases/tag/v0.40.2):
0.40.2 Bug fixes for compression and Pipeline

[Compare
Source](https://redirect.github.com/Stirling-Tools/Stirling-PDF/compare/v0.40.1...v0.40.2)

<!-- Release notes generated using configuration in .github/release.yml
at main -->

Lots of bug fixes for

-   UI
- Compression (Thanks
[@&#8203;Abdurrahman-shaikh](https://redirect.github.com/Abdurrahman-shaikh)
for fix)
-   Pipeline (when OCR or HTML is used)
-   And lots of other changes!

##### What's Changed

##### Bug Fixes

- Fix: incorrect `setAttribute` syntax for `tooltip` `data-title` by
[@&#8203;Ludy87](https://redirect.github.com/Ludy87) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2847](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2847)
- Fix issue
[#&#8203;2842](https://redirect.github.com/Stirling-Tools/Stirling-PDF/issues/2842):
Handle qpdf exit code 3 as success with warnings by
[@&#8203;Abdurrahman-shaikh](https://redirect.github.com/Abdurrahman-shaikh)
in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2883](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2883)
- Fix: wrong link `picture_as_pdf` change to `img-to-pdf`
[#&#8203;2867](https://redirect.github.com/Stirling-Tools/Stirling-PDF/issues/2867)
by [@&#8203;Ludy87](https://redirect.github.com/Ludy87) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2869](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2869)
- Fixed firefox compatibility and added missing icons to feature pages
by [@&#8203;reecebrowne](https://redirect.github.com/reecebrowne) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2863](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2863)

##### Enhancements

- Add: Translation Support for `Sort by:` in Home Page by
[@&#8203;Ludy87](https://redirect.github.com/Ludy87) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2850](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2850)
- Add: Configurable UI Language Support with Dynamic Filtering by
[@&#8203;Ludy87](https://redirect.github.com/Ludy87) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2846](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2846)

##### Minor Enhancements

- Update sonarqube.yml and removal of gradle keys by
[@&#8203;Frooodle](https://redirect.github.com/Frooodle) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2866](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2866)
- Pipeline fix for some features missing documentation by
[@&#8203;Frooodle](https://redirect.github.com/Frooodle) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2882](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2882)

##### Docker Updates

- Bump actions/setup-java from 4.6.0 to 4.7.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2855](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2855)
- Bump actions/setup-python from 5.3.0 to 5.4.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2856](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2856)
- Bump gradle/actions from 4.2.2 to 4.3.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2870](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2870)
- removes remnants of verification metadata by
[@&#8203;Ludy87](https://redirect.github.com/Ludy87) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2884](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2884)

##### Translation Changes

- Update messages_it_IT.properties by
[@&#8203;kmau](https://redirect.github.com/kmau) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2852](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2852)
- Update messages_de_DE.properties by
[@&#8203;mjbohn](https://redirect.github.com/mjbohn) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2849](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2849)
- 🌐 Sync Translations + Update README Progress
Table + Update Verification Metadata by
[@&#8203;stirlingbot](https://redirect.github.com/stirlingbot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2860](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2860)
- Update messages_it_IT.properties by
[@&#8203;kmau](https://redirect.github.com/kmau) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2861](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2861)
- Update messages_it_IT.properties by
[@&#8203;albanobattistella](https://redirect.github.com/albanobattistella)
in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2865](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2865)

##### Other Changes

- checks the compatibility of the licenses by
[@&#8203;Ludy87](https://redirect.github.com/Ludy87) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2844](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2844)
- Bump actions/create-github-app-token from 1.11.1 to 1.11.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2853](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2853)
- Bump crazy-max/ghaction-github-labeler from 5.1.0 to 5.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2854](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2854)
- Bump github/codeql-action from 3.28.6 to 3.28.8 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2857](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2857)
- 🌐 Sync Translations + Update README Progress
Table + Update Verification Metadata by
[@&#8203;stirlingbot](https://redirect.github.com/stirlingbot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2859](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2859)
- Create sonarqube.yml by
[@&#8203;Frooodle](https://redirect.github.com/Frooodle) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2862](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2862)
- Update sync_files.yml by
[@&#8203;Frooodle](https://redirect.github.com/Frooodle) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2872](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2872)
- Update screenshots by
[@&#8203;reecebrowne](https://redirect.github.com/reecebrowne) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2875](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2875)
- Update sonarqube.yml to remove depreciated cache feature (will update
later) by [@&#8203;Frooodle](https://redirect.github.com/Frooodle) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2885](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2885)
- Bump org.panteleyev.jpackageplugin from 1.6.0 to 1.6.1 by
[@&#8203;dependabot](https://redirect.github.com/dependabot) in
[https://github.com/Stirling-Tools/Stirling-PDF/pull/2851](https://redirect.github.com/Stirling-Tools/Stirling-PDF/pull/2851)

**Full Changelog**:
https://github.com/Stirling-Tools/Stirling-PDF/compare/v0.40.1...v0.40.2

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 03:15:31 +01:00
TrueCharts Bot
ad8a3d944f chore(helm): update chart kube-prometheus-stack 68.4.4 → 68.4.5 (#31640)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[kube-prometheus-stack](https://redirect.github.com/prometheus-operator/kube-prometheus)
([source](https://redirect.github.com/prometheus-community/helm-charts))
| patch | `68.4.4` -> `68.4.5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>prometheus-community/helm-charts
(kube-prometheus-stack)</summary>

###
[`v68.4.5`](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-68.4.4...kube-prometheus-stack-68.4.5)

[Compare
Source](https://redirect.github.com/prometheus-community/helm-charts/compare/kube-prometheus-stack-68.4.4...kube-prometheus-stack-68.4.5)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJyZW5vdmF0ZS9oZWxtIiwidHlwZS9wYXRjaCJdfQ==-->
2025-02-05 02:15:24 +00:00
TrueCharts Bot
1463e8b7d3 chore(helm): update image ghcr.io/elfhosted/jackett 0.22.1363 → 0.22.1368 (#31650) 2025-02-05 03:15:18 +01:00
TrueCharts Bot
7c1efcb0d8 chore(helm): update image docker.io/vaultwarden/server 1.33.0 → 1.33.1 (#31649) 2025-02-05 03:15:11 +01:00
TrueCharts Bot
412c1da84c chore(helm): update image docker.io/nocodb/nocodb 0.260.2 → 0.260.4 (#31647)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/nocodb/nocodb | patch | `143abde` -> `5b16976` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 03:15:04 +01:00
TrueCharts Bot
54ff6a3513 chore(helm): update image docker.io/grafana/grafana 11.5.0 → 11.5.1 (#31644)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/grafana/grafana | patch | `0a2874c` -> `5781759` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 03:14:33 +01:00
TrueCharts Bot
3ece43b8e8 chore(helm): update image docker.io/clickhouse/clickhouse-server 25.1.2.3 → 25.1.3.23 (#31642)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/clickhouse/clickhouse-server | patch | `82659b1` ->
`e9908bc` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 03:14:18 +01:00
TrueCharts Bot
fdb7bfa0ce chore(helm): update image docker.io/netdata/netdata v2.2.3 → v2.2.4 (#31646)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/netdata/netdata](https://netdata.cloud)
([source](https://redirect.github.com/netdata/netdata)) | patch |
`c8d12ad` -> `1a72322` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>netdata/netdata (docker.io/netdata/netdata)</summary>

###
[`v2.2.4`](https://redirect.github.com/netdata/netdata/blob/HEAD/CHANGELOG.md#v224-2025-02-04)

[Compare
Source](https://redirect.github.com/netdata/netdata/compare/v2.2.3...v2.2.4)

[Full
Changelog](https://redirect.github.com/netdata/netdata/compare/v2.2.3...v2.2.4)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 03:13:59 +01:00
TrueCharts Bot
69b6d8f8f0 chore(helm): update webtop (#31637)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| lscr.io/linuxserver/webtop | digest | `79e27a2` -> `b2d6f6f` |
| lscr.io/linuxserver/webtop | digest | `c0c6479` -> `57c7ace` |
| lscr.io/linuxserver/webtop | digest | `2a4497c` -> `49dd94d` |
| lscr.io/linuxserver/webtop | digest | `15c1234` -> `92e91e9` |
| lscr.io/linuxserver/webtop | digest | `3468863` -> `e757b60` |
| lscr.io/linuxserver/webtop | digest | `a64c0f0` -> `1862166` |
| lscr.io/linuxserver/webtop | digest | `76a6860` -> `ac2579a` |
| lscr.io/linuxserver/webtop | digest | `15a752a` -> `3ea4591` |
| lscr.io/linuxserver/webtop | digest | `d8b4420` -> `d4c8bd5` |
| lscr.io/linuxserver/webtop | digest | `b8e8ea3` -> `8feff49` |
| lscr.io/linuxserver/webtop | digest | `e1a1c5c` -> `6af36bd` |
| lscr.io/linuxserver/webtop | digest | `940c4f4` -> `6d2b302` |
| lscr.io/linuxserver/webtop | digest | `cf606bd` -> `0012ee7` |
| lscr.io/linuxserver/webtop | digest | `b62235e` -> `e867a0f` |
| lscr.io/linuxserver/webtop | digest | `98468eb` -> `c4df281` |
| lscr.io/linuxserver/webtop | digest | `8fc1f36` -> `d7a360c` |
| lscr.io/linuxserver/webtop | digest | `249b276` -> `abd2618` |
| lscr.io/linuxserver/webtop | digest | `ef4d9b0` -> `5f7efec` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:10:09 +01:00
TrueCharts Bot
f5d2441582 chore(flux): update helm release cilium 1.16.6 → 1.17.0 (clustertool) (#31654)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cilium](https://cilium.io/)
([source](https://redirect.github.com/cilium/cilium)) | minor | `1.16.6`
-> `1.17.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cilium/cilium (cilium)</summary>

###
[`v1.17.0`](https://redirect.github.com/cilium/cilium/releases/tag/v1.17.0):
1.17.0

[Compare
Source](https://redirect.github.com/cilium/cilium/compare/1.16.6...1.17.0)

We are excited to announce the **Cilium** **1.17.0** release!

A total of 2761 new commits have been contributed to this release by a
growing community of over 880 developers and over 20,800 GitHub stars!
🤩

To keep up to date with all the latest Cilium releases, see
[Announcements](https://redirect.github.com/cilium/cilium/discussions/categories/announcements)

Here's what's new in v1.17.0:

🚠 **Networking**

- 🚦 **Quality of Service:** Annotate your Pods
for Guaranteed, Burstable or BestEffort egress network traffic priority
([#&#8203;36025](https://redirect.github.com/cilium/cilium/issues/36025),
[@&#8203;hemanthmalla](https://redirect.github.com/hemanthmalla))
- 🌐 **Multi-Cluster Service API:** Use Kubernetes
MCS to manage global services in a Cilium Cluster Mesh
([#&#8203;34439](https://redirect.github.com/cilium/cilium/issues/34439),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- 🔀 **Load Balance based on L4 Protocol:**
Differentiate TCP and UDP based protocols for load balancing, so
multiple services on the same port can be directed to different backends
([#&#8203;33434](https://redirect.github.com/cilium/cilium/issues/33434),
[@&#8203;jibi](https://redirect.github.com/jibi))
- 🧲 **Per-Service LB Algorithms:** Choose maglev or random load
balancing algorithms for individual services
([#&#8203;35735](https://redirect.github.com/cilium/cilium/issues/35735),
[@&#8203;kl52752](https://redirect.github.com/kl52752))
-  **Deny lists for Service source ranges:** Control whether
Kubernetes loadBalancerSourceRanges are treated as an allow or deny list
([#&#8203;36120](https://redirect.github.com/cilium/cilium/issues/36120),
[@&#8203;borkmann](https://redirect.github.com/borkmann))
- 🏊 **Better control over IPAM:** IPs can be allocated
statically using AWS tags, and multi-pool can support single IP ranges
for pools
([#&#8203;34622](https://redirect.github.com/cilium/cilium/issues/34622),
[@&#8203;antonipp](https://redirect.github.com/antonipp);
[#&#8203;34618](https://redirect.github.com/cilium/cilium/issues/34618),
[@&#8203;juliusmh](https://redirect.github.com/juliusmh))
- 🔌 **Dynamic MTU detection:** Cilium respects changes
made to MTU made at runtime without requiring agent restart
([#&#8203;34314](https://redirect.github.com/cilium/cilium/issues/34314),
[@&#8203;dylandreimerink](https://redirect.github.com/dylandreimerink))

💂‍♀️ **Security**

- 🚀 **Improved network policy performance:** The cost of
computing complex combinations of network policies has been reduced
(Various PRs by [@&#8203;joamaki](https://redirect.github.com/joamaki),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme),
[@&#8203;marseel](https://redirect.github.com/marseel),
[@&#8203;nathanjsweet](https://redirect.github.com/nathanjsweet),
[@&#8203;squeed](https://redirect.github.com/squeed) and
[@&#8203;youngnick](https://redirect.github.com/youngnick))
- 🗂️ **Prioritize critical network policies:** Cilium
respects Kubernetes priorityNamespaces to prioritize endpoint
propagation for critical namespaces when using CiliumEndpointSlices
([#&#8203;34199](https://redirect.github.com/cilium/cilium/issues/34199),
[@&#8203;Kaczyniec](https://redirect.github.com/Kaczyniec))
- 📋 **Validate Network Policies:** Receive better feedback
from Kubernetes when creating network policies
([#&#8203;34585](https://redirect.github.com/cilium/cilium/issues/34585),
[@&#8203;squeed](https://redirect.github.com/squeed);
[#&#8203;35904](https://redirect.github.com/cilium/cilium/issues/35904),
[@&#8203;renyunkang](https://redirect.github.com/renyunkang);
[#&#8203;36598](https://redirect.github.com/cilium/cilium/issues/36598),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- 🏷️ **Select CIDRGroups by Label:** Add labels to CIDRGroups and
use these for network policy selection
([#&#8203;36087](https://redirect.github.com/cilium/cilium/issues/36087),
[@&#8203;squeed](https://redirect.github.com/squeed))
- 🛎️ **Extend ToServices for in-cluster services:** Services
with a selector can be selected with ToServices network policies
statements
([#&#8203;34208](https://redirect.github.com/cilium/cilium/issues/34208),
[@&#8203;chaunceyjiang](https://redirect.github.com/chaunceyjiang))
- 🚧 **FQDN Filtering for hostNetwork:** Use
CiliumClusterwideNetworkPolicy to configure Layer 7 filtering for DNS
requests on nodes in the cluster
([#&#8203;34024](https://redirect.github.com/cilium/cilium/issues/34024),
[@&#8203;atykhyy](https://redirect.github.com/atykhyy))
- 📶 **HTTP policies on port ranges:** Redirect multiple
ports in a single policy towards Envoy for Layer 7 filtering of HTTP
traffic
([#&#8203;36056](https://redirect.github.com/cilium/cilium/issues/36056),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))

🕸️ **Service Mesh & Gateway API**

- ⛩️ **Gateway API 1.2.1:** Add support for the latest
Gateway API v1.2.1 release, including HTTP retries and mirror fractions
([#&#8203;34720](https://redirect.github.com/cilium/cilium/issues/34720),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- 📝 **Static Gateway Addressing:** Cilium now supports statically
specifying addresses for gateways
([#&#8203;33042](https://redirect.github.com/cilium/cilium/issues/33042),
[@&#8203;chaunceyjiang](https://redirect.github.com/chaunceyjiang))
- 🔐 **Improved Envoy TLS handling:** Use SDS for
managing TLS visibility secrets in Envoy, improving policy calculation
speed and secrets access
([#&#8203;35513](https://redirect.github.com/cilium/cilium/issues/35513),
[@&#8203;youngnick](https://redirect.github.com/youngnick))

🛰️ **Observability**

- 🔍 **Dynamic Hubble Metrics:** Configure Hubble metrics with a new
hubble-metrics-config ConfigMap to tune your network observability
([#&#8203;35185](https://redirect.github.com/cilium/cilium/issues/35185),
[@&#8203;rectified95](https://redirect.github.com/rectified95))
- 🛤️ **Track enabled features using Prometheus:** The
cilium-agent and cilium-operator components expose Prometheus metrics
for which features are enabled.
([#&#8203;35852](https://redirect.github.com/cilium/cilium/issues/35852),
[@&#8203;aanm](https://redirect.github.com/aanm))
- 📊 **Many new metrics:** Improved metrics related to BGP,
network connections, network policy, pod management, and Cilium
component status (Various PRs by
[@&#8203;AwesomePatrol](https://redirect.github.com/AwesomePatrol),
[@&#8203;harsimran-pabla](https://redirect.github.com/harsimran-pabla),
[@&#8203;joestringer](https://redirect.github.com/joestringer),
[@&#8203;jshr-w](https://redirect.github.com/jshr-w),
[@&#8203;mikejoh](https://redirect.github.com/mikejoh),
[@&#8203;nimishamehta5](https://redirect.github.com/nimishamehta5),
[@&#8203;odinuge](https://redirect.github.com/odinuge),
[@&#8203;ovidiutirla](https://redirect.github.com/ovidiutirla),
[@&#8203;rectified95](https://redirect.github.com/rectified95) and
[@&#8203;sjdot](https://redirect.github.com/sjdot))

🌅  **Scale**

- 📈 **Better cluster connectivity checking:**
The cilium-health component for cluster-wide network connectivity health
detection is better tuned for reliable health checking at high scale
([#&#8203;35163](https://redirect.github.com/cilium/cilium/issues/35163),
[@&#8203;jshr-w](https://redirect.github.com/jshr-w))
-  **Rate-limit monitor events:** Balance the
number of eBPF events against the CPU usage required to process them
([#&#8203;29711](https://redirect.github.com/cilium/cilium/issues/29711),
[@&#8203;siwiutki](https://redirect.github.com/siwiutki))
- 👥 **Double-Write Identity mode:** New allocation
mode for Security Identities to ease migration between CRD and KVStore
identity backends
([#&#8203;31920](https://redirect.github.com/cilium/cilium/issues/31920),
[@&#8203;antonipp](https://redirect.github.com/antonipp))
- ⚖️ **Better scale testing:** This release benefits from
regular automated scale testing for network policy
([#&#8203;35278](https://redirect.github.com/cilium/cilium/issues/35278),
[@&#8203;marseel](https://redirect.github.com/marseel))

🏘️ **Community**

- ❤️ Many end-users have stepped forward to tell their stories
running Cilium in production. If your company wants to submit their case
studies let us know. We would love to hear your feedback!
- [Seznam](https://www.cncf.io/case-studies/seznam/), [Alibaba
Cloud](https://www.cncf.io/case-studies/alibaba/),
[SysEleven](https://www.cncf.io/case-studies/syseleven/),
[QingCloud](https://www.cncf.io/case-studies/qingcloud/),
[ECCO](https://www.youtube.com/watch?v=Ennjmo9TFaM),
[Reddit](https://www.youtube.com/watch?v=YNDp7Id7Bbs),
[Confluent](https://www.youtube.com/watch?v=vOSiVeBXYpM),
[SamsungAds](https://www.youtube.com/watch?v=2KlVTx611bk), and
[Sony](https://www.youtube.com/watch?v=M0PincxlHpI)
- The [Cilium Annual Report
2024](https://redirect.github.com/cilium/cilium.io/blob/main/Annual-Reports/Cilium_Annual_Report\_2024.pdf)
was released covering all the highlights from across the community and
marking the “Year of Kubernetes Networking”
- The community gathered at [Cilium + eBPF
Day](https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/co-located-events/cilium-ebpf-day/)
and the [Cilium Developer
Summit](https://redirect.github.com/cilium/dev-summits/tree/main/2024-NA)
in Salt Lake City
- Meet us at the upcoming
[CiliumCon](https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/co-located-events/ciliumcon/)
and the [Cilium Developer
Summit](https://docs.google.com/forms/d/e/1FAIpQLSd8E1dtCYiwqcw1MemQU3RDKlIQNBi2dRVMVGqDPgSow9mKjA/viewform?usp=header)
in London

And finally, we would like to thank you to all contributors of Cilium
that helped directly and indirectly with the project. The success of
Cilium could not happen without all of you. ❤️ ❤️ ❤️

## Other changes

**Bugfixes:**

- Addresses attached to dummy devices aren't ignored from node addresses
even if the device is down, unblocking usage of host network
nodelocaldns with eBPF host routing.
([#&#8203;34228](https://redirect.github.com/cilium/cilium/issues/34228),
[@&#8203;hemanthmalla](https://redirect.github.com/hemanthmalla))
- agent: defend against null pointer refs in cecManager.getEndpoint()
(Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37188](https://redirect.github.com/cilium/cilium/issues/37188),
[@&#8203;aetimmes](https://redirect.github.com/aetimmes))
- Allow cilium agent to start on linux kernels that don't have
CONFIG_XFRM. (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37123](https://redirect.github.com/cilium/cilium/issues/37123),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- bgpv2: Do not fail if PeerAddress is not configured for a peer
([#&#8203;36488](https://redirect.github.com/cilium/cilium/issues/36488),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- bpf-tproxy: don't look for local 'established' UDP sockets
([#&#8203;34591](https://redirect.github.com/cilium/cilium/issues/34591),
[@&#8203;atykhyy](https://redirect.github.com/atykhyy))
- bpf:nat: restore a NAT entry if its REV NAT is not found
([#&#8203;35304](https://redirect.github.com/cilium/cilium/issues/35304),
[@&#8203;sugangli](https://redirect.github.com/sugangli))
- bugfix: fixed extravolumes mount in cilium-preflight
([#&#8203;35386](https://redirect.github.com/cilium/cilium/issues/35386),
[@&#8203;tokarev-artem](https://redirect.github.com/tokarev-artem))
- Cilium no longer fails compiling bpf programs if listing network links
is interrupted.
([#&#8203;35259](https://redirect.github.com/cilium/cilium/issues/35259),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))
- cilium-cli/connectivity: fix nil-pointer dereference if minimum
version can't be detected
([#&#8203;35802](https://redirect.github.com/cilium/cilium/issues/35802),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- cilium-dbg: fix status commands for cluster connectivity health
([#&#8203;33972](https://redirect.github.com/cilium/cilium/issues/33972),
[@&#8203;darox](https://redirect.github.com/darox))
- cli: fix a case when connectivity perf command was hanging if LRP was
enabled in the cluster
([#&#8203;35063](https://redirect.github.com/cilium/cilium/issues/35063),
[@&#8203;marseel](https://redirect.github.com/marseel))
- clustermesh: fix MCS-API service export cache not properly deleted
(Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36892](https://redirect.github.com/cilium/cilium/issues/36892),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- clustermesh: add support for targetPort in MCS-API (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36875](https://redirect.github.com/cilium/cilium/issues/36875),
[@&#8203;MrFreezeex](https://redirect.github.com/MrFreezeex))
- Correctly format `cilium status -o json` CLI output for errors and
warnings
([#&#8203;34654](https://redirect.github.com/cilium/cilium/issues/34654),
[@&#8203;nimishamehta5](https://redirect.github.com/nimishamehta5))
- Datasource error fixed for Cilium Operator dashboard
([#&#8203;35420](https://redirect.github.com/cilium/cilium/issues/35420),
[@&#8203;VergeDX](https://redirect.github.com/VergeDX))
- Do not leak ipcache entries when apiserver entities are cluster
external
([#&#8203;35868](https://redirect.github.com/cilium/cilium/issues/35868),
[@&#8203;hemanthmalla](https://redirect.github.com/hemanthmalla))
- endpoint: Skip incremental updates on an endpoint without policy map
(Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37312](https://redirect.github.com/cilium/cilium/issues/37312),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))
- envoy: add configurable access log buffer size (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36823](https://redirect.github.com/cilium/cilium/issues/36823),
[@&#8203;aetimmes](https://redirect.github.com/aetimmes))
- envoy: Configure internal address config based on IP family (Backport
PR
[#&#8203;36781](https://redirect.github.com/cilium/cilium/issues/36781),
Upstream PR
[#&#8203;36733](https://redirect.github.com/cilium/cilium/issues/36733),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- Export Map{Key,Value} fields to prevent `map {get,list}` handler
panics.
([#&#8203;36219](https://redirect.github.com/cilium/cilium/issues/36219),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- Fix a bug that prevents a pod from accessing Nodeport services when
the pod is also in scope of a broad-range Egress Gateway policy.
(Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36929](https://redirect.github.com/cilium/cilium/issues/36929),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- Fix bug causing the endpoint regeneration failure handler to be
effective only once (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37085](https://redirect.github.com/cilium/cilium/issues/37085),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- Fix bug potentially causing newly added endpoints to remain stuck in
waiting-to-regenerate state forever, causing traffic from/to that
endpoint to be incorrectly dropped. (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;37086](https://redirect.github.com/cilium/cilium/issues/37086),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- Fix bug that would break all pod-to-pod connectivity when using the
per-tunnel IPsec key system.
([#&#8203;35806](https://redirect.github.com/cilium/cilium/issues/35806),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- Fix clustermesh endpointslice synchronization connectivity test
([#&#8203;34455](https://redirect.github.com/cilium/cilium/issues/34455),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- fix concurrency issue related with allocator cache (Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37328](https://redirect.github.com/cilium/cilium/issues/37328),
[@&#8203;aanm](https://redirect.github.com/aanm))
- Fix configuration of proxy-max-concurrent-retries (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37061](https://redirect.github.com/cilium/cilium/issues/37061),
[@&#8203;joestringer](https://redirect.github.com/joestringer))
- Fix error in Cilium-cli that caused the encryption status per-node
command to retrieve only the status of the 1st node.
([#&#8203;34637](https://redirect.github.com/cilium/cilium/issues/34637),
[@&#8203;smagnani96](https://redirect.github.com/smagnani96))
- Fix Hubble exporter config uses wrong separator
([#&#8203;34621](https://redirect.github.com/cilium/cilium/issues/34621),
[@&#8203;chaunceyjiang](https://redirect.github.com/chaunceyjiang))
- Fix incorrect deletion of revNAT entries due to service ID conflict
([#&#8203;34552](https://redirect.github.com/cilium/cilium/issues/34552),
[@&#8203;haozhangami](https://redirect.github.com/haozhangami))
- Fix incorrect trace reason for egress packets when WireGuard is used
with Host Firewall.
([#&#8203;35354](https://redirect.github.com/cilium/cilium/issues/35354),
[@&#8203;smagnani96](https://redirect.github.com/smagnani96))
- Fix memory leak caused by service events when when CNPs/CCNPs are
disabled (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36727](https://redirect.github.com/cilium/cilium/issues/36727),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- Fix missing Helm chart version for status command
([#&#8203;34748](https://redirect.github.com/cilium/cilium/issues/34748),
[@&#8203;pgils](https://redirect.github.com/pgils))
- Fix race condition on cilium_ratelimit map
([#&#8203;34554](https://redirect.github.com/cilium/cilium/issues/34554),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- Fix runtime panic with L2announcer name generation
([#&#8203;35031](https://redirect.github.com/cilium/cilium/issues/35031),
[@&#8203;YutaroHayakawa](https://redirect.github.com/YutaroHayakawa))
- Fix services could not be removed in sync-lb-maps-with-k8s-services
controller
([#&#8203;33885](https://redirect.github.com/cilium/cilium/issues/33885),
[@&#8203;haozhangami](https://redirect.github.com/haozhangami))
- fix(clustermesh): mesh connection mode
([#&#8203;34932](https://redirect.github.com/cilium/cilium/issues/34932),
[@&#8203;littlejo](https://redirect.github.com/littlejo))
- Fix: cilium-cli install --repository flag respects repository even
with cached versions.
([#&#8203;35670](https://redirect.github.com/cilium/cilium/issues/35670),
[@&#8203;renyunkang](https://redirect.github.com/renyunkang))
- fix: Hubble metrics not deleted for deleted pods (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36819](https://redirect.github.com/cilium/cilium/issues/36819),
[@&#8203;rectified95](https://redirect.github.com/rectified95))
- Fixed Cilium CLI fatal error: concurrent map read and map write
([#&#8203;35311](https://redirect.github.com/cilium/cilium/issues/35311),
[@&#8203;chaunceyjiang](https://redirect.github.com/chaunceyjiang))
- Fixes a bug where identities may be leaked if a pod changes labels and
is immediately deleted.
([#&#8203;35947](https://redirect.github.com/cilium/cilium/issues/35947),
[@&#8203;orange30](https://redirect.github.com/orange30))
- Fixes a type error that occurred when enabling the Grafana dashboards
in the Helm chart. (Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;36939](https://redirect.github.com/cilium/cilium/issues/36939),
[@&#8203;nicl-dev](https://redirect.github.com/nicl-dev))
- Fixes BPF Masquerading exclusion CIDR for IPAM modes "eni", "azure"
and "alibabacloud".
([#&#8203;35624](https://redirect.github.com/cilium/cilium/issues/35624),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- gateway-api: Add service observable event handler
([#&#8203;33352](https://redirect.github.com/cilium/cilium/issues/33352),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- helm: Render valid image specs when tag is empty
([#&#8203;34891](https://redirect.github.com/cilium/cilium/issues/34891),
[@&#8203;BenoitKnecht](https://redirect.github.com/BenoitKnecht))
- hubble: fix metrics configuration parsing (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36371](https://redirect.github.com/cilium/cilium/issues/36371),
[@&#8203;kaworu](https://redirect.github.com/kaworu))
- ipam: Avoid empty CIDR in ENI mode
([#&#8203;35695](https://redirect.github.com/cilium/cilium/issues/35695),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- k8s: Avoid panic while checking ip mode
([#&#8203;35782](https://redirect.github.com/cilium/cilium/issues/35782),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- l4lb: fix inability to properly update service after agent restart
([#&#8203;34077](https://redirect.github.com/cilium/cilium/issues/34077),
[@&#8203;oblazek](https://redirect.github.com/oblazek))
- Make initial nat gc async during Daemon initialization.
([#&#8203;34070](https://redirect.github.com/cilium/cilium/issues/34070),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- Make LB-IPAM allow IP sharing between services with the same ports but
different protocols
([#&#8203;34691](https://redirect.github.com/cilium/cilium/issues/34691),
[@&#8203;ldlb9527](https://redirect.github.com/ldlb9527))
- maps/nat/stats: Use Start context when waiting for maps (Backport PR
[#&#8203;37277](https://redirect.github.com/cilium/cilium/issues/37277),
Upstream PR
[#&#8203;37262](https://redirect.github.com/cilium/cilium/issues/37262),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- Metrics: Fix the reporting of bootstrap metric "overall" scope as it
was not capturing a part of initialization
([#&#8203;34971](https://redirect.github.com/cilium/cilium/issues/34971),
[@&#8203;marseel](https://redirect.github.com/marseel))
- nodeinit: move kubelet restart inside if/else in startup.bash
(Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37282](https://redirect.github.com/cilium/cilium/issues/37282),
[@&#8203;ayuspin](https://redirect.github.com/ayuspin))
- operator: don't reconcile non-GAMMA xRoutes without a Cilium-managed
Gateway (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;35718](https://redirect.github.com/cilium/cilium/issues/35718),
[@&#8203;aetimmes](https://redirect.github.com/aetimmes))
- Policy rule labels are tracked more accurately in endpoint policy
maps.
([#&#8203;34437](https://redirect.github.com/cilium/cilium/issues/34437),
[@&#8203;jrajahalme](https://redirect.github.com/jrajahalme))
- Remove "\_count" suffix from doublewrite metrics (Backport PR
[#&#8203;37277](https://redirect.github.com/cilium/cilium/issues/37277),
Upstream PR
[#&#8203;36585](https://redirect.github.com/cilium/cilium/issues/36585),
[@&#8203;antonipp](https://redirect.github.com/antonipp))
- Reopened connections are now correctly counted towards opened in
Active Connection Tracking
([#&#8203;34082](https://redirect.github.com/cilium/cilium/issues/34082),
[@&#8203;AwesomePatrol](https://redirect.github.com/AwesomePatrol))
- sysctlfix: close systemd config file before triggering reload
([#&#8203;36368](https://redirect.github.com/cilium/cilium/issues/36368),
[@&#8203;dylandreimerink](https://redirect.github.com/dylandreimerink))
- The cilium dnsproxy now handles EDNS0 large buffersize advertisements
better.
([#&#8203;34852](https://redirect.github.com/cilium/cilium/issues/34852),
[@&#8203;bimmlerd](https://redirect.github.com/bimmlerd))

**CI Changes:**

- .github/workflows: Enable DualStack for
conformance-kind-proxy-embedded
([#&#8203;36398](https://redirect.github.com/cilium/cilium/issues/36398),
[@&#8203;dylandreimerink](https://redirect.github.com/dylandreimerink))
- .github/workflows: fix ci image cache cleaner
([#&#8203;34819](https://redirect.github.com/cilium/cilium/issues/34819),
[@&#8203;aanm](https://redirect.github.com/aanm))
- .github: Add disk-cleanup GHA to ipsec upgrade tests
([#&#8203;34321](https://redirect.github.com/cilium/cilium/issues/34321),
[@&#8203;chancez](https://redirect.github.com/chancez))
- .github: add missing export in variable
([#&#8203;34818](https://redirect.github.com/cilium/cilium/issues/34818),
[@&#8203;aanm](https://redirect.github.com/aanm))
- .github: Clean up cilium-cli action usages
([#&#8203;33573](https://redirect.github.com/cilium/cilium/issues/33573),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- .github: extend timeout for tests-e2e-upgrade workflow
([#&#8203;35696](https://redirect.github.com/cilium/cilium/issues/35696),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- .github: prevent failure when deleting GitHub Actions cache
([#&#8203;34844](https://redirect.github.com/cilium/cilium/issues/34844),
[@&#8203;aanm](https://redirect.github.com/aanm))
- .github: quote arguments in bash string comparison
([#&#8203;35842](https://redirect.github.com/cilium/cilium/issues/35842),
[@&#8203;devodev](https://redirect.github.com/devodev))
- .github: remove CI tests from PR runs if not required
([#&#8203;34726](https://redirect.github.com/cilium/cilium/issues/34726),
[@&#8203;aanm](https://redirect.github.com/aanm))
- .github: remove use of deprecated --disable-check cilium-cli option
([#&#8203;35776](https://redirect.github.com/cilium/cilium/issues/35776),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- .github: Set --interactive=false for cilium status (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37151](https://redirect.github.com/cilium/cilium/issues/37151),
[@&#8203;joestringer](https://redirect.github.com/joestringer))
- .github: Use --input-file when testing piping flows into Hubble CLI
([#&#8203;35858](https://redirect.github.com/cilium/cilium/issues/35858),
[@&#8203;chancez](https://redirect.github.com/chancez))
- .github: Use github ref for git push, not quay ref
([#&#8203;34392](https://redirect.github.com/cilium/cilium/issues/34392),
[@&#8203;joestringer](https://redirect.github.com/joestringer))
- \[v1.17] gh: replace kernel development trees with 6.12 kernel
([#&#8203;36841](https://redirect.github.com/cilium/cilium/issues/36841),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- \[v1.17] gha: use /test to trigger tests in stable branches
([#&#8203;36690](https://redirect.github.com/cilium/cilium/issues/36690),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- Add an empty Dockerfile for cilium-cli
([#&#8203;34370](https://redirect.github.com/cilium/cilium/issues/34370),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- Add concurrency to e2e-upgrade tests
([#&#8203;34806](https://redirect.github.com/cilium/cilium/issues/34806),
[@&#8203;aanm](https://redirect.github.com/aanm))
- Add concurrency to test-ipsec-upgrade
([#&#8203;35362](https://redirect.github.com/cilium/cilium/issues/35362),
[@&#8203;aanm](https://redirect.github.com/aanm))
- Add Hubble CLI integration tests and skip running e2e/conformance on
Hubble CLI only changes
([#&#8203;33850](https://redirect.github.com/cilium/cilium/issues/33850),
[@&#8203;chancez](https://redirect.github.com/chancez))
- Allow Renovate to bump to golang v1.22
([#&#8203;33820](https://redirect.github.com/cilium/cilium/issues/33820),
[@&#8203;ferozsalam](https://redirect.github.com/ferozsalam))
- ariane: don't run full test suite for BPF test changes
([#&#8203;34931](https://redirect.github.com/cilium/cilium/issues/34931),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- ariane: don't run tests for renovate config changes
([#&#8203;36543](https://redirect.github.com/cilium/cilium/issues/36543),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- ariane: manage workflow exclusions for changes to CODEOWNERS and
USERS.md
([#&#8203;34894](https://redirect.github.com/cilium/cilium/issues/34894),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- Ariane: skip E2E tests when changing unit tests only
([#&#8203;35334](https://redirect.github.com/cilium/cilium/issues/35334),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- bpf/tests: test ipv6 udp packets when redirecting from l3 to l2
([#&#8203;36536](https://redirect.github.com/cilium/cilium/issues/36536),
[@&#8203;rgo3](https://redirect.github.com/rgo3))
- bpf: complexity-tests: add HAVE_SET_RETVAL and HAVE_NETNS_COOKIE for
bpf_sock tests
([#&#8203;35291](https://redirect.github.com/cilium/cilium/issues/35291),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- Bugfix: fix cluster name in 100 nodes scale test
([#&#8203;33973](https://redirect.github.com/cilium/cilium/issues/33973),
[@&#8203;thorn3r](https://redirect.github.com/thorn3r))
- CFP-25694: Move cilium/cilium-cli code into cilium/cilium repository
([#&#8203;34178](https://redirect.github.com/cilium/cilium/issues/34178),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- chore(dep): Bump gateway api to the lastest version
([#&#8203;34505](https://redirect.github.com/cilium/cilium/issues/34505),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- ci-clustermesh-upgrade: Increment timeout between rollouts to 10min
([#&#8203;34638](https://redirect.github.com/cilium/cilium/issues/34638),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- ci-e2e-upgrade: Cover wireguard + geneve tunnel (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37163](https://redirect.github.com/cilium/cilium/issues/37163),
[@&#8203;jschwinger233](https://redirect.github.com/jschwinger233))
- CI-Runtime: Allow passing extra cilium options.
([#&#8203;34478](https://redirect.github.com/cilium/cilium/issues/34478),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- ci/ipsec: Cilium agents in ci-ipsec-e2e no longer share host's boot ID
([#&#8203;35951](https://redirect.github.com/cilium/cilium/issues/35951),
[@&#8203;jschwinger233](https://redirect.github.com/jschwinger233))
- ci: 100 node scale - alert on bootstrap/cpu/memory regressions
([#&#8203;34897](https://redirect.github.com/cilium/cilium/issues/34897),
[@&#8203;marseel](https://redirect.github.com/marseel))
- CI: Add channel arguments to GKE related workflows
([#&#8203;35522](https://redirect.github.com/cilium/cilium/issues/35522),
[@&#8203;brlbil](https://redirect.github.com/brlbil))
- ci: add leak detection to conformance-ipsec-upgrade (Backport PR
[#&#8203;37169](https://redirect.github.com/cilium/cilium/issues/37169),
Upstream PR
[#&#8203;36377](https://redirect.github.com/cilium/cilium/issues/36377),
[@&#8203;smagnani96](https://redirect.github.com/smagnani96))
- CI: Add list and filter artifacts steps
([#&#8203;35172](https://redirect.github.com/cilium/cilium/issues/35172),
[@&#8203;brlbil](https://redirect.github.com/brlbil))
- CI: Add merge and upload composite action
([#&#8203;35355](https://redirect.github.com/cilium/cilium/issues/35355),
[@&#8203;brlbil](https://redirect.github.com/brlbil))
- ci: add network policy scale test
([#&#8203;35278](https://redirect.github.com/cilium/cilium/issues/35278),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: add watch request thresholds
([#&#8203;35808](https://redirect.github.com/cilium/cilium/issues/35808),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: allow all GKE K8s release channels
([#&#8203;33770](https://redirect.github.com/cilium/cilium/issues/33770),
[@&#8203;nbusseneau](https://redirect.github.com/nbusseneau))
- ci: clustermesh run tests concurrently
([#&#8203;33942](https://redirect.github.com/cilium/cilium/issues/33942),
[@&#8203;viktor-kurchenko](https://redirect.github.com/viktor-kurchenko))
- ci: configure connectivity test in delegated ipam e2e
([#&#8203;36475](https://redirect.github.com/cilium/cilium/issues/36475),
[@&#8203;wedaly](https://redirect.github.com/wedaly))
- ci: conformance-kind: don't explicitly enable session affinity
([#&#8203;35290](https://redirect.github.com/cilium/cilium/issues/35290),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- ci: datapath-verifier: also run on 6.12 kernel
([#&#8203;36619](https://redirect.github.com/cilium/cilium/issues/36619),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- ci: fix cleanup of stale kops clusters.
([#&#8203;35986](https://redirect.github.com/cilium/cilium/issues/35986),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: fix native wireguard encryption
([#&#8203;35520](https://redirect.github.com/cilium/cilium/issues/35520),
[@&#8203;marseel](https://redirect.github.com/marseel))
- CI: Fix syntax error in Image Cache Cleaner
([#&#8203;35104](https://redirect.github.com/cilium/cilium/issues/35104),
[@&#8203;brlbil](https://redirect.github.com/brlbil))
- ci: increase verbosity of print-downgrade-script.sh
([#&#8203;34668](https://redirect.github.com/cilium/cilium/issues/34668),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: Introduce CILIUM_INSTALL_NET_PERF_EXTRA_ARGS env var
([#&#8203;35178](https://redirect.github.com/cilium/cilium/issues/35178),
[@&#8203;markpash](https://redirect.github.com/markpash))
- ci: kind proxy run tests concurrently
([#&#8203;33944](https://redirect.github.com/cilium/cilium/issues/33944),
[@&#8203;viktor-kurchenko](https://redirect.github.com/viktor-kurchenko))
- CI: l4lb allow extra opts
([#&#8203;34813](https://redirect.github.com/cilium/cilium/issues/34813),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- ci: more robust hubble relay service port-forwarding (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37110](https://redirect.github.com/cilium/cilium/issues/37110),
[@&#8203;rolinh](https://redirect.github.com/rolinh))
- ci: Move CiliumEndpointSlice migration to schedule
([#&#8203;34828](https://redirect.github.com/cilium/cilium/issues/34828),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: netperf always run hubble
([#&#8203;35268](https://redirect.github.com/cilium/cilium/issues/35268),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: Reduce concurrency for AWS CNI test
([#&#8203;34683](https://redirect.github.com/cilium/cilium/issues/34683),
[@&#8203;marseel](https://redirect.github.com/marseel))
- CI: remove unsed env variable
([#&#8203;35149](https://redirect.github.com/cilium/cilium/issues/35149),
[@&#8203;brlbil](https://redirect.github.com/brlbil))
- ci: run privileged tests in parallel except for IPSec
([#&#8203;35232](https://redirect.github.com/cilium/cilium/issues/35232),
[@&#8203;marseel](https://redirect.github.com/marseel))
- ci: skip certain workflows for changes only affecting cilium-cli
([#&#8203;34550](https://redirect.github.com/cilium/cilium/issues/34550),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- ci: switch most remaining workflows to new IPsec key system
([#&#8203;35295](https://redirect.github.com/cilium/cilium/issues/35295),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- ci: Update branch matrix list in call-backport-label-updater
([#&#8203;33761](https://redirect.github.com/cilium/cilium/issues/33761),
[@&#8203;pippolo84](https://redirect.github.com/pippolo84))
- ci: Update ref to cilium/scaffolding in ClusterMesh scale test
workflow
([#&#8203;34499](https://redirect.github.com/cilium/cilium/issues/34499),
[@&#8203;learnitall](https://redirect.github.com/learnitall))
- CI: Update tested K8S versions
([#&#8203;35726](https://redirect.github.com/cilium/cilium/issues/35726),
[@&#8203;brlbil](https://redirect.github.com/brlbil))
- ci: use the VERSION file from the PR branch in push-charts-ci.yaml
([#&#8203;35950](https://redirect.github.com/cilium/cilium/issues/35950),
[@&#8203;ferozsalam](https://redirect.github.com/ferozsalam))
- cilium-cli/connectivity: allow to specify log levels to check
([#&#8203;36231](https://redirect.github.com/cilium/cilium/issues/36231),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- cilium-cli/connectivity: disable warning log checks before v1.17
([#&#8203;36358](https://redirect.github.com/cilium/cilium/issues/36358),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- cilium-cli/connectivity: fix IPv6 feature check for 2ndary node IPv6
([#&#8203;36513](https://redirect.github.com/cilium/cilium/issues/36513),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- cilium-cli: connectivity: fix the local-redirect-policy flow
validation
([#&#8203;34919](https://redirect.github.com/cilium/cilium/issues/34919),
[@&#8203;ysksuzuki](https://redirect.github.com/ysksuzuki))
- cilium-cli: Define CLI_MAIN_DIR Make variable
([#&#8203;34910](https://redirect.github.com/cilium/cilium/issues/34910),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- cilium-cli: Ignore "No egress gateway found" drops
([#&#8203;35609](https://redirect.github.com/cilium/cilium/issues/35609),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- cilium-cli: Improve tcpdump termination timeout handling
([#&#8203;36021](https://redirect.github.com/cilium/cilium/issues/36021),
[@&#8203;liyihuang](https://redirect.github.com/liyihuang))
- cilium-cli: retry exec-in-pod requests in case of transient errors
([#&#8203;35961](https://redirect.github.com/cilium/cilium/issues/35961),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- cilium-cli: Run BGP tests sequentially
([#&#8203;35727](https://redirect.github.com/cilium/cilium/issues/35727),
[@&#8203;rastislavs](https://redirect.github.com/rastislavs))
- Cleanup leaked GCE kops clusters
([#&#8203;35915](https://redirect.github.com/cilium/cilium/issues/35915),
[@&#8203;marseel](https://redirect.github.com/marseel))
- Cleanups after LLVM upgrade.
([#&#8203;32067](https://redirect.github.com/cilium/cilium/issues/32067),
[@&#8203;gentoo-root](https://redirect.github.com/gentoo-root))
- cli/connectivity: Check for unexpected warning logs
([#&#8203;35723](https://redirect.github.com/cilium/cilium/issues/35723),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- cli/connectivity: Test strict mode encryption
([#&#8203;35231](https://redirect.github.com/cilium/cilium/issues/35231),
[@&#8203;jschwinger233](https://redirect.github.com/jschwinger233))
- cli: Don't ignore datapath bug packet drops
([#&#8203;36105](https://redirect.github.com/cilium/cilium/issues/36105),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- clustermesh: Run cilium-cli inside Docker
([#&#8203;33749](https://redirect.github.com/cilium/cilium/issues/33749),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- conformance-{gateway-api,ingress}: Run cilium-cli inside Docker
([#&#8203;33724](https://redirect.github.com/cilium/cilium/issues/33724),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- contrib/scripts/kind.sh: fix DNS resolution on nodes
([#&#8203;34154](https://redirect.github.com/cilium/cilium/issues/34154),
[@&#8203;atykhyy](https://redirect.github.com/atykhyy))
- datapath: Improve XFRM leak tests
([#&#8203;35796](https://redirect.github.com/cilium/cilium/issues/35796),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- Enabling IPSec pod-to-pod-with-l7-policy-encryption connectivity test
for v1.15 and v1.16.
([#&#8203;35742](https://redirect.github.com/cilium/cilium/issues/35742),
[@&#8203;smagnani96](https://redirect.github.com/smagnani96))
- envoy: Add renovate configuration for cilium-proxy image
([#&#8203;33424](https://redirect.github.com/cilium/cilium/issues/33424),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- Fix bug in testsuite where a list of Pods was initialized with several
empty elements rather than allocating the buffer with space for enough
elements.
([#&#8203;35164](https://redirect.github.com/cilium/cilium/issues/35164),
[@&#8203;rusttech](https://redirect.github.com/rusttech))
- Fix bug preventing the ability to build images with non-stripped
binaries
([#&#8203;35326](https://redirect.github.com/cilium/cilium/issues/35326),
[@&#8203;learnitall](https://redirect.github.com/learnitall))
- Fix cilium CLI connectivity tests in IPv6-only clusters.
([#&#8203;36026](https://redirect.github.com/cilium/cilium/issues/36026),
[@&#8203;wedaly](https://redirect.github.com/wedaly))
- Fix flake in node manager `TestNodeManagerEmitStatus` test
([#&#8203;36097](https://redirect.github.com/cilium/cilium/issues/36097),
[@&#8203;glrf](https://redirect.github.com/glrf))
- fqdn-perf: allow to inject additional metrics measurements
([#&#8203;33583](https://redirect.github.com/cilium/cilium/issues/33583),
[@&#8203;marseel](https://redirect.github.com/marseel))
- gh: cilium-config: enable IPv6 BPF Masquerade with HostFW
([#&#8203;33686](https://redirect.github.com/cilium/cilium/issues/33686),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gh: e2e-upgrade: add coverage for 6.12 kernel
([#&#8203;36640](https://redirect.github.com/cilium/cilium/issues/36640),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gh: e2e-upgrade: re-enable config 12
([#&#8203;34218](https://redirect.github.com/cilium/cilium/issues/34218),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gh: e2e-upgrade: use DSR-Geneve in config 15 (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36982](https://redirect.github.com/cilium/cilium/issues/36982),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gh: harmonize lvh kernel naming scheme (Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37322](https://redirect.github.com/cilium/cilium/issues/37322),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gh: nat46x64: don't set DSR dispatch mode when LB mode is SNAT
([#&#8203;33726](https://redirect.github.com/cilium/cilium/issues/33726),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gh: update removed --loglevel option for kind (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36935](https://redirect.github.com/cilium/cilium/issues/36935),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- gha(update-label-backport): ignore leading 'v' in branch parameter
([#&#8203;34013](https://redirect.github.com/cilium/cilium/issues/34013),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: Add coverage for policy secret sync
([#&#8203;36040](https://redirect.github.com/cilium/cilium/issues/36040),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: Allow CRD mismatch for Gateway API conformance
([#&#8203;33536](https://redirect.github.com/cilium/cilium/issues/33536),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: always collect and upload sysdump if 100 nodes scale test fails
([#&#8203;36367](https://redirect.github.com/cilium/cilium/issues/36367),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: always respect the given image-tag in the helm-default action
([#&#8203;36293](https://redirect.github.com/cilium/cilium/issues/36293),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: Bump k8s version to v1.32.0 (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36905](https://redirect.github.com/cilium/cilium/issues/36905),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: bump ubuntu version in conformance-externalworkloads (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36859](https://redirect.github.com/cilium/cilium/issues/36859),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: compress profiles archives in scale/perf tests
([#&#8203;33729](https://redirect.github.com/cilium/cilium/issues/33729),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: correctly downgrade to patch release in ipsec workflows (Backport
PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36858](https://redirect.github.com/cilium/cilium/issues/36858),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: default the helm-default image-tag also in pull request workflows
([#&#8203;36314](https://redirect.github.com/cilium/cilium/issues/36314),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: Disable envoy version check in upgrade/downgrade tests (Backport
PR
[#&#8203;36739](https://redirect.github.com/cilium/cilium/issues/36739),
Upstream PR
[#&#8203;36734](https://redirect.github.com/cilium/cilium/issues/36734),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: Enable Ingress Controller test in upgrade
([#&#8203;34185](https://redirect.github.com/cilium/cilium/issues/34185),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: Enable ingress-controller in e2e tests
([#&#8203;36043](https://redirect.github.com/cilium/cilium/issues/36043),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: Enable parallel requests for L7 tests
([#&#8203;36623](https://redirect.github.com/cilium/cilium/issues/36623),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: enable the log-errors check in the clustermesh upgrade workflow
([#&#8203;35739](https://redirect.github.com/cilium/cilium/issues/35739),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: extra Cilium agents CPU and Mem metrics in clustermesh scale test
([#&#8203;36481](https://redirect.github.com/cilium/cilium/issues/36481),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: fix case mismatch in conformance clustermesh ipFamily variable
([#&#8203;34555](https://redirect.github.com/cilium/cilium/issues/34555),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: fix permissions of update label backport PR workflow
([#&#8203;35117](https://redirect.github.com/cilium/cilium/issues/35117),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: fix retrieval of DNS server in conformance external workloads
(Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37361](https://redirect.github.com/cilium/cilium/issues/37361),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: Retrieve eks supported version via aws cli (Backport PR
[#&#8203;37222](https://redirect.github.com/cilium/cilium/issues/37222),
Upstream PR
[#&#8203;37210](https://redirect.github.com/cilium/cilium/issues/37210),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: Simplify integration test job
([#&#8203;34676](https://redirect.github.com/cilium/cilium/issues/34676),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- gha: test disabled kvstoremesh clustermesh upgrade/downgrade tests
([#&#8203;36242](https://redirect.github.com/cilium/cilium/issues/36242),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: uniform downgrade settings in clustermesh upgrade/downgrade test
([#&#8203;36239](https://redirect.github.com/cilium/cilium/issues/36239),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- gha: Update logic to extract gateway-api version
([#&#8203;35189](https://redirect.github.com/cilium/cilium/issues/35189),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- ginkgo: Get rid of K8sUpdates
([#&#8203;35035](https://redirect.github.com/cilium/cilium/issues/35035),
[@&#8203;brb](https://redirect.github.com/brb))
- Ginkgo: test runner: add flag to allow helm overrides
([#&#8203;34096](https://redirect.github.com/cilium/cilium/issues/34096),
[@&#8203;tommyp1ckles](https://redirect.github.com/tommyp1ckles))
- github: Add a workflow to build cilium-cli binaries
([#&#8203;34462](https://redirect.github.com/cilium/cilium/issues/34462),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- github: bump LVH image versions
([#&#8203;35719](https://redirect.github.com/cilium/cilium/issues/35719),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- github: Checkout code before running cilium/cilium-cli action
([#&#8203;36117](https://redirect.github.com/cilium/cilium/issues/36117),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- github: Fix branch name in build-go-caches.yaml
([#&#8203;36906](https://redirect.github.com/cilium/cilium/issues/36906),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- github: Simplify the checkout logic
([#&#8203;36190](https://redirect.github.com/cilium/cilium/issues/36190),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- hive/metrics: Fix flaky test
([#&#8203;36418](https://redirect.github.com/cilium/cilium/issues/36418),
[@&#8203;ovidiutirla](https://redirect.github.com/ovidiutirla))
- hubble: ignore some testifylint linter errors
([#&#8203;36096](https://redirect.github.com/cilium/cilium/issues/36096),
[@&#8203;rolinh](https://redirect.github.com/rolinh))
- integration: Bump ubuntu to 24.04 for arm runners (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;37042](https://redirect.github.com/cilium/cilium/issues/37042),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- Introduce ClusterMesh scale tests
([#&#8203;33562](https://redirect.github.com/cilium/cilium/issues/33562),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- ipsec: Fix arguments in XFRM IN policy test
([#&#8203;36030](https://redirect.github.com/cilium/cilium/issues/36030),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- ipsec: Run cilium-cli inside Docker
([#&#8203;33750](https://redirect.github.com/cilium/cilium/issues/33750),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- labeler: Add cilium-cli label
([#&#8203;34447](https://redirect.github.com/cilium/cilium/issues/34447),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- Makefile: Increase timeout for integration tests to 12min (Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37279](https://redirect.github.com/cilium/cilium/issues/37279),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- metrics: Add metrics config test for Hubble.
([#&#8203;34325](https://redirect.github.com/cilium/cilium/issues/34325),
[@&#8203;rectified95](https://redirect.github.com/rectified95))
- Miscellaneus improvements to the clustermesh scale test
([#&#8203;34704](https://redirect.github.com/cilium/cilium/issues/34704),
[@&#8203;giorio94](https://redirect.github.com/giorio94))
- Modify bpftrace script in CI to ignore proxy traffic if destination is
outside pod CIDRs. (Backport PR
[#&#8203;37126](https://redirect.github.com/cilium/cilium/issues/37126),
Upstream PR
[#&#8203;36364](https://redirect.github.com/cilium/cilium/issues/36364),
[@&#8203;smagnani96](https://redirect.github.com/smagnani96))
- net-perf-gke: Shorten the cluster name
([#&#8203;34260](https://redirect.github.com/cilium/cilium/issues/34260),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- option: Fix merge conflict in test expectations
([#&#8203;33572](https://redirect.github.com/cilium/cilium/issues/33572),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- perf: Run cilium-cli inside Docker
([#&#8203;33752](https://redirect.github.com/cilium/cilium/issues/33752),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- policy/ci: Add Complex Allow Test to Policy Engine
([#&#8203;35156](https://redirect.github.com/cilium/cilium/issues/35156),
[@&#8203;nathanjsweet](https://redirect.github.com/nathanjsweet))
- Quarantine of high-scale IPcache
([#&#8203;36376](https://redirect.github.com/cilium/cilium/issues/36376),
[@&#8203;Artyop](https://redirect.github.com/Artyop))
- Reapply "kind.sh: fix DNS resolution on nodes, make external DNS
configurable
([#&#8203;34293](https://redirect.github.com/cilium/cilium/issues/34293),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- Remove ghc in GHA disk cleanup
([#&#8203;34320](https://redirect.github.com/cilium/cilium/issues/34320),
[@&#8203;chancez](https://redirect.github.com/chancez))
- renovate: Fix image updates for IPsec workflows
([#&#8203;35555](https://redirect.github.com/cilium/cilium/issues/35555),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- renovate: manually bump version
([#&#8203;35660](https://redirect.github.com/cilium/cilium/issues/35660),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- renovate: Only update patch version for statedb
([#&#8203;33623](https://redirect.github.com/cilium/cilium/issues/33623),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- renovate: use proper image repository for config check
([#&#8203;36227](https://redirect.github.com/cilium/cilium/issues/36227),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- renovate: various smaller updates
([#&#8203;36135](https://redirect.github.com/cilium/cilium/issues/36135),
[@&#8203;julianwiedmann](https://redirect.github.com/julianwiedmann))
- Revert "ci: increase verbosity of print-downgrade-script.sh"
([#&#8203;34863](https://redirect.github.com/cilium/cilium/issues/34863),
[@&#8203;marseel](https://redirect.github.com/marseel))
- Run cilium-cli inside Docker
([#&#8203;33753](https://redirect.github.com/cilium/cilium/issues/33753),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- Run cilium-cli inside Docker
([#&#8203;33797](https://redirect.github.com/cilium/cilium/issues/33797),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- Run ipv6 smoke test inside Docker
([#&#8203;34191](https://redirect.github.com/cilium/cilium/issues/34191),
[@&#8203;michi-covalent](https://redirect.github.com/michi-covalent))
- Run scheduled workflows every 8h instead of 6h
([#&#8203;34898](https://redirect.github.com/cilium/cilium/issues/34898),
[@&#8203;auriaave](https://redirect.github.com/auriaave))
- scale-test: disable kube-proxy and configure KPR
([#&#8203;33664](https://redirect.github.com/cilium/cilium/issues/33664),
[@&#8203;thorn3r](https://redirect.github.com/thorn3r))
- Skip tracking unmarked plain-text TCP RST packets generated from proxy
timeouts in the CI bpftrace script. (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;36962](https://redirect.github.com/cilium/cilium/issues/36962),
[@&#8203;smagnani96](https://redirect.github.com/smagnani96))
- test, cli/connectivity: Remove stale error log exceptions
([#&#8203;35848](https://redirect.github.com/cilium/cilium/issues/35848),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- test/helpers: Update operator lock error
([#&#8203;34307](https://redirect.github.com/cilium/cilium/issues/34307),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- test/k8s: remove unused migrate-svc manifests
([#&#8203;36388](https://redirect.github.com/cilium/cilium/issues/36388),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- test/runtime: Remove already-covered test for agent restart
([#&#8203;34357](https://redirect.github.com/cilium/cilium/issues/34357),
[@&#8203;pchaigno](https://redirect.github.com/pchaigno))
- test: add dual-stack to delegated IPAM E2E test
([#&#8203;34937](https://redirect.github.com/cilium/cilium/issues/34937),
[@&#8203;wedaly](https://redirect.github.com/wedaly))
- test: Add unit tests for directory policy watcher
([#&#8203;33920](https://redirect.github.com/cilium/cilium/issues/33920),
[@&#8203;tamilmani1989](https://redirect.github.com/tamilmani1989))
- test: Cilium Identity management tests
([#&#8203;34743](https://redirect.github.com/cilium/cilium/issues/34743),
[@&#8203;dlapcevic](https://redirect.github.com/dlapcevic))
- test: drop no-op `-cilium.provision-k8s` flag (Backport PR
[#&#8203;37374](https://redirect.github.com/cilium/cilium/issues/37374),
Upstream PR
[#&#8203;37300](https://redirect.github.com/cilium/cilium/issues/37300),
[@&#8203;tklauser](https://redirect.github.com/tklauser))
- test: e2e tests for delegated IPAM
([#&#8203;34839](https://redirect.github.com/cilium/cilium/issues/34839),
[@&#8203;wedaly](https://redirect.github.com/wedaly))
- test: Fix the flake for TestRestoredPort (Backport PR
[#&#8203;37247](https://redirect.github.com/cilium/cilium/issues/37247),
Upstream PR
[#&#8203;37106](https://redirect.github.com/cilium/cilium/issues/37106),
[@&#8203;sayboras](https://redirect.github.com/sayboras))
- test: Move demo-httpd from Docker to Quay (Backport PR
[#&#8203;37247](https

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2025-02-05 03:04:47 +01:00
TrueCharts Bot
c647919517 chore(container): update docker.io/tailscale/tailscale docker tag to v1.80.0 (#31653)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [docker.io/tailscale/tailscale](https://tailscale.com/kb/1282/docker)
([source](https://redirect.github.com/tailscale/tailscale)) | final |
minor | `v1.78.3` -> `v1.80.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>tailscale/tailscale (docker.io/tailscale/tailscale)</summary>

###
[`v1.80.0`](https://redirect.github.com/tailscale/tailscale/releases/tag/v1.80.0)

[Compare
Source](https://redirect.github.com/tailscale/tailscale/compare/v1.78.3...v1.80.0)

Please refer to the changelog available at
[https://tailscale.com/changelog](https://tailscale.com/changelog#2025-01-30).

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2025-02-05 03:04:04 +01:00
TrueCharts Bot
29219a28c9 chore(helm): update image ghcr.io/linuxserver/smokeping digest to 6db40c6 (#31632) 2025-02-05 03:03:37 +01:00
TrueCharts Bot
f95e13f36a chore(helm): update image redmine digest to 34271e3 (#31635)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| redmine | digest | `d03e49a` -> `34271e3` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:03:30 +01:00
TrueCharts Bot
7c05cfb586 chore(helm): update image ghcr.io/linuxserver/lazylibrarian digest to 11d05bd (#31629)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/linuxserver/lazylibrarian | digest | `65cf531` -> `11d05bd` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:03:05 +01:00
TrueCharts Bot
a60af6ca11 chore(helm): update image friendica digest to 6ae9660 (#31623)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| friendica | digest | `782821e` -> `6ae9660` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:02:46 +01:00
TrueCharts Bot
184a50b9ad chore(helm): update image docker.io/searxng/searxng digest to cb1f826 (#31621) 2025-02-05 03:02:34 +01:00
TrueCharts Bot
50266d773c chore(helm): update image docker.io/mikenye/tar1090 digest to 786ceeb (#31620)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/mikenye/tar1090 | digest | `2b80bce` -> `786ceeb` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:02:28 +01:00
TrueCharts Bot
68006a484d chore(helm): update image docker.io/machines/filestash digest to 3355b98 (#31619)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/machines/filestash | digest | `ebcd431` -> `3355b98` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:01:32 +01:00
TrueCharts Bot
277cebb5c2 chore(helm): update image docker.io/jgraph/drawio digest to 37246b7 (#31617)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/jgraph/drawio](https://www.drawio.com)
([source](https://redirect.github.com/jgraph/docker-drawio)) | digest |
`4273fe3` -> `37246b7` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:01:18 +01:00
TrueCharts Bot
63600da1b4 chore(helm): update image docker.io/diygod/rsshub digest to baaea53 (#31616)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/diygod/rsshub | digest | `937eff0` -> `baaea53` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:00:58 +01:00
TrueCharts Bot
61c4b1c1db chore(helm): update image docker.io/bitnami/alertmanager digest to e8d2dc5 (#31614)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/bitnami/alertmanager](https://redirect.github.com/bitnami/containers)
([source](https://redirect.github.com/bitnami/containers/tree/HEAD/bitnami/alertmanager))
| digest | `48b6281` -> `e8d2dc5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 03:00:21 +01:00
TrueCharts Bot
d1f2d2e934 chore(flux): update image cert-manager 6.5.2 → 6.5.3 (clustertool) (#31639)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cert-manager](https://truecharts.org/charts/system/cert-manager)
([source](https://cert-manager.io/)) | patch | `6.5.2` -> `6.5.3` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2025-02-05 01:59:46 +00:00
TrueCharts Bot
6489150235 chore(helm): update image docker digest to ba55987 (#31613)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker | digest | `3ab005a` -> `ba55987` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:59:24 +01:00
TrueCharts Bot
061b2c8e63 chore(helm): update rdesktop (#31636) 2025-02-05 02:57:33 +01:00
TrueCharts Bot
f006faa46e chore(helm): update image ghcr.io/meeb/tubesync digest to d226f4c (#31634) 2025-02-05 02:57:27 +01:00
TrueCharts Bot
78caf33059 chore(helm): update image ghcr.io/linuxserver/orcaslicer digest to 6853c24 (#31630) 2025-02-05 02:57:21 +01:00
TrueCharts Bot
3120304d82 chore(helm): update image ghcr.io/linuxserver/synclounge digest to ba531c3 (#31633)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/synclounge](https://redirect.github.com/linuxserver/docker-synclounge/packages)
([source](https://redirect.github.com/linuxserver/docker-synclounge)) |
digest | `9b95ed9` -> `ba531c3` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:57:16 +01:00
TrueCharts Bot
2130dea7c4 chore(helm): update image ghcr.io/linuxserver/rsnapshot digest to fe0790b (#31631)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/rsnapshot](https://redirect.github.com/linuxserver/docker-rsnapshot/packages)
([source](https://redirect.github.com/linuxserver/docker-rsnapshot)) |
digest | `55eff6d` -> `fe0790b` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 01:56:55 +00:00
TrueCharts Bot
0e9ca851da chore(helm): update image ghcr.io/linuxserver/duckdns digest to 0f61de8 (#31627) 2025-02-05 02:56:50 +01:00
TrueCharts Bot
d7136319aa chore(helm): update image ghcr.io/linuxserver/ddclient digest to 855acbb (#31625)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/ddclient](https://redirect.github.com/linuxserver/docker-ddclient/packages)
([source](https://redirect.github.com/linuxserver/docker-ddclient)) |
digest | `eb5b5fa` -> `855acbb` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 01:56:49 +00:00
TrueCharts Bot
e408c7cd2e chore(helm): update image docker.io/soulraven1980/wdosg digest to 671be9a (#31622)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/soulraven1980/wdosg | digest | `09f2518` -> `671be9a` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:56:43 +01:00
TrueCharts Bot
026d01b595 chore(helm): update image ghcr.io/linuxserver/digikam digest to f495e34 (#31626) 2025-02-05 02:56:39 +01:00
TrueCharts Bot
50b60ff20b chore(helm): update image ghcr.io/linuxserver/filezilla digest to 69a485e (#31628)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/filezilla](https://redirect.github.com/linuxserver/docker-filezilla/packages)
([source](https://redirect.github.com/linuxserver/docker-filezilla)) |
digest | `ac766d5` -> `69a485e` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:56:32 +01:00
TrueCharts Bot
eb6d17dff7 chore(helm): update image ghcr.io/linuxserver/boinc digest to 74292b2 (#31624)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/linuxserver/boinc | digest | `0f49864` -> `74292b2` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:56:26 +01:00
TrueCharts Bot
ae57a6f9f9 chore(helm): update image docker.io/clamav/clamav digest to cb9aed5 (#31615)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/clamav/clamav](https://redirect.github.com/Cisco-Talos/clamav.git)
([source](https://redirect.github.com/Cisco-Talos/clamav)) | digest |
`e23d053` -> `cb9aed5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 01:54:11 +00:00
TrueCharts Bot
2c11f9bd03 chore(helm): update image docker.io/lmscommunity/lyrionmusicserver digest to d31ddf5 (#31618)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/lmscommunity/lyrionmusicserver | digest | `e220821` ->
`d31ddf5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:53:57 +01:00
TrueCharts Bot
b44aade2a3 chore(github-action): update golangci/golangci-lint-action digest to e60da84 (#31612) 2025-02-05 02:43:31 +01:00
TrueCharts Bot
d3164ee7c0 chore(container): update golang:1.23.5 docker digest to e213430 (#31611)
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| golang | final | digest | `8c10f21` -> `e213430` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-05 02:43:08 +01:00
Alfred Göppel
8e0f07af7d fix(devcontainer): Update version (#31602)
**Description**
<!--
Please include a summary of the change and which issue is fixed. Please
also include relevant motivation and context. List any dependencies that
are required for this change.
-->
⚒️ Fixes  # <!--(issue)-->

**⚙️ Type of change**

- [ ] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] 🔃 Refactor of current code

**🧪 How Has This Been Tested?**
<!--
Please describe the tests that you ran to verify your changes. Provide
instructions so we can reproduce. Please also list any relevant details
for your test configuration
-->

**📃 Notes:**
<!-- Please enter any other relevant information here -->

**✔️ Checklist:**

- [ ] ⚖️ My code follows the style guidelines of this project
- [ ] 👀 I have performed a self-review of my own code
- [ ] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [ ] 📄 I have made corresponding changes to the documentation
- [ ] ⚠️ My changes generate no new warnings
- [ ] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [ ] ⬆️ I increased versions for any altered app according to semantic
versioning
- [ ] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):` or `chore(chart-name):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._

---------

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Signed-off-by: Xstar97TheNoob <9399967+xstar97@users.noreply.github.com>
Co-authored-by: Xstar97TheNoob <9399967+xstar97@users.noreply.github.com>
2025-02-04 19:40:35 -05:00
TrueCharts Bot
b258f943af chore(helm): update chart cert-manager v1.16.3 → v1.17.0 (#31609)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cert-manager](https://cert-manager.io)
([source](https://redirect.github.com/cert-manager/cert-manager)) |
minor | `v1.16.3` -> `v1.17.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cert-manager/cert-manager (cert-manager)</summary>

###
[`v1.17.0`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.17.0)

[Compare
Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.16.3...v1.17.0)

cert-manager is the easiest way to automatically manage certificates in
Kubernetes and OpenShift clusters.

v1.17.0 is a feature release with several improvements, including:

-   A helpful compliance change to RSA signatures on certificates
- An easier way to specify passwords for
[PKCS#12](https://redirect.github.com/PKCS/cert-manager/issues/12) and
JKS keystores
-   A few feature flag promotions (and a deprecation)
-   Dependency bumps and other smaller improvements

#### Major Themes

##### RSA Certificate Compliance

The United States Department of Defense published [a
memo](https://dl.dod.cyber.mil/wp-content/uploads/pki-pke/pdf/unclass-memo_dodcryptoalgorithms.pdf)
in 2022 which introduced some requirements on the kinds of cryptography
they require to be supported in software they use.

In effect, the memo requires that software be able to support larger RSA
keys (3072-bit and 4096-bit) and hashing algorithms (SHA-384 at a
minimum).

cert-manager supported large RSA keys long before the memo was
published, but a quirk in implementation meant that cert-manager always
used SHA-256 when signing with RSA.

In v1.17.0, cert-manager will choose a hash algorithm based on the RSA
key length: 3072-bit keys will use SHA-384, and 4096-bit keys will use
SHA-512. This matches similar behavior already present for ECDSA
signatures.

Our expectation is that this change will have minimal impact beyond a
slight increase to security and better compliance; we're not aware of
Kubernetes based environments which support RSA 2048 with SHA-256 but
fail with RSA 4096 and SHA-512. However, if you're using larger RSA
keys, you should be aware of the change.

##### Easier Keystore Passwords for
[PKCS#12](https://redirect.github.com/PKCS/cert-manager/issues/12) and
JKS

Specifying passwords on
[PKCS#12](https://redirect.github.com/PKCS/cert-manager/issues/12) and
JKS keystores is supported in cert-manager
for compatibility reasons with software which expects or requires
passwords to be set; however, these passwords are [not relevant to
security](https://cert-manager.io/docs/faq/#why-are-passwords-on-jks-or-pkcs12-files-not-helpful)
and never have been in cert-manager.

The initial implementation of the `keystores` feature required these
"passwords" to be stored in a Kubernetes secret, which would then be
read by cert-manager when creating the keystore after a certificate was
issued. This is cumbersome, especially when many passwords are set to
default values such as `changeit` or `password`.

In cert-manager v1.17, it's now possible to set a keystore password
using a literal string value inside the `Certificate` resource itself,
making this process much easier with no change to security.

For example:

```yaml
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: my-cert-password
spec:
  secretName: my-cert-password
  issuerRef:
    name: my-issuer
    kind: ClusterIssuer
  keystores:
    jks:
      create: true
      password: "abc123"
    pkcs12:
      create: true
      password: "password"
  dnsNames:
  - example.com
```

The new `password` field is mutually exclusive with the
`passwordSecretRef` field, so be sure to only set one.

##### Feature Flag Promotions / Deprecations

cert-manager's feature flags allow for easier testing and adoption of
new features with a reduced risk of breaking changes. In cert-manager
v1.17, two feature gates have been promoted to "beta", and as such are
now enabled by default in all installations:

- `NameConstraints`, allowing users to specify the name constraints
extension which can be helpful when creating CA certificates for private
PKI
- `UseDomainQualifiedFinalizer`, which stops a Kubernetes warning from
being printed in logs

In addition, we added a new feature gate: `CAInjectorMerging`, which
intelligently combines certificates used by the
[`CAInjector`](../../concepts/ca-injector.md) component, making it safer
to use when issuing certificates are rotated. If you're making heavy use
of the CA injector, you should consider enabling this feature gate.

Finally, we deprecated the `ValidateCAA` feature gate which will be
removed entirely in cert-manager v1.18.0. This feature gate aimed to
validate the `CAA` DNS record during ACME issuance, but has seen low
adoption and limited testing since its introduction back in 2019.

##### Other Changes

There are many other PRs which were merged in this release cycle and
we'd encourage you to read the release notes below. One PR that's worth
highlighting is a change to add more structured logging information to
certain log lines.

If you were previously filtering logs using `grep` or similar tools
(which is highly discouraged!) be aware that some log lines have changed
format.

#### Community

As always, we'd like to thank all of the community members who helped in
this release cycle, including all below who merged a PR and anyone that
helped by commenting on issues, testing, or getting involved in
cert-manager meetings. We're lucky to have you involved.

A special thanks to:

-   [@&#8203;hawksight](https://redirect.github.com/hawksight)
-   [@&#8203;aidy](https://redirect.github.com/aidy)
-   [@&#8203;bashlion](https://redirect.github.com/bashlion)
-   [@&#8203;7ing](https://redirect.github.com/7ing)
-   [@&#8203;fadecore](https://redirect.github.com/fadecore)
-   [@&#8203;schedin](https://redirect.github.com/schedin)
-   [@&#8203;jkroepke](https://redirect.github.com/jkroepke)
-   [@&#8203;sdarwin](https://redirect.github.com/sdarwin)

for their contributions, comments and support!

Also, thanks to the cert-manager maintainer team for their help in this
release:

-   [@&#8203;inteon](https://redirect.github.com/inteon)
-   [@&#8203;erikgb](https://redirect.github.com/erikgb)
-   [@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish)
-   [@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot)
-   [@&#8203;munnerz](https://redirect.github.com/munnerz)
-   [@&#8203;maelvls](https://redirect.github.com/maelvls)

And finally, thanks to the cert-manager steering committee for their
feedback in this release cycle:

- [@&#8203;FlorianLiebhart](https://redirect.github.com/FlorianLiebhart)
-   [@&#8203;ssyno](https://redirect.github.com/ssyno)
-   [@&#8203;ianarsenault](https://redirect.github.com/ianarsenault)
-   [@&#8203;TrilokGeer](https://redirect.github.com/TrilokGeer)

#### Changes by Kind

##### Feature

- Potentially BREAKING: The CA and SelfSigned issuers now use SHA-512
when signing with RSA keys 4096 bits and above, and SHA-384 when signing
with RSA keys 3072 bits and above. If you were previously using a larger
RSA key as a CA, be sure to check that your systems support the new hash
algorithms.
([#&#8203;7368](https://redirect.github.com/cert-manager/cert-manager/issues/7368),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))
- Add CAInjectorMerging feature gate to the ca-injector, enabling this
will change the behaviour of the ca-injector to merge in new CA
certificates instead of outright replacing the existing one.
([#&#8203;7469](https://redirect.github.com/cert-manager/cert-manager/issues/7469),
[@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))
- Added image pull secrets to deployments when service accounts aren't
created
([#&#8203;7411](https://redirect.github.com/cert-manager/cert-manager/issues/7411),
[@&#8203;TheHenrick](https://redirect.github.com/TheHenrick))
- Added the ability to customize client ID when using username/password
authentication for Venafi client
([#&#8203;7484](https://redirect.github.com/cert-manager/cert-manager/issues/7484),
[@&#8203;ilyesAj](https://redirect.github.com/ilyesAj))
- Helm: New value `webhook.extraEnv` allows you to set custom
environment variables in the webhook Pod.
Helm: New value `cainjector.extraEnv` allows you to set custom
environment variables in the cainjector Pod.
Helm: New value `startupapicheck.extraEnv` allows you to set custom
environment variables in the startupapicheck Pod.
([#&#8203;7317](https://redirect.github.com/cert-manager/cert-manager/issues/7317),
[@&#8203;wallrj](https://redirect.github.com/wallrj))
- Increase the amount of PEM data `pki.DecodeX509CertificateSetBytes` is
able to parse, to enable reading larger TLS trust bundles
([#&#8203;7464](https://redirect.github.com/cert-manager/cert-manager/issues/7464),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))
- New configuration option tenantID for the AzureDNS provider when using
managed identities with service principals. This enhancement allows
users to specify the tenant ID when using managed identities, offering
better flexibility in multi-tenant environments.
([#&#8203;7376](https://redirect.github.com/cert-manager/cert-manager/issues/7376),
[@&#8203;jochenrichter](https://redirect.github.com/jochenrichter))
- Promote the `UseDomainQualifiedFinalizer` feature to Beta.
([#&#8203;7488](https://redirect.github.com/cert-manager/cert-manager/issues/7488),
[@&#8203;jsoref](https://redirect.github.com/jsoref))
- Allow JKS/PKCS12 keystore passwords to be set as literal values in
Certificate resources, mutually exclusive with the existing
passwordSecretRef field
([#&#8203;6657](https://redirect.github.com/cert-manager/cert-manager/issues/6657),
[@&#8203;rquinio1A](https://redirect.github.com/rquinio1A))
- Allow templating ServiceAccount annotations by running the built-in
Helm `tpl` function on keys and values, to aid with workload identity
configuration
([#&#8203;7501](https://redirect.github.com/cert-manager/cert-manager/issues/7501),
[@&#8203;fcrespofastly](https://redirect.github.com/fcrespofastly))
- Promote CA NameConstraints feature gate to Beta (enabled by default)
([#&#8203;7494](https://redirect.github.com/cert-manager/cert-manager/issues/7494),
[@&#8203;tanujd11](https://redirect.github.com/tanujd11))

##### Documentation

- Add example for IPv6 in `--dns01-recursive-nameservers`
([#&#8203;7367](https://redirect.github.com/cert-manager/cert-manager/issues/7367),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))
- Updated the chart documentation to show `enableGatewayAPI` in the
config example.
([#&#8203;7354](https://redirect.github.com/cert-manager/cert-manager/issues/7354),
[@&#8203;puerco](https://redirect.github.com/puerco))

##### Bug or Regression

- BUGFIX: A change in v1.16.0 caused cert-manager's ACME ClusterIssuer
to look in the wrong namespace for resources required for the issuance
(eg. credential Secrets). This is now fixed in v1.16.1+ and v1.17.0+
([#&#8203;7339](https://redirect.github.com/cert-manager/cert-manager/issues/7339),
[@&#8203;inteon](https://redirect.github.com/inteon))
- BUGFIX: Helm will now accept percentages for the
`podDisruptionBudget.minAvailable` and
`podDisruptionBudget.maxAvailable` values.
([#&#8203;7343](https://redirect.github.com/cert-manager/cert-manager/issues/7343),
[@&#8203;inteon](https://redirect.github.com/inteon))
- Fix ACME HTTP-01 solver for IPv6 endpoints
([#&#8203;7391](https://redirect.github.com/cert-manager/cert-manager/issues/7391),
[@&#8203;Peac36](https://redirect.github.com/Peac36))
- Fix the behavior of `renewBeforePercentage` to comply with its spec
([#&#8203;7421](https://redirect.github.com/cert-manager/cert-manager/issues/7421),
[@&#8203;adam-sroka](https://redirect.github.com/adam-sroka))
- Helm: allow `enabled` to be set as a value to toggle cert-manager as a
dependency.
([#&#8203;7350](https://redirect.github.com/cert-manager/cert-manager/issues/7350),
[@&#8203;inteon](https://redirect.github.com/inteon))
- SECURITY (low risk): Limit maximum allowed PEM size to prevent
potential DoS in cert-manager controller from attacker-controlled PEM.
See
[GHSA-r4pg-vg54-wxx4](https://redirect.github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4)
([#&#8203;7400](https://redirect.github.com/cert-manager/cert-manager/issues/7400),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))
- The Certificate object will no longer create CertificateRequest or
Secret objects while being deleted
([#&#8203;7361](https://redirect.github.com/cert-manager/cert-manager/issues/7361),
[@&#8203;ThatsMrTalbot](https://redirect.github.com/ThatsMrTalbot))
- The issuer will now more quickly retry when its linked Secret is
updated to fix an issue that caused a high back-off timeout.
([#&#8203;7455](https://redirect.github.com/cert-manager/cert-manager/issues/7455),
[@&#8203;inteon](https://redirect.github.com/inteon))
- Upgrades Venafi vCert library fixing a bug which caused the RSA 3072
bit key size for TPP certificate enrollment to not work.
([#&#8203;7498](https://redirect.github.com/cert-manager/cert-manager/issues/7498),
[@&#8203;inteon](https://redirect.github.com/inteon))

##### Other (Cleanup or Flake)

- ⚠️ Potentially BREAKING: Log messages that were not structured have
now been replaced with structured logs. If you were matching on specific
log strings, this could break your setup.
([#&#8203;7461](https://redirect.github.com/cert-manager/cert-manager/issues/7461),
[@&#8203;inteon](https://redirect.github.com/inteon))
- DEPRECATION: The `ValidateCAA` feature gate is now deprecated, with
removal scheduled for cert-manager 1.18. In 1.17, enabling this feature
gate will print a warning.
([#&#8203;7491](https://redirect.github.com/cert-manager/cert-manager/issues/7491),
[@&#8203;jsoref](https://redirect.github.com/jsoref))
- Remove `Neither --kubeconfig nor --master was specified` warning
message when the controller and the webhook services boot
([#&#8203;7457](https://redirect.github.com/cert-manager/cert-manager/issues/7457),
[@&#8203;Peac36](https://redirect.github.com/Peac36))
- Move 'live' DNS tests into a separate package to contain test
flakiness and improve developer UX
([#&#8203;7530](https://redirect.github.com/cert-manager/cert-manager/issues/7530),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJyZW5vdmF0ZS9oZWxtIiwidHlwZS9taW5vciJdfQ==-->

---------

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2025-02-04 08:13:10 +00:00
TrueCharts Bot
87d364108b chore(helm): update chart mongodb 15.3.1 → 15.3.2 (#31608) 2025-02-04 02:51:27 +01:00
TrueCharts Bot
ddc85d9b0f chore(helm): update image lscr.io/linuxserver/kdenlive digest to a50ff0d (#31605)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| lscr.io/linuxserver/kdenlive | digest | `ed29513` -> `a50ff0d` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS44Ni4xIiwidXBkYXRlZEluVmVyIjoiMzkuODYuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2025-02-04 01:51:22 +00:00