Skip to content

chore(deps): update ghcr.io/rancher/local-path-provisioner/charts/local-path-provisioner docker tag to v0.0.36#534

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-rancher-local-path-provisioner-charts-local-path-provisioner-0.x
Open

chore(deps): update ghcr.io/rancher/local-path-provisioner/charts/local-path-provisioner docker tag to v0.0.36#534
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ghcr.io-rancher-local-path-provisioner-charts-local-path-provisioner-0.x

Conversation

@renovate

@renovate renovate Bot commented May 15, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/rancher/local-path-provisioner/charts/local-path-provisioner patch 0.0.350.0.36

Release Notes

rancher/local-path-provisioner (ghcr.io/rancher/local-path-provisioner/charts/local-path-provisioner)

v0.0.36: Local Path Provisioner v0.0.36

Compare Source

Security Fixes

  • Fixed HelperPod Template Injection, a high-severity HelperPod template injection vulnerability. A user with permission to edit the local-path-config ConfigMap could manipulate helperPod.yaml and cause the provisioner to create unsafe HelperPods during PVC provisioning or cleanup operations. This release adds HelperPod template validation to reject unsafe security-sensitive fields such as privileged containers, hostPath volumes, and dangerous pod security settings.

What's Changed

New Contributors

Full Changelog: rancher/local-path-provisioner@v0.0.35...v0.0.36


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label May 15, 2026
@renovate renovate Bot force-pushed the renovate/ghcr.io-rancher-local-path-provisioner-charts-local-path-provisioner-0.x branch from 6f79480 to 4bf15fe Compare May 17, 2026 00:20
@renovate renovate Bot force-pushed the renovate/ghcr.io-rancher-local-path-provisioner-charts-local-path-provisioner-0.x branch from 4bf15fe to cec7d8e Compare June 20, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants