Describe the bug
charts/redis-ha/values.yaml pins haproxy.image.tag: 3.3.10-alpine (set in #405, 2026-06-14). That image carries three critical CVEs:
haproxy:3.3.14-alpine was rebuilt 2026-09-18 on Alpine 3.24, whose APKINDEX carries libcrypto3/libssl3 3.5.8-r0 and socat 1.8.1.3-r0 — so it clears all three.
The underlying cause
This is the third time an image pin here has gone stale into a CVE report (#392 for 3.0.8-alpine, then #405's bump, now this). No Renovate or Dependabot configuration exists in this repository — I checked renovate.json, renovate.json5, .renovaterc*, .github/renovate.* and .github/dependabot.*; none are present, and no PR in the repo's history was authored by a bot. Every image tag in values.yaml — haproxy, redis, busybox, shellcheck, redis_exporter — is hand-maintained, so they drift until someone files a report like this one.
Renovate's built-in helm-values manager would pick up haproxy and redis automatically, since both have sibling repository/tag keys. exporter.tag (line 753) has no sibling repository and would need an annotation comment.
Happy to send a config PR if you'd want one — though it needs the Renovate GitHub App installed on the repo, which only you can do. Your call entirely.
Minor
README.md line 262 still documents haproxy.image.tag as 3.0.8-alpine — helm-docs wasn't re-run after #405. The linked PR fixes that row in passing.
Prepared with the help of Claude Code; package versions verified against the Alpine v3.24 APKINDEX and the chart on master, and reviewed before filing.
Describe the bug
charts/redis-ha/values.yamlpinshaproxy.image.tag: 3.3.10-alpine(set in #405, 2026-06-14). That image carries three critical CVEs:haproxy:3.3.14-alpinewas rebuilt 2026-09-18 on Alpine 3.24, whose APKINDEX carrieslibcrypto3/libssl33.5.8-r0 andsocat1.8.1.3-r0 — so it clears all three.The underlying cause
This is the third time an image pin here has gone stale into a CVE report (#392 for 3.0.8-alpine, then #405's bump, now this). No Renovate or Dependabot configuration exists in this repository — I checked
renovate.json,renovate.json5,.renovaterc*,.github/renovate.*and.github/dependabot.*; none are present, and no PR in the repo's history was authored by a bot. Every image tag invalues.yaml— haproxy, redis, busybox, shellcheck, redis_exporter — is hand-maintained, so they drift until someone files a report like this one.Renovate's built-in
helm-valuesmanager would pick up haproxy and redis automatically, since both have siblingrepository/tagkeys.exporter.tag(line 753) has no siblingrepositoryand would need an annotation comment.Happy to send a config PR if you'd want one — though it needs the Renovate GitHub App installed on the repo, which only you can do. Your call entirely.
Minor
README.mdline 262 still documentshaproxy.image.tagas3.0.8-alpine— helm-docs wasn't re-run after #405. The linked PR fixes that row in passing.Prepared with the help of Claude Code; package versions verified against the Alpine v3.24 APKINDEX and the chart on master, and reviewed before filing.