Commit Graph
57886 Commits
Author SHA1 Message Date
TrueCharts BotandGitHub 33b1a80587 chore(rsshub): update image docker.io/diygod/rsshub digest to 48146b4 (#48511)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/diygod/rsshub | digest | `72c22bf` → `48146b4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9yc3NodWIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:24:19 +02:00
TrueCharts BotandGitHub 37d2aa0174 chore(nextcloud): update image docker.io/clamav/clamav digest to f7954ca (#48510)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/clamav/clamav](https://redirect.github.com/Cisco-Talos/clamav.git)
([source](https://redirect.github.com/Cisco-Talos/clamav)) | digest |
`de10aee` → `f7954ca` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9uZXh0Y2xvdWQiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:24:10 +02:00
TrueCharts BotandGitHub adf31e4175 feat(local-ai): update image docker.io/localai/localai v4.2.6 → v4.3.1 (#48501)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/localai/localai](https://redirect.github.com/mudler/LocalAI)
| minor | `c41d534` → `28f0aa9` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>mudler/LocalAI (docker.io/localai/localai)</summary>

###
[`v4.3.1`](https://redirect.github.com/mudler/LocalAI/releases/tag/v4.3.1)

[Compare
Source](https://redirect.github.com/mudler/LocalAI/compare/v4.3.0...v4.3.1)

<!-- Release notes generated using configuration in .github/release.yml
at master -->

#### What's Changed

##### Other Changes

- Fix kokoros backend build break from Backend trait drift by
[@&#8203;Copilot](https://redirect.github.com/Copilot) in
[#&#8203;9972](https://redirect.github.com/mudler/LocalAI/pull/9972)
- chore: :arrow\_up: Update antirez/ds4 to
`f91c12b50a1448527c435c028bfc70d1b00f6c33` by
[@&#8203;localai-bot](https://redirect.github.com/localai-bot) in
[#&#8203;9975](https://redirect.github.com/mudler/LocalAI/pull/9975)
- chore: :arrow\_up: Update ikawrakow/ik\_llama.cpp to
`9f7ba245ab41e118f03aa8dd5134d18a81159d02` by
[@&#8203;localai-bot](https://redirect.github.com/localai-bot) in
[#&#8203;9973](https://redirect.github.com/mudler/LocalAI/pull/9973)
- chore: :arrow\_up: Update ggml-org/llama.cpp to
`549b9d84330c327e6791fa812a7d60c0cf63572e` by
[@&#8203;localai-bot](https://redirect.github.com/localai-bot) in
[#&#8203;9974](https://redirect.github.com/mudler/LocalAI/pull/9974)

**Full Changelog**:
<https://github.com/mudler/LocalAI/compare/v4.3.0...v4.3.1>

###
[`v4.3.0`](https://redirect.github.com/mudler/LocalAI/releases/tag/v4.3.0)

[Compare
Source](https://redirect.github.com/mudler/LocalAI/compare/v4.2.6...v4.3.0)

### 🎉 LocalAI 4.3.0 Release! 🚀

<h1 align="center">
  <br>
<img height="300"
src="https://raw.githubusercontent.com/mudler/LocalAI/refs/heads/master/core/http/static/logo.png">
  <br>
  <br>
</h1>

LocalAI 4.3.0 is out!

This release **hardens the trust boundary** and **improves defaults for
speed**. Backend OCI images now ship with **keyless cosign signatures**
and a per-gallery `verification:` policy, with an opt-in strict mode
that fails closed.
The `llama-cpp` server-side prompt cache works **by default**: repeated
system prompts (agents, OpenAI/Anthropic-compatible CLIs, coding
assistants) collapse from **minutes to seconds** without touching YAML.
Distributed mode gets rounds of optimizations. Usage tracking grows a
**per-API-key + per-user Sources view** so admins can finally answer
"who is burning the GPU?". And, for everyone on a Jetson/DGX box, the
**L4T13 (cu130/aarch64) backends are back**.

***

#### 📌 TL;DR

| Feature | Summary |
| ----------------------------- |
-------------------------------------------------------------------------------------------------------------------------------------
|
| 🔐 **Signed Backends** | Keyless cosign + sigstore-go verification for
backend OCI images, OCI 1.1 referrers, `not_before` revocation, opt-in
strict mode. |
|  **Prompt Cache by Default** | `llama-cpp` server-side prompt cache
works out of the box. Repeated system prompts go from 5-8 min to
seconds. |
| 📊 **Usage per API Key** | New Sources tab attributes traffic to keys
and users. Revoked keys stay readable in history. |
| 🛰️ **Distributed v3** | Per-request replica routing, cached
`probeHealth`, async per-node installs with streaming progress, unified
backend-logs entry point. |
| 🩺 **Traces UI Stays Snappy** | `LOCALAI_TRACING_MAX_BODY_BYTES` caps
API + backend trace payloads. Admin Traces page stops drowning in 40 MB
embeddings. |
| 🧊 **Nix Flake** | Dockerless setup for NixOS users via `flake.nix` +
dev shell. |
| 🦾 **Jetson Thor Restored** | `vllm` / `sglang` / `vllm-omni` L4T13
backends switched to PyPI aarch64+cu130 wheels (torch 2.10 ABI fix). |

***

#### 🚀 New Features & Major Enhancements

##### 🔐 Signed Backends with Keyless Cosign

LocalAI now verifies that backend OCI images came from our CI, not a
compromised registry or MITM. This closes a real trust gap: the gallery
YAML told LocalAI which image to pull, but nothing checked the bytes.

The producer side (`.github/workflows/backend_merge.yml`) signs every
merged backend image (and every per-arch entry under the manifest list)
with **sigstore/cosign** keyless via Fulcio + Rekor, using OCI 1.1
referrers (no legacy `:tag.sig`). The consumer side
(`pkg/oci/cosignverify`, built on **sigstore-go**) verifies signatures
against a per-gallery `verification:` policy:

```yaml
verification:
  issuer_regex: "^https://token\\.actions\\.githubusercontent\\.com$"
  identity_regex: "^https://github\\.com/mudler/LocalAI/\\.github/workflows/backend_merge\\.yml@.*$"
  not_before: "2026-05-22T00:00:00Z"
```

- **TUF trusted root** cached process-wide, so N backends from one
gallery do **1** fetch, not N.
- **`not_before` is the revocation lever**: keyless Fulcio certs are
ephemeral, so revocation is policy-side. Advance the date in the gallery
YAML and every signature predating the cutoff is invalidated.
- **Digest pinning** closes the TOCTOU window between verify and pull.
- **Strict mode**: `--require-backend-integrity` (or
`LOCALAI_REQUIRE_BACKEND_INTEGRITY=true`) escalates missing policy /
empty SHA256 from warn to **hard-fail**.

Rollout is backward-compatible: until a gallery ships a `verification:`
block, installs proceed with a warning. The default `backend/index.yaml`
will be populated next, and strict mode is opt-in. See
[.agents/backend-signing.md](.agents/backend-signing.md) for the full
producer + consumer story.

> 🔗 PRs:
[#&#8203;9823](https://redirect.github.com/mudler/LocalAI/issues/9823)
(consumer + producer + plumbing),
[#&#8203;9957](https://redirect.github.com/mudler/LocalAI/issues/9957)
(fix for current cosign releases).

***

#####  Prompt Cache: On by Default

`llama-cpp` ships with a server-side prompt cache, but until now LocalAI
was not enabling it by default. Repeated system prompts (agents,
Claude-Code-style coding assistants, OpenAI-compatible CLIs with long
instructions) were re-prefilled on every call. With this release, the
same workload collapses to **seconds** without no specific configuration
on your side.

Two changes, one default flip each:

1. **`kv_unified=true` by default** in `grpc-server.cpp`. The previous
`false` was silently force-disabling `cache_idle_slots` at server init
(the host prompt cache was being allocated but never written across
requests).
2. **`prompt_cache_all` defaults to `true`** at the YAML layer, matching
upstream `llama.cpp`'s own `common.h` default. The per-request
`cache_prompt` knob is now on out of the box.

You can still opt out with `options: ["kv_unified:false"]` or
`prompt_cache_all: false`, and there are new option keys
(`cache_idle_slots`, `checkpoint_every_nt`) for tuning. Docs in
`docs/content/advanced/model-configuration.md` got a worked example for
the repeated-system-prompt workload and a proper explanation of how
`kv_unified`, `cache_ram`, and `cache_idle_slots` interact.

> 🔗 PRs:
[#&#8203;9925](https://redirect.github.com/mudler/LocalAI/issues/9925)
(kv\_unified + cache\_idle\_slots defaults + docs),
[#&#8203;9951](https://redirect.github.com/mudler/LocalAI/issues/9951)
(prompt\_cache\_all tristate default).

***

##### 📊 Per-API-Key Usage Tracking

Closes
[#&#8203;9862](https://redirect.github.com/mudler/LocalAI/issues/9862).
The usage page now answers "**who** spent these tokens?", not just "how
many tokens were spent".

- `usage_records` gained `Source` (`apikey` / `web` / `legacy`),
`APIKeyID`, `APIKeyName`, plus an idempotent backfill of pre-feature
rows on `InitDB`.
- Auth middleware plumbs the resolved `*UserAPIKey` and the request
source through the Echo context. Usage middleware snapshots the key id +
name, so **revoked keys stay readable in history** (rendered as
`(revoked)`).
- New endpoints: `GET /api/auth/usage/sources` (self, no legacy) and
`GET /api/auth/admin/usage/sources` (admin, with `user_id` /
`api_key_id` filters, 200-key truncation).
- React Usage page gains a **Sources tab** with a source-mix ribbon, a
top-7 + Other time chart, and a searchable/sortable table with drill-in
chip.
- Admin view (follow-up in
[#&#8203;9935](https://redirect.github.com/mudler/LocalAI/issues/9935))
also rolls up `(source, user_id, user_name)` so Web UI session traffic
is split per user instead of lumped into one global "Web UI" row, and
every named-key row shows the owning account.

Docs: `features/authentication.md` gained a full Usage Tracking section
with the new tab, endpoints, response shape and migration notes.

> 🔗 PRs:
[#&#8203;9920](https://redirect.github.com/mudler/LocalAI/issues/9920)
(core + Sources tab),
[#&#8203;9935](https://redirect.github.com/mudler/LocalAI/issues/9935)
(per-user attribution in admin view).

***

##### 🛰️ Distributed Mode v3

Distributed mode keeps hardening. This release fixes the two things that
bit operators hardest in practice and lays the groundwork for the next
round of UX.

**Per-request routing across replicas
([#&#8203;9968](https://redirect.github.com/mudler/LocalAI/issues/9968))**
restores cross-node load balancing. The bug: `ModelLoader.Load` cached a
`*Model` whose embedded `InFlightTrackingClient` was bound to a single
`(nodeID, replicaIndex)`. After the first request, every subsequent call
reused that wrapper and **pinned to whichever node won the first pick**,
even after the reconciler scaled the model out. The reproducer from the
report:

```
dgx-spark1     loaded   in_flight=6
nvidia-thor1   loaded   in_flight=0       (← idle, never gets traffic)
```

Now `SmartRouter.Route` runs per request, the existing `in_flight ASC,
last_used ASC, available_vram DESC` round-robin actually fires, and the
replica-selection rule lives in **one place** (`PickBestReplica`) with a
mirror spec asserting the SQL `ORDER BY` and the Go picker agree on a
seeded dataset. `probeHealth` is now memoized per `(nodeID, addr)` with
a 30s TTL and `singleflight` coalescing, so a burst of new requests
doesn't stall on a `HealthCheck` that llama.cpp serializes against
in-flight `Predict`.

**Async per-node installs via the gallery job queue
([#&#8203;9928](https://redirect.github.com/mudler/LocalAI/issues/9928)).**
`POST /api/nodes/:id/backends/install` used to block the request for up
to 3 minutes while the worker pulled the image, freezing the React UI's
Backends picker. It now returns **HTTP 202 + `jobID`** immediately,
scoped to a one-element `targetNodeIDs` allowlist, with a node-scoped
opcache row so concurrent installs on different nodes don't collide. The
Operations panel surfaces a `nodeID` field for attribution.

**Resilient backend installs with streaming progress
([#&#8203;9958](https://redirect.github.com/mudler/LocalAI/issues/9958)).**
Two phases:

- *Phase 1*: `LOCALAI_NATS_BACKEND_INSTALL_TIMEOUT` /
`LOCALAI_NATS_BACKEND_UPGRADE_TIMEOUT` env vars (default **15m**,
previously hardcoded 3m). A NATS round-trip timeout while the worker is
still pulling no longer reports as a hard failure: per-node status
becomes `running_on_worker`, the queue row stays alive without bumping
`Attempts`, and `ListBackends` proactively clears install rows whose
intent is satisfied (so the UI updates instantly instead of waiting up
to 15m for the next reconciler tick).
- *Phase 2*: workers publish debounced (\~250ms)
`BackendInstallProgressEvent` values on a transient
`nodes.<nodeID>.backend.install.<opID>.progress` subject. The master
subscribes for the duration of the request and forwards each event into
`OpStatus.UpdateStatus`, so the admin UI gets **per-byte progress for
distributed installs** the same way local-mode does, with no UI changes.
Backward compatible: old workers stay silent, new masters tolerate
silence.

**Unified backend-logs entry point
([#&#8203;9949](https://redirect.github.com/mudler/LocalAI/issues/9949)).**
`/app/backend-logs/:modelId` is now a single, mode-aware route. In
standalone it's the local WebSocket view, unchanged. In distributed it
probes `nodesApi.getModels`, filters by `model_name`, then routes: 0
hits → empty state with a link to Nodes; 1 hit → `<Navigate replace>` to
the per-node logs URL preserving the `?from=` deep-link timestamp; N
hits → a picker listing each hosting worker with node id, replica index
and load state. Every view that links to backend logs now points at the
same URL.

**Bug-hunt harness.** A new distributed test harness landed in
`tests/distributed/` to catch the kind of regressions the
[#&#8203;9968](https://redirect.github.com/mudler/LocalAI/issues/9968)
reproducer surfaced.

> 🔗 PRs:
[#&#8203;9968](https://redirect.github.com/mudler/LocalAI/issues/9968),
[#&#8203;9928](https://redirect.github.com/mudler/LocalAI/issues/9928),
[#&#8203;9958](https://redirect.github.com/mudler/LocalAI/issues/9958),
[#&#8203;9949](https://redirect.github.com/mudler/LocalAI/issues/9949),
plus the `tests(distributed): add bug-hunt harness` commit.

***

##### 🩺 Admin Traces UI: Stays Responsive Under Load

Two complementary caps fix the symptom where the admin Traces page sat
in "loading" forever on a chatty agent-pool RAG deployment.

- **API-side
([#&#8203;9946](https://redirect.github.com/mudler/LocalAI/issues/9946))**:
`LOCALAI_TRACING_MAX_BODY_BYTES` (default 64 KiB) caps each captured
request/response body in the trace middleware. The full payload still
flows to the real client; only the trace copy is bounded.
`body_truncated` + original `body_bytes` are recorded so the dashboard
can surface that truncation happened. Observed before the fix on a live
deployment: `/api/traces` returned **44.6 MB** (466 traces, 447
`/embeddings`, top body 1.38 MB). The Traces UI Clear button is also
kept enabled during loading, which is exactly when you need it.
- **Backend-side
([#&#8203;9960](https://redirect.github.com/mudler/LocalAI/issues/9960))**:
`RecordBackendTrace` walks the `Data` map and replaces any string value
larger than the cap with `<truncated: N bytes>`. Producers
(`core/backend/llm.go`, `core/trace/audio_snippet.go`) apply
head-preserving truncation upstream so the UI still shows useful leading
content. TTS / `audio_transform` traces drop the base64 snippet when the
encoded blob exceeds the cap (truncated base64 is undecodable; the React
`WaveformPlayer` already no-ops without it).

Both knobs are live-tunable from the Traces settings panel.

> 🔗 PRs:
[#&#8203;9946](https://redirect.github.com/mudler/LocalAI/issues/9946)
(API side),
[#&#8203;9960](https://redirect.github.com/mudler/LocalAI/issues/9960)
(backend side).

***

##### 🧊 Nix Flake for NixOS Users

New `flake.nix` + `flake.lock` ship a reproducible, dockerless setup for
NixOS, plus a dev shell for hacking on LocalAI without a container.

> 🔗 PRs:
[#&#8203;9851](https://redirect.github.com/mudler/LocalAI/issues/9851)
(initial flake),
[#&#8203;9894](https://redirect.github.com/mudler/LocalAI/issues/9894)
(correct src path + dev shell).

***

##### 🦾 Jetson Thor (L4T13) Backends Restored

The `cuda13-nvidia-l4t-arm64-vllm` / `sglang` / `vllm-omni` backends
crashed at import with an undefined `c10::MessageLogger` symbol after
the `pypi.jetson-ai-lab.io/sbsa/cu130` mirror started shipping torch
2.11 next to vllm/sglang wheels built against torch 2.10. Per the
[PyTorch April 2026
announcement](https://pytorch.org/blog/vllm-and-pytorch-work-together-to-improve-the-developer-experience-on-aarch64/),
all three backends now pull from **PyPI's official aarch64 + cu130
wheels** instead, with the L4T13 `pyproject.toml` retired in favor of
the standard `requirements-${profile}.txt` pattern used everywhere else.

> 🔗 PR:
[#&#8203;9950](https://redirect.github.com/mudler/LocalAI/issues/9950).

***

##### 📎 Chat: File Attachments + Stream Usage + Selection

Three independent fixes that together make the chat experience visibly
better:

- **Text-file attachments actually reach the model (regression from
react-ui port)
([#&#8203;9896](https://redirect.github.com/mudler/LocalAI/issues/9896)).**
`.txt`, `.md`, `.csv`, `.json` content was silently dropped in
`useChat.js` (only image\_url and audio\_url branches added content; the
`else` branch only pushed metadata). `Home.jsx` also never called
`file.text()` for files attached from the home screen. Both fixed. PDF
files still need a parser (PDF.js or server-side extraction) and are
flagged as a known limitation.
- **Stream `include_usage` returns non-zero with tools
([#&#8203;9941](https://redirect.github.com/mudler/LocalAI/issues/9941)).**
Fixes
[#&#8203;9927](https://redirect.github.com/mudler/LocalAI/issues/9927).
`processTools` discarded the cumulative `TokenUsage` from
`ComputeChoices`, so the streaming trailer reported `{0, 0, 0}` whenever
a `tools` array was present. The fix forwards the authoritative final
usage via a sentinel chunk before `close(responses)`, with the outer
loop updated to capture before the empty-Choices skip. The OpenAI
streaming spec contract is preserved (intermediate chunks still carry no
`usage`).
- **Chat selection stops getting wiped every second
([#&#8203;9917](https://redirect.github.com/mudler/LocalAI/issues/9917)).**
React 19 dropped the old `lastHtml === nextHtml` short-circuit in its
DOM diff, so the 1s `/api/operations` poll re-assigning `setOperations`
with a fresh array reference was collapsing text selection on every
assistant message. Now JSON-compared and short-circuited. Bonus: the
per-message copy button works over plain HTTP via a hidden-textarea +
`execCommand('copy')` fallback when `navigator.clipboard` is
unavailable.

***

##### 🔧 llama.cpp Stability + Refactors

- **`tensor_buft_overrides` sentinel terminator
([#&#8203;9919](https://redirect.github.com/mudler/LocalAI/issues/9919)).**
Mirror upstream `common/arg.cpp:645-658`: pad placeholders at the end of
the main vector so `back().pattern == nullptr` holds, and append a
single `{nullptr, nullptr}` to the draft vector when non-empty.
- **`refactor(agents): bump skillserver, drop redundant Name`
([#&#8203;9916](https://redirect.github.com/mudler/LocalAI/issues/9916)).**
`list_skills` and `search_skills` now return the same shape (only `id`,
no duplicated `name`). Adds a Ginkgo regression that drives the LocalAI
`FilesystemManager` through an in-process MCP session.
- **Swagger refreshes
([#&#8203;9872](https://redirect.github.com/mudler/LocalAI/issues/9872),
[#&#8203;9962](https://redirect.github.com/mudler/LocalAI/issues/9962))**
keep the OpenAPI surface in sync with the routes added this cycle.

***

##### 🛠️ CI & Image Plumbing

- **Chronologically-orderable master tags.** Master images are now also
tagged `master-<epoch>-<sha>` so they sort by build time. The
pre-existing `master` tag still moves with `HEAD`.
- **Backend signing CI**: `COSIGN_EXPERIMENTAL=1` is set for the oci-1-1
referrers mode in the backend-signing job to keep current cosign
versions happy.

***

#### 🐛 Bug Fixes (recap)

- 🔁 `fix(distributed): route per request across loaded replicas + cache
probeHealth` -
[#&#8203;9968](https://redirect.github.com/mudler/LocalAI/issues/9968)
- 🧰 `fix(distributed): make admin backend installs resilient and
observable` -
[#&#8203;9958](https://redirect.github.com/mudler/LocalAI/issues/9958)
-  `fix(nodes): make per-node backend install async via gallery job
queue` -
[#&#8203;9928](https://redirect.github.com/mudler/LocalAI/issues/9928)
- 🧾 `fix(traces): cap backend trace Data to keep admin UI responsive` -
[#&#8203;9960](https://redirect.github.com/mudler/LocalAI/issues/9960)
- 🧾 `fix(traces): cap captured body size to keep admin Traces UI
responsive` -
[#&#8203;9946](https://redirect.github.com/mudler/LocalAI/issues/9946)
- 🪟 `fix(react-ui): unify backend-logs entry point for distributed mode`
- [#&#8203;9949](https://redirect.github.com/mudler/LocalAI/issues/9949)
- 📎 `fix: inject text-file content into chat completions messages` -
[#&#8203;9896](https://redirect.github.com/mudler/LocalAI/issues/9896)
- 🧮 `fix(openai): stream usage non-zero when tools are enabled` -
[#&#8203;9941](https://redirect.github.com/mudler/LocalAI/issues/9941)
- 🧷 `fix(react-ui/chat): stop wiping selection on every /api/operations
poll` -
[#&#8203;9917](https://redirect.github.com/mudler/LocalAI/issues/9917)
- 🧱 `fix(llama-cpp): terminate tensor_buft_overrides with sentinel` -
[#&#8203;9919](https://redirect.github.com/mudler/LocalAI/issues/9919)
- 🦾 `fix(L4T13 backends): switch vllm/sglang/vllm-omni to PyPI
aarch64+cu130 wheels` -
[#&#8203;9950](https://redirect.github.com/mudler/LocalAI/issues/9950)
- 🧊 `fix(nix): correct flake src path and add dev shell` -
[#&#8203;9894](https://redirect.github.com/mudler/LocalAI/issues/9894)
- 🔐 `Fix backend manifest merge signing on current cosign releases` -
[#&#8203;9957](https://redirect.github.com/mudler/LocalAI/issues/9957)
- 🧯 `[utils] Fail immediately on extraction errors` -
[#&#8203;9926](https://redirect.github.com/mudler/LocalAI/issues/9926)

***

#### 👒 Dependencies

Heavy bump cycle across submodules and Go/Python deps:

- **`ggml-org/llama.cpp`**: 7 bumps
([#&#8203;9855](https://redirect.github.com/mudler/LocalAI/issues/9855),
[#&#8203;9876](https://redirect.github.com/mudler/LocalAI/issues/9876),
[#&#8203;9897](https://redirect.github.com/mudler/LocalAI/issues/9897),
[#&#8203;9915](https://redirect.github.com/mudler/LocalAI/issues/9915),
[#&#8203;9934](https://redirect.github.com/mudler/LocalAI/issues/9934),
[#&#8203;9952](https://redirect.github.com/mudler/LocalAI/issues/9952),
[#&#8203;9963](https://redirect.github.com/mudler/LocalAI/issues/9963))
- **`ggml-org/whisper.cpp`**: 4 bumps
([#&#8203;9877](https://redirect.github.com/mudler/LocalAI/issues/9877),
[#&#8203;9898](https://redirect.github.com/mudler/LocalAI/issues/9898),
[#&#8203;9929](https://redirect.github.com/mudler/LocalAI/issues/9929),
[#&#8203;9954](https://redirect.github.com/mudler/LocalAI/issues/9954))
- **`ikawrakow/ik_llama.cpp`**: 7 bumps
([#&#8203;9866](https://redirect.github.com/mudler/LocalAI/issues/9866),
[#&#8203;9875](https://redirect.github.com/mudler/LocalAI/issues/9875),
[#&#8203;9899](https://redirect.github.com/mudler/LocalAI/issues/9899),
[#&#8203;9914](https://redirect.github.com/mudler/LocalAI/issues/9914),
[#&#8203;9930](https://redirect.github.com/mudler/LocalAI/issues/9930),
[#&#8203;9953](https://redirect.github.com/mudler/LocalAI/issues/9953),
[#&#8203;9966](https://redirect.github.com/mudler/LocalAI/issues/9966))
- **`leejet/stable-diffusion.cpp`**: 4 bumps
([#&#8203;9907](https://redirect.github.com/mudler/LocalAI/issues/9907),
[#&#8203;9933](https://redirect.github.com/mudler/LocalAI/issues/9933),
[#&#8203;9955](https://redirect.github.com/mudler/LocalAI/issues/9955),
[#&#8203;9965](https://redirect.github.com/mudler/LocalAI/issues/9965))
- **`antirez/ds4`**: 5 bumps
([#&#8203;9864](https://redirect.github.com/mudler/LocalAI/issues/9864),
[#&#8203;9900](https://redirect.github.com/mudler/LocalAI/issues/9900),
[#&#8203;9909](https://redirect.github.com/mudler/LocalAI/issues/9909),
[#&#8203;9932](https://redirect.github.com/mudler/LocalAI/issues/9932),
[#&#8203;9964](https://redirect.github.com/mudler/LocalAI/issues/9964))
- **`ace-step/acestep.cpp`**: bumped to `ed53caf` with wrapper API
adapted
([#&#8203;9908](https://redirect.github.com/mudler/LocalAI/issues/9908),
[#&#8203;9913](https://redirect.github.com/mudler/LocalAI/issues/9913))
- **Model gallery**: checksum refreshes
([#&#8203;9901](https://redirect.github.com/mudler/LocalAI/issues/9901),
[#&#8203;9910](https://redirect.github.com/mudler/LocalAI/issues/9910))
- **Go modules**: `alecthomas/kong` 1.14→1.15
([#&#8203;9881](https://redirect.github.com/mudler/LocalAI/issues/9881)),
`aws/aws-sdk-go-v2` 1.41.6→1.41.7
([#&#8203;9892](https://redirect.github.com/mudler/LocalAI/issues/9892)),
`onsi/ginkgo/v2` 2.28.2→2.29.0
([#&#8203;9882](https://redirect.github.com/mudler/LocalAI/issues/9882)),
`golang.org/x/crypto` 0.50→0.51
([#&#8203;9886](https://redirect.github.com/mudler/LocalAI/issues/9886))
- **Python**: `transformers` ≥5.8.1
([#&#8203;9883](https://redirect.github.com/mudler/LocalAI/issues/9883)),
`sentence-transformers` 5.4→5.5
([#&#8203;9888](https://redirect.github.com/mudler/LocalAI/issues/9888))

***

#### 📖 Documentation

- `docs: ⬆️ update docs version mudler/LocalAI` -
[#&#8203;9863](https://redirect.github.com/mudler/LocalAI/issues/9863)
- Plus inline docs updates folded into the feature PRs above
(prompt-cache explainer, authentication / usage tracking section,
backend signing guide).

***

#### 🙌 New Contributors

- [@&#8203;Azteczek](https://redirect.github.com/Azteczek) made their
first contribution in
[#&#8203;9851](https://redirect.github.com/mudler/LocalAI/pull/9851)
- [@&#8203;inquam](https://redirect.github.com/inquam) made their first
contribution in
[#&#8203;9896](https://redirect.github.com/mudler/LocalAI/pull/9896)
- [@&#8203;RinZ27](https://redirect.github.com/RinZ27) made their first
contribution in
[#&#8203;9926](https://redirect.github.com/mudler/LocalAI/pull/9926)

Enjoy!

***

**Full Changelog**:
<https://github.com/mudler/LocalAI/compare/v4.2.6...v4.3.0>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9sb2NhbC1haSIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=-->
2026-05-27 07:24:01 +02:00
TrueCharts BotandGitHub 00cbcab54d fix(docker): update image docker 29.5.1 → 29.5.2 (#48500)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker | patch | `eed377f` → `6b9cd91` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9kb2NrZXIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-05-27 07:23:53 +02:00
TrueCharts BotandGitHub ee2bc248e6 chore(yourls): update image yourls digest to cf5f0b4 (#48499)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| yourls | digest | `233e258` → `cf5f0b4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC95b3VybHMiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:23:15 +02:00
TrueCharts BotandGitHub 17c7358ce8 chore(monica): update image monica digest to 356531e (#48497)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| monica | digest | `8e1229b` → `356531e` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9tb25pY2EiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:23:09 +02:00
TrueCharts BotandGitHub 2c1b53d1e7 chore(yacy): update image docker.io/yacy/yacy_search_server digest to 9e8b192 (#48490)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/yacy/yacy_search_server | digest | `798d491` → `9e8b192` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC95YWN5IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9kaWdlc3QiXX0=-->
2026-05-27 07:23:02 +02:00
TrueCharts BotandGitHub c815f7af6d chore(tubesync): update image ghcr.io/meeb/tubesync digest to d319b51 (#48489)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/meeb/tubesync | digest | `ca71f3f` → `d319b51` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC90dWJlc3luYyIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
2026-05-27 07:22:55 +02:00
TrueCharts BotandGitHub af4f395a68 feat(ghostfolio): update image docker.io/ghostfolio/ghostfolio 3.4.0 → 3.5.0 (#48488)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/ghostfolio/ghostfolio](https://redirect.github.com/ghostfolio/ghostfolio)
| minor | `5e4e8b5` → `200c57a` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>ghostfolio/ghostfolio
(docker.io/ghostfolio/ghostfolio)</summary>

###
[`v3.5.0`](https://redirect.github.com/ghostfolio/ghostfolio/blob/HEAD/CHANGELOG.md#350---2026-05-24)

[Compare
Source](https://redirect.github.com/ghostfolio/ghostfolio/compare/3.4.0...3.5.0)

##### Added

- Configured the `min-release-age` in `.npmrc`

##### Changed

- Removed the deprecated attributes (`assetClass`, `countries`,
`currency`, `dataSource`, `name`, `sectors`, `symbol` and `url`) from
the holdings of the public portfolio endpoint response
- Removed the deprecated `api/v1/order` endpoints
- Upgraded `@keyv/redis` from version `4.4.0` to `5.1.6`

##### Fixed

- Fixed a layout regression that caused a double scrollbar on pages
without tabs
- Resolved an issue with missing cash positions caused by an incorrect
data source

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9naG9zdGZvbGlvIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->
2026-05-27 07:22:48 +02:00
TrueCharts BotandGitHub 85b0c31708 fix(maintainerr): update image docker.io/maintainerr/maintainerr 3.12.0 → 3.12.1 (#48485)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/maintainerr/maintainerr](https://redirect.github.com/Maintainerr/Maintainerr)
| patch | `8d52584` → `0778e0e` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Maintainerr/Maintainerr
(docker.io/maintainerr/maintainerr)</summary>

###
[`v3.12.1`](https://redirect.github.com/Maintainerr/Maintainerr/blob/HEAD/CHANGELOG.md#3121-2026-05-23)

[Compare
Source](https://redirect.github.com/Maintainerr/Maintainerr/compare/v3.12.0...v3.12.1)

#### Highlights

- Added `ruleEvaluationFailed` field to `collection_media` table to
track rule evaluation failures for collection media.
- Improved performance of rule evaluation by reducing concurrency and
introducing deduplication for uncached media lookups.

#### Features

- Added detailed error logging for Emby image upload failures, including
server response body for better debugging.

#### Fixes

- Resolved issue where Emby overlays would not revert after media was
removed from a collection.
- Fixed incorrect rendering of overlay notification titles for
Emby/Jellyfin movies.
- Corrected collection `ruleGroup` entity type in the server.
- Addressed issues with rule evaluation failure tracking for collection
media.

#### Performance

- Reduced `RULE_EVALUATION_CONCURRENCY` from 16 to 8 to prevent
overloading co-located backends.
- Improved rule evaluation performance by deduplicating uncached
Sonarr/Radarr identity lookups per run.
- Batched rule operand reads with bounded concurrency for better
efficiency.
- Parallelized per-item Plex watch-history reads during rule execution.

#### Database migrations

- Added `ruleEvaluationFailed` column to the `collection_media` table to
track rule evaluation failures.

#### Internal

- Renamed internal settings services and decoupled them into separate
operations and data layers.
- Removed unused `forwardRef` imports from `SettingsModule` after
refactoring.
- Added tests for `ArrLookupCache` deduplication and eviction on
failure.
- Added tests to ensure fresh series reads during empty-show cleanup.

#### Dependencies

- Updated 13 dependencies, including nodemailer, glob, qs, postcss,
[@&#8203;hookform/resolvers](https://redirect.github.com/hookform/resolvers),
typescript-eslint, and vite.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9tYWludGFpbmVyciIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-27 07:22:05 +02:00
TrueCharts BotandGitHub 08cee6b575 chore(searxng): update image docker.io/searxng/searxng digest to 1a9d213 (#48473)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/searxng/searxng | digest | `4f0db33` → `1a9d213` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9zZWFyeG5nIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9kaWdlc3QiXX0=-->
2026-05-27 07:21:57 +02:00
TrueCharts BotandGitHub 97da68fc59 chore(wordpress): update image docker.io/bitnamisecure/wordpress digest to a1c720b (#48486)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/bitnamisecure/wordpress | digest | `4965c05` → `a1c720b` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC93b3JkcHJlc3MiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:21:53 +02:00
TrueCharts BotandGitHub ef663f8905 chore(sshwifty): update image docker.io/niruix/sshwifty digest to 610b0c8 (#48484)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/niruix/sshwifty | digest | `cb414e4` → `610b0c8` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9zc2h3aWZ0eSIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
2026-05-27 07:21:43 +02:00
TrueCharts BotandGitHub b1d80454f8 chore(filestash): update image docker.io/machines/filestash digest to 76f3a45 (#48472)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/machines/filestash | digest | `3ee7f7a` → `76f3a45` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9maWxlc3Rhc2giLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:21:31 +02:00
TrueCharts BotandGitHub e82790141a chore(factorio): update image docker.io/factoriotools/factorio digest to 0bd437f (#48471)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/factoriotools/factorio | digest | `3cd46d3` → `0bd437f` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9mYWN0b3JpbyIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
2026-05-27 07:21:15 +02:00
TrueCharts BotandGitHub b6e3f82462 feat(xen-orchestra): update image docker.io/ronivay/xen-orchestra 5.200.1 → 5.201.0 (#48470)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/ronivay/xen-orchestra | minor | `46692f8` → `2675535` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC94ZW4tb3JjaGVzdHJhIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->
2026-05-27 07:21:06 +02:00
TrueCharts BotandGitHub cc76db96f8 fix(rdtclient): update image ghcr.io/rogerfar/rdtclient 2.0.133 → 2.0.134 (#48469)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/rogerfar/rdtclient](https://redirect.github.com/rogerfar/rdt-client)
| patch | `ed50479` → `2d42d68` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>rogerfar/rdt-client (ghcr.io/rogerfar/rdtclient)</summary>

###
[`v2.0.134`](https://redirect.github.com/rogerfar/rdt-client/blob/HEAD/CHANGELOG.md#20134---2026-05-22)

[Compare
Source](https://redirect.github.com/rogerfar/rdt-client/compare/v2.0.133...v2.0.134)

##### Changed

Upgraded torbox.net dependency.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9yZHRjbGllbnQiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-05-27 07:20:46 +02:00
TrueCharts BotandGitHub a5936ecccd fix(fireshare): update image docker.io/shaneisrael/fireshare 1.6.11 → 1.6.12 (#48468)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/shaneisrael/fireshare](https://redirect.github.com/ShaneIsrael/fireshare)
| patch | `3dbde8e` → `e4489db` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>ShaneIsrael/fireshare
(docker.io/shaneisrael/fireshare)</summary>

###
[`v1.6.12`](https://redirect.github.com/ShaneIsrael/fireshare/releases/tag/v1.6.12)

[Compare
Source](https://redirect.github.com/ShaneIsrael/fireshare/compare/v1.6.11...v1.6.12)

#### Bug Fixes

- Improved logic in scan\_video (CLI) to avoid duplicate VideoGameLink
associations which would cause unique constraint errors.
- Adjusted admin password warning logic to not show when LDAP is
enabled.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9maXJlc2hhcmUiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-05-27 07:20:35 +02:00
TrueCharts BotandGitHub 9192f4813b chore(tachidesk-docker): update image ghcr.io/suwayomi/tachidesk digest to 0839e70 (#48467)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/suwayomi/tachidesk | digest | `410e07f` → `0839e70` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC90YWNoaWRlc2stZG9ja2VyIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9kaWdlc3QiXX0=-->
2026-05-27 07:20:25 +02:00
TrueCharts BotandGitHub 03f6cb675e feat(wekan): update image docker.io/wekanteam/wekan v9.26 → v9.30 (#48461)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/wekanteam/wekan](https://redirect.github.com/wekan/wekan) |
minor | `be29bc4` → `a29ae17` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>wekan/wekan (docker.io/wekanteam/wekan)</summary>

###
[`v9.30`](https://redirect.github.com/wekan/wekan/blob/HEAD/CHANGELOG.md#v930-2026-05-22-WeKan--release)

[Compare
Source](https://redirect.github.com/wekan/wekan/compare/v9.29...v9.30)

This release adds the following updates:

- [Try to fix Snap build LXD container network Internet
access](https://redirect.github.com/wekan/wekan/commit/07e6f663db0fb077dad6d88c1bd9d53139375cae).
  Thanks to xet7.
- [Fix Snap LXD container to work when network already
exists](https://redirect.github.com/wekan/wekan/commit/fb05b1a847be2e47d8c27c3959e063caf7cde886).
  Thanks to xet7.
- [Release scripts: Use locally cached
files](https://redirect.github.com/wekan/wekan/commit/6463a1ef87b2741c3bafdd39391efcd9c6534b83).
  Thanks to xet7.

Thanks to above GitHub users for their contributions and translators for
their translations.

###
[`v9.29`](https://redirect.github.com/wekan/wekan/blob/HEAD/CHANGELOG.md#v929-2026-05-22-WeKan--release)

[Compare
Source](https://redirect.github.com/wekan/wekan/compare/v9.28...v9.29)

This release adds the following updates:

- [Try to fix
Snap](https://redirect.github.com/wekan/wekan/commit/83078736f527101e1b983037c33a9b26c9639542).
  Thanks to xet7.
- [Updated
dependencies](https://redirect.github.com/wekan/wekan/commit/3e33c766d6f63eb2369898bcab9233e9e49240be).
  Thanks to developers of dependencies.

Thanks to above GitHub users for their contributions and translators for
their translations.

###
[`v9.28`](https://redirect.github.com/wekan/wekan/blob/HEAD/CHANGELOG.md#v928-2026-05-22-WeKan--release)

[Compare
Source](https://redirect.github.com/wekan/wekan/compare/v9.26...v9.28)

This release adds the following updates:

- [Build scripts: Update arm64 build
script](https://redirect.github.com/wekan/wekan/commit/e7f2068105b36b8003be4e416594b213555141db).
  Thanks to xet7.
- [Try to fix Snap by using correct versions of
dependencies](https://redirect.github.com/wekan/wekan/commit/ecbecc9d861743a1b7b4b48db65fa93cf5194257).
  Thanks to xet7.

Thanks to above GitHub users for their contributions and translators for
their translations.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC93ZWthbiIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=-->
2026-05-27 07:20:14 +02:00
TrueCharts BotandGitHub 8d20d91147 feat(etherpad): update image ghcr.io/ether/etherpad 3.1.0 → 3.2.0 (#48459)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/ether/etherpad](https://redirect.github.com/ether/etherpad) |
minor | `7bae8bd` → `ba06bc0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>ether/etherpad (ghcr.io/ether/etherpad)</summary>

###
[`v3.2.0`](https://redirect.github.com/ether/etherpad/blob/HEAD/CHANGELOG.md#320)

[Compare
Source](https://redirect.github.com/ether/etherpad/compare/3.1.0...3.2.0)

3.2 adds first-class reverse-proxy / ingress support —
`X-Forwarded-Prefix` and `X-Ingress-Path` are now honoured under
`trustProxy`, so Etherpad can live under a subpath (Traefik, Nginx,
Kubernetes Ingress) without breaking the PWA manifest, social-meta URLs,
or any of the bootstrap asset links. The admin settings page learns to
show *resolved* runtime values next to `${VAR:default}` placeholders,
the v3.1.0 admin pad-list filter chips now apply server-side (so "show
empty pads" no longer returns 0–12 of hundreds), and the v3.1.0
redesigned outdated-version gritter actually fires in production now
(the session-based author lookup it shipped with always returned null
for pad visitors).

##### Notable enhancements

- **HTTP — accept `X-Forwarded-Prefix` and `X-Ingress-Path` under
`trustProxy`
([#&#8203;7802](https://redirect.github.com/ether/etherpad/issues/7802)
/
[#&#8203;7806](https://redirect.github.com/ether/etherpad/issues/7806)).**
With `trustProxy: true`, Etherpad now honours `X-Forwarded-Prefix`
(de-facto Traefik / Spring) and `X-Ingress-Path` (Kubernetes Ingress) in
addition to the prefix it already inferred from the request path. The
shared `sanitizeProxyPath` helper added in 3.1.0 (defence-in-depth:
`[A-Za-z0-9_./-]` only, `//+` collapsed, `..` traversal rejected) is
extended to the new headers and applied consistently across
`/manifest.json`, `socialMeta` `og:url` / `og:image`, and the
`index.html` / `pad.html` / `timeslider.html` / `export_html.html`
templates (manifest links, jslicense links, reconnect URLs). A
pre-existing `..` segment-count miscalculation in `pad.html` /
`timeslider.html` that broke the manifest link when served from a deep
subpath is also fixed in passing. New end-to-end suite covers the
prefix-applied / prefix-ignored matrix under `trustProxy=true|false` for
both header names. `settings.json.template` documents the new headers
alongside the existing `trustProxy` notes.
- **Admin settings — resolved runtime values surface on env-pill chips
([#&#8203;7803](https://redirect.github.com/ether/etherpad/issues/7803)
/
[#&#8203;7807](https://redirect.github.com/ether/etherpad/issues/7807)).**
The `/admin/settings` socket payload now carries a new `resolved` field
alongside the existing raw-file `results` blob, carrying the actual
in-memory settings module run through a new redactor
(`AdminSettingsRedact`) that replaces known-sensitive paths
(`users.*.password`, `dbSettings.password`,
`sso.clients[*].client_secret`, `sessionKey`, …) with `[REDACTED]`. The
admin SPA's `EnvPill` renders a `→ active value` chip when the path is
resolved, or `→ ••••••` with a redacted tooltip when the server returned
the sentinel — so `port: ${PORT:9001}` now shows `→ 9001` (or whatever
the live value is) instead of silently falling back to the template
default. Old admin SPAs that don't read `resolved` continue to work; the
save round-trip is unchanged so `${VAR:default}` literals are still
preserved verbatim on disk. The admin test script glob picks up
`.test.tsx` alongside `.test.ts` so the new `EnvPill` and
`resolveByPath` tests run under `tsx --test`.

##### Notable fixes

- **Admin pads — filter chip now applies server-side, before pagination
([#&#8203;7798](https://redirect.github.com/ether/etherpad/issues/7798)).**
The 3.1.0 admin pad-list filter chips (`active` / `recent` / `empty` /
`stale`) ran on the client *after* the 12-row page slice had already
arrived. On a deployment with hundreds of pads, clicking "empty pads" on
page 1 only matched the 0–12 empties that happened to land in the
current page, with the pagination footer reporting nonsense totals
(reported on a 3.1.0 deployment). The filter is now part of the
`padLoad` socket query — pattern filter on names runs first (cheap),
metadata hydration for the matching pad universe is gated on a non-`all`
filter or a non-`padName` sort and runs under a 16-way concurrency cap
(was unbounded `Promise.all`, which fanned out to thousands of in-flight
`padManager.getPad()` reads on busy deployments), then the filter chip,
then sort + slice. `total` reflects the filtered universe so the footer
makes sense. Older admin clients that don't send `filter` keep working —
the server defaults to `all`. The `if/else if` ladder that duplicated
the hydrate-and-sort loop per `sortBy` is folded into one pipeline with
a single comparator switch.
- **Pad outdated notice — author now resolved from token cookie, not
session (Qodo
[#&#8203;7804](https://redirect.github.com/ether/etherpad/issues/7804) /
[#&#8203;7805](https://redirect.github.com/ether/etherpad/issues/7805)).**
The 3.1.0 redesigned outdated-version gritter never fired in production.
`resolveRequestAuthor()` looked for an `authorID` on `req.session.user`,
which Etherpad does not populate for pad visitors (express-session only
carries the admin-login user), so `computeOutdated()` always returned
EMPTY. The lookup now mirrors how the socket.io handshake resolves
pad-visitor identity — read the HttpOnly `token` (or `<prefix>token`)
cookie and call `authorManager.getAuthorId(token, user)` via a dynamic
import (same circular-init guard pattern the file already uses for
`PadManager`). The admin OpenAPI document gains a `description` note
clarifying that `/api/version-status` is a public pad-side endpoint that
lives in the admin doc only because it shares the same internal route
registration.
- **Localisation — silence spurious "could not translate element
content" warning
([#&#8203;7797](https://redirect.github.com/ether/etherpad/issues/7797)).**
`<select data-l10n-id="…">` with `<option>` element children — the
pattern used by `ep_headings2`, `ep_align`, `ep_font_size`,
`ep_font_family`, … — used to drop into the textContent branch of
`html10n.translateNode`, hunt for a text-node child to overwrite, find
none, and emit `Unexpected error: could not translate element content
for key …` on every pad load. The `SELECT` / `INPUT` / `TEXTAREA`
aria-label fallback already lived inside the same else-branch *after*
the warning, so the accessible name landed correctly but the noisy
console line still fired. Form-control elements now short-circuit into
the aria-label path *before* the text-node hunt — aria-label is the only
sensible localization target for these elements (a `<select>`'s text is
its `<option>` labels, not its own name). Closes the console warning
reported on Etherpad 3.1.0.

##### Internal / contributor-facing

- **CI — swap archived `ep_readonly_guest` for `ep_guest` in the plugin
matrix
([#&#8203;7795](https://redirect.github.com/ether/etherpad/issues/7795)
/
[#&#8203;7808](https://redirect.github.com/ether/etherpad/issues/7808)).**
`ep_readonly_guest` is archived (read-only on GitHub) and its
`authenticate` hook unconditionally swapped `req.session.user` with a
read-only guest, *even when the request carried an HTTP Authorization
header*. That silently demoted admin login attempts and stalled the
`anonymizeAuthorSocket` tests for 14 min/run on every with-plugins CI
matrix. The pre-fix theory from 3.1.0
([#&#8203;7796](https://redirect.github.com/ether/etherpad/issues/7796))
blamed `ep_hash_auth.handleMessage`; that was a red herring —
`handleMessage` only fires on the `/pad` namespace, never on
`/settings`. `ep_guest` is the maintained successor (same authors, same
purpose); 1.0.72 on npm already defers to basic auth / admin paths.
Swapping the matrix unblocks the `anonymizeAuthorSocket` suite on Linux,
Windows, and the upgrade-from-latest-release workflow. The runtime probe
added in
[#&#8203;7796](https://redirect.github.com/ether/etherpad/issues/7796)
stays — it still catches any other authenticate-hook plugin that rejects
the test's plain-text credentials (e.g. a future hashed-only plugin).
- **Tests — admin `saveSettings` round-trip + cross-restart persistence
([#&#8203;7819](https://redirect.github.com/ether/etherpad/issues/7819)
/ [#&#8203;7820](https://redirect.github.com/ether/etherpad/issues/7820)
/
[#&#8203;7821](https://redirect.github.com/ether/etherpad/issues/7821)).**
The admin `saveSettings` socket had zero direct backend coverage and the
existing e2e "restart works" test only checked that the page renders
after a restart, neither of which catches a deployment that resets
`settings.json` on restart, nor the user-visible workflow that triggered
[#&#8203;7819](https://redirect.github.com/ether/etherpad/issues/7819)
(add a top-level plugin block via Raw, save, watch it disappear). Three
new backend specs (`adminSettingsSave.ts`) verify byte-for-byte write,
top-level-block augmentation round-tripping through the next `load`, and
`/* */` comments surviving the write path. A new e2e spec mirrors the
[#&#8203;7819](https://redirect.github.com/ether/etherpad/issues/7819)
user workflow — open Raw, prepend an `ep_oauth`-shaped top-level block,
save, `restartEtherpad()`, re-login, confirm the block is still in Raw
and surfaces as its own Form-view section (`Ep oauth` from
`humanize()`). A separate `docker.yml` job (`adminSettings_7819.ts`)
authenticates via `POST /admin-auth/` (always-requireAdmin, regardless
of `settings.requireAuthentication`), saves a hand-built
minimal-but-viable settings document containing a marker block, `docker
exec test grep`s for it, `docker restart`s the container, waits for the
health probe, and re-greps. Both checks must pass.
- **Bug report template** now asks contributors whether the abstraction
in their proposed fix matches the rest of the codebase, to head off
premature-generalisation fixes earlier in review.

##### Dependencies

- `ueberdb2` 6.0.3 → 6.1.2 (two patch releases of cleanup on top of the
6.1.0 `findKeysPaged` API that the 3.1.0 sessionstorage OOM fix relies
on).
- `semver` 7.8.0 → 7.8.1, `lru-cache` 11.3.6 → 11.5.0,
`@elastic/elasticsearch` 9.4.0 → 9.4.1, `pg` 8.20.0 → 8.21.0,
`openapi-backend` 5.16.1 → 5.17.0, `tsx` 4.22.0 → 4.22.3,
`@tanstack/react-query` 5.100.10 → 5.100.11 +
`@tanstack/react-query-devtools`, `js-cookie` 3.0.6 → 3.0.7, plus two
dev-dependency group bumps.

##### Localisation

- Multiple updates from translatewiki.net.

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9ldGhlcnBhZCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=-->
2026-05-27 07:19:58 +02:00
TrueCharts BotandGitHub 57c98fca27 fix(openobserve): update image public.ecr.aws/zinclabs/openobserve v0.90.1 → v0.90.3 (#48457)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| public.ecr.aws/zinclabs/openobserve | patch | `7e09fce` → `f778561` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9vcGVub2JzZXJ2ZSIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-27 07:19:37 +02:00
TrueCharts BotandGitHub b5f650bc5c chore(thelounge): update image docker.io/thelounge/thelounge digest to ee5d2e8 (#48454)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/thelounge/thelounge](https://redirect.github.com/thelounge/thelounge-docker)
| digest | `197048e` → `ee5d2e8` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC90aGVsb3VuZ2UiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:18:59 +02:00
TrueCharts BotandGitHub 7f1ab3d68f chore(farmos): update image docker.io/farmos/farmos digest to d083818 (#48453)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/farmos/farmos | digest | `a631191` → `d083818` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9mYXJtb3MiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 07:18:50 +02:00
TrueCharts BotandGitHub 7b7c0f4966 chore(tt-rss): update image ghcr.io/tt-rss/tt-rss digest to 3fb1155 (#48540)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/tt-rss/tt-rss | digest | `cfa267a` → `3fb1155` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC90dC1yc3MiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 06:57:40 +02:00
TrueCharts BotandGitHub 73b1d9afb1 chore(impostor-server): update image docker.io/aeonlucid/impostor digest to a6f1ae8 (#48533)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/aeonlucid/impostor | digest | `cdc3a89` → `a6f1ae8` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9pbXBvc3Rvci1zZXJ2ZXIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-27 00:39:10 +02:00
TrueCharts BotandGitHub 7bb7c309cc chore(drawio): update image docker.io/jgraph/drawio digest to c01c93e (#48528)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [docker.io/jgraph/drawio](https://www.drawio.com)
([source](https://redirect.github.com/jgraph/docker-drawio)) | digest |
`b87c521` → `c01c93e` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9kcmF3aW8iLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-26 18:26:06 +02:00
TrueCharts BotandGitHub 398d2f802c chore(rickroll): update image docker.io/modem7/docker-rickroll digest to 412c6f6 (#48527)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/modem7/docker-rickroll | digest | `a1e96ad` → `412c6f6` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9yaWNrcm9sbCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
2026-05-26 12:11:29 +02:00
TrueCharts BotandGitHub 192e65c675 chore(newyearcountdownclock): update image docker.io/modem7/newyearcountdown digest to c312cc3 (#48526)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/modem7/newyearcountdown | digest | `cd09e48` → `c312cc3` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9uZXd5ZWFyY291bnRkb3duY2xvY2siLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-26 12:10:40 +02:00
TrueCharts BotandGitHub 5f422d162a chore(grocy): update image ghcr.io/linuxserver/grocy digest to fa81947 (#48518)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/grocy](https://redirect.github.com/linuxserver/docker-grocy/packages)
([source](https://redirect.github.com/linuxserver/docker-grocy)) |
digest | `971fb0b` → `fa81947` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9ncm9jeSIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
2026-05-26 05:56:07 +02:00
TrueCharts BotandGitHub 72cf468e39 chore(steam-headless): update image docker.io/josh5/steam-headless digest to c95869d (#48523)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/josh5/steam-headless | digest | `3acd5b5` → `c95869d` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9zdGVhbS1oZWFkbGVzcyIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvZGlnZXN0Il19-->
2026-05-26 05:55:41 +02:00
TrueCharts BotandGitHub 58106de32f fix(speedtest-tracker): update image ghcr.io/linuxserver/speedtest-tracker 1.14.2 → 1.14.3 (#48514)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/speedtest-tracker](https://redirect.github.com/linuxserver/docker-speedtest-tracker/packages)
([source](https://redirect.github.com/linuxserver/docker-speedtest-tracker))
| patch | `3f75c5e` → `8b18bf5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9zcGVlZHRlc3QtdHJhY2tlciIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-25 23:42:37 +02:00
TrueCharts BotandGitHub 033b23b8fe chore(anything-llm): update image ghcr.io/mintplex-labs/anything-llm digest to 1d25fa1 (#48451)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| ghcr.io/mintplex-labs/anything-llm | digest | `2cf1159` → `1d25fa1` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9hbnl0aGluZy1sbG0iLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-25 21:32:33 +00:00
TrueCharts BotandGitHub a74e1e1ad8 chore(automatic-ripping-machine): update image docker.io/automaticrippingmachine/automatic-ripping-machine digest to 8820722 (#48452)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/automaticrippingmachine/automatic-ripping-machine](https://redirect.github.com/automatic-ripping-machine/automatic-ripping-machine)
| digest | `fe0cb8b` → `8820722` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9hdXRvbWF0aWMtcmlwcGluZy1tYWNoaW5lIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9kaWdlc3QiXX0=-->
2026-05-25 21:32:16 +00:00
TrueCharts BotandGitHub a2f921fc94 fix(n8n): update image ghcr.io/n8n-io/n8n 2.22.2 → 2.22.3 (#48508)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/n8n-io/n8n](https://n8n.io)
([source](https://redirect.github.com/n8n-io/n8n)) | patch | `bf26d48` →
`75d18a9` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9uOG4iLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-05-25 17:44:44 +02:00
TrueCharts BotandGitHub 7ec741d419 fix(minecraft-java): update image ghcr.io/itzg/minecraft-server 2026.5.2 → 2026.5.3 (#48507)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `0e10897` → `2924b8e` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `7eb42b8` → `ae5d563` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `0adef25` → `18f27c8` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `76c8d92` → `0d47cfd` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `83b6b38` → `8ca8ce3` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `d563435` → `e9ecf2c` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `3abc323` → `e755f58` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `8c951a2` → `0ca9313` |
|
[ghcr.io/itzg/minecraft-server](https://redirect.github.com/itzg/docker-minecraft-server)
| patch | `5476619` → `189ac37` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>itzg/docker-minecraft-server
(ghcr.io/itzg/minecraft-server)</summary>

###
[`v2026.5.3`](https://redirect.github.com/itzg/docker-minecraft-server/releases/tag/2026.5.3)

[Compare
Source](https://redirect.github.com/itzg/docker-minecraft-server/compare/2026.5.2...2026.5.3)

<!-- Release notes generated using configuration in .github/release.yml
at d3754005413ac5cee8988b0e6e046c2d6857fb7d -->

##### What's Changed

##### Enhancements

- Load env vars from file or archive at startup by
[@&#8203;ChipWolf](https://redirect.github.com/ChipWolf) in
[#&#8203;4053](https://redirect.github.com/itzg/docker-minecraft-server/pull/4053)

##### Documentation

- build(deps): bump zensical from 0.0.40 to 0.0.41 in /docs in the
patches group by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;4057](https://redirect.github.com/itzg/docker-minecraft-server/pull/4057)
- examples: fix invalid data volume for vanilla-tweaks by
[@&#8203;itzg](https://redirect.github.com/itzg) in
[#&#8203;4064](https://redirect.github.com/itzg/docker-minecraft-server/pull/4064)
- build(deps): bump pymdown-extensions from 10.21.2 to 10.21.3 in /docs
by [@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;4072](https://redirect.github.com/itzg/docker-minecraft-server/pull/4072)
- Specify .mrpack extension for local mrpack files by
[@&#8203;roziscoding](https://redirect.github.com/roziscoding) in
[#&#8203;4079](https://redirect.github.com/itzg/docker-minecraft-server/pull/4079)

##### Other Changes

- Update dependency itzg/mc-image-helper to v1.57.4 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4054](https://redirect.github.com/itzg/docker-minecraft-server/pull/4054)
- Update dependency itzg/easy-add to v0.8.12 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4055](https://redirect.github.com/itzg/docker-minecraft-server/pull/4055)
- build(deps): Bump mc-image-helper java8 to 1.51.2 by
[@&#8203;harrisonablack](https://redirect.github.com/harrisonablack) in
[#&#8203;4056](https://redirect.github.com/itzg/docker-minecraft-server/pull/4056)
- Adjust labels for docs in dependabot.yml by
[@&#8203;itzg](https://redirect.github.com/itzg) in
[#&#8203;4041](https://redirect.github.com/itzg/docker-minecraft-server/pull/4041)
- Update dependency itzg/mc-server-runner to v1.14.6 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4035](https://redirect.github.com/itzg/docker-minecraft-server/pull/4035)
- Update dependency itzg/mc-image-helper to v1.58.0 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4059](https://redirect.github.com/itzg/docker-minecraft-server/pull/4059)
- Update java8 builds to 1.51.3-java8 by
[@&#8203;itzg](https://redirect.github.com/itzg) in
[#&#8203;4060](https://redirect.github.com/itzg/docker-minecraft-server/pull/4060)
- Update dependency itzg/mc-monitor to v0.16.3 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4063](https://redirect.github.com/itzg/docker-minecraft-server/pull/4063)
- Update dependency itzg/mc-monitor to v0.16.4 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4065](https://redirect.github.com/itzg/docker-minecraft-server/pull/4065)
- Update dependency itzg/rcon-cli to v1.7.5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4066](https://redirect.github.com/itzg/docker-minecraft-server/pull/4066)
- feat: Server library cleanup on paper install by
[@&#8203;harrisonablack](https://redirect.github.com/harrisonablack) in
[#&#8203;4046](https://redirect.github.com/itzg/docker-minecraft-server/pull/4046)
- Update dependency itzg/restify to v1.7.14 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4070](https://redirect.github.com/itzg/docker-minecraft-server/pull/4070)
- Update dependency itzg/mc-server-runner to v1.14.7 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4069](https://redirect.github.com/itzg/docker-minecraft-server/pull/4069)
- Update dependency itzg/easy-add to v0.8.13 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4067](https://redirect.github.com/itzg/docker-minecraft-server/pull/4067)
- Update dependency itzg/mc-monitor to v0.16.5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4071](https://redirect.github.com/itzg/docker-minecraft-server/pull/4071)
- Update dependency itzg/mc-image-helper to v1.59.1 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;4076](https://redirect.github.com/itzg/docker-minecraft-server/pull/4076)
- Pin java11 and java16 to java8 branch of mc-image-helper by
[@&#8203;itzg](https://redirect.github.com/itzg) in
[#&#8203;4077](https://redirect.github.com/itzg/docker-minecraft-server/pull/4077)

##### New Contributors

- [@&#8203;harrisonablack](https://redirect.github.com/harrisonablack)
made their first contribution in
[#&#8203;4056](https://redirect.github.com/itzg/docker-minecraft-server/pull/4056)
- [@&#8203;roziscoding](https://redirect.github.com/roziscoding) made
their first contribution in
[#&#8203;4079](https://redirect.github.com/itzg/docker-minecraft-server/pull/4079)

**Full Changelog**:
<https://github.com/itzg/docker-minecraft-server/compare/2026.5.2...2026.5.3>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9taW5lY3JhZnQtamF2YSIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-25 17:38:32 +02:00
TrueCharts BotandGitHub af30b7f09e feat(victoriametrics): update image docker.io/victoriametrics/victoria-metrics v1.143.0 → v1.144.0 (#48509) 2026-05-25 17:28:35 +02:00
TrueCharts BotandGitHub ae0e9e4e89 fix(slink): update image docker.io/anirdev/slink v1.11.3 → v1.11.5 (#48458) 2026-05-25 17:28:25 +02:00
TrueCharts BotandGitHub 0569e8d0cc fix(healthchecks): update image ghcr.io/linuxserver/healthchecks 4.2.20260518 → 4.2.20260525 (#48506)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/healthchecks](https://redirect.github.com/linuxserver/docker-healthchecks/packages)
([source](https://redirect.github.com/linuxserver/docker-healthchecks))
| patch | `c4be6f1` → `9c41e78` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9oZWFsdGhjaGVja3MiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-05-25 17:28:15 +02:00
TrueCharts BotandGitHub 93f487f917 fix(docuseal): update image docker.io/docuseal/docuseal 3.0.0 → 3.0.1 (#48505)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/docuseal/docuseal | patch | `0e1990a` → `af8cdcd` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9kb2N1c2VhbCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-25 17:28:08 +02:00
TrueCharts BotandGitHub 6e55f3961b fix(cloudflared): update image docker.io/cloudflare/cloudflared 2026.5.0 → 2026.5.1 (#48504)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/cloudflare/cloudflared](https://redirect.github.com/cloudflare/cloudflared)
| patch | `59bab8d` → `a5b5e6f` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>cloudflare/cloudflared
(docker.io/cloudflare/cloudflared)</summary>

###
[`v2026.5.1`](https://redirect.github.com/cloudflare/cloudflared/releases/tag/2026.5.1)

[Compare
Source](https://redirect.github.com/cloudflare/cloudflared/compare/2026.5.0...2026.5.1)

##### SHA256 Checksums:

```
cloudflared-amd64.pkg: f1b8ff401fce3863dac400129f27fce90fe5b682582c70c60c8e4d5ab2258c3d
cloudflared-arm64.pkg: 8e35c67d5488baa6656aff2d777258c27c7dd08a4a8f022afbf536a52c0c3496
cloudflared-darwin-amd64.tgz: c232c2be1fda76ffb5dff55874c4d4e3d3137bd426e3e73d539c3ecbe20526a2
cloudflared-darwin-arm64.tgz: 086dd6628a3608eba7327af1092abcc52b10994524112ae49bf356ec49bef8c4
cloudflared-fips-linux-amd64: 8df480451aaf0829fea35b208e137cf692002eed4ae000093aa8669545f47873
cloudflared-fips-linux-amd64.deb: bc4e5f62220b3997c0919e5eff399627c2d862f990e42837f0530cef576da5b5
cloudflared-fips-linux-x86_64.rpm: d0faf1bf239b8e616d360b515ffc8006b35f7acc6258fe646483f68b825beda4
cloudflared-linux-386: 3b2dce38a91e0806ac581cfdd80fd3b382a5c85cad2bb351e95a0820bbc4e8b1
cloudflared-linux-386.deb: de68946f1a7a4290088a8f9ec5cc10e864604a23c63bf9636c6bd4e1d6820488
cloudflared-linux-386.rpm: 6525ed3edb564bf7196869236379db8412e8577d6c5725b159a3c1abec6de412
cloudflared-linux-aarch64.rpm: 30d02e78f1f1bb713ef0df0b412b1289788a5204f98b42206e51349f9e26229a
cloudflared-linux-amd64: 3c6a5ba995a258dbe90f98e5fdb2c2620b7be72c3ca761614f6eb52aee252cea
cloudflared-linux-amd64.deb: 4274f6106efbe586e8e2127aba02798c55bcfd99a45d14f08779d6afc51e8752
cloudflared-linux-arm: 9f30ac7accb7968b5f204a49749d0f2ea42b2c3e3ca43470d13791d50557ca45
cloudflared-linux-arm.deb: 2047dfda06bc19d9c274b265250e3057b8896264699571cf701e0cb27cad0481
cloudflared-linux-arm.rpm: aced95394d2a0130974df1e74f115b2a46b6f3027b48823dddebe876ac907608
cloudflared-linux-arm64: 7b7a8b9a2764acab0fecda633cb54a6c0df42d7f8ca1ec45c78333c2227d8d91
cloudflared-linux-arm64.deb: 649d1e835392fddf009e9697c077e793bd66c331138cff256ab4ff939dd2fed2
cloudflared-linux-armhf: 85f8751e744f1a136dc6da3050ca30f18378e926db72c46d2ed6981c1b054873
cloudflared-linux-armhf.deb: c6d3f9daaf3b2033fc0ec567c7e82982acfd7817dcd0ea5f84e4861d7f9cff63
cloudflared-linux-armhf.rpm: 584e133ffe5d14079995e9658b606ba29846707781e8b986353736e4ea5a50d3
cloudflared-linux-x86_64.rpm: 66b56510509f310a96462bad26d2a524e709687c2695ae65909696aead414815
cloudflared-windows-386.exe: fee35ed451cf3c405a5736447a3f2cce7482b3ca1f6f0f1b1e3c2ae7b18d3d06
cloudflared-windows-386.msi: b4bcccc19a92168a45282c3fb76de5adc8b1632c97c0fbf380f69504a24017a2
cloudflared-windows-amd64.exe: 8b97b5af442651e07c52caa9c79c6f60032bc10b675c2b36dd11c7690d9942e3
cloudflared-windows-amd64.msi: 506124ecc4140973304f7aa41070e9d1258a5d26125331bb6d16dceab4fa5b4e
```

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9jbG91ZGZsYXJlZCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-25 17:27:12 +02:00
TrueCharts BotandGitHub 8e8d7e03ef chore(rsshub): update image docker.io/diygod/rsshub digest to 72c22bf (#48503)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/diygod/rsshub | digest | `b56b767` → `72c22bf` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9yc3NodWIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-25 17:27:08 +02:00
TrueCharts BotandGitHub 99a4e545ea chore(mysql-workbench): update image ghcr.io/linuxserver/mysql-workbench digest to c291059 (#48502)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/linuxserver/mysql-workbench](https://redirect.github.com/linuxserver/docker-mysql-workbench/packages)
([source](https://redirect.github.com/linuxserver/docker-mysql-workbench))
| digest | `2510a21` → `c291059` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9teXNxbC13b3JrYmVuY2giLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-25 17:26:40 +02:00
TrueCharts BotandGitHub 95153621cd chore(cops): update image lscr.io/linuxserver/cops digest to 592f7d0 (#48495) 2026-05-25 04:51:42 +02:00
TrueCharts BotandGitHub 1e8a38cbbb chore(friendica): update image friendica digest to ef537a8 (#48496)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| friendica | digest | `b10f45f` → `ef537a8` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9mcmllbmRpY2EiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL2RpZ2VzdCJdfQ==-->
2026-05-25 04:51:33 +02:00
TrueCharts BotandGitHub 2a9367ef26 feat(mealie): update image ghcr.io/mealie-recipes/mealie v3.18.0 → v3.19.0 (#48494)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[ghcr.io/mealie-recipes/mealie](https://redirect.github.com/mealie-recipes/mealie)
| minor | `2db8344` → `116555e` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>mealie-recipes/mealie (ghcr.io/mealie-recipes/mealie)</summary>

###
[`v3.19.0`](https://redirect.github.com/mealie-recipes/mealie/releases/tag/v3.19.0)

[Compare
Source](https://redirect.github.com/mealie-recipes/mealie/compare/v3.18.0...v3.19.0)

### 🍴🍴🍴🍴🍴🍴

This release contains important security fixes in the query filter
API. For more information, see:
[#&#8203;7629](https://redirect.github.com/mealie-recipes/mealie/issues/7629)

#### 🎉 Highlights

This release adds more flexible, in-app management of AI providers. You
can now add multiple AI providers for different tasks (e.g. one provider
for general use, and one provider for importing recipes from videos).
These providers can be mixed between completely unrelated services (e.g.
OpenAI, Azure, locally-hosted via Ollama, etc.). <img width="500"
alt="image"
src="https://github.com/user-attachments/assets/e740f213-5045-41f2-84d7-4cc2de81417e"
/>

Existing settings configured via environment variables (e.g.
`OPENAI_API_KEY`) will automatically be imported one time upon upgrading
your instance. For more information, check out [the
PR](https://redirect.github.com/mealie-recipes/mealie/pull/7650) or the
in-app announcement!

####  New features

- feat: In-app AI Provider Configuration
[@&#8203;michael-genson](https://redirect.github.com/michael-genson)
([#&#8203;7650](https://redirect.github.com/mealie-recipes/mealie/issues/7650))

#### 🐛 Bug fixes

- fix: Inconsistent "from an image" vs "from images" translation
[@&#8203;michael-genson](https://redirect.github.com/michael-genson)
([#&#8203;7642](https://redirect.github.com/mealie-recipes/mealie/issues/7642))
- fix: Protect sensitive data in query filter API (GHSA-8m57-7cv5-rjp8)
[@&#8203;michael-genson](https://redirect.github.com/michael-genson)
([#&#8203;7629](https://redirect.github.com/mealie-recipes/mealie/issues/7629))
- fix: enforce organize-group-data permission on food/tag/category
mutations [@&#8203;hay-kot](https://redirect.github.com/hay-kot)
([#&#8203;7651](https://redirect.github.com/mealie-recipes/mealie/issues/7651))
- fix: Prevent swiping AND scrolling on shopping list
[@&#8203;michael-genson](https://redirect.github.com/michael-genson)
([#&#8203;7659](https://redirect.github.com/mealie-recipes/mealie/issues/7659))

#### 🧰 Maintenance

<details>
<summary>6 changes</summary>

- chore(l10n): New Crowdin updates
[@&#8203;hay-kot](https://redirect.github.com/hay-kot)
([#&#8203;7643](https://redirect.github.com/mealie-recipes/mealie/issues/7643))
- chore(l10n): New Crowdin updates
[@&#8203;hay-kot](https://redirect.github.com/hay-kot)
([#&#8203;7646](https://redirect.github.com/mealie-recipes/mealie/issues/7646))
- chore(l10n): New Crowdin updates
[@&#8203;hay-kot](https://redirect.github.com/hay-kot)
([#&#8203;7649](https://redirect.github.com/mealie-recipes/mealie/issues/7649))
- chore(l10n): New Crowdin updates
[@&#8203;hay-kot](https://redirect.github.com/hay-kot)
([#&#8203;7652](https://redirect.github.com/mealie-recipes/mealie/issues/7652))
- chore(l10n): Crowdin locale sync
@&#8203;[mealie-actions\[bot\]](https://redirect.github.com/apps/mealie-actions)
([#&#8203;7655](https://redirect.github.com/mealie-recipes/mealie/issues/7655))
- chore(l10n): New Crowdin updates
[@&#8203;hay-kot](https://redirect.github.com/hay-kot)
([#&#8203;7653](https://redirect.github.com/mealie-recipes/mealie/issues/7653))

</details>

### 🍴🍴🍴🍴🍴🍴

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9tZWFsaWUiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2026-05-24 22:44:26 +02:00
TrueCharts BotandGitHub 5e2cf712c0 chore(lyrion-music-server): update image docker.io/lmscommunity/lyrionmusicserver digest to 3af6bce (#48492)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/lmscommunity/lyrionmusicserver | digest | `8899e80` →
`3af6bce` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9seXJpb24tbXVzaWMtc2VydmVyIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9kaWdlc3QiXX0=-->
2026-05-24 22:43:36 +02:00
TrueCharts BotandGitHub cc778fedb2 chore(dashy): update image ghcr.io/lissy93/dashy digest to ddf8197 (#48491) 2026-05-24 22:43:10 +02:00
TrueCharts BotandGitHub ba449fb4d3 fix(minecraft-bedrock): update image docker.io/itzg/minecraft-bedrock-server 2026.5.2 → 2026.5.3 (#48493)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/itzg/minecraft-bedrock-server](https://redirect.github.com/itzg/docker-minecraft-bedrock-server)
| patch | `ddf6c66` → `d0aa4e6` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>itzg/docker-minecraft-bedrock-server
(docker.io/itzg/minecraft-bedrock-server)</summary>

###
[`v2026.5.3`](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/releases/tag/2026.5.3)

[Compare
Source](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/compare/2026.5.2...2026.5.3)

<!-- Release notes generated using configuration in .github/release.yml
at f6dcda10d5fbb6f5af4be959a3ce39ad8db6aacd -->

#### What's Changed

##### Bug Fixes

- Switch to json metadata provided by kittizz/bedrock-server-downloads
by [@&#8203;itzg](https://redirect.github.com/itzg) in
[#&#8203;638](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/pull/638)

##### Other Changes

- Update dependency itzg/mc-monitor to v0.16.4 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;633](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/pull/633)
- Update dependency itzg/easy-add to v0.8.13 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;634](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/pull/634)
- Update dependency itzg/mc-server-runner to v1.14.7 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;636](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/pull/636)
- Update dependency itzg/mc-monitor to v0.16.5 by
[@&#8203;renovate](https://redirect.github.com/renovate)\[bot] in
[#&#8203;637](https://redirect.github.com/itzg/docker-minecraft-bedrock-server/pull/637)

**Full Changelog**:
<https://github.com/itzg/docker-minecraft-bedrock-server/compare/2026.5.2...2026.5.3>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9taW5lY3JhZnQtYmVkcm9jayIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->
2026-05-24 22:43:06 +02:00
TrueCharts BotandGitHub 0e00dc943c fix(multus-cni): update image docker.io/alpine/crane 0.21.5 → 0.21.6 (#48487)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| docker.io/alpine/crane | patch | `e6b0b53` → `22394f6` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9tdWx0dXMtY25pIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->
2026-05-24 10:19:10 +02:00