5
5
replace github.com/fluxcd/helm-controller/api => ./api
6
6
7
7
require (
8
- github.com/fluxcd/helm-controller/api v0.17.1
8
+ github.com/fluxcd/helm-controller/api v0.17.2
9
9
github.com/fluxcd/pkg/apis/acl v0.0.3
10
10
github.com/fluxcd/pkg/apis/kustomize v0.3.1
11
11
github.com/fluxcd/pkg/apis/meta v0.10.2
@@ -16,26 +16,32 @@ require (
16
16
github.com/onsi/ginkgo v1.16.5
17
17
github.com/onsi/gomega v1.17.0
18
18
github.com/spf13/pflag v1.0.5
19
- github.com/yvasiyarov/go-metrics v0.0.0-20150112132944-c25f46c4b940 // indirect
20
- github.com/yvasiyarov/gorelic v0.0.7 // indirect
21
- github.com/yvasiyarov/newrelic_platform_go v0.0.0-20160601141957-9c099fbc30e9 // indirect
22
- golang.org/x/text v0.3.7 // indirect
23
- helm.sh/helm/v3 v3.8.0
24
- k8s.io/api v0.23.1
25
- k8s.io/apiextensions-apiserver v0.23.1
26
- k8s.io/apimachinery v0.23.1
27
- k8s.io/cli-runtime v0.23.1
28
- k8s.io/client-go v0.23.1
19
+ helm.sh/helm/v3 v3.8.1
20
+ k8s.io/api v0.23.4
21
+ k8s.io/apiextensions-apiserver v0.23.4
22
+ k8s.io/apimachinery v0.23.4
23
+ k8s.io/cli-runtime v0.23.4
24
+ k8s.io/client-go v0.23.4
29
25
sigs.k8s.io/controller-runtime v0.11.0
30
26
sigs.k8s.io/kustomize/api v0.10.1
31
27
sigs.k8s.io/yaml v1.3.0
32
28
)
33
29
34
- // Temporary fork of Helm v3.8.0 with patch applied from
35
- // https://github.com/helm/helm/pull/10486 to solve memory leak and issues as
36
- // described in https://github.com/fluxcd/helm-controller/issues/351.
37
- // TODO: Remove once Helm v3.8.1 is released.
38
- replace helm.sh/helm/v3 v3.8.0 => github.com/hiddeco/helm/v3 v3.0.0-20220128105410-34ef0a7a5811
30
+ // Pin kustomize to v4.4.1
31
+ replace (
32
+ sigs.k8s.io/kustomize/api => sigs.k8s.io/kustomize/api v0.10.1
33
+ sigs.k8s.io/kustomize/kyaml => sigs.k8s.io/kustomize/kyaml v0.13.0
34
+ )
35
+
36
+ // Fix CVE-2021-30465
37
+ // Fix CVE-2021-43784
38
+ // Fix GO-2021-0085
39
+ // Fix GO-2021-0087
40
+ replace github.com/opencontainers/runc => github.com/opencontainers/runc v1.0.3
41
+
42
+ // Fix CVE-2021-43816
43
+ // Fix CVE-2022-23648
44
+ replace github.com/containerd/containerd => github.com/containerd/containerd v1.5.10
39
45
40
46
require (
41
47
cloud.google.com/go v0.99.0 // indirect
@@ -141,7 +147,8 @@ require (
141
147
golang.org/x/oauth2 v0.0.0-20211104180415-d3ed0bb246c8 // indirect
142
148
golang.org/x/sync v0.0.0-20210220032951-036812b2e83c // indirect
143
149
golang.org/x/sys v0.0.0-20211216021012-1d35b9e2eb4e // indirect
144
- golang.org/x/term v0.0.0-20210615171337-6886f2dfbf5b // indirect
150
+ golang.org/x/term v0.0.0-20210927222741-03fcf44c2211 // indirect
151
+ golang.org/x/text v0.3.7 // indirect
145
152
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac // indirect
146
153
gomodules.xyz/jsonpatch/v2 v2.2.0 // indirect
147
154
google.golang.org/appengine v1.6.7 // indirect
@@ -153,39 +160,14 @@ require (
153
160
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 // indirect
154
161
gopkg.in/yaml.v2 v2.4.0 // indirect
155
162
gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b // indirect
156
- k8s.io/apiserver v0.23.1 // indirect
157
- k8s.io/component-base v0.23.1 // indirect
163
+ k8s.io/apiserver v0.23.4 // indirect
164
+ k8s.io/component-base v0.23.4 // indirect
158
165
k8s.io/klog/v2 v2.30.0 // indirect
159
166
k8s.io/kube-openapi v0.0.0-20211115234752-e816edb12b65 // indirect
160
- k8s.io/kubectl v0.23.1 // indirect
167
+ k8s.io/kubectl v0.23.4 // indirect
161
168
k8s.io/utils v0.0.0-20211208161948-7d6a63dca704 // indirect
162
169
oras.land/oras-go v1.1.0 // indirect
163
170
sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2 // indirect
164
171
sigs.k8s.io/kustomize/kyaml v0.13.0 // indirect
165
- sigs.k8s.io/structured-merge-diff/v4 v4.2.0 // indirect
172
+ sigs.k8s.io/structured-merge-diff/v4 v4.2.1 // indirect
166
173
)
167
-
168
- // pin kustomize to v4.4.1
169
- replace (
170
- sigs.k8s.io/kustomize/api => sigs.k8s.io/kustomize/api v0.10.1
171
- sigs.k8s.io/kustomize/kyaml => sigs.k8s.io/kustomize/kyaml v0.13.0
172
- )
173
-
174
- // Fix CVE-2021-41092
175
- // Due to https://github.com/oras-project/oras-go/blob/v0.4.0/go.mod#L14
176
- // pulled in by Helm.
177
- replace github.com/docker/cli => github.com/docker/cli v20.10.9+incompatible
178
-
179
- // Fix CVE-2021-30465
180
- // Fix CVE-2021-43784
181
- // Fix GO-2021-0085
182
- // Fix GO-2021-0087
183
- replace github.com/opencontainers/runc => github.com/opencontainers/runc v1.0.3
184
-
185
- // Fix CVE-2021-41190
186
- // Due to https://github.com/oras-project/oras-go/blob/v0.4.0/go.mod#L21,
187
- // pulled in by Helm.
188
- replace github.com/opencontainers/image-spec => github.com/opencontainers/image-spec v1.0.2
189
-
190
- // Fix CVE-2021-43816
191
- replace github.com/containerd/containerd => github.com/containerd/containerd v1.5.9
0 commit comments