chore(deps): update dependency argoproj/argo-cd to v3.5.4 #94

Open
renovatebot wants to merge 1 commit from renovate/argocd into main
Collaborator

This PR contains the following updates:

Package Update Change
argoproj/argo-cd patch v3.5.3 -> v3.5.4

Release Notes

argoproj/argo-cd (argoproj/argo-cd)

v3.5.4

Compare Source

Quick Start

Non-HA:
kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.4/manifests/install.yaml
HA:
kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.4/manifests/ha/install.yaml

Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog

Security fixes
  • CRITICAL: A Kustomize remote ref can run commands in the repo-server (GHSA-9v9p-x54c-58gc)
  • CRITICAL: A Kustomize Helm config home can run commands in the repo-server (GHSA-fw5c-w8rc-j7fx)
  • CRITICAL: A Jsonnet import can read files from the repo-server (GHSA-m3vr-7329-44ww)
  • CRITICAL: AppProject restrictions bypassed by PreDelete/PostDelete resource hooks (GHSA-fmxq-cgp8-87wp, CVE-2026-77459)
  • HIGH: Login failure rate limit can be bypassed via concurrent requests (GHSA-4439-h7jw-5cjj, CVE-2025-61560)
  • HIGH: Command injection via a repository proxy URL on SSH Git repositories (GHSA-j6cw-g6p4-7hch, CVE-2026-55797)
  • MODERATE: Extension proxy RBAC ignores application namespace when applications-in-any-namespace is enabled (GHSA-g3ff-q88g-chrj)
  • MODERATE: An oversized OCI manifest can exhaust repo-server memory (GHSA-w996-f2wq-x9c6)
Potentially-breaking changes
  • Kustomize builds that render Helm charts no longer honor helmGlobals.configHome. Ordinary http, https, and oci chart repositories still work. Builds that depended on a Helm plugin registered from that directory will not (GHSA-fw5c-w8rc-j7fx).
  • An OCI manifest larger than 4 MiB is now rejected (GHSA-w996-f2wq-x9c6).
Features
Bug fixes
Other work

Full Changelog: https://github.com/argoproj/argo-cd/compare/v3.5.3...v3.5.4


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [argoproj/argo-cd](https://github.com/argoproj/argo-cd) | patch | `v3.5.3` -> `v3.5.4` | --- ### Release Notes <details> <summary>argoproj/argo-cd (argoproj/argo-cd)</summary> ### [`v3.5.4`](https://github.com/argoproj/argo-cd/releases/tag/v3.5.4) [Compare Source](https://github.com/argoproj/argo-cd/compare/v3.5.3...v3.5.4) #### Quick Start ##### Non-HA: ```shell kubectl create namespace argocd kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.4/manifests/install.yaml ``` ##### HA: ```shell kubectl create namespace argocd kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.5.4/manifests/ha/install.yaml ``` #### Release Signatures and Provenance All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the [documentation](https://argo-cd.readthedocs.io/en/stable/operator-manual/signed-release-assets) on how to verify. #### Release Notes Blog Post For a detailed breakdown of the key changes and improvements in this release, check out the [official blog post](https://blog.argoproj.io/argo-cd-v3-0-release-candidate-a0b933f4e58f) #### Upgrading If upgrading from a different minor version, be sure to read the [upgrading](https://argo-cd.readthedocs.io/en/stable/operator-manual/upgrading/overview/) documentation. #### Changelog ##### Security fixes - CRITICAL: A Kustomize remote ref can run commands in the repo-server ([GHSA-9v9p-x54c-58gc](https://github.com/argoproj/argo-cd/security/advisories/GHSA-9v9p-x54c-58gc)) - CRITICAL: A Kustomize Helm config home can run commands in the repo-server ([GHSA-fw5c-w8rc-j7fx](https://github.com/argoproj/argo-cd/security/advisories/GHSA-fw5c-w8rc-j7fx)) - CRITICAL: A Jsonnet import can read files from the repo-server ([GHSA-m3vr-7329-44ww](https://github.com/argoproj/argo-cd/security/advisories/GHSA-m3vr-7329-44ww)) - CRITICAL: AppProject restrictions bypassed by PreDelete/PostDelete resource hooks ([GHSA-fmxq-cgp8-87wp](https://github.com/argoproj/argo-cd/security/advisories/GHSA-fmxq-cgp8-87wp), CVE-2026-77459) - HIGH: Login failure rate limit can be bypassed via concurrent requests ([GHSA-4439-h7jw-5cjj](https://github.com/argoproj/argo-cd/security/advisories/GHSA-4439-h7jw-5cjj), CVE-2025-61560) - HIGH: Command injection via a repository proxy URL on SSH Git repositories ([GHSA-j6cw-g6p4-7hch](https://github.com/argoproj/argo-cd/security/advisories/GHSA-j6cw-g6p4-7hch), CVE-2026-55797) - MODERATE: Extension proxy RBAC ignores application namespace when applications-in-any-namespace is enabled ([GHSA-g3ff-q88g-chrj](https://github.com/argoproj/argo-cd/security/advisories/GHSA-g3ff-q88g-chrj)) - MODERATE: An oversized OCI manifest can exhaust repo-server memory ([GHSA-w996-f2wq-x9c6](https://github.com/argoproj/argo-cd/security/advisories/GHSA-w996-f2wq-x9c6)) ##### Potentially-breaking changes - Kustomize builds that render Helm charts no longer honor `helmGlobals.configHome`. Ordinary `http`, `https`, and `oci` chart repositories still work. Builds that depended on a Helm plugin registered from that directory will not ([GHSA-fw5c-w8rc-j7fx](https://github.com/argoproj/argo-cd/security/advisories/GHSA-fw5c-w8rc-j7fx)). - An OCI manifest larger than 4 MiB is now rejected ([GHSA-w996-f2wq-x9c6](https://github.com/argoproj/argo-cd/security/advisories/GHSA-w996-f2wq-x9c6)). ##### Features - [`f37dc0c`](https://github.com/argoproj/argo-cd/commit/f37dc0c742724e1b5f2393839a24d9664f31ede7): feat(server): log username on login attempts (cherry-pick [#&#8203;29841](https://github.com/argoproj/argo-cd/issues/29841) for 3.5) ([#&#8203;29861](https://github.com/argoproj/argo-cd/issues/29861)) ([@&#8203;argo-cd-cherry-pick-bot](https://github.com/argo-cd-cherry-pick-bot)\[bot]) ##### Bug fixes - [`5c8aa46`](https://github.com/argoproj/argo-cd/commit/5c8aa4620c0a606e9fe5e03a07e3dcaabe81fbe6): fix(cmp): clean up tgz stream temporary directories ([#&#8203;29148](https://github.com/argoproj/argo-cd/issues/29148)) (cherry-pick [#&#8203;29156](https://github.com/argoproj/argo-cd/issues/29156) for 3.5) ([#&#8203;29773](https://github.com/argoproj/argo-cd/issues/29773)) ([@&#8203;argo-cd-cherry-pick-bot](https://github.com/argo-cd-cherry-pick-bot)\[bot]) - [`7f0a058`](https://github.com/argoproj/argo-cd/commit/7f0a05834b05103d69d7c150e1ee36541b314696): fix(security): coordinated security fixes (release-3.5) ([#&#8203;30038](https://github.com/argoproj/argo-cd/issues/30038)) ([@&#8203;crenshaw-dev](https://github.com/crenshaw-dev)) - [`482c71a`](https://github.com/argoproj/argo-cd/commit/482c71a558b3001e028316232fe2f86c25becb09): fix(ui): manifest viewer jumpiness ([#&#8203;29691](https://github.com/argoproj/argo-cd/issues/29691)) (cherry pick 3.5) ([#&#8203;29725](https://github.com/argoproj/argo-cd/issues/29725)) ([@&#8203;crenshaw-dev](https://github.com/crenshaw-dev)) - [`1f8100a`](https://github.com/argoproj/argo-cd/commit/1f8100a3db64fdc520b768c5606b6fca4e4ad09c): fix: cherry-pick [#&#8203;29737](https://github.com/argoproj/argo-cd/issues/29737) (release-3.5) ([#&#8203;29749](https://github.com/argoproj/argo-cd/issues/29749)) ([@&#8203;blakepettersson](https://github.com/blakepettersson)) - [`9886fc1`](https://github.com/argoproj/argo-cd/commit/9886fc1363e92a517b811375505317912cdb82b9): fix: use ObjectMeta in session login test (release-3.5) ([#&#8203;29919](https://github.com/argoproj/argo-cd/issues/29919)) ([@&#8203;crenshaw-dev](https://github.com/crenshaw-dev)) ##### Other work - [`a9d0b96`](https://github.com/argoproj/argo-cd/commit/a9d0b9684a6470741a9ee61a05d4f70eb76c85d6): fix(manifest-generate-paths): do not report changes on cache miss without path updates (cherry-pick [#&#8203;29442](https://github.com/argoproj/argo-cd/issues/29442) for 3.5) ([#&#8203;29849](https://github.com/argoproj/argo-cd/issues/29849)) ([@&#8203;argo-cd-cherry-pick-bot](https://github.com/argo-cd-cherry-pick-bot)\[bot]) - [`fc2d94d`](https://github.com/argoproj/argo-cd/commit/fc2d94d906db9e0a4650e7936036022cc9fe232d): fix(repo-server): cherry-pick health check timeout resulting in CrashLoopBackOff to release-3.5 branch ([#&#8203;29901](https://github.com/argoproj/argo-cd/issues/29901)) ([@&#8203;aali309](https://github.com/aali309)) - [`f0de0be`](https://github.com/argoproj/argo-cd/commit/f0de0be59114d7eb3bfb3b4c2793b65ba013ad1f): test(flaky): accept connection reset by peer as valid mTLS rejection (cherry-pick [#&#8203;28367](https://github.com/argoproj/argo-cd/issues/28367) for 3.5) ([#&#8203;29850](https://github.com/argoproj/argo-cd/issues/29850)) ([@&#8203;argo-cd-cherry-pick-bot](https://github.com/argo-cd-cherry-pick-bot)\[bot]) **Full Changelog**: https://github.com/argoproj/argo-cd/compare/v3.5.3...v3.5.4 <a href="https://argoproj.github.io/cd/"><img src="https://raw.githubusercontent.com/argoproj/argo-site/master/content/pages/cd/gitops-cd.png" width="25%" ></a> </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0MS43My4wIiwidXBkYXRlZEluVmVyIjoiNDEuNzMuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
renovatebot scheduled this pull request to auto merge when all checks succeed 2026-10-07 00:04:45 -04:00
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/argocd:renovate/argocd
git switch renovate/argocd

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/argocd
git switch renovate/argocd
git rebase main
git switch main
git merge --ff-only renovate/argocd
git switch renovate/argocd
git rebase main
git switch main
git merge --no-ff renovate/argocd
git switch main
git merge --squash renovate/argocd
git switch main
git merge --ff-only renovate/argocd
git switch main
git merge renovate/argocd
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
smig/nuc-talos!94
No description provided.