-
Notifications
You must be signed in to change notification settings - Fork 17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update hashicorp/consul docker tag to v1.20.2 #78
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/hashicorp-consul-1.x
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Branch automerge failureThis PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.
|
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
7 times, most recently
from
July 24, 2023 03:06
4a3e83d
to
b30c242
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
4 times, most recently
from
August 8, 2023 16:15
59c4cc9
to
e336c1b
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.16.0
chore(deps): update hashicorp/consul docker tag to v1.16.1
Aug 8, 2023
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
September 5, 2023 06:52
deb46ba
to
912d508
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
3 times, most recently
from
September 20, 2023 00:14
fd8aa94
to
d97884e
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.16.1
chore(deps): update hashicorp/consul docker tag to v1.16.2
Sep 20, 2023
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
September 25, 2023 04:04
d97884e
to
03606c9
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
October 31, 2023 19:51
03606c9
to
b24b891
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.16.2
chore(deps): update hashicorp/consul docker tag to v1.16.3
Oct 31, 2023
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
November 3, 2023 19:18
32ad394
to
367cafd
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.16.3
chore(deps): update hashicorp/consul docker tag to v1.17.0
Nov 3, 2023
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
November 6, 2023 04:48
367cafd
to
186e118
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
November 21, 2023 09:35
186e118
to
01cdf46
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
December 15, 2023 00:16
01cdf46
to
2431514
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
July 12, 2024 00:23
ca1a4ba
to
a88c4de
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.19.0
chore(deps): update hashicorp/consul docker tag to v1.19.1
Jul 12, 2024
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
August 23, 2024 23:15
a88c4de
to
f938058
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
August 27, 2024 21:33
b7b87c7
to
9ef120e
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.19.1
chore(deps): update hashicorp/consul docker tag to v1.19.2
Aug 27, 2024
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
3 times, most recently
from
September 16, 2024 03:02
ad9afd2
to
2db1de3
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
4 times, most recently
from
October 15, 2024 03:55
111c3c1
to
de8797a
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.19.2
chore(deps): update hashicorp/consul docker tag to v1.20.0
Oct 15, 2024
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
October 21, 2024 04:19
a1a9dd5
to
87d8c2e
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
October 30, 2024 19:34
87d8c2e
to
fcf1c84
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.20.0
chore(deps): update hashicorp/consul docker tag to v1.20.1
Oct 30, 2024
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
November 13, 2024 10:12
fcf1c84
to
cb03d9e
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
November 25, 2024 21:24
8ed912e
to
9238c8b
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
2 times, most recently
from
December 9, 2024 04:22
7120dc0
to
e3251c1
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
December 23, 2024 21:51
e3251c1
to
2aa10d8
Compare
renovate
bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
January 6, 2025 07:47
2aa10d8
to
4d5fdc9
Compare
renovate
bot
changed the title
chore(deps): update hashicorp/consul docker tag to v1.20.1
chore(deps): update hashicorp/consul docker tag to v1.20.2
Jan 6, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.11.2
->1.20.2
Release Notes
hashicorp/consul (hashicorp/consul)
v1.20.2
Compare Source
1.20.2 (December 26, 2024)
SECURITY:
github.com/golang-jwt/jwt/v4
to v4.5.1 to address GHSA-29wx-vh33-7x7r. [GH-21951]golang.org/x/crypto
to v0.31.0 to address GO-2024-3321. [GH-22001]golang.org/x/net
to v0.33.0 to address GO-2024-3333. [GH-22021]registry.access.redhat.com/ubi9-minimal
image to 9.5 to address CVE-2024-3596,CVE-2024-2511,CVE-2024-26458. [GH-22011]FEATURES:
BUG FIXES:
v1.20.1
Compare Source
BREAKING CHANGES:
HttpConnectionManager.normalize_path
by default on inbound traffic to mesh proxies. This resolves CVE-2024-10005. [GH-21816]SECURITY:
contains
andignoreCase
to L7 Intentions HTTP header matching criteria to support configuration resilient to variable casing and multiple values. This resolves CVE-2024-10006. [GH-21816]http.incoming.requestNormalization
to Mesh configuration entry to support inbound service traffic request normalization. This resolves CVE-2024-10005 and CVE-2024-10006. [GH-21816]IMPROVEMENTS:
v1.20.0
Compare Source
SECURITY:
CVE-2024-34155 [GH-21705]
v1.55.5 or higher
. This resolves CVEsCVE-2020-8911 and
CVE-2020-8912. [GH-21684]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
v1.19.2
Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
v1.19.1
Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
This affected Nomad integrations with Consul. [GH-21361]
tag.name.service.consul
, were being disregarded. [GH-21361]that was always being logged on each prepared query evaluation. [GH-21381]
v1.19.0
Compare Source
BREAKING CHANGES:
consul
element in the metric name have been removed. Please use the same metric without the secondconsul
instead. As an example instead ofconsul.consul.state.config_entries
useconsul.state.config_entries
[GH-20674]SECURITY:
1.27.5 and 1.28.3
. This resolves CVECVE-2024-32475 (
auto_sni
). [GH-21017]v0.18.7 or higher
. This resolves CVECVE-2020-8559. [GH-21017]
FEATURES:
Use
v1dns
in theexperiments
agent config to disable.The legacy server will be removed in a future release of Consul.
See the Consul 1.19.x Release Notes for removed DNS features. [GH-20715]
IMPROVEMENTS:
github.com/envoyproxy/go-control-plane
to 0.12.0. [GH-20973]consul-dataplane
now accepts partition, namespace, token as metadata to default those query parameters.consul-dataplane
v1.5+ will send this information automatically. [GH-20899]consul snapshot decode
CLI command to output a JSON object stream of all the snapshots data. [GH-20824]telemetry.disable_per_tenancy_usage_metrics
in agent configuration to disable setting tenancy labels on usage metrics. This significantly decreases CPU utilization in clusters with many admin partitions or namespaces.DEPRECATIONS:
local_storage
,aws_storage
,azure_blob_storage
, andgoogle_storage
in snapshot agent configuration files are now deprecated. Use thebackup_destinations
config object instead.BUG FIXES:
v1.18.2
Compare Source
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
SECURITY:
alpine:3.19
. [GH-20897]vault/api
to v1.12.2 to address CVE-2024-28180(removes indirect dependency on impacted
go-jose.v2
) [GH-20910]CVE-2024-24787 and
CVE-2024-24788 [GH-21074]
1.26.8, 1.27.4, 1.27.5, 1.28.2 and 1.28.3
. This resolves CVEsCVE-2024-27919 (
http2
). [GH-20956] and CVE-2024-32475 (auto_sni
). [GH-21030]v0.18.7 or higher
. This resolves CVECVE-2020-8559. [GH-21034]
1.21.9
. This resolves CVECVE-2023-45288 (
http2
). [GH-20956]v0.24.0
. This resolves CVECVE-2023-45288 (
x/net
). [GH-20956]IMPROVEMENTS:
BUG FIXES:
DefaultForFailover
.DNS requests against sameness groups without this field set will now error as intended.
v1.18.1
Compare Source
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
BREAKING CHANGES:
SECURITY:
google.golang.org/protobuf
to v1.33.0 to address CVE-2024-24786. [GH-20801]alpine3.19
. This resolves CVEsCVE-2023-52425
CVE-2023-52426 [GH-20812]
1.21.8
. This resolves CVEsCVE-2024-24783 (
crypto/x509
).CVE-2023-45290 (
net/http
).CVE-2023-45289 (
net/http
,net/http/cookiejar
).CVE-2024-24785 (
html/template
).CVE-2024-24784 (
net/mail
). [GH-20812]IMPROVEMENTS:
backup_destinations
config file object.BUG FIXES:
v1.18.0
Compare Source
BREAKING CHANGES:
telemetry.disable_hostname
when determining whether to prefix gauge-type metrics with the hostname of the Consul agent. Previously, if only the default metric sink was enabled, this configuration was ignored and always treated astrue
, even though its default value isfalse
. [GH-20312]SECURITY:
golang.org/x/crypto
to v0.17.0 to address CVE-2023-48795. [GH-20023]FEATURES:
Use
v2dns
in theexperiments
agent config to enable.It will automatically be enabled when using the
resource-apis
(Catalog v2) experiment.The new DNS implementation will be the default in Consul 1.19.
See the Consul 1.18.x Release Notes for deprecated DNS features. [GH-20643]
IMPROVEMENTS:
envoy.config.core.v3.HeaderValueOption.append
. [GH-20078]envoy.config.route.v3.HeaderMatcher.safe_regex_match
andenvoy.type.matcher.v3.RegexMatcher.google_re2
. [GH-20013]BUG FIXES:
v1.17.3
Compare Source
SECURITY:
FEATURES:
exported-services
to list all services exported and their consumers. Refer to the CLI docs for more information. [GH-20331]IMPROVEMENTS:
Internal.ServiceDump
when mesh gateway is not used. [GH-20168]Internal.ServiceDump
watch from proxycfg [GH-20168]CaseInsensitive
flag to service-routers that allows paths and path prefixes to ignore URL upper and lower casing. [GH-19647]BUG FIXES:
http
protocol fails with a protocol-mismatch error. [GH-20481]v1.17.2
Compare Source
KNOWN ISSUES:
SECURITY:
ubi9-minimal:9.3
as the base image. [GH-20014]IMPROVEMENTS:
match_subject_alt_names
in favor ofmatch_typed_subject_alt_names
. [GH-19954]envoy.config.router.v3.WeightedCluster.total_weight
. [GH-20011]envoy.config.cluster.v3.Cluster.http_protocol_options
[GH-20010]envoy.config.cluster.v3.Cluster.http2_protocol_options
,envoy.config.bootstrap.v3.Admin.access_log_path
[GH-19940]envoy.extensions.filters.http.lua.v3.Lua.inline_code
[GH-20012]DEPRECATIONS:
-admin-access-log-path
flag fromconsul connect envoy
command in favor of:-admin-access-log-config
. [GH-19943]BUG FIXES:
v1.17.1
Compare Source
SECURITY:
github.com/golang-jwt/jwt/v4
to v4.5.0 to address PRISMA-2022-0270. [GH-19705]CVE-2023-45283: (
path/filepath
) recognize ??\ as a Root Local Device path prefix (Windows)CVE-2023-45284: recognize device names with trailing spaces and superscripts (Windows)
CVE-2023-39326: (
net/http
) limit chunked data overheadCVE-2023-45285: (
cmd/go
) go get may unexpectedly fallback to insecure git [GH-19840]FEATURES:
peering exported-services
to list services exported to a peer . Refer to the CLI docs for more information. [GH-19821]IMPROVEMENTS:
stats_flush_interval
to 60 seconds when using the Consul Telemetry Collector, unless custom stats sink are present or an explicit flush interval is configured. [GH-19663]BUG FIXES:
xds_fetch_timeout_ms
option to proxy registrations that allows users to prevent endpoints from dropping when they have proxies with a large number of upstreams. [GH-19871]v1.17.0
Compare Source
BREAKING CHANGES:
DEPRECATIONS:
-admin-access-log-path
flag fromconsul connect envoy
command in favor of:-admin-access-log-config
. [GH-15946]SECURITY:
golang.org/x/net
to v0.17.0 to address CVE-2023-39325/ CVE-2023-44487(
x/net/http2
). [GH-19225]This resolves vulnerability CVE-2023-39325
/ CVE-2023-44487(
net/http
). [GH-19225]google.golang.org/grpc
to 1.56.3.This resolves vulnerability CVE-2023-44487. [GH-19414]
FEATURE PREVIEW: Catalog v2
This release provides the ability to preview Consul's v2 Catalog and Resource API if enabled. The new model supports
multi-port application deployments with only a single Envoy proxy. Note that the v1 and v2 catalogs are not cross
compatible, and not all Consul features are available within this v2 feature preview. See the v2 Catalog and Resource
API documentation for more information. The v2 Catalog and
Resources API should be considered a feature preview within this release and should not be used in production
environments.
Limitations
Significant Pull Requests
FEATURES:
acl.tokens.dns
config field which specifies the token used implicitly during dns checks. [GH-17936]bind-var
flag toconsul acl binding-rule
for templated policy variables. [GH-18719]consul acl templated-policy
commands to read, list and preview templated policies. [GH-18816]IMPROVEMENTS:
CheckRegisterOpts
to Agent API [GH-18943]Token
field toServiceRegisterOpts
type in Agent API [GH-18983]-templated-policy
,-templated-policy-file
,-replace-templated-policy
,-append-templated-policy
,-replace-templated-policy-file
,-append-templated-policy-file
and-var
flags for creating or updating tokens/roles. [GH-18708]tls.defaults.verify_server_hostname
configuration option. This specifies the default value for any interfaces that support theverify_server_hostname
option. [GH-17155]BUG FIXES:
/v1/catalog/services
endpoint [GH-18322]performance.grpc_keepalive_timeout
andperformance.grpc_keepalive_interval
now exist to allow for configuration on how often these dead connections will be cleaned up. [GH-19339]v1.16.6
Compare Source
SECURITY:
IMPROVEMENTS:
Internal.ServiceDump
when mesh gateway is not used. [GH-20168]Internal.ServiceDump
watch from proxycfg [GH-20168]BUG FIXES:
http
protocol fails with a protocol-mismatch error. [GH-20481]v1.16.5
Compare Source
KNOWN ISSUES:
SECURITY:
ubi9-minimal:9.3
as the base image. [GH-20014]IMPROVEMENTS:
match_subject_alt_names
in favor ofmatch_typed_subject_alt_names
. [GH-19954]envoy.config.router.v3.WeightedCluster.total_weight
. [GH-20011]envoy.config.cluster.v3.Cluster.http_protocol_options
[GH-20010]envoy.config.cluster.v3.Cluster.http2_protocol_options
,envoy.config.bootstrap.v3.Admin.access_log_path
[GH-19940]envoy.extensions.filters.http.lua.v3.Lua.inline_code
[GH-20012]BUG FIXES:
v1.16.4
Compare Source
SECURITY:
github.com/golang-jwt/jwt/v4
to v4.5.0 to address PRISMA-2022-0270. [GH-19705]CVE-2023-45283: (
path/filepath
) recognize ??\ as a Root Local Device path prefix (Windows)CVE-2023-45284: recognize device names with trailing spaces and superscripts (Windows)
CVE-2023-39326: (
net/http
) limit chunked data overheadCVE-2023-45285: (
cmd/go
) go get may unexpectedly fallback to insecure git [GH-19840]IMPROVEMENTS:
default ports of consul listed here - https://developer.hashicorp.com/consul/docs/install/ports [GH-18329]
stats_flush_interval
to 60 seconds when using the Consul Telemetry Collector, unless custom stats sink are present or an explicit flush interval is configured. [GH-19663]BUG FIXES:
xds_fetch_timeout_ms
option to proxy registrations that allows users to prevent endpoints from dropping when they have proxies with a large number of upstreams. [GH-19871]v1.16.3
Compare Source
SECURITY:
golang.org/x/net
to v0.17.0 to address CVE-2023-39325/ CVE-2023-44487(
x/net/http2
). [GH-19225]This resolves vulnerability CVE-2023-39325
/ CVE-2023-44487(
net/http
). [GH-19225]google.golang.org/grpc
to 1.56.3.This resolves vulnerability CVE-2023-44487. [GH-19414]
BUG FIXES:
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.