Security update for helm
This update for helm fixes the following issues: - Update to version 3.17.2 (bsc#1238688, CVE-2025-22870): * Updating to 0.37.0 for x/net * build(deps): bump the k8s-io group with 7 updates - Update to version 3.17.1: * merge null child chart objects * build(deps): bump the k8s-io group with 7 updates * fix: check group for resource info match - Update to 3.17.0 (bsc#1235318, CVE-2024-45338): Full changelog: https://github.com/helm/helm/releases/tag/v3.17.0 * Notable Changes - Allow pulling and installation by OCI digest - Annotations and dependencies are now in chart metadata output - New --take-ownership flag for install and upgrade commands - SDK: Authorizer and registry authorizer are now configurable - Removed the Kubernetes configuration file permissions check - Added username/password to helm push and dependency build/update subcommands - Added toYamlPretty template function - Update to version 3.16.4 (bsc#1234482, CVE-2024-45337): * Bump golang.org/x/crypto from 0.30.0 to 0.31.0 * Bump the k8s-io group with 7 updates
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for helm fixes the following issues: - Update to version 3.17.2 (bsc#1238688, CVE-2025-22870): * Updating to 0.37.0 for x/net * build(deps): bump the k8s-io group with 7 updates - Update to version 3.17.1: * merge null child chart objects * build(deps): bump the k8s-io group with 7 updates * fix: check group for resource info match - Update to 3.17.0 (bsc#1235318, CVE-2024-45338): Full changelog: https://github.com/helm/helm/releases/tag/v3.17.0 * Notable Changes - Allow pulling and installation by OCI digest - Annotations and dependencies are now in chart metadata output - New --take-ownership flag for install and upgrade commands - SDK: Authorizer and registry authorizer are now configurable - Removed the Kubernetes configuration file permissions check - Added username/password to helm push and dependency build/update subcommands - Added toYamlPretty template function - Update to version 3.16.4 (bsc#1234482, CVE-2024-45337): * Bump golang.org/x/crypto from 0.30.0 to 0.31.0 * Bump the k8s-io group with 7 updates
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1219969
- https://bugzilla.suse.com/1220207
- https://bugzilla.suse.com/1234482
- https://bugzilla.suse.com/1235318
- https://bugzilla.suse.com/1238688
- https://www.suse.com/security/cve/CVE-2024-25620
- https://www.suse.com/security/cve/CVE-2024-26147
- https://www.suse.com/security/cve/CVE-2024-45337
- https://www.suse.com/security/cve/CVE-2024-45338
- https://www.suse.com/security/cve/CVE-2025-22870
- https://www.suse.com/support/update/announcement/2025/suse-su-202520196-1/