George Jenkins
c3b336af15
Merge pull request #32341 from mmorel-35/testifylint-manual-assert-internal-1
...
chore(internal): refactor: convert tests to testify assert/require part 1
4 weeks ago
Matthieu MOREL
f280d9c1b5
chore(internal): refactor: convert tests to testify assert/require part 2
...
refactor: convert tests to testify assert/require in internal/chart/v3/util
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
d72b28ebcb
chore(internal): refactor: convert tests to testify assert/require part 1
...
refactor: convert tests to testify assert/require in internal/chart/v3/lint/rules
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
秀吉
68977ec0b5
fix(ci): pin govulncheck-action to the v1.1.0 release ( #32304 )
...
golang/govulncheck-action published v1.1.0 on 2026-07-10, tagging the
master commit (032d455) the govulncheck step was already pinned to.
Update the pin comment to # pin@v1.1.0 so it matches the repo's
pin@<tag> convention and Dependabot can track the action by semver
again.
The pinned SHA is unchanged; v1.1.0 points to that commit, so CI
behavior is identical and only the trailing comment changes.
Closes : #32301
Signed-off-by: thc1006 <84045975+thc1006@users.noreply.github.com>
1 month ago
Terry Howe
b963afaddf
ci: track GitHub Actions updates on dev-v3 via Dependabot
...
Dependabot reads its config only from the default branch, and the
github-actions ecosystem was configured for main only. As a result,
Action version bumps never flowed to dev-v3, leaving its workflows
(e.g. govulncheck-action) frozen and drifting from main.
Add a github-actions update block targeting dev-v3 so Action bumps are
opened there too, matching the existing gomod/dev-v3 arrangement.
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
1 month ago
dependabot[bot]
fb53c00ae7
chore(deps): bump actions/stale from 10.3.0 to 10.4.0 ( #32330 )
...
Bumps [actions/stale](https://github.com/actions/stale ) from 10.3.0 to 10.4.0.
- [Release notes](https://github.com/actions/stale/releases )
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md )
- [Commits](eb5cf3af3a...1e223db275 )
---
updated-dependencies:
- dependency-name: actions/stale
dependency-version: 10.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
dependabot[bot]
dad026acb8
chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 ( #32334 )
...
Bumps [github.com/mattn/go-shellwords](https://github.com/mattn/go-shellwords ) from 1.0.13 to 1.0.14.
- [Commits](https://github.com/mattn/go-shellwords/compare/v1.0.13...v1.0.14 )
---
updated-dependencies:
- dependency-name: github.com/mattn/go-shellwords
dependency-version: 1.0.14
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
dependabot[bot]
84e63e5c38
chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 ( #32333 )
...
Bumps [oras.land/oras-go/v2](https://github.com/oras-project/oras-go ) from 2.6.1 to 2.6.2.
- [Release notes](https://github.com/oras-project/oras-go/releases )
- [Commits](https://github.com/oras-project/oras-go/compare/v2.6.1...v2.6.2 )
---
updated-dependencies:
- dependency-name: oras.land/oras-go/v2
dependency-version: 2.6.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
Matheus Pimenta
73c1fb2451
Address review comments
...
Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
1 month ago
Matheus Pimenta
bfebbb7c1a
Fix vanishing empty lines
...
Signed-off-by: Matheus Pimenta <matheuscscp@gmail.com>
1 month ago
Akanksha Trehun
7b9a5c8911
fix: add missing https:// to Oracle link in ADOPTERS.md ( #32324 )
...
Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
1 month ago
Akanksha Trehun
cfa3b24fe6
fix: remove trailing whitespace in .golangci.yml ( #32325 )
...
Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
1 month ago
Akanksha Trehun
a91e9f6a24
fix(Makefile): update outdated .sha256 comment for Helm v4 ( #32323 )
...
Signed-off-by: Akanksha Trehun <akankshatrehun@gmail.com>
1 month ago
Matthieu MOREL
16787d65f5
feat(linters): add new revive rules for better code quality
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
9662fdd73b
refactor: enable several checks from gocritic
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
7bfcdb0fc3
fix(linters): update golangci-lint to 2.12.2
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matt Farina
d5465e930e
Merge pull request #32317 from TerryHowe/chore/bump-x-crypto-0.54.0
...
chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
1 month ago
Matt Farina
950ce2e121
Merge pull request #32316 from helm/fix/codeql-analyze-4.37.0
...
chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0
1 month ago
Terry Howe
8118a4da1e
chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0
...
The init and autobuild steps were bumped to 4.37.0 (#32313 , #32305 ) but the analyze step remained at 4.36.2, causing CodeQL to fail on main with: "Loaded a configuration file for version '4.37.0', but running version '4.36.2'". Align analyze with the other codeql-action steps.
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
1 month ago
Terry Howe
0fc3b93853
chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
...
x/crypto v0.54.0 raises golang.org/x/term to v0.45.0 and golang.org/x/sys to v0.47.0 via minimum version selection.
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
1 month ago
Terry Howe
71901a4c7c
chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.37.0
...
The init and autobuild steps were bumped to 4.37.0 (#32313 , #32305 ) but the analyze step remained at 4.36.2, causing CodeQL to fail on main with: "Loaded a configuration file for version '4.37.0', but running version '4.36.2'". Align analyze with the other codeql-action steps.
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
1 month ago
dependabot[bot]
a71eb99db4
chore(deps): bump github/codeql-action/init from 4.36.2 to 4.37.0 ( #32313 )
...
Bumps [github/codeql-action/init](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/init
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
dependabot[bot]
ea52bdf7e2
chore(deps): bump github/codeql-action/autobuild from 4.36.2 to 4.37.0 ( #32305 )
...
Bumps [github/codeql-action/autobuild](https://github.com/github/codeql-action ) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
dependabot[bot]
a242855a7e
chore(deps): bump golang.org/x/text from 0.39.0 to 0.40.0 ( #32309 )
...
Bumps [golang.org/x/text](https://github.com/golang/text ) from 0.39.0 to 0.40.0.
- [Release notes](https://github.com/golang/text/releases )
- [Commits](https://github.com/golang/text/compare/v0.39.0...v0.40.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/text
dependency-version: 0.40.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
dependabot[bot]
f25f955578
chore(deps): bump github/codeql-action/upload-sarif ( #32311 )
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.36.3 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](54f647b7e1...99df26d4f1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 month ago
Terry Howe
d461463085
Merge pull request #32299 from benoittgt/avoid-issue-with-govuln-deprecation
...
fix(ci): resolve Node 20 deprecation in govulncheck
1 month ago
Benoit Tigeot
ed651de9b1
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Benoit Tigeot <benoittgt@users.noreply.github.com>
1 month ago
Benoit Tigeot
ca24a55c31
fix(ci): resolve Node 20 deprecation in govulncheck
...
The pinned v1.0.4 used actions/checkout@v4 and
actions/setup-go@v5 internally, both built on Node 20.
Latest main uses v6 of both, which run on Node 24.
Signed-off-by: Benoit Tigeot <benoit.tigeot@lifen.fr>
1 month ago
Terry Howe
d262c7ca79
Merge pull request #32296 from mmorel-35/gocritic-singleCaseSwitch
...
chore: fix emptyStringTest, nestingReduce and singleCaseSwitch checks issues from gocritic
1 month ago
Terry Howe
50fb6ff85b
Merge pull request #32294 from mmorel-35/testifylint
...
chore: fix several checks issues from testifylint
1 month ago
Terry Howe
a572f23b82
Merge pull request #32298 from helm/dependabot/go_modules/main/golang.org/x/text-0.39.0
...
chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0
1 month ago
dependabot[bot]
e3fbe2e9d1
chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0
...
Bumps [golang.org/x/text](https://github.com/golang/text ) from 0.38.0 to 0.39.0.
- [Release notes](https://github.com/golang/text/releases )
- [Commits](https://github.com/golang/text/compare/v0.38.0...v0.39.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/text
dependency-version: 0.39.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
1 month ago
Matthieu MOREL
96b315f188
chore: fix emptyStringTest, nestingReduce and singleCaseSwitch checks issues from gocritic
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
c1569ea83f
Update pkg/cmd/history_test.go
...
Co-authored-by: George Jenkins <gvjenkins@gmail.com>
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
65077c10fa
test: replace assert.Equal with require.EqualError for improved error handling
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
4ade4a5495
test: replace assert.Contains with assert.ErrorContains for better error handling
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Matthieu MOREL
f34ad6c337
chore: fix several checks issues from testifylint
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
George Jenkins
7b999ddc07
Merge pull request #32293 from mmorel-35/gocritic-httpNoBody
...
chore: fix several checks issues from gocritic
1 month ago
LarytheLord
47bde11959
test(cli): use t.Cleanup for resetEnv with t.Setenv
...
Signed-off-by: LarytheLord <llawlietbagsum@gmail.com>
1 month ago
LarytheLord
9b30076180
test(cli): isolate user-agent rest config test from host kubeconfig
...
Signed-off-by: LarytheLord <llawlietbagsum@gmail.com>
1 month ago
Matthieu MOREL
07259ecc86
chore: fix several checks issues from gocritic
...
Signed-off-by: Matthieu MOREL <matthieu.morel35@gmail.com>
1 month ago
Mahesh Sadupalli
143631f735
fix(engine): prevent Files.Lines panic on empty file
...
Files.Lines guards against a nil entry but an empty file inside a
chart is stored as a non-nil zero-length byte slice, so the trailing
newline check indexes s[-1] and panics. The engine recovers the panic
into a render error, making every template/install/upgrade/lint that
references the file fail.
Extend the guard to len(f[path]) == 0 and return an empty slice,
matching the behaviour for missing files.
Fixes #32279
Signed-off-by: Mahesh Sadupalli <mahesh.sadupalli@gmail.com>
1 month ago
Terry Howe
543b94d673
Merge pull request #31211 from kimsungmin1/main-fix-push-scope
...
fix: set [pull,push] scope when helm push to a registry(use token auth) - v4
1 month ago
kimsungmin1
d539556a8d
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: kimsungmin1 <142377392+kimsungmin1@users.noreply.github.com>
1 month ago
Terry Howe
b229279def
Merge pull request #32285 from helm/dependabot/github_actions/main/github/codeql-action/upload-sarif-4.36.3
...
chore(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.36.3
1 month ago
dependabot[bot]
e9eda8c598
chore(deps): bump github/codeql-action/upload-sarif
...
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) from 4.36.2 to 4.36.3.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...54f647b7e1 )
---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.36.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
1 month ago
kimsm28
503acff975
fix(registry): resolve golangci-lint issues in token-auth tests
...
- Use (*net.ListenConfig).Listen with the test context instead of
net.Listen (noctx).
- Use suite.NoError instead of suite.Nil for the error check
(testifylint).
- Drop the unnecessary leading blank lines in the scope test funcs
(whitespace).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: kimsm28 <sm28.kim@samsung.com>
1 month ago
kimsm28
4e9ca06856
chore: go mod tidy after rebase on main
...
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: kimsm28 <sm28.kim@samsung.com>
1 month ago
kimsm28
3cbee7e935
fix(registry): use plain-http registry in token-auth scope test
...
The scope test configured a TLS registry while advertising an http token
realm. oras refuses to send credentials to an http token realm when the
registry itself was contacted over https, so the auth server was never
reached and the test timed out ("timeout waiting for auth request").
Use a plain-http registry so the registry and token-realm schemes match;
the scope carried in the token request is what this test verifies, and
that is independent of TLS.
Also make the auth handler's channel send non-blocking so that a client
retry can never block the handler and stall the push/pull flow, which
addresses the review comment about a potential deadlock.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: kimsm28 <sm28.kim@samsung.com>
1 month ago
Terry Howe
26ada49c1a
Update pkg/registry/client.go
...
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Terry Howe <terrylhowe@gmail.com>
1 month ago