Update quay.io/argoproj/argocd Docker tag to v2.6.6 #1157
Loading…
Reference in New Issue
No description provided.
Delete Branch "renovate/quay.io-argoproj-argocd-2.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v2.4.11
->v2.6.6
Release Notes
argoproj/argo-cd
v2.6.6
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 12 contributions from 4 contributors with 0 features and 3 bug fixes.
Bug fixes (3)
Documentation (4)
Other (5)
v2.6.5
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Known Issues
Broken matrix-nested git files generator in 2.6.5
Argo CD 2.5.14 introduced a bug in the matrix-nested git files generator. The bug only applies when the git files
generator is the second generator nested under a matrix. For example:
The nested git files generator will produce no parameters, causing the matrix generator to also produce no parameters.
This will cause the ApplicationSet to produce no Applications. If the ApplicationSet controller is
configured with the ability to delete applications,
it will delete all Applications which were previously created by the ApplicationSet.
To avoid this issue, upgrade directly to >=2.5.15 or >= 2.6.6.
Changes
This release includes 6 contributions from 2 contributors with 0 features and 3 bug fixes.
Bug fixes (3)
Documentation (2)
Other (1)
v2.6.4
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 15 contributions from 3 contributors with 0 features and 5 bug fixes.
Bug fixes (5)
Documentation (5)
Other (5)
v2.6.3
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 19 contributions from 16 contributors (7 of them new) with 0 features and 7 bug fixes.
A special thanks goes to the 7 new contributors:
Bug fixes (7)
Documentation (8)
Other (4)
v2.6.2
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 2 contributions from 1 contributors with 0 features and 0 bug fixes.
Security (1)
Other (1)
v2.6.1
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 1 contributions from 1 contributors with 0 features and 1 bug fixes.
Security (1)
v2.6.0
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 235 contributions from 94 contributors (54 of them new) with 39 features and 34 bug fixes.
Features (39)
aud
claim from OIDC providers by default (#12187)create-delete
policy #9101 (#11107)Bug fixes (34)
argocd-cmd-params-cm
(#11776)Documentation (32)
Other (105)
appv1
prefix everywhere (#10621)v2.5.15
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 13 contributions from 4 contributors with 0 features and 4 bug fixes.
Bug fixes (4)
Documentation (4)
Other (5)
v2.5.14
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Known Issues
Broken matrix-nested git files generator in 2.5.14
Argo CD 2.5.14 introduced a bug in the matrix-nested git files generator. The bug only applies when the git files
generator is the second generator nested under a matrix. For example:
The nested git files generator will produce no parameters, causing the matrix generator to also produce no parameters.
This will cause the ApplicationSet to produce no Applications. If the ApplicationSet controller is
configured with the ability to delete applications,
it will delete all Applications which were previously created by the ApplicationSet.
To avoid this issue, upgrade directly to >=2.5.15 or >= 2.6.6.
Changes
This release includes 5 contributions from 2 contributors with 0 features and 3 bug fixes.
Bug fixes (3)
Documentation (1)
Other (1)
v2.5.13
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 11 contributions from 4 contributors with 0 features and 4 bug fixes.
Bug fixes (4)
Documentation (3)
Other (4)
v2.5.12
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 14 contributions from 12 contributors (6 of them new) with 0 features and 5 bug fixes.
A special thanks goes to the 6 new contributors:
Bug fixes (5)
Documentation (5)
Other (4)
v2.5.11
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 6 contributions from 5 contributors with 0 features and 2 bug fixes.
Security (1)
Bug fixes (2)
Documentation (2)
Other (1)
v2.5.10
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 10 contributions from 9 contributors (3 of them new) with 0 features and 3 bug fixes.
A special thanks goes to the 3 new contributors:
Bug fixes (3)
Documentation (3)
Other (4)
v2.5.9
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 4 contributions from 4 contributors (2 of them new) with 0 features and 3 bug fixes.
A special thanks goes to the 2 new contributors:
Bug fixes (3)
Other (1)
v2.5.8
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Known Issues
If you use the bundled Dex instance for SSO, a bug in 2.5.8 will prevent CLI clients from successfully authenticating with the Argo CD API. A patch for the bug is being tested as of Friday, Jan 27, and a fix will be released shortly.
Changes
This release includes 5 contributions from 4 contributors (1 of them new) with 0 features and 1 bug fixes.
A special thanks goes to the 1 new contributors:
Security (2)
Bug fixes (1)
Documentation (1)
Other (1)
v2.5.7
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 6 contributions from 3 contributors with 0 features and 2 bug fixes.
Bug fixes (2)
Other (4)
v2.5.6
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 21 contributions from 11 contributors (4 of them new) with 0 features and 6 bug fixes.
A special thanks goes to the 4 new contributors:
Bug fixes (6)
Documentation (7)
Other (8)
v2.5.5
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 14 contributions from 9 contributors (1 of them new) with 0 features and 6 bug fixes.
A special thanks goes to the 1 new contributor:
Bug fixes (6)
Documentation (3)
Other (5)
v2.5.4
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 20 contributions from 16 contributors (10 of them new) with 0 features and 6 bug fixes.
A special thanks goes to the 10 new contributors:
Bug fixes
Documentation
Other
v2.5.3
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 21 contributions from 15 contributors (6 of them new) with 0 features and 11 bug fixes.
A special thanks goes to the 6 new contributors:
Bug fixes
Documentation
Other
v2.5.2
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 8 contributions from 5 contributors (2 of them new) with 0 features and 3 bug fixes.
A special thanks goes to the 2 new contributors:
Bug fixes
Documentation
v2.5.1
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
Security fixes
This release includes openssl version 3.0.2-0ubuntu1.7, which patches high-severity vulnerabilities.
v2.5.0
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 301 contributions from 136 contributors (89 of them new) with 59 features and 62 bug fixes.
Features
Bug fixes
Documentation
Slack
notification service (#8776) (#10311)install
instead of curling directly to /usr/local/bin (#9944)Other
98ccd3d
(#10787)3951079
) (#10616)c036d3f
(#10423)v2.4.27
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 10 contributions from 4 contributors with 0 features and 3 bug fixes.
Bug fixes (3)
Documentation (2)
Other (5)
v2.4.26
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 3 contributions from 3 contributors (1 of them new) with 0 features and 1 bug fixes.
A special thanks goes to the 1 new contributor:
Bug fixes (1)
Documentation (1)
Other (1)
v2.4.25
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 11 contributions from 5 contributors with 0 features and 3 bug fixes.
Bug fixes (3)
Documentation (3)
Other (5)
v2.4.24
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 13 contributions from 11 contributors (6 of them new) with 0 features and 4 bug fixes.
A special thanks goes to the 6 new contributors:
Bug fixes (4)
Documentation (5)
Other (4)
v2.4.23
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 4 contributions from 3 contributors with 0 features and 0 bug fixes.
Security (1)
Documentation (2)
Other (1)
v2.4.22
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 8 contributions from 7 contributors (3 of them new) with 0 features and 2 bug fixes.
A special thanks goes to the 3 new contributors:
Bug fixes (2)
goutils
tov1.1.1
[release-2.4] (#12219) (#12222)Documentation (3)
Other (3)
v2.4.21
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 3 contributions from 3 contributors (1 of them new) with 0 features and 2 bug fixes.
A special thanks goes to the 1 new contributors:
Bug fixes (2)
Other (1)
v2.4.20
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Known Issues
If you use the bundled Dex instance for SSO, a bug in 2.4.20 will prevent CLI clients from successfully authenticating with the Argo CD API. A patch for the bug is being tested as of Friday, Jan 27, and a fix will be released shortly.
Changes
This release includes 2 contributions from 2 contributors with 0 features and 0 bug fixes.
Security (1)
Other (1)
v2.4.19
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 28 contributions from 12 contributors (4 of them new) with 0 features and 5 bug fixes.
A special thanks goes to the 4 new contributors:
Bug fixes (5)
Documentation (5)
Other (18)
v2.4.18
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 29 contributions from 12 contributors (6 of them new) with 0 features and 10 bug fixes.
A special thanks goes to the 6 new contributors:
Bug fixes (10)
Documentation (4)
Other (15)
v2.4.17
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 1 contributions from 1 contributors with 0 features and 1 bug fixes.
Bug fixes
v2.4.16
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 9 contributions from 6 contributors (4 of them new) with 0 features and 2 bug fixes.
A special thanks goes to the 4 new contributors:
Security fixes
This release includes openssl version 3.0.2-0ubuntu1.7, which patches high-severity vulnerabilities.
Bug fixes
Documentation
Other
v2.4.15
Compare Source
Quick Start
Non-HA:
HA:
Release signatures
All Argo CD container images and CLI binaries are signed by cosign. See the documentation on how to verify the signatures.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
This release includes 24 contributions from 15 contributors (10 of them new) with 9 bug fixes.
A special thanks goes to the 10 new contributors:
Bug fixes
HEAD
in bitbucket leads to a 404 page (#10862)Documentation
Other
v2.4.14
Compare Source
Quick Start
Non-HA:
HA:
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changes
Other
v2.4.13
Compare Source
Quick Start
Non-HA:
HA:
Security fixes
CVE-2022-39222 is a backchannel attack against the Dex OIDC provider. If you are impacted Argo CD, an attacker could use the process described in the vulnerability description to steal an Argo CD token from some Argo CD user. The attacker could then impersonate the targeted user and act with the victim's privileges.
Am I impacted?
This Dex vulnerability impacts Argo CD users who either 1) use the bundled Dex instance for OIDC or 2) use an external Dex instance running Dex <= 2.34.x.
If you do not use Dex, then you are not impacted.
Bundled Dex
To determine if you use the bundled Dex instance, run this command, replacing
argocd
with the namespace where your Argo CD instance is installed:If that command prints
true
, then you use the bundled Dex instance, and you should upgrade.External Dex
To determine if you use an external Dex instance, run this command:
That will print your Argo CD instance's OIDC config. It might be obvious whether the OIDC provider is Dex (for example, the word
dex
might be in the URL). Or you might have to contact whoever manages the configured OIDC provider to ask.You will also have to check with whoever manages the Dex instance to determine if it is still running a vulnerable version (<= 2.34.x).
How can I resolve the vulnerability as a user of the bundled Dex instance?
Upgrading Dex is the only way to resolve the vulnerability.
If you're using the manifests from the argo-cd repository to install Argo CD, the easiest way to resolve the vulnerability is to use the latest release's manifests, which point to the Dex 2.35.0 image. If you do not want to upgrade the full manifest, then you can manually change the Dex image tags in your deployed manifests to use a >= 2.35.0 tag.
If you're using the argo-helm argo-cd chart, you can either upgrade to 5.5.8 which points to the new Dex version, or you can set the
dex.image.tag
parameter to a >= 2.35.0 tag.To confirm that you are using a patched version of Dex, use this command (replacing
argocd
with the namespace where your Argo CD instance is deployed):The image tag should point to a Dex version >= 2.35.0.
Bug fixes
Other changes
v2.4.12
Compare Source
Quick Start
Non-HA:
HA:
Bug fixes
Other changes
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.
Update quay.io/argoproj/argocd Docker tag to v2.5.0to Update quay.io/argoproj/argocd Docker tag to v2.5.19a38152b2b
to7e7d5ea5a2
Update quay.io/argoproj/argocd Docker tag to v2.5.1to Update quay.io/argoproj/argocd Docker tag to v2.5.27e7d5ea5a2
to4a5755583c
Update quay.io/argoproj/argocd Docker tag to v2.5.2to Update quay.io/argoproj/argocd Docker tag to v2.5.34a5755583c
toa0b4cf8ca8
Update quay.io/argoproj/argocd Docker tag to v2.5.3to Update quay.io/argoproj/argocd Docker tag to v2.5.4a0b4cf8ca8
toa5c8a6e213
Update quay.io/argoproj/argocd Docker tag to v2.5.4to Update quay.io/argoproj/argocd Docker tag to v2.5.5a5c8a6e213
to80347bfb03
Update quay.io/argoproj/argocd Docker tag to v2.5.5to Update quay.io/argoproj/argocd Docker tag to v2.5.680347bfb03
tob4fac457b4
Update quay.io/argoproj/argocd Docker tag to v2.5.6to Update quay.io/argoproj/argocd Docker tag to v2.5.7b4fac457b4
to73475f81a4
Update quay.io/argoproj/argocd Docker tag to v2.5.7to Update quay.io/argoproj/argocd Docker tag to v2.5.873475f81a4
to4720d9c38c
Update quay.io/argoproj/argocd Docker tag to v2.5.8to Update quay.io/argoproj/argocd Docker tag to v2.5.94720d9c38c
to88f750c0e2
Update quay.io/argoproj/argocd Docker tag to v2.5.9to Update quay.io/argoproj/argocd Docker tag to v2.5.1088f750c0e2
to54952f1367
Update quay.io/argoproj/argocd Docker tag to v2.5.10to Update quay.io/argoproj/argocd Docker tag to v2.6.054952f1367
to37aaa2b9af
Update quay.io/argoproj/argocd Docker tag to v2.6.0to Update quay.io/argoproj/argocd Docker tag to v2.6.137aaa2b9af
to518d8b602d
Update quay.io/argoproj/argocd Docker tag to v2.6.1to Update quay.io/argoproj/argocd Docker tag to v2.6.2518d8b602d
to81178b6f2b
Update quay.io/argoproj/argocd Docker tag to v2.6.2to Update quay.io/argoproj/argocd Docker tag to v2.6.381178b6f2b
tof7da3c3e07
Update quay.io/argoproj/argocd Docker tag to v2.6.3to Update quay.io/argoproj/argocd Docker tag to v2.6.4f7da3c3e07
tofc794671dd
fc794671dd
to9f26ee21a9
Update quay.io/argoproj/argocd Docker tag to v2.6.4to Update quay.io/argoproj/argocd Docker tag to v2.6.59f26ee21a9
toffb9aa9922
ffb9aa9922
to38255dc0b3
Update quay.io/argoproj/argocd Docker tag to v2.6.5to Update quay.io/argoproj/argocd Docker tag to v2.6.638255dc0b3
to8d46081068