Skip to content

fix(deps): update dependencies causing vulnerabilities [ICNS-2292]#64

Merged
fyousfi-ionos merged 2 commits into
mainfrom
fix-security-issue+
Jul 17, 2025
Merged

fix(deps): update dependencies causing vulnerabilities [ICNS-2292]#64
fyousfi-ionos merged 2 commits into
mainfrom
fix-security-issue+

Conversation

@fyousfi-ionos

@fyousfi-ionos fyousfi-ionos commented Jul 17, 2025

Copy link
Copy Markdown
Contributor

This pull request includes a minor version update for the helm.sh/helm/v3 dependency in the go.mod file. The version has been updated from v3.17.3 to v3.17.4.

We cannot update to the latest version (3.18.4) currently, because it requires updating other dependencies, and those other dependencies are not yet supported by github.com/cert-manager/cert-manager
But this should achieve the goal of fixing the vulnerability https://github.com/ionos-cloud/cert-manager-webhook-ionos-cloud/security/dependabot/13

Also this updates github.com/go-viper/mapstructure/v2 as it fixes https://github.com/ionos-cloud/cert-manager-webhook-ionos-cloud/security/dependabot/11

@fyousfi-ionos fyousfi-ionos changed the title fix(deps): update dependency [ICNS-2292] fix(deps): update helm.sh/helm/v3 [ICNS-2292] Jul 17, 2025
@fyousfi-ionos fyousfi-ionos changed the title fix(deps): update helm.sh/helm/v3 [ICNS-2292] fix(deps): update helm.sh/helm/v3 to fix vulnerability [ICNS-2292] Jul 17, 2025
@fyousfi-ionos fyousfi-ionos changed the title fix(deps): update helm.sh/helm/v3 to fix vulnerability [ICNS-2292] fix(deps): update dependencies causing vulnerabilities [ICNS-2292] Jul 17, 2025

@akrieg-ionos akrieg-ionos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, also good background info in the description

@fyousfi-ionos
fyousfi-ionos merged commit 79387c4 into main Jul 17, 2025
4 checks passed
@fyousfi-ionos
fyousfi-ionos deleted the fix-security-issue+ branch July 17, 2025 09:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants