Skip to content

Commit 56511e2

Browse files
authored
Update helm and related dependencies (#590)
Addresses the following reported vulnerabilities identified by dependabot. CVE-2026-35206 GHSA-hr2v-4r36-88hr Adjusts test code to address deprecations in functions identified by golangci-lint as a result of the dependency upgrade. Signed-off-by: Jose R. Gonzalez <komish@flutes.dev>
1 parent 4aa87c6 commit 56511e2

3 files changed

Lines changed: 137 additions & 168 deletions

File tree

go.mod

Lines changed: 29 additions & 34 deletions
Original file line numberDiff line numberDiff line change
@@ -16,16 +16,16 @@ require (
1616
github.com/stretchr/testify v1.11.1
1717
golang.org/x/mod v0.35.0
1818
gopkg.in/yaml.v3 v3.0.1
19-
helm.sh/helm/v3 v3.18.6
20-
k8s.io/api v0.33.3
21-
k8s.io/apimachinery v0.33.3
22-
k8s.io/client-go v0.33.3
23-
k8s.io/kubectl v0.33.3
19+
helm.sh/helm/v3 v3.20.2
20+
k8s.io/api v0.35.1
21+
k8s.io/apimachinery v0.35.1
22+
k8s.io/client-go v0.35.1
23+
k8s.io/kubectl v0.35.1
2424
)
2525

2626
require (
2727
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
28-
github.com/BurntSushi/toml v1.5.0 // indirect
28+
github.com/BurntSushi/toml v1.6.0 // indirect
2929
github.com/MakeNowJust/heredoc v1.0.0 // indirect
3030
github.com/Masterminds/goutils v1.1.1 // indirect
3131
github.com/Masterminds/semver/v3 v3.4.0 // indirect
@@ -34,18 +34,18 @@ require (
3434
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
3535
github.com/blang/semver/v4 v4.0.0 // indirect
3636
github.com/chai2010/gettext-go v1.0.2 // indirect
37-
github.com/containerd/containerd v1.7.29 // indirect
37+
github.com/containerd/containerd v1.7.30 // indirect
3838
github.com/containerd/errdefs v0.3.0 // indirect
3939
github.com/containerd/log v0.1.0 // indirect
4040
github.com/containerd/platforms v0.2.1 // indirect
41-
github.com/cyphar/filepath-securejoin v0.4.1 // indirect
41+
github.com/cyphar/filepath-securejoin v0.6.1 // indirect
4242
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
43-
github.com/emicklei/go-restful/v3 v3.11.0 // indirect
43+
github.com/emicklei/go-restful/v3 v3.12.2 // indirect
4444
github.com/evanphx/json-patch v5.9.11+incompatible // indirect
4545
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
4646
github.com/fatih/color v1.16.0 // indirect
4747
github.com/fsnotify/fsnotify v1.9.0 // indirect
48-
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
48+
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
4949
github.com/go-errors/errors v1.4.2 // indirect
5050
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
5151
github.com/go-logr/logr v1.4.3 // indirect
@@ -54,11 +54,8 @@ require (
5454
github.com/go-openapi/swag v0.23.0 // indirect
5555
github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
5656
github.com/gobwas/glob v0.2.3 // indirect
57-
github.com/gogo/protobuf v1.3.2 // indirect
5857
github.com/google/btree v1.1.3 // indirect
59-
github.com/google/gnostic-models v0.6.9 // indirect
60-
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
61-
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
58+
github.com/google/gnostic-models v0.7.0 // indirect
6259
github.com/gosuri/uitable v0.0.4 // indirect
6360
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
6461
github.com/hashicorp/errwrap v1.1.0 // indirect
@@ -83,20 +80,18 @@ require (
8380
github.com/mitchellh/copystructure v1.2.0 // indirect
8481
github.com/mitchellh/go-wordwrap v1.0.1 // indirect
8582
github.com/mitchellh/reflectwalk v1.0.2 // indirect
86-
github.com/moby/spdystream v0.5.0 // indirect
8783
github.com/moby/term v0.5.2 // indirect
8884
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
89-
github.com/modern-go/reflect2 v1.0.2 // indirect
85+
github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect
9086
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
9187
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
92-
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
9388
github.com/opencontainers/go-digest v1.0.0 // indirect
9489
github.com/opencontainers/image-spec v1.1.1 // indirect
9590
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
9691
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
9792
github.com/pkg/errors v0.9.1 // indirect
9893
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
99-
github.com/rubenv/sql-migrate v1.8.0 // indirect
94+
github.com/rubenv/sql-migrate v1.8.1 // indirect
10095
github.com/russross/blackfriday/v2 v2.1.0 // indirect
10196
github.com/sagikazarmark/locafero v0.11.0 // indirect
10297
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
@@ -109,34 +104,34 @@ require (
109104
github.com/subosito/gotenv v1.6.0 // indirect
110105
github.com/x448/float16 v0.8.4 // indirect
111106
github.com/xlab/treeprint v1.2.0 // indirect
112-
go.yaml.in/yaml/v2 v2.4.2 // indirect
107+
go.yaml.in/yaml/v2 v2.4.3 // indirect
113108
go.yaml.in/yaml/v3 v3.0.4 // indirect
114109
golang.org/x/crypto v0.46.0 // indirect
115110
golang.org/x/net v0.48.0 // indirect
116111
golang.org/x/oauth2 v0.34.0 // indirect
117112
golang.org/x/sync v0.19.0 // indirect
118-
golang.org/x/sys v0.39.0 // indirect
119-
golang.org/x/term v0.38.0 // indirect
120-
golang.org/x/text v0.32.0 // indirect
113+
golang.org/x/sys v0.40.0 // indirect
114+
golang.org/x/term v0.39.0 // indirect
115+
golang.org/x/text v0.33.0 // indirect
121116
golang.org/x/time v0.12.0 // indirect
122117
google.golang.org/genproto/googleapis/rpc v0.0.0-20251202230838-ff82c1b0f217 // indirect
123118
google.golang.org/grpc v1.79.3 // indirect
124119
google.golang.org/protobuf v1.36.10 // indirect
125-
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
120+
gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
126121
gopkg.in/inf.v0 v0.9.1 // indirect
127122
gopkg.in/yaml.v2 v2.4.0 // indirect
128-
k8s.io/apiextensions-apiserver v0.33.3 // indirect
129-
k8s.io/apiserver v0.33.3 // indirect
130-
k8s.io/cli-runtime v0.33.3 // indirect
131-
k8s.io/component-base v0.33.3 // indirect
123+
k8s.io/apiextensions-apiserver v0.35.1 // indirect
124+
k8s.io/apiserver v0.35.1 // indirect
125+
k8s.io/cli-runtime v0.35.1 // indirect
126+
k8s.io/component-base v0.35.1 // indirect
132127
k8s.io/klog/v2 v2.130.1 // indirect
133-
k8s.io/kube-openapi v0.0.0-20250318190949-c8a335a9a2ff // indirect
134-
k8s.io/utils v0.0.0-20241104100929-3ea5e8cea738 // indirect
128+
k8s.io/kube-openapi v0.0.0-20250910181357-589584f1c912 // indirect
129+
k8s.io/utils v0.0.0-20251002143259-bc988d571ff4 // indirect
135130
oras.land/oras-go/v2 v2.6.0 // indirect
136-
sigs.k8s.io/json v0.0.0-20241010143419-9aa6b5e7a4b3 // indirect
137-
sigs.k8s.io/kustomize/api v0.19.0 // indirect
138-
sigs.k8s.io/kustomize/kyaml v0.19.0 // indirect
131+
sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
132+
sigs.k8s.io/kustomize/api v0.20.1 // indirect
133+
sigs.k8s.io/kustomize/kyaml v0.20.1 // indirect
139134
sigs.k8s.io/randfill v1.0.0 // indirect
140-
sigs.k8s.io/structured-merge-diff/v4 v4.6.0 // indirect
141-
sigs.k8s.io/yaml v1.5.0 // indirect
135+
sigs.k8s.io/structured-merge-diff/v6 v6.3.0 // indirect
136+
sigs.k8s.io/yaml v1.6.0 // indirect
142137
)

0 commit comments

Comments
 (0)