-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed #94
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
February 23, 2024 07:40
c3d6f92
to
4647d3c
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.1 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Feb 23, 2024
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
Mar 5, 2024
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Mar 6, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
March 6, 2024 05:20
4647d3c
to
3281913
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
Mar 6, 2024
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Mar 7, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
March 7, 2024 06:47
3281913
to
482de08
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
Mar 7, 2024
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Mar 8, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
March 8, 2024 06:34
482de08
to
7560155
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
Mar 8, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 16, 2024 05:11
3b3ebb7
to
4931393
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 16, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 16, 2024 17:42
4931393
to
9040eab
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
Apr 16, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 17, 2024 08:11
9040eab
to
60bfcfc
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 17, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 19, 2024 18:37
60bfcfc
to
3164064
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
Apr 19, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 21, 2024 08:46
3164064
to
4144400
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 21, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 21, 2024 19:38
4144400
to
6526884
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
Apr 21, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 23, 2024 06:24
6526884
to
be9d40f
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 23, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 24, 2024 08:39
be9d40f
to
d5329b4
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
Apr 24, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 26, 2024 05:17
d5329b4
to
b1327ff
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 26, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 27, 2024 20:26
b1327ff
to
a42495e
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
Apr 27, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 28, 2024 05:12
a42495e
to
448f597
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 28, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 28, 2024 17:25
448f597
to
74dc708
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
Apr 28, 2024
renovate
bot
force-pushed
the
renovate/go-helm.sh/helm/v3-vulnerability
branch
from
April 29, 2024 08:55
74dc708
to
8e44212
Compare
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.4 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
Apr 29, 2024
renovate
bot
changed the title
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security]
chore(deps): update module helm.sh/helm/v3 to v3.14.2 [security] - autoclosed
Apr 29, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v3.11.3
->v3.14.2
GitHub Vulnerability Alerts
CVE-2024-25620
A Helm contributor discovered a path traversal vulnerability when Helm saves a chart including at download time.
Impact
When either the Helm client or SDK is used to save a chart whose name within the
Chart.yaml
file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the relative path. The validation and linting did not detect the path changes in the name.Patches
This issue has been resolved in Helm v3.14.1.
Workarounds
Check all charts used by Helm for path changes in their name as found in the
Chart.yaml
file. This includes dependencies.Credits
Disclosed by Dominykas Blyžė at Nearform Ltd.
CVE-2024-26147
A Helm contributor discovered uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content.
Impact
When either an
index.yaml
file or a pluginsplugin.yaml
file were missing all metadata a panic would occur in Helm.In the Helm SDK this is found when using the
LoadIndexFile
orDownloadIndexFile
functions in therepo
package or theLoadDir
function in theplugin
package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation.Patches
This issue has been resolved in Helm v3.14.2.
Workarounds
If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem.
If using Helm SDK versions prior to 3.14.2, calls to affected functions can use
recover
to catch the panic.For more information
Helm's security policy is spelled out in detail in our SECURITY document.
Credits
Disclosed by Jakub Ciolek at AlphaSense.
Path traversal in helm.sh/helm/v3
BIT-helm-2024-25620 / CVE-2024-25620 / GHSA-v53g-5gjp-272r / GO-2024-2554
More information
Details
Path traversal in helm.sh/helm/v3
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Helm dependency management path traversal
BIT-helm-2024-25620 / CVE-2024-25620 / GHSA-v53g-5gjp-272r / GO-2024-2554
More information
Details
A Helm contributor discovered a path traversal vulnerability when Helm saves a chart including at download time.
Impact
When either the Helm client or SDK is used to save a chart whose name within the
Chart.yaml
file includes a relative path change, the chart would be saved outside its expected directory based on the changes in the relative path. The validation and linting did not detect the path changes in the name.Patches
This issue has been resolved in Helm v3.14.1.
Workarounds
Check all charts used by Helm for path changes in their name as found in the
Chart.yaml
file. This includes dependencies.Credits
Disclosed by Dominykas Blyžė at Nearform Ltd.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Helm shows secrets in clear text
CVE-2019-25210 / GHSA-jw44-4f3j-q396
More information
Details
An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm. It displays values of secrets when the --dry-run flag is used. This is a security concern in some use cases, such as a --dry-run call by a CI/CD tool. NOTE: the vendor's position is that this behavior was introduced intentionally, and cannot be removed without breaking backwards compatibility (some users may be relying on these values).
Severity
Moderate
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Helm's Missing YAML Content Leads To Panic
BIT-helm-2024-26147 / CVE-2024-26147 / GHSA-r53h-jv2g-vpx6
More information
Details
A Helm contributor discovered uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content.
Impact
When either an
index.yaml
file or a pluginsplugin.yaml
file were missing all metadata a panic would occur in Helm.In the Helm SDK this is found when using the
LoadIndexFile
orDownloadIndexFile
functions in therepo
package or theLoadDir
function in theplugin
package. For the Helm client this impacts functions around adding a repository and all Helm functions if a malicious plugin is added as Helm inspects all known plugins on each invocation.Patches
This issue has been resolved in Helm v3.14.2.
Workarounds
If a malicious plugin has been added which is causing all Helm client commands to panic, the malicious plugin can be manually removed from the filesystem.
If using Helm SDK versions prior to 3.14.2, calls to affected functions can use
recover
to catch the panic.For more information
Helm's security policy is spelled out in detail in our SECURITY document.
Credits
Disclosed by Jakub Ciolek at AlphaSense.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
helm/helm (helm.sh/helm/v3)
v3.14.2
: Helm v3.14.2Compare Source
Helm v3.14.2 is a security (patch) release. Users are strongly recommended to update to this release.
A Helm contributor discovered uninitialized variable vulnerability when Helm parses index and plugin yaml files missing expected content.
Jakub Ciolek with AlphaSense discovered the vulnerability.
Installation and Upgrading
Download Helm v3.14.2. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
v3.14.1
: Helm v3.14.1Compare Source
Helm v3.14.1 is a security (patch) release. Users are strongly recommended to update to this release.
A Helm contributor discovered a path traversal vulnerability when Helm saves a chart including at download time.
Dominykas Blyžė with Nearform Ltd. discovered the vulnerability.
Installation and Upgrading
Download Helm v3.14.1. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
v3.14.0
: Helm v3.14.0Compare Source
Helm v3.14.0 is a feature release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Notable Changes
helm search
flag of--fail-on-no-result
tpl
invocation access todefines
tpl
function--kube-version
tolint
commandignore
pkg is now publicInstallation and Upgrading
Download Helm v3.14.0. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
3fc9f4b
(George Jenkins)69dcc92
(Matt Farina)c042264
(Matt Farina)6e5332e
(Joe Julian)869c1d2
(Antoine Deschênes)847369c
(Matt Farina)08ea59c
(dependabot[bot])30e1a2c
(dependabot[bot])803cf2d
(Matt Farina)a997de1
(Marcin Owsiany)ignore
pkg public again5586760
(Ismail Alidzhikov)b3cb20a
(dependabot[bot])e5fff68
(Matt Farina)bfec4ec
(Marcin Owsiany)70c1519
(dependabot[bot])be10183
(dependabot[bot])015e174
(Matt Farina)2a211bf
(dependabot[bot])ce87ece
(Sean Mills)3cb6b06
(dependabot[bot])42c5af2
(dependabot[bot])312a073
(lixin18)8814bfb
(Marcin Chojnacki)c54e39a
(dependabot[bot])d6e9197
(dependabot[bot])9f0313e
(Denis Policastro)24e2864
(Matt Farina)c5fe7dd
(dependabot[bot])992dc58
(Matt Farina)81362d9
(Marcel Humburg)6d1f6cd
(dependabot[bot])372ccca
(dependabot[bot])a1a21ae
(dependabot[bot])250f0bd
(Dmitry Chepurovskiy)0ec47f8
(Dmitry Chepurovskiy)f94e5db
(Ian Zink)b0d1637
(Serge Logvinov)544cabb
(dependabot[bot])25371e2
(Matt Farina)919bffe
(genofire)e6d9b99
(Dmitry Chepurovskiy)e219c75
(Dmitry Chepurovskiy)f004d42
(b4nks)9d3d17a
(Ian Zink)828763e
(Lars Zimmermann)fe4c01f
(Hidde Beydals)da3c666
(Hidde Beydals)21ea847
(Ian Zink)415af5b
(Andy Smith)102e931
(dependabot[bot])2505592
(dependabot[bot])c372b15
(Matt Farina)8b0a78c
(dependabot[bot])58ccfc0
(dependabot[bot])0619d08
(Ian Zink)4199be8
(abrarcv170)0403305
(Antony Chazapis)GoFish
from package managers for installing the binarya9377f9
(y-yagi)tpl
invocation access todefines
in a containing one"b261a1b
(Graham Reed)tpl
"36d417d
(Graham Reed)1a3e9a9
(Stefan McShane)786707c
(Antony Chazapis)6a4035a
(Daniel Strobusch)95905f1
(Graham Reed)fa067ec
(Mathias Neerup)f28447c
(Mathias Neerup)b9cece6
(Bhargav Ravuri)141fa4a
(muang0)4cb62d1
(muang0)dbb21fc
(muang0)fcc0332
(muang0)a1a1aaf
(muang0)fa025fc
(zak905)tpl
invocation access todefines
in a containing onea7d3fd6
(Graham Reed)e2a7c79
(Graham Reed)tpl
db4f330
(Graham Reed)d008340
(James Oden)4f99c86
(James Oden)d94c509
(James Oden)a9d59f9
(Quentin Devos)v3.13.3
: Helm v3.13.3Compare Source
Helm v3.13.3 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.13.3. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
c8b9489
(Matt Farina)2f03d01
(Sean Mills)2e63576
(genofire)v3.13.2
: Helm v3.13.2Compare Source
Helm v3.13.2 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.13.2. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
2a2fb3b
(dependabot[bot])8f554be
(Marcel Humburg)00a334c
(dependabot[bot])12826e8
(Marcin Chojnacki)666b199
(Dmitry Chepurovskiy)7e0084a
(Dmitry Chepurovskiy)10018ff
(Dmitry Chepurovskiy)3b4cacf
(Dmitry Chepurovskiy)e785e6c
(Matt Farina)268dced
(Matt Farina)99ce118
(dependabot[bot])28f208c
(Ian Zink)v3.13.1
: Helm v3.13.1Compare Source
Helm v3.13.1 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.13.1. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
3547a4b
(Matt Farina)6f9ad87
(Ian Zink)bae7b32
(Lars Zimmermann)06e4fb1
(Hidde Beydals)0e7ec78
(b4nks)0ac7894
(Hidde Beydals)0901269
(Ian Zink)6101393
(Ian Zink)c99a8ac
(dependabot[bot])52a029d
(abrarcv170)ff8e61d
(dependabot[bot])v3.13.0
: Helm v3.13.0Compare Source
Helm v3.13.0 is a feature release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Notable Changes
--dry-run
flag now has multiple options which can enable Helm to connect to a Kubernetes instance. The default, when--dry-run
is used, is unchanged.--plain-http
flaghelm get metadata
command--json
flag when creating it. JSON is faster to parse and uses less memory which impacts larger files. This is backwards compatible as Helm, all the way back to 3.0.0, parsing can handle JSON content in the index.yaml file.Installation and Upgrading
Download Helm v3.13.0. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
825e86f
(Matt Farina)169561a
(Michał Słapek)417040d
(dependabot[bot])610217f
(dependabot[bot])c2ab954
(Matt Farina)b9fd7f5
(dependabot[bot])ca3a05e
(Joe Julian)04ec71a
(Joe Julian)ebb3168
(dependabot[bot])fa45978
(dependabot[bot])e01731d
(ithrael)4944acb
(Maxim Trofimov)6138e10
(Maxim Trofimov)199784f
(Maxim Trofimov)b786cb4
(Maxim Trofimov)df5904d
(Maxim Trofimov)fa89665
(dependabot[bot])4283b2c
(dependabot[bot])d82cc90
(dependabot[bot])479be0c
(Tim Chaplin)4e5e68d
(Bingtan Lu)3c26d65
(dependabot[bot])ee1cbed
(ithrael)0eb3df6
(ithrael)0688046
(ithrael)db9460c
(ithrael)817e646
(dependabot[bot])758dc01
(Ian Zink)04850dc
(dependabot[bot])2011a31
(0xff-dev)bf543d9
(guoguangwu)3607cd7
(Antonio Gamez Diaz)197d1de
(Antonio Gamez Diaz)5b08985
(satoru)48dbda2
(suzaku)aab4c45
(dependabot[bot])c3a4122
(dependabot[bot])5c7a631
(MR ZHAO)helm get metadata
command0b5e9d3
(Mikhail Kopylov)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.