Skip to content

fix(deps): update module helm.sh/helm/v3 to v3.17.4 [security]#175

Merged
botty-mcbottington[bot] merged 1 commit intomainfrom
renovate/go-helm.sh-helm-v3-vulnerability
Jul 23, 2025
Merged

fix(deps): update module helm.sh/helm/v3 to v3.17.4 [security]#175
botty-mcbottington[bot] merged 1 commit intomainfrom
renovate/go-helm.sh-helm-v3-vulnerability

Conversation

@botty-mcbottington
Copy link
Copy Markdown
Contributor

@botty-mcbottington botty-mcbottington bot commented Jul 9, 2025

This PR contains the following updates:

Package Change Age Confidence
helm.sh/helm/v3 v3.17.3 -> v3.17.4 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2025-53547

A Helm contributor discovered that a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated.

Impact

Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependencies are updated and this file is written, can be crafted in a way that can cause execution if that same content were in a file that is executed (e.g., a bash.rc file or shell script). If the Chart.lock file is symlinked to one of these files updating dependencies will write the lock file content to the symlinked file. This can lead to unwanted execution. Helm warns of the symlinked file but did not stop execution due to symlinking.

This affects when dependencies are updated. When using the helm command this happens when helm dependency update is run. helm dependency build can write a lock file when one does not exist but this vector requires one to already exist. This affects the Helm SDK when the downloader Manager performs an update.

Patches

This issue has been resolved in Helm v3.18.4

Workarounds

Ensure the Chart.lock file in a chart is not a symlink prior to updating dependencies.

For more information

Helm's security policy is spelled out in detail in our SECURITY document.

Credits

Disclosed by Jakub Ciolek at AlphaSense.


Release Notes

helm/helm (helm.sh/helm/v3)

v3.17.4: Helm v3.17.4

Compare Source

Helm v3.17.4 is a patch release, this bring is the security release noted below. This is intended for Helm SDK users. CLI users are recommended to use the latest version of Helm.

Security Advisories

GHSA-557j-xg8c-q2mm: Chart Dependency Updating With Malicious Chart.yaml Content And Symlink

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Installation and Upgrading

Download Helm v3.17.4. The common platform binaries are here:

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 3.18.5 is the next patch release and will be on August 13, 2025
  • 3.19.0 is the next minor release and will be on September 11, 2025

Changelog

  • fixup! Updating link handling 0e59b9e (Luis Rascao)
  • Updating link handling 3663598 (Robert Sirchia)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@botty-mcbottington botty-mcbottington bot force-pushed the renovate/go-helm.sh-helm-v3-vulnerability branch 14 times, most recently from 35c8d6e to cab9c7a Compare July 17, 2025 00:34
@botty-mcbottington botty-mcbottington bot changed the title fix(deps): update module helm.sh/helm/v3 to v3.18.4 [security] fix(deps): update module helm.sh/helm/v3 to v3.17.4 [security] Jul 17, 2025
@botty-mcbottington botty-mcbottington bot force-pushed the renovate/go-helm.sh-helm-v3-vulnerability branch 2 times, most recently from 172bb51 to 2d5e381 Compare July 22, 2025 00:35
@botty-mcbottington botty-mcbottington bot force-pushed the renovate/go-helm.sh-helm-v3-vulnerability branch from 2d5e381 to a91c75c Compare July 23, 2025 00:35
@botty-mcbottington botty-mcbottington bot merged commit b74ff3d into main Jul 23, 2025
3 checks passed
@botty-mcbottington botty-mcbottington bot deleted the renovate/go-helm.sh-helm-v3-vulnerability branch July 23, 2025 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants