Skip to content

Update all non-major dependencies - #166

Merged
csi-components-e2e merged 1 commit into
mainfrom
renovate/all-non-major-dependencies
Sep 30, 2026
Merged

csi-components-e2e merged 1 commit into
mainfrom
renovate/all-non-major-dependencies

Conversation

@csi-components-e2e

@csi-components-e2e csi-components-e2e commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

This PR contains the following updates:

Package Type Update Change
public.ecr.aws/docker/library/golang (source) stage digest 3680233 → e0174e5
public.ecr.aws/eks-distro-build-tooling/eks-distro-minimal-base stage digest 2a6bd21 → c8a0394

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@csi-components-e2e csi-components-e2e added the dependencies Pull requests that update a dependency file label Sep 29, 2026
@csi-components-e2e
csi-components-e2e enabled auto-merge (squash) September 29, 2026 19:12
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Trivy Output

702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-snapshotter:67cec9a818b0ddae87d46a7c05edc273191550b5-v8.6.0-eksbuild.8

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-snapshotter:67cec9a818b0ddae87- │  amazon  │        0        │    -    │
│ d46a7c05edc273191550b5-v8.6.0-eksbuild.8 (amazon 2023.12.20260928 (Amazon        │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-snapshotter                                                                  │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-snapshotter (gobinary)
==========================
Total: 2 (UNKNOWN: 0, LOW: 2, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌──────────────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐
│                           Library                            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                         │
├──────────────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────┤
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace            │ CVE-2026-81870 │ LOW      │ fixed  │ v1.43.0           │ 1.45.0        │ github.com/open-telemetry/opentelemetry-go:           │
│                                                              │                │          │        │                   │               │ OpenTelemetry-Go: Information disclosure via exporter │
│                                                              │                │          │        │                   │               │ configuration logging                                 │
│                                                              │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-81870            │
├──────────────────────────────────────────────────────────────┤                │          │        │                   │               │                                                       │
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptrace- │                │          │        │                   │               │                                                       │
│ grpc                                                         │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
└──────────────────────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-attacher:67cec9a818b0ddae87d46a7c05edc273191550b5-v4.12.0-eksbuild.8

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-attacher:67cec9a818b0ddae87d46- │  amazon  │        0        │    -    │
│ a7c05edc273191550b5-v4.12.0-eksbuild.8 (amazon 2023.12.20260928 (Amazon Linux))  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-attacher                                                                     │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-attacher (gobinary)
=======================
Total: 2 (UNKNOWN: 0, LOW: 2, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌──────────────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐
│                           Library                            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                         │
├──────────────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────┤
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace            │ CVE-2026-81870 │ LOW      │ fixed  │ v1.43.0           │ 1.45.0        │ github.com/open-telemetry/opentelemetry-go:           │
│                                                              │                │          │        │                   │               │ OpenTelemetry-Go: Information disclosure via exporter │
│                                                              │                │          │        │                   │               │ configuration logging                                 │
│                                                              │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-81870            │
├──────────────────────────────────────────────────────────────┤                │          │        │                   │               │                                                       │
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptrace- │                │          │        │                   │               │                                                       │
│ grpc                                                         │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
└──────────────────────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-provisioner:67cec9a818b0ddae87d46a7c05edc273191550b5-v6.3.0-eksbuild.7

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-provisioner:67cec9a818b0ddae87- │  amazon  │        0        │    -    │
│ d46a7c05edc273191550b5-v6.3.0-eksbuild.7 (amazon 2023.12.20260928 (Amazon        │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-provisioner                                                                  │ gobinary │        3        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-provisioner (gobinary)
==========================
Total: 3 (UNKNOWN: 0, LOW: 3, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌──────────────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐
│                           Library                            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                         │
├──────────────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────┤
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace            │ CVE-2026-81870 │ LOW      │ fixed  │ v1.44.0           │ 1.45.0        │ github.com/open-telemetry/opentelemetry-go:           │
│                                                              │                │          │        │                   │               │ OpenTelemetry-Go: Information disclosure via exporter │
│                                                              │                │          │        │                   │               │ configuration logging                                 │
│                                                              │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-81870            │
├──────────────────────────────────────────────────────────────┤                │          │        │                   │               │                                                       │
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptrace- │                │          │        │                   │               │                                                       │
│ grpc                                                         │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
├──────────────────────────────────────────────────────────────┤                │          │        │                   │               │                                                       │
│ go.opentelemetry.io/otel/sdk                                 │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
└──────────────────────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-resizer:67cec9a818b0ddae87d46a7c05edc273191550b5-v2.2.1-eksbuild.6

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-resizer:67cec9a818b0ddae87d46a- │  amazon  │        0        │    -    │
│ 7c05edc273191550b5-v2.2.1-eksbuild.6 (amazon 2023.12.20260928 (Amazon Linux))    │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-resizer                                                                      │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


csi-resizer (gobinary)
======================
Total: 2 (UNKNOWN: 0, LOW: 2, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌──────────────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐
│                           Library                            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                         │
├──────────────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────┤
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace            │ CVE-2026-81870 │ LOW      │ fixed  │ v1.40.0           │ 1.45.0        │ github.com/open-telemetry/opentelemetry-go:           │
│                                                              │                │          │        │                   │               │ OpenTelemetry-Go: Information disclosure via exporter │
│                                                              │                │          │        │                   │               │ configuration logging                                 │
│                                                              │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-81870            │
├──────────────────────────────────────────────────────────────┤                │          │        │                   │               │                                                       │
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptrace- │                │          │        │                   │               │                                                       │
│ grpc                                                         │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
└──────────────────────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-node-driver-registrar:67cec9a818b0ddae87d46a7c05edc273191550b5-v2.17.0-eksbuild.7

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/csi-node-driver-registrar:67cec9a8- │  amazon  │        0        │    -    │
│ 18b0ddae87d46a7c05edc273191550b5-v2.17.0-eksbuild.7 (amazon 2023.12.20260928     │          │                 │         │
│ (Amazon Linux))                                                                  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ csi-node-driver-registrar                                                        │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)

702945799511.dkr.ecr.us-west-2.amazonaws.com/livenessprobe:67cec9a818b0ddae87d46a7c05edc273191550b5-v2.19.0-eksbuild.7

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/livenessprobe:67cec9a818b0ddae87d4- │  amazon  │        0        │    -    │
│ 6a7c05edc273191550b5-v2.19.0-eksbuild.7 (amazon 2023.12.20260928 (Amazon Linux)) │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ livenessprobe                                                                    │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)

702945799511.dkr.ecr.us-west-2.amazonaws.com/snapshot-controller:67cec9a818b0ddae87d46a7c05edc273191550b5-v8.6.0-eksbuild.8

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/snapshot-controller:67cec9a818b0dd- │  amazon  │        0        │    -    │
│ ae87d46a7c05edc273191550b5-v8.6.0-eksbuild.8 (amazon 2023.12.20260928 (Amazon    │          │                 │         │
│ Linux))                                                                          │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ snapshot-controller                                                              │ gobinary │        2        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


snapshot-controller (gobinary)
==============================
Total: 2 (UNKNOWN: 0, LOW: 2, MEDIUM: 0, HIGH: 0, CRITICAL: 0)

┌──────────────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────┐
│                           Library                            │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                         Title                         │
├──────────────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────┤
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace            │ CVE-2026-81870 │ LOW      │ fixed  │ v1.43.0           │ 1.45.0        │ github.com/open-telemetry/opentelemetry-go:           │
│                                                              │                │          │        │                   │               │ OpenTelemetry-Go: Information disclosure via exporter │
│                                                              │                │          │        │                   │               │ configuration logging                                 │
│                                                              │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-81870            │
├──────────────────────────────────────────────────────────────┤                │          │        │                   │               │                                                       │
│ go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptrace- │                │          │        │                   │               │                                                       │
│ grpc                                                         │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
│                                                              │                │          │        │                   │               │                                                       │
└──────────────────────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────┘
702945799511.dkr.ecr.us-west-2.amazonaws.com/volume-modifier-for-k8s:67cec9a818b0ddae87d46a7c05edc273191550b5-v0.9.6-eksbuild.1

Report Summary

┌──────────────────────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                                      Target                                      │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ 702945799511.dkr.ecr.us-west-2.amazonaws.com/volume-modifier-for-k8s:67cec9a818- │  amazon  │        0        │    -    │
│ b0ddae87d46a7c05edc273191550b5-v0.9.6-eksbuild.1 (amazon 2023.12.20260928        │          │                 │         │
│ (Amazon Linux))                                                                  │          │                 │         │
├──────────────────────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ volume-modifier-for-k8s                                                          │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)

public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.0

Report Summary

┌──────────────────────────────────────────────────────────────────┬──────────┬─────────────────┬─────────┐
│                              Target                              │   Type   │ Vulnerabilities │ Secrets │
├──────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.0 (amazon │  amazon  │        2        │    -    │
│ 2023.12.20260831 (Amazon Linux))                                 │          │                 │         │
├──────────────────────────────────────────────────────────────────┼──────────┼─────────────────┼─────────┤
│ usr/bin/aws-ebs-csi-driver                                       │ gobinary │        0        │    -    │
└──────────────────────────────────────────────────────────────────┴──────────┴─────────────────┴─────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.66.0 (amazon 2023.12.20260831 (Amazon Linux))
=================================================================================================
Total: 2 (UNKNOWN: 0, LOW: 0, MEDIUM: 0, HIGH: 2, CRITICAL: 0)

┌──────────────┬────────────────┬──────────┬────────┬──────────────────────┬──────────────────────┬────────────────────────────────────────────────────────┐
│   Library    │ Vulnerability  │ Severity │ Status │  Installed Version   │    Fixed Version     │                         Title                          │
├──────────────┼────────────────┼──────────┼────────┼──────────────────────┼──────────────────────┼────────────────────────────────────────────────────────┤
│ pcre2        │ CVE-2026-89161 │ HIGH     │ fixed  │ 10.40-1.amzn2023.0.3 │ 10.40-1.amzn2023.0.4 │ pcre2: PCRE2: Memory corruption vulnerability in       │
│              │                │          │        │                      │                      │ pcre2_jit_match                                        │
│              │                │          │        │                      │                      │ https://avd.aquasec.com/nvd/cve-2026-89161             │
├──────────────┼────────────────┤          │        ├──────────────────────┼──────────────────────┼────────────────────────────────────────────────────────┤
│ systemd-libs │ CVE-2026-16742 │          │        │ 252.23-12.amzn2023   │ 252.23-13.amzn2023   │ systemd: systemd-homed: Local privilege escalation via │
│              │                │          │        │                      │                      │ missing home-record signature verification             │
│              │                │          │        │                      │                      │ https://avd.aquasec.com/nvd/cve-2026-16742             │
└──────────────┴────────────────┴──────────┴────────┴──────────────────────┴──────────────────────┴────────────────────────────────────────────────────────┘

@csi-components-e2e csi-components-e2e changed the title Update public.ecr.aws/eks-distro-build-tooling/eks-distro-minimal-base:latest-al23 Docker digest to c8a0394 Update all non-major dependencies Sep 30, 2026
@csi-components-e2e
csi-components-e2e force-pushed the renovate/all-non-major-dependencies branch 3 times, most recently from 0ebc279 to b922fb7 Compare September 30, 2026 07:47
@csi-components-e2e
csi-components-e2e merged commit de53c3a into main Sep 30, 2026
14 of 19 checks passed
@csi-components-e2e
csi-components-e2e deleted the renovate/all-non-major-dependencies branch September 30, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants