WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: upgrade helm.sh/helm/v3 to v3.17.4 to address security vulnerabilities (#1555)
This commit upgrades the Helm dependency from v3.17.1 to v3.17.4 to fix
multiple security vulnerabilities identified by Trivy security scanning:
- CVE-2025-53547 (HIGH): Helm Chart Code Execution
- CVE-2025-32386 (MEDIUM): Helm Allows A Specially Crafted Chart Archive
- CVE-2025-32387 (MEDIUM): Helm Allows A Specially Crafted JSON Schema
The Helm upgrade requires bumping Kubernetes client packages from v0.32.1
to v0.32.2 (patch version) as transitive dependencies. These are backward
compatible updates with no breaking changes.
Note: CVE-2025-55198 and CVE-2025-55199 remain present as they require
Helm v3.18.5, which would necessitate a K8s minor version upgrade.
Fixes: dapr/dapr#9086
Co-authored-by: @cursoragent
Signed-off-by: inishchith <[email protected]>
0 commit comments