Skip to content

Add GO-2026-5026 security fix to changelog#2118

Merged
TerryHowe merged 1 commit into
helm:mainfrom
Promptless:promptless/document-cve-2026-39821-fix
May 29, 2026
Merged

Add GO-2026-5026 security fix to changelog#2118
TerryHowe merged 1 commit into
helm:mainfrom
Promptless:promptless/document-cve-2026-39821-fix

Conversation

@promptless-for-oss

Copy link
Copy Markdown
Contributor

Open this suggestion in Promptless to view citations and reasoning process

Documents the golang.org/x/net security update (CVE-2026-39821) in the Helm 4 changelog for both the main branch (PR #32153) and dev-v3 backport (PR #32152).

Trigger Events


Tip: Tag @Promptless in GitHub PR comments to guide documentation changes during code review 🐙

Add entries for PRs #32153 (main) and #32152 (dev-v3) which bump
golang.org/x/net to v0.55.0 to address the GO-2026-5026 vulnerability.

Signed-off-by: promptless[bot] <promptless[bot]@users.noreply.github.com>
Comment thread docs/changelog.md

| PR | Date | Author | Title |
|---|---|---|---|
| #32153 | 2026-05-27 | TerryHowe | fix(deps): bump golang.org/x/net to v0.55.0 for GO-2026-5026 |

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added changelog entry for PR #32153 which bumps golang.org/x/net to v0.55.0 to fix GO-2026-5026 (CVE-2026-39821), a Punycode validation vulnerability in the idna package.

Source: helm/helm#32153

Comment thread docs/changelog.md

| PR | Date | Author | Title |
|---|---|---|---|
| #32152 | 2026-05-27 | TerryHowe | fix(deps): bump golang.org/x/net to v0.55.0 for GO-2026-5026 [dev-v3] |

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added changelog entry for PR #32152, the dev-v3 backport of the same GO-2026-5026 fix.

Source: helm/helm#32152

@promptless-for-oss

Copy link
Copy Markdown
Contributor Author

Just a reminder: If you'd like me to act on any feedback you have via Github comments, just type @Promptless in your suggestion and I'll get right on it! (I won't show up in the user dropdown, but I'll process any request that has @Promptless in the comment body.)

@TerryHowe TerryHowe left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@TerryHowe
TerryHowe merged commit c3fbab1 into helm:main May 29, 2026
3 checks passed
@promptless-for-oss
promptless-for-oss deleted the promptless/document-cve-2026-39821-fix branch May 29, 2026 16:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants