Skip to content

charts/authentik: update postgresql chart tag to v18.8.11 - #508

Merged
rissson merged 2 commits into
mainfrom
renovate/postgresql-18.x
Aug 18, 2026
Merged

charts/authentik: update postgresql chart tag to v18.8.11#508
rissson merged 2 commits into
mainfrom
renovate/postgresql-18.x

Conversation

@renovate

@renovate renovate Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
postgresql (source) patch 18.8.818.8.11

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Aug 14, 2026
@renovate
renovate Bot requested a review from a team as a code owner August 14, 2026 23:12
@renovate
renovate Bot force-pushed the renovate/postgresql-18.x branch from e4fd193 to 4c3cd95 Compare August 17, 2026 17:00
@renovate renovate Bot changed the title Update postgresql Docker tag to v18.8.9 Update postgresql Docker tag to v18.8.10 Aug 17, 2026
@renovate
renovate Bot force-pushed the renovate/postgresql-18.x branch from 4c3cd95 to b6e86d6 Compare August 18, 2026 03:00
@renovate renovate Bot changed the title Update postgresql Docker tag to v18.8.10 Update postgresql Docker tag to v18.8.11 Aug 18, 2026
Signed-off-by: Marc 'risson' Schmitt <marc.schmitt@risson.space>
@rissson rissson changed the title Update postgresql Docker tag to v18.8.11 charts/authentik: update postgresql chart tag to v18.8.11 Aug 18, 2026
@rissson
rissson enabled auto-merge (squash) August 18, 2026 13:17
@rissson
rissson merged commit 3400139 into main Aug 18, 2026
2 checks passed
@rissson
rissson deleted the renovate/postgresql-18.x branch August 18, 2026 13:26
Sammyrules7 pushed a commit to Sammyrules7/Servers that referenced this pull request Aug 24, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [authentik](https://goauthentik.io) ([source](https://github.com/goauthentik/helm)) | minor | `2026.5.x` → `2026.8.x` |
| [docker.io/library/busybox](https://hub.docker.com/_/busybox) ([source](https://github.com/docker-library/busybox)) | minor | `1.37.0` → `1.38.0` |
| [docker.io/livekit/livekit-server](https://github.com/livekit/livekit) | patch | `v1.13.4` → `v1.13.5` |
| [docker.io/mikefarah/yq](https://mikefarah.gitbook.io/yq/) ([source](https://github.com/mikefarah/yq)) | patch | `4.53.3` → `4.53.6` |
| [fluxcd/flux2](https://github.com/fluxcd/flux2) | patch | `v2.9.3` → `v2.9.4` |
| [ghcr.io/bjw-s-labs/helm/app-template](https://github.com/bjw-s-labs/helm-charts) | minor | `5.0.1` → `5.1.0` |
| [ghcr.io/element-hq/lk-jwt-service](https://github.com/element-hq/lk-jwt-service) | minor | `0.5.0` → `0.6.0` |
| ghcr.io/element-hq/matrix-authentication-service | digest | `73bb86f` → `e82b2e4` |
| [ghcr.io/element-hq/synapse](https://github.com/element-hq/synapse) | minor | `v1.157.2` → `v1.159.0` |
| [ghcr.io/fluxcd/notification-controller](https://github.com/fluxcd/notification-controller) | patch | `v1.9.2` → `v1.9.3` |
| [ghcr.io/fluxcd/source-controller](https://github.com/fluxcd/source-controller) | patch | `v1.9.3` → `v1.9.4` |
| [keda](https://github.com/kedacore/keda) | patch | `2.20.1` → `2.20.2` |
| [openclaw-operator](https://paperclip.inc) ([source](https://github.com/paperclipinc/openclaw-operator)) | minor | `0.38.1` → `0.39.0` |
| [renovate/renovate](https://renovatebot.com) ([source](https://github.com/renovatebot/renovate)) | minor | [`43.281.1` → `43.288.0`](https://octochangelog.com/compare?repo=renovatebot%2Frenovate&from=43.281.1&to=43.288.0) |
| [victoria-metrics-k8s-stack](https://github.com/VictoriaMetrics/helm-charts) | minor | `0.87.x` → `0.91.x` |

---

### Release Notes

<details>
<summary>goauthentik/helm (authentik)</summary>

### [`v2026.8.0`](https://github.com/goauthentik/helm/releases/tag/authentik-2026.8.0)

[Compare Source](https://github.com/goauthentik/helm/compare/authentik-2026.5.6...authentik-2026.8.0)

authentik is an open-source Identity Provider focused on flexibility and versatility

See <https://docs.goauthentik.io/releases/2026.8>

#### What's Changed

- charts/authentik: render automountServiceAccountToken when set to false by [@&#8203;PendaGTP](https://github.com/PendaGTP) in [#&#8203;499](https://github.com/goauthentik/helm/pull/499)
- charts/authentik: update postgresql chart tag to v18.8.1 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;487](https://github.com/goauthentik/helm/pull/487)
- charts/authentik: avoid mounting envFrom secret if secret configuration disabled by [@&#8203;baprx](https://github.com/baprx) in [#&#8203;497](https://github.com/goauthentik/helm/pull/497)
- charts/authentik: update postgresql chart tag to v18.8.2 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;500](https://github.com/goauthentik/helm/pull/500)
- charts/authentik: update postgresql chart tag to v18.8.4 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;501](https://github.com/goauthentik/helm/pull/501)
- charts/authentik: update postgresql chart tag to v18.8.5 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;502](https://github.com/goauthentik/helm/pull/502)
- charts/authentik: update postgresql chart tag to v18.8.6 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;504](https://github.com/goauthentik/helm/pull/504)
- charts/authentik: update postgresql chart tag to v18.8.7 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;505](https://github.com/goauthentik/helm/pull/505)
- charts/authentik: update postgresql chart tag to v18.8.8 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;506](https://github.com/goauthentik/helm/pull/506)
- charts/authentik: update docker.io/library/postgres Docker tag to v17.11 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;507](https://github.com/goauthentik/helm/pull/507)
- charts/authentik: update postgresql chart tag to v18.8.11 by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;508](https://github.com/goauthentik/helm/pull/508)
- charts/authentik: bump to 2026.8.0 by [@&#8203;authentik-automation](https://github.com/authentik-automation)\[bot] in [#&#8203;510](https://github.com/goauthentik/helm/pull/510)

#### New Contributors

- [@&#8203;PendaGTP](https://github.com/PendaGTP) made their first contribution in [#&#8203;499](https://github.com/goauthentik/helm/pull/499)

**Full Changelog**: <https://github.com/goauthentik/helm/compare/authentik-2026.5.6...authentik-2026.8.0>

</details>

<details>
<summary>livekit/livekit (docker.io/livekit/livekit-server)</summary>

### [`v1.13.5`](https://github.com/livekit/livekit/releases/tag/v1.13.5)

[Compare Source](https://github.com/livekit/livekit/compare/v1.13.4...v1.13.5)

##### Added

- add mock for testing region pins with API ([#&#8203;4691](https://github.com/livekit/livekit/issues/4691))
- Add country to participant closing log ([#&#8203;4693](https://github.com/livekit/livekit/issues/4693))
- Tests for down stream packet push. ([#&#8203;4692](https://github.com/livekit/livekit/issues/4692))
- Add status code for twirp request latency prometheus metric ([#&#8203;4621](https://github.com/livekit/livekit/issues/4621))
- Support more h264 profiles ([#&#8203;4708](https://github.com/livekit/livekit/issues/4708))
- log high stream start latency. ([#&#8203;4714](https://github.com/livekit/livekit/issues/4714))

##### Changed

- Use simulcast constructor for VP9 if simulcasted. ([#&#8203;4696](https://github.com/livekit/livekit/issues/4696))
- send resolved ringing timeout ([#&#8203;4697](https://github.com/livekit/livekit/issues/4697))
- Update go deps ([#&#8203;4645](https://github.com/livekit/livekit/issues/4645))
- protocol deps for logging webhook status ([#&#8203;4699](https://github.com/livekit/livekit/issues/4699))
- protocol update with webhook status logging ([#&#8203;4700](https://github.com/livekit/livekit/issues/4700))
- Record subscribe stream start time in prometheus. ([#&#8203;4704](https://github.com/livekit/livekit/issues/4704))
- A bit better counting for track publish. ([#&#8203;4707](https://github.com/livekit/livekit/issues/4707))

##### Fixed

- Fix padding bit in forwarded packet. ([#&#8203;4690](https://github.com/livekit/livekit/issues/4690))
- Spelling fixes ([#&#8203;4698](https://github.com/livekit/livekit/issues/4698))
- Do not call telemetry listener under pending track lock. ([#&#8203;4706](https://github.com/livekit/livekit/issues/4706))
- Fix getRefLayerRTPTimestamp off-by-one that can panic on max layer index ([#&#8203;4712](https://github.com/livekit/livekit/issues/4712))

</details>

<details>
<summary>mikefarah/yq (docker.io/mikefarah/yq)</summary>

### [`v4.53.6`](https://github.com/mikefarah/yq/releases/tag/v4.53.6)

[Compare Source](https://github.com/mikefarah/yq/compare/v4.53.4...v4.53.6)

- Fixing release build issue
  - Fixed line wrapping bug ([#&#8203;2824](https://github.com/mikefarah/yq/issues/2824), [#&#8203;2823](https://github.com/mikefarah/yq/issues/2823)) Thanks [@&#8203;mxey](https://github.com/mxey)
  - Bumped dependencies

### [`v4.53.4`](https://github.com/mikefarah/yq/releases/tag/v4.53.4)

[Compare Source](https://github.com/mikefarah/yq/compare/v4.53.3...v4.53.4)

- Close input files after processing each one ([#&#8203;2796](https://github.com/mikefarah/yq/issues/2796)) ([#&#8203;2808](https://github.com/mikefarah/yq/issues/2808)) Thanks [@&#8203;MsfPablo](https://github.com/MsfPablo)
- Fixed non string HCL string keys ([#&#8203;2795](https://github.com/mikefarah/yq/issues/2795))
- Fixed heap allocation bug ([#&#8203;2809](https://github.com/mikefarah/yq/issues/2809)) Thanks [@&#8203;MsfPablo](https://github.com/MsfPablo)
- Fix deleting commented empty list YAML output ([#&#8203;2765](https://github.com/mikefarah/yq/issues/2765)) Thanks [@&#8203;dpersek](https://github.com/dpersek)
- Fix (has) return false for negative array indices ([#&#8203;2769](https://github.com/mikefarah/yq/issues/2769)) Thanks [@&#8203;maximilize](https://github.com/maximilize)
- Fix (sort): avoid int64 overflow comparing large integers ([#&#8203;2771](https://github.com/mikefarah/yq/issues/2771)) Thanks [@&#8203;maximilize](https://github.com/maximilize)
- Fix: preserve correct parent references in explode merge anchor reconstruction ([#&#8203;2730](https://github.com/mikefarah/yq/issues/2730)) Thanks [@&#8203;vomba](https://github.com/vomba)
- Improve Guard ExpressionParser initialization with sync.Once ([#&#8203;2789](https://github.com/mikefarah/yq/issues/2789)) Thanks [@&#8203;arcaven](https://github.com/arcaven)
- Fix: reject negative indent instead of panicking ([#&#8203;2746](https://github.com/mikefarah/yq/issues/2746)) Thanks [@&#8203;StressTestor](https://github.com/StressTestor)
- Fix: parse signed hex and octal integers ([#&#8203;2749](https://github.com/mikefarah/yq/issues/2749)) Thanks [@&#8203;StressTestor](https://github.com/StressTestor)
- Fix: skip UTF-8 BOM when processing front matter ([#&#8203;2751](https://github.com/mikefarah/yq/issues/2751)) Thanks [@&#8203;StressTestor](https://github.com/StressTestor)
- Fix !!merge tag regression for yq  ([#&#8203;2705](https://github.com/mikefarah/yq/issues/2705)) Thanks [@&#8203;W-Floyd](https://github.com/W-Floyd)
- Default to yaml when a file's extension is not a recognised format ([#&#8203;2785](https://github.com/mikefarah/yq/issues/2785)) Thanks [@&#8203;devthedevil](https://github.com/devthedevil)
- Bumped dependencies

</details>

<details>
<summary>fluxcd/flux2 (fluxcd/flux2)</summary>

### [`v2.9.4`](https://github.com/fluxcd/flux2/releases/tag/v2.9.4)

[Compare Source](https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4)

#### Highlights

Flux v2.9.4 is a patch release that ships various fixes to the Flux controllers, covering source-watcher tarball extraction and glob expansion limits, the refspecs accepted by `ImageUpdateAutomation`, the HTTP request limits of the notification-controller servers, and Helm repository index loading, OCI chart digest pinning, `Bucket` error handling and GCS static authentication in source-controller. On the CLI side, `flux migrate -f` now supports migrating repositories to Flux 2.9. Users are encouraged to upgrade for the best experience.

Note that this release contains CRD schema changes for `ArtifactGenerator` and `ImageUpdateAutomation`; both CRDs must be updated along with the controllers.

ℹ️ Please follow the [Upgrade Procedure for Flux v2.7+](https://github.com/fluxcd/flux2/discussions/5572) for a smooth upgrade from Flux v2.6 to the latest version.

Fixes:

- Confine tarball extraction and bound glob expansion (source-watcher)
- Disallow force-update and deletion via refspecs (image-automation-controller)
- Unify HTTP server request limits (notification-controller)
- Align Helm repository index loading with upstream Helm v4 (source-controller)
- Improve error handling in `Bucket` reconciliation (source-controller)
- Pin OCI chart verification by digest (source-controller)
- Limit GCS static authentication to service account keys (source-controller)
- Restrict the `allow-webhooks` network policy to the receiver port (flux CLI)

Improvements:

- Add support for migrating repositories to 2.9 in `flux migrate -f` (flux CLI)
- Update fluxcd/pkg dependencies, which align the ECR host detection with upstream (source-controller, image-reflector-controller, flux CLI)
- Update Bitbucket Cloud receiver guidance (notification-controller)

#### Components changelog

- source-controller [v1.9.4](https://github.com/fluxcd/source-controller/blob/v1.9.4/CHANGELOG.md)
- source-watcher [v2.2.3](https://github.com/fluxcd/source-watcher/blob/v2.2.3/CHANGELOG.md)
- notification-controller [v1.9.3](https://github.com/fluxcd/notification-controller/blob/v1.9.3/CHANGELOG.md)
- image-reflector-controller [v1.2.4](https://github.com/fluxcd/image-reflector-controller/blob/v1.2.4/CHANGELOG.md)
- image-automation-controller [v1.2.4](https://github.com/fluxcd/image-automation-controller/blob/v1.2.4/CHANGELOG.md)

#### CLI changelog

- \[release/v2.9.x] Add support for 2.9 in `migrate -f` by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6021](https://github.com/fluxcd/flux2/pull/6021)
- Update fluxcd/pkg dependencies by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6026](https://github.com/fluxcd/flux2/pull/6026)
- \[release/v2.9.x] fix: restrict `allow-webhooks` netpol to receiver port by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6029](https://github.com/fluxcd/flux2/pull/6029)
- Update toolkit components by [@&#8203;fluxcdbot](https://github.com/fluxcdbot) in [#&#8203;6031](https://github.com/fluxcd/flux2/pull/6031)

**Full Changelog**: <https://github.com/fluxcd/flux2/compare/v2.9.3...v2.9.4>

</details>

<details>
<summary>element-hq/lk-jwt-service (ghcr.io/element-hq/lk-jwt-service)</summary>

### [`v0.6.0`](https://github.com/element-hq/lk-jwt-service/releases/tag/v0.6.0)

[Compare Source](https://github.com/element-hq/lk-jwt-service/compare/v0.5.0...v0.6.0)

### Delegation of delayed leave events

This release adds support for delegating delayed leave events to the service via the new `/delegate_delayed_leave` endpoint. This spares clients having to maintain their dead man's switch themselves and improves the mechanism's accuracy. Delegated events can be persisted across service restarts using a new optional storage backend based on Redis.

In a related change, the previously introduced `delay_cs_api_url` parameter was deprecated on all endpoints. For increased security, the service now ignores this parameter entirely and instead resolves the C-S API location using `.well-known` discovery. Homeserver admins should make sure to configure `.well-known` discovery appropriately.

Further noteworthy changes include a new health check endpoint `/healthz` and improved test coverage.

> \[!IMPORTANT]
> As we continue progressing on [MSC4195](https://github.com/matrix-org/matrix-spec-proposals/pull/4195), the service will undergo further breaking changes. Specifically, the endpoints the service currently provides will be integrated into the Client-Server API to be served by the home server in future. For Synapse, we're planning to run the service as a sidecar application service to which Synapse will proxy incoming requests via [MSC4512](https://github.com/matrix-org/matrix-spec-proposals/pull/4512). Other homeservers can choose to follow this approach if they want to reuse the service implementation.
>
> On a related note, we also have a Rust rewrite in flight ([#&#8203;197](https://github.com/element-hq/lk-jwt-service/pull/197)). This won't impact the service's external interface but will change the way the service is built.

#### Docker image

The service is available as a Docker image from the [GitHub Container Registry](https://github.com/element-hq/lk-jwt-service/pkgs/container/lk-jwt-service).

```
docker pull ghcr.io/element-hq/lk-jwt-service:0.6.0
```

#### Precompiled binaries

The service is available as static precompiled binaries for amd64 and arm64 on linux attached to this release below.

#### What's Changed

- feat: healthcheck for container environments by [@&#8203;Ninos](https://github.com/Ninos) in [#&#8203;186](https://github.com/element-hq/lk-jwt-service/pull/186)
- Delegated MatrixRTC leave events via delayed events (MSC4140) by [@&#8203;fkwp](https://github.com/fkwp) in [#&#8203;181](https://github.com/element-hq/lk-jwt-service/pull/181)
- feat(healthcheck): error messages & use `localhost` instead of static ip (`ipv4` & `ipv6` compatibility) by [@&#8203;Ninos](https://github.com/Ninos) in [#&#8203;189](https://github.com/element-hq/lk-jwt-service/pull/189)
- Deprecate CS-API URL parameters and use .well-known discovery instead by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;188](https://github.com/element-hq/lk-jwt-service/pull/188)
- Update element-hq/setup-ess-cluster-action digest to [`23c5b95`](https://github.com/element-hq/lk-jwt-service/commit/23c5b95) by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;192](https://github.com/element-hq/lk-jwt-service/pull/192)
- Add job persistence layer using Redis by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;187](https://github.com/element-hq/lk-jwt-service/pull/187)
- Map restart errors to Aborted rather than Disconnected by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;191](https://github.com/element-hq/lk-jwt-service/pull/191)
- Unbreak the CI by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;194](https://github.com/element-hq/lk-jwt-service/pull/194)
- Update all non-major dependencies by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;193](https://github.com/element-hq/lk-jwt-service/pull/193)
- Add early black-box integration tests by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;195](https://github.com/element-hq/lk-jwt-service/pull/195)
- Expand the existing integration tests to the remaining endpoints by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;196](https://github.com/element-hq/lk-jwt-service/pull/196)
- Add black-box tests for token generation by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;198](https://github.com/element-hq/lk-jwt-service/pull/198)
- Add black-box tests for LIVEKIT\_INSECURE\_SKIP\_VERIFY\_TLS by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;199](https://github.com/element-hq/lk-jwt-service/pull/199)
- Add black-box tests for delayed event delegation by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;200](https://github.com/element-hq/lk-jwt-service/pull/200)
- Avoid setting disconnectReason to null in black-box tests by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;201](https://github.com/element-hq/lk-jwt-service/pull/201)
- Allow participants to update their own metadata by [@&#8203;basnijholt](https://github.com/basnijholt) in [#&#8203;202](https://github.com/element-hq/lk-jwt-service/pull/202)
- Update module github.com/google/cel-go to v0.29.0 \[SECURITY] by [@&#8203;renovate](https://github.com/renovate)\[bot] in [#&#8203;204](https://github.com/element-hq/lk-jwt-service/pull/204)
- Add status badges by [@&#8203;Johennes](https://github.com/Johennes) in [#&#8203;211](https://github.com/element-hq/lk-jwt-service/pull/211)

#### New Contributors

- [@&#8203;Ninos](https://github.com/Ninos) made their first contribution in [#&#8203;186](https://github.com/element-hq/lk-jwt-service/pull/186)
- [@&#8203;Johennes](https://github.com/Johennes) made their first contribution in [#&#8203;188](https://github.com/element-hq/lk-jwt-service/pull/188)
- [@&#8203;basnijholt](https://github.com/basnijholt) made their first contribution in [#&#8203;202](https://github.com/element-hq/lk-jwt-service/pull/202)

**Full Changelog**: <https://github.com/element-hq/lk-jwt-service/compare/v0.5.0...v0.6.0>

</details>

<details>
<summary>element-hq/synapse (ghcr.io/element-hq/synapse)</summary>

### [`v1.159.0`](https://github.com/element-hq/synapse/releases/tag/v1.159.0)

[Compare Source](https://github.com/element-hq/synapse/compare/v1.158.0...v1.159.0)

Changelog: <https://github.com/element-hq/synapse/blob/release-v1.159/CHANGES.md>

### [`v1.158.0`](https://github.com/element-hq/synapse/releases/tag/v1.158.0)

[Compare Source](https://github.com/element-hq/synapse/compare/v1.157.2...v1.158.0)

Changelog: <https://github.com/element-hq/synapse/blob/release-v1.158/CHANGES.md>

</details>

<details>
<summary>fluxcd/notification-controller (ghcr.io/fluxcd/notification-controller)</summary>

### [`v1.9.3`](https://github.com/fluxcd/notification-controller/releases/tag/v1.9.3)

[Compare Source](https://github.com/fluxcd/notification-controller/compare/v1.9.2...v1.9.3)

#### Changelog

[v1.9.3 changelog](https://github.com/fluxcd/notification-controller/blob/v1.9.3/CHANGELOG.md)

#### Container images

- `docker.io/fluxcd/notification-controller:v1.9.3`
- `ghcr.io/fluxcd/notification-controller:v1.9.3`

Supported architectures: `linux/amd64`, `linux/arm64` and `linux/arm/v7`.

The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the [security documentation](https://fluxcd.io/flux/security/).

</details>

<details>
<summary>fluxcd/source-controller (ghcr.io/fluxcd/source-controller)</summary>

### [`v1.9.4`](https://github.com/fluxcd/source-controller/releases/tag/v1.9.4)

[Compare Source](https://github.com/fluxcd/source-controller/compare/v1.9.3...v1.9.4)

#### Changelog

[v1.9.4 changelog](https://github.com/fluxcd/source-controller/blob/v1.9.4/CHANGELOG.md)

#### Container images

- `docker.io/fluxcd/source-controller:v1.9.4`
- `ghcr.io/fluxcd/source-controller:v1.9.4`

Supported architectures: `linux/amd64`, `linux/arm64` and `linux/arm/v7`.

The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the [security documentation](https://fluxcd.io/flux/security/).

</details>

<details>
<summary>kedacore/keda (keda)</summary>

### [`v2.20.2`](https://github.com/kedacore/keda/blob/HEAD/CHANGELOG.md#v2202)

[Compare Source](https://github.com/kedacore/keda/compare/v2.20.1...v2.20.2)

##### Improvements

- **General**: Introduce a dedicated `HPAActive` condition on `ScaledObject` mirroring the HPA's own `ScalingActive` status, so transient HPA metric gaps no longer flip the `Ready` condition to `False` ([#&#8203;7914](https://github.com/kedacore/keda/issues/7914))

##### Fixes

- **General**: Fix concurrent map writes panic in the shared root CA `CertPool` ([#&#8203;7910](https://github.com/kedacore/keda/issues/7910))
- **General**: Fix nil pointer dereference in AWS Secret Manager `TriggerAuthentication` when `awsSecretManager.credentials` is omitted and no `awsSecretManager.podIdentity` is set ([#&#8203;7927](https://github.com/kedacore/keda/issues/7927))
- **General**: Fix nil pointer dereference in `customScalingStrategy.GetEffectiveMaxScale` when `customScalingQueueLengthDeduction` is omitted; the optional field is now treated as zero deduction instead of panicking ([#&#8203;7798](https://github.com/kedacore/keda/issues/7798))
- **General**: Fix nil pointer dereference in `GetCurrentReplicas` when a Deployment/StatefulSet/ReplicaSet is returned from the informer cache with an undefaulted `spec.replicas`; a nil value is now treated as the Kubernetes default of 1 instead of panicking ([#&#8203;7863](https://github.com/kedacore/keda/issues/7863))
- **General**: Fix `ScaledJob` CRD validation to include "default" as a valid value for `scalingStrategy.strategy` ([#&#8203;7855](https://github.com/kedacore/keda/issues/7855))
- **General**: Guard `GetCurrentReplicas` against nil `Status.ScaleTargetGVKR` to prevent operator panics under the cache race documented in ([#&#8203;4389](https://github.com/kedacore/keda/issues/4389)) / ([#&#8203;4955](https://github.com/kedacore/keda/issues/4955))
- **General**: Restore core `""` API group in events RBAC so that client-go's event broadcaster can write legacy events ([#&#8203;7922](https://github.com/kedacore/keda/issues/7922))
- **General**: Restore gRPC reconnect backoff in the metrics service client; an unset `Backoff` in `WithConnectParams` disabled backoff and caused a zero-delay reconnect loop that flooded logs when keda-operator was unreachable ([#&#8203;7856](https://github.com/kedacore/keda/issues/7856))
- **General**: Share HTTP transports across scalers to reuse connection pools and avoid re-dial storms at high ScaledObject counts ([#&#8203;7789](https://github.com/kedacore/keda/issues/7789))
- **General**: Treat negative external metric values as zero to prevent incorrect HPA scaling ([#&#8203;7880](https://github.com/kedacore/keda/issues/7880))
- **Azure Blob Storage Scaler**: Fix `globPattern` never matching when written in path-style with a leading `/`, since blob names never have one ([#&#8203;6492](https://github.com/kedacore/keda/issues/6492))
- **MongoDB Scaler**: Disconnect the client when the initial `Ping` fails so the background topology-monitoring connections opened by `mongo.Connect` are not leaked ([#&#8203;5612](https://github.com/kedacore/keda/issues/5612))

</details>

<details>
<summary>paperclipinc/openclaw-operator (openclaw-operator)</summary>

### [`v0.39.0`](https://github.com/paperclipinc/openclaw-operator/blob/HEAD/CHANGELOG.md#0390-2026-08-12)

[Compare Source](https://github.com/paperclipinc/openclaw-operator/compare/v0.38.3...v0.39.0)

##### Features

- **mesh:** add a mesh provider abstraction and NetBird support ([#&#8203;594](https://github.com/paperclipinc/openclaw-operator/issues/594)) ([56824b3](https://github.com/paperclipinc/openclaw-operator/commit/56824b34756b45b9a8fc9b8a170eb2a97a9ec4de))
- **workspace:** add a configurable file update policy ([#&#8203;593](https://github.com/paperclipinc/openclaw-operator/issues/593)) ([83e9dfd](https://github.com/paperclipinc/openclaw-operator/commit/83e9dfdcce7d796991cf1488d67eec30b4ef50a3))

##### Bug Fixes

- complete the metrics pipeline (OTel endpoint, ServiceMonitor lifecycle, metrics ingress isolation) ([#&#8203;590](https://github.com/paperclipinc/openclaw-operator/issues/590)) ([2b79d1e](https://github.com/paperclipinc/openclaw-operator/commit/2b79d1eed264ef0c4379d273e20faef6ee3ad973))
- scope the operator-namespace cache entry to Secrets in namespaced mode ([#&#8203;591](https://github.com/paperclipinc/openclaw-operator/issues/591)) ([a74bab1](https://github.com/paperclipinc/openclaw-operator/commit/a74bab1960393bdf0ad41415902a10b9390611bb))

### [`v0.38.3`](https://github.com/paperclipinc/openclaw-operator/blob/HEAD/CHANGELOG.md#0383-2026-07-28)

[Compare Source](https://github.com/paperclipinc/openclaw-operator/compare/v0.38.2...v0.38.3)

##### Bug Fixes

- use fully-qualified Docker Hub image names to prevent ImageInspectError ([#&#8203;562](https://github.com/paperclipinc/openclaw-operator/issues/562)) ([8aabb56](https://github.com/paperclipinc/openclaw-operator/commit/8aabb56ee2e30708e48f50961b6c131508f81b71))

### [`v0.38.2`](https://github.com/paperclipinc/openclaw-operator/blob/HEAD/CHANGELOG.md#0382-2026-07-28)

[Compare Source](https://github.com/paperclipinc/openclaw-operator/compare/v0.38.1...v0.38.2)

##### Bug Fixes

- **service:** expose the managed metrics port alongside custom Service ports ([#&#8203;583](https://github.com/paperclipinc/openclaw-operator/issues/583)) ([6e22165](https://github.com/paperclipinc/openclaw-operator/commit/6e221655e6e4e97137781d608d8208c8f775d8d6))
- **statefulset:** hash rendered ConfigMap data so config changes roll the pod ([#&#8203;579](https://github.com/paperclipinc/openclaw-operator/issues/579)) ([5082152](https://github.com/paperclipinc/openclaw-operator/commit/508215234c53d8108a302e990c4268fee12dd20c))

</details>

<details>
<summary>renovatebot/renovate (renovate/renovate)</summary>

### [`v43.288.0`](https://github.com/renovatebot/renovate/releases/tag/43.288.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.287.0...43.288.0)

##### Features

- **exec:** support custom stream output writers ([#&#8203;44910](https://github.com/renovatebot/renovate/issues/44910)) ([5ff2229](https://github.com/renovatebot/renovate/commit/5ff2229e2709e5f9bc9429b41dc980fffc78be9a))
- **manager/pixi:** gate pixi.lock updates behind `allowedUnsafeExecutions` ([#&#8203;44939](https://github.com/renovatebot/renovate/issues/44939)) ([f60995a](https://github.com/renovatebot/renovate/commit/f60995a404a1766c302e6c5fbd615676ff7e27ba))

### [`v43.287.0`](https://github.com/renovatebot/renovate/releases/tag/43.287.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.286.1...43.287.0)

##### Features

- **copier:** convert ssh \_src\_path to https URL for datasource lookup ([#&#8203;44552](https://github.com/renovatebot/renovate/issues/44552)) ([932b7b2](https://github.com/renovatebot/renovate/commit/932b7b26b58911384e6f443203917700576dde83)), closes [#&#8203;44528](https://github.com/renovatebot/renovate/issues/44528)

##### Bug Fixes

- **github:** include `commitTrailers` in platform-native commits ([#&#8203;44918](https://github.com/renovatebot/renovate/issues/44918)) ([d32e38e](https://github.com/renovatebot/renovate/commit/d32e38ec2b7a73e6a299ab11c7fe7e996c8a4807))

##### Miscellaneous Chores

- **deps:** update dependency lint-staged to v17.1.1 (main) ([#&#8203;44935](https://github.com/renovatebot/renovate/issues/44935)) ([736438b](https://github.com/renovatebot/renovate/commit/736438b5e844bcff8c76ce640b8325d8f62f5261))
- **deps:** update dependency oxlint-tsgolint to v7 (main) ([#&#8203;44907](https://github.com/renovatebot/renovate/issues/44907)) ([1809104](https://github.com/renovatebot/renovate/commit/1809104c03920423c0fd2db6479cb9fc376e6c04))

### [`v43.286.1`](https://github.com/renovatebot/renovate/releases/tag/43.286.1)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.286.0...43.286.1)

##### Bug Fixes

- **deps:** update ghcr.io/renovatebot/base-image docker tag to v13.78.1 (main) ([#&#8203;44932](https://github.com/renovatebot/renovate/issues/44932)) ([648b7a8](https://github.com/renovatebot/renovate/commit/648b7a85b6aa04cebc338d45852a30614784e897))

### [`v43.286.0`](https://github.com/renovatebot/renovate/releases/tag/43.286.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.7...43.286.0)

##### Features

- **deps:** update ghcr.io/renovatebot/base-image docker tag to v13.78.0 (main) ([#&#8203;44931](https://github.com/renovatebot/renovate/issues/44931)) ([db1b150](https://github.com/renovatebot/renovate/commit/db1b150aa13ca5f1f72e43e3176fbdbe032f43ff))

##### Miscellaneous Chores

- **deps:** update dependency astral-sh/uv to v0.12.0 (main) ([#&#8203;44927](https://github.com/renovatebot/renovate/issues/44927)) ([5b56a5a](https://github.com/renovatebot/renovate/commit/5b56a5a3ba8b37551b204c19b901adb97bab0d0d))
- **deps:** update dependency tsdown to v0.22.13 (main) ([#&#8203;44925](https://github.com/renovatebot/renovate/issues/44925)) ([05f36d5](https://github.com/renovatebot/renovate/commit/05f36d512b412da0f4bf1be77c081839756d4797))
- **deps:** update dependency uv to v0.12.0 (main) ([#&#8203;44928](https://github.com/renovatebot/renovate/issues/44928)) ([9fe51ed](https://github.com/renovatebot/renovate/commit/9fe51ed0c855c976d2542be03b74bc169f2b1d08))

##### Build System

- **deps:** update opentelemetry-js monorepo (main) ([#&#8203;44930](https://github.com/renovatebot/renovate/issues/44930)) ([59dca2b](https://github.com/renovatebot/renovate/commit/59dca2b8b8e98e0bff3bb874fa941da0d1d70f96))

### [`v43.285.7`](https://github.com/renovatebot/renovate/releases/tag/43.285.7)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.6...43.285.7)

##### Bug Fixes

- **packagist:** Throw on transient errors ([#&#8203;44328](https://github.com/renovatebot/renovate/issues/44328)) ([2a5308b](https://github.com/renovatebot/renovate/commit/2a5308bafb162579e12a0019c691fdf88fc85484))

##### Code Refactoring

- **types:** make `currentVersionTimestamp` a Timestamp ([#&#8203;44917](https://github.com/renovatebot/renovate/issues/44917)) ([12f5fde](https://github.com/renovatebot/renovate/commit/12f5fde66e3ea6cc6ccd5797cfa48c945469629e))

### [`v43.285.6`](https://github.com/renovatebot/renovate/releases/tag/43.285.6)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.5...43.285.6)

##### Bug Fixes

- **deps:** update ghcr.io/renovatebot/base-image docker tag to v13.77.9 (main) ([#&#8203;44919](https://github.com/renovatebot/renovate/issues/44919)) ([18c59f8](https://github.com/renovatebot/renovate/commit/18c59f8d95b9cb93beb7dc9ccacf359c54cff867))

### [`v43.285.5`](https://github.com/renovatebot/renovate/releases/tag/43.285.5)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.4...43.285.5)

##### Bug Fixes

- **datasource/go:** resolve `sourceUrl` from `GOPROXY` `Origin` ([#&#8203;44902](https://github.com/renovatebot/renovate/issues/44902)) ([feeb236](https://github.com/renovatebot/renovate/commit/feeb23667cd631186afbed1c8550d1d3a6391b77))

##### Documentation

- **manager:** indicate where `lockFileMaintenance` runs external commands ([#&#8203;44914](https://github.com/renovatebot/renovate/issues/44914)) ([5ffc308](https://github.com/renovatebot/renovate/commit/5ffc308673f8d3ee3b4a9b0a13a14c2d57618eed))

##### Miscellaneous Chores

- **deps:** update dependency [@&#8203;biomejs/biome](https://github.com/biomejs/biome) to v2.5.5 (main) ([#&#8203;44906](https://github.com/renovatebot/renovate/issues/44906)) ([9c1fe2c](https://github.com/renovatebot/renovate/commit/9c1fe2c8a9c68c527355358b7f1cf2dafe22d0ea))
- **deps:** update dependency astral-sh/uv to v0.11.33 (main) ([#&#8203;44912](https://github.com/renovatebot/renovate/issues/44912)) ([e41e315](https://github.com/renovatebot/renovate/commit/e41e31525a711de936b209ca344ccd1f98abbbda))
- **deps:** update dependency oxlint-tsgolint to v0.25.0 (main) ([#&#8203;44424](https://github.com/renovatebot/renovate/issues/44424)) ([196101a](https://github.com/renovatebot/renovate/commit/196101a6bb07ea081416b6cf040e0032d3956e0b))
- **deps:** update dependency uv to v0.11.33 (main) ([#&#8203;44913](https://github.com/renovatebot/renovate/issues/44913)) ([9c7d468](https://github.com/renovatebot/renovate/commit/9c7d468c3d6504a602a41872e79a35c9cff7b3e7))

##### Code Refactoring

- move checkMinimumReleaseAge to lib/util/minimum-release-age.ts ([#&#8203;44904](https://github.com/renovatebot/renovate/issues/44904)) ([5173de0](https://github.com/renovatebot/renovate/commit/5173de026b96db955036a1e7a78947fbf6e64d45))

### [`v43.285.4`](https://github.com/renovatebot/renovate/releases/tag/43.285.4)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.3...43.285.4)

##### Build System

- **deps:** update dependency re2 to v1.26.1 (main) ([#&#8203;44903](https://github.com/renovatebot/renovate/issues/44903)) ([48399bc](https://github.com/renovatebot/renovate/commit/48399bc198062078654d365c997087da10e877f6))

### [`v43.285.3`](https://github.com/renovatebot/renovate/releases/tag/43.285.3)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.2...43.285.3)

##### Build System

- **deps:** update dependency p-map to v7.0.6 (main) ([#&#8203;44893](https://github.com/renovatebot/renovate/issues/44893)) ([352c728](https://github.com/renovatebot/renovate/commit/352c728cab56f5f8366054d5db0ec3f7470756f7))

### [`v43.285.2`](https://github.com/renovatebot/renovate/releases/tag/43.285.2)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.1...43.285.2)

##### Bug Fixes

- **deps:** update ghcr.io/renovatebot/base-image docker tag to v13.77.8 (main) ([#&#8203;44892](https://github.com/renovatebot/renovate/issues/44892)) ([dfc9a0a](https://github.com/renovatebot/renovate/commit/dfc9a0ae9f3514f4b5f4843b60de160f785936f7))

### [`v43.285.1`](https://github.com/renovatebot/renovate/releases/tag/43.285.1)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.285.0...43.285.1)

##### Bug Fixes

- **gerrit:** use max available Code-Review vote value for autoApprove ([#&#8203;44425](https://github.com/renovatebot/renovate/issues/44425)) ([d83651c](https://github.com/renovatebot/renovate/commit/d83651c8def6d272111ef5651f449e4659eab66a))

##### Miscellaneous Chores

- **deps:** update dependency [@&#8203;smithy/util-stream](https://github.com/smithy/util-stream) to v4.7.11 (main) ([#&#8203;44891](https://github.com/renovatebot/renovate/issues/44891)) ([707c440](https://github.com/renovatebot/renovate/commit/707c440a1bb460880658242bfbccf2637d29a068))

### [`v43.285.0`](https://github.com/renovatebot/renovate/releases/tag/43.285.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.284.1...43.285.0)

##### Features

- **managers/mise:** set `depType` for tools and task tools ([#&#8203;44868](https://github.com/renovatebot/renovate/issues/44868)) ([0ad45c5](https://github.com/renovatebot/renovate/commit/0ad45c5484d636b8352fb283d25181c45b9d68ec))

### [`v43.284.1`](https://github.com/renovatebot/renovate/releases/tag/43.284.1)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.284.0...43.284.1)

##### Bug Fixes

- **post-upgrade:** skip executable detection for directories ([#&#8203;44884](https://github.com/renovatebot/renovate/issues/44884)) ([3f46080](https://github.com/renovatebot/renovate/commit/3f4608037632930c43dd37f37f1797b7ed5dc4e9))

##### Miscellaneous Chores

- **vscode:** enable TypeScript 7 ([#&#8203;44883](https://github.com/renovatebot/renovate/issues/44883)) ([27b4832](https://github.com/renovatebot/renovate/commit/27b48322279047a0ae43771b3c0541eaca363854))

### [`v43.284.0`](https://github.com/renovatebot/renovate/releases/tag/43.284.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.283.0...43.284.0)

##### Features

- **github-actions:** update mise checksums ([#&#8203;44876](https://github.com/renovatebot/renovate/issues/44876)) ([7700d62](https://github.com/renovatebot/renovate/commit/7700d62238155e8328998652d8839f78e2d3af94))

##### Tests

- **util/git:** reference default branch ([#&#8203;44877](https://github.com/renovatebot/renovate/issues/44877)) ([a44bbfa](https://github.com/renovatebot/renovate/commit/a44bbfadcfe9a5d6cf2d2ede08aba71196eb8c39))

### [`v43.283.0`](https://github.com/renovatebot/renovate/releases/tag/43.283.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.282.0...43.283.0)

##### Features

- add `commitTrailers` option ([#&#8203;44651](https://github.com/renovatebot/renovate/issues/44651)) ([ddbbb68](https://github.com/renovatebot/renovate/commit/ddbbb687f965cf1791a5185a66c42dce79ab35f7))

### [`v43.282.0`](https://github.com/renovatebot/renovate/releases/tag/43.282.0)

[Compare Source](https://github.com/renovatebot/renovate/compare/43.281.1...43.282.0)

##### Features

- **manager/mise:** run mise lock in safe mode without allowedUnsafeExecutions ([#&#8203;44749](https://github.com/renovatebot/renovate/issues/44749)) ([94f0219](https://github.com/renovatebot/renovate/commit/94f02196134cd7645d492e4fd962e382554be84c)), closes [jdx/mise#11146](https://github.com/jdx/mise/issues/11146) [jdx/mise#11145](https://github.com/jdx/mise/issues/11145) [jdx/mise#11151](https://github.com/jdx/mise/issues/11151)

##### Bug Fixes

- **deps:** update ghcr.io/renovatebot/base-image docker tag to v13.77.7 (main) ([#&#8203;44872](https://github.com/renovatebot/renovate/issues/44872)) ([8971306](https://github.com/renovatebot/renovate/commit/8971306954446a657031571f5c3fb54d9973b859))

##### Documentation

- update references to jaegertracing/jaeger to v2.20.0 (main) ([#&#8203;44864](https://github.com/renovatebot/renovate/issues/44864)) ([20a51f8](https://github.com/renovatebot/renovate/commit/20a51f8734aaa4a057d10f8ea05e258d72730a33))
- update references to otel/opentelemetry-collector-contrib to v0.157.0 (main) ([#&#8203;44865](https://github.com/renovatebot/renovate/issues/44865)) ([1cae2cc](https://github.com/renovatebot/renovate/commit/1cae2cc16db734e08895fd18af833f9c0d19d3a4))
- update references to python to [`5f1cdbc`](https://github.com/renovatebot/renovate/commit/5f1cdbc) (main) ([#&#8203;44863](https://github.com/renovatebot/renovate/issues/44863)) ([f9532ad](https://github.com/renovatebot/renovate/commit/f9532ad1db5b23c68b9bff9e70aa91c392053ebf))
- update references to renovate/renovate (main) ([#&#8203;44866](https://github.com/renovatebot/renovate/issues/44866)) ([011c0b4](https://github.com/renovatebot/renovate/commit/011c0b4890b7732f9caa0544eecdc6b415354715))
- update references to renovatebot/github-action to v46.1.21 (main) ([#&#8203;44870](https://github.com/renovatebot/renovate/issues/44870)) ([5c7f980](https://github.com/renovatebot/renovate/commit/5c7f980ea6d15b012a4e771a40d7feaf7119ab87))

##### Miscellaneous Chores

- **deps:** lock file maintenance (main) ([#&#8203;44867](https://github.com/renovatebot/renovate/issues/44867)) ([34e99c6](https://github.com/renovatebot/renovate/commit/34e99c60e9dd362af4cc05a53d02c6c8444bbeb4))
- **deps:** update dependency [@&#8203;smithy/util-stream](https://github.com/smithy/util-stream) to v4.7.10 (main) ([#&#8203;44804](https://github.com/renovatebot/renovate/issues/44804)) ([8333627](https://github.com/renovatebot/renovate/commit/8333627c1f5fde7737cb16a6b9d525fdc555a66e))
- **deps:** update dependency pnpm to v11.15.1 (main) ([#&#8203;44862](https://github.com/renovatebot/renovate/issues/44862)) ([d701006](https://github.com/renovatebot/renovate/commit/d7010066a2ee47a4c92429acc6f6cf8e0c872bd9))
- **deps:** update dependency tsdown to v0.22.12 (main) ([#&#8203;44861](https://github.com/renovatebot/renovate/issues/44861)) ([9d3b990](https://github.com/renovatebot/renovate/commit/9d3b990782f350ecdc094a53d033ad35c2b60713))
- **deps:** update ghcr.io/containerbase/devcontainer docker tag to v14.13.11 (main) ([#&#8203;44869](https://github.com/renovatebot/renovate/issues/44869)) ([2249f86](https://github.com/renovatebot/renovate/commit/2249f8628dbafe40dfb584c84b78f2ee3a09fbe0))
- **deps:** update ghcr.io/containerbase/devcontainer docker tag to v14.13.12 (main) ([#&#8203;44871](https://github.com/renovatebot/renovate/issues/44871)) ([c15ebab](https://github.com/renovatebot/renovate/commit/c15ebab6c22006b3a5ca5a6f360bd260bfe361ea))

</details>

<details>
<summary>VictoriaMetrics/helm-charts (victoria-metrics-k8s-stack)</summary>

### [`v0.91.2`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.91.2)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.91.1...victoria-metrics-k8s-stack-0.91.2)

### Release notes for version 0.91.2

**Release date:** 22 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.150.0](https://img.shields.io/badge/v1.150.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11500) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- fixed sync-job `OUTPUT=-` generating malformed YAML for ConfigMap manifests. See [#&#8203;3169](https://github.com/VictoriaMetrics/helm-charts/issues/3169)

### [`v0.91.1`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.91.1)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.91.0...victoria-metrics-k8s-stack-0.91.1)

### Release notes for version 0.91.1

**Release date:** 21 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.150.0](https://img.shields.io/badge/v1.150.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11500) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- fixed sync-job ignoring `defaultRules.groups.<name>.spec` overrides (e.g. `interval`). Per-group spec fields are now merged on top of the common group spec and applied to the generated VMRule. See [#&#8203;3166](https://github.com/VictoriaMetrics/helm-charts/issues/3166)

### [`v0.91.0`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.91.0)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.90.2...victoria-metrics-k8s-stack-0.91.0)

### Release notes for version 0.91.0

**Release date:** 17 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.150.0](https://img.shields.io/badge/v1.150.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11500) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- bump version of VM components to [v1.150.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.150.0)
- fixed sync-job deleting all rules and dashboards on upstream HTTP errors. The job now aborts on any fetch failure instead of treating missing data as orphaned resources. HTTP 429 is now retried like 5xx errors. See [#&#8203;3163](https://github.com/VictoriaMetrics/helm-charts/issues/3163)

### [`v0.90.2`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.90.2)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.90.1...victoria-metrics-k8s-stack-0.90.2)

### Release notes for version 0.90.2

**Release date:** 08 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.149.0](https://img.shields.io/badge/v1.149.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11490) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- fixed sync-job ignoring `defaultRules.rules.<name>.enabled: false`, causing disabled rules to reappear in generated VMRule resources. See [#&#8203;3151](https://github.com/VictoriaMetrics/helm-charts/issues/3151)

### [`v0.90.1`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.90.1)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.90.0...victoria-metrics-k8s-stack-0.90.1)

### Release notes for version 0.90.1

**Release date:** 07 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.149.0](https://img.shields.io/badge/v1.149.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11490) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- fixed sync-job silently ignoring extra fields set under `defaultRules.group.spec` (such as `params` and `interval`) and `defaultRules.rules.*.spec`. The configured values were not applied to the generated VMRule resources. See [#&#8203;3149](https://github.com/VictoriaMetrics/helm-charts/issues/3149)

### [`v0.90.0`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.90.0)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.89.0...victoria-metrics-k8s-stack-0.90.0)

### Release notes for version 0.90.0

**Release date:** 06 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.149.0](https://img.shields.io/badge/v1.149.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11490) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- added `vldistributed` as an alternative to `vlsingle` and `vlcluster` for multi-zone VictoriaLogs deployments. Set `vldistributed.enabled: true` (mutually exclusive with `vlsingle` and `vlcluster`). The `victorialogs-cluster` dashboard and VL alert rules are enabled automatically when `vldistributed.enabled` is set.

### [`v0.89.0`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.89.0)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.88.0...victoria-metrics-k8s-stack-0.89.0)

### Release notes for version 0.89.0

**Release date:** 05 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.149.0](https://img.shields.io/badge/v1.149.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11490) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- bump version of VM components to [v1.149.0](https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.149.0)

### [`v0.88.0`](https://github.com/VictoriaMetrics/helm-charts/releases/tag/victoria-metrics-k8s-stack-0.88.0)

[Compare Source](https://github.com/VictoriaMetrics/helm-charts/compare/victoria-metrics-k8s-stack-0.87.0...victoria-metrics-k8s-stack-0.88.0)

### Release notes for version 0.88.0

**Release date:** 04 Aug 2026

![Helm: v3](https://img.shields.io/badge/Helm-v3.14%2B-informational?color=informational\&logo=helm\&link=https%3A%2F%2Fgithub.com%2Fhelm%2Fhelm%2Freleases%2Ftag%2Fv3.14.0) ![AppVersion: v1.148.0](https://img.shields.io/badge/v1.148.0-success?logo=VictoriaMetrics\&labelColor=gray\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fvictoriametrics%2Fchangelog%2F%23v11480) ![VM Operator: 0.67.2](https://img.shields.io/badge/VM_Operator-0.67.2-success?logo=kubernetes\&logoColor=7B3FE4\&labelColor=white\&link=https%3A%2F%2Fdocs.victoriametrics.com%2Fhelm%2Fvictoria-metrics-operator%2Fchangelog%2F%230672)

- added `syncJob.extraVolumes` and `syncJob.extraVolumeMounts` to allow mounting custom CA certificates into the sync-job pod. To trust a self-signed certificate, create a Secret with the CA cert, mount it via these fields, and set `SSL_CERT_FILE=/path/to/ca.crt` in `syncJob.env`. See [#&#8203;3127](https://github.com/VictoriaMetrics/helm-charts/issues/3127)
- added per-component `namespaceOverride` to all operator-managed components (`vmsingle`, `vmcluster`, `vmagent`, `vmalert`, `alertmanager`, `vmauth`, `vlsingle`, `vlcluster`, `vlagent`, `vtsingle`, `vtcluster`). Setting `<component>.namespaceOverride: <ns>` deploys that CR, its Ingress, and its HTTPRoute into a separate namespace while keeping the rest of the stack in the release namespace. Cross-component FQDNs are updated automatically. See [#&#8203;3113](https://github.com/VictoriaMetrics/helm-charts/issues/3113)
- restored `VM_ENABLEDPROMETHEUSCONVERTER_*` env vars when `operator.disable_prometheus_converter: true` and removed Prometheus CRD names (`PodMonitor`, `ServiceMonitor`, etc.) from `--controller.disableReconcileFor`. In operator v0.68.x the `controllersByName` map does not include Prometheus CRD names — passing them causes the operator to fail on startup.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yODEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjI4MS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: https://forgejo.maio-tech.com/Sammy/Servers/pulls/9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant