Skip to content

Commit 66c139a

Browse files
* bump helm * Adding changelog file to new location * Deleting changelog file from old location * Adding changelog file to new location * Deleting changelog file from old location --------- Co-authored-by: soloio-bulldozer[bot] <48420018+soloio-bulldozer[bot]@users.noreply.github.com> Co-authored-by: changelog-bot <changelog-bot>
1 parent fc25d58 commit 66c139a

File tree

4 files changed

+43
-29
lines changed

4 files changed

+43
-29
lines changed
+8
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
changelog:
2+
- type: DEPENDENCY_BUMP
3+
dependencyOwner: helm.sh
4+
dependencyRepo: helm
5+
dependencyTag: v3.14.2
6+
description: Bump helm to fix CVE-2024-26147
7+
issueLink: https://github.com/solo-io/gloo/issues/9185
8+
resolvesIssue: false

docs/content/static/content/osa_provided.md

+2-2
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ Name|Version|License
4040
[saiskee/gettercheck](https://github.com/saiskee/gettercheck)|v0.0.0-20210820204958-38443d06ebe0|MIT License
4141
[sergi/go-diff](https://github.com/sergi/go-diff)|v1.1.0|MIT License
4242
[spf13/afero](https://github.com/spf13/afero)|v1.9.2|Apache License 2.0
43-
[spf13/cobra](https://github.com/spf13/cobra)|v1.7.0|Apache License 2.0
43+
[spf13/cobra](https://github.com/spf13/cobra)|v1.8.0|Apache License 2.0
4444
[spf13/pflag](https://github.com/spf13/pflag)|v1.0.5|BSD 3-clause "New" or "Revised" License
4545
[spf13/viper](https://github.com/spf13/viper)|v1.8.1|MIT License
4646
[go.opencensus.io](https://go.opencensus.io)|v0.24.0|Apache License 2.0
@@ -56,7 +56,7 @@ Name|Version|License
5656
[google.golang.org/grpc](https://google.golang.org/grpc)|v1.59.0|Apache License 2.0
5757
[google.golang.org/protobuf](https://google.golang.org/protobuf)|v1.32.0|BSD 3-clause "New" or "Revised" License
5858
[AlecAivazis/survey.v1](https://gopkg.in/AlecAivazis/survey.v1)|v1.8.7|MIT License
59-
[helm/v3](https://helm.sh/helm/v3)|v3.13.2|Apache License 2.0
59+
[helm/v3](https://helm.sh/helm/v3)|v3.14.2|Apache License 2.0
6060
[k8s.io/api](https://k8s.io/api)|v0.28.3|Apache License 2.0
6161
[k8s.io/apiextensions-apiserver](https://k8s.io/apiextensions-apiserver)|v0.28.3|Apache License 2.0
6262
[k8s.io/apimachinery](https://k8s.io/apimachinery)|v0.28.3|Apache License 2.0

go.mod

+19-17
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ require (
5858
github.com/solo-io/solo-apis v0.0.0-20231206142556-d2e3ed6d4476
5959
github.com/solo-io/solo-kit v0.34.2
6060
github.com/spf13/afero v1.9.2
61-
github.com/spf13/cobra v1.7.0
61+
github.com/spf13/cobra v1.8.0
6262
github.com/spf13/pflag v1.0.5
6363
github.com/spf13/viper v1.8.1
6464
go.opencensus.io v0.24.0
@@ -72,14 +72,14 @@ require (
7272
google.golang.org/grpc v1.59.0
7373
google.golang.org/protobuf v1.32.0
7474
gopkg.in/AlecAivazis/survey.v1 v1.8.7
75-
helm.sh/helm/v3 v3.13.2
76-
k8s.io/api v0.28.3
77-
k8s.io/apiextensions-apiserver v0.28.3
78-
k8s.io/apimachinery v0.28.3
79-
k8s.io/client-go v0.28.3
75+
helm.sh/helm/v3 v3.14.2
76+
k8s.io/api v0.29.0
77+
k8s.io/apiextensions-apiserver v0.29.0
78+
k8s.io/apimachinery v0.29.0
79+
k8s.io/client-go v0.29.0
8080
k8s.io/code-generator v0.28.3
81-
k8s.io/component-base v0.28.3
82-
k8s.io/kubectl v0.28.3
81+
k8s.io/component-base v0.29.0
82+
k8s.io/kubectl v0.29.0
8383
k8s.io/utils v0.0.0-20230726121419-3b25d923346b
8484
knative.dev/networking v0.0.0-20211210083629-bace06e98aee
8585
knative.dev/pkg v0.0.0-20211206113427-18589ac7627e
@@ -110,7 +110,7 @@ require (
110110
github.com/Masterminds/sprig/v3 v3.2.3 // indirect
111111
github.com/Masterminds/squirrel v1.5.4 // indirect
112112
github.com/Microsoft/go-winio v0.6.1 // indirect
113-
github.com/Microsoft/hcsshim v0.11.0 // indirect
113+
github.com/Microsoft/hcsshim v0.11.4 // indirect
114114
github.com/ProtonMail/go-crypto v0.0.0-20210428141323-04723f9f07d7 // indirect
115115
github.com/acomagu/bufpipe v1.0.3 // indirect
116116
github.com/armon/go-metrics v0.3.11 // indirect
@@ -126,9 +126,9 @@ require (
126126
github.com/chai2010/gettext-go v1.0.2 // indirect
127127
github.com/cockroachdb/apd/v2 v2.0.1 // indirect
128128
github.com/containerd/cgroups v1.1.0 // indirect
129-
github.com/containerd/containerd v1.7.6 // indirect
129+
github.com/containerd/containerd v1.7.11 // indirect
130130
github.com/containerd/continuity v0.4.3 // indirect
131-
github.com/cpuguy83/go-md2man/v2 v2.0.2 // indirect
131+
github.com/cpuguy83/go-md2man/v2 v2.0.3 // indirect
132132
github.com/creack/pty v1.1.18 // indirect
133133
github.com/cyphar/filepath-securejoin v0.2.4 // indirect
134134
github.com/davecgh/go-spew v1.1.1 // indirect
@@ -159,7 +159,7 @@ require (
159159
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
160160
github.com/go-kit/log v0.2.1 // indirect
161161
github.com/go-logfmt/logfmt v0.5.1 // indirect
162-
github.com/go-logr/logr v1.2.4 // indirect
162+
github.com/go-logr/logr v1.3.0 // indirect
163163
github.com/go-openapi/analysis v0.19.5 // indirect
164164
github.com/go-openapi/errors v0.19.2 // indirect
165165
github.com/go-openapi/jsonpointer v0.20.0 // indirect
@@ -303,19 +303,19 @@ require (
303303
gopkg.in/yaml.v2 v2.4.0 // indirect
304304
gopkg.in/yaml.v3 v3.0.1 // indirect
305305
gotest.tools/v3 v3.5.0 // indirect
306-
k8s.io/apiserver v0.28.3 // indirect
307-
k8s.io/cli-runtime v0.28.3 // indirect
306+
k8s.io/apiserver v0.29.0 // indirect
307+
k8s.io/cli-runtime v0.29.0 // indirect
308308
k8s.io/component-helpers v0.28.3 // indirect
309309
k8s.io/gengo v0.0.0-20230829151522-9cce18d56c01 // indirect
310-
k8s.io/klog/v2 v2.100.1 // indirect
310+
k8s.io/klog/v2 v2.110.1 // indirect
311311
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 // indirect
312312
k8s.io/metrics v0.28.3 // indirect
313313
oras.land/oras-go v1.2.4 // indirect
314314
sigs.k8s.io/json v0.0.0-20221116044647-bc3834ca7abd // indirect
315315
sigs.k8s.io/kustomize/api v0.13.5-0.20230601165947-6ce0bf390ce3 // indirect
316316
sigs.k8s.io/kustomize/kustomize/v5 v5.0.4-0.20230601165947-6ce0bf390ce3 // indirect
317317
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 // indirect
318-
sigs.k8s.io/structured-merge-diff/v4 v4.3.0 // indirect
318+
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 // indirect
319319
)
320320

321321
replace (
@@ -343,15 +343,17 @@ replace (
343343
// Required for proper serialization of CRDs
344344
github.com/renstrom/dedent => github.com/lithammer/dedent v1.0.0
345345

346-
// Pin Kube libraries to v0.27
346+
// Pin Kube libraries to v0.28
347347
// These should be upgraded collectively
348348
k8s.io/api => k8s.io/api v0.28.3
349349
k8s.io/apiextensions-apiserver => k8s.io/apiextensions-apiserver v0.28.3
350350
k8s.io/apimachinery => k8s.io/apimachinery v0.28.3
351+
k8s.io/apiserver => k8s.io/apiserver v0.28.3
351352
k8s.io/cli-runtime => k8s.io/cli-runtime v0.28.3
352353
k8s.io/client-go => k8s.io/client-go v0.28.3
353354
k8s.io/code-generator => k8s.io/code-generator v0.28.3
354355
k8s.io/component-base => k8s.io/component-base v0.28.3
356+
k8s.io/component-helpers => k8s.io/component-helpers v0.28.3
355357
// version of kube-openapi used by client-go v0.28.3
356358
k8s.io/kube-openapi => k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00
357359
k8s.io/kubectl => k8s.io/kubectl v0.28.3

go.sum

+14-10
Original file line numberDiff line numberDiff line change
@@ -760,8 +760,8 @@ github.com/Microsoft/go-winio v0.4.14/go.mod h1:qXqCSQ3Xa7+6tgxaGTIe4Kpcdsi+P8jB
760760
github.com/Microsoft/go-winio v0.4.16/go.mod h1:XB6nPKklQyQ7GC9LdcBEcBl8PF76WugXOPRXwdLnMv0=
761761
github.com/Microsoft/go-winio v0.6.1 h1:9/kr64B9VUZrLm5YYwbGtUJnMgqWVOdUAXu6Migciow=
762762
github.com/Microsoft/go-winio v0.6.1/go.mod h1:LRdKpFKfdobln8UmuiYcKPot9D2v6svN5+sAH+4kjUM=
763-
github.com/Microsoft/hcsshim v0.11.0 h1:7EFNIY4igHEXUdj1zXgAyU3fLc7QfOKHbkldRVTBdiM=
764-
github.com/Microsoft/hcsshim v0.11.0/go.mod h1:OEthFdQv/AD2RAdzR6Mm1N1KPCztGKDurW1Z8b8VGMM=
763+
github.com/Microsoft/hcsshim v0.11.4 h1:68vKo2VN8DE9AdN4tnkWnmdhqdbpUFM8OF3Airm7fz8=
764+
github.com/Microsoft/hcsshim v0.11.4/go.mod h1:smjE4dvqPX9Zldna+t5FG3rnoHhaB7QYxPRqGcpAD9w=
765765
github.com/NYTimes/gziphandler v0.0.0-20170623195520-56545f4a5d46/go.mod h1:3wb06e3pkSAbeQ52E9H9iFoQsEEwGN64994WTCIhntQ=
766766
github.com/NYTimes/gziphandler v1.1.1/go.mod h1:n/CVRwUEOgIxrgPvAQhUUr9oeUtvrhMomdKFjzJNB0c=
767767
github.com/Netflix/go-expect v0.0.0-20180615182759-c93bf25de8e8/go.mod h1:oX5x61PbNXchhh0oikYAH+4Pcfw5LKv21+Jnpr6r6Pc=
@@ -921,8 +921,9 @@ github.com/coreos/go-systemd/v22 v22.5.0/go.mod h1:Y58oyj3AT4RCenI/lSvhwexgC+NSV
921921
github.com/coreos/pkg v0.0.0-20180928190104-399ea9e2e55f/go.mod h1:E3G3o1h8I7cfcXa63jLwjI0eiQQMgzzUDFVpN/nH/eA=
922922
github.com/cpuguy83/go-md2man/v2 v2.0.0-20190314233015-f79a8a8ca69d/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU=
923923
github.com/cpuguy83/go-md2man/v2 v2.0.0/go.mod h1:maD7wRr/U5Z6m/iR4s+kqSMx2CaBsrgA7czyZG/E6dU=
924-
github.com/cpuguy83/go-md2man/v2 v2.0.2 h1:p1EgwI/C7NhT0JmVkwCD2ZBK8j4aeHQX2pMHHBfMQ6w=
925924
github.com/cpuguy83/go-md2man/v2 v2.0.2/go.mod h1:tgQtvFlXSQOSOSIRvRPT7W67SCa46tRHOmNcaadrF8o=
925+
github.com/cpuguy83/go-md2man/v2 v2.0.3 h1:qMCsGGgs+MAzDFyp9LpAe1Lqy/fY/qCovCm0qnXZOBM=
926+
github.com/cpuguy83/go-md2man/v2 v2.0.3/go.mod h1:tgQtvFlXSQOSOSIRvRPT7W67SCa46tRHOmNcaadrF8o=
926927
github.com/cratonica/2goarray v0.0.0-20190331194516-514510793eaa h1:Wg+722vs7a2zQH5lR9QWYsVbplKeffaQFIs5FTdfNNo=
927928
github.com/cratonica/2goarray v0.0.0-20190331194516-514510793eaa/go.mod h1:6Arca19mRx58CA7OWEd7Wu1NpC1rd3uDnNs6s1pj/DI=
928929
github.com/creack/pty v1.1.7/go.mod h1:lj5s0c3V2DBrqTV7llrYr5NG6My20zk30Fl46Y7DoTY=
@@ -1087,8 +1088,9 @@ github.com/go-logr/logr v0.2.0/go.mod h1:z6/tIYblkpsD+a4lm/fGIIU9mZ+XfAiaFtq7xTg
10871088
github.com/go-logr/logr v1.2.0/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
10881089
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
10891090
github.com/go-logr/logr v1.2.3/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
1090-
github.com/go-logr/logr v1.2.4 h1:g01GSCwiDw2xSZfjJ2/T9M+S6pFdcNtFYsp+Y43HYDQ=
10911091
github.com/go-logr/logr v1.2.4/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
1092+
github.com/go-logr/logr v1.3.0 h1:2y3SDp0ZXuc6/cjLSZ+Q3ir+QB9T/iG5yYRXqsagWSY=
1093+
github.com/go-logr/logr v1.3.0/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
10921094
github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
10931095
github.com/go-logr/zapr v1.2.3/go.mod h1:eIauM6P8qSvTw5o2ez6UEAfGjQKrxQTl5EoK+Qa2oG4=
10941096
github.com/go-logr/zapr v1.2.4 h1:QHVo+6stLbfJmYGkQ7uGHUCu5hnAFAj6mDe6Ea0SeOo=
@@ -1973,8 +1975,9 @@ github.com/spf13/cast v1.5.0/go.mod h1:SpXXQ5YoyJw6s3/6cMTQuxvgRl3PCJiyaX9p6b155
19731975
github.com/spf13/cobra v1.0.0/go.mod h1:/6GTrnGXV9HjY+aR4k0oJ5tcvakLuG6EuKReYlHNrgE=
19741976
github.com/spf13/cobra v1.1.1/go.mod h1:WnodtKOvamDL/PwE2M4iKs8aMDBZ5Q5klgD3qfVJQMI=
19751977
github.com/spf13/cobra v1.1.3/go.mod h1:pGADOWyqRD/YMrPZigI/zbliZ2wVD/23d+is3pSWzOo=
1976-
github.com/spf13/cobra v1.7.0 h1:hyqWnYt1ZQShIddO5kBpj3vu05/++x6tJ6dg8EC572I=
19771978
github.com/spf13/cobra v1.7.0/go.mod h1:uLxZILRyS/50WlhOIKD7W6V5bgeIt+4sICxh6uRMrb0=
1979+
github.com/spf13/cobra v1.8.0 h1:7aJaZx1B85qltLMc546zn58BxxfZdR/W22ej9CFoEf0=
1980+
github.com/spf13/cobra v1.8.0/go.mod h1:WXLWApfZ71AjXPya3WOlMsY9yMs7YeiHhFVlvLyhcho=
19781981
github.com/spf13/jwalterweatherman v1.0.0/go.mod h1:cQK4TGJAtQXfYWX+Ddv3mKDzgVb68N+wFjFa4jdeBTo=
19791982
github.com/spf13/jwalterweatherman v1.1.0 h1:ue6voC5bR5F8YxI5S67j9i582FU4Qvo2bmqnqMYADFk=
19801983
github.com/spf13/jwalterweatherman v1.1.0/go.mod h1:aNWZUN0dPAAO/Ljvb5BEdw96iTZ0EXowPYD95IqWIGo=
@@ -3024,8 +3027,8 @@ gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
30243027
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
30253028
gotest.tools/v3 v3.5.0 h1:Ljk6PdHdOhAb5aDMWXjDLMMhph+BpztA4v1QdqEW2eY=
30263029
gotest.tools/v3 v3.5.0/go.mod h1:isy3WKz7GK6uNw/sbHzfKBLvlvXwUyV06n6brMxxopU=
3027-
helm.sh/helm/v3 v3.13.2 h1:IcO9NgmmpetJODLZhR3f3q+6zzyXVKlRizKFwbi7K8w=
3028-
helm.sh/helm/v3 v3.13.2/go.mod h1:GIHDwZggaTGbedevTlrQ6DB++LBN6yuQdeGj0HNaDx0=
3030+
helm.sh/helm/v3 v3.14.2 h1:V71fv+NGZv0icBlr+in1MJXuUIHCiPG1hW9gEBISTIA=
3031+
helm.sh/helm/v3 v3.14.2/go.mod h1:2itvvDv2WSZXTllknfQo6j7u3VVgMAvm8POCDgYH424=
30293032
honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
30303033
honnef.co/go/tools v0.0.0-20190106161140-3f1c8253044a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
30313034
honnef.co/go/tools v0.0.0-20190418001031-e561f6794a2a/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4=
@@ -3060,8 +3063,9 @@ k8s.io/klog v1.0.0/go.mod h1:4Bi6QPql/J/LkTDqv7R/cd3hPo4k2DG6Ptcz060Ez5I=
30603063
k8s.io/klog/v2 v2.0.0/go.mod h1:PBfzABfn139FHAV07az/IF9Wp1bkk3vpT2XSJ76fSDE=
30613064
k8s.io/klog/v2 v2.2.0/go.mod h1:Od+F08eJP+W3HUb4pSrPpgp9DGU4GzlpG/TmITuYh/Y=
30623065
k8s.io/klog/v2 v2.80.1/go.mod h1:y1WjHnz7Dj687irZUWR/WLkLc5N1YHtjLdmgWjndZn0=
3063-
k8s.io/klog/v2 v2.100.1 h1:7WCHKK6K8fNhTqfBhISHQ97KrnJNFZMcQvKp7gP/tmg=
30643066
k8s.io/klog/v2 v2.100.1/go.mod h1:y1WjHnz7Dj687irZUWR/WLkLc5N1YHtjLdmgWjndZn0=
3067+
k8s.io/klog/v2 v2.110.1 h1:U/Af64HJf7FcwMcXyKm2RPM22WZzyR7OSpYj5tg3cL0=
3068+
k8s.io/klog/v2 v2.110.1/go.mod h1:YGtd1984u+GgbuZ7e08/yBuAfKLSO0+uR1Fhi6ExXjo=
30653069
k8s.io/kms v0.28.3/go.mod h1:kSMjU2tg7vjqqoWVVCcmPmNZ/CofPsoTbSxAipCvZuE=
30663070
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00 h1:aVUu9fTY98ivBPKR9Y5w/AuzbMm96cd3YHRTU83I780=
30673071
k8s.io/kube-openapi v0.0.0-20231010175941-2dd684a91f00/go.mod h1:AsvuZPBlUDVuCdzJ87iajxtXuR9oktsTctW/R9wwouA=
@@ -3149,8 +3153,8 @@ sigs.k8s.io/kustomize/kustomize/v5 v5.0.4-0.20230601165947-6ce0bf390ce3/go.mod h
31493153
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3 h1:W6cLQc5pnqM7vh3b7HvGNfXrJ/xL6BDMS0v1V/HHg5U=
31503154
sigs.k8s.io/kustomize/kyaml v0.14.3-0.20230601165947-6ce0bf390ce3/go.mod h1:JWP1Fj0VWGHyw3YUPjXSQnRnrwezrZSrApfX5S0nIag=
31513155
sigs.k8s.io/structured-merge-diff/v4 v4.2.3/go.mod h1:qjx8mGObPmV2aSZepjQjbmb2ihdVs8cGKBraizNC69E=
3152-
sigs.k8s.io/structured-merge-diff/v4 v4.3.0 h1:UZbZAZfX0wV2zr7YZorDz6GXROfDFj6LvqCRm4VUVKk=
3153-
sigs.k8s.io/structured-merge-diff/v4 v4.3.0/go.mod h1:N8hJocpFajUSSeSJ9bOZ77VzejKZaXsTtZo4/u7Io08=
3156+
sigs.k8s.io/structured-merge-diff/v4 v4.4.1 h1:150L+0vs/8DA78h1u02ooW1/fFq/Lwr+sGiqlzvrtq4=
3157+
sigs.k8s.io/structured-merge-diff/v4 v4.4.1/go.mod h1:N8hJocpFajUSSeSJ9bOZ77VzejKZaXsTtZo4/u7Io08=
31543158
sigs.k8s.io/yaml v1.2.0/go.mod h1:yfXDCHCao9+ENCvLSE62v9VSji2MKu5jeNfTrofGhJc=
31553159
sigs.k8s.io/yaml v1.3.0/go.mod h1:GeOyir5tyXNByN85N/dRIT9es5UQNerPYEKK56eTBm8=
31563160
sigs.k8s.io/yaml v1.4.0 h1:Mk1wCc2gy/F0THH0TAp1QYyJNzRm2KCLy3o5ASXVI5E=

0 commit comments

Comments
 (0)