Skip to content
This repository was archived by the owner on Feb 16, 2024. It is now read-only.

Commit 7fcf40f

Browse files
Bump helm.sh/helm/v3 from 3.10.1 to 3.10.3 (#191)
Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.10.1 to 3.10.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/helm/helm/releases">helm.sh/helm/v3's releases</a>.</em></p> <blockquote> <h2>Helm v3.10.3</h2> <h2>v3.10.3</h2> <p>Helm v3.10.3 is a security (patch) release. Users are strongly recommended to update to this release.</p> <p>While fuzz testing Helm, provided by the CNCF:</p> <ul> <li>a possible stack overflow was discovered with the <em>strvals</em> package. Stack overflow cannot be recovered from in Go. This can potentially be used to produce a denial of service (DOS) for SDK users. More details are available in <a href="https://github.com/helm/helm/security/advisories/GHSA-6rx9-889q-vv2r">the advisory</a>.</li> <li>a possible segmentation violation was discovered with the <em>repo</em> package. Some segmentation violations cannot be recovered from in Go. This can potentially be used to produce a denial of service (DOS) for SDK users. More details are available in <a href="https://github.com/helm/helm/security/advisories/GHSA-53c4-hhmh-vw5q">the advisory</a>.</li> <li>a possible segmentation violation was discovered with the <em>chartutil</em> package. This can potentially be used to produce a denial of service (DOS) for SDK users. More details are available in <a href="https://github.com/helm/helm/security/advisories/GHSA-67fx-wx78-jx33">the advisory</a></li> </ul> <p>The community keeps growing, and we'd love to see you there!</p> <ul> <li>Join the discussion in <a href="https://kubernetes.slack.com">Kubernetes Slack</a>: <ul> <li>for questions and just to hang out</li> <li>for discussing PRs, code, and bugs</li> </ul> </li> <li>Hang out at the Public Developer Call: Thursday, 9:30 Pacific via <a href="https://zoom.us/j/696660622">Zoom</a></li> <li>Test, debug, and contribute charts: <a href="https://artifacthub.io/packages/search?kind=0">ArtifactHub/packages</a></li> </ul> <h2>Installation and Upgrading</h2> <p>Download Helm v3.10.3. The common platform binaries are here:</p> <ul> <li><a href="https://get.helm.sh/helm-v3.10.3-darwin-amd64.tar.gz">MacOS amd64</a> (<a href="https://get.helm.sh/helm-v3.10.3-darwin-amd64.tar.gz.sha256sum">checksum</a> / 77a94ebd37eab4d14aceaf30a372348917830358430fcd7e09761eed69f08be5)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-darwin-arm64.tar.gz">MacOS arm64</a> (<a href="https://get.helm.sh/helm-v3.10.3-darwin-arm64.tar.gz.sha256sum">checksum</a> / 4f3490654349d6fee8d4055862efdaaf9422eca1ffd2a15393394fd948ae3377)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-linux-amd64.tar.gz">Linux amd64</a> (<a href="https://get.helm.sh/helm-v3.10.3-linux-amd64.tar.gz.sha256sum">checksum</a> / 950439759ece902157cf915b209b8d694e6f675eaab5099fb7894f30eeaee9a2)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-linux-arm.tar.gz">Linux arm</a> (<a href="https://get.helm.sh/helm-v3.10.3-linux-arm.tar.gz.sha256sum">checksum</a> / dca718eb68c72c51fc7157c4c2ebc8ce7ac79b95fc9355c5427ded99e913ec4c)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-linux-arm64.tar.gz">Linux arm64</a> (<a href="https://get.helm.sh/helm-v3.10.3-linux-arm64.tar.gz.sha256sum">checksum</a> / 260cda5ff2ed5d01dd0fd6e7e09bc80126e00d8bdc55f3269d05129e32f6f99d)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-linux-386.tar.gz">Linux i386</a> (<a href="https://get.helm.sh/helm-v3.10.3-linux-386.tar.gz.sha256sum">checksum</a> / 592e98a492cb782aa7cd67e9afad76e51cd68f5160367600fe542c2d96aa0ad4)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-linux-ppc64le.tar.gz">Linux ppc64le</a> (<a href="https://get.helm.sh/helm-v3.10.3-linux-ppc64le.tar.gz.sha256sum">checksum</a> / 93cdf398abc68e388d1b46d49d8e1197544930ecd3e81cc58d0a87a4579d60ed)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-linux-s390x.tar.gz">Linux s390x</a> (<a href="https://get.helm.sh/helm-v3.10.3-linux-s390x.tar.gz.sha256sum">checksum</a> / 6cfa0b9078221f980ef400dc40c95eb71be81d14fdf247ca55efedb068e1d4fa)</li> <li><a href="https://get.helm.sh/helm-v3.10.3-windows-amd64.zip">Windows amd64</a> (<a href="https://get.helm.sh/helm-v3.10.3-windows-amd64.zip.sha256sum">checksum</a> / 5d97aa26830c1cd6c520815255882f148040587fd7cdddb61ef66e4c081566e0)</li> </ul> <p>This release was signed with <code>F126 1BDE 9290 12C8 FF2E 501D 6EA5 D759 8529 A53E </code> and can be found at <a href="https://github.com/hickeyma"><code>@​hickeyma</code></a> <a href="https://keybase.io/hickeyma">keybase account</a>. Please use the attached signatures for verifying this release using <code>gpg</code>.</p> <p>The <a href="https://helm.sh/docs/intro/quickstart/">Quickstart Guide</a> will get you going from there. For <strong>upgrade instructions</strong> or detailed installation notes, check the <a href="https://helm.sh/docs/intro/install/">install guide</a>. You can also use a <a href="https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3">script to install</a> on any system with <code>bash</code>.</p> <h2>What's Next</h2> <ul> <li>3.11.0 is the next feature release and will be on January 18, 2023.</li> </ul> <h2>Changelog</h2> <ul> <li>Fix backwards compatibility 835b7334cfe2e5e27870ab3ed4135f136eecc704 (Martin Hickey)</li> <li>Update string handling 3caf8b586b47e838e492f9ec05396bf8c5851b92 (Martin Hickey)</li> <li>Update repo handling 7c0e203529d4b9d51c5fe57c9e0bd9df1bd95ab4 (Martin Hickey)</li> <li>Update schema validation handling f4b93226c6066e009a5162d0b08debbf3d82a67f (Martin Hickey)</li> </ul> <p>Helm v3.10.2 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/helm/helm/commit/835b7334cfe2e5e27870ab3ed4135f136eecc704"><code>835b733</code></a> Fix backwards compatibility</li> <li><a href="https://github.com/helm/helm/commit/3caf8b586b47e838e492f9ec05396bf8c5851b92"><code>3caf8b5</code></a> Update string handling</li> <li><a href="https://github.com/helm/helm/commit/7c0e203529d4b9d51c5fe57c9e0bd9df1bd95ab4"><code>7c0e203</code></a> Update repo handling</li> <li><a href="https://github.com/helm/helm/commit/f4b93226c6066e009a5162d0b08debbf3d82a67f"><code>f4b9322</code></a> Update schema validation handling</li> <li><a href="https://github.com/helm/helm/commit/50f003e5ee8704ec937a756c646870227d7c8b58"><code>50f003e</code></a> fix a few function names on comments</li> <li><a href="https://github.com/helm/helm/commit/c3a62f7880be8bdc904f2d54c4b0c16a86ec204c"><code>c3a62f7</code></a> redirect registry client output to stderr</li> <li><a href="https://github.com/helm/helm/commit/727bdf1813df73073d5a8eba4581201ef6518f93"><code>727bdf1</code></a> Readiness &amp; liveness probes correct port</li> <li>See full diff in <a href="https://github.com/helm/helm/compare/v3.10.1...v3.10.3">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=helm.sh/helm/v3&package-manager=go_modules&previous-version=3.10.1&new-version=3.10.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/stackabletech/stackablectl/network/alerts). </details>
1 parent e2e58c0 commit 7fcf40f

File tree

2 files changed

+50
-1193
lines changed

2 files changed

+50
-1193
lines changed

go.mod

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,11 @@ go 1.19
44

55
require (
66
github.com/mittwald/go-helm-client v0.11.5
7-
helm.sh/helm/v3 v3.10.1
7+
helm.sh/helm/v3 v3.10.3
88
k8s.io/client-go v0.25.3
99
)
1010

1111
require (
12-
cloud.google.com/go v0.102.1 // indirect
1312
cloud.google.com/go/compute v1.10.0 // indirect
1413
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
1514
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
@@ -24,8 +23,6 @@ require (
2423
github.com/Masterminds/semver/v3 v3.1.1 // indirect
2524
github.com/Masterminds/sprig/v3 v3.2.2 // indirect
2625
github.com/Masterminds/squirrel v1.5.3 // indirect
27-
github.com/PuerkitoBio/purell v1.1.1 // indirect
28-
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
2926
github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d // indirect
3027
github.com/beorn7/perks v1.0.1 // indirect
3128
github.com/cespare/xxhash/v2 v2.1.2 // indirect
@@ -60,7 +57,6 @@ require (
6057
github.com/google/gofuzz v1.2.0 // indirect
6158
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
6259
github.com/google/uuid v1.3.0 // indirect
63-
github.com/googleapis/gnostic v0.5.5 // indirect
6460
github.com/gorilla/mux v1.8.0 // indirect
6561
github.com/gosuri/uitable v0.0.4 // indirect
6662
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
@@ -95,7 +91,6 @@ require (
9591
github.com/opencontainers/image-spec v1.1.0-rc2 // indirect
9692
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
9793
github.com/pkg/errors v0.9.1 // indirect
98-
github.com/pmezard/go-difflib v1.0.0 // indirect
9994
github.com/prometheus/client_golang v1.13.0 // indirect
10095
github.com/prometheus/client_model v0.3.0 // indirect
10196
github.com/prometheus/common v0.37.0 // indirect
@@ -108,7 +103,6 @@ require (
108103
github.com/spf13/cast v1.5.0 // indirect
109104
github.com/spf13/cobra v1.6.0 // indirect
110105
github.com/spf13/pflag v1.0.5 // indirect
111-
github.com/stretchr/testify v1.8.0 // indirect
112106
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
113107
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
114108
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
@@ -127,7 +121,6 @@ require (
127121
google.golang.org/genproto v0.0.0-20221018160656-63c7b68cfc55 // indirect
128122
google.golang.org/grpc v1.50.1 // indirect
129123
google.golang.org/protobuf v1.28.1 // indirect
130-
gopkg.in/gorp.v1 v1.7.2 // indirect
131124
gopkg.in/inf.v0 v0.9.1 // indirect
132125
gopkg.in/yaml.v2 v2.4.0 // indirect
133126
gopkg.in/yaml.v3 v3.0.1 // indirect

0 commit comments

Comments
 (0)