chore(deps): update dependency prometheus/prometheus to v3 - #672
renovate[bot] wants to merge 1 commit into
Conversation
5de0d0f to
d20c060
Compare
d20c060 to
95fa5f1
Compare
95fa5f1 to
44197a4
Compare
44197a4 to
57f11ec
Compare
57f11ec to
c5ab24a
Compare
c5ab24a to
691f066
Compare
691f066 to
abe4707
Compare
abe4707 to
f11cb2f
Compare
f11cb2f to
184901c
Compare
184901c to
84a4c13
Compare
84a4c13 to
d8d7958
Compare
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
d1a4f01 to
c031116
Compare
c031116 to
97bc2cb
Compare
97bc2cb to
bba2ea0
Compare
bba2ea0 to
e78ac48
Compare
e78ac48 to
a02450c
Compare
62fc392 to
7514f19
Compare
2b939f4 to
6062762
Compare
6062762 to
fd82558
Compare
fd82558 to
6826ca1
Compare
6826ca1 to
a6cd708
Compare
a6cd708 to
6fae0db
Compare
9ae4a49 to
d5dd4be
Compare
d5dd4be to
32d2244
Compare
32d2244 to
ef5b7f6
Compare
ef5b7f6 to
0bb0d64
Compare
0bb0d64 to
9f15fb9
Compare
9f15fb9 to
288f1b8
Compare
288f1b8 to
37df6a7
Compare
37df6a7 to
db561b7
Compare
db561b7 to
e77f148
Compare
e77f148 to
1f48368
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
1f48368 to
27d932b
Compare
This PR contains the following updates:
v2.49.1→v3.15.0Release Notes
prometheus/prometheus (prometheus/prometheus)
v3.15.0: 3.15.0 / 2026-09-24Compare Source
endwas not aligned tostepcaused subqueries inside it to evaluate past the parent's last actual step, inflatingpeakSamplesin the query stats and against thequery.max-sampleslimit, and wasting storage I/O reading samples that were never used in the result. Add tests to prevent regression of the fix made in #18081. #18598--log.level; useruntime.log_levelconfiguration to supply the default level. #19511runtime.log_levelon configuration reload. #19511--auto-gomemlimit.refresh-intervalflag to periodically re-detect the container or system memory limit and updateGOMEMLIMITat runtime. #18843__meta_docker_container_imageand__meta_docker_container_image_id. #19386--enable-feature=st-storageflag now automatically enables XOR2 float chunk encoding and ST-capable histogram chunk encoding, so you no longer need to passxor2-encodingandhistograms-st-encodingalongside it. #19518session_nameandtagsfields for STS AssumeRole sessions. The previously undocumentedservice_namefield is now also documented. #19569zstd-scrape. #19502--enable-feature=xor2-encodingis deprecated; usestorage.tsdb.chunk_encoding.floats: xor2instead. Check that other software reading the TSDB directly (e.g. Thanos sidecar) supports XOR2 before enabling. #19461prometheus_tsdb_head_appenders_created_totalmetric. #19411_countand_sumseries in scrape appender v2. #19323prometheus_tsdb_head_series_pending_commit_underflow_totalto report pending-sample reservation underflows. #19470request_concurrency. #19506info()enrichment for composite expressions with mixed@/offset references or selector-free vector branches, preventing metadata from being evaluated at an unrelated timestamp. #19387request_concurrencyinstead of hanging service discovery indefinitely. #19524prometheus_sd_last_update_timestamp_secondsseries for a config that is removed on reload. #19131DetectResetno longer misses a counter reset when a populated bucket behind an empty one disappears, which could make histogramrate()/increase()undercount. #19367.*\|(foo)\|.*). #19516anchoredorsmoothedmodifier when the selected series has no samples inside the query window, for example a query evaluated inside a scrape gap. #19431@is used as the matrix argument of a call that is not step-invariant (for examplequantile_over_time(scalar(x), metric[...:...] @ T)). #19187@ start()/@ end()before range selectors, matching the existing rejection of literal offsets and@ <timestamp>. #19406histogram_quantileandhistogram_fraction. #19330firstOOOChunkIDmodulo 2^23 instead of growing unbounded. #19216__meta_kubernetes_service_loadbalancer_ipfromstatus.loadBalancer.ingress, falling back to deprecatedspec.loadBalancerIP. #19404tsdb dumpsilently dropping native histogram samples. #18051Manager.TargetsDroppedCountsto avoid miscounting dropped targets. #19304v3.14.0: 3.14.0 / 2026-08-17Compare Source
statsquery parameter of/api/v1/queryand/api/v1/query_rangefor values other thantrueandall. Other values still enable basic statistics but now return a deprecation warning; they will be rejected in the next major release. #19124/api/v1/status/confignow correctly showsseparator: ""andreplacement: ""in relabel configs when explicitly set to empty, instead of omitting them. #18653__meta_hetzner_datacenterlabel forhcloudtargets, following its removal from the Hetzner Cloud API. #19269promql-duration-exprfeature flag is now a no-op. #19033first_over_timeto stable. It no longer requires thepromql-experimental-functionsfeature flag. #19093oci_sd_configs). #18919start_timestamp(instant-vector)function returning the start timestamp of each sample in the given vector. Requires theuse-start-timestampsfeature flag. #19089rate()andincrease()to use start timestamps as an alternative for rate extrapolation. Hidden behind theuse-start-timestampsfeature flag. #18619histograms-st-encodingfeature flag. #18609k8s.pod.nameandk8s_pod_nameboth becomek8s_pod_name), and expose theprometheus_api_otlp_translation_warnings_totalcounter labelled bycategoryto track such warnings. #18957--remote-write.pathflag topush metricsfor backends that use a non-default remote-write endpoint. #19086prometheus_tsdb_head_native_histogram_seriesandprometheus_tsdb_head_native_histogram_bucketsgauges tracking the number of native histogram series and buckets in the head. #19170step(),range(),min_of(),max_of()) in range selectors and subqueries. #18625{job=~"foo|bar|baz"}). #18833promtool check configfrom making AWS metadata service (IMDS) network calls when theregionfield is omitted in EC2, ECS, RDS, MSK, ElastiCache, and Lightsail service discovery configs. #19037docker_sdanddockerswarm_sdonunix,npipe, andtcphosts. Previously an unresponsive daemon could freeze discovery indefinitely, silently pinning targets to a stale snapshot. #19237mad_over_timereturning 0 instead ofNaNwhen the range contains aNaNsample. #19040--enable-feature=promql-binop-fill-modifiersincheck rules, which previously rejected validfill()/fill_left()/fill_right()expressions. #19153AZURE_FEDERATED_TOKEN_FILEenvironment variable for workload identity authentication instead of hardcoding the token file path. #18973rule_group_last_rule_duration_sum_secondsandrule_group_last_restore_duration_secondsseries when a rule group is removed or renamed on reload. Previously each reload leaked two series per dropped group, growing/metricscardinality over time. #19107stale_series_compaction_thresholdis used in the config file. #19016prometheus_tsdb_head_stale_seriesover-counting and early eviction of series that change between float, integer histogram, and float histogram sample types. #19183--enable-feature=xor2-encodingcould silently revert to XOR after compaction. #19145--web.enable-admin-apiis enabled. #19025v3.13.3: 3.13.3 / 2026-09-07Compare Source
v3.13.2: 3.13.2 / 2026-07-29Compare Source
What's Changed
Full Changelog: prometheus/prometheus@v3.13.1...v3.13.2
v3.13.1: 3.13.1 / 2026-07-10Compare Source
This is a bugfix release for 3.13 LTS.
v3.13.0: 3.13.0 / 2026-07-01Compare Source
This is a Long Term Support LTS release.
sanitize-htmlto fix a cross-site scripting vulnerability (CVE-2026-44990). #18697/assets/third-party-licenses.txt, replacing thenpm_licenses.tar.bz2archive previously shipped in release tarballs and container images. #18997--http.config.fileare now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949min()andmax()duration-expression functions (experimental feature flagexperimental-duration-expr) tomin_of()andmax_of()to avoid confusion with theminandmaxaggregate operators. #18687min_of(a, b)andmax_of(a, b)scalar experimental functions, returning the smaller or larger of two scalar values. #18687samplesRead(andsamplesReadPerStepwithstats=alland thepromql-per-step-statsfeature flag) in the query stats response, and add theprometheus_engine_query_samples_read_totalengine counter.samplesReadreflects storage I/O distinct fromtotalQueryableSamples, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081__convert_classic_histograms_to_nhcb__internal label to allow per-target override ofconvert_classic_histograms_to_nhcbscrape configuration via relabeling. #18840storage.tsdb.chunk_encoding.floatsconfiguration field to select float chunk encoding (xororxor2) at runtime, independently of the--enable-feature=xor2-encodingflag. #18769__always_scrape_classic_histograms__and__scrape_native_histograms__internal labels to allow per-target override of thealways_scrape_classic_histogramsandscrape_native_histogramsscrape configuration via relabeling. #18929fill_left(x) fill_right(x)asfill(x)when both fill values are equal. #18851--enable-feature=created-timestamp-zero-ingestion). #18813endwas not aligned tostepcaused subqueries inside it to evaluate past the parent's last actual step, inflatingpeakSamplesin the query stats and against thequery.max-sampleslimit, and wasting storage I/O reading samples that were never used in the result. #18081@modifier (e.g.predict_linear(metric[60s] @ T, X)) silently under-countedtotalQueryableSamplesfor steps after step 0. #18081fill_left/fill_rightproducing missing samples in range queries when usinggroup_left/group_right. #188501[5m] smoothedand similar expressions when extended range selectors are enabled. #18764smoothedinstant vector selector produces no samples for a series. #18943foo offset -(5)). #18768{}. Via prometheus/common v0.69.0. #18949check healthyandcheck readywhen--urlends with a trailing slash. #18854private_iporpublic_ipfield, but do have private NICs attached. #18772v3.12.0: 3.12.0 / 2026-05-28Compare Source
This release contains security fixes, new features (especially around PromQL and Service Discovery), performance improvements in TSDB, Start Timestamp improvements and numerous bug fixes.
Thanks to all contributors!
Key Highlights
rate(),irate(),increase(), andresets(). New experimental functionsstart(),end(),range(), andstep()are introduced.Changelog
/-/configendpoint. Thanks to @August829 and @Phaxma for reporting. GHSA-39j6-789q-qxvh #18649st-storageflag is enabled. #18221/api/v1/status/self_metricsendpoint returning the current state of the Prometheus server's own metrics about itself as JSON. #18411outscale_sd_configs) for discovering scrape targets from the Outscale Cloud API. #18139sort,sort_by_labelorsort_by_label_descis used within range (matrix) queries, as these functions do not have effect in that context. #18498start(),end(),range(), andstep()experimental functions #17877resets()function to consider start timestamp resets. Hidden behinduse-start-timestampsfeature flag. #18627CheckpointFromInMemorySeriesoption toagent.DBthat enables checkpoint based on in-memory series. #17948rate(),irate(), andincrease()calculations, behind a feature flaguse-start-timestamps. Doesn't work together with extended range selectorsanchoredandsmoothed. #18344st-synthesiswhich synthesizes unknown STs for scraped cumulative metrics. Useful when Remote Writing 2.0 with delta or Otel-based backends. #18279@stannotation inloadblocks to specify per-sample start timestamps. #18360external_idfield to ECS/MSK/RDS/Elasticache. #18579external_idfield. #17171--headerflag toquery instantcommand, matching existingquery rangebehaviour. #18418info()function incorrectly handling negated__name__matchers #17932/parse_ast. #18624health_filterfor Health API filtering, fixing breakage when using Catalog-only fields likeServiceTagsinfilter. #18479 #18499smoothedrate/increase returning zero instead of no result when all data falls strictly after the query range. #18523range()keyword in duration expressions such asfoo[5m+range()]. #18623@modifier is used. #18531prometheus_sd_refresh*andprometheus_sd_discovered_targetsmetrics for specific scrape jobs are deleted when the scrape job is removed. #17614--enable-featureflag description and sort feature names. #18487v3.11.3: 3.11.3 / 2026-04-27Compare Source
This release fixes mutiple security issues.
We would like to thank the following people for the responsible disclosures:
Shadowbyte (4c1dr3aper) - Charlie Lewis for the Remote-Read snappy decode vulnerability.
Brett Gervasoni for the AzureAD OAuth
client_secretvulnerability.@iiihaiii and @Ngocnn97 for the Old UI XSS vulnerability.
[SECURITY] AzureAD remote write: Fix OAuth
client_secretbeing exposed in plaintext via/-/configendpoint. GHSA-wg65-39gg-5wfj / CVE-2026-42151 #18590[SECURITY] Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit. GHSA-8rm2-7qqf-34qm / CVE-2026-42154 #18584
[SECURITY] UI: Fix stored XSS via unescaped
lelabel values in old UI heatmap chart tick labels. GHSA-fw8g-cg8f-9j28 #18588v3.11.2: 3.11.2 / 2026-04-13Compare Source
This release has a fix for a Stored XSS vulnerability that can be triggered via crafted metric names and label values in Prometheus web UI tooltips and metrics explorer. Thanks to Duc Anh Nguyen from TinyxLab for reporting it.
health_filterfield for Health API filtering. #18499v3.11.1: 3.11.1 / 2026-04-07Compare Source
insecure: true. #18469v3.11.0: 3.11.0 / 2026-04-02Compare Source
__meta_hetzner_datacenterlabel is deprecated for the rolerobotbut kept for backward compatibility, use the__meta_hetzner_robot_datacenterlabel instead. For the rolehcloud, the label is deprecated and will stop working after the 1 July 2026. #17850__meta_hetzner_hcloud_datacenter_locationand__meta_hetzner_hcloud_datacenter_location_network_zonelabels are deprecated, use the__meta_hetzner_hcloud_locationand__meta_hetzner_hcloud_location_network_zonelabels instead. #17850prometheus_sd_last_update_timestamp_secondsmetric to track the last time a service discovery update was sent to consumers. #18194__meta_kubernetes_pod_deployment_name,__meta_kubernetes_pod_cronjob_nameand__meta_kubernetes_pod_job_name, respectively. #17774</and>/operators for trimming observations from native histograms. #17904histogram_quantilesvariadic function for computing multiple quantiles at once. #17285storage.tsdb.retention.percentageconfiguration to configure the maximum percent of disk usable for TSDB storage. #18080st-storagefeature flag. When enabled, Prometheus stores ingested start timestamps (ST, previously called Created Timestamp) from scrape or OTLP in the TSDB and Agent WAL, and exposes them via Remote Write 2. [#&Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.