FlawAtlas
Search the atlas
SUSE-SU-2025:20196-1 Not scored

Security update for helm

This update for helm fixes the following issues: - Update to version 3.17.2 (bsc#1238688, CVE-2025-22870): * Updating to 0.37.0 for x/net * build(deps): bump the k8s-io group with 7 updates - Update to version 3.17.1: * merge null child chart objects * build(deps): bump the k8s-io group with 7 updates * fix: check group for resource info match - Update to 3.17.0 (bsc#1235318, CVE-2024-45338): Full changelog: https://github.com/helm/helm/releases/tag/v3.17.0 * Notable Changes - Allow pulling and installation by OCI digest - Annotations and dependencies are now in chart metadata output - New --take-ownership flag for install and upgrade commands - SDK: Authorizer and registry authorizer are now configurable - Removed the Kubernetes configuration file permissions check - Added username/password to helm push and dependency build/update subcommands - Added toYamlPretty template function - Update to version 3.16.4 (bsc#1234482, CVE-2024-45337): * Bump golang.org/x/crypto from 0.30.0 to 0.31.0 * Bump the k8s-io group with 7 updates

Exploit probability Not scored
Published April 22, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Micro 6.0 helm

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:20196-1

This update for helm fixes the following issues: - Update to version 3.17.2 (bsc#1238688, CVE-2025-22870): * Updating to 0.37.0 for x/net * build(deps): bump the k8s-io group with 7 updates - Update to version 3.17.1: * merge null child chart objects * build(deps): bump the k8s-io group with 7 updates * fix: check group for resource info match - Update to 3.17.0 (bsc#1235318, CVE-2024-45338): Full changelog: https://github.com/helm/helm/releases/tag/v3.17.0 * Notable Changes - Allow pulling and installation by OCI digest - Annotations and dependencies are now in chart metadata output - New --take-ownership flag for install and upgrade commands - SDK: Authorizer and registry authorizer are now configurable - Removed the Kubernetes configuration file permissions check - Added username/password to helm push and dependency build/update subcommands - Added toYamlPretty template function - Update to version 3.16.4 (bsc#1234482, CVE-2024-45337): * Bump golang.org/x/crypto from 0.30.0 to 0.31.0 * Bump the k8s-io group with 7 updates

View original source

05 / REFERENCES

Further evidence