Skip to content

chore(deps): update networkpolicy docker tag to v4.6.0 - #153

Merged
lunarys merged 1 commit into
mainfrom
renovate/networkpolicy-4.x
Jul 31, 2026
Merged

chore(deps): update networkpolicy docker tag to v4.6.0#153
lunarys merged 1 commit into
mainfrom
renovate/networkpolicy-4.x

Conversation

@renovate

@renovate renovate Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
networkpolicy minor 4.4.04.6.0

Release Notes

lunarys/generic-helm-chart (networkpolicy)

v4.6.0

Compare Source

Features
  • network-policy: allow multiple local subnet cidr (c0115b7)

v4.5.0

Compare Source

Bug Fixes
  • config: enforce single key restriction for subPath mounting in config values (7d3e95d)
  • cronjob: remove default schedule (08cab12)
Features
  • cronjob: add initial generic-cronjob implementation (fbdbff2)
  • cronjob: enhance generic CronJob with service account support and network policy integration (cf2cc06)
  • cronjob: integrate custom network labels for enhanced network policy support (9d8c379)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

lunarys commented Jul 31, 2026

Copy link
Copy Markdown
Owner

Renovate Review: networkpolicy 4.4.0 → 4.6.0 (minor)

Risk: 🟡 MEDIUM

Check Result
Inputs ✅ complete
Description vs. diff ✅ consistent (single-line bump to 03_apps/values.yaml's networkPolicyChartVersion default)
Rendered diff 🔴 none at all — no rendered-diff comment exists on this PR
Changelog vs. config ✅ checked against what's already known, no violation found

Details:

  • This only touches 03_apps/values.yaml, which is outside the pr-diff workflow's trigger paths (03_apps/apps/**, 02_bootstrap/**) — so unlike PR chore(deps): update externalsecrets docker tag to v4.6.0 #128 (which hit this same coverage gap but still got a rendered diff because it also touched an in-scope file), this PR triggers no rendered diff at all, not even a "no changes detected" comment. This is a wider blind spot than a truncated diff: zero visibility into the actual rendered effect of bumping the repo-wide default network-policy chart version.
  • This default is used by every app in the repo with networkpolicy.enabled: true (mosquitto, teamspeak, jellyfin, n8n, adguard-sync, heimdall, home-assistant, crowdsec web-ui, cloudnative-pg components, kyverno, nodered, and more) that doesn't pin its own version — a materially wider blast radius than a single-app bump.
  • The same v4.5.0/v4.6.0 changelog already reviewed for PR chore(deps): update generic-service docker tag to v4.6.0 #146 (generic-service) applies here: the subPath single-key restriction and the multi-subnet-CIDR feature. PR chore(deps): update generic-service docker tag to v4.6.0 #146's rendered diffs showed the CIDR feature as an additive, benign widening (adds the cluster's IPv6 ULA range alongside the existing trusted /20) — but that was confirmed specifically for the generic-service-based apps, not independently for whichever apps render their network policies through this separate default.

Why medium: a security-relevant, repo-wide default changes with literally no rendered-diff visibility at all — the same feature was benign where it could be checked directly (#146), but that can't be independently confirmed here.


Generated by Claude Code

@lunarys
lunarys merged commit 7377334 into main Jul 31, 2026
@renovate
renovate Bot deleted the renovate/networkpolicy-4.x branch July 31, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant