You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[BUGFIX] TSDB: Fix the head-chunk cache returning samples from the wrong chunk, or spurious not-found errors, to range queries after head-chunk truncation. #19134
[SECURITY] UI: Bump sanitize-html to fix a cross-site scripting vulnerability (CVE-2026-44990). #18697
[CHANGE] UI: Third-party npm dependency licenses are now embedded in the Prometheus binary and served at /assets/third-party-licenses.txt, replacing the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images. #18997
[CHANGE] API: Use SHA-256 instead of SHA-1 to generate rule group pagination tokens. #18927
[CHANGE] HTTP clients: Credentials (Authorization header, basic auth, bearer token, OAuth2, configured headers) are no longer forwarded when following a redirect to a different host; affects scraping, remote read/write, alerting, and service discovery. Via prometheus/common v0.69.0 (CVE-2025-4673CVE-2023-45289). #18949
[CHANGE] promtool: Relative file paths in the file passed to --http.config.file are now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949
[CHANGE] PromQL: Rename the min() and max() duration-expression functions (experimental feature flag experimental-duration-expr) to min_of() and max_of() to avoid confusion with the min and max aggregate operators. #18687
[FEATURE] API: Add experimental search endpoints to search metric names, label names, and label values. #18573
[FEATURE] Discovery/AWS: Add ability to filter RDS instances. #18859
[FEATURE] PromQL: Add min_of(a, b) and max_of(a, b) scalar experimental functions, returning the smaller or larger of two scalar values. #18687
[FEATURE] PromQL: Add support for smoothed/anchored rate with native histograms. #18564
[FEATURE] PromQL: Expose per-query samplesRead (and samplesReadPerStep with stats=all and the promql-per-step-stats feature flag) in the query stats response, and add the prometheus_engine_query_samples_read_total engine counter. samplesRead reflects storage I/O distinct from totalQueryableSamples, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081
[FEATURE] Scrape: Add __convert_classic_histograms_to_nhcb__ internal label to allow per-target override of convert_classic_histograms_to_nhcb scrape configuration via relabeling. #18840
[FEATURE] TSDB: Add storage.tsdb.chunk_encoding.floats configuration field to select float chunk encoding (xor or xor2) at runtime, independently of the --enable-feature=xor2-encoding flag. #18769
[FEATURE] remote_write: Add Certificate support for ingesting data into an Azure Monitor Workspace. #18217
[FEATURE] Scrape: Add __always_scrape_classic_histograms__ and __scrape_native_histograms__ internal labels to allow per-target override of the always_scrape_classic_histograms and scrape_native_histograms scrape configuration via relabeling. #18929
[ENHANCEMENT] Release: Container images are now also published to the GitHub Container Registry (ghcr.io). #18791
[ENHANCEMENT] PromQL: Prettify fill_left(x) fill_right(x) as fill(x) when both fill values are equal. #18851
[ENHANCEMENT] UI: Improve autocompletion after closing a function bracket. #18894
[PERF] Labels: Add case-insensitive prefix matching to speed up evaluation of long case-insensitive regular expressions (up to ~2x faster). #18540
[PERF] TSDB: Reduce per-sample overhead in chunk population, speeding up affected queries by ~12-15% in benchmarks. #18699
[PERF] TSDB: Eliminate unnecessary heap allocations in the V2 histogram WAL decoder, reducing allocations by up to 50% and memory by up to 10% for deployments using native histograms with created-timestamp storage enabled (--enable-feature=created-timestamp-zero-ingestion). #18813
[BUGFIX] Discovery/AWS: Fix failure when processing an AWS RDS cluster without instances. #18845
[BUGFIX] Fix race condition in initTime that could cause ErrOutOfBounds. #18629
[BUGFIX] PromQL: A range query whose end was not aligned to step caused subqueries inside it to evaluate past the parent's last actual step, inflating peakSamples in the query stats and against the query.max-samples limit, and wasting storage I/O reading samples that were never used in the result. #18081
[BUGFIX] PromQL: A range query containing an at-modifier-unsafe function over a range-vector with an @ modifier (e.g. predict_linear(metric[60s] @​ T, X)) silently under-counted totalQueryableSamples for steps after step 0. #18081
[BUGFIX] PromQL: Fix fill_left/fill_right producing missing samples in range queries when using group_left/group_right. #18850
[BUGFIX] PromQL: Fix for resets() and changes() in anchored range extenders with histograms. #18906
[BUGFIX] PromQL: Fix panic on 1[5m] smoothed and similar expressions when extended range selectors are enabled. #18764
[BUGFIX] PromQL: Fix panic when a smoothed instant vector selector produces no samples for a series. #18943
[BUGFIX] PromQL: Fix panic when using a parenthesised plain number as an offset (e.g. foo offset -(5)). #18768
[BUGFIX] promtool: Fix panic when parsing exposition text containing empty braces {}. Via prometheus/common v0.69.0. #18949
[BUGFIX] Promtool: Fix check healthy and check ready when --url ends with a trailing slash. #18854
[BUGFIX] Rules: Close PromQL query after each rule evaluation to ensure resources are released. #18733
[BUGFIX] Scaleway SD: Resolve VPC/IPAM-only instances that have no legacy private_ip or public_ip field, but do have private NICs attached. #18772
[BUGFIX] TSDB: Do not leak head series when an integer histogram append is rejected (e.g. out-of-order). #18838
[BUGFIX] UI: Escape label values offered by PromQL autocomplete. #18658
[BUGFIX] TSDB: Fix chunk snapshot encoding for EncXOR2 chunks, preventing corruption on TSDB restart when EncXOR2-encoded series were present. #18739
[BUGFIX] TSDB: Store a millisecond timestamp (not a WAL segment number) in walExpiries when a series is evicted via CompactStaleHead/CompactSelectedSeries, so the series's label record is correctly retained in the next WAL checkpoint and replays cleanly. #18847
[BUGFIX] TSDB: Prevent loss of samples at the chunk-range boundary when CompactSelectedSeries (and CompactStaleHead) evict the series — the per-slice compaction loop now runs one more iteration so the boundary timestamp is captured in a block before the in-memory copy is removed. #18849
Configuration
📅 Schedule: (in timezone America/New_York)
Branch creation
"after 12am and before 2am on monday"
Automerge
At any time (no schedule defined)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
The deployed prom/prometheus container moves from v3.12.0 to the pinned v3.13.1 digest; this is a direct image update in the Prometheus Deployment, with the configuration, persistent volume, Alertmanager, and all other containers unchanged. The target is the first bug-fix release of the 3.13 LTS line.
Performance & Stability
Range-query correctness after head truncation:v3.13.1 fixes the head-chunk cache, which could return samples from the wrong chunk or false not-found errors after truncation. This applies automatically to this deployment's persistent standalone TSDB and range-query consumers.
CVE-2026-44990, CVSS 9.3: The deployed v3.12.0 lock file contains the advisory's exact vulnerable sanitize-html 2.17.3, while v3.13.1 contains patched 2.17.5; this PR therefore resolves the critical xmp sanitizer-bypass XSS rather than merely avoiding a vulnerable intermediate release. The Prometheus UI is exposed through TLS and Authentik, so the fix is relevant and automatic.
CVE-2025-4673, CVSS 6.8: Go net/http could retain proxy authentication headers across cross-origin redirects before Go 1.23.10/1.24.4. Both Prometheus versions are built with Go 1.26, so neither v3.12.0 nor v3.13.1 is affected; the broader prometheus/common cross-host stripping is defense-in-depth for Prometheus-configured credentials, not this PR's remediation of the CVE.
CVE-2023-45289, CVSS 4.3: Go net/http could forward sensitive headers to an incorrectly matched redirect domain before Go 1.21.8/1.22.1. The Go 1.26 builds of both old and proposed Prometheus are outside that range, so this CVE is contextual rather than resolved by the PR. The new Prometheus-level behavior still matters operationally because the checked configuration uses basic-auth and bearer-token scrapes plus Alertmanager.
Authenticated cross-host redirects are an unresolved compatibility boundary:credentials are newly stripped when a redirect changes host. The repository actively configures basic-auth and bearer-token scrapes plus HTTPS Alertmanager, so the changed path is in actual use. Direct hostnames in the file do not prove that those servers never redirect, and CI cannot reach them; any integration that relies on a credentialed cross-host redirect will fail after this update until its target URL or authentication arrangement is corrected. See Further Follow-up for the required pre-merge determination.
Quantify authenticated redirect chains before merge: CI inspection established active basic-auth jobs (blackbox, qbittorrent-api-pod, and qbittorrent-api-ingress), bearer-token jobs (hass, Kubernetes API/node/cAdvisor, MetalLB, and karakeep), and HTTPS Alertmanager in the checked configuration, but it cannot contact those private destinations. From an authorized cluster environment, enumerate every active target through /api/v1/targets, include the configured Alertmanager endpoint, and reproduce each authenticated request with its mounted credential while recording the full redirect chain without printing secret headers—for example, use curl --silent --show-error --location --dump-header <protected-file> --output /dev/null <scrape-or-alertmanager-URL> from a protected administrative shell, then compare the authority (scheme://host:port) of every Location hop and securely delete the header capture. Confirmed same-host/no-redirect chains support changing the verdict to renovate:safe; any relied-upon cross-host hop requires changing the configured URL to the final host or arranging authentication at that host before merge, while an unremediated dependency keeps the update incompatible.
Use renovate:risk until authenticated redirect compatibility is established: v3.13.1 fixes the deployed UI's critical XSS and several TSDB/rule issues, but it also changes authentication behavior on actively used clients, and CI cannot determine whether any private scrape or Alertmanager endpoint relies on cross-host redirects. Confirming no such redirect supports renovate:safe; any relied-upon cross-host redirect must be remediated before merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v3.12.0→v3.13.1Release Notes
prometheus/prometheus (prom/prometheus)
v3.13.1: 3.13.1 / 2026-07-10Compare Source
This is a bugfix release for 3.13 LTS.
v3.13.0: 3.13.0 / 2026-07-01Compare Source
This is a Long Term Support LTS release.
sanitize-htmlto fix a cross-site scripting vulnerability (CVE-2026-44990). #18697/assets/third-party-licenses.txt, replacing thenpm_licenses.tar.bz2archive previously shipped in release tarballs and container images. #18997--http.config.fileare now resolved relative to that config file's directory instead of its parent directory. Via prometheus/common v0.69.0. #18949min()andmax()duration-expression functions (experimental feature flagexperimental-duration-expr) tomin_of()andmax_of()to avoid confusion with theminandmaxaggregate operators. #18687min_of(a, b)andmax_of(a, b)scalar experimental functions, returning the smaller or larger of two scalar values. #18687samplesRead(andsamplesReadPerStepwithstats=alland thepromql-per-step-statsfeature flag) in the query stats response, and add theprometheus_engine_query_samples_read_totalengine counter.samplesReadreflects storage I/O distinct fromtotalQueryableSamples, which counts samples loaded into the evaluator (and so over-counts when a sample is reused across multiple range-vector windows). #18081__convert_classic_histograms_to_nhcb__internal label to allow per-target override ofconvert_classic_histograms_to_nhcbscrape configuration via relabeling. #18840storage.tsdb.chunk_encoding.floatsconfiguration field to select float chunk encoding (xororxor2) at runtime, independently of the--enable-feature=xor2-encodingflag. #18769__always_scrape_classic_histograms__and__scrape_native_histograms__internal labels to allow per-target override of thealways_scrape_classic_histogramsandscrape_native_histogramsscrape configuration via relabeling. #18929fill_left(x) fill_right(x)asfill(x)when both fill values are equal. #18851--enable-feature=created-timestamp-zero-ingestion). #18813endwas not aligned tostepcaused subqueries inside it to evaluate past the parent's last actual step, inflatingpeakSamplesin the query stats and against thequery.max-sampleslimit, and wasting storage I/O reading samples that were never used in the result. #18081@modifier (e.g.predict_linear(metric[60s] @​ T, X)) silently under-countedtotalQueryableSamplesfor steps after step 0. #18081fill_left/fill_rightproducing missing samples in range queries when usinggroup_left/group_right. #188501[5m] smoothedand similar expressions when extended range selectors are enabled. #18764smoothedinstant vector selector produces no samples for a series. #18943foo offset -(5)). #18768{}. Via prometheus/common v0.69.0. #18949check healthyandcheck readywhen--urlends with a trailing slash. #18854private_iporpublic_ipfield, but do have private NICs attached. #18772Configuration
📅 Schedule: (in timezone America/New_York)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.