This repository has been archived by the owner on Aug 19, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.46 #497
Open
iudicael-bot
wants to merge
1
commit into
main
Choose a base branch
from
renovate/ghcr.io-miniflux-miniflux-2.x
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
iudicael-bot
bot
added
renovate/container
type/patch
size/XS
Denotes a PR that changes 0-9 lines, ignoring generated files.
area/cluster
Changes made in the cluster directory
labels
Oct 16, 2022
🦙 MegaLinter status: ✅ SUCCESS
See errors details in artifact MegaLinter reports on CI Job page |
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.39
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.40
Nov 13, 2022
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
November 13, 2022 23:54
2edfa8f
to
33fcdbb
Compare
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.40
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.40 - autoclosed
Nov 25, 2022
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.40 - autoclosed
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.40
Nov 25, 2022
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.40
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.41
Dec 10, 2022
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
December 10, 2022 19:13
33fcdbb
to
4d337cc
Compare
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
January 30, 2023 01:20
4d337cc
to
753aa4d
Compare
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.41
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42
Jan 30, 2023
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42 - autoclosed
Jan 30, 2023
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42 - autoclosed
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42
Jan 30, 2023
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42 - autoclosed
Mar 15, 2023
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42 - autoclosed
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42
Mar 15, 2023
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.42
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.43
Mar 17, 2023
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
March 17, 2023 03:18
753aa4d
to
d5b7063
Compare
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.43
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.44
May 6, 2023
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
May 6, 2023 21:37
d5b7063
to
03edbc8
Compare
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.44
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.45
Jun 22, 2023
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
June 22, 2023 04:37
03edbc8
to
3d86b37
Compare
| datasource | package | from | to | | ---------- | ------------------------- | ------ | ------ | | docker | ghcr.io/miniflux/miniflux | 2.0.38 | 2.0.46 |
iudicael-bot
bot
force-pushed
the
renovate/ghcr.io-miniflux-miniflux-2.x
branch
from
July 22, 2023 02:22
3d86b37
to
af8877e
Compare
iudicael-bot
bot
changed the title
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.45
fix(container): update image ghcr.io/miniflux/miniflux to v2.0.46
Jul 22, 2023
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
area/cluster
Changes made in the cluster directory
renovate/container
size/XS
Denotes a PR that changes 0-9 lines, ignoring generated files.
type/patch
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.0.38
->2.0.46
Release Notes
miniflux/v2
v2.0.46
Compare Source
golang.org/x/*
dependencies andgo-oidc
to v3.6.0go-httpbin
to run tests locally and avoid remote calls tohttpbin.org
total_unread
andfeed_count
pq: time zone displacement out of range
errorsenclosures_user_entry_url_idx
v2.0.45
Compare Source
changed_at
andpublished_at
github.com/tdewolff/minify/v2
,github.com/prometheus/client_golang
,golang.org/x/*
dependenciesv2.0.44
Compare Source
ilpost.it
theverge.com
PROXY_IMAGES
option is backward compatible withPROXY_OPTION
andPROXY_MEDIA_TYPES
word-wrap
rule to break very long entry title into multiple linesnone
,double-tap
, andswipe
.is lower than that of newer entries.
consistent timeline.
Quay.io
(RedHat)golang.org/x/*
,github.com/lib/pq
,mvdan.cc/xurls/v2
andgithub.com/prometheus/client_golang
dependenciesv2.0.43
Compare Source
Avoid XSS when opening a broken image due to unescaped ServerError in proxy handler (CVE-2023-27592)
Creating an RSS feed item with the inline description containing an
<img>
tagwith a
srcset
attribute pointing to an invalid URL likehttp:a<script>alert(1)</script>
, we can coerce the proxy handler into an errorcondition where the invalid URL is returned unescaped and in full.
This results in JavaScript execution on the Miniflux instance as soon as the
user is convinced to open the broken image.
Use
r.RemoteAddr
to check/metrics
endpoint network access (CVE-2023-27591)HTTP headers like
X-Forwarded-For
orX-Real-Ip
can be easily spoofed. Assuch, it cannot be used to test if the client IP is allowed.
The recommendation is to use HTTP Basic authentication to protect the
metrics endpoint, or run Miniflux behind a trusted reverse-proxy.
Add HTTP Basic authentication for
/metrics
endpointAdd proxy support for several media types
Parse feed categories from RSS, Atom and JSON feeds
Ignore empty link when discovering feeds
Disable CGO explicitly to make sure the binary is statically linked
Add CSS classes to differentiate between category/feed/entry view and icons
Add rewrite and scraper rules for
blog.cloudflare.com
Add
color-scheme
to themesAdd new keyboard shortcut to toggle open/close entry attachments section
Sanitizer: allow
id
attribute in<sup>
elementAdd Indonesian Language
Update translations
Update Docker Compose examples:
depends_on
version
elementUpdate scraping rules for
ilpost.it
Bump
github.com/PuerkitoBio/goquery
from1.8.0
to1.8.1
Bump
github.com/tdewolff/minify/v2
from2.12.4
to2.12.5
Bump
github.com/yuin/goldmark
from1.5.3
to1.5.4
Bump
golang.org/x/*
dependenciesv2.0.42
Compare Source
golang.org/x/*
dependenciesilpost.it
v2.0.41
Compare Source
with SNI proxies. The existing HTTP-01 challenge support has been left
as-is.
golang.org/x/net/*
dependenciesv2.0.40
Compare Source
github.com/mitchellh/go-server-timing
continuation
parameter and result for Google Reader API ID callsrecalbox.com
v2.0.39
Compare Source
/v1/
Basic
authorization headermake run
command to execute migrations automaticallytheverge.com
,royalroad.com
,swordscomic.com
, andsmbc-comics.com
golang.org/x/*
dependenciesgithub.com/tdewolff/minify/v2
from2.12.0
to2.12.4
github.com/yuin/goldmark
from1.4.13
to1.5.2
github.com/lib/pq
from1.10.6
to1.10.7
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.