Skip to content

chore(deps): update apache/apisix docker tag to v3.18.0 - #606

Open
renovate[bot] wants to merge 2 commits into
devfrom
deps/apache-apisix-3.x
Open

chore(deps): update apache/apisix docker tag to v3.18.0#606
renovate[bot] wants to merge 2 commits into
devfrom
deps/apache-apisix-3.x

Conversation

@renovate

@renovate renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
apache/apisix minor 3.17.0-debian3.18.0-debian

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the 🗡️ dependencies Pull requests that update a dependency file label Aug 21, 2026
@renovate
renovate Bot requested a review from wax911 August 21, 2026 11:38
@anitrend

anitrend Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

OpenCode Dependabot Risk Review

Schema: local-stack.dependabot-risk.v1

Decision: NEUTRAL
Risk: UNKNOWN
Automerge allowed: false
Update type: semver-minor
Ecosystem: docker

Summary

Renovate bot proposes a minor bump of apache/apisix from 3.17.0-debian to 3.18.0-debian in apisix/api-gateway/docker-compose.yml. The change is limited to the expected dependency file and no workflow, secret, stack, or deployment files are modified. However, apisix is a gateway/proxy service flagged for breaking config risk and is stateful (etcd), and no release notes are available to confirm the minor update is non-breaking. Additionally, the committed generated stack (stacks/infrastructure.yml) still pins 3.17.0-debian, so this source-only change introduces drift that must be reconciled.

Changed runtime artifacts

Image / dependency From To Risk note
apache/apisix 3.17.0-debian 3.18.0-debian minor update to a gateway/proxy service with breaking config risk; release notes not available to confirm no breaking config migration

Runtime impact

Expected rolling service update of the apisix gateway; however, generated stack drift (stacks/infrastructure.yml still at 3.17.0-debian) means the deployed stack would not reflect this change until regenerated.

Breaking change assessment

Unable to confirm. No release notes for apache/apisix 3.18.0 were available; as a gateway/proxy service with breaking config risk, a minor bump cannot be assumed non-breaking without release-note verification.

Required checks

  • ./stackctl.sh sync
  • ./stackctl.sh up --dry-run --no-logs

Manual follow-up

  • Verify apache/apisix 3.18.0 release notes for breaking config/migration changes before merge
  • Regenerate the committed stack (stackctl generate) so stacks/infrastructure.yml matches the updated compose source and avoids drift

Sources checked

  • Dependabot metadata
  • PR diff
  • PR title/body/labels

@anitrend

anitrend Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

OpenCode risk gate: neutral. Manual review required. Risk: unknown. Reason: Renovate bot proposes a minor bump of apache/apisix from 3.17.0-debian to 3.18.0-debian in apisix/api-gateway/docker-compose.yml. The change is limited to the expected dependency file and no workflow, secret, stack, or deployment files are modified. However, apisix is a gateway/proxy service flagged for breaking config risk and is stateful (etcd), and no release notes are available to confirm the minor update is non-breaking. Additionally, the committed generated stack (stacks/infrastructure.yml) still pins 3.17.0-debian, so this source-only change introduces drift that must be reconciled.

@renovate

renovate Bot commented Aug 21, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🗡️ dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants