chore(deps): update hashicorp/consul docker tag to v1.22.7 - #21
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
November 20, 2022 12:01
de1314f to
418f8b0
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
March 17, 2023 09:59
418f8b0 to
343cea1
Compare
Welcome to Codecov 🎉Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests. Thanks for integrating Codecov - We've got you covered ☂️ |
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
March 31, 2023 03:12
343cea1 to
e831c20
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
June 2, 2023 01:21
e831c20 to
39fc6e8
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
June 26, 2023 20:19
39fc6e8 to
4991bd6
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
June 27, 2023 01:31
4991bd6 to
73706a2
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
August 8, 2023 19:10
73706a2 to
1132981
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
September 20, 2023 00:23
1132981 to
443ff44
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
October 31, 2023 19:36
443ff44 to
d80c6a7
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
November 3, 2023 22:12
d80c6a7 to
7e3ff8e
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
December 15, 2023 01:32
7e3ff8e to
9951ede
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
January 23, 2024 21:44
9951ede to
c4774dd
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
February 14, 2024 01:16
c4774dd to
ae7a6f7
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
February 27, 2024 22:19
ae7a6f7 to
f1a3950
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
March 27, 2024 01:24
f1a3950 to
55ff3b0
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
January 6, 2025 06:23
f17aa60 to
6022c58
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
February 13, 2025 14:46
6022c58 to
286b2a7
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
February 20, 2025 19:02
286b2a7 to
e722405
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
March 12, 2025 15:01
e722405 to
51cfd35
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
April 28, 2025 06:51
51cfd35 to
7070a70
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
May 6, 2025 19:18
7070a70 to
651a6bc
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
May 23, 2025 15:39
651a6bc to
c3546cc
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
June 24, 2025 08:34
c3546cc to
68d4c96
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
July 24, 2025 08:54
68d4c96 to
bdab2da
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
August 13, 2025 16:27
bdab2da to
37d973c
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
September 23, 2025 13:05
37d973c to
e88025f
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
October 27, 2025 11:13
e88025f to
b36c630
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
November 26, 2025 19:55
b36c630 to
00fb597
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-consul-1.x
branch
from
December 17, 2025 15:56
00fb597 to
02e2583
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.10.0→1.22.7Release Notes
hashicorp/consul (hashicorp/consul)
v1.22.7Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
replacePrefixMatchis not configured [GH-23390]v1.22.6Compare Source
SECURITY:
IMPROVEMENTS:
v1.22.5Compare Source
SECURITY:
alpine3.23[GH-23194]IMPROVEMENTS:
--aws-iam-endpointflag toconsul logincommand for AWS IAM auth method to support custom IAM endpoint configuration [GH-23109]v1.22.3Compare Source
SECURITY:
alpine3.23.2[GH-23138]IMPROVEMENTS:
consul services imported-servicesand new api(/v1/exported-services) command to list services imported by partitions within a local datacenter [GH-12045]v1.22.2Compare Source
1.22.2 (December 15, 2025)
SECURITY:
IMPROVEMENTS:
BUG FIXES:
consul config writecommand to provide actionable guidance when config entries cannot be modified due to references by gateways or routers. [GH-22921]v1.22.1Compare Source
SECURITY:
golang.org/x/textto v0.39.0 to address GO-2026-5970. [GH-23761]google.golang.org/grpcto v1.82.1 to address GHSA-hrxh-6v49-42gf. [GH-23761]1.26.5. This resolves vulnerabilitiesGO-2026-4970 (
os).GO-2026-5856 (
crypto/tls). [GH-23761]GET /v1/agent/connect/ca/rootsand
POST /v1/agent/connect/authorizeused the agent-side cache unconditionally, evenwhen
http_config { use_cache = false }was configured by the operator. A remote callercould bypass this setting and grow the agent cache without bound by varying the request
ACL token. Both endpoints now skip the cache and issue a direct RPC when
use_cacheisdisabled. (SECVULN-50292, SECVULN-50293)
ShadowServiceRouterConfigEntry.CheckEntwhen a service-router config entry contained a route with a nil
Destination. A craftedsnapshot restore or replication message containing such an entry could crash the FSM
decode path. The nil guard now treats a missing destination as non-enterprise data and
continues decoding safely. (SECVULN-50291)
(
envoy_public_listener_json) with an HTTP Connection Manager filter would skip Consul'sinbound request-normalization defaults. An attacker could exploit the un-normalized path
to bypass L7 intention
denyrules using percent-encoded path equivalents. Consul nowinjects path normalization (enabled by default, unless the mesh config option
InsecureDisablePathNormalizationis set) on every HCM filter chain in user-providedpublic listeners before L7 intention enforcement is applied. (SECVULN-50295)
PUT /v1/agent/check/update/:iddecoded an unbounded JSON request body beforeresolving the caller's ACL token. An unauthenticated caller could retain multiple
large JSON decoder buffers concurrently inside the Consul process before each request
was rejected with HTTP 403, causing attacker-controlled heap growth proportional to
request body size and concurrency. The endpoint now caps the request body to
check_output_max_size(default 4 KB, operator-configurable) plus 512 bytes forJSON framing before any decoding occurs, returning HTTP 413 for oversized bodies.
This limit applies to chunked transfer encoding as well as declared
Content-Length.(SECVULN-50418)
and gRPC-TLS listeners accepted an unlimited number of TCP connections per source IP
before any request processing, ACL check, or rate limiting could occur. A remote attacker
could exhaust agent file descriptors, goroutines, and memory by opening many connections
and withholding the gRPC or TLS handshake. A new per-client-IP connection limiter is now
applied before the gRPC server observes the connection, controlled by the new
limits.grpc_max_conns_per_clientconfiguration option (default 100). The gRPC handshaketimeout has also been reduced from the library default of 120 seconds to 20 seconds.
(SECVULN-50294)
IMPROVEMENTS:
ProxyDefaults.spec.configkeys for controlling theserverresponse header on API Gateway HTTP listeners:envoy_suppress_envoy_headers(removes the header entirely) andenvoy_server_header_name(renames it to a custom value). If both are set, suppress takes precedence.BUG FIXES:
v1.22.0Compare Source
SECURITY:
FEATURES:
IMPROVEMENTS:
consul operator utilization [-today-only] [-message] [-y]to generate a bundle with census utilization snapshot. Main flow is implemented in consul-enterprisehttp: Added a new API Handler for
/v1/operator/utilization. Core functionality to be implemented in consul-enterpriseagent: Always enabled census metrics collection with configurable option to export it to Hashicorp Reporting [GH-22843]
snapshot agentnow supports authenticating to Azure Blob Storage using Azure Managed Service Identities (MSI). [GH-11171]BUG FIXES:
consul operator utilization --helpto show only available options without extra parameters. [GH-22912]v1.21.5Compare Source
SECURITY:
mitchellh/mapstructuretogo-viper/mapstructureto v2 to address CVE-2025-52893. [GH-22581]FEATURES:
max_request_headers_kbto configure maximum header size for requests from downstream to upstream [GH-22604]max_request_headers_kbto configure maximum header size for requests from downstream to upstream in API Gateway config and proxy-defaults [GH-22679]max_request_headers_kbto configure maximum header size for requests from downstream to upstream in Mesh Gateway via service-defaults and proxy-defaults [GH-22722]max_request_headers_kbto configure maximum header size for requests from downstream to upstream in Terminating Gateway service-defaults and proxy-defaults [GH-22680]IMPROVEMENTS:
BUG FIXES:
v1.21.4Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
v1.21.3Compare Source
IMPROVEMENTS:
BUG FIXES:
v1.21.2Compare Source
SECURITY:
CVE-2025-4802
CVE-2024-40896
CVE-2024-12243
CVE-2025-24528
CVE-2025-3277
CVE-2024-12133
CVE-2024-57970
CVE-2025-31115 [GH-22409]
IMPROVEMENTS:
datacenterresulting in non-generation of X.509 certificates when using external CA for agent TLS communication. [GH-22382]BUG FIXES:
v1.21.1Compare Source
SECURITY:
golang.org/x/textto v0.39.0 to address GO-2026-5970. [GH-23761]google.golang.org/grpcto v1.82.1 to address GHSA-hrxh-6v49-42gf. [GH-23761]1.26.5. This resolves vulnerabilitiesGO-2026-4970 (
os).GO-2026-5856 (
crypto/tls). [GH-23761]GET /v1/agent/connect/ca/rootsand
POST /v1/agent/connect/authorizeused the agent-side cache unconditionally, evenwhen
http_config { use_cache = false }was configured by the operator. A remote callercould bypass this setting and grow the agent cache without bound by varying the request
ACL token. Both endpoints now skip the cache and issue a direct RPC when
use_cacheisdisabled. (SECVULN-50292, SECVULN-50293)
ShadowServiceRouterConfigEntry.CheckEntwhen a service-router config entry contained a route with a nil
Destination. A craftedsnapshot restore or replication message containing such an entry could crash the FSM
decode path. The nil guard now treats a missing destination as non-enterprise data and
continues decoding safely. (SECVULN-50291)
(
envoy_public_listener_json) with an HTTP Connection Manager filter would skip Consul'sinbound request-normalization defaults. An attacker could exploit the un-normalized path
to bypass L7 intention
denyrules using percent-encoded path equivalents. Consul nowinjects path normalization (enabled by default, unless the mesh config option
InsecureDisablePathNormalizationis set) on every HCM filter chain in user-providedpublic listeners before L7 intention enforcement is applied (SECVULN-50295)
PUT /v1/agent/check/update/:iddecoded an unbounded JSON request body beforeresolving the caller's ACL token. An unauthenticated caller could retain multiple
large JSON decoder buffers concurrently inside the Consul process before each request
was rejected with HTTP 403, causing attacker-controlled heap growth proportional to
request body size and concurrency. The endpoint now caps the request body to
check_output_max_size(default 4 KB, operator-configurable) plus 512 bytes forJSON framing before any decoding occurs, returning HTTP 413 for oversized bodies.
This limit applies to chunked transfer encoding as well as declared
Content-Length.(SECVULN-50418)
and gRPC-TLS listeners accepted an unlimited number of TCP connections per source IP
before any request processing, ACL check, or rate limiting could occur. A remote attacker
could exhaust agent file descriptors, goroutines, and memory by opening many connections
and withholding the gRPC or TLS handshake. A new per-client-IP connection limiter is now
applied before the gRPC server observes the connection, controlled by the new
limits.grpc_max_conns_per_clientconfiguration option (default 100). The gRPC handshaketimeout has also been reduced from the library default of 120 seconds to 20 seconds.
(SECVULN-50294)
IMPROVEMENTS:
ProxyDefaults.spec.configkeys for controlling theserverresponse header on API Gateway HTTP listeners:envoy_suppress_envoy_headers(removes the header entirely) andenvoy_server_header_name(renames it to a custom value). If both are set, suppress takes precedence.BUG FIXES:
v1.21.0Compare Source
v1.20.6Compare Source
1.20.6 (April 25, 2025)
SECURITY:
golang.org/x/netto v0.38.0 to address GHSA-vvgc-356p-c3xw and GO-2025-3595.Update
github.com/golang-jwt/jwt/v4to v4.5.2 to address GO-2025-3553 and GHSA-mh63-6h87-95cp.Update
Goto v1.23.8 to address GO-2025-3563. [GH-22268]IMPROVEMENTS:
BUG FIXES:
v1.20.5Compare Source
1.20.5 (March 11, 2025)
SECURITY:
golang.org/x/cryptoto v0.35.0 to address GO-2025-3487.Update
golang.org/x/oauth2to v0.27.0 to address GO-2025-3488.Update
github.com/go-jose/go-jose/v3to v3.0.4 to address GO-2025-3485. [GH-22207]BUG FIXES:
v1.20.4Compare Source
1.20.4 (February 20, 2025)
IMPROVEMENTS:
BUG FIXES:
v1.20.3Compare Source
SECURITY:
CVE-2024-45341 and
CVE-2024-45336 [GH-22084]
CVE-2025-22866 [GH-22132]
IMPROVEMENTS:
BUG FIXES:
v1.20.2Compare Source
SECURITY:
github.com/golang-jwt/jwt/v4to v4.5.1 to address GHSA-29wx-vh33-7x7r. [GH-21951]golang.org/x/cryptoto v0.31.0 to address GO-2024-3321. [GH-22001]golang.org/x/netto v0.33.0 to address GO-2024-3333. [GH-22021]registry.access.redhat.com/ubi9-minimalimage to 9.5 to address CVE-2024-3596,CVE-2024-2511,CVE-2024-26458. [GH-22011]FEATURES:
BUG FIXES:
v1.20.1Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
v1.20.0Compare Source
SECURITY:
CVE-2024-34155 [GH-21705]
v1.55.5 or higher. This resolves CVEsCVE-2020-8911 and
CVE-2020-8912. [GH-21684]
FEATURES:
IMPROVEMENTS:
BUG FIXES:
v1.19.2Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
v1.19.1Compare Source
SECURITY:
IMPROVEMENTS:
BUG FIXES:
This affected Nomad integrations with Consul. [GH-21361]
tag.name.service.consul, were being disregarded. [GH-21361]that was always being logged on each prepared query evaluation. [GH-21381]
v1.19.0Compare Source
BREAKING CHANGES:
consulelement in the metric name have been removed. Please use the same metric without the secondconsulinstead. As an example instead ofconsul.consul.state.config_entriesuseconsul.state.config_entries[GH-20674]SECURITY:
1.27.5 and 1.28.3. This resolves CVECVE-2024-32475 (
auto_sni). [GH-21017]v0.18.7 or higher. This resolves CVECVE-2020-8559. [GH-21017]
FEATURES:
Use
v1dnsin theexperimentsagent config to disable.The legacy server will be removed in a future release of Consul.
See the Consul 1.19.x Release Notes for removed DNS features. [GH-20715]
IMPROVEMENTS:
github.com/envoyproxy/go-control-planeto 0.12.0. [GH-20973]consul-dataplanenow accepts partition, namespace, token as metadata to default those query parameters.consul-dataplanev1.5+ will send this information automatically. [GH-20899]consul snapshot decodeCLI command to output a JSON object stream of all the snapshots data. [GH-20824]telemetry.disable_per_tenancy_usage_metricsin agent configuration to disable setting tenancy labels on usage metrics. This significantly decreases CPU utilization in clusters with many admin partitions or namespaces.DEPRECATIONS:
local_storage,aws_storage,azure_blob_storage, andgoogle_storagein snapshot agent configuration files are now deprecated. Use thebackup_destinationsconfig object instead.BUG FIXES:
v1.18.2Compare Source
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
SECURITY:
alpine3.23[GH-23194]IMPROVEMENTS:
--aws-iam-endpointflag toconsul logincommand for AWS IAM auth method to support custom IAM endpoint configuration [GH-23109]v1.18.1Compare Source
Enterprise LTS: Consul Enterprise 1.18 is a Long-Term Support (LTS) release.
SECURITY:
registry.access.redhat.com/ubi9-minimalimage to 9.6 to address CVEs [GH-11815]IMPROVEMENTS:
BUG FIXES:
v1.18.0Compare Source
BREAKING CHANGES:
telemetry.disable_hostnamewhen determining whether to prefix gauge-type metrics with the hostname of the Consul agent. Previously, if only the default metric sink was enabled, this configuration was ignored and always treated astrue, even though its default value isfalse. [GH-20312]SECURITY:
golang.org/x/cryptoto v0.17.0 to address CVE-2023-48795. [GH-20023]FEATURES:
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.