Skip to content

Conversation

@inishchith
Copy link
Contributor

@inishchith inishchith commented Sep 29, 2025

Description

  • upgrade helm.sh/helm/v3 to v3.17.4 to address security vulnerabilities

This commit upgrades the Helm dependency from v3.17.1 to v3.17.4 to fix multiple security vulnerabilities identified by Trivy security scanning:

The Helm upgrade requires bumping Kubernetes client packages from v0.32.1 to v0.32.2 (patch version) as transitive dependencies. These are backward compatible updates with no breaking changes.

Note: CVE-2025-55198 and CVE-2025-55199 remain present as they require Helm v3.18.5, which would necessitate a K8s minor version upgrade.

Issue reference

We strive to have all PR being opened based on an issue, where the problem or feature have been discussed prior to implementation.

Please reference the issue this PR will close: Fixes: dapr/dapr#9086

Checklist

Please make sure you've completed the relevant tasks for this PR, out of the following list:

  • Code compiles correctly
  • Created/updated tests
  • Extended the documentation

@inishchith inishchith requested review from a team as code owners September 29, 2025 21:57
@inishchith inishchith changed the title fix: upgrade helm.sh/helm/v3 to v3.17.4 to address security vulnerabi… fix: upgrade helm.sh/helm/v3 to v3.17.4 to address security vulnerabilities Sep 29, 2025
@inishchith
Copy link
Contributor Author

@yaron2 @JoshVanL - could you take a look whenever?

@yaron2
Copy link
Member

yaron2 commented Oct 2, 2025

Can you please base this PR against the 1.16 branch?

…lities

This commit upgrades the Helm dependency from v3.17.1 to v3.17.4 to fix
multiple security vulnerabilities identified by Trivy security scanning:

- CVE-2025-53547 (HIGH): Helm Chart Code Execution
- CVE-2025-32386 (MEDIUM): Helm Allows A Specially Crafted Chart Archive
- CVE-2025-32387 (MEDIUM): Helm Allows A Specially Crafted JSON Schema

The Helm upgrade requires bumping Kubernetes client packages from v0.32.1
to v0.32.2 (patch version) as transitive dependencies. These are backward
compatible updates with no breaking changes.

Note: CVE-2025-55198 and CVE-2025-55199 remain present as they require
Helm v3.18.5, which would necessitate a K8s minor version upgrade.

Fixes: dapr/dapr#9086

Co-authored-by: @cursoragent
Signed-off-by: inishchith <[email protected]>
@inishchith inishchith changed the base branch from master to release-1.16 October 2, 2025 06:44
@inishchith inishchith force-pushed the fix/upgrade-helm-v3.17.4-security-fixes branch from cd74253 to 4384607 Compare October 2, 2025 06:44
@inishchith
Copy link
Contributor Author

@yaron2 - done!

@yaron2 yaron2 merged commit b741268 into dapr:release-1.16 Oct 6, 2025
32 of 33 checks passed
JoshVanL pushed a commit to JoshVanL/dapr-cli that referenced this pull request Oct 31, 2025
…lities (dapr#1555)

This commit upgrades the Helm dependency from v3.17.1 to v3.17.4 to fix
multiple security vulnerabilities identified by Trivy security scanning:

- CVE-2025-53547 (HIGH): Helm Chart Code Execution
- CVE-2025-32386 (MEDIUM): Helm Allows A Specially Crafted Chart Archive
- CVE-2025-32387 (MEDIUM): Helm Allows A Specially Crafted JSON Schema

The Helm upgrade requires bumping Kubernetes client packages from v0.32.1
to v0.32.2 (patch version) as transitive dependencies. These are backward
compatible updates with no breaking changes.

Note: CVE-2025-55198 and CVE-2025-55199 remain present as they require
Helm v3.18.5, which would necessitate a K8s minor version upgrade.

Fixes: dapr/dapr#9086

Co-authored-by: @cursoragent

Signed-off-by: inishchith <[email protected]>
cicoyle pushed a commit to cicoyle/cli that referenced this pull request Nov 10, 2025
…lities (dapr#1555)

This commit upgrades the Helm dependency from v3.17.1 to v3.17.4 to fix
multiple security vulnerabilities identified by Trivy security scanning:

- CVE-2025-53547 (HIGH): Helm Chart Code Execution
- CVE-2025-32386 (MEDIUM): Helm Allows A Specially Crafted Chart Archive
- CVE-2025-32387 (MEDIUM): Helm Allows A Specially Crafted JSON Schema

The Helm upgrade requires bumping Kubernetes client packages from v0.32.1
to v0.32.2 (patch version) as transitive dependencies. These are backward
compatible updates with no breaking changes.

Note: CVE-2025-55198 and CVE-2025-55199 remain present as they require
Helm v3.18.5, which would necessitate a K8s minor version upgrade.

Fixes: dapr/dapr#9086

Co-authored-by: @cursoragent

Signed-off-by: inishchith <[email protected]>
Signed-off-by: Cassandra Coyle <[email protected]>
@marcduiker
Copy link
Contributor

@holopin-bot @inishchith Thank you! Here's a digital badge as a small token of appreciation.

@holopin-bot
Copy link

holopin-bot bot commented Nov 18, 2025

Congratulations @inishchith, the maintainer of this repository has issued you a badge! Here it is: https://holopin.io/claim/cmi4ewtcx001ajp04ei3dztp2

This badge can only be claimed by you, so make sure that your GitHub account is linked to your Holopin account. You can manage those preferences here: https://holopin.io/account.
Or if you're new to Holopin, you can simply sign up with GitHub, which will do the trick!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerabilities in DAPR Binary(Slim Mode) - Helm Dependencies

3 participants