Update quay.io/argoproj/argocd Docker tag to v3.5.0 - #293
Open
vshn-renovate wants to merge 1 commit into
Open
Conversation
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
May 6, 2026 08:28
9d142a1 to
7df9454
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
2 times, most recently
from
May 6, 2026 09:49
7df9454 to
126459f
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
2 times, most recently
from
May 12, 2026 21:27
34f5349 to
b47a18c
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
May 28, 2026 12:11
b47a18c to
0c4955a
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
May 28, 2026 12:30
0c4955a to
34d125a
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
June 18, 2026 09:30
34d125a to
42f7d62
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
June 18, 2026 09:49
42f7d62 to
c57967b
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
July 9, 2026 16:50
c57967b to
ebd20a9
Compare
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
August 3, 2026 08:10
ebd20a9 to
acf8c1a
Compare
Signed-off-by: Renovate Bot <tech+renovate@vshn.ch>
vshn-renovate
force-pushed
the
commodore-renovate/quay.io-argoproj-argocd-3.x
branch
from
August 4, 2026 08:28
acf8c1a to
c0753d9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v3.3.12→v3.5.0Release Notes
argoproj/argo-cd (quay.io/argoproj/argocd)
v3.5.0Compare Source
Quick Start
Non-HA:
HA:
Release Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Release Notes Blog Post
For a detailed breakdown of the key changes and improvements in this release, check out the official blog post
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Features
be19446: feat(Jitter): Add Configurable Jitter for Webhook-Triggered application Refreshes (#25433) (@adityaraj178)5b30739: feat(appset): add concurrency when managing applications (#26642) (@rumstead)29fd8db: feat(appset): filtering repos by archived status #20736 (#21505) (@prune998)57942ce: feat(cli): Add support for Source Integrity configuration (#26997) (@olivergondza)3cc6ba7: feat(cli): add --app-namespace flag to missing argocd app subcommands (#27942) (@Mangaal)0e729cc: feat(cli): add appset-namespace for appset command (#27022) (@Mangaal)744983b: feat(health): Add healthcheck for gardener "Shoot" resources (#25750) (@Sven1410)6cc786d: feat(health): add GatewayClass health check (#26591) (@dnfwlq8054)eabd4d6: feat(health): add pause and unpause actions to psmdb resource (#27616) (@KyriosGN0)daadf86: feat(health): additional promoter.argoproj.io health checks (#27170) (@crenshaw-dev)4b69a7f: feat(health): finalizer messages for Promoter checks (#27478) (@crenshaw-dev)289a4c0: feat(health): support BackendTLSPolicy.gateway.networking.k8s.io (#27385) (@snorwin)4cdc650: feat(helm): support wildcard glob patterns forvalueFiles(#26768) (@nitishfy)f7a7deb: feat(hydrator): dynamically manage README template from argocd-cm ConfigMap [updated] (#19067) (#24309) (@gyu-young-park)86936e2: feat(hydrator): make manifest hydration queue concurrency configurable (#27926) (#27948) (@GuruduGanesh)2308e17: feat(hydrator): opt-in source integrity verification for dry sources (Alpha) (#19302) (#28084) (@mladjan-gadzic)bf1591d: feat(hydrator): support syncSource repoURL for separate destination repo (#27011) (@boostrack)41b6fee: feat(impersonation): allow to disable strict enforcement (#27084) (cherry-pick #27573 for 3.5) (#28595) (@argo-cd-cherry-pick-bot[bot])0c0140c: feat(metrics): add parallelism limit repo server (#27911) (@pjiang-dev)7d2eb77: feat(renovate): clean up config and remove github app (#27738) (@rumstead)153ec67: feat(resource_customizations): add health checks for VictoriaMetrics (#27451) (@megative)6b84ea9: feat(server): drop objects from non-allowed namespaces before they enter the cache. (#28018) (@christianh814)224b75a: feat(server): use typed Argo CD EventList for event-listing APIs (#25767) (#26322) (@chansuke)64a0417: feat(ui): Add AppSet to Application Resource Tree (#26601) (@pjiang-dev)b035a77: feat(ui): ApplicationSet Preview Apps tab in UI (#27799) (@pjiang-dev)566c172: feat(ui): add GitOps Promoter resource icon (#26894) (@crenshaw-dev)0dd8874: feat(ui): add nauth.io resource icon (#28226) (@choufraise)f16d08a: feat(ui): add repo url as filter in home page (#26670) (#27418) (@adityaraj178)91e7664: feat(ui): per-application notice banner and info icon (#14405) (#27719) (@gdsoumya)1b405ce: feat(ui): search filter by target revision (#24038) (@choejwoo)706a037: feat(ui): support creating multi-source applications in New App panel[CONTINUED..](#27095) (@aali309)2fcf104: feat(ui): support spec.sourceHydrator.drySource.repoURL (@crenshaw-dev)74d1fe0: feat(ui): use toggle-auto-sync resource action in app details page (#21564) (#27226) (@shiiyan)db7d672: feat(webhooks): add webhook support for GHCR (#26462) (@nitishfy)6d92e17: feat: Add ProvideClusterInfo and Config fields to ExecProviderConfig (#24282) (#27976) (@mikeshng)022f935: feat: Add basic support for git tag path prefixes (#27290) (@k4r1)aad3422: feat: Add suspend/resume actions for MariaDB (#27675) (#27674) (@mgross2)586430c: feat: Migrate from Helm 3 to Helm 4 (#28076) (@reggie-k)c61c1dc: feat: Render Helm ValuesObject as YAML in log output instead of binary (#18342) (#27649) (@subhramit)9a19735: feat: Support Azure Service Principal authentication for Azure DevOps repositories (#25324) (@allanyung)97082e8: feat: add Gateway API support to network view (#26188) (@tete17)603c900: feat: add action to delete recyclable Numaflow pipelines (#25900) (@dpadhiar)de94161: feat: add action to restart StrimziPodSet (#27266) (@KyriosGN0)a2b91ce: feat: add depth option to ui (#26618) (@blakepettersson)1dc2ad0: feat: add health check for karpenter.sh/NodeClaim (#26876) (@Navneet072300)611fcb0: feat: add sync overrun option to sync windows (#25361) (#25510) (@puskunalis)48f18e2: feat: add toggle-auto-sync resource action for Application (#21564) (#26477) (@vikasrao23)2df5f75: feat: adds mTLS support in repo-server (#26715) (@ppapapetrou76)4d02fc2: feat: expose Appset UI and fix pie chart summary (#26666) (@pjiang-dev)a889f46: feat: make appset proxy-url param a native flag (#27788) (@ppapapetrou76)ad310c2: feat: replace error message in webhook handler with metrics (#27215) (@alexmt)01187d1: feat: support Azure AD groups claims overflow via Microsoft Graph API (#27397) (@gravufo)f71239c: feat: support destinationServiceAccounts in global projects (#23059) (@enneitex)f460a3c: feat: surface root cause in sync failure message and cache discovery errors (#27750) (@ppapapetrou76)3eebbcb: feat: use impersonation for server operations (logs, delete, etc) #22996 (#26898) (@alexymantha)Bug fixes
b982144: Revert "fix: prevent automatic refreshes from informer resync and status updates" (#27562) (@agaudreault)c5d1c91: fix(UI): show RollingSync step clearly when labels match no step (#26877) (@aali309)c52bf66: fix(appcontroller): application controller in core mode fails to sync when server.secretkey is missing (#26793) (@anandf)e81969f: fix(applicationset): include repo URL in git file generator errors (#28075) (@morning-verlu)e4fe7f6: fix(appset): don't release finalizer while children still terminate (cherry-pick #28999 for 3.5) (#29006) (@argo-cd-cherry-pick-bot[bot])06fae9d: fix(appset): fall back to create when patch returns NotFound (#17312) (cherry-pick #28645 for 3.5) (#28716) (@argo-cd-cherry-pick-bot[bot])45a84df: fix(ci): add .gitkeep to images dir (#26892) (@blakepettersson)4c42071: fix(ci): openssf scorecard doesn't allow global vars (#27203) (@crenshaw-dev)36f4ff7: fix(ci): pin goreman version used in ci-build.yaml (#27062) (#27061) (@dudinea)25b3037: fix(ci): pnpm sbom generation (#27337) (#27339) (@crenshaw-dev)99c51df: fix(ci): renovatebot action uses floating image tag (#27023) (#27024) (@dudinea)fb82b16: fix(ci): run yarn install with --frozen-lockfile (#27098) (#27099) (@dudinea)b403f5c: fix(cli): hide unsupported --tls-server-name kubectl REST flag (#27694) (#27711) (@SAY-5)60b878d: fix(cli): hide unsupported kubectl REST flags (#25875) (#25977) (@HyejunKoo)21fe1fb: fix(cli): honor --kube-context when creating core-mode REST config (#12883) (#27661) (@ystkfujii)52f7b3b: fix(cli): print clear timeout message when argocd app wait times out (#28274) (@pncloud)f48091a: fix(cli): return immediately from 'app wait' when app is already in desired state (#12211) (#27503) (@jheyduk)6256abf: fix(cli): uses DrySource revision for app diff/manifests with sourceHydrator (#23817) (#24670) (@adityaraj178)c3c12c1: fix(commitserver): Static analysis fixes (#27085) (@olivergondza)5a20f9b: fix(controller): gracefully handle k8s resource size limit for applications (#27802) (@nitishfy)32f23a4: fix(controller): reduce secret deepcopies and deserialization (#27049) (@rumstead)4051511: fix(controller): replace removed kubectl PodRequestsAndLimits (#27895) (@mfacenet)5ec0603: fix(controller): requeue source hydration on periodic refresh timeout (#27009) (@boostrack)a62624a: fix(diff): don't drop manager-owned descendant fields when filtering webhook mutations (cherry-pick #28819 for 3.5) (#28895) (@argo-cd-cherry-pick-bot[bot])e960635: fix(docs): Fix formatting and clarity about requestedScopes in Keycloak integration docs (#27019) (@todaywasawesome)d449294: fix(docs): Fix manifest path in Source Hydrator docs (#27123) (@olivergondza)2f48cfb: fix(docs): revert bogus 3.3-3.4 upgrade guide changes in #26322 (@dudinea)c2044db: fix(health): PromotionStrategy stuck Progressing after no-op re-hydration (#28124) (#28125) (@crenshaw-dev)9c67c89: fix(health): add missing HPA degraded states for metric failures (#26274) (@rickbrouwer)0b42a6d: fix(helm): pass registry passwords through stdin (Cherry-Pick) (#28834) (@nitishfy)ae10c0c: fix(hook): Fixed hook code issues that caused stuck applications on "Deleting" state (Issues #18355 and #17191) (#26724) (@nikos445)4d2b6fa: fix(hydrator): align dry source validation cache keys with hydrator (#27182) (@agaudreault)8c29202: fix(hydrator): fix race condition in status update with hydrate annotation (#27183) (@agaudreault)f298f45: fix(hydrator): preserve all source type fields in GetDrySource() (#27189) (@agaudreault)f73e136: fix(lint): unnecessary nesting (#27815) (@crenshaw-dev)6a0457a: fix(makefile): Run goals with bind mounts on SELinux enabled host (build-ui,build-docs,serve-docs) (#28003) (@olivergondza)7fa7d82: fix(normalizers): include resource context in failed normalization log (#27769) (@rafaelmfried)d0810e3: fix(oidc_userinfo): allow userInfo URL to be customized (#27720) (@the-technat)87d79f9: fix(performance): add cache support for ResolveRevision to reduce Git operations (#27193) (@agaudreault)5c1b930: fix(progressivesync): check if error == notfound (cherry-pick #28663 for 3.5) (#28670) (@argo-cd-cherry-pick-bot[bot])4f47dd0: fix(rbac): resolve RBAC regression for project-scoped resources in multi-namespace architecture (#25289) (#26573) (@tcfwbper)3b60b5e: fix(reposerver): honor depth of referenced source instead of primary source (cherry-pick #28339 for 3.5) (#28340) (@alexandresavicki)f397bf6: fix(server): Avoid error when attempting a second delete operation (#27495) (@thomastaylor312)382c507: fix(server): Cache glob patterns to improve RBAC evaluation performance (#25759) (@Sinhyeok)4259f46: fix(server): Ensure OIDC config is refreshed at server restart (#26913) (@OpenGuidou)91d83d3: fix(server): fix find container logic for terminal (#26858) (@linghaoSu)d6b2be8: fix(server): make server.glob.cache.size optional (#28242) (#28243) (@crenshaw-dev)1dd9075: fix(settings): only trigger reload for app.kubernetes.io/part-of=argocd secrets (#27213) (@EronWright)212f51d: fix(sharding): fix log format verb and document intentional shard-0 fallback (#27222) (@nitishfy)8feb146: fix(ssa): do not run auth reconcile with SSA (#26175) (#27601) (@agaudreault)134b428: fix(ssd): regression causing diff to error on new objects (#27679) (#27703) (@agaudreault)63a009e: fix(test): make fail message better for TestAuthReconcileWithMissingNamespace (#26856) (@cjcocokrisp)abf7311: fix(ui): Application Summary crashes on load for non-hydrator apps (#28112) (@agaudreault)b4af746: fix(ui): ApplicationSet detail view for non-default namespace (#27928) (#27931) (@AsifAd)25df43d: fix(ui): Improve message on self-healing disabling panel (#26977) (#26978) (@bebosudo)30efe53: fix(ui): OCI revision metadata never renders due to conflicting guard clause (#26948) (#27097) (@karimzakzouk)30ab5b5: fix(ui): adapt new applicationset icon test to react-testing-library (@jwinters01)993533a: fix(ui): add icon for view.promoter.argoproj.io API group (#28246) (#28247) (@crenshaw-dev)1bd0d48: fix(ui): add truncation and tooltip for long sync status branch names (#27260) (@choejwoo)a5012a0: fix(ui): add url origin to return_url (#27733) (@Sumis34)f6ade14: fix(ui): app/appset size of ResourceIcon (#28141) (@agaudreault)0c80d13: fix(ui): avoid mutating toolbar input in AddAuthToToolbar (@jwinters01)8206eb9: fix(ui): contain settings textareas within panel width (#27943) (@choejwoo)d1d0e5d: fix(ui): don't prefetch errors (#27877) (#27925) (@blakepettersson)4fbe92a: fix(ui): guard against undefined groupName in project role groups edit (@jwinters01)8e2571f: fix(ui): handle 401 error in stream (#26917) (@linghaoSu)2653f25: fix(ui): include Deleting and Terminated apps in Syncing operation filter (#27874) (@choejwoo)4b4bbc8: fix(ui): include _-prefixed dirs in embedded assets (#26589) (@choejwoo)9a05e0e: fix(ui): placate sonar with adding compare function for repo path sort autocomplete (#26906) (@reggie-k)5453172: fix(ui): prevent pod logs viewer crash on stale container index (#27553) (@youhonglian)b6a715c: fix(ui): prevent wide gaps in grouped resource tree (#25747) (@choejwoo)566c622: fix(ui): reduce loaded application data on list operation (Relates [#15509]) (#25451) (@aveuiller)3c889f4: fix(ui): regenerate pnpm-lock.yaml against public npm registry (@jwinters01)a39953d: fix(ui): remove auto-sync toggle from app top bar (#27868) (@shiiyan)b1db1b1: fix(ui): restore public registry tarball URLs in pnpm-lock.yaml (@jwinters01)fc821b8: fix(ui): restore token diff highlighting in resource diff view (@jwinters01)26621ad: fix(ui): return full source for non-hydrator apps in Parameters tab (#26946) (@himeshp)45b926d: fix(ui): show clear-all button for annotation-only filters (#26937) (@choejwoo)bc5d359: fix(ui): update cluster count logic in ApplicationsSummary (cherry-pick #28768 for 3.5) (#28777) (@argo-cd-cherry-pick-bot[bot])9fb0c8c: fix(ui): wrap component in AppContextReact.Provider (#28131) (@blakepettersson)3e01594: fix(ui):ArgoCD UI Displays Layouts Before Login Page (#25463) (@aali309)68cbd05: fix: Add X-Frame-Options and CSP headers to Swagger UI endpoints (#26521) (@rohansood10)0aa8c41: fix: ApplicationSet DuckType Generator panics on non-string values in Clus… (#27265) (@xiangjingli)d011b7b: fix: Bitbucket webhook diffstat does not work with upper case repo slug (#26594) (@Mangaal)4535a1f: fix: Don't mark CRD degraded while 'Installing' (#26126) (@kbweave)c70acd5: fix: GetRefSources populates refSources for multi source app with a single source (#27787) (@reggie-k)cd2255a: fix: GnuPG keys listed with unicode characters mangled (#27591) (@olivergondza)269e0b8: fix: Hook resources not created at PostSync when configured with PreDelete PostDelete hooks (#26996) (@reggie-k)422ef23: fix: Revert "fix: avoid calling UpdateRevisionForPaths unnecessary (#25151)" (#27241) (@alexmt)69e6f94: fix: Subscription health check when installplanapproval is set to manual (#25923) (@mbaldessari)3cbae65: fix: Update checkPermissions to not exit the namespace loop after the first namespace regardless (#23855) (#24735) (@andrii-korotkov)5fa6fd3: fix: Watch APIServices like we do CRDs (cherry-pick #28289 for 3.5) (#28320) (@argo-cd-cherry-pick-bot[bot])5d039f8: fix: add a lock on clusterinformer (cherry-pick #28216 for 3.5) (#28311) (@argo-cd-cherry-pick-bot[bot])62670d6: fix: address SSD applier nil pointer in error cases (#27126) (@leoluz)ab27dd3: fix: address nil pointer when SSD returns error (@leoluz)8569aad: fix: arch less ui build (#28180) (@blakepettersson)9a5c6b7: fix: auto-sync skipped when newer commit arrives during sync with manifest-generate-paths (#27875) (cherry-pick #28227 for 3.5) (#28332) (@argo-cd-cherry-pick-bot[bot])92c3ef2: fix: avoid scanning symlinks in whole repo on each app manifest operation (#26718) (@alexmt)21615be: fix: avoid stale informer cache in RevisionMetadata handler (#27392) (@gdsoumya)c3b498c: fix: cancel log stream goroutines on client disconnect (#27243) (@alexmt)e684b7e: fix: clean up orphaned temp packfiles left by an interrupted git fetch (#18831) (#28083) (@lexfrei)8981a5b: fix: controller incorrectly detecting diff during app normalization (#27002) (@alexmt)aa3269e: fix: correct grammar and capitalization in CLI help text (#27637) (@Rishmish94)bc04869: fix: deleted resource are incorrectly shown in UI (cherry-pick #28322 for 3.5) (#28335) (@argo-cd-cherry-pick-bot[bot])54fa590: fix: don't clobber non-ignored fields on "replace" (cherry-pick #27136 for 3.5) (#28505) (@argo-cd-cherry-pick-bot[bot])e0e827d: fix: downgrade DiffFromCache log level for cache-miss errors (#26185) (@cp319391)6bb2027: fix: exclude live status from normalization (#28201) (@blakepettersson)bec3925: fix: fix failure on Sync of resources that do not fit into last-applied-configuration (#28421) (cherry-pick #28440 for 3.5) (#28523) (@argo-cd-cherry-pick-bot[bot])a5e6a2e: fix: fixes a regression of dex config env vars substituion - Cherry pick of #28369 in 3.5 (#28409) (@ppapapetrou76)3ede508: fix: fixes a regression of wif for google cloud repos (#27883) (@ppapapetrou76)985f6f5: fix: fixes parsing of dex passwords with dollar sign (#28027) (@ppapapetrou76)1042e12: fix: force attempt http2 with custom tls config (#26975) (#26976) ([@maxverbeek](https://redirect.github.com/ma