Security update for helm
| Announcement ID: | SUSE-SU-2025:20278-1 |
|---|---|
| Release Date: | 2025-04-22T13:48:50Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves five vulnerabilities can now be installed.
Description:
This update for helm fixes the following issues:
-
Update to version 3.17.2 (bsc#1238688, CVE-2025-22870):
-
Updating to 0.37.0 for x/net
-
build(deps): bump the k8s-io group with 7 updates
-
Update to version 3.17.1:
-
merge null child chart objects
- build(deps): bump the k8s-io group with 7 updates
-
fix: check group for resource info match
-
Update to 3.17.0 (bsc#1235318, CVE-2024-45338):
Full changelog: https://github.com/helm/helm/releases/tag/v3.17.0
-
Notable Changes
- Allow pulling and installation by OCI digest
- Annotations and dependencies are now in chart metadata output
- New --take-ownership flag for install and upgrade commands
- SDK: Authorizer and registry authorizer are now configurable
- Removed the Kubernetes configuration file permissions check
- Added username/password to helm push and dependency build/update subcommands
- Added toYamlPretty template function
-
Update to version 3.16.4 (bsc#1234482, CVE-2024-45337):
-
Bump golang.org/x/crypto from 0.30.0 to 0.31.0
- Bump the k8s-io group with 7 updates
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Micro 6.1
zypper in -t patch SUSE-SLE-Micro-6.1-75=1
Package List:
-
SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64)
- helm-debuginfo-3.17.2-slfo.1.1_1.1
- helm-3.17.2-slfo.1.1_1.1
-
SUSE Linux Micro 6.1 (noarch)
- helm-bash-completion-3.17.2-slfo.1.1_1.1
References:
- https://www.suse.com/security/cve/CVE-2024-25620.html
- https://www.suse.com/security/cve/CVE-2024-26147.html
- https://www.suse.com/security/cve/CVE-2024-45337.html
- https://www.suse.com/security/cve/CVE-2024-45338.html
- https://www.suse.com/security/cve/CVE-2025-22870.html
- https://bugzilla.suse.com/show_bug.cgi?id=1219969
- https://bugzilla.suse.com/show_bug.cgi?id=1220207
- https://bugzilla.suse.com/show_bug.cgi?id=1234482
- https://bugzilla.suse.com/show_bug.cgi?id=1235318
- https://bugzilla.suse.com/show_bug.cgi?id=1238688