Skip to content

chore(deps): update kyverno docker tag to v3.9.0 - #177

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/kyverno-3.x
Open

chore(deps): update kyverno docker tag to v3.9.0#177
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/kyverno-3.x

Conversation

@renovate

@renovate renovate Bot commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
kyverno (source) minor 3.8.23.9.0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

Copy link
Copy Markdown

Helm Template Diff — kyverno3.8.23.9.0

2879 changed lines
--- /tmp/old.yaml	2026-08-28 08:05:01.878046379 +0000
+++ /tmp/new.yaml	2026-08-28 08:05:00.346059243 +0000
@@ -1,5 +1,5 @@
-Pulled: ghcr.io/kyverno/charts/kyverno:3.8.2
-Digest: sha256:2d267f9a36a0cf42efb735f5e984acac8a9f5eabe501f48138825f1cf07efafe
+Pulled: ghcr.io/kyverno/charts/kyverno:3.9.0
+Digest: sha256:12f0567d8ca52c858eef0628ee5214348e6d6f554cc71de5b50379b93d6d46c1
 ---
 # Source: kyverno/templates/admission-controller/serviceaccount.yaml
 apiVersion: v1
@@ -13,8 +13,8 @@
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: kyverno-admission-controller
     app.kubernetes.io/part-of: kyverno
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: kyverno-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: kyverno-3.9.0
 automountServiceAccountToken: false
 
 ---
@@ -30,8 +30,8 @@
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: kyverno-background-controller
     app.kubernetes.io/part-of: kyverno
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: kyverno-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: kyverno-3.9.0
 automountServiceAccountToken: false
 ---
 # Source: kyverno/templates/reports-controller/serviceaccount.yaml
@@ -46,8 +46,8 @@
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/name: kyverno-reports-controller
     app.kubernetes.io/part-of: kyverno
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: kyverno-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: kyverno-3.9.0
 automountServiceAccountToken: false
 ---
 # Source: kyverno/templates/config/configmap.yaml
@@ -61,8 +61,8 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: kyverno-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: kyverno-3.9.0
   annotations:
     helm.sh/resource-policy: "keep"
 data:
@@ -190,11 +190,11 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: kyverno-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: kyverno-3.9.0
 data:
   namespaces: "{\"exclude\":[],\"include\":[]}"
-  metricsExposure: "{\"kyverno_admission_requests_total\":{\"disabledLabelDimensions\":[\"resource_namespace\"]},\"kyverno_admission_review_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\"]},\"kyverno_cleanup_controller_deletedobjects_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_generating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_image_validating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_mutating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_policy_results_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_policy_rule_info_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_validating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]}}"
+  metricsExposure: "{\"kyverno_admission_requests_total\":{\"disabledLabelDimensions\":[\"resource_namespace\"]},\"kyverno_admission_review_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\"]},\"kyverno_cleanup_controller_deletedobjects_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_generating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_generating_policy_results_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_image_validating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_image_validating_policy_results_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_mutating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_mutating_policy_results_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_policy_results_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_policy_rule_info_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]},\"kyverno_validating_policy_execution_duration_seconds\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"resource_request_operation\"]},\"kyverno_validating_policy_results_total\":{\"disabledLabelDimensions\":[\"resource_namespace\",\"policy_namespace\"]}}"
   bucketBoundaries: "0.005, 0.01, 0.025, 0.05, 0.1, 0.25, 0.5, 1, 2.5, 5, 10, 15, 20, 25, 30"
 ---
 # Source: kyverno/charts/crds/templates/kyverno.io/kyverno.io_cleanuppolicies.yaml
@@ -206,8 +206,8 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno-crds
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: crds-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: crds-3.9.0
   annotations:
     controller-gen.kubebuilder.io/version: v0.20.0
   name: cleanuppolicies.kyverno.io
@@ -2822,8 +2822,8 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno-crds
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: crds-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: crds-3.9.0
   annotations:
     controller-gen.kubebuilder.io/version: v0.20.0
   name: clustercleanuppolicies.kyverno.io
@@ -5438,8 +5438,8 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno-crds
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: crds-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: crds-3.9.0
   annotations:
     controller-gen.kubebuilder.io/version: v0.20.0
   name: clusterpolicies.kyverno.io
@@ -5585,7 +5585,7 @@
                         properties:
                           expression:
                             description: |-
-                              Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                              expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                               CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                               'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -5601,7 +5601,7 @@
                             type: string
                           name:
                             description: |-
-                              Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                              name is an identifier for this match condition, used for strategic merging of MatchConditions,
                               as well as providing an identifier for logging purposes. A good name should be descriptive of
                               the associated expression.
                               Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -7023,8 +7023,8 @@
                         orphanDownstreamOnPolicyDelete:
                           description: |-
                             OrphanDownstreamOnPolicyDelete controls whether generated resources should be deleted when the rule that generated
-                            them is deleted with synchronization enabled. This option is only applicable to generate rules of the data type.
-                            See https://kyverno.io/docs/writing-policies/generate/#data-examples.
+                            them is deleted with synchronization enabled.
+                            See https://kyverno.io/docs/writing-policies/generate/.
                             Defaults to "false" if not specified.
                           type: boolean
                         synchronize:
@@ -8456,8 +8456,9 @@
                             must be satisfied for the validation rule to succeed.
                           x-kubernetes-preserve-unknown-fields: true
                         assert:
-                          description: Assert defines a kyverno-json assertion tree.
-                          type: object
+                          description: |-
+                            Assert defines a kyverno-json assertion tree.
+                            Deprecated, kept only for backward compatibility but has no effect since 1.19.
                           x-kubernetes-preserve-unknown-fields: true
                         cel:
                           description: CEL allows validation checks using the Common
@@ -8520,7 +8521,7 @@
                                   which is used to apply the validation.
                                 properties:
                                   expression:
-                                    description: "Expression represents the expression
+                                    description: "expression represents the expression
                                       which will be evaluated by CEL.\nref: https://github.com/google/cel-spec\nCEL
                                       expressions have access to the contents of the
                                       API request/response, organized into CEL variables
@@ -8585,7 +8586,7 @@
                                     type: string
                                   message:
                                     description: |-
-                                      Message represents the message displayed when validation fails. The message is required if the Expression contains
+                                      message represents the message displayed when validation fails. The message is required if the Expression contains
                                       line breaks. The message must not contain line breaks.
                                       If unset, the message is "failed rule: {Rule}".
                                       e.g. "must be a URL with the host matching spec.host"
@@ -8608,7 +8609,7 @@
                                     type: string
                                   reason:
                                     description: |-
-                                      Reason represents a machine-readable description of why this validation failed.
+                                      reason represents a machine-readable description of why this validation failed.
                                       If this is the first validation in the list to fail, this reason, as well as the
                                       corresponding HTTP response code, are used in the
                                       HTTP response to the client.
@@ -8631,13 +8632,13 @@
                               properties:
                                 apiVersion:
                                   description: |-
-                                    APIVersion is the API group version the resources belong to.
+                                    apiVersion is the API group version the resources belong to.
                                     In format of "group/version".
                                     Required.
                                   type: string
                                 kind:
                                   description: |-
-                                    Kind is the API kind the resources belong to.
+                                    kind is the API kind the resources belong to.
                                     Required.
                                   type: string
                               type: object
@@ -8675,7 +8676,7 @@
                                   type: string
                                 parameterNotFoundAction:
                                   description: |-
-                                    `parameterNotFoundAction` controls the behavior of the binding when the resource
+                                    parameterNotFoundAction controls the behavior of the binding when the resource
                                     exists, and name or selector is valid, but there are no parameters
                                     matched by the binding. If the value is set to `Allow`, then no
                                     matched parameters will be treated as successful validation by the binding.
@@ -8755,12 +8756,12 @@
                                 properties:
                                   expression:
                                     description: |-
-                                      Expression is the expression that will be evaluated as the value of the variable.
+                                      expression is the expression that will be evaluated as the value of the variable.
                                       The CEL expression has access to the same identifiers as the CEL expressions in Validation.
                                     type: string
                                   name:
                                     description: |-
-                                      Name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
+                                      name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
                                       The variable can be accessed in other expressions through `variables`
                                       For example, if name is "foo", the variable will be available as `variables.foo`
                                     type: string
@@ -10604,7 +10605,7 @@
                       properties:
                         expression:
                           description: |-
-                            Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                            expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                             CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                             'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -10620,7 +10621,7 @@
                           type: string
                         name:
                           description: |-
-                            Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                            name is an identifier for this match condition, used for strategic merging of MatchConditions,
                             as well as providing an identifier for logging purposes. A good name should be descriptive of
                             the associated expression.
                             Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -10674,7 +10675,7 @@
                             properties:
                               expression:
                                 description: |-
-                                  Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                                  expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                                   CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                                   'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -10690,7 +10691,7 @@
                                 type: string
                               name:
                                 description: |-
-                                  Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                                  name is an identifier for this match condition, used for strategic merging of MatchConditions,
                                   as well as providing an identifier for logging purposes. A good name should be descriptive of
                                   the associated expression.
                                   Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -12128,8 +12129,8 @@
                             orphanDownstreamOnPolicyDelete:
                               description: |-
                                 OrphanDownstreamOnPolicyDelete controls whether generated resources should be deleted when the rule that generated
-                                them is deleted with synchronization enabled. This option is only applicable to generate rules of the data type.
-                                See https://kyverno.io/docs/writing-policies/generate/#data-examples.
+                                them is deleted with synchronization enabled.
+                                See https://kyverno.io/docs/writing-policies/generate/.
                                 Defaults to "false" if not specified.
                               type: boolean
                             synchronize:
@@ -13581,9 +13582,9 @@
                                 must be satisfied for the validation rule to succeed.
                               x-kubernetes-preserve-unknown-fields: true
                             assert:
-                              description: Assert defines a kyverno-json assertion
-                                tree.
-                              type: object
+                              description: |-
+                                Assert defines a kyverno-json assertion tree.
+                                Deprecated, kept only for backward compatibility but has no effect since 1.19.
                               x-kubernetes-preserve-unknown-fields: true
                             cel:
                               description: CEL allows validation checks using the
@@ -13646,7 +13647,7 @@
                                       which is used to apply the validation.
                                     properties:
                                       expression:
-                                        description: "Expression represents the expression
+                                        description: "expression represents the expression
                                           which will be evaluated by CEL.\nref: https://github.com/google/cel-spec\nCEL
                                           expressions have access to the contents
                                           of the API request/response, organized into
@@ -13716,7 +13717,7 @@
                                         type: string
                                       message:
                                         description: |-
-                                          Message represents the message displayed when validation fails. The message is required if the Expression contains
+                                          message represents the message displayed when validation fails. The message is required if the Expression contains
                                           line breaks. The message must not contain line breaks.
                                           If unset, the message is "failed rule: {Rule}".
                                           e.g. "must be a URL with the host matching spec.host"
@@ -13739,7 +13740,7 @@
                                         type: string
                                       reason:
                                         description: |-
-                                          Reason represents a machine-readable description of why this validation failed.
+                                          reason represents a machine-readable description of why this validation failed.
                                           If this is the first validation in the list to fail, this reason, as well as the
                                           corresponding HTTP response code, are used in the
                                           HTTP response to the client.
@@ -13762,13 +13763,13 @@
                                   properties:
                                     apiVersion:
                                       description: |-
-                                        APIVersion is the API group version the resources belong to.
+                                        apiVersion is the API group version the resources belong to.
                                         In format of "group/version".
                                         Required.
                                       type: string
                                     kind:
                                       description: |-
-                                        Kind is the API kind the resources belong to.
+                                        kind is the API kind the resources belong to.
                                         Required.
                                       type: string
                                   type: object
@@ -13806,7 +13807,7 @@
                                       type: string
                                     parameterNotFoundAction:
                                       description: |-
-                                        `parameterNotFoundAction` controls the behavior of the binding when the resource
+                                        parameterNotFoundAction controls the behavior of the binding when the resource
                                         exists, and name or selector is valid, but there are no parameters
                                         matched by the binding. If the value is set to `Allow`, then no
                                         matched parameters will be treated as successful validation by the binding.
@@ -13886,12 +13887,12 @@
                                     properties:
                                       expression:
                                         description: |-
-                                          Expression is the expression that will be evaluated as the value of the variable.
+                                          expression is the expression that will be evaluated as the value of the variable.
                                           The CEL expression has access to the same identifiers as the CEL expressions in Validation.
                                         type: string
                                       name:
                                         description: |-
-                                          Name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
+                                          name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
                                           The variable can be accessed in other expressions through `variables`
                                           For example, if name is "foo", the variable will be available as `variables.foo`
                                         type: string
@@ -15887,7 +15888,7 @@
                         properties:
                           expression:
                             description: |-
-                              Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                              expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                               CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                               'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -15903,7 +15904,7 @@
                             type: string
                           name:
                             description: |-
-                              Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                              name is an identifier for this match condition, used for strategic merging of MatchConditions,
                               as well as providing an identifier for logging purposes. A good name should be descriptive of
                               the associated expression.
                               Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -17119,8 +17120,8 @@
                         orphanDownstreamOnPolicyDelete:
                           description: |-
                             OrphanDownstreamOnPolicyDelete controls whether generated resources should be deleted when the rule that generated
-                            them is deleted with synchronization enabled. This option is only applicable to generate rules of the data type.
-                            See https://kyverno.io/docs/writing-policies/generate/#data-examples.
+                            them is deleted with synchronization enabled.
+                            See https://kyverno.io/docs/writing-policies/generate/.
                             Defaults to "false" if not specified.
                           type: boolean
                         synchronize:
@@ -18406,6 +18407,12 @@
                             type: object
                           type: array
                       type: object
+                    reportProperties:
+                      additionalProperties:
+                        type: string
+                      description: ReportProperties are the additional properties
+                        from the rule that will be added to the policy report result
+                      type: object
                     skipBackgroundRequests:
                       default: true
                       description: |-
@@ -18422,8 +18429,9 @@
                             must be satisfied for the validation rule to succeed.
                           x-kubernetes-preserve-unknown-fields: true
                         assert:
-                          description: Assert defines a kyverno-json assertion tree.
-                          type: object
+                          description: |-
+                            Assert defines a kyverno-json assertion tree.
+                            Deprecated, kept only for backward compatibility but has no effect since 1.19.
                           x-kubernetes-preserve-unknown-fields: true
                         cel:
                           description: CEL allows validation checks using the Common
@@ -18486,7 +18494,7 @@
                                   which is used to apply the validation.
                                 properties:
                                   expression:
-                                    description: "Expression represents the expression
+                                    description: "expression represents the expression
                                       which will be evaluated by CEL.\nref: https://github.com/google/cel-spec\nCEL
                                       expressions have access to the contents of the
                                       API request/response, organized into CEL variables
@@ -18551,7 +18559,7 @@
                                     type: string
                                   message:
                                     description: |-
-                                      Message represents the message displayed when validation fails. The message is required if the Expression contains
+                                      message represents the message displayed when validation fails. The message is required if the Expression contains
                                       line breaks. The message must not contain line breaks.
                                       If unset, the message is "failed rule: {Rule}".
                                       e.g. "must be a URL with the host matching spec.host"
@@ -18574,7 +18582,7 @@
                                     type: string
                                   reason:
                                     description: |-
-                                      Reason represents a machine-readable description of why this validation failed.
+                                      reason represents a machine-readable description of why this validation failed.
                                       If this is the first validation in the list to fail, this reason, as well as the
                                       corresponding HTTP response code, are used in the
                                       HTTP response to the client.
@@ -18597,13 +18605,13 @@
                               properties:
                                 apiVersion:
                                   description: |-
-                                    APIVersion is the API group version the resources belong to.
+                                    apiVersion is the API group version the resources belong to.
                                     In format of "group/version".
                                     Required.
                                   type: string
                                 kind:
                                   description: |-
-                                    Kind is the API kind the resources belong to.
+                                    kind is the API kind the resources belong to.
                                     Required.
                                   type: string
                               type: object
@@ -18641,7 +18649,7 @@
                                   type: string
                                 parameterNotFoundAction:
                                   description: |-
-                                    `parameterNotFoundAction` controls the behavior of the binding when the resource
+                                    parameterNotFoundAction controls the behavior of the binding when the resource
                                     exists, and name or selector is valid, but there are no parameters
                                     matched by the binding. If the value is set to `Allow`, then no
                                     matched parameters will be treated as successful validation by the binding.
@@ -18721,12 +18729,12 @@
                                 properties:
                                   expression:
                                     description: |-
-                                      Expression is the expression that will be evaluated as the value of the variable.
+                                      expression is the expression that will be evaluated as the value of the variable.
                                       The CEL expression has access to the same identifiers as the CEL expressions in Validation.
                                     type: string
                                   name:
                                     description: |-
-                                      Name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
+                                      name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
                                       The variable can be accessed in other expressions through `variables`
                                       For example, if name is "foo", the variable will be available as `variables.foo`
                                     type: string
@@ -20628,7 +20636,7 @@
                       properties:
                         expression:
                           description: |-
-                            Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                            expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                             CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                             'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -20644,7 +20652,7 @@
                           type: string
                         name:
                           description: |-
-                            Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                            name is an identifier for this match condition, used for strategic merging of MatchConditions,
                             as well as providing an identifier for logging purposes. A good name should be descriptive of
                             the associated expression.
                             Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -20698,7 +20706,7 @@
                             properties:
                               expression:
                                 description: |-
-                                  Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                                  expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                                   CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                                   'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -20714,7 +20722,7 @@
                                 type: string
                               name:
                                 description: |-
-                                  Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                                  name is an identifier for this match condition, used for strategic merging of MatchConditions,
                                   as well as providing an identifier for logging purposes. A good name should be descriptive of
                                   the associated expression.
                                   Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -22152,8 +22160,8 @@
                             orphanDownstreamOnPolicyDelete:
                               description: |-
                                 OrphanDownstreamOnPolicyDelete controls whether generated resources should be deleted when the rule that generated
-                                them is deleted with synchronization enabled. This option is only applicable to generate rules of the data type.
-                                See https://kyverno.io/docs/writing-policies/generate/#data-examples.
+                                them is deleted with synchronization enabled.
+                                See https://kyverno.io/docs/writing-policies/generate/.
                                 Defaults to "false" if not specified.
                               type: boolean
                             synchronize:
@@ -23605,9 +23613,9 @@
                                 must be satisfied for the validation rule to succeed.
                               x-kubernetes-preserve-unknown-fields: true
                             assert:
-                              description: Assert defines a kyverno-json assertion
-                                tree.
-                              type: object
+                              description: |-
+                                Assert defines a kyverno-json assertion tree.
+                                Deprecated, kept only for backward compatibility but has no effect since 1.19.
                               x-kubernetes-preserve-unknown-fields: true
                             cel:
                               description: CEL allows validation checks using the
@@ -23670,7 +23678,7 @@
                                       which is used to apply the validation.
                                     properties:
                                       expression:
-                                        description: "Expression represents the expression
+                                        description: "expression represents the expression
                                           which will be evaluated by CEL.\nref: https://github.com/google/cel-spec\nCEL
                                           expressions have access to the contents
                                           of the API request/response, organized into
@@ -23740,7 +23748,7 @@
                                         type: string
                                       message:
                                         description: |-
-                                          Message represents the message displayed when validation fails. The message is required if the Expression contains
+                                          message represents the message displayed when validation fails. The message is required if the Expression contains
                                           line breaks. The message must not contain line breaks.
                                           If unset, the message is "failed rule: {Rule}".
                                           e.g. "must be a URL with the host matching spec.host"
@@ -23763,7 +23771,7 @@
                                         type: string
                                       reason:
                                         description: |-
-                                          Reason represents a machine-readable description of why this validation failed.
+                                          reason represents a machine-readable description of why this validation failed.
                                           If this is the first validation in the list to fail, this reason, as well as the
                                           corresponding HTTP response code, are used in the
                                           HTTP response to the client.
@@ -23786,13 +23794,13 @@
                                   properties:
                                     apiVersion:
                                       description: |-
-                                        APIVersion is the API group version the resources belong to.
+                                        apiVersion is the API group version the resources belong to.
                                         In format of "group/version".
                                         Required.
                                       type: string
                                     kind:
                                       description: |-
-                                        Kind is the API kind the resources belong to.
+                                        kind is the API kind the resources belong to.
                                         Required.
                                       type: string
                                   type: object
@@ -23830,7 +23838,7 @@
                                       type: string
                                     parameterNotFoundAction:
                                       description: |-
-                                        `parameterNotFoundAction` controls the behavior of the binding when the resource
+                                        parameterNotFoundAction controls the behavior of the binding when the resource
                                         exists, and name or selector is valid, but there are no parameters
                                         matched by the binding. If the value is set to `Allow`, then no
                                         matched parameters will be treated as successful validation by the binding.
@@ -23910,12 +23918,12 @@
                                     properties:
                                       expression:
                                         description: |-
-                                          Expression is the expression that will be evaluated as the value of the variable.
+                                          expression is the expression that will be evaluated as the value of the variable.
                                           The CEL expression has access to the same identifiers as the CEL expressions in Validation.
                                         type: string
                                       name:
                                         description: |-
-                                          Name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
+                                          name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
                                           The variable can be accessed in other expressions through `variables`
                                           For example, if name is "foo", the variable will be available as `variables.foo`
                                         type: string
@@ -25793,8 +25801,8 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno-crds
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: crds-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: crds-3.9.0
   annotations:
     controller-gen.kubebuilder.io/version: v0.20.0
   name: globalcontextentries.kyverno.io
@@ -26579,8 +26587,8 @@
     app.kubernetes.io/instance: kyverno
     app.kubernetes.io/managed-by: Helm
     app.kubernetes.io/part-of: kyverno-crds
-    app.kubernetes.io/version: 3.8.2
-    helm.sh/chart: crds-3.8.2
+    app.kubernetes.io/version: 3.9.0
+    helm.sh/chart: crds-3.9.0
   annotations:
     controller-gen.kubebuilder.io/version: v0.20.0
   name: policies.kyverno.io
@@ -26727,7 +26735,7 @@
                         properties:
                           expression:
                             description: |-
-                              Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                              expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                               CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                               'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -26743,7 +26751,7 @@
                             type: string
                           name:
                             description: |-
-                              Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                              name is an identifier for this match condition, used for strategic merging of MatchConditions,
                               as well as providing an identifier for logging purposes. A good name should be descriptive of
                               the associated expression.
                               Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -28165,8 +28173,8 @@
                         orphanDownstreamOnPolicyDelete:
                           description: |-
                             OrphanDownstreamOnPolicyDelete controls whether generated resources should be deleted when the rule that generated
-                            them is deleted with synchronization enabled. This option is only applicable to generate rules of the data type.
-                            See https://kyverno.io/docs/writing-policies/generate/#data-examples.
+                            them is deleted with synchronization enabled.
+                            See https://kyverno.io/docs/writing-policies/generate/.
                             Defaults to "false" if not specified.
                           type: boolean
                         synchronize:
@@ -29598,8 +29606,9 @@
                             must be satisfied for the validation rule to succeed.
                           x-kubernetes-preserve-unknown-fields: true
                         assert:
-                          description: Assert defines a kyverno-json assertion tree.
-                          type: object
+                          description: |-
+                            Assert defines a kyverno-json assertion tree.
+                            Deprecated, kept only for backward compatibility but has no effect since 1.19.
                           x-kubernetes-preserve-unknown-fields: true
                         cel:
                           description: CEL allows validation checks using the Common
@@ -29662,7 +29671,7 @@
                                   which is used to apply the validation.
                                 properties:
                                   expression:
-                                    description: "Expression represents the expression
+                                    description: "expression represents the expression
                                       which will be evaluated by CEL.\nref: https://github.com/google/cel-spec\nCEL
                                       expressions have access to the contents of the
                                       API request/response, organized into CEL variables
@@ -29727,7 +29736,7 @@
                                     type: string
                                   message:
                                     description: |-
-                                      Message represents the message displayed when validation fails. The message is required if the Expression contains
+                                      message represents the message displayed when validation fails. The message is required if the Expression contains
                                       line breaks. The message must not contain line breaks.
                                       If unset, the message is "failed rule: {Rule}".
                                       e.g. "must be a URL with the host matching spec.host"
@@ -29750,7 +29759,7 @@
                                     type: string
                                   reason:
                                     description: |-
-                                      Reason represents a machine-readable description of why this validation failed.
+                                      reason represents a machine-readable description of why this validation failed.
                                       If this is the first validation in the list to fail, this reason, as well as the
                                       corresponding HTTP response code, are used in the
                                       HTTP response to the client.
@@ -29773,13 +29782,13 @@
                               properties:
                                 apiVersion:
                                   description: |-
-                                    APIVersion is the API group version the resources belong to.
+                                    apiVersion is the API group version the resources belong to.
                                     In format of "group/version".
                                     Required.
                                   type: string
                                 kind:
                                   description: |-
-                                    Kind is the API kind the resources belong to.
+                                    kind is the API kind the resources belong to.
                                     Required.
                                   type: string
                               type: object
@@ -29817,7 +29826,7 @@
                                   type: string
                                 parameterNotFoundAction:
                                   description: |-
-                                    `parameterNotFoundAction` controls the behavior of the binding when the resource
+                                    parameterNotFoundAction controls the behavior of the binding when the resource
                                     exists, and name or selector is valid, but there are no parameters
                                     matched by the binding. If the value is set to `Allow`, then no
                                     matched parameters will be treated as successful validation by the binding.
@@ -29897,12 +29906,12 @@
                                 properties:
                                   expression:
                                     description: |-
-                                      Expression is the expression that will be evaluated as the value of the variable.
+                                      expression is the expression that will be evaluated as the value of the variable.
                                       The CEL expression has access to the same identifiers as the CEL expressions in Validation.
                                     type: string
                                   name:
                                     description: |-
-                                      Name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
+                                      name is the name of the variable. The name must be a valid CEL identifier and unique among all variables.
                                       The variable can be accessed in other expressions through `variables`
                                       For example, if name is "foo", the variable will be available as `variables.foo`
                                     type: string
@@ -31746,7 +31755,7 @@
                       properties:
                         expression:
                           description: |-
-                            Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                            expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                             CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                             'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -31762,7 +31771,7 @@
                           type: string
                         name:
                           description: |-
-                            Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                            name is an identifier for this match condition, used for strategic merging of MatchConditions,
                             as well as providing an identifier for logging purposes. A good name should be descriptive of
                             the associated expression.
                             Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -31817,7 +31826,7 @@
                             properties:
                               expression:
                                 description: |-
-                                  Expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
+                                  expression represents the expression which will be evaluated by CEL. Must evaluate to bool.
                                   CEL expressions have access to the contents of the AdmissionRequest and Authorizer, organized into CEL variables:
 
                                   'object' - The object from the incoming request. The value is null for DELETE requests.
@@ -31833,7 +31842,7 @@
                                 type: string
                               name:
                                 description: |-
-                                  Name is an identifier for this match condition, used for strategic merging of MatchConditions,
+                                  name is an identifier for this match condition, used for strategic merging of MatchConditions,
                                   as well as providing an identifier for logging purposes. A good name should be descriptive of
                                   the associated expression.
                                   Name must be a qualified name consisting of alphanumeric characters, '-', '_' or '.', and
@@ -33271,8 +33280,8 @@
                             orphanDownstreamOnPolicyDelete:
                               description: |-
                                 OrphanDownstreamOnPolicyDelete controls whether generated resources should be deleted when the rule that generated
-                                them is deleted with synchronization enabled. This option is only applicable to generate rules of the data type.
-                                See https://kyverno.io/docs/writing-policies/generate/#data-examples.
+                                them is deleted with synchronization enabled.
+                                See https://kyverno.io/docs/writing-policies/generate/.
                                 Defaults to "false" if not specified.
                               type: boolean
                             synchronize:
@@ -34724,9 +34733,9 @@
                                 must be satisfied for the validation rule to succeed.
                               x-kubernetes-preserve-unknown-fields: true
                             assert:
-                              description: Assert defines a kyverno-json assertion
-                                tree.
-                              type: object
+                              description: |-
+                                Assert defines a kyverno-json assertion tree.
+                                Deprecated, kept only for backward compatibility but has no effect since 1.19.
                               x-kubernetes-preserve-unknown-fields: true
                             cel:
                               description: CEL allows validation checks using the
@@ -34789,7 +34798,7 @@
                                       which is used to apply the validation.
                                     properties:
                                       expression:
-                                        description: "Expression represents the expression
+                                        description: "expression represents the expression
                                           which will be evaluated by CEL.\nref: https://github.com/google/cel-spec\nCEL
                                           expressions have access to the contents
                                           of the API request/response, organized into
@@ -34859,7 +34868,7 @@
                                         type: string
                                       message:
                                         description: |-
-                                          Message represents the message displayed when validation fails. The message is required if the Expression contains
+                                          message represents the message displayed when validation fails. The message is required if the Expression contains
                                           line breaks. The message must not contain line breaks.
                                           If unset, the message is "failed rule: {Rule}".
                                           e.g. "must be a URL with the host matching spec.host"
@@ -34882,7 +34891,7 @@
                                         type: string
                                       reason:
                                         description: |-
-                                          Reason represents a machine-readable description of why this validation failed.
+                                          reason represents a machine-readable description of why this validation failed.
                                           If this is the first validation in the list to fail, this reason, as well as the
                                           corresponding HTTP response code, are used in the
                                           HTTP response to the client.
@@ -34905,13 +34914,13 @@
                                   properties:
                                     apiVersion:
                                       description: |-
-                                        APIVersion is the API group version the resources belong to.
+                                        apiVersion is the API group version the resources belong to.
                                         In format of "group/version".
                                         Required.
                                       type: string
                                     kind:
                                       description: |-
-                                        Kind is the API kind the resources belong to.
+                                        kind is the API kind the resources belong to.
                                         Required.
                                       type: string
                                   type: object
@@ -34949,7 +34958,7 @@
                                       type: string
                                     parameterNotFoundAction:
                                       description: |-
-                                        `parameterNotFoundAction` controls the behavior of the binding when the resource
+                                        parameterNotFoundAction controls the behavior of the binding when the resource
                                         exists, and name or selector is valid, but there are no parameters
                                         matched by the binding. If the value is set to `Allow`, then no
                                         matched parameters will be treated as successful validation by the binding.
@@ -35029,12 +35038,12 @@
                                     properties:
                                       expression:
                                         description: |-
-                                          Expression is the expression that will be evaluated as the value of the variable.
+                                          expression is the expression that will be evaluated as the value of the variable.
                                           The CEL expression has access to the same identifiers as the CEL
... (truncated, diff exceeds 60000 chars)

lunarys commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Renovate Review: kyverno 3.8.2 → 3.9.0 (minor, kyverno app)

Risk: 🟡 MEDIUM

Check Result
Inputs Degraded — the PR body contains only the summary table, no ### Release Notes section at all (unlike #174/#175/#176), so breaking-change assessment falls back to raw version numbers only. Diff comment present (slug 03-apps-apps-kyverno-kyverno), matching the changed app.
Description vs. diff Consistent — table says 3.8.23.9.0 (minor); the only changed file is 03_apps/apps/kyverno/kyverno-app.yaml, a single-line version: 3.8.23.9.0 bump.
Rendered diff Truncated by the char-cap — header reports "2879 changed lines" but the comment body cuts off after ~840 lines with ... (truncated, diff exceeds 60000 chars). Only roughly the first 29% of the diff is visible.
RBAC Not verifiable — no kind: Role/ClusterRole/RoleBinding/ClusterRoleBinding lines appear in the visible ~840 lines, but Kyverno's admission/background/reports controllers each carry substantial ClusterRoles, and the truncated ~71% of the diff could contain RBAC changes not shown here.
Changelog vs. config Not verifiable — no changelog text available to check against kyverno-app.yaml's settings.skipCrds: false (this app installs Kyverno's own CRDs, e.g. ClusterPolicy) or the three live ClusterPolicy resources under 03_apps/apps/kyverno/kyverno-resources/ (require-ingress-access-annotation, require-namespace-networkpolicy; both validationFailureAction: Audit / background: true, one using an apiCall context against cilium.io/v2).

Details:

  • The visible portion of the diff (the first ~840 lines) shows only helm.sh/chart/app.kubernetes.io/version label bumps and the image digest change (ghcr.io/kyverno/charts/kyverno:3.8.23.9.0) — no render errors and no visible resource additions/removals in that portion.
  • kyverno-app.yaml sets settings.skipCrds: false, so this PR would also update the live-installed CRDs (ClusterPolicy/Policy/etc.) — combined with the missing changelog and the truncated diff, there's no way to confirm from available inputs whether the untruncated remainder changes ClusterPolicy schema/semantics or the admission-controller's ClusterRole in a way that affects the three live policies (e.g. any change to accepted validationFailureAction values or the context.apiCall field).

Worth noting (non-blocking):

  • 03_apps/apps/kyverno/kyverno-resources/networkpolicy-coverage-policy.yaml has a TODO: maybe should be extended to make sure Deployments are covered by the Policies comment linking to kyverno.io/policies/other/require-netpol/require-netpol — unrelated to this version bump, but worth revisiting since it's an outstanding TODO in a file this PR touches indirectly.

Why MEDIUM: two inputs are degraded at once for a CRD-owning, cluster-wide admission-webhook component — no changelog to check for breaking changes, and a diff truncated at the char-cap hiding roughly 71% of the rendered output (including where RBAC/CRD content would most likely surface). Per procedure this missing-input-plus-truncated-diff combination is a Medium trigger even though the visible slice looks benign.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant