Skip to content

fix(deps): update all ungrouped dependencies#9345

Merged
moukoublen merged 1 commit intomainfrom
renovate/all-ungrouped-dependencies
Apr 14, 2026
Merged

fix(deps): update all ungrouped dependencies#9345
moukoublen merged 1 commit intomainfrom
renovate/all-ungrouped-dependencies

Conversation

@elastic-renovate-prod
Copy link
Copy Markdown
Contributor

@elastic-renovate-prod elastic-renovate-prod Bot commented Apr 13, 2026

This PR contains the following updates:

Package Type Update Change
cloud.google.com/go/storage require patch v1.62.0 -> v1.62.1
docker final minor 29.3.1-cli -> 29.4.0-cli
github.com/aws/aws-sdk-go-v2/service/s3 require minor v1.98.0 -> v1.99.0
github.com/google/go-containerregistry require patch v0.21.4 -> v0.21.5
golang.org/x/crypto require minor v0.49.0 -> v0.50.0
golang.org/x/net require minor v0.52.0 -> v0.53.0
google.golang.org/api require minor v0.274.0 -> v0.275.0
helm.sh/helm/v4 require patch v4.1.3 -> v4.1.4
registry.access.redhat.com/ubi9/ubi-minimal final patch 9.7-1773939694 -> 9.7-1776104705

Release Notes

google/go-containerregistry (github.com/google/go-containerregistry)

v0.21.5

Compare Source

What's Changed

Full Changelog: google/go-containerregistry@v0.21.4...v0.21.5

googleapis/google-api-go-client (google.golang.org/api)

v0.275.0

Compare Source

Features
helm/helm (helm.sh/helm/v4)

v4.1.4: Helm v4.1.4

Compare Source

Helm v4.1.4 is a security fix patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

  • Join the discussion in Kubernetes Slack:
    • for questions and just to hang out
    • for discussing PRs, code, and bugs
  • Hang out at the Public Developer Call: Thursday, 9:30 Pacific via Zoom
  • Test, debug, and contribute charts: ArtifactHub/packages

Security fixes

  • GHSA-hr2v-4r36-88hr Helm Chart extraction output directory collapse via Chart.yaml name dot-segment
  • GHSA-q5jf-9vfq-h4h7 Plugin verification fails open when .prov is missing, allowing unsigned plugin install
  • GHSA-vmx8-mqv2-9gmg Path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory

A big thank you to the reporters of these issues (@​maru1009, @​1seal).

Installation and Upgrading

Download Helm v4.1.4. The common platform binaries are here:

The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with bash.

What's Next

  • 4.1.5 and 3.20.3 are the next patch (bug fix) releases and will be on April 8, 2026
  • 4.2.0 and 3.21.0 are the next minor (feature) releases and will be on May 13, 2026

Changelog

  • fix: Plugin missing provenance bypass 05fa379 (George Jenkins)
  • fix: Chart dot-name path bug 4e7994d (George Jenkins)
  • ignore error plugin loads (cli, getter) 2581943 (George Jenkins)
  • fix: Plugin version path traversal 36c8539 (George Jenkins)
  • fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow c61e086 (Terry Howe)

Configuration

📅 Schedule: Branch creation - "after 1am on monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@elastic-renovate-prod elastic-renovate-prod Bot added the >renovate PRs created by or relating to Renovate label Apr 13, 2026
@elastic-renovate-prod
Copy link
Copy Markdown
Contributor Author

elastic-renovate-prod Bot commented Apr 13, 2026

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 9 additional dependencies were updated

Details:

Package Change
cloud.google.com/go/iam v1.6.0 -> v1.7.0
github.com/docker/cli v29.3.1+incompatible -> v29.4.0+incompatible
golang.org/x/mod v0.34.0 -> v0.35.0
golang.org/x/net v0.52.0 -> v0.53.0
golang.org/x/sys v0.42.0 -> v0.43.0
golang.org/x/term v0.41.0 -> v0.42.0
golang.org/x/text v0.35.0 -> v0.36.0
golang.org/x/tools v0.43.0 -> v0.44.0
google.golang.org/genproto/googleapis/api v0.0.0-20260401001100-f93e5f3e9f0f -> v0.0.0-20260401024825-9d38bb4040a9
File name: hack/helm/release/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 7 additional dependencies were updated

Details:

Package Change
cloud.google.com/go/iam v1.6.0 -> v1.7.0
golang.org/x/crypto v0.49.0 -> v0.50.0
golang.org/x/net v0.52.0 -> v0.53.0
golang.org/x/sys v0.42.0 -> v0.43.0
golang.org/x/term v0.41.0 -> v0.42.0
golang.org/x/text v0.35.0 -> v0.36.0
google.golang.org/genproto/googleapis/api v0.0.0-20260401001100-f93e5f3e9f0f -> v0.0.0-20260401024825-9d38bb4040a9
File name: hack/operatorhub/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 2 additional dependencies were updated

Details:

Package Change
github.com/docker/cli v29.3.1+incompatible -> v29.4.0+incompatible
golang.org/x/sys v0.42.0 -> v0.43.0

@elastic-renovate-prod elastic-renovate-prod Bot requested a review from a team as a code owner April 13, 2026 02:16
@prodsecmachine
Copy link
Copy Markdown
Collaborator

prodsecmachine commented Apr 13, 2026

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 13, 2026

🔍 Preview links for changed docs

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 13, 2026

Vale Linting Results

Summary: 1 warning found

⚠️ Warnings (1)
File Line Rule Message
docs/reference/third-party-dependencies/main.md 17 Elastic.BritishSpellings Use American English spelling 'license' instead of British English 'Licence'.

The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

@elastic-renovate-prod elastic-renovate-prod Bot force-pushed the renovate/all-ungrouped-dependencies branch from df6be70 to 0087376 Compare April 13, 2026 14:03
@elastic-renovate-prod elastic-renovate-prod Bot force-pushed the renovate/all-ungrouped-dependencies branch from 0087376 to 9c2206e Compare April 13, 2026 22:06
@moukoublen moukoublen merged commit 0b72d0d into main Apr 14, 2026
9 checks passed
@moukoublen moukoublen deleted the renovate/all-ungrouped-dependencies branch April 14, 2026 06:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

>renovate PRs created by or relating to Renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants