Releases: HomeLabHD/weave-gitops
Release list
latest-dev
📦 weave-gitops — v0.38.0-dev+5e3cd5d
Release type: prerelease • Commit:
5e3cd5d
Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/weave-gitops |
dev-5e3cd5d latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/weave-gitops |
dev-5e3cd5d latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/weave-gitops |
dev-5e3cd5d latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/weave-gitops
docker pull docker.io/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
cr.pcfae.com/hlhd/weave-gitops
docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
ghcr.io/homelabhd/weave-gitops
docker pull ghcr.io/homelabhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
Notable Changes
Features
- config: toolchains flag-day: want: wrapper + retention (SoFMeRight)
Bug Fixes
- build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
- build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
- ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
- build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
- build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
- ci: select gitops-server.dockerfile as the image build target (SoFMeRight) ×2
- deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
- deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
- deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
- deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
- deps: clear audition freshness gate and restore the Go build (SoFMeRight)
- deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
- logger: pass built message as argument, not format string (SoFMeRight)
- deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
- deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
- commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
- build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
- config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)
Documentation
- readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
- refresh generated badges (stagefreight) ×4
Tests
- http: generate self-signed localhost cert at test time (SoFMeRight)
CI/CD
- exclude vendored website/ docs tree from lint (SoFMeRight)
- add StageFreight pipeline — build the weave-gitops webapp from upstream main (SoFMeRight)
- do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×15
- deps: update managed dependencies (stagefreight) ×6
- deps: bump frontend CVE deps within-major (SoFMeRight)
- deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
Other Changes
- Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)
Security
🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-31789 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a... |
| High | CVE-2025-15467 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may... |
| High | CVE-2025-69421 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a... |
| High | CVE-2026-28387 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or... |
| High | CVE-2026-28388 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary... |
| High | CVE-2026-28389 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-28390 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-45447 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process... |
| Medium | CVE-2026-0915 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0... |
| Medium | CVE-2026-18374 | libc6 | 2.36-9+deb12u13 | — | Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow... |
| Medium | CVE-2026-19499 | libc6 | 2.36-9+deb12u13 | — | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding... |
| Medium | CVE-2026-19542 | libc6 | 2.36-9+deb12u13 | — | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application... |
| Medium | CVE-2026-4046 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to... |
| Medium | CVE-2026-4437 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response... |
| Medium | CVE-2026-5435 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds... |
| Medium | CVE-2026-5450 | libc6 | 2.36-9+deb12u13 | — | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024... |
| Medium | CVE-2026-5928 | libc6 | 2.36-9+deb12u13 | — | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library... |
| Medium | CVE-2026-6238 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when... |
| Medium | CVE-2026-6368 | libc6 | 2.36-9+deb12u13 | — | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may... |
| Medium | CVE-2026-6791 | libc6 | 2.36-9+deb12u13 | — | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation... |
| Medium | CVE-2026-77117 | libc6 | 2.36-9+deb12u13 | — | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide chara... |
dev-f6637da
📦 weave-gitops — v0.39.1-dev+f6637da
Release type: prerelease • Commit:
f6637da
Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/weave-gitops |
dev-f6637da latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/weave-gitops |
dev-f6637da latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/weave-gitops |
dev-f6637da latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/weave-gitops
docker pull docker.io/hlhd/weave-gitops@sha256:406319411bde3e3d53a9df7462434a667422f259b16e1458f0f15c9ceaf61a74
cr.pcfae.com/hlhd/weave-gitops
docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:406319411bde3e3d53a9df7462434a667422f259b16e1458f0f15c9ceaf61a74
ghcr.io/homelabhd/weave-gitops
docker pull ghcr.io/homelabhd/weave-gitops@sha256:406319411bde3e3d53a9df7462434a667422f259b16e1458f0f15c9ceaf61a74
Notable Changes
Bug Fixes
- build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
- build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
- ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
Documentation
- refresh generated badges (stagefreight) ×4
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×4
- deps: update managed dependencies (stagefreight) ×2
Security
🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-31789 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a... |
| High | CVE-2025-15467 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may... |
| High | CVE-2025-69421 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a... |
| High | CVE-2026-28387 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or... |
| High | CVE-2026-28388 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary... |
| High | CVE-2026-28389 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-28390 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-45447 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process... |
| Medium | CVE-2026-0915 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0... |
| Medium | CVE-2026-18374 | libc6 | 2.36-9+deb12u13 | — | Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow... |
| Medium | CVE-2026-19499 | libc6 | 2.36-9+deb12u13 | — | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding... |
| Medium | CVE-2026-19542 | libc6 | 2.36-9+deb12u13 | — | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application... |
| Medium | CVE-2026-4046 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to... |
| Medium | CVE-2026-4437 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response... |
| Medium | CVE-2026-5435 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds... |
| Medium | CVE-2026-5450 | libc6 | 2.36-9+deb12u13 | — | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024... |
| Medium | CVE-2026-5928 | libc6 | 2.36-9+deb12u13 | — | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library... |
| Medium | CVE-2026-6238 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when... |
| Medium | CVE-2026-6368 | libc6 | 2.36-9+deb12u13 | — | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may... |
| Medium | CVE-2026-6791 | libc6 | 2.36-9+deb12u13 | — | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation... |
| Medium | CVE-2026-77117 | libc6 | 2.36-9+deb12u13 | — | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no... |
| Medium | CVE-2026-80489 | libc6 | 2.36-9+deb12u13 | — | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no... |
| Medium | CVE-2026-8674 | libc6 | 2.36-9+deb12u13 | — | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library... |
| Medium | CVE-2026-86805 | libc6 | 2.36-9+deb12u13 | — | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges... |
| Medium | CVE-2026-89092 | libc6 | 2.36-9+deb12u13 | — | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS... |
| Medium | CVE-2026-95818 | libc6 | 2.36-9+deb12u13 | — | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid... |
| Medium | CVE-2025-69419 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte... |
| Medium | CVE-2026-31790 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The... |
| Medium | CVE-2026-34182 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher a... |
dev-5e3cd5d
📦 weave-gitops — v0.38.0-dev+5e3cd5d
Release type: prerelease • Commit:
5e3cd5d
Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/weave-gitops |
dev-5e3cd5d latest-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/weave-gitops |
dev-5e3cd5d latest-dev |
| GitHub Container Registry | ghcr.io/homelabhd/weave-gitops |
dev-5e3cd5d latest-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/weave-gitops
docker pull docker.io/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
cr.pcfae.com/hlhd/weave-gitops
docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
ghcr.io/homelabhd/weave-gitops
docker pull ghcr.io/homelabhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686
Notable Changes
Features
- config: toolchains flag-day: want: wrapper + retention (SoFMeRight)
Bug Fixes
- build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
- build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
- ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
- build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
- build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
- ci: select gitops-server.dockerfile as the image build target (SoFMeRight) ×2
- deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
- deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
- deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
- deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
- deps: clear audition freshness gate and restore the Go build (SoFMeRight)
- deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
- logger: pass built message as argument, not format string (SoFMeRight)
- deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
- deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
- commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
- build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
- config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)
Documentation
- readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
- refresh generated badges (stagefreight) ×4
Tests
- http: generate self-signed localhost cert at test time (SoFMeRight)
CI/CD
- exclude vendored website/ docs tree from lint (SoFMeRight)
- add StageFreight pipeline — build the weave-gitops webapp from upstream main (SoFMeRight)
- do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×15
- deps: update managed dependencies (stagefreight) ×6
- deps: bump frontend CVE deps within-major (SoFMeRight)
- deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
Other Changes
- Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)
Security
🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-31789 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a... |
| High | CVE-2025-15467 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may... |
| High | CVE-2025-69421 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a... |
| High | CVE-2026-28387 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or... |
| High | CVE-2026-28388 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary... |
| High | CVE-2026-28389 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-28390 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-45447 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process... |
| Medium | CVE-2026-0915 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0... |
| Medium | CVE-2026-18374 | libc6 | 2.36-9+deb12u13 | — | Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow... |
| Medium | CVE-2026-19499 | libc6 | 2.36-9+deb12u13 | — | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding... |
| Medium | CVE-2026-19542 | libc6 | 2.36-9+deb12u13 | — | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application... |
| Medium | CVE-2026-4046 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to... |
| Medium | CVE-2026-4437 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response... |
| Medium | CVE-2026-5435 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds... |
| Medium | CVE-2026-5450 | libc6 | 2.36-9+deb12u13 | — | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024... |
| Medium | CVE-2026-5928 | libc6 | 2.36-9+deb12u13 | — | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library... |
| Medium | CVE-2026-6238 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when... |
| Medium | CVE-2026-6368 | libc6 | 2.36-9+deb12u13 | — | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may... |
| Medium | CVE-2026-6791 | libc6 | 2.36-9+deb12u13 | — | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation... |
| Medium | CVE-2026-77117 | libc6 | 2.36-9+deb12u13 | — | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide chara... |
v0.39.1
📦 weave-gitops — v0.39.1
Release type: latest • Commit:
5e3cd5d
Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/weave-gitops |
v0.39.1 latest |
| cr.pcfae.com | cr.pcfae.com/hlhd/weave-gitops |
v0.39.1 latest |
| GitHub Container Registry | ghcr.io/homelabhd/weave-gitops |
v0.39.1 latest |
Digest pull commands & supply chain artifacts
docker.io/hlhd/weave-gitops
docker pull docker.io/hlhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998
cr.pcfae.com/hlhd/weave-gitops
docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998
ghcr.io/homelabhd/weave-gitops
docker pull ghcr.io/homelabhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998
Highlights
- config: toolchains flag-day: want: wrapper + retention
- build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version
- build: forward version metadata build args to make (stop reporting v0.0.0)
- ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages
- build: enable corepack for yarn in the node 26 UI stage
- build: bump go-build base to golang 1.27.1 for the go 1.27.0 module
- ci: select gitops-server.dockerfile as the image build target
- deps: hold only the upstream-blocked deps from freshness (scoped, not blanket)
Notable Changes
Features
- config: toolchains flag-day: want: wrapper + retention (SoFMeRight)
Bug Fixes
- build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
- build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
- ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
- build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
- build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
- ci: select gitops-server.dockerfile as the image build target (SoFMeRight) ×2
- deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
- deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
- deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
- deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
- deps: clear audition freshness gate and restore the Go build (SoFMeRight)
- deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
- logger: pass built message as argument, not format string (SoFMeRight)
- deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
- deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
- commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
- build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
- config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)
Documentation
- readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
- refresh generated badges (stagefreight) ×4
Tests
- http: generate self-signed localhost cert at test time (SoFMeRight)
CI/CD
- exclude vendored website/ docs tree from lint (SoFMeRight)
- add StageFreight pipeline — build the weave-gitops webapp from upstream main (SoFMeRight)
- do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×15
- deps: update managed dependencies (stagefreight) ×6
- deps: bump frontend CVE deps within-major (SoFMeRight)
- deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
- config: migrate to current stagefreight schema + canonical suite (SoFMeRight)
Other Changes
- Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)
Security
🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected
Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2026-31789 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a... |
| High | CVE-2025-15467 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may... |
| High | CVE-2025-69421 | libssl3 | 3.0.17-1~deb12u3 | 3.0.18-1~deb12u2 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a... |
| High | CVE-2026-28387 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or... |
| High | CVE-2026-28388 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary... |
| High | CVE-2026-28389 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-28390 | libssl3 | 3.0.17-1~deb12u3 | 3.0.19-1~deb12u2 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process... |
| High | CVE-2026-45447 | libssl3 | 3.0.17-1~deb12u3 | 3.0.20-1~deb12u2 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process... |
| Medium | CVE-2026-0915 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0... |
| Medium | CVE-2026-18374 | libc6 | 2.36-9+deb12u13 | — | Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow... |
| Medium | CVE-2026-19499 | libc6 | 2.36-9+deb12u13 | — | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding... |
| Medium | CVE-2026-19542 | libc6 | 2.36-9+deb12u13 | — | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application... |
| Medium | CVE-2026-4046 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to... |
| Medium | CVE-2026-4437 | libc6 | 2.36-9+deb12u13 | 2.36-9+deb12u14 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response... |
| Medium | CVE-2026-5435 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds... |
| Medium | CVE-2026-5450 | libc6 | 2.36-9+deb12u13 | — | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024... |
| Medium | CVE-2026-5928 | libc6 | 2.36-9+deb12u13 | — | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library... |
| Medium | CVE-2026-6238 | libc6 | 2.36-9+deb12u13 | — | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when... |
| Medium | CVE-2026-6368 | libc6 | 2.3... |