mirror of https://github.com/helm/helm
release-3.22
release-4.3
dependabot/go_modules/main/github.com/fluxcd/cli-utils-1.3.0
main
dev-v3
release-3.21
release-4.2
copilot/important-issues-review
copilot/fix-analyze-go-job
release-3.20
release-4.1
release-3.19
release-4.0
copilot/backport-reflect-pointer-change
release-3.18
release-3.17
release-3.16
release-3.15
release-3.14
release-3.13
release-3.12
release-3.11
release-3.10
release-3.9
release-3.8
release-3.7
release-3.6
release-3.6.2
release-3.6.1
release-3.5
release-3.4
dev-v2
release-2.17
release-3.3
release-2.16
release-3.2
release-3.1
release-3.0
release-2.15
release-2.14
release-2.13
release-2.12
release-2.11
release-2.10
release-2.9
release-2.8
release-2.7
release-2.6
release-2.5
release-2.4
release-2.3
release-2.2
release-2.1
release-2.0
kube-update-test
release-v1.2.1
v3.22.0
v4.3.0
v3.22.0-rc.1
v4.3.0-rc.1
v3.21.4
v4.2.4
v3.21.3
v4.2.3
v3.21.2
v4.2.2
v3.21.1
v4.2.1
v3.21.0
v4.2.0
v3.21.0-rc.1
v4.2.0-rc.1
v3.20.2
v4.1.4
v3.20.1
v4.1.3
v4.1.2
v4.1.1
v3.20.0
v4.1.0
v3.19.5
v4.0.5
v3.20.0-rc.1
v4.1.0-rc.1
v4.0.4
v3.19.4
v4.0.2
v3.19.3
v4.0.1
v3.19.2
v4.0.0
v3.19.1
v4.0.0-rc.1
v4.0.0-beta.2
v4.0.0-beta.1
v3.19.0
v3.19.0-rc.1
v4.0.0-alpha.1
v3.18.6
v3.18.5
v3.17.4
v3.18.4
v3.18.3
v3.18.2
v3.18.1
v3.18.0
v3.18.0-rc.2
v3.18.0-rc.1
v3.17.3
v3.17.2
v3.17.1
v3.17.0
v3.17.0-rc.1
v3.16.4
v3.16.3
v3.16.2
v3.16.1
v3.16.0
v3.16.0-rc.1
v3.15.4
v3.15.3
v3.15.2
v3.15.1
v3.15.0
v3.15.0-rc.2
v3.15.0-rc.1
v3.14.4
v3.14.3
v3.14.2
v3.14.1
v3.14.0
v3.14.0-rc.1
v3.13.3
v3.13.2
v3.13.1
v3.13.0
v3.13.0-rc.1
v3.12.3
v3.12.2
v3.12.1
v3.12.0
v3.12.0-rc.1
v3.11.3
v3.11.2
v3.12.0-dev.1
v3.11.1
v3.11.0
v3.11.0-rc.2
v3.11.0-rc.1
v3.10.3
v3.10.2
v3.10.1
v3.10.0
v3.10.0-rc.1
v3.9.4
v3.9.3
v3.9.2
v3.9.1
v3.9.0
v3.9.0-rc.1
v3.8.2
v3.8.1
v3.8.0
v3.8.0-rc.2
v3.8.0-rc.1
v3.7.2
v3.7.1
v3.7.0
v3.7.0-rc.3
v3.7.0-rc.2
v3.7.0-rc.1
v3.6.3
v3.6.2
v3.6.1
v3.6.0
v3.6.0-rc.1
v3.5.4
v3.5.3
v3.5.2
v3.5.1
v3.5.0
v3.5.0-rc.2
v3.5.0-rc.1
v3.4.2
v3.4.1
v3.4.0
v2.17.0
v3.4.0-rc.1
v2.17.0-rc.1
v3.3.4
v2.16.12
v3.3.3
v2.16.11
v3.3.2
v3.3.1
v2.16.10
v3.3.0
v3.3.0-rc.2
v3.3.0-rc.1
v2.16.9
v3.2.4
v2.16.8
v3.2.3
v3.2.2
v3.2.1
v2.16.7
v3.1.3
v3.2.0
v3.2.0-rc.1
v2.16.6
v2.16.5
v2.16.4
v3.1.2
v3.1.1
v2.16.3
v2.16.2
v3.1.0
v3.1.0-rc.3
v3.1.0-rc.2
v3.1.0-rc.1
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.16.1
v3.0.0-rc.4
v3.0.0-rc.3
v2.16.0
v3.0.0-rc.2
v2.16.0-rc.2
v2.16.0-rc.1
v3.0.0-rc.1
v2.15.2
v2.15.1
v3.0.0-beta.5
v2.15.0
v2.15.0-rc.2
v2.15.0-rc.1
v3.0.0-beta.4
v3.0.0-beta.3
v3.0.0-beta.2
v3.0.0-beta.1
v2.14.3
v3.0.0-alpha.2
v2.14.2
v2.14.1
v3.0.0-alpha.1
v2.14.0
v2.14.0-rc.2
v2.14.0-rc.1
v2.13.1
v2.13.1-rc.1
v2.13.0
v2.13.0-rc.2
v2.13.0-rc.1
v2.12.3
v2.12.2
v2.12.1
v2.12.0
v2.12.0-rc.2
v2.12.0-rc.1
v2.11.0
v2.11.0-rc.4
v2.11.0-rc.3
v2.11.0-rc.2
v2.11.0-rc.1
v2.10.0
v2.10.0-rc.3
v2.10.0-rc.2
v2.10.0-rc.1
v2.9.1
v2.9.0
v2.9.0-rc5
v2.9.0-rc4
v2.9.0-rc3
v2.9.0-rc2
v2.9.0-rc1
v2.8.2
v2.8.2-rc1
v2.8.1
v2.8.0
v2.8.0-rc.1
v2.7.2
v2.7.1
v2.7.0
v2.7.0-rc1
v2.6.2
v2.6.1
v2.6.0
v2.5.1
v2.5.0
v2.4.2
v2.4.1
v2.4.0
v2.3.1
v2.3.0
1.999.0
v1.0
v1.1
v1.2
v1.2.1
v2.0.0
v2.0.0-alpha.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-rc.1
v2.0.0-rc.2
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.2.0
v2.2.1
v2.2.2
v2.2.3
${ noResults }
6 Commits (v4.3.0-rc.1)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
67d54fd880
|
fix(provenance): support GnuPG keybox (pubring.kbx) keyrings (#32281)
* fix(provenance): support GnuPG keybox (pubring.kbx) keyrings Starting with GnuPG 2.1, file-backed public keyrings can use ~/.gnupg/pubring.kbx instead of the legacy pubring.gpg. Helm only read the legacy format, so chart and plugin verification failed on installations using the file-backed keybox. Make the keyring loader format-aware: - GnuPG keybox (pubring.kbx): extract OpenPGP keyblocks from the keybox container without adding a dependency. Skip ephemeral blobs, matching GnuPG's own read behavior. - ASCII-armored keyrings: load single or concatenated exports. - Legacy binary packet streams (pubring.gpg): retain the existing path. defaultKeyring() falls back to pubring.kbx when pubring.gpg is absent. pubring.gpg keeps precedence when both files exist. This change covers file-backed public keyrings. It does not read the SQLite database used by keyboxd, which needs a separate design. Related to #31836 Signed-off-by: Ruslan Shaydullin <shaydullin.r.d@outlook.com> * fix(provenance): treat only not-exist as keyring absence in defaultKeyring A stat error other than 'not exist' (e.g. a permission problem) meant the file may well be present, but defaultKeyring() skipped past it: an unreadable pubring.gpg silently lost precedence to pubring.kbx, and the surfaced error could point at the wrong file. Treat only fs.ErrNotExist as absence. For any other stat error, return that path unchanged so the real error surfaces when the keyring is opened. Signed-off-by: Ruslan Shaydullin <shaydullin.r.d@outlook.com> --------- Signed-off-by: Ruslan Shaydullin <shaydullin.r.d@outlook.com> Co-authored-by: George Jenkins <gvjenkins@gmail.com> |
3 weeks ago |
|
|
7c9176ae35 |
Update dependencies and refactor crypto imports to use ProtonMail's go-crypto package
Signed-off-by: Siew Kam Onn <kosiew@gmail.com> |
12 months ago |
|
|
e458a67f0c
|
ref(pkg/chart): add validation method to chart
Consolidate validation of Chart.yaml. Signed-off-by: Adam Reese <adam@reese.io> |
8 years ago |
|
|
0c6b6d1c62 |
fix(*): correct file permissions on source files
|
10 years ago |
|
|
9ae97c341c
|
fix(helm): read passphrase from prompt
This prompts the user to enter a passphrase if the given PGP key is encrypted. Closes #1447 |
10 years ago |
|
|
ce83a8a777 |
feat(pkg/provenance): add OpenPGP signatures
This adds support for OpenPGP signatures containing provenance data. Such information can be used to verify the integrity of a Chart by testing that its file hash, metadata, and images are correct. This first PR does not contain all of the tooling necessary for end-to-end chart integrity. It contains just the library. See #983 |
10 years ago |