Skip to content

Releases: HomeLabHD/weave-gitops

latest-dev

latest-dev Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 28 Sep 12:44

📦 weave-gitops — v0.38.0-dev+5e3cd5d

Release type: prerelease • Commit: 5e3cd5d

Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/weave-gitops dev-5e3cd5d latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/weave-gitops dev-5e3cd5d latest-dev
GitHub Container Registry ghcr.io/homelabhd/weave-gitops dev-5e3cd5d latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/weave-gitops

docker pull docker.io/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686

cr.pcfae.com/hlhd/weave-gitops

docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686

ghcr.io/homelabhd/weave-gitops

docker pull ghcr.io/homelabhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686

Notable Changes

Features

  • config: toolchains flag-day: want: wrapper + retention (SoFMeRight)

Bug Fixes

  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
  • build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
  • ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
  • build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
  • build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
  • ci: select gitops-server.dockerfile as the image build target (SoFMeRight) ×2
  • deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
  • deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
  • deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
  • deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
  • deps: clear audition freshness gate and restore the Go build (SoFMeRight)
  • deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
  • logger: pass built message as argument, not format string (SoFMeRight)
  • deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
  • deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
  • commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
  • build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
  • config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)

Documentation

  • readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
  • refresh generated badges (stagefreight) ×4

Tests

  • http: generate self-signed localhost cert at test time (SoFMeRight)

CI/CD

  • exclude vendored website/ docs tree from lint (SoFMeRight)
  • add StageFreight pipeline — build the weave-gitops webapp from upstream main (SoFMeRight)
  • do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×15
  • deps: update managed dependencies (stagefreight) ×6
  • deps: bump frontend CVE deps within-major (SoFMeRight)
  • deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)

Other Changes

  • Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)

Security

🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-31789 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a...
High CVE-2025-15467 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may...
High CVE-2025-69421 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a...
High CVE-2026-28387 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or...
High CVE-2026-28388 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary...
High CVE-2026-28389 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-28390 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-45447 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process...
Medium CVE-2026-0915 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0...
Medium CVE-2026-18374 libc6 2.36-9+deb12u13 — Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow...
Medium CVE-2026-19499 libc6 2.36-9+deb12u13 — Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding...
Medium CVE-2026-19542 libc6 2.36-9+deb12u13 — Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application...
Medium CVE-2026-4046 libc6 2.36-9+deb12u13 2.36-9+deb12u14 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to...
Medium CVE-2026-4437 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response...
Medium CVE-2026-5435 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds...
Medium CVE-2026-5450 libc6 2.36-9+deb12u13 — Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024...
Medium CVE-2026-5928 libc6 2.36-9+deb12u13 — Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library...
Medium CVE-2026-6238 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when...
Medium CVE-2026-6368 libc6 2.36-9+deb12u13 — Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may...
Medium CVE-2026-6791 libc6 2.36-9+deb12u13 — When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation...
Medium CVE-2026-77117 libc6 2.36-9+deb12u13 — Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide chara...
Read more

dev-f6637da

dev-f6637da Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 29 Sep 10:38

📦 weave-gitops — v0.39.1-dev+f6637da

Release type: prerelease • Commit: f6637da

Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/weave-gitops dev-f6637da latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/weave-gitops dev-f6637da latest-dev
GitHub Container Registry ghcr.io/homelabhd/weave-gitops dev-f6637da latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/weave-gitops

docker pull docker.io/hlhd/weave-gitops@sha256:406319411bde3e3d53a9df7462434a667422f259b16e1458f0f15c9ceaf61a74

cr.pcfae.com/hlhd/weave-gitops

docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:406319411bde3e3d53a9df7462434a667422f259b16e1458f0f15c9ceaf61a74

ghcr.io/homelabhd/weave-gitops

docker pull ghcr.io/homelabhd/weave-gitops@sha256:406319411bde3e3d53a9df7462434a667422f259b16e1458f0f15c9ceaf61a74

Notable Changes

Bug Fixes

  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
  • build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
  • ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)

Documentation

  • refresh generated badges (stagefreight) ×4

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×4
  • deps: update managed dependencies (stagefreight) ×2

Security

🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-31789 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a...
High CVE-2025-15467 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may...
High CVE-2025-69421 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a...
High CVE-2026-28387 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or...
High CVE-2026-28388 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary...
High CVE-2026-28389 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-28390 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-45447 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process...
Medium CVE-2026-0915 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0...
Medium CVE-2026-18374 libc6 2.36-9+deb12u13 — Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow...
Medium CVE-2026-19499 libc6 2.36-9+deb12u13 — Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding...
Medium CVE-2026-19542 libc6 2.36-9+deb12u13 — Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application...
Medium CVE-2026-4046 libc6 2.36-9+deb12u13 2.36-9+deb12u14 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to...
Medium CVE-2026-4437 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response...
Medium CVE-2026-5435 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds...
Medium CVE-2026-5450 libc6 2.36-9+deb12u13 — Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024...
Medium CVE-2026-5928 libc6 2.36-9+deb12u13 — Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library...
Medium CVE-2026-6238 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when...
Medium CVE-2026-6368 libc6 2.36-9+deb12u13 — Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may...
Medium CVE-2026-6791 libc6 2.36-9+deb12u13 — When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation...
Medium CVE-2026-77117 libc6 2.36-9+deb12u13 — Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no...
Medium CVE-2026-80489 libc6 2.36-9+deb12u13 — Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no...
Medium CVE-2026-8674 libc6 2.36-9+deb12u13 — Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library...
Medium CVE-2026-86805 libc6 2.36-9+deb12u13 — A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges...
Medium CVE-2026-89092 libc6 2.36-9+deb12u13 — The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS...
Medium CVE-2026-95818 libc6 2.36-9+deb12u13 — A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid...
Medium CVE-2025-69419 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte...
Medium CVE-2026-31790 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The...
Medium CVE-2026-34182 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher a...
Read more

dev-5e3cd5d

dev-5e3cd5d Pre-release
Pre-release

Choose a tag to compare

@SoFMeRight SoFMeRight released this 29 Sep 12:21

📦 weave-gitops — v0.38.0-dev+5e3cd5d

Release type: prerelease • Commit: 5e3cd5d

Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/weave-gitops dev-5e3cd5d latest-dev
cr.pcfae.com cr.pcfae.com/hlhd/weave-gitops dev-5e3cd5d latest-dev
GitHub Container Registry ghcr.io/homelabhd/weave-gitops dev-5e3cd5d latest-dev
Digest pull commands & supply chain artifacts

docker.io/hlhd/weave-gitops

docker pull docker.io/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686

cr.pcfae.com/hlhd/weave-gitops

docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686

ghcr.io/homelabhd/weave-gitops

docker pull ghcr.io/homelabhd/weave-gitops@sha256:dfc66a762833d4afe4032e790715fdbd9d0f41539650d126ca6067064d7c3686

Notable Changes

Features

  • config: toolchains flag-day: want: wrapper + retention (SoFMeRight)

Bug Fixes

  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
  • build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
  • ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
  • build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
  • build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
  • ci: select gitops-server.dockerfile as the image build target (SoFMeRight) ×2
  • deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
  • deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
  • deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
  • deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
  • deps: clear audition freshness gate and restore the Go build (SoFMeRight)
  • deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
  • logger: pass built message as argument, not format string (SoFMeRight)
  • deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
  • deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
  • commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
  • build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
  • config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)

Documentation

  • readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
  • refresh generated badges (stagefreight) ×4

Tests

  • http: generate self-signed localhost cert at test time (SoFMeRight)

CI/CD

  • exclude vendored website/ docs tree from lint (SoFMeRight)
  • add StageFreight pipeline — build the weave-gitops webapp from upstream main (SoFMeRight)
  • do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×15
  • deps: update managed dependencies (stagefreight) ×6
  • deps: bump frontend CVE deps within-major (SoFMeRight)
  • deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)

Other Changes

  • Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)

Security

🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-31789 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a...
High CVE-2025-15467 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may...
High CVE-2025-69421 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a...
High CVE-2026-28387 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or...
High CVE-2026-28388 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary...
High CVE-2026-28389 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-28390 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-45447 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process...
Medium CVE-2026-0915 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0...
Medium CVE-2026-18374 libc6 2.36-9+deb12u13 — Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow...
Medium CVE-2026-19499 libc6 2.36-9+deb12u13 — Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding...
Medium CVE-2026-19542 libc6 2.36-9+deb12u13 — Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application...
Medium CVE-2026-4046 libc6 2.36-9+deb12u13 2.36-9+deb12u14 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to...
Medium CVE-2026-4437 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response...
Medium CVE-2026-5435 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds...
Medium CVE-2026-5450 libc6 2.36-9+deb12u13 — Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024...
Medium CVE-2026-5928 libc6 2.36-9+deb12u13 — Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library...
Medium CVE-2026-6238 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when...
Medium CVE-2026-6368 libc6 2.36-9+deb12u13 — Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may...
Medium CVE-2026-6791 libc6 2.36-9+deb12u13 — When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation...
Medium CVE-2026-77117 libc6 2.36-9+deb12u13 — Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide chara...
Read more

v0.39.1

Choose a tag to compare

@SoFMeRight SoFMeRight released this 28 Sep 12:58

📦 weave-gitops — v0.39.1

Release type: latest • Commit: 5e3cd5d

Security: 🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Image Availability

Registry Image Tags
Docker Hub docker.io/hlhd/weave-gitops v0.39.1 latest
cr.pcfae.com cr.pcfae.com/hlhd/weave-gitops v0.39.1 latest
GitHub Container Registry ghcr.io/homelabhd/weave-gitops v0.39.1 latest
Digest pull commands & supply chain artifacts

docker.io/hlhd/weave-gitops

docker pull docker.io/hlhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998

cr.pcfae.com/hlhd/weave-gitops

docker pull cr.pcfae.com/hlhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998

ghcr.io/homelabhd/weave-gitops

docker pull ghcr.io/homelabhd/weave-gitops@sha256:311ef00d185dcfc334e92fd1b1d3505c34945ecf0256818bcbeb1dbb789ab998

Highlights

  • config: toolchains flag-day: want: wrapper + retention
  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version
  • build: forward version metadata build args to make (stop reporting v0.0.0)
  • ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages
  • build: enable corepack for yarn in the node 26 UI stage
  • build: bump go-build base to golang 1.27.1 for the go 1.27.0 module
  • ci: select gitops-server.dockerfile as the image build target
  • deps: hold only the upstream-blocked deps from freshness (scoped, not blanket)

Notable Changes

Features

  • config: toolchains flag-day: want: wrapper + retention (SoFMeRight)

Bug Fixes

  • build: use canonical VERSION/COMMIT/BUILD_DATE ARGs for auto-injected version (SoFMeRight)
  • build: forward version metadata build args to make (stop reporting v0.0.0) (SoFMeRight)
  • ui: restore the dashboard — fix MUI 9 Tabs render loop on detail pages (SoFMeRight)
  • build: enable corepack for yarn in the node 26 UI stage (SoFMeRight)
  • build: bump go-build base to golang 1.27.1 for the go 1.27.0 module (SoFMeRight)
  • ci: select gitops-server.dockerfile as the image build target (SoFMeRight) ×2
  • deps: hold only the upstream-blocked deps from freshness (scoped, not blanket) (SoFMeRight)
  • deps: scope dependency freshness to security-only (archived-upstream fork) (SoFMeRight)
  • deps: add ttlcache pseudo-version hashes to go.sum (dropped on rebase) (SoFMeRight)
  • deps: pin ttlcache via replace so the deps gate cannot re-downgrade it (SoFMeRight)
  • deps: clear audition freshness gate and restore the Go build (SoFMeRight)
  • deps: remediate blocking frontend + pip CVEs (audition security gate) (SoFMeRight)
  • logger: pass built message as argument, not format string (SoFMeRight)
  • deps: modernize k8s stack to 0.36 to unblock the deps gate (SoFMeRight)
  • deps: bump gomega to v1.42.1 to unblock the deps gate (SoFMeRight)
  • commit: fall back to chore, not docs, when a commit has no type (SoFMeRight)
  • build: name the dockerfile explicitly (was silently building the dev stub) (SoFMeRight)
  • config: prerelease publishes to all registries (match stable/dev) (SoFMeRight)

Documentation

  • readme: reconcile README with scribe blocks; keep local tweaks (SoFMeRight)
  • refresh generated badges (stagefreight) ×4

Tests

  • http: generate self-signed localhost cert at test time (SoFMeRight)

CI/CD

  • exclude vendored website/ docs tree from lint (SoFMeRight)
  • add StageFreight pipeline — build the weave-gitops webapp from upstream main (SoFMeRight)
  • do not cancel release or dependabot runs in concurrency (weaveworks#5320) (Charles Sibbald)

Maintenance

  • governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) ×15
  • deps: update managed dependencies (stagefreight) ×6
  • deps: bump frontend CVE deps within-major (SoFMeRight)
  • deps: bump Go 1.27 + go-git/x-crypto/grpc/go-jose/go-billy/otel (SoFMeRight)
  • config: migrate to current stagefreight schema + canonical suite (SoFMeRight)

Other Changes

  • Revert "fix(build): name the dockerfile explicitly (was silently building the dev stub)" (SoFMeRight)

Security

🛡️ ❌ Critical — 1 critical and 7 high vulnerabilities detected

Vulnerability details (1 critical, 7 high, 27 medium, 26 low)
Severity CVE Package Installed Fixed Description
Critical CVE-2026-31789 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a...
High CVE-2025-15467 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may...
High CVE-2025-69421 libssl3 3.0.17-1~deb12u3 3.0.18-1~deb12u2 Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a...
High CVE-2026-28387 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or...
High CVE-2026-28388 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary...
High CVE-2026-28389 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-28390 libssl3 3.0.17-1~deb12u3 3.0.19-1~deb12u2 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process...
High CVE-2026-45447 libssl3 3.0.17-1~deb12u3 3.0.20-1~deb12u2 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process...
Medium CVE-2026-0915 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0...
Medium CVE-2026-18374 libc6 2.36-9+deb12u13 — Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow...
Medium CVE-2026-19499 libc6 2.36-9+deb12u13 — Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding...
Medium CVE-2026-19542 libc6 2.36-9+deb12u13 — Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application...
Medium CVE-2026-4046 libc6 2.36-9+deb12u13 2.36-9+deb12u14 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to...
Medium CVE-2026-4437 libc6 2.36-9+deb12u13 2.36-9+deb12u14 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response...
Medium CVE-2026-5435 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds...
Medium CVE-2026-5450 libc6 2.36-9+deb12u13 — Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024...
Medium CVE-2026-5928 libc6 2.36-9+deb12u13 — Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library...
Medium CVE-2026-6238 libc6 2.36-9+deb12u13 — The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when...
Medium CVE-2026-6368 libc6 2.3...
Read more