Skip to content
This repository has been archived by the owner on Jul 17, 2024. It is now read-only.

Upgrade Helm v3 dependency #152

Closed
janotav opened this issue Jun 17, 2020 · 3 comments · Fixed by #163
Closed

Upgrade Helm v3 dependency #152

janotav opened this issue Jun 17, 2020 · 3 comments · Fixed by #163
Assignees
Labels
enhancement New feature or request

Comments

@janotav
Copy link

janotav commented Jun 17, 2020

There is currently helm.sh/helm/v3 v3.1.0 dependency. This version of Helm is subject to following vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2020-11013

Could you please either:
a) upgrade the dependency to 3.2.x that is not affected
b) confirm that 2to3 is not affected by the vulnerability

Thanks!

@hickeyma
Copy link
Collaborator

@janotav Thanks for raising. The plugin is not affected by the vulnerability.

I think though you raise a good point and it should be updated to the latest version of the libs.

@janotav
Copy link
Author

janotav commented Jun 17, 2020

@hickeyma thank you for the confirmation

The dependency upgrade actually cascades and it was my impression that https://github.com/maorfr/helm-plugin-utils currently does not support the new APIs.

Shall I close this or do you want to keep it open for the sake of the upgrade?

@hickeyma
Copy link
Collaborator

hickeyma commented Jun 17, 2020

It is ok as it is not affected either by the vulnerabilities.

Lets leave the issue open, as can use it for updating the libs. 👍

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants