diff --git a/CHANGELOG.md b/CHANGELOG.md index 639c7768..846e9a3b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,27 @@ All notable changes to this project are documented in this file. +## 0.15.1 + +**Release date:** 2021-06-18 + +This prerelease updates the Helm dependency to `v3.6.1`, this update +is a security update and ensures credentials are only passed to the +defined URL in a `HelmRelease`. + +**Note:** there have been reports from the Helm user community that +this new behavior may cause issues with Helm repository providers +like Artifactory. If this happens to be a problem for you, the +behavior can be disabled by setting `PassCredentials` in the +`HelmRepositorySpec`. + +For more details, see: +https://github.com/helm/helm/security/advisories/GHSA-56hp-xqp3-w2jf + +Improvements: +* Update Helm to v3.6.1 + [#388](https://github.com/fluxcd/source-controller/pull/388) + ## 0.15.0 **Release date:** 2021-06-17 diff --git a/config/manager/kustomization.yaml b/config/manager/kustomization.yaml index 6c6ce5ee..9c58ba62 100644 --- a/config/manager/kustomization.yaml +++ b/config/manager/kustomization.yaml @@ -6,4 +6,4 @@ resources: images: - name: fluxcd/source-controller newName: fluxcd/source-controller - newTag: v0.15.0 + newTag: v0.15.1 diff --git a/go.mod b/go.mod index 2a40a99f..7efa687d 100644 --- a/go.mod +++ b/go.mod @@ -17,7 +17,7 @@ require ( github.com/fluxcd/pkg/ssh v0.1.0 github.com/fluxcd/pkg/untar v0.1.0 github.com/fluxcd/pkg/version v0.1.0 - github.com/fluxcd/source-controller/api v0.15.0 + github.com/fluxcd/source-controller/api v0.15.1 github.com/go-git/go-billy/v5 v5.3.1 github.com/go-git/go-git/v5 v5.4.2 github.com/go-logr/logr v0.4.0