Skip to content

chore(deps): update helm release cert-manager to v1.20.2#2337

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/cert-manager-1.x
Open

chore(deps): update helm release cert-manager to v1.20.2#2337
renovate[bot] wants to merge 1 commit intomainfrom
renovate/cert-manager-1.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Apr 13, 2026

This PR contains the following updates:

Package Update Change
cert-manager (source) patch v1.20.1v1.20.2

Release Notes

cert-manager/cert-manager (cert-manager)

v1.20.2

Compare Source

v1.20.2 fixes invalid YAML generated in the Helm chart when both webhook.config
and webhook.volumes are defined, and bumps Go to 1.26.2 along with dependencies
to address reported vulnerabilities.

Changes by Kind

Bug or Regression
Other (Cleanup or Flake)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from bo0tzz as a code owner April 13, 2026 09:58
@renovate renovate bot enabled auto-merge (squash) April 13, 2026 09:58
@github-actions
Copy link
Copy Markdown

--- . Kustomization: flux-system/flux-system HelmRelease: dns/cert-manager

+++ . Kustomization: flux-system/flux-system HelmRelease: dns/cert-manager

@@ -6,13 +6,13 @@

   namespace: dns
 spec:
   interval: 1h
   chart:
     spec:
       chart: cert-manager
-      version: v1.20.1
+      version: v1.20.2
       sourceRef:
         kind: HelmRepository
         name: cert-manager
         namespace: dns
       interval: 1h
   values:

@github-actions
Copy link
Copy Markdown

--- . HelmRelease: dns/cert-manager Deployment: dns/cert-manager

+++ . HelmRelease: dns/cert-manager Deployment: dns/cert-manager

@@ -39,20 +39,20 @@

       volumes:
       - name: config
         configMap:
           name: cert-manager
       containers:
       - name: cert-manager-controller
-        image: quay.io/jetstack/cert-manager-controller:v1.20.1
+        image: quay.io/jetstack/cert-manager-controller:v1.20.2
         imagePullPolicy: IfNotPresent
         args:
         - --v=2
         - --config=/var/cert-manager/config/config.yaml
         - --cluster-resource-namespace=$(POD_NAMESPACE)
         - --leader-election-namespace=kube-system
-        - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.20.1
+        - --acme-http01-solver-image=quay.io/jetstack/cert-manager-acmesolver:v1.20.2
         - --max-concurrent-challenges=60
         ports:
         - containerPort: 9402
           name: http-metrics
           protocol: TCP
         - containerPort: 9403
--- . HelmRelease: dns/cert-manager Job: dns/cert-manager-startupapicheck

+++ . HelmRelease: dns/cert-manager Job: dns/cert-manager-startupapicheck

@@ -31,13 +31,13 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-startupapicheck
-        image: quay.io/jetstack/cert-manager-startupapicheck:v1.20.1
+        image: quay.io/jetstack/cert-manager-startupapicheck:v1.20.2
         imagePullPolicy: IfNotPresent
         args:
         - check
         - api
         - --wait=1m
         - -v
--- . HelmRelease: dns/cert-manager Deployment: dns/cert-manager-webhook

+++ . HelmRelease: dns/cert-manager Deployment: dns/cert-manager-webhook

@@ -35,13 +35,13 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-webhook
-        image: quay.io/jetstack/cert-manager-webhook:v1.20.1
+        image: quay.io/jetstack/cert-manager-webhook:v1.20.2
         imagePullPolicy: IfNotPresent
         args:
         - --v=2
         - --secure-port=10250
         - --dynamic-serving-ca-secret-namespace=$(POD_NAMESPACE)
         - --dynamic-serving-ca-secret-name=cert-manager-webhook-ca
--- . HelmRelease: dns/cert-manager Deployment: dns/cert-manager-cainjector

+++ . HelmRelease: dns/cert-manager Deployment: dns/cert-manager-cainjector

@@ -35,13 +35,13 @@

       securityContext:
         runAsNonRoot: true
         seccompProfile:
           type: RuntimeDefault
       containers:
       - name: cert-manager-cainjector
-        image: quay.io/jetstack/cert-manager-cainjector:v1.20.1
+        image: quay.io/jetstack/cert-manager-cainjector:v1.20.2
         imagePullPolicy: IfNotPresent
         args:
         - --v=2
         - --leader-election-namespace=kube-system
         ports:
         - containerPort: 9402

Copy link
Copy Markdown

@claude claude bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cert-manager: v1.20.1 → v1.20.2

Verdict: Safe to merge

This is a patch release with two changes:

  • Helm bug fix: fixes invalid YAML when both webhook.config and webhook.volumes are defined — this repo uses neither, so not impacted
  • Security maintenance: Go bumped to 1.26.2, vulnerable Go dependencies updated

No breaking changes, no deprecations, no config changes needed.

Sources consulted:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants