fix(container): update image public.ecr.aws/docker/library/redis (d5ac52d ➔ 6f81e89) #2243

Open
renovate-bot wants to merge 1 commit from renovate/public.ecr.aws-docker-library-redis-8.10.2 into main
Collaborator

This PR contains the following updates:

Package Update Change
public.ecr.aws/docker/library/redis (source) digest d5ac52d → 6f81e89

⚠️ Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (in timezone Europe/Rome)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [public.ecr.aws/docker/library/redis](https://hub.docker.com/_/redis) ([source](https://github.com/redis/docker-library-redis)) | digest | `d5ac52d` → `6f81e89` | --- > ⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/6) for more information. --- ### Configuration 📅 **Schedule**: (in timezone Europe/Rome) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
fix(container): update image public.ecr.aws/docker/library/redis (d5ac52d ➔ 6f81e89)
All checks were successful
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 6s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 42s
Konflate 2 resources changed
6962bbe19e
Collaborator

Routine: only container-image and chart-version changes; 2 resources across 2 apps

image from to upstream
public.ecr.aws/docker/library/redis 8.10.2@sha256:d5ac52… 8.10.2@sha256:6f81e8… ❔

konflate 0.6.4 · rendered 6962bbe · full diff →

<!-- konflate:pr-2243 --> **Routine**: only container-image and chart-version changes; 2 resources across 2 apps | image | from | to | upstream | |---|---|---|---| | `public.ecr.aws/docker/library/redis` | `8.10.2@sha256:d5ac52…` | `8.10.2@sha256:6f81e8…` | ❔ | <sub>konflate 0.6.4 · rendered `6962bbe` · [full diff →](https://konflate.aresu.eu/#/pr/2243)</sub>
Collaborator

✅ Automated recommendation: APPROVE

Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)

Recommendation: Approve

This is a routine Renovate digest-only container image update. The only change is the Redis image digest for the immich-redis sidecar container, with the tag 8.10.2 remaining unchanged.

Change Summary

File Change
kubernetes/apps/media/immich/app/helmrelease.yaml Redis image digest d5ac52d → 6f81e89

Required Checks

  1. Validate manifest against target cluster version ✓ — Konflate rendered the HelmRelease successfully (exit code 0). The manifest uses the app-template chart via OCIRepository and conforms to the HelmRelease helm-v2 schema.

  2. Check for resource quota / limit changes ✓ — Not applicable. This is a digest-only update with no resource definitions added, removed, or modified. The redis sidecar container has no resource requests or limits defined (consistent with the original manifest).

  3. Verify file path sanitization ✓ — Not applicable to this change. The file_serving_changes risk flag was triggered by the HelmRelease file path, but the diff contains no path, mount, or configuration changes. The NFS persistence definition (library, pointing to truenas.aresu.eu:/mnt/tank/kubernetes/immich) is completely unchanged.

  4. Check for directory traversal vulnerabilities ✓ — Not applicable. No path-related fields or mount configurations were modified.

Konflate Rendered Diff

Only the media/immich-redis Deployment image tag changed. The rendered diff shows the full Deployment manifest, confirming no unexpected side-effects from the Helm template rendering.

Non-blocking Caveat

  • Missing OCI revision/source labels: The image digest provenance analysis reports that revision metadata is unavailable for public.ecr.aws/docker/library/redis. This is expected for this registry; same-tag digest refreshes carry no actionable revision metadata. The tag (8.10.2) is unchanged, and the change is a routine upstream rebuild refresh.
<!-- ai-pr-reviewer --> <!-- ai-pr-reviewer:{"version":1,"head_sha":"6962bbe19ef7332412c7d87165f721effce2276e","base_sha":"99d361ab30fa22ff3914f4e9db25eec2a50a0b8e","review_scope":"full","review_result":"clean","required_checks":"complete"} --> <!-- ai-pr-review-sha:6962bbe19ef7332412c7d87165f721effce2276e --> <!-- ai-pr-review-fingerprint:d78549d91b5c0c09e2b33fc3f938240d5a70b85801347dc96b03936915a69739|cfg:d27ea58bdbdafc403f62b1b84c70d905cc97c77c6d72d767872b88951af9ea8d --> ✅ **Automated recommendation: APPROVE** _Analysis engine: minimax/MiniMax-M2-7-anthropic@http://litellm.ai.svc.cluster.local:4000/v1 (anthropic)_ **Recommendation: Approve** This is a routine Renovate digest-only container image update. The only change is the Redis image digest for the `immich-redis` sidecar container, with the tag `8.10.2` remaining unchanged. ## Change Summary | File | Change | |---|---| | `kubernetes/apps/media/immich/app/helmrelease.yaml` | Redis image digest `d5ac52d` → `6f81e89` | ## Required Checks 1. **Validate manifest against target cluster version** ✓ — Konflate rendered the HelmRelease successfully (exit code 0). The manifest uses the `app-template` chart via OCIRepository and conforms to the HelmRelease helm-v2 schema. 2. **Check for resource quota / limit changes** ✓ — Not applicable. This is a digest-only update with no resource definitions added, removed, or modified. The redis sidecar container has no resource requests or limits defined (consistent with the original manifest). 3. **Verify file path sanitization** ✓ — Not applicable to this change. The `file_serving_changes` risk flag was triggered by the HelmRelease file path, but the diff contains no path, mount, or configuration changes. The NFS persistence definition (`library`, pointing to `truenas.aresu.eu:/mnt/tank/kubernetes/immich`) is completely unchanged. 4. **Check for directory traversal vulnerabilities** ✓ — Not applicable. No path-related fields or mount configurations were modified. ## Konflate Rendered Diff Only the `media/immich-redis` Deployment image tag changed. The rendered diff shows the full Deployment manifest, confirming no unexpected side-effects from the Helm template rendering. ## Non-blocking Caveat - **Missing OCI revision/source labels**: The image digest provenance analysis reports that revision metadata is unavailable for `public.ecr.aws/docker/library/redis`. This is expected for this registry; same-tag digest refreshes carry no actionable revision metadata. The tag (`8.10.2`) is unchanged, and the change is a routine upstream rebuild refresh.
All checks were successful
Labeler / Labeler (pull_request) Successful in 3s
Lint / actionlint (pull_request) Successful in 6s
Lint / yamllint (pull_request) Successful in 12s
AI PR Review / AI PR Review (pull_request) Successful in 42s
Konflate 2 resources changed
This pull request can be merged automatically.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/public.ecr.aws-docker-library-redis-8.10.2:renovate/public.ecr.aws-docker-library-redis-8.10.2
git switch renovate/public.ecr.aws-docker-library-redis-8.10.2

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/public.ecr.aws-docker-library-redis-8.10.2
git switch renovate/public.ecr.aws-docker-library-redis-8.10.2
git rebase main
git switch main
git merge --ff-only renovate/public.ecr.aws-docker-library-redis-8.10.2
git switch renovate/public.ecr.aws-docker-library-redis-8.10.2
git rebase main
git switch main
git merge --no-ff renovate/public.ecr.aws-docker-library-redis-8.10.2
git switch main
git merge --squash renovate/public.ecr.aws-docker-library-redis-8.10.2
git switch main
git merge --ff-only renovate/public.ecr.aws-docker-library-redis-8.10.2
git switch main
git merge renovate/public.ecr.aws-docker-library-redis-8.10.2
git push origin main
Sign in to join this conversation.
No description provided.