Skip to content

chore(deps): bump helm.sh/helm/v3 from 3.17.3 to 3.17.4 in /tools/helm#6604

Merged
ti-chi-bot[bot] merged 1 commit intomainfrom
dependabot/go_modules/tools/helm/helm.sh/helm/v3-3.17.4
Dec 19, 2025
Merged

chore(deps): bump helm.sh/helm/v3 from 3.17.3 to 3.17.4 in /tools/helm#6604
ti-chi-bot[bot] merged 1 commit intomainfrom
dependabot/go_modules/tools/helm/helm.sh/helm/v3-3.17.4

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 15, 2025

Bumps helm.sh/helm/v3 from 3.17.3 to 3.17.4.

Release notes

Sourced from helm.sh/helm/v3's releases.

Helm v3.17.4 is a patch release, this bring is the security release noted below. This is intended for Helm SDK users. CLI users are recommended to use the latest version of Helm.

Security Advisories

GHSA-557j-xg8c-q2mm: Chart Dependency Updating With Malicious Chart.yaml Content And Symlink

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Installation and Upgrading

Download Helm v3.17.4. The common platform binaries are here:

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 3.18.5 is the next patch release and will be on August 13, 2025
  • 3.19.0 is the next minor release and will be on September 11, 2025

Changelog

  • fixup! Updating link handling 0e59b9e5b951d34584bed39a28786893bbb0fbe2 (Luis Rascao)
  • Updating link handling 36635988fdd9c173d7bf75ab65e115763d68a3c4 (Robert Sirchia)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Dec 15, 2025
@ti-chi-bot ti-chi-bot bot requested a review from howardlau1999 December 15, 2025 04:01
@github-actions github-actions bot added the v2 for operator v2 label Dec 15, 2025
@ti-chi-bot
Copy link
Contributor

ti-chi-bot bot commented Dec 15, 2025

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a pingcap member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@github-actions github-actions bot marked this pull request as draft December 15, 2025 04:06
@github-actions
Copy link

/ok-to-test

@github-actions
Copy link

/test ready-for-review

@ti-chi-bot
Copy link
Contributor

ti-chi-bot bot commented Dec 15, 2025

@github-actions[bot]: Cannot trigger testing until a trusted user reviews the PR and leaves an /ok-to-test message.

Details

In response to this:

/ok-to-test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@ti-chi-bot
Copy link
Contributor

ti-chi-bot bot commented Dec 15, 2025

@github-actions[bot]: Cannot trigger testing until a trusted user reviews the PR and leaves an /ok-to-test message.

Details

In response to this:

/test ready-for-review

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@liubog2008
Copy link
Member

/test ready-for-review

@dependabot dependabot bot force-pushed the dependabot/go_modules/tools/helm/helm.sh/helm/v3-3.17.4 branch from 939b66a to 1bf5663 Compare December 16, 2025 09:54
@github-actions
Copy link

/ok-to-test

@github-actions
Copy link

/test ready-for-review

@ti-chi-bot ti-chi-bot marked this pull request as ready for review December 16, 2025 09:59
@ti-chi-bot ti-chi-bot bot requested a review from shonge December 16, 2025 09:59
@codecov-commenter
Copy link

codecov-commenter commented Dec 16, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 41.21%. Comparing base (e14e232) to head (412d9d0).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #6604   +/-   ##
=======================================
  Coverage   41.21%   41.21%           
=======================================
  Files         350      350           
  Lines       20174    20174           
=======================================
  Hits         8314     8314           
  Misses      11860    11860           
Flag Coverage Δ
unittest 41.21% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.17.3 to 3.17.4.
- [Release notes](https://github.com/helm/helm/releases)
- [Commits](helm/helm@v3.17.3...v3.17.4)

---
updated-dependencies:
- dependency-name: helm.sh/helm/v3
  dependency-version: 3.17.4
  dependency-type: indirect
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/tools/helm/helm.sh/helm/v3-3.17.4 branch from 1bf5663 to 412d9d0 Compare December 18, 2025 03:54
@github-actions
Copy link

/ok-to-test

@github-actions github-actions bot marked this pull request as draft December 18, 2025 03:59
@github-actions
Copy link

/test ready-for-review

@liubog2008
Copy link
Member

/test pull-e2e

@liubog2008
Copy link
Member

/lgtm

@ti-chi-bot
Copy link
Contributor

ti-chi-bot bot commented Dec 18, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: liubog2008

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ti-chi-bot ti-chi-bot bot added the lgtm label Dec 18, 2025
@ti-chi-bot
Copy link
Contributor

ti-chi-bot bot commented Dec 18, 2025

[LGTM Timeline notifier]

Timeline:

  • 2025-12-18 09:35:25.414551701 +0000 UTC m=+1724870.228329263: ☑️ agreed by liubog2008.

@ti-chi-bot ti-chi-bot bot added the approved label Dec 18, 2025
@liubog2008
Copy link
Member

/test pull-e2e

@ti-chi-bot ti-chi-bot bot merged commit b283c20 into main Dec 19, 2025
11 of 15 checks passed
@ti-chi-bot ti-chi-bot bot deleted the dependabot/go_modules/tools/helm/helm.sh/helm/v3-3.17.4 branch December 19, 2025 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved contribution dependencies Pull requests that update a dependency file go Pull requests that update go code lgtm ok-to-test size/XS v2 for operator v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants