mirror of https://github.com/helm/helm
Backports the golang.org/x/net upgrade already present on main (commit on main bumped to v0.53.0). The v0.52.0 currently pinned in release-4.2 is affected by GO-2026-4918, a HTTP/2 vulnerability in golang.org/x/net/http2 fixed in v0.53.0. This affects any downstream image that ships the helm v4.2.x binary: vulnerability scanners (Trivy, MS S360, etc.) flag the embedded golang.org/x/net version even though helm's own code paths may not be exploitable. A patch release on release-4.2 that includes this bump lets downstream consumers clear the finding without waiting for v4.3.0. Verified locally with go 1.26.3 on windows/amd64: go get golang.org/x/net@v0.53.0 go mod tidy go build ./... # passes Refs: https://pkg.go.dev/vuln/GO-2026-4918 Signed-off-by: Sukhbir Singh <sukhbirsingh@microsoft.com>pull/32131/head
parent
06468084e8
commit
02bb1602a7
Loading…
Reference in new issue