Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade helm to 3.13.2 #4128

Merged
merged 2 commits into from
Nov 9, 2023
Merged

upgrade helm to 3.13.2 #4128

merged 2 commits into from
Nov 9, 2023

Conversation

cbodonnell
Copy link
Contributor

@cbodonnell cbodonnell commented Nov 9, 2023

What this PR does / why we need it:

This PR upgrades the Helm binary in the kotsadm image to 3.13.2 to resolve some CVEs. It also bumps a few go.mod packages to resolve some other CVEs.

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Steps to reproduce

Does this PR introduce a user-facing change?

* Upgrades the Helm binary in the kotsadm image to 3.13.2 to resolve CVE-2023-39325 and GHSA-m425-mq94-257g with high severity and CVE-2023-44487 and GHSA-jq35-85cj-fj4p with medium severity
* Upgrades the google.golang.org/grpc go module to v1.59.0 to resolve GHSA-m425-mq94-257g with high severity and  CVE-2023-44487 with medium severity
* Upgrades the github.com/docker/docker go module to v24.0.7 to resolve GHSA-jq35-85cj-fj4p with medium severity

Does this PR require documentation?

@cbodonnell cbodonnell merged commit 32fbc64 into main Nov 9, 2023
163 checks passed
@cbodonnell cbodonnell deleted the cbo/resolve-cves branch November 9, 2023 21:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants