feat(container): update image ghcr.io/coder/code-server (4.138.0 ➔ 4.139.1) #2221

Merged
GiorgioAresu merged 1 commit from renovate/ghcr.io-coder-code-server-4.x into main 2026-09-26 07:44:55 +02:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/coder/code-server minor 4.138.0 → 4.139.1

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Europe/Rome)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | ghcr.io/coder/code-server | minor | `4.138.0` → `4.139.1` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/6) for more information. --- ### Configuration 📅 **Schedule**: (in timezone Europe/Rome) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMDQuMiIsInVwZGF0ZWRJblZlciI6IjQ0LjEwNC4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
feat(container): update image ghcr.io/coder/code-server (4.138.0 ➔ 4.139.1)
All checks were successful
Labeler / Labeler (pull_request) Successful in 4s
Lint / actionlint (pull_request) Successful in 6s
Lint / yamllint (pull_request) Successful in 13s
AI PR Review / AI PR Review (pull_request) Successful in 44s
Konflate 2 resources changed
7c0ec9efb6
Collaborator

Routine: only container-image and chart-version changes; 2 resources across 2 apps

image from to upstream
ghcr.io/coder/code-server 4.138.0@sha256:81706b… 4.139.1@sha256:0c067c… ❔

konflate 0.6.4 · rendered 7c0ec9e · full diff →

<!-- konflate:pr-2221 --> **Routine**: only container-image and chart-version changes; 2 resources across 2 apps | image | from | to | upstream | |---|---|---|---| | `ghcr.io/coder/code-server` | `4.138.0@sha256:81706b…` | `4.139.1@sha256:0c067c…` | ❔ | <sub>konflate 0.6.4 · rendered `7c0ec9e` · [full diff →](https://konflate.aresu.eu/#/pr/2221)</sub>
Collaborator

✅ Automated recommendation: APPROVE

Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)

Recommendation: Approve

Routine Renovate container image bump for the code-server sidecar in the zigbee2mqtt HelmRelease. No functional changes beyond the version/tag update.


Changes

File Change
kubernetes/apps/home-automation/zigbee2mqtt/app/helmrelease.yaml ghcr.io/coder/code-server 4.138.0 → 4.139.1 (with new @sha256: digest)

Required Checks — Addressed

Validate manifest against target cluster version — ✅ Verified

  • The manifest is a HelmRelease using apiVersion: helm.toolkit.fluxcd.io/v2, a stable Flux API. No Kubernetes API version changes are involved — this is purely a container image reference bump. The HelmRelease schema validates correctly (yamlls schema present in the file).

Check for resource quota / limit changes — ✅ Verified (not applicable)

  • The code-server container's resources block (requests.cpu: 10m, limits.memory: 512Mi) is unchanged. Only the image.tag field was modified.

Standards Compliance

Per .agents/instructions/pr-review.instructions.md and AGENTS.md:

  • Container images are correctly pinned with both version tag and @sha256: digest (new image includes full digest sha256:0c067c3cf09ed…). ✅
  • metadata.namespace is absent from the HelmRelease — intentional per repo convention; namespace is injected at build time via kustomize. ✅
  • No resource limit changes that would affect cluster quota. ✅

Evidence Provider Findings

Konflate rendered diff confirms:

  • Deployment home-automation/zigbee2mqtt — only image tag changed (ghcr.io/coder/code-server:4.138.0 → 4.139.1)
  • All other fields (resources, persistence, route, security context) — unchanged
  • Render exit code 0, no warnings or errors

Caveat

The upstream release source for coder/code-server 4.139.1 could not be confirmed via the GitHub API lookup in the corpus (GH API enrichment returned no release data). This is a minor upstream-verification gap for a patch/minor image bump; it does not block approval given the routine nature of the change and the pinned digest providing image integrity.

<!-- ai-pr-reviewer --> <!-- ai-pr-reviewer:{"version":1,"head_sha":"7c0ec9efb6b45238965b3a43d2f3970cb6c51f73","base_sha":"a1aee1f245b17e66af8d8b37e176afeed92c68d5","review_scope":"full","review_result":"clean","required_checks":"complete"} --> <!-- ai-pr-review-sha:7c0ec9efb6b45238965b3a43d2f3970cb6c51f73 --> <!-- ai-pr-review-fingerprint:2c16259d946452139e497d7599cc7321c280de552000a1a7602f4e0e928d25da|cfg:d27ea58bdbdafc403f62b1b84c70d905cc97c77c6d72d767872b88951af9ea8d --> ✅ **Automated recommendation: APPROVE** _Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)_ **Recommendation: Approve** Routine Renovate container image bump for the code-server sidecar in the zigbee2mqtt HelmRelease. No functional changes beyond the version/tag update. --- ## Changes | File | Change | |---|---| | `kubernetes/apps/home-automation/zigbee2mqtt/app/helmrelease.yaml` | `ghcr.io/coder/code-server` `4.138.0` → `4.139.1` (with new `@sha256:` digest) | --- ## Required Checks — Addressed **Validate manifest against target cluster version** — ✅ Verified - The manifest is a `HelmRelease` using `apiVersion: helm.toolkit.fluxcd.io/v2`, a stable Flux API. No Kubernetes API version changes are involved — this is purely a container image reference bump. The HelmRelease schema validates correctly (yamlls schema present in the file). **Check for resource quota / limit changes** — ✅ Verified (not applicable) - The code-server container's `resources` block (`requests.cpu: 10m`, `limits.memory: 512Mi`) is unchanged. Only the `image.tag` field was modified. --- ## Standards Compliance Per `.agents/instructions/pr-review.instructions.md` and `AGENTS.md`: - Container images are correctly pinned with both version tag and `@sha256:` digest (new image includes full digest `sha256:0c067c3cf09ed…`). ✅ - `metadata.namespace` is absent from the `HelmRelease` — intentional per repo convention; namespace is injected at build time via kustomize. ✅ - No resource limit changes that would affect cluster quota. ✅ ## Evidence Provider Findings Konflate rendered diff confirms: - Deployment `home-automation/zigbee2mqtt` — only image tag changed (`ghcr.io/coder/code-server:4.138.0` → `4.139.1`) - All other fields (resources, persistence, route, security context) — unchanged - Render exit code 0, no warnings or errors ## Caveat The upstream release source for `coder/code-server` 4.139.1 could not be confirmed via the GitHub API lookup in the corpus (GH API enrichment returned no release data). This is a minor upstream-verification gap for a patch/minor image bump; it does not block approval given the routine nature of the change and the pinned digest providing image integrity.
Sign in to join this conversation.
No description provided.