Skip to content

WIP: Enable Renovate vulnerability alerts - #410

Closed
erikgb wants to merge 1 commit into
cert-manager:mainfrom
erikgb:vul-alerts
Closed

WIP: Enable Renovate vulnerability alerts#410
erikgb wants to merge 1 commit into
cert-manager:mainfrom
erikgb:vul-alerts

Conversation

@erikgb

@erikgb erikgb commented Sep 6, 2025

Copy link
Copy Markdown
Member

I want to see how this works, and eventually consider enabling it for our release branches.

Replaces #407

Signed-off-by: Erik Godding Boye <egboye@gmail.com>
@cert-manager-prow cert-manager-prow Bot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 6, 2025
@cert-manager-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign munnerz for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@cert-manager-prow cert-manager-prow Bot added dco-signoff: yes Indicates that all commits in the pull request have the valid DCO sign-off message. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Sep 6, 2025
@cert-manager-prow

Copy link
Copy Markdown
Contributor

PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@cert-manager-prow cert-manager-prow Bot added the needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. label Sep 8, 2025
@maelvls

maelvls commented Sep 9, 2025

Copy link
Copy Markdown
Member

Will it push the alerts to https://github.com/cert-manager/cert-manager/security/advisories? I.e., to that UI:

screenshot-2025-06-02-1145 106-fs8

That would be super useful, then I can start triaging and publishing advisories, starting with CVE-2025-47907.

@erikgb

erikgb commented Sep 9, 2025

Copy link
Copy Markdown
Member Author

@maelvls, I am not sure how this will work. But this PR is blocked by octo-sts/app#1039 anyway now. Hoping for Octo STS to include the missing permission in their next revision.

@erikgb erikgb closed this Sep 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dco-signoff: yes Indicates that all commits in the pull request have the valid DCO sign-off message. do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants