Skip to content

fix(container): update image ghcr.io/stacklok/toolhive/toolhive-operator to v0.29.3 - #1657

Merged
Stormcargo merged 1 commit into
mainfrom
renovate/ghcr.io-stacklok-toolhive-toolhive-operator-0.x
Jun 13, 2026
Merged

Stormcargo merged 1 commit into
mainfrom
renovate/ghcr.io-stacklok-toolhive-toolhive-operator-0.x

Conversation

@renovate

@renovate renovate Bot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
ghcr.io/stacklok/toolhive/toolhive-operator patch 0.29.10.29.3

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions github-actions Bot added the area/kubernetes Changes made in the kubernetes directory label Jun 13, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ghcr.io/stacklok/toolhive/toolhive-operator (Helm chart, OCIRepository): 0.29.1 → 0.29.3

Verdict: Safe to merge

This is a chart version bump that tracks the main stacklok/toolhive release stream (v0.29.1 → v0.29.2 → v0.29.3). No breaking changes or actionable deprecations for this repo.

Notes (informational, no action required):

  • MCPRegistry CRD deprecated (v0.29.2) — superseded by the toolhive-registry-server Helm chart; still functional but now emits a deprecation warning. Not used anywhere in this repo, so unaffected.
  • New Warn-level log for unauthenticated proxies (v0.29.3)GetAuthenticationMiddleware now logs at Warn (was Debug) when an MCPServer/vMCP runs without OIDCConfigRef. This is a follow-up to GHSA-hfrv-94x5-85p2 and does not change behavior, only visibility. This repo's kubernetes/apps/ai-slop/ha-mcp and grafana-mcp MCPServers, and the tools-gateway VirtualMCPServer (incomingAuth.type: anonymous), run without OIDC config — expect new Warn-level startup logs there. This matches the intentional internal-only design (ingressClassName: internal), so no change needed.
  • v0.29.2 also bundles two security hardening fixes: a path-traversal fix in LocalStore.getFilePath, and new X-Content-Type-Options/Cross-Origin-Resource-Policy response headers on the thv REST API — both pure upside.
  • The v0.29.2 fix for operator.serviceAccount.name overrides doesn't apply here since this repo's helmrelease.yaml only sets operator.replicaCount and operator.resources.limits.memory.

Sources consulted:

@Stormcargo
Stormcargo merged commit 3d1c728 into main Jun 13, 2026
2 checks passed
@Stormcargo
Stormcargo deleted the renovate/ghcr.io-stacklok-toolhive-toolhive-operator-0.x branch June 13, 2026 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/kubernetes Changes made in the kubernetes directory renovate/container type/patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant