Compare commits

..
Author SHA1 Message Date
Renovate Bot ae698fcb79 chore(deps): update helm release prometheus to v29
AI Code Review / ai-review (pull_request) Skipped
scan.yaml / test (pull_request) Successful in 6s
renovate/stability-days Updates have met minimum release age requirement
2026-10-05 00:05:51 +00:00
7915346868 chore(deps): update gitea/gitea docker tag to v28 (#58)
scan.yaml / test (push) Successful in 8s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [gitea/gitea](https://github.com/go-gitea/gitea) | major | `1.27.3` → `28.0.0` |

---

### Release Notes

<details>
<summary>go-gitea/gitea (gitea/gitea)</summary>

### [`v28.0.0`](https://github.com/go-gitea/gitea/blob/HEAD/CHANGELOG.md#2800---2026-09-30)

[Compare Source](https://github.com/go-gitea/gitea/compare/v1.27.3...v28.0.0)

- BREAKING
  - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
  - Feat(actions)!: add RUN\_RETENTION\_DAYS to delete old action runs ([#&#8203;38855](https://github.com/go-gitea/gitea/pull/38855))

- SECURITY
  - Fix(git): reject invalid and duplicate Git objects on push ([#&#8203;39472](https://github.com/go-gitea/gitea/pull/39472))
  - Fix(git)!: route Git network operations through an internal proxy and update egress settings ([#&#8203;39426](https://github.com/go-gitea/gitea/pull/39426))
  - Fix(ssh): identify presented public keys by fingerprint ([#&#8203;39423](https://github.com/go-gitea/gitea/pull/39423))
  - Fix(actions): keep cancelled and unapproved fork PR runs behind the approval gate ([#&#8203;39399](https://github.com/go-gitea/gitea/pull/39399))
  - Fix(deps): update golang.org/x/crypto SSH to address denial of service ([#&#8203;39219](https://github.com/go-gitea/gitea/pull/39219))
  - Fix(repo): enforce repository-scoped authorization for team access, deletion, and package unlinking ([#&#8203;39063](https://github.com/go-gitea/gitea/pull/39063))

- FEATURES
  - Feat(actions): update actionslib, support `self:`, misc fixes ([#&#8203;39358](https://github.com/go-gitea/gitea/pull/39358))
  - Feat(api): list all packages for site administrators ([#&#8203;38968](https://github.com/go-gitea/gitea/pull/38968))
  - Feat: manage bot accounts from the admin UI, API and CLI ([#&#8203;38966](https://github.com/go-gitea/gitea/pull/38966))
  - Feat(user): Personal access tokens can be regenerated ([#&#8203;38907](https://github.com/go-gitea/gitea/pull/38907))
  - Feat(actions): support `$/` prefix in reusable workflow `uses:` ([#&#8203;38822](https://github.com/go-gitea/gitea/pull/38822))
  - Feat(actions): add force-cancel workflow run API ([#&#8203;38756](https://github.com/go-gitea/gitea/pull/38756))
  - Feat(licenses): support REUSE specification in licenses ([#&#8203;38720](https://github.com/go-gitea/gitea/pull/38720))
  - Feat(api): add project APIs ([#&#8203;38691](https://github.com/go-gitea/gitea/pull/38691))
  - Feat(webhook): fire repository event on repo rename ([#&#8203;38641](https://github.com/go-gitea/gitea/pull/38641))
  - Feat: admin impersonates a user ([#&#8203;38614](https://github.com/go-gitea/gitea/pull/38614))
  - Feat(actions): add build queue view ([#&#8203;38585](https://github.com/go-gitea/gitea/pull/38585))
  - Feat(setting): add shared \[redis] section as default for redis-backed subsystems ([#&#8203;38550](https://github.com/go-gitea/gitea/pull/38550))
  - Feat(repo): prioritize well-known READMEs and optimize discovery ([#&#8203;38532](https://github.com/go-gitea/gitea/pull/38532))
  - Feat(actions): implement adaptive auto-refresh for workflow runs list ([#&#8203;38329](https://github.com/go-gitea/gitea/pull/38329))
  - Feat(auth): add `disable-2fa` command ([#&#8203;38275](https://github.com/go-gitea/gitea/pull/38275))
  - Feat: Add audit logging ([#&#8203;38189](https://github.com/go-gitea/gitea/pull/38189))
  - Feat(repo): add quick repository switcher to repo header ([#&#8203;38188](https://github.com/go-gitea/gitea/pull/38188))
  - Feat(repo): support file exclusion logic in .gitea/template in template generation ([#&#8203;38064](https://github.com/go-gitea/gitea/pull/38064))
  - Feat(web): Add org removal functionality to admin user details page ([#&#8203;38013](https://github.com/go-gitea/gitea/pull/38013))
  - Feat: add watch options ([#&#8203;37571](https://github.com/go-gitea/gitea/pull/37571))
  - Feat: add deploy tokens ([#&#8203;37306](https://github.com/go-gitea/gitea/pull/37306))
  - Feat(diff): Add search and extension filter to diff sidebar ([#&#8203;37068](https://github.com/go-gitea/gitea/pull/37068))
  - Feat: Replace SSE with WebSocket for UI notifications ([#&#8203;36965](https://github.com/go-gitea/gitea/pull/36965))
  - Feat(actions): Add artifact preview in Actions run view ([#&#8203;36754](https://github.com/go-gitea/gitea/pull/36754))
  - Feat(packages): add support for uploading helm provenance files ([#&#8203;36695](https://github.com/go-gitea/gitea/pull/36695))
  - Feat: Add support for dynamic matrix evaluation in Gitea Actions workflows ([#&#8203;36564](https://github.com/go-gitea/gitea/pull/36564))
  - Feat: Add max-parallel Support for Gitea Actions ([#&#8203;36357](https://github.com/go-gitea/gitea/pull/36357))
  - Feat(actions): Add Actions API endpoints for workflow run management and logs ([#&#8203;35382](https://github.com/go-gitea/gitea/pull/35382))
  - Feat: Add block on pending codeowner reviews branch protection ([#&#8203;34995](https://github.com/go-gitea/gitea/pull/34995))

- ENHANCEMENTS
  - Enhance: allow auto-closing PRs from PRs ([#&#8203;39393](https://github.com/go-gitea/gitea/pull/39393))
  - Enhance(actions): add pending job status and align job statuses with GitHub ([#&#8203;39376](https://github.com/go-gitea/gitea/pull/39376))
  - Enhance(acme): add configurable ACME profile ([#&#8203;39375](https://github.com/go-gitea/gitea/pull/39375))
  - Enhance(emoji): update to Unicode 17, unify and lazy-load emoji data ([#&#8203;39363](https://github.com/go-gitea/gitea/pull/39363))
  - Enhance: improve issue-pattern capture groups and support both internal\&external trackers enabled ([#&#8203;39354](https://github.com/go-gitea/gitea/pull/39354))
  - Enhance: update mermaid to v12 ([#&#8203;39331](https://github.com/go-gitea/gitea/pull/39331))
  - Enhance(notifications): mark current notification page as read ([#&#8203;39294](https://github.com/go-gitea/gitea/pull/39294))
  - Enhance: support `ETag` on streamed repository archives, support `If-None-Match: *` ([#&#8203;39289](https://github.com/go-gitea/gitea/pull/39289))
  - Enhance: truncate but show long lines in diffs ([#&#8203;39279](https://github.com/go-gitea/gitea/pull/39279))
  - Enhance(packages): implement npm single-version API and add per-version repository ([#&#8203;39267](https://github.com/go-gitea/gitea/pull/39267))
  - Enhance: move window\.config to JSON, improve CSP format ([#&#8203;39236](https://github.com/go-gitea/gitea/pull/39236))
  - Enhance: improve commit page header ([#&#8203;39229](https://github.com/go-gitea/gitea/pull/39229))
  - Enhance: Improve validation errors for secrets/variables ([#&#8203;39221](https://github.com/go-gitea/gitea/pull/39221))
  - Enhance(repo): check full repo name for dangerous operations ([#&#8203;39213](https://github.com/go-gitea/gitea/pull/39213))
  - Enhance(web): hide attachment dropzone on preview tab in combo editor ([#&#8203;39204](https://github.com/go-gitea/gitea/pull/39204))
  - Enhance(web): show attachment URL and UUID in dropzone preview ([#&#8203;39203](https://github.com/go-gitea/gitea/pull/39203))
  - Enhance(actions): make workflow dispatch choice dropdown support search ([#&#8203;39154](https://github.com/go-gitea/gitea/pull/39154))
  - Enhance(repo): unify diff stats on commit pages, misc diff tweaks ([#&#8203;39134](https://github.com/go-gitea/gitea/pull/39134))
  - Enhance: use browser's locale to detect week's first day for the contribution map ([#&#8203;38995](https://github.com/go-gitea/gitea/pull/38995))
  - Enhance(ui): forced colors mode enhancements ([#&#8203;38991](https://github.com/go-gitea/gitea/pull/38991))
  - Enhance: user-friendly packages setup manual ([#&#8203;38946](https://github.com/go-gitea/gitea/pull/38946))
  - Enhance: inherit team access for all units ([#&#8203;38938](https://github.com/go-gitea/gitea/pull/38938))
  - Enhance(admin): show impersonation banner and keep password change with the user ([#&#8203;38924](https://github.com/go-gitea/gitea/pull/38924))
  - Enhance(ui): tint toast backgrounds by level ([#&#8203;38919](https://github.com/go-gitea/gitea/pull/38919))
  - Enhance(repo): add default object format setting ([#&#8203;38877](https://github.com/go-gitea/gitea/pull/38877))
  - Enhance(actions): set ref\_protected in context ([#&#8203;38852](https://github.com/go-gitea/gitea/pull/38852))
  - Enhance(ui): restyle toasts ([#&#8203;38842](https://github.com/go-gitea/gitea/pull/38842))
  - Enhance: refine repo watching ([#&#8203;38835](https://github.com/go-gitea/gitea/pull/38835))
  - Enhance: fall back to DEFAULT\_TEMPLATE.md when style-specific template is missing ([#&#8203;38803](https://github.com/go-gitea/gitea/pull/38803))
  - Enhance(api): add GitHub-compatible /repos/{owner}/{repo}/commits/{ref} endpoint ([#&#8203;38770](https://github.com/go-gitea/gitea/pull/38770))
  - Enhance(api): expose file mode in contents API response ([#&#8203;38713](https://github.com/go-gitea/gitea/pull/38713))
  - Enhance(tls): use go's tls defaults ([#&#8203;38687](https://github.com/go-gitea/gitea/pull/38687))
  - Enhance(ui): improve luminance calculations ([#&#8203;38682](https://github.com/go-gitea/gitea/pull/38682))
  - Enhance(api): add `tag_filter` query parameter to release list API ([#&#8203;38681](https://github.com/go-gitea/gitea/pull/38681))
  - Enhance(actions): replace `ansi_up` with first-party code ([#&#8203;38619](https://github.com/go-gitea/gitea/pull/38619))
  - Enhance: keep status check list scrolled on merge box reload ([#&#8203;38597](https://github.com/go-gitea/gitea/pull/38597))
  - Enhance(actions): action view enhancements ([#&#8203;38594](https://github.com/go-gitea/gitea/pull/38594))
  - Enhance(ui): tweak tooltip style and misc fixes ([#&#8203;38524](https://github.com/go-gitea/gitea/pull/38524))
  - Enhance: improve e-mail templates ([#&#8203;38396](https://github.com/go-gitea/gitea/pull/38396))
  - Enhance(webhook): add reviewer name to MS Teams review request notifications ([#&#8203;38289](https://github.com/go-gitea/gitea/pull/38289))
  - Enhance: extend <video> tag allowed attributes ([#&#8203;38279](https://github.com/go-gitea/gitea/pull/38279))
  - Enhance(packages/npm): expand version metadata and support npm deprecate ([#&#8203;37890](https://github.com/go-gitea/gitea/pull/37890))

- PERFORMANCE
  - Perf(references): scan only the keyword window before a reference ([#&#8203;39396](https://github.com/go-gitea/gitea/pull/39396))
  - Perf(frontend): enable vite module preload ([#&#8203;39332](https://github.com/go-gitea/gitea/pull/39332))
  - Perf(gitdiff): optimize inline diff highlighting using cache ([#&#8203;38706](https://github.com/go-gitea/gitea/pull/38706))

- BUGFIXES
  - Fix(actions): preserve admitted jobs and runs in their concurrency group ([#&#8203;39461](https://github.com/go-gitea/gitea/pull/39461))
  - Fix(api): commit tree SHA is the commit ID ([#&#8203;39449](https://github.com/go-gitea/gitea/pull/39449))
  - Fix: PR merge ([#&#8203;39442](https://github.com/go-gitea/gitea/pull/39442))
  - Fix(actions): evaluate job-level `if:` before concurrency check ([#&#8203;39437](https://github.com/go-gitea/gitea/pull/39437))
  - Fix(api): allow pending-inline-comment-only reviews ([#&#8203;39433](https://github.com/go-gitea/gitea/pull/39433))
  - Fix: sanitize external render command line arguments ([#&#8203;39417](https://github.com/go-gitea/gitea/pull/39417))
  - Fix(LFS): recalculate repo LFSSize after gc-lfs removes orphaned data ([#&#8203;39406](https://github.com/go-gitea/gitea/pull/39406))
  - Fix(indexer): index full file paths and real offsets in bleve ([#&#8203;39405](https://github.com/go-gitea/gitea/pull/39405))
  - Fix(git): keep leading dashes in git grep search patterns ([#&#8203;39404](https://github.com/go-gitea/gitea/pull/39404))
  - Fix: use clearer message for ldap auth failure ([#&#8203;39392](https://github.com/go-gitea/gitea/pull/39392))
  - Fix(repo): commit page fails to render unsigned commits with a different committer ([#&#8203;39381](https://github.com/go-gitea/gitea/pull/39381))
  - Fix: focus confirm button and use red for delete confirmations ([#&#8203;39350](https://github.com/go-gitea/gitea/pull/39350))
  - Fix(migrations): preserve SHA-256 pull request commit IDs ([#&#8203;39343](https://github.com/go-gitea/gitea/pull/39343))
  - Fix(ui): misc ui fixes ([#&#8203;39336](https://github.com/go-gitea/gitea/pull/39336))
  - Fix(actions): use gitea's clock for actions durations ([#&#8203;39323](https://github.com/go-gitea/gitea/pull/39323))
  - Fix(actions): never show negative running durations ([#&#8203;39322](https://github.com/go-gitea/gitea/pull/39322))
  - Fix: package registry keypair creation race ([#&#8203;39319](https://github.com/go-gitea/gitea/pull/39319))
  - Fix: add default timeout and handle errors for HaveIBeenPwned API ([#&#8203;39316](https://github.com/go-gitea/gitea/pull/39316))
  - Fix(user): unify email validation for registration and settings ([#&#8203;39304](https://github.com/go-gitea/gitea/pull/39304))
  - Fix(ui): use button elements for branch and tag dropdown tabs ([#&#8203;39285](https://github.com/go-gitea/gitea/pull/39285))
  - Fix(auth): fix ssh and gpg key verification on windows ([#&#8203;39283](https://github.com/go-gitea/gitea/pull/39283))
  - Fix(feed): use meaningful lines as comment excerpt ([#&#8203;39276](https://github.com/go-gitea/gitea/pull/39276))
  - Fix(projects): allow max columns to the limit ([#&#8203;39272](https://github.com/go-gitea/gitea/pull/39272))
  - Fix: pass merge commit messages to git via stdin ([#&#8203;39269](https://github.com/go-gitea/gitea/pull/39269))
  - Fix(repo): surface unrelated histories on Sync Fork ([#&#8203;39258](https://github.com/go-gitea/gitea/pull/39258))
  - Fix: avoid nil panic and refactor some trivial problems ([#&#8203;39251](https://github.com/go-gitea/gitea/pull/39251))
  - Fix: restore missing blob file when re-publishing a package ([#&#8203;39239](https://github.com/go-gitea/gitea/pull/39239))
  - Fix(automerge): validate head commit before merge ([#&#8203;39235](https://github.com/go-gitea/gitea/pull/39235))
  - Fix(httplib): prevent leaking localhost:3000 in public links ([#&#8203;39217](https://github.com/go-gitea/gitea/pull/39217))
  - Fix(setting): honor bare -1 for timeout settings ([#&#8203;39181](https://github.com/go-gitea/gitea/pull/39181))
  - Fix: correct repo/attatchment absolute url and release layout ([#&#8203;39178](https://github.com/go-gitea/gitea/pull/39178))
  - Fix(web): populate the reason for "cannot commit to branch" in web editor commit form ([#&#8203;39155](https://github.com/go-gitea/gitea/pull/39155))
  - Fix(process): reap entire process group on cmd.Cancel ([#&#8203;39143](https://github.com/go-gitea/gitea/pull/39143))
  - Fix: recognize linguist language aliases ([#&#8203;39135](https://github.com/go-gitea/gitea/pull/39135))
  - Fix(repo): preserve transfer recipient collaboration ([#&#8203;39042](https://github.com/go-gitea/gitea/pull/39042))
  - Fix(db): make paginated database reads always require "order" option ([#&#8203;39017](https://github.com/go-gitea/gitea/pull/39017))
  - Fix: make local queue PopItem can be notified ([#&#8203;39011](https://github.com/go-gitea/gitea/pull/39011))
  - Fix: classify git failures on stderr, restrict migration failure detail ([#&#8203;39010](https://github.com/go-gitea/gitea/pull/39010))
  - Fix: allow re-requesting uncounted review approvals ([#&#8203;38988](https://github.com/go-gitea/gitea/pull/38988))
  - Fix(actions): allow larger scheduled workflows ([#&#8203;38985](https://github.com/go-gitea/gitea/pull/38985))
  - Fix: resolve actions commit status permission per repository ([#&#8203;38977](https://github.com/go-gitea/gitea/pull/38977))
  - Fix(deps): update module golang.org/x/image to v0.45.0 \[security] ([#&#8203;38930](https://github.com/go-gitea/gitea/pull/38930))
  - Fix(deps): update module golang.org/x/mod to v0.40.0 \[security] ([#&#8203;38914](https://github.com/go-gitea/gitea/pull/38914))
  - Fix: dedupe issue cross-reference timeline entries ([#&#8203;38881](https://github.com/go-gitea/gitea/pull/38881))
  - Fix(server): set `ReadHeaderTimeout` on HTTP servers ([#&#8203;38878](https://github.com/go-gitea/gitea/pull/38878))
  - Fix(repo): avoid a repo-sized temp file for every bundle download ([#&#8203;38863](https://github.com/go-gitea/gitea/pull/38863))
  - Fix(lfs): ensure lock listing paginates with a total order ([#&#8203;38850](https://github.com/go-gitea/gitea/pull/38850))
  - Fix(avatar): use sha256 and inline the federated avatar lookup ([#&#8203;38843](https://github.com/go-gitea/gitea/pull/38843))
  - Fix(gitdiff): render exact-limit diffs and zero-limit comments ([#&#8203;38838](https://github.com/go-gitea/gitea/pull/38838))
  - Fix(deps): update dependency mermaid to v11.16.1 \[security] ([#&#8203;38813](https://github.com/go-gitea/gitea/pull/38813))
  - Fix: misc fixes in pub/gpg/tests ([#&#8203;38809](https://github.com/go-gitea/gitea/pull/38809))
  - Fix: git diff blob excerpt ([#&#8203;38808](https://github.com/go-gitea/gitea/pull/38808))
  - Fix(packages): show error for duplicate cleanup rules [#&#8203;37820](https://github.com/go-gitea/gitea/issues/37820) ([#&#8203;38786](https://github.com/go-gitea/gitea/pull/38786))
  - Fix(actions): fix runner docs link ([#&#8203;38783](https://github.com/go-gitea/gitea/pull/38783))
  - Fix: git cache ([#&#8203;38763](https://github.com/go-gitea/gitea/pull/38763))
  - Fix(actions): evaluate each `${{ }}` part on its own ([#&#8203;38754](https://github.com/go-gitea/gitea/pull/38754))
  - Fix: don't report failed network requests as JavaScript errors ([#&#8203;38732](https://github.com/go-gitea/gitea/pull/38732))
  - Fix(gitdiff): prevent index out of range panic in GetLineTypeMarker ([#&#8203;38728](https://github.com/go-gitea/gitea/pull/38728))
  - Fix(api): document X-Total-Count instead of non-existent X-Total header ([#&#8203;38717](https://github.com/go-gitea/gitea/pull/38717))
  - Fix(actions): dynamic matrix expansion correctness fixes ([#&#8203;38690](https://github.com/go-gitea/gitea/pull/38690))
  - Fix(auth): record last sign-in on reverse proxy login ([#&#8203;38672](https://github.com/go-gitea/gitea/pull/38672))
  - Fix(api): accept fully-qualified refs in contents API ([#&#8203;38650](https://github.com/go-gitea/gitea/pull/38650))
  - Fix(deps): update module github.com/getkin/kin-openapi to v0.144.0 \[security] ([#&#8203;38623](https://github.com/go-gitea/gitea/pull/38623))
  - Fix(deps): update dependency js-yaml to v5.2.2 \[security] ([#&#8203;38622](https://github.com/go-gitea/gitea/pull/38622))
  - Fix: abort superseded issue suggestion requests ([#&#8203;38620](https://github.com/go-gitea/gitea/pull/38620))
  - Fix(issue): display error toast on batch action failures instead of reloading page ([#&#8203;38593](https://github.com/go-gitea/gitea/pull/38593))
  - Fix(deps): update module google.golang.org/grpc to v1.82.1 \[security] ([#&#8203;38567](https://github.com/go-gitea/gitea/pull/38567))
  - Fix(deps): update module github.com/google/go-github/v88 to v89 ([#&#8203;38433](https://github.com/go-gitea/gitea/pull/38433))
  - Fix(deps): update go dependencies ([#&#8203;38429](https://github.com/go-gitea/gitea/pull/38429))
  - Fix(deps): update go dependencies ([#&#8203;38346](https://github.com/go-gitea/gitea/pull/38346))
  - Fix(deps): update npm dependencies ([#&#8203;38342](https://github.com/go-gitea/gitea/pull/38342))
  - Fix(base): correct natural sort of numbers with leading zeros ([#&#8203;38163](https://github.com/go-gitea/gitea/pull/38163))
  - Fix(ui): avoid layout shifts in `overflow-menu` and repo filter ([#&#8203;37818](https://github.com/go-gitea/gitea/pull/37818))
  - Fix: make auth source group sync correctly handle team removal ([#&#8203;37161](https://github.com/go-gitea/gitea/pull/37161))
  - Fix(release): separate publication time from the release date ([#&#8203;36761](https://github.com/go-gitea/gitea/pull/36761))

- TESTING
  - Test: stop tests from writing into `~/.ssh` ([#&#8203;39348](https://github.com/go-gitea/gitea/pull/39348))
  - Test(e2e): log out to switch users in pr-review test ([#&#8203;39328](https://github.com/go-gitea/gitea/pull/39328))
  - Test: release fixtures loader lock before database work ([#&#8203;39263](https://github.com/go-gitea/gitea/pull/39263))
  - Test: speed up tests, fix transaction bug ([#&#8203;39030](https://github.com/go-gitea/gitea/pull/39030))
  - Test: run frontend unit tests in browsers ([#&#8203;38860](https://github.com/go-gitea/gitea/pull/38860))
  - Test(pubsub): stop racing the Redis SUBSCRIBE ack ([#&#8203;38661](https://github.com/go-gitea/gitea/pull/38661))
  - Test(e2e): add pull request merge box test, update AGENTS.md ([#&#8203;38576](https://github.com/go-gitea/gitea/pull/38576))
  - Test(e2e): deterministically wait for event stream in logout propagation test ([#&#8203;38535](https://github.com/go-gitea/gitea/pull/38535))

- BUILD
  - Refactor: fix `go vet` errors related to composite literals ([#&#8203;39341](https://github.com/go-gitea/gitea/pull/39341))
  - Build(gogit): disable gogit builds for stable releases ([#&#8203;39324](https://github.com/go-gitea/gitea/pull/39324))
  - Refactor: replace jquery.are-you-sure with first-party code ([#&#8203;39233](https://github.com/go-gitea/gitea/pull/39233))
  - Refactor: http request binding ([#&#8203;38971](https://github.com/go-gitea/gitea/pull/38971))
  - Refactor: clean up git repo and model migration packages ([#&#8203;38564](https://github.com/go-gitea/gitea/pull/38564))
  - Refactor: prepare to decouple the "model migration" package and "models" package ([#&#8203;38533](https://github.com/go-gitea/gitea/pull/38533))
  - Build: fix snapcraft release ([#&#8203;38260](https://github.com/go-gitea/gitea/pull/38260))
  - Build(release): use native golang toolchain for official release builds ([#&#8203;37828](https://github.com/go-gitea/gitea/pull/37828))

- DOCS
  - Docs(webhook): review\.type comment lists values the webhook never sends ([#&#8203;39451](https://github.com/go-gitea/gitea/pull/39451))
  - Docs(api): document verification and files on the compare endpoint ([#&#8203;39440](https://github.com/go-gitea/gitea/pull/39440))
  - Docs(api): name the unadopted-repository search parameter query ([#&#8203;39370](https://github.com/go-gitea/gitea/pull/39370))
  - Docs: remove unused COOKIE\_USERNAME from app.example.ini ([#&#8203;39365](https://github.com/go-gitea/gitea/pull/39365))
  - Docs: document NOTICE\_ON\_SUCCESS for every cron task ([#&#8203;39352](https://github.com/go-gitea/gitea/pull/39352))
  - Docs: correct ALLOW\_LOCALNETWORKS description in app.example.ini ([#&#8203;39240](https://github.com/go-gitea/gitea/pull/39240))
  - Docs: fix typo in README about app.ini restart ([#&#8203;39223](https://github.com/go-gitea/gitea/pull/39223))
  - Docs: fix dead localization doc link in the READMEs ([#&#8203;39211](https://github.com/go-gitea/gitea/pull/39211))
  - Docs: Update CHANGELOG for release 1.27.3 ([#&#8203;39170](https://github.com/go-gitea/gitea/pull/39170))
  - Docs: Update CHANGELOG for version 1.27.2 ([#&#8203;38923](https://github.com/go-gitea/gitea/pull/38923))
  - Docs: Update PGP key expiration date to July 23, 2027 ([#&#8203;38747](https://github.com/go-gitea/gitea/pull/38747))
  - Docs(api): document 401/403 responses for user key endpoints ([#&#8203;38711](https://github.com/go-gitea/gitea/pull/38711))
  - Docs: Update Changelog for release v1.27.1 ([#&#8203;38670](https://github.com/go-gitea/gitea/pull/38670))
  - Docs: Update Changelog for 1.27 ([#&#8203;38440](https://github.com/go-gitea/gitea/pull/38440))
  - Docs: Update Security docs ([#&#8203;38422](https://github.com/go-gitea/gitea/pull/38422))

- MISC
  - Refactor: make git http respond error message ([#&#8203;39390](https://github.com/go-gitea/gitea/pull/39390))
  - Refactor(api): convert bot accounts through the admin user edit endpoint ([#&#8203;39355](https://github.com/go-gitea/gitea/pull/39355))
  - Refactor: replace AWS SDK with a REST client for CodeCommit migration ([#&#8203;39330](https://github.com/go-gitea/gitea/pull/39330))
  - Refactor: replace Azure Blob SDK with a REST client ([#&#8203;39315](https://github.com/go-gitea/gitea/pull/39315))
  - Refactor: npm route handlers ([#&#8203;39275](https://github.com/go-gitea/gitea/pull/39275))
  - Refactor: GetDiffShortStat and fix panic caused by inconsistent "changed file number" ([#&#8203;39248](https://github.com/go-gitea/gitea/pull/39248))
  - Refactor(templates): update djlint to 1.46.0 and resolve its new findings ([#&#8203;39231](https://github.com/go-gitea/gitea/pull/39231))
  - Refactor: pagination/pager ([#&#8203;39162](https://github.com/go-gitea/gitea/pull/39162))
  - Refactor: share package registry error status classification ([#&#8203;39133](https://github.com/go-gitea/gitea/pull/39133))
  - Refactor: drop two unmaintained dependencies, rename the byte size helpers ([#&#8203;39083](https://github.com/go-gitea/gitea/pull/39083))
  - Refactor(automerge): fix error handling, populate recent automerge tasks on restart ([#&#8203;39001](https://github.com/go-gitea/gitea/pull/39001))
  - Refactor: deploy key and private route handlers ([#&#8203;38999](https://github.com/go-gitea/gitea/pull/38999))
  - Refactor: wiki edit form ([#&#8203;38918](https://github.com/go-gitea/gitea/pull/38918))
  - Refactor: clean up form binding & validation ([#&#8203;38873](https://github.com/go-gitea/gitea/pull/38873))
  - Refactor: markup render ([#&#8203;38864](https://github.com/go-gitea/gitea/pull/38864))
  - Refactor: api token scope check ([#&#8203;38862](https://github.com/go-gitea/gitea/pull/38862))
  - Refactor: replace `gliderlabs/ssh` with `golang.org/x/crypto/ssh` ([#&#8203;38837](https://github.com/go-gitea/gitea/pull/38837))
  - Refactor: form binding validation ([#&#8203;38832](https://github.com/go-gitea/gitea/pull/38832))
  - Refactor: prepare vue components for vapor mode ([#&#8203;38798](https://github.com/go-gitea/gitea/pull/38798))
  - Refactor: use the shared workflow model from actionslib ([#&#8203;38768](https://github.com/go-gitea/gitea/pull/38768))
  - Refactor(modelmigration): thread context through migration functions ([#&#8203;38758](https://github.com/go-gitea/gitea/pull/38758))
  - Refactor: migrate remaining Vue components to `<script setup>` ([#&#8203;38752](https://github.com/go-gitea/gitea/pull/38752))
  - Refactor: introduce trString for frontend ([#&#8203;38741](https://github.com/go-gitea/gitea/pull/38741))
  - Refactor(diff): drive diff DOM init from the global selector observer ([#&#8203;38740](https://github.com/go-gitea/gitea/pull/38740))
  - Refactor(git): clarify GetBranch behavior to make it only gets an existing branch ([#&#8203;38662](https://github.com/go-gitea/gitea/pull/38662))
  - Refactor: replace debounce/throttle deps with first-party code ([#&#8203;38610](https://github.com/go-gitea/gitea/pull/38610))
  - Refactor: hide git repo path details from more packages ([#&#8203;38601](https://github.com/go-gitea/gitea/pull/38601))
  - Refactor: retry file remove/rename when a file is busy and clean up os detection ([#&#8203;38588](https://github.com/go-gitea/gitea/pull/38588))
  - Perf(emoji): optimize FindEmojiSubmatchIndex using slice-based Trie ([#&#8203;38573](https://github.com/go-gitea/gitea/pull/38573))
  - Refactor: implement mcaptcha client and add comments/tests ([#&#8203;38561](https://github.com/go-gitea/gitea/pull/38561))
  - Refactor: use WithRepo instead of WithDir for most git operations, clean up model migrations ([#&#8203;38555](https://github.com/go-gitea/gitea/pull/38555))
  - Refactor: remove Path field from git.Repository ([#&#8203;38552](https://github.com/go-gitea/gitea/pull/38552))
  - Refactor: make git package handle all git operations ([#&#8203;38543](https://github.com/go-gitea/gitea/pull/38543))
  - Refactor: remove unnecessary git command wrapper functions ([#&#8203;38531](https://github.com/go-gitea/gitea/pull/38531))
  - Refactor: git repo and relative path handling ([#&#8203;38522](https://github.com/go-gitea/gitea/pull/38522))
  - Refactor: clean up fragile diff render templates, use backend typed structs ([#&#8203;38517](https://github.com/go-gitea/gitea/pull/38517))
  - Refactor: correct git repo design and fix some legacy problems ([#&#8203;38512](https://github.com/go-gitea/gitea/pull/38512))
  - Refactor: fix legacy problems in cmd/serv.go ([#&#8203;38505](https://github.com/go-gitea/gitea/pull/38505))
  - Refactor: remove Ctx field from git.Repository ([#&#8203;38500](https://github.com/go-gitea/gitea/pull/38500))
  - Refactor: decouple git.Repository(ctx) from git.Commit & git.Tree ([#&#8203;38464](https://github.com/go-gitea/gitea/pull/38464))
  - Refactor: introduce ActivePageTimer to help to do partial page refresh ([#&#8203;38372](https://github.com/go-gitea/gitea/pull/38372))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/58
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-04 21:53:01 +00:00
840c354ea3 chore(deps): update terraform azurerm to v5 (#55)
scan.yaml / test (push) Successful in 7s
This PR contains the following updates:

| Package | Type | Update | Change | Pending |
|---|---|---|---|---|
| [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` |

---

### Release Notes

<details>
<summary>hashicorp/terraform-provider-azurerm (azurerm)</summary>

### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0)

FEATURES:

- **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#&#8203;33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313))
- **New List Resource**: `azurerm_windows_virtual_machine` ([#&#8203;33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332))

ENHANCEMENTS:

- dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#&#8203;33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495))
- dependencies: `network` - update API version to `2025-07-01` ([#&#8203;33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441))
- Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#&#8203;33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316))
- Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#&#8203;33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204))
- Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#&#8203;33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193))
- Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#&#8203;33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300))
- Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#&#8203;33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318))
- Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#&#8203;33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346))
- Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#&#8203;33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373))
- `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))
- `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#&#8203;33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463))

BUG FIXES:

- Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#&#8203;33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488))
- `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#&#8203;33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082))

### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0)

FEATURES:

- **New List Resource**: `azurerm_batch_account` ([#&#8203;33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252))
- **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#&#8203;33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334))
- **New Resource**: `azurerm_storage_discovery_workspace` ([#&#8203;31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479))

ENHANCEMENTS:

- dependencies: `containers` - update API version to `2026-05-01` ([#&#8203;32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688))
- dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#&#8203;33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413))
- dependencies: `qumulo` - update API version to `2026-04-16` ([#&#8203;33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421))
- dependencies: `servicebus` - update to API version `2026-01-01` ([#&#8203;33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450))
- `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#&#8203;33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448))
- `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#&#8203;33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168))
- `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#&#8203;33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457))
- `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))
- `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#&#8203;31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135))

BUG FIXES:

- `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#&#8203;33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424))

### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0)

FEATURES:

- **New List Resource**: `azurerm_analysis_services_server` ([#&#8203;33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250))
- **New List Resource**: `azurerm_application_insights_workbook` ([#&#8203;33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244))
- **New List Resource**: `azurerm_attestation_provider` ([#&#8203;33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251))
- **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#&#8203;33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307))
- **New List Resource**: `azurerm_eventhub_consumer_group` ([#&#8203;33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335))
- **New List Resource**: `azurerm_linux_virtual_machine` ([#&#8203;33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333))
- **New List Resource**: `azurerm_virtual_hub_connection` ([#&#8203;33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311))

ENHANCEMENTS:

- dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))
- `azurerm_private_endpoint` - lock on private service connection resource ids ([#&#8203;33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298))
- `azurerm_storage_account` - add support for the `public_network_access` property ([#&#8203;33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292))

BUG FIXES:

- `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#&#8203;33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339))
- `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#&#8203;33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274))

### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0)

FEATURES:

- **New List Resource**: `azurerm_application_insights_standard_web_test` ([#&#8203;33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243))
- **New List Resource**: `azurerm_application_insights_workbook_template` ([#&#8203;33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245))
- **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#&#8203;33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247))
- **New List Resource**: `azurerm_availability_set` ([#&#8203;33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241))
- **New List Resource**: `azurerm_batch_application` ([#&#8203;33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254))
- **New List Resource**: `azurerm_dedicated_host_group` ([#&#8203;33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257))
- **New List Resource**: `azurerm_log_analytics_workspace` ([#&#8203;33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259))

ENHANCEMENTS:

- dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
- dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
- dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#&#8203;33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195))
- dependencies: `netapp` - update API version to `2026-05-01` ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
- Data Source: `azurerm_api_management_workspace` - export the `description` property ([#&#8203;33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205))
- Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#&#8203;33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125))
- Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
- Data Source: `azurerm_automation_account` - export the `encryption` block ([#&#8203;33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135))
- Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#&#8203;33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190))
- Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#&#8203;33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191))
- `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#&#8203;32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690))
- `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#&#8203;32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645))
- `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))
- `azurerm_linux_web_app` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
- `azurerm_linux_web_app_slot` - add support for the `8.5` value in the  `site_config.application_stack.php_version` property ([#&#8203;33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308))
- `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#&#8203;33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215))
- `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#&#8203;32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121))
- `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#&#8203;33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236))
- `azurerm_storage_table` - add support for AAD authentication ([#&#8203;32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997))
- `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))
- `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#&#8203;30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328))

BUG FIXES:

- `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#&#8203;33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258))

### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0)

FEATURES:

- **New Data Source**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
- **New List Resource**: `azurerm_cognitive_deployment` ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
- **New List Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))
- **New Resource**: `azurerm_playwright_workspace` ([#&#8203;31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954))

ENHANCEMENTS:

- dependencies: `go-azure-helpers` - update version to `0.82.0` ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))
- dependencies: `sql` - update API version to `2025-01-01` ([#&#8203;33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201))
- Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#&#8203;33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126))
- `azurerm_cognitive_deployment` - add Resource Identity support ([#&#8203;33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149))
- `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#&#8203;32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935))
- `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#&#8203;33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222))
- `azurerm_managed_application` - add support for the `identity` block ([#&#8203;30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725))
- `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#&#8203;32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887))
- `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#&#8203;33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069))
- `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#&#8203;33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140))
- `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#&#8203;33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142))

BUG FIXES:

- Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#&#8203;33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182))
- `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#&#8203;33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216))

### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0)

FEATURES:

- **New List Resource**: `azurerm_user_assigned_identity` ([#&#8203;32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667))

ENHANCEMENTS:

- dependencies: `go` - update to `1.26.6` ([#&#8203;33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141))
- dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#&#8203;33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079))
- `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#&#8203;33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023))
- `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
- `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
- `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#&#8203;33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116))
- `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#&#8203;32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092))
- `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
- `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#&#8203;32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473))
- `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#&#8203;32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714))
- `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#&#8203;32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834))

BUG FIXES:

- `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#&#8203;33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151))
- `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#&#8203;33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136))
- `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#&#8203;33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011))

### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0)

ENHANCEMENTS:

- dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#&#8203;31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586))
- dependencies: `codesigning` - update to API version `2025-10-13` ([#&#8203;31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714))
- `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
- `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
- `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#&#8203;32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753))
- `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))
- `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#&#8203;32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885))

BUG FIXES:

- `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
- `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980))
- `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#&#8203;32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982))
- `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#&#8203;32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798))
- `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create  ([#&#8203;33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071))
- `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978))
- `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#&#8203;32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979))
- `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075))

### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1)

NOTES:

In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated.

BUG FIXES:

- `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#&#8203;32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912))
- `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914))
- `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#&#8203;32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929))

### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026)

[Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0)

NOTES:

- **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide).
- When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)).

FEATURES:

- **New Action**: `azurerm_web_app_set_slot_distribution` ([#&#8203;32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364))
- **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#&#8203;32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881))

ENHANCEMENTS:

- dependencies: `grpc` update to `1.82.1` ([#&#8203;32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852))
- dependencies: `loadbalancers` - update to API version `2025-01-01` ([#&#8203;32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644))
- `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#&#8203;32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100))
- `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#&#8203;32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752))
- `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#&#8203;32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777))
- `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#&#8203;32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562))
- `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_subnet` - export the `network_security_group_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_subnet` - export the `route_table_id` property ([#&#8203;32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847))
- `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
- `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#&#8203;32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840))
- `cdn` - migrate to `go-azure-sdk` ([#&#8203;32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849))
- `sentinel` - migrate to `go-azure-sdk` ([#&#8203;32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759))

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-03 18:55:31 +00:00
0f0082d54d chore(deps): update helm release fluent-bit to v0.58.3 (#57)
scan.yaml / test (push) Successful in 7s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [fluent-bit](https://fluentbit.io/) ([source](https://github.com/fluent/helm-charts)) | patch | `0.58.2` → `0.58.3` |

---

### Release Notes

<details>
<summary>fluent/helm-charts (fluent-bit)</summary>

### [`v0.58.3`](https://github.com/fluent/helm-charts/releases/tag/fluent-bit-0.58.3)

[Compare Source](https://github.com/fluent/helm-charts/compare/fluent-bit-0.58.2...fluent-bit-0.58.3)

##### Changed

- Update *Fluent Bit* OCI image to [v5.1.3](https://github.com/fluent/fluent-bit/releases/tag/v5.1.3). ([#&#8203;759](https://github.com/fluent/helm-charts/pull/759)) [@&#8203;stevehipwell](https://github.com/stevehipwell)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #57
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-03 18:55:02 +00:00
jorgen.stensrudandClaude Opus 5.5 4a4b8e3540 feat(keycloak): forte-cli device-code client + forte-drop-mcp audience mapper (#44)
scan.yaml / test (push) Successful in 5s
Adds the shared public forte-cli client (RFC 8628 device-code only) to the forte realm, with an oidc-audience-mapper that puts https://mcp.drop.forteapps.net/mcp into aud so the forte-drop-mcp sidecar accepts its tokens. Supersedes #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-01 11:25:34 +00:00
60b8fa657a chore(deps): update nikitafilonov/ai-review docker tag to v1 (#53)
scan.yaml / test (push) Successful in 8s
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| nikitafilonov/ai-review | docker | major | `v0.77.0` → `v1.1.0` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #53
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-10-01 09:40:57 +00:00
c940259545 chore(deps): update helm release opencost to v2 (#50)
scan.yaml / test (push) Successful in 5s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [opencost](https://github.com/opencost/opencost-helm-chart) | major | `1.43.2` → `2.5.32` |

---

### Release Notes

<details>
<summary>opencost/opencost-helm-chart (opencost)</summary>

### [`v2.5.32`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.32)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32)

OpenCost and OpenCost UI

#### What's Changed

- Upgrade OpenCost Helm Chart to v1.121.3 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;385](https://github.com/opencost/opencost-helm-chart/pull/385)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.31...opencost-2.5.32>

### [`v2.5.31`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.31)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31)

OpenCost and OpenCost UI

#### What's Changed

- Release OpenCost v1.121.2 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;384](https://github.com/opencost/opencost-helm-chart/pull/384)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.30...opencost-2.5.31>

### [`v2.5.30`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.30)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30)

OpenCost and OpenCost UI

#### What's Changed

- feat: add opencost.exporter.extraEnvFrom to source env from ConfigMap/Secret by [@&#8203;ahauserv](https://github.com/ahauserv) in [#&#8203;378](https://github.com/opencost/opencost-helm-chart/pull/378)

#### New Contributors

- [@&#8203;ahauserv](https://github.com/ahauserv) made their first contribution in [#&#8203;378](https://github.com/opencost/opencost-helm-chart/pull/378)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.29...opencost-2.5.30>

### [`v2.5.29`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.29)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29)

OpenCost and OpenCost UI

#### What's Changed

- Release OpenCost v1.121.1 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;377](https://github.com/opencost/opencost-helm-chart/pull/377)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.28...opencost-2.5.29>

### [`v2.5.28`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.28)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28)

OpenCost and OpenCost UI

#### What's Changed

- Inference Cost params added to helm by [@&#8203;simanadler](https://github.com/simanadler) in [#&#8203;370](https://github.com/opencost/opencost-helm-chart/pull/370)
- Release OpenCost v1.121.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;372](https://github.com/opencost/opencost-helm-chart/pull/372)

#### New Contributors

- [@&#8203;simanadler](https://github.com/simanadler) made their first contribution in [#&#8203;370](https://github.com/opencost/opencost-helm-chart/pull/370)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.27...opencost-2.5.28>

### [`v2.5.27`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.27)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27)

OpenCost and OpenCost UI

#### What's Changed

- KCM-5392: Add support for configuring external labels for Opencost installation with Collector data source by [@&#8203;avrodrigues5](https://github.com/avrodrigues5) in [#&#8203;371](https://github.com/opencost/opencost-helm-chart/pull/371)

#### New Contributors

- [@&#8203;avrodrigues5](https://github.com/avrodrigues5) made their first contribution in [#&#8203;371](https://github.com/opencost/opencost-helm-chart/pull/371)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.26...opencost-2.5.27>

### [`v2.5.26`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.26)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.25...opencost-2.5.26)

OpenCost and OpenCost UI

#### What's Changed

- add timeout configuration for override in probes by [@&#8203;aman-kumar29](https://github.com/aman-kumar29) in [#&#8203;369](https://github.com/opencost/opencost-helm-chart/pull/369)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.3.0...opencost-2.5.26>

### [`v2.5.25`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.25)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25)

OpenCost and OpenCost UI

#### What's Changed

- Release OpenCost v1.120.4 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;366](https://github.com/opencost/opencost-helm-chart/pull/366)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.24...opencost-2.5.25>

### [`v2.5.24`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.24)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24)

OpenCost and OpenCost UI

#### What's Changed

- fix(service): use opencost.exporter.debugPort for service targetPort by [@&#8203;aman-kumar29](https://github.com/aman-kumar29) in [#&#8203;364](https://github.com/opencost/opencost-helm-chart/pull/364)

#### New Contributors

- [@&#8203;aman-kumar29](https://github.com/aman-kumar29) made their first contribution in [#&#8203;364](https://github.com/opencost/opencost-helm-chart/pull/364)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.23...opencost-2.5.24>

### [`v2.5.23`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.23)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23)

OpenCost and OpenCost UI

#### What's Changed

- feat(gateway-api): Add support for filters by [@&#8203;HartmannVolker](https://github.com/HartmannVolker) in [#&#8203;356](https://github.com/opencost/opencost-helm-chart/pull/356)

#### New Contributors

- [@&#8203;HartmannVolker](https://github.com/HartmannVolker) made their first contribution in [#&#8203;356](https://github.com/opencost/opencost-helm-chart/pull/356)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.22...opencost-2.5.23>

### [`v2.5.22`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.22)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22)

OpenCost and OpenCost UI

#### What's Changed

- Release OpenCost v1.120.3 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;357](https://github.com/opencost/opencost-helm-chart/pull/357)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.21...opencost-2.5.22>

### [`v2.5.21`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.21)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21)

OpenCost and OpenCost UI

#### What's Changed

- feat: add extraObjects for tpl-rendered extra manifests by [@&#8203;younsl](https://github.com/younsl) in [#&#8203;354](https://github.com/opencost/opencost-helm-chart/pull/354)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.20...opencost-2.5.21>

### [`v2.5.20`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.20)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20)

OpenCost and OpenCost UI

#### What's Changed

- Update Helm chart for v1.120.2 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;355](https://github.com/opencost/opencost-helm-chart/pull/355)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.19...opencost-2.5.20>

### [`v2.5.19`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.19)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19)

OpenCost and OpenCost UI

#### What's Changed

- Consistent Usage of `opencost.namespace` Helper by [@&#8203;ioboi](https://github.com/ioboi) in [#&#8203;353](https://github.com/opencost/opencost-helm-chart/pull/353)

#### New Contributors

- [@&#8203;ioboi](https://github.com/ioboi) made their first contribution in [#&#8203;353](https://github.com/opencost/opencost-helm-chart/pull/353)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.18...opencost-2.5.19>

### [`v2.5.18`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.18)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18)

OpenCost and OpenCost UI

#### What's Changed

- feat: Add plugins.install.plugins list and existingSecret support (adopts [#&#8203;328](https://github.com/opencost/opencost-helm-chart/issues/328)) by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;344](https://github.com/opencost/opencost-helm-chart/pull/344)
- feat: add OCI cloud cost configuration example to cloudIntegrationJSON by [@&#8203;Kush172005](https://github.com/Kush172005) in [#&#8203;345](https://github.com/opencost/opencost-helm-chart/pull/345)
- Release Opencost v1.120.1 - Bump Helm Chart by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;347](https://github.com/opencost/opencost-helm-chart/pull/347)
- Fix UI route tls by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;352](https://github.com/opencost/opencost-helm-chart/pull/352)

#### New Contributors

- [@&#8203;Kush172005](https://github.com/Kush172005) made their first contribution in [#&#8203;345](https://github.com/opencost/opencost-helm-chart/pull/345)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.14...opencost-2.5.18>

### [`v2.5.14`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.14)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14)

OpenCost and OpenCost UI

#### What's Changed

- Release Opencost v1.120.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;341](https://github.com/opencost/opencost-helm-chart/pull/341)
- Cdp/opencost v1.120.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;343](https://github.com/opencost/opencost-helm-chart/pull/343)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.12...opencost-2.5.14>

### [`v2.5.12`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.12)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12)

OpenCost and OpenCost UI

#### What's Changed

- Create Empty /var/configs dir by [@&#8203;HMetcalfeW](https://github.com/HMetcalfeW) in [#&#8203;333](https://github.com/opencost/opencost-helm-chart/pull/333)

#### New Contributors

- [@&#8203;HMetcalfeW](https://github.com/HMetcalfeW) made their first contribution in [#&#8203;333](https://github.com/opencost/opencost-helm-chart/pull/333)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.11...opencost-2.5.12>

### [`v2.5.11`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.11)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11)

OpenCost and OpenCost UI

#### What's Changed

- add admin token infra support by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;339](https://github.com/opencost/opencost-helm-chart/pull/339)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.10...opencost-2.5.11>

### [`v2.5.10`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.10)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10)

OpenCost and OpenCost UI

#### What's Changed

- Add cloudIntegrationJSON support by [@&#8203;thomasvn](https://github.com/thomasvn) in [#&#8203;337](https://github.com/opencost/opencost-helm-chart/pull/337)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.9...opencost-2.5.10>

### [`v2.5.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.9)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9)

OpenCost and OpenCost UI

#### What's Changed

- Fix collectorDataSource retention env var conditions by [@&#8203;dag-andersen](https://github.com/dag-andersen) in [#&#8203;336](https://github.com/opencost/opencost-helm-chart/pull/336)

#### New Contributors

- [@&#8203;dag-andersen](https://github.com/dag-andersen) made their first contribution in [#&#8203;336](https://github.com/opencost/opencost-helm-chart/pull/336)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.8...opencost-2.5.9>

### [`v2.5.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.8)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8)

OpenCost and OpenCost UI

#### What's Changed

- Opencost v1.119.2 Changes by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;334](https://github.com/opencost/opencost-helm-chart/pull/334)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.7...opencost-2.5.8>

### [`v2.5.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.7)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7)

OpenCost and OpenCost UI

#### What's Changed

- fix: fix csv export condition in deployment by [@&#8203;meroupatate](https://github.com/meroupatate) in [#&#8203;330](https://github.com/opencost/opencost-helm-chart/pull/330)

#### New Contributors

- [@&#8203;meroupatate](https://github.com/meroupatate) made their first contribution in [#&#8203;330](https://github.com/opencost/opencost-helm-chart/pull/330)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.6...opencost-2.5.7>

### [`v2.5.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.6)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6)

OpenCost and OpenCost UI

#### What's Changed

- Do not grant permissions on nodes/proxy by default by [@&#8203;Farenjihn](https://github.com/Farenjihn) in [#&#8203;329](https://github.com/opencost/opencost-helm-chart/pull/329)

#### New Contributors

- [@&#8203;Farenjihn](https://github.com/Farenjihn) made their first contribution in [#&#8203;329](https://github.com/opencost/opencost-helm-chart/pull/329)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.5...opencost-2.5.6>

### [`v2.5.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.5)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5)

OpenCost and OpenCost UI

#### What's Changed

- Add PRICING\_CONFIGMAP\_NAME env to achnowledge configmapName helm value by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;316](https://github.com/opencost/opencost-helm-chart/pull/316)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.4...opencost-2.5.5>

### [`v2.5.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.4)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4)

OpenCost and OpenCost UI

#### What's Changed

- feat(opencost): add Gateway API HTTPRoute support by [@&#8203;younsl](https://github.com/younsl) in [#&#8203;322](https://github.com/opencost/opencost-helm-chart/pull/322)

#### New Contributors

- [@&#8203;younsl](https://github.com/younsl) made their first contribution in [#&#8203;322](https://github.com/opencost/opencost-helm-chart/pull/322)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.3...opencost-2.5.4>

### [`v2.5.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.3)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3)

OpenCost and OpenCost UI

#### What's Changed

- Add configurable nginx proxy timeouts to helm chart by [@&#8203;peatey](https://github.com/peatey) in [#&#8203;326](https://github.com/opencost/opencost-helm-chart/pull/326)

#### New Contributors

- [@&#8203;peatey](https://github.com/peatey) made their first contribution in [#&#8203;326](https://github.com/opencost/opencost-helm-chart/pull/326)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.2...opencost-2.5.3>

### [`v2.5.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.2)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2)

OpenCost and OpenCost UI

#### What's Changed

- Update cloud-integration secret path by [@&#8203;thomasvn](https://github.com/thomasvn) in [#&#8203;324](https://github.com/opencost/opencost-helm-chart/pull/324)

#### New Contributors

- [@&#8203;thomasvn](https://github.com/thomasvn) made their first contribution in [#&#8203;324](https://github.com/opencost/opencost-helm-chart/pull/324)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.1...opencost-2.5.2>

### [`v2.5.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.1)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1)

OpenCost and OpenCost UI

#### What's Changed

- Release Opencost v1.119.1 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;325](https://github.com/opencost/opencost-helm-chart/pull/325)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.5.0...opencost-2.5.1>

### [`v2.5.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.5.0)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0)

OpenCost and OpenCost UI

#### What's Changed

- Release Opencost v1.119.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;323](https://github.com/opencost/opencost-helm-chart/pull/323)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.1...opencost-2.5.0>

### [`v2.4.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.1)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1)

OpenCost and OpenCost UI

#### What's Changed

- fix: mcp disable procedure by [@&#8203;marijus-ravickas](https://github.com/marijus-ravickas) in [#&#8203;319](https://github.com/opencost/opencost-helm-chart/pull/319)

#### New Contributors

- [@&#8203;marijus-ravickas](https://github.com/marijus-ravickas) made their first contribution in [#&#8203;319](https://github.com/opencost/opencost-helm-chart/pull/319)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.4.0...opencost-2.4.1>

### [`v2.4.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.4.0)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0)

OpenCost and OpenCost UI

#### What's Changed

- added-mcp-config by [@&#8203;sneaxhuh](https://github.com/sneaxhuh) in [#&#8203;311](https://github.com/opencost/opencost-helm-chart/pull/311)
- Update Opencost to v1.118.0 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;314](https://github.com/opencost/opencost-helm-chart/pull/314)

#### New Contributors

- [@&#8203;sneaxhuh](https://github.com/sneaxhuh) made their first contribution in [#&#8203;311](https://github.com/opencost/opencost-helm-chart/pull/311)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.2...opencost-2.4.0>

### [`v2.3.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.2)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2)

OpenCost and OpenCost UI

#### What's Changed

- fix: use default sc when sc name not specified by [@&#8203;cwyl02](https://github.com/cwyl02) in [#&#8203;312](https://github.com/opencost/opencost-helm-chart/pull/312)

#### New Contributors

- [@&#8203;cwyl02](https://github.com/cwyl02) made their first contribution in [#&#8203;312](https://github.com/opencost/opencost-helm-chart/pull/312)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.1...opencost-2.3.2>

### [`v2.3.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.1)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1)

OpenCost and OpenCost UI

#### What's Changed

- feat: Add option to use cm to set CLUSTER\_ID envvar by [@&#8203;gracedo](https://github.com/gracedo) in [#&#8203;307](https://github.com/opencost/opencost-helm-chart/pull/307)

#### New Contributors

- [@&#8203;gracedo](https://github.com/gracedo) made their first contribution in [#&#8203;307](https://github.com/opencost/opencost-helm-chart/pull/307)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.3.0...opencost-2.3.1>

### [`v2.3.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.3.0)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0)

OpenCost and OpenCost UI

#### What's Changed

- Add configs to mount custom ca certs to opencost container by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;303](https://github.com/opencost/opencost-helm-chart/pull/303)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.9...opencost-2.3.0>

### [`v2.2.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.9)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9)

OpenCost and OpenCost UI

#### What's Changed

- Add chart installation notes by [@&#8203;dejanu](https://github.com/dejanu) in [#&#8203;305](https://github.com/opencost/opencost-helm-chart/pull/305)
- Release Opencost v1.117.6 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;309](https://github.com/opencost/opencost-helm-chart/pull/309)

#### New Contributors

- [@&#8203;dejanu](https://github.com/dejanu) made their first contribution in [#&#8203;305](https://github.com/opencost/opencost-helm-chart/pull/305)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.8...opencost-2.2.9>

### [`v2.2.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.8)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8)

OpenCost and OpenCost UI

#### What's Changed

- Release Opencost v1.117.5 by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;306](https://github.com/opencost/opencost-helm-chart/pull/306)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.7...opencost-2.2.8>

### [`v2.2.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.7)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7)

OpenCost and OpenCost UI

#### What's Changed

- Add uiPath configuration for OpenCost UI by [@&#8203;gustavo-sdo](https://github.com/gustavo-sdo) in [#&#8203;298](https://github.com/opencost/opencost-helm-chart/pull/298)

#### New Contributors

- [@&#8203;gustavo-sdo](https://github.com/gustavo-sdo) made their first contribution in [#&#8203;298](https://github.com/opencost/opencost-helm-chart/pull/298)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.6...opencost-2.2.7>

### [`v2.2.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.6)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6)

OpenCost and OpenCost UI

#### What's Changed

- Dodizzle/proxy fix by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;301](https://github.com/opencost/opencost-helm-chart/pull/301)
- allow: set path for internal prometheus by [@&#8203;dodizzle](https://github.com/dodizzle) in [#&#8203;271](https://github.com/opencost/opencost-helm-chart/pull/271)

#### New Contributors

- [@&#8203;dodizzle](https://github.com/dodizzle) made their first contribution in [#&#8203;271](https://github.com/opencost/opencost-helm-chart/pull/271)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.5...opencost-2.2.6>

### [`v2.2.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.5)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5)

OpenCost and OpenCost UI

#### What's Changed

- Release v1.117.3 of Opencost by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;300](https://github.com/opencost/opencost-helm-chart/pull/300)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.4...opencost-2.2.5>

### [`v2.2.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.4)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4)

OpenCost and OpenCost UI

#### What's Changed

- Release v1.117.2 of Opencost by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;299](https://github.com/opencost/opencost-helm-chart/pull/299)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.3...opencost-2.2.4>

### [`v2.2.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.3)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3)

OpenCost and OpenCost UI

#### What's Changed

- Update env var names and values by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;297](https://github.com/opencost/opencost-helm-chart/pull/297)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.2...opencost-2.2.3>

### [`v2.2.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.2)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2)

OpenCost and OpenCost UI

#### What's Changed

- Advance to Opencost v1.117.0 by [@&#8203;mbolt35](https://github.com/mbolt35) in [#&#8203;296](https://github.com/opencost/opencost-helm-chart/pull/296)

#### New Contributors

- [@&#8203;mbolt35](https://github.com/mbolt35) made their first contribution in [#&#8203;296](https://github.com/opencost/opencost-helm-chart/pull/296)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.1...opencost-2.2.2>

### [`v2.2.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.1)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1)

OpenCost and OpenCost UI

#### What's Changed

- Add `insecureSkipVerify` to `prometheus.external`  by [@&#8203;charleshu-8](https://github.com/charleshu-8) in [#&#8203;294](https://github.com/opencost/opencost-helm-chart/pull/294)

#### New Contributors

- [@&#8203;charleshu-8](https://github.com/charleshu-8) made their first contribution in [#&#8203;294](https://github.com/opencost/opencost-helm-chart/pull/294)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.2.0...opencost-2.2.1>

### [`v2.2.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.2.0)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0)

OpenCost and OpenCost UI

#### What's Changed

- Bump image tags and chart version by [@&#8203;cpetersen5](https://github.com/cpetersen5) in [#&#8203;291](https://github.com/opencost/opencost-helm-chart/pull/291)

#### New Contributors

- [@&#8203;cpetersen5](https://github.com/cpetersen5) made their first contribution in [#&#8203;291](https://github.com/opencost/opencost-helm-chart/pull/291)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.9...opencost-2.2.0>

### [`v2.1.9`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.9)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9)

OpenCost and OpenCost UI

#### What's Changed

- Change ETL env variable name by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;285](https://github.com/opencost/opencost-helm-chart/pull/285)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.8...opencost-2.1.9>

### [`v2.1.8`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.8)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8)

OpenCost and OpenCost UI

#### What's Changed

- tweak params by [@&#8203;ameijer](https://github.com/ameijer) in [#&#8203;289](https://github.com/opencost/opencost-helm-chart/pull/289)
- add option to override the default container command by [@&#8203;nishanthreddydd](https://github.com/nishanthreddydd) in [#&#8203;290](https://github.com/opencost/opencost-helm-chart/pull/290)

#### New Contributors

- [@&#8203;nishanthreddydd](https://github.com/nishanthreddydd) made their first contribution in [#&#8203;290](https://github.com/opencost/opencost-helm-chart/pull/290)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.7...opencost-2.1.8>

### [`v2.1.7`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.7)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7)

OpenCost and OpenCost UI

#### What's Changed

- (doc) update readme to easily install unittest by [@&#8203;karthik-suresh](https://github.com/karthik-suresh) in [#&#8203;284](https://github.com/opencost/opencost-helm-chart/pull/284)
- Add ability to configure resolution for prometheus by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;282](https://github.com/opencost/opencost-helm-chart/pull/282)
- Add support for Pod Disruption Budget by [@&#8203;josephteddick](https://github.com/josephteddick) in [#&#8203;287](https://github.com/opencost/opencost-helm-chart/pull/287)

#### New Contributors

- [@&#8203;karthik-suresh](https://github.com/karthik-suresh) made their first contribution in [#&#8203;284](https://github.com/opencost/opencost-helm-chart/pull/284)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.6...opencost-2.1.7>

### [`v2.1.6`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.6)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6)

OpenCost and OpenCost UI

#### What's Changed

- feat(sec) - customize service account mounting by [@&#8203;cpsmx](https://github.com/cpsmx) in [#&#8203;283](https://github.com/opencost/opencost-helm-chart/pull/283)

#### New Contributors

- [@&#8203;cpsmx](https://github.com/cpsmx) made their first contribution in [#&#8203;283](https://github.com/opencost/opencost-helm-chart/pull/283)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.5...opencost-2.1.6>

### [`v2.1.5`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.5)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5)

OpenCost and OpenCost UI

#### What's Changed

- Update opencost ui 1.115.0 image by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;281](https://github.com/opencost/opencost-helm-chart/pull/281)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.4...opencost-2.1.5>

### [`v2.1.4`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.4)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4)

OpenCost and OpenCost UI

#### What's Changed

- Bump OC to 1.115.0 by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;277](https://github.com/opencost/opencost-helm-chart/pull/277)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.3...opencost-2.1.4>

### [`v2.1.3`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.3)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3)

OpenCost and OpenCost UI

#### What's Changed

- Promless Config by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;275](https://github.com/opencost/opencost-helm-chart/pull/275)
- Add values examples and notes to values.yaml. Update version numbers by [@&#8203;Sean-Holcomb](https://github.com/Sean-Holcomb) in [#&#8203;276](https://github.com/opencost/opencost-helm-chart/pull/276)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.2...opencost-2.1.3>

### [`v2.1.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.2)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.1...opencost-2.1.2)

OpenCost and OpenCost UI

#### What's Changed

- Add support for API Ingress by [@&#8203;josephteddick](https://github.com/josephteddick) in [#&#8203;255](https://github.com/opencost/opencost-helm-chart/pull/255)

#### New Contributors

- [@&#8203;josephteddick](https://github.com/josephteddick) made their first contribution in [#&#8203;255](https://github.com/opencost/opencost-helm-chart/pull/255)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-parquet-exporter-0.2.0...opencost-2.1.2>

### [`v2.1.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.1)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1)

OpenCost and OpenCost UI

#### What's Changed

- Fix for [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272) to make feature flag actually work. by [@&#8203;tintii](https://github.com/tintii) in [#&#8203;274](https://github.com/opencost/opencost-helm-chart/pull/274)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.1.0...opencost-2.1.1>

### [`v2.1.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.1.0)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0)

OpenCost and OpenCost UI

#### What's Changed

- Openshift Security Context Constraints and updated ClusterRole with access to internal prometheus. by [@&#8203;v0nNemizez](https://github.com/v0nNemizez) in [#&#8203;267](https://github.com/opencost/opencost-helm-chart/pull/267)

#### New Contributors

- [@&#8203;v0nNemizez](https://github.com/v0nNemizez) made their first contribution in [#&#8203;267](https://github.com/opencost/opencost-helm-chart/pull/267)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.2...opencost-2.1.0>

### [`v2.0.2`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.2)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2)

OpenCost and OpenCost UI

#### What's Changed

- Add opencost.ui.useIPv6 feature flag by [@&#8203;tintii](https://github.com/tintii) in [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272)

#### New Contributors

- [@&#8203;tintii](https://github.com/tintii) made their first contribution in [#&#8203;272](https://github.com/opencost/opencost-helm-chart/pull/272)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.1...opencost-2.0.2>

### [`v2.0.1`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.1)

[Compare Source](https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1)

OpenCost and OpenCost UI

#### What's Changed

- add sha256sums of configMaps to trigger a restart of the pod, if the configMap changes by [@&#8203;kastl-ars](https://github.com/kastl-ars) in [#&#8203;264](https://github.com/opencost/opencost-helm-chart/pull/264)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/opencost-2.0.0...opencost-2.0.1>

### [`v2.0.0`](https://github.com/opencost/opencost-helm-chart/releases/tag/opencost-2.0.0)

OpenCost and OpenCost UI

#### What's Changed

- add seperate openshift block to handle openshift related configurations and add frontend nginx config by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;245](https://github.com/opencost/opencost-helm-chart/pull/245)
- Updating chart badge by [@&#8203;TheUnixRoot](https://github.com/TheUnixRoot) in [#&#8203;261](https://github.com/opencost/opencost-helm-chart/pull/261)
- Fix: Chart release script by [@&#8203;mittal-ishaan](https://github.com/mittal-ishaan) in [#&#8203;262](https://github.com/opencost/opencost-helm-chart/pull/262)

#### New Contributors

- [@&#8203;TheUnixRoot](https://github.com/TheUnixRoot) made their first contribution in [#&#8203;261](https://github.com/opencost/opencost-helm-chart/pull/261)

**Full Changelog**: <https://github.com/opencost/opencost-helm-chart/compare/1.45.0-helm...opencost-2.0.0>

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJicmVha2luZy1jaGFuZ2UiLCJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/50
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-30 08:36:32 +00:00
danijel.simeunovic 407b06831f bump submodule
scan.yaml / test (push) Successful in 14s
2026-09-30 10:35:10 +02:00
danijel.simeunovic 3b8ec25c43 bump submodule
scan.yaml / test (push) Successful in 1m22s
2026-09-30 10:26:18 +02:00
danijel.simeunovic 3358950b34 format error
scan.yaml / test (push) Successful in 16s
2026-09-30 08:01:32 +00:00
danijel.simeunovic b2db9cd909 review with sonnet 5.5
scan.yaml / test (push) Successful in 18s
2026-09-30 08:00:59 +00:00
4d406c0223 chore(deps): update dependency kubernetes-helm to v4 (#48)
scan.yaml / test (push) Successful in 11s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [kubernetes-helm](https://github.com/helm/helm) | major | `3.20.2` → `4.2.4` |

---

### Release Notes

<details>
<summary>helm/helm (kubernetes-helm)</summary>

### [`v4.2.4`](https://github.com/helm/helm/releases/tag/v4.2.4): Helm v4.2.4

Helm v4.2.4 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom-lfx.platform.linuxfoundation.org/meeting/91295593969?password=17825db5-c698-44cc-9f00-ef1f61f5d3fb)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- fix: Improve error reporting for helm template --debug with --show-only- [#&#8203;31185](https://github.com/helm/helm/issues/31185) by [@&#8203;kyokuping](https://github.com/kyokuping)
- fix: fetch logs from all containers in test pods- [#&#8203;32099](https://github.com/helm/helm/issues/32099) by [@&#8203;SebTardif](https://github.com/SebTardif)
- fix(provenance): check error return in Digest and encodeRelease- [#&#8203;32136](https://github.com/helm/helm/issues/32136) by [@&#8203;SebTardif](https://github.com/SebTardif)
- fix panic on repeated IsReachable calls- [#&#8203;32184](https://github.com/helm/helm/issues/32184) by [@&#8203;atkrad](https://github.com/atkrad)
- fix: set \[pull,push] scope when helm push to a registry(use token auth) - v4- [#&#8203;31211](https://github.com/helm/helm/issues/31211) by [@&#8203;kimsungmin1](https://github.com/kimsungmin1)
- Fix missing conflict retry with server-side apply- [#&#8203;32088](https://github.com/helm/helm/issues/32088) by [@&#8203;Kajot-dev](https://github.com/Kajot-dev)
- Properly format the extra field in gzipped packages- [#&#8203;31884](https://github.com/helm/helm/issues/31884) by [@&#8203;ouillie](https://github.com/ouillie)
- Fix vanishing empty lines- [#&#8203;32327](https://github.com/helm/helm/issues/32327) by [@&#8203;matheuscscp](https://github.com/matheuscscp)
- fix: pass registry client to downloader.Manager in upgrade- [#&#8203;32400](https://github.com/helm/helm/issues/32400) by [@&#8203;SetagGnaw](https://github.com/SetagGnaw)
- chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1- for GO-2026-6061 [#&#8203;32450](https://github.com/helm/helm/issues/32450)
- fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158- [#&#8203;32521](https://github.com/helm/helm/issues/32521) by [@&#8203;TerryHowe](https://github.com/TerryHowe)

#### Installation and Upgrading

Download Helm v4.2.4. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.4-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-darwin-amd64.tar.gz.sha256sum) / 6c163d687ca03c3b5c01928e53bbbcf9518278f47ce7a2f249a5a08e8bdaa2bc)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.4-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-darwin-arm64.tar.gz.sha256sum) / d747eb4e28bd2727173d15b759fa0a17822291ec09db7ced3d55af290a3661a2)
- [Linux amd64](https://get.helm.sh/helm-v4.2.4-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-amd64.tar.gz.sha256sum) / c306b46f719b0a4da32d0f78ee21bf90ce8d602f15b22ab753f0674d1670a7f3)
- [Linux arm](https://get.helm.sh/helm-v4.2.4-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-arm.tar.gz.sha256sum) / 894e901f7daaf9b458baad7b5c685bfeef49070d7d53f99687bd5846a6c13639)
- [Linux arm64](https://get.helm.sh/helm-v4.2.4-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-arm64.tar.gz.sha256sum) / 564de2191b881e9f71b5606b25345821ea1682f06ab90499d3ab22b530176da1)
- [Linux i386](https://get.helm.sh/helm-v4.2.4-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-386.tar.gz.sha256sum) / 45297aeac0c65173a89e8de832997f952ba5115c2db09b2e3f2c23a601e70583)
- [Linux loong64](https://get.helm.sh/helm-v4.2.4-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-loong64.tar.gz.sha256sum) / faafbfecc1a06196e650c3ce0c74d5ac32cb1c0c0a855fa76e59dd100cb8d4c4)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.4-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-ppc64le.tar.gz.sha256sum) / 5c00073e9d493de201384bb7eb19d60615bd7c39db52148473e8ce6da84bc70a)
- [Linux s390x](https://get.helm.sh/helm-v4.2.4-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-s390x.tar.gz.sha256sum) / 5396a35fca5fa46e5614140363f389ce66f96886c1b25f256d9e3028299422fa)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.4-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.4-linux-riscv64.tar.gz.sha256sum) / d8532a3524ca842887b15ab794377dc9c8ced8f26264c84171b4b0aafff05411)
- [Windows amd64](https://get.helm.sh/helm-v4.2.4-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.4-windows-amd64.zip.sha256sum) / e94d83a4706fd82078c98dade2079fa9d9680c1c2bfb93bfc304ee6bc2412a32)
- [Windows arm64](https://get.helm.sh/helm-v4.2.4-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.4-windows-arm64.zip.sha256sum) / dbe8b49ea9877abe3d77354a792efb01920da9f65a492fcb8b4fce4e08bbae8f)

This release was signed with `208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155` and can be found at [@&#8203;scottrigby](https://github.com/scottrigby) [keybase account](https://keybase.io/r6by). Please use the attached signatures for verifying this release using `gpg`.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- Minimal fix to build failure from [#&#8203;31211](https://github.com/helm/helm/issues/31211). [`3900f43`](https://github.com/helm/helm/commit/3900f434fd3ef2b84065dc04508df48f288dba00) (Scott Rigby)
- fix: bump go.opentelemetry.io/otel to v1.44.0 for GO-2026-5158 ([#&#8203;32521](https://github.com/helm/helm/issues/32521)) [`f7c6e8f`](https://github.com/helm/helm/commit/f7c6e8f0f1e0e649e8d03b1535db4f3b8d0c9af2) (Terry Howe)
- chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 [`035a2c3`](https://github.com/helm/helm/commit/035a2c38e9a75ca0988c8449c0b7257f30d04064) (dependabot\[bot])
- fix: pass registry client to downloader.Manager in upgrade [`f76a5f4`](https://github.com/helm/helm/commit/f76a5f46a952f731cc1543f348121297c8b3f6cc) (Gates Wang)
- Apply suggestions [`5a7c6c7`](https://github.com/helm/helm/commit/5a7c6c7c732b04ad6517b452d538da9e18993d67) (Will Noble)
- Properly format the extra field in gzipped packages [`2281848`](https://github.com/helm/helm/commit/22818486ce0fc18d92e01ba39faf65f70ffa8865) (Will Noble)
- Fix missing conflict retry with server-side apply ([#&#8203;32088](https://github.com/helm/helm/issues/32088)) [`2c979a1`](https://github.com/helm/helm/commit/2c979a17ac6b6d7bfe2d6650b69fa9effe963d4d) (Jakub Jaruszewski)
- Potential fix for pull request finding [`2bd2c66`](https://github.com/helm/helm/commit/2bd2c66544634e419ede3cfa18952cce5a5acd08) (kimsungmin1)
- fix(registry): resolve golangci-lint issues in token-auth tests [`183a540`](https://github.com/helm/helm/commit/183a5402291c553898b9c404bc17c95c81ea1c6c) (kimsm28)
- chore: go mod tidy after rebase on main [`08d8da1`](https://github.com/helm/helm/commit/08d8da1aa9080772e57ab5bf5b00b3c13364af00) (kimsm28)
- fix(registry): use plain-http registry in token-auth scope test [`9655b5a`](https://github.com/helm/helm/commit/9655b5aecc0d36142d0620ff5ed762065a997739) (kimsm28)
- Update pkg/registry/client.go [`430dfac`](https://github.com/helm/helm/commit/430dfac3eeab03886f511761e3969f738f760364) (Terry Howe)
- test: improve client\_scope\_test.go to avoid data races and brittle assertions [`9569605`](https://github.com/helm/helm/commit/9569605eccf8318fe25bf78c46c4eb462ce8fc3f) (kimsm28)
- fix typos in withScopeHint function comment [`63f2b68`](https://github.com/helm/helm/commit/63f2b6809919e5e8e3e04f52064a536a14f1ff9b) (kimsm28)
- fix registry test failures by adjusting DockerRegistryHost and auth server listener management [`f7488c0`](https://github.com/helm/helm/commit/f7488c0be8c65dd16386c215cac4332900667278) (kimsm28)
- fix variable naming requestUrl -> requestURL [`8fe78fb`](https://github.com/helm/helm/commit/8fe78fbe46eb2db5c75ab1cc89699c750017dca6) (kimsm28)
- fix typo, remove unnecessary code, fix to avoid to use the assertion in http hanlder [`d0670d2`](https://github.com/helm/helm/commit/d0670d2fb2c3426cde4b41927b5e9b8b4370df93) (kimsm28)
- change suite.Nil, suite.NotNill to more proper function(suite.NoError, suite.Error) [`804256e`](https://github.com/helm/helm/commit/804256ef659226f26b2222ccb8f9cf18ef1b1946) (kimsungmin1)
- change client\_scope\_test.go to use httptest [`d79bceb`](https://github.com/helm/helm/commit/d79bceb807692512461d8007040c41bcd1547041) (kimsungmin1)
- fix typo [`d34fcd9`](https://github.com/helm/helm/commit/d34fcd9264225a1e6296c4b0ee124dc69f3b3ecc) (kimsungmin1)
- remove freeport dependency [`9fbd190`](https://github.com/helm/helm/commit/9fbd190c30addb4786e4fe930a0fe98bf354116a) (kimsungmin1)
- add newline in license header [`9275661`](https://github.com/helm/helm/commit/9275661357afdfe12b8ce561e8103673f16cca8d) (kimsungmin1)
- fix scope when helm push to a registry that use token auth [`fef91f3`](https://github.com/helm/helm/commit/fef91f3e6942a20148542461eaebfb24f2c09584) (kimsungmin1)
- fix panic on repeated IsReachable calls [`e89ce68`](https://github.com/helm/helm/commit/e89ce68bc5fec430bc1e2f0aef1aca6a2e71f795) (Mohammad Abdolirad)
- fix(provenance): check error return in Digest [`ff1ac83`](https://github.com/helm/helm/commit/ff1ac83bfb1246cdf1b57a4db0042085cc8b265d) (Sebastien Tardif)
- fix: address review feedback [`4b4dedb`](https://github.com/helm/helm/commit/4b4dedb2bdcfac886c124a361a5126e3c5e3c5df) (Sebastien Tardif)
- fix: fetch logs from all containers in test pods [`7c80103`](https://github.com/helm/helm/commit/7c8010322b8639cdf7844ac1ae5f8d444db43935) (Sebastien Tardif)
- chore: rename savedErr to clear its specific purpose [`ecc9cd2`](https://github.com/helm/helm/commit/ecc9cd2f1b5b53dadcd12395c032bc5b3ca02937) (Jeaeun Kim)
- chore: fix lint [`f6211ba`](https://github.com/helm/helm/commit/f6211ba49bfbf5768ea44be3a1402869a4709b37) (Jeaeun Kim)
- chore: store err separately for clarity [`3507ea5`](https://github.com/helm/helm/commit/3507ea5bfdbad921684ac131896b6968c76e9ca6) (Jeaeun Kim)
- chore: Improve error reporting for `helm template --debug` with `--show-only` [`211ffae`](https://github.com/helm/helm/commit/211ffae93d2d741a2dbcd74b4aa2a1bc2fc27d5f) (Jeaeun Kim)
- Address review comments [`51a9837`](https://github.com/helm/helm/commit/51a9837ba177812c381515886c4f0cd0b7a633e6) (Matheus Pimenta)
- Fix vanishing empty lines [`83a8b70`](https://github.com/helm/helm/commit/83a8b70ffc1bcf97bb293cf6b35bd3b5093e8c30) (Matheus Pimenta)

**Full Changelog**: <https://github.com/helm/helm/compare/v4.2.3...v4.2.4>

### [`v4.2.3`](https://github.com/helm/helm/releases/tag/v4.2.3): Helm v4.2.3

Helm v4.2.3 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Installation and Upgrading

Download Helm v4.2.3. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.3-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-darwin-amd64.tar.gz.sha256sum) / ff3ac86755a45f3422473bc1200776aac0fe04c5766abe6ca66699f7b564b23b)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.3-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-darwin-arm64.tar.gz.sha256sum) / 048ecf5ad3160f83d918f9fe945238d2132b079640f7b106175331c25f242c64)
- [Linux amd64](https://get.helm.sh/helm-v4.2.3-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-amd64.tar.gz.sha256sum) / e9b88b4ee95b18c706839c28d3a0220e5bc470e9cd9262410c90793c45ff8b7c)
- [Linux arm](https://get.helm.sh/helm-v4.2.3-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-arm.tar.gz.sha256sum) / ba00678361ca7a03ec42ca1ea459543e1d8eab2a7d5429a5eda71dc9741c8a9b)
- [Linux arm64](https://get.helm.sh/helm-v4.2.3-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-arm64.tar.gz.sha256sum) / 21abd9354d39b2cd79a8d76be6912cd137a983cbf997193503fb8a6a6e2f2785)
- [Linux i386](https://get.helm.sh/helm-v4.2.3-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-386.tar.gz.sha256sum) / 31d57972d36e60388e173327fffcf9d58f272349dfa9ed3e1914f3cd88fe7283)
- [Linux loong64](https://get.helm.sh/helm-v4.2.3-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-loong64.tar.gz.sha256sum) / 232f82d787d530a621b2006965ed2b99644b4391bbc6261e9787f95700fc44f7)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.3-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-ppc64le.tar.gz.sha256sum) / 43fc5a4b20839c3669a0748498bd2613b095e288425bf5678c6ba664eb4a0e70)
- [Linux s390x](https://get.helm.sh/helm-v4.2.3-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-s390x.tar.gz.sha256sum) / 17932091e19d352585b540a482fca9b953d32a8ad7afec72bf9cbbcd96b094cb)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.3-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.3-linux-riscv64.tar.gz.sha256sum) / 09ff0772730678c652b9ac4a2b32cd20f4e62a2b040403bcacd4ad845d3d3e9c)
- [Windows amd64](https://get.helm.sh/helm-v4.2.3-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.3-windows-amd64.zip.sha256sum) / 5ca7de684c92d48b93d5c34a029fdda57b38e1eac04bc8541bdf1eb249388679)
- [Windows arm64](https://get.helm.sh/helm-v4.2.3-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.3-windows-arm64.zip.sha256sum) / 5f444ed097688ed3abaf1d8801e21110d9bddeb6ed13939afcac302888527ab5)

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.4 and 3.21.4 are the next patch releases scheduled for August 12, 2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 [`43e8b7f`](https://github.com/helm/helm/commit/43e8b7feece8beb0fcba47059ec9b522fd929a64) (Terry Howe)

### [`v4.2.2`](https://github.com/helm/helm/releases/tag/v4.2.2): Helm v4.2.2

Helm v4.2.2 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- Revert: Fixed a race condition in WaitForDelete where the status observer canceled the watch too early, causing intermittent failures when running a full test suite [#&#8203;32214](https://github.com/helm/helm/issues/32214)

#### Installation and Upgrading

Download Helm v4.2.2. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.2-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-darwin-amd64.tar.gz.sha256sum) / 10c1e36ee8c5f2e2ee25a16599cb03ab74c0953cd889cacb980a49ba4b6574ba)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.2-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-darwin-arm64.tar.gz.sha256sum) / 5410a0dae3d5d91f45653b161260d9301aabc4ae80ae50a6605d66884b6df8ea)
- [Linux amd64](https://get.helm.sh/helm-v4.2.2-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-amd64.tar.gz.sha256sum) / 9adafecab4d406853bba163a70e9f104f47dbbf65ce24b7653bae7e36150bcb6)
- [Linux arm](https://get.helm.sh/helm-v4.2.2-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-arm.tar.gz.sha256sum) / 7e9490169874695e04ab1af47c5620621fc13c84219a258fcc1afdcd40ca7438)
- [Linux arm64](https://get.helm.sh/helm-v4.2.2-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-arm64.tar.gz.sha256sum) / 78803142087a0069fa4b50d3f32a84d3ef25c14d1ee8a40fbccf86a6216d2f36)
- [Linux i386](https://get.helm.sh/helm-v4.2.2-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-386.tar.gz.sha256sum) / 8e1fdcda4a476ffc5d1179c7f16d33a3d54267efa08fd720f7678277d68bc2d5)
- [Linux loong64](https://get.helm.sh/helm-v4.2.2-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-loong64.tar.gz.sha256sum) / b8bfe96b8b0b0e2af51af4a00ef521cc5a7e03793aea3568cf8500a63ae05041)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.2-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-ppc64le.tar.gz.sha256sum) / 814a80fd98eb9e4c5a9d610f3b9c15ffe120c2f5e39df16a2f491723ebc90126)
- [Linux s390x](https://get.helm.sh/helm-v4.2.2-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-s390x.tar.gz.sha256sum) / d84cdf1123f20cfbef19a2af1cd6afe8b00626bd9846bccb9dae978c810c8274)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.2-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.2-linux-riscv64.tar.gz.sha256sum) / f07c105180dff2619ab45134b9b47b7845387e8f3299e12ebe0efb87c7548717)
- [Windows amd64](https://get.helm.sh/helm-v4.2.2-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.2-windows-amd64.zip.sha256sum) / 5fad8562e98c34fa5af3ef904086a5874a6701050f9bf36e30238c975df94dcd)
- [Windows arm64](https://get.helm.sh/helm-v4.2.2-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.2-windows-arm64.zip.sha256sum) / 2e993d6a1dd8197a33e65d8e90b26df9d248ff3501701dea401856aa265a2dab)

This release was signed by [@&#8203;gjenkins8](https://github.com/gjenkins8) with key BF88 8333 D96A 1C18 E268 2AAE D79D 67C9 EC01 6739, which can be found at <https://keys.openpgp.org/vks/v1/by-fingerprint/BF888333D96A1C18E2682AAED79D67C9EC016739>. Please use the attached signatures for verifying this release using gpg.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.3 and 3.21.2 are the next patch releases scheduled for July 8, 2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- Revert "fix(kube): prevent spurious early exit in WaitForDelete during informer sync" [`b05881c`](https://github.com/helm/helm/commit/b05881cf967a5a09e19866799d0edfd40675803a) (George Jenkins)

**Full Changelog**: <https://github.com/helm/helm/compare/v4.2.1...v4.2.2>

### [`v4.2.1`](https://github.com/helm/helm/releases/tag/v4.2.1): Helm v4.2.1

Helm v4.2.1 is a patch release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- Fixed data race detected by -race flag when concurrent goroutines (upgrade + rollback, install + uninstall) both call GetWaiterWithOptions on the same FailingKubeClient instance [#&#8203;31925](https://github.com/helm/helm/issues/31925)
- Fixed helm command success messages writing to stderr instead of stdout. Now correctly outputing to stdout [#&#8203;32056](https://github.com/helm/helm/issues/32056)
- Fixed Helm 4 emitting "unable to find exact version" when using version range constraints [#&#8203;31757](https://github.com/helm/helm/issues/31757)
- Fixed a race condition in WaitForDelete where the status observer canceled the watch too early, causing intermittent failures when running a full test suite [#&#8203;32081](https://github.com/helm/helm/issues/32081)
- Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 [#&#8203;32153](https://github.com/helm/helm/issues/32153)
- Fixed SDK errors by upgrading dependencies: cli-utils 1.2.1, controller-runtime 0.24.1 and k8s 1.36.1 [#&#8203;32128](https://github.com/helm/helm/issues/32128)
- Dependency updates

#### Installation and Upgrading

Download Helm v4.2.1. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.1-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-darwin-amd64.tar.gz.sha256sum) / 2a21c9f368d608bcf6eb794ebc06514eb6b529a846b60fe4a43dea7bcce65228)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.1-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-darwin-arm64.tar.gz.sha256sum) / 896472d2ec0740c60f64a9df0fc30d478beee38a1a2a6ed91aa6e6ee177c1575)
- [Linux amd64](https://get.helm.sh/helm-v4.2.1-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-amd64.tar.gz.sha256sum) / 479dca836e5b45e8bd222400c5591b0e3a647378f03ff96597180db97c17fdae)
- [Linux arm](https://get.helm.sh/helm-v4.2.1-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-arm.tar.gz.sha256sum) / 49e8f7856de6eab170dc09671cfb0578cc455d820df5b0f54e6453058dc0e3f3)
- [Linux arm64](https://get.helm.sh/helm-v4.2.1-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-arm64.tar.gz.sha256sum) / 596b9a73d366c1e72ce67d595c22805480e30914593aafbc9f547694e72814db)
- [Linux i386](https://get.helm.sh/helm-v4.2.1-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-386.tar.gz.sha256sum) / e038eab680f22b1cebe68fd0536cf2397b0c10798dcb23c28e500e0804ec1a55)
- [Linux loong64](https://get.helm.sh/helm-v4.2.1-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-loong64.tar.gz.sha256sum) / 8ae26f15638d951c4ed21d0d3018b8800a137646e5e5151a3856cf324c2852ae)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.1-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-ppc64le.tar.gz.sha256sum) / 6f34eca5e314e941577a07be6c8b356f66b9cdefbed1175da1e7916368febcfc)
- [Linux s390x](https://get.helm.sh/helm-v4.2.1-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-s390x.tar.gz.sha256sum) / e6355691887d4185b7e077f058483c04f353229feb7d4a72edc3ebe0b8738a6a)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.1-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.1-linux-riscv64.tar.gz.sha256sum) / 16a4299f14ff1ffa79bb22115051911c662fa2ecdd90e85b65d7d143e8de9d02)
- [Windows amd64](https://get.helm.sh/helm-v4.2.1-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.1-windows-amd64.zip.sha256sum) / 6e7fa7839444b8ddc407c5bcdb1edd1024f57d09c2db971dec511ee2f2616eb0)
- [Windows arm64](https://get.helm.sh/helm-v4.2.1-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.1-windows-arm64.zip.sha256sum) / ae4c9acd0d9acd1f9e9da2f60105f793f65fd49ab7c03c6c7d13804c3b885657)

This release was signed with `208D D36E D5BB 3745 A167 43A4 C7C6 FBB5 B91C 1155` and can be found at [@&#8203;scottrigby](https://github.com/scottrigby) [keybase account](https://keybase.io/r6by). Please use the attached signatures for verifying this release using `gpg`.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.2 and 3.21.2 are the next patch releases scheduled for July 8, 2026
- 4.3.0 and 3.22.0 are the next minor releases scheduled for September 9, 2026

#### Changelog

- fix: protect FailingKubeClient.RecordedWaitOptions from data race ([#&#8203;31925](https://github.com/helm/helm/issues/31925)) [`d591a19`](https://github.com/helm/helm/commit/d591a19b953bd9cfdf7d9ddd83c2f4ffdaeafb29) (Terry Howe)
- fix: route registry client output to stdout instead of stderr ([#&#8203;32056](https://github.com/helm/helm/issues/32056)) [`2a9fcae`](https://github.com/helm/helm/commit/2a9fcae29280472edec988c6bf0528e4ae79b33a) (Terry Howe)
- chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 [`ffa5bd6`](https://github.com/helm/helm/commit/ffa5bd693eee68ba9c1ba42d160c69114eda962c) (dependabot\[bot])
- chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 [`9f9dbaf`](https://github.com/helm/helm/commit/9f9dbaf94008044a516cda4837565237306578a7) (dependabot\[bot])
- chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 [`64a2891`](https://github.com/helm/helm/commit/64a2891699ae9c8f2d0e06d5db3dd117649886a2) (dependabot\[bot])
- chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 [`e54a4a2`](https://github.com/helm/helm/commit/e54a4a2b7d4ed9ca3bb4be7562f76dd5f2fd8f71) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 [`acb762b`](https://github.com/helm/helm/commit/acb762b0ef8882b062ba8f6b87261411309875b8) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 [`768586d`](https://github.com/helm/helm/commit/768586df3f2a79fca5202b6713f8675bb097a904) (dependabot\[bot])
- fix(version): avoid false range detection on prerelease x/X [`eabfae5`](https://github.com/helm/helm/commit/eabfae560459d1ffe1f7a3268d5441238e9f84b2) (Benoit Tigeot)
- fix(version): version range || can has no space [`e3fd51f`](https://github.com/helm/helm/commit/e3fd51f331e14fb4056951540d2f2ffde81b405c) (Benoit Tigeot)
- feat: report in debug the version we select with version range arg [`1e47395`](https://github.com/helm/helm/commit/1e47395a9566bcaaaf7ed9e31a8367eb1f95e0a3) (Benoit Tigeot)
- fix: prevent warning when using version range constraints [`a33e239`](https://github.com/helm/helm/commit/a33e23939a85ac60eb9a6bee818f2c5459fda576) (Benoit Tigeot)
- fix(kube): always propagate context.Canceled in WaitForDelete [`fa06d44`](https://github.com/helm/helm/commit/fa06d4455724afe22bbe00af7925549a82d95e6c) (Terry Howe)
- fix(kube): prevent spurious early exit in WaitForDelete during informer sync [`360d483`](https://github.com/helm/helm/commit/360d4835df0fb8bd7cbde4cad0cbc79de01a6e93) (Terry Howe)
- chore(deps): bump github.com/tetratelabs/wazero from 1.11.0 to 1.12.0 [`7651edf`](https://github.com/helm/helm/commit/7651edf21e31b5c33df82e67f23855d1358d021d) (dependabot\[bot])
- chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 [`b132e7e`](https://github.com/helm/helm/commit/b132e7e43f3620eb60ef3524527c1b2fceed90e9) (dependabot\[bot])
- fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026 [`eee491a`](https://github.com/helm/helm/commit/eee491a7461a524b87e5bb73ea5a0c4f82c72469) (Terry Howe)
- chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 [`3e3c575`](https://github.com/helm/helm/commit/3e3c5751b1723239cbce042533db0d84b65c6bc1) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.5 to 4.36.0 [`c4ce2bb`](https://github.com/helm/helm/commit/c4ce2bb364dbfb781059e628572d7177ba191cc4) (dependabot\[bot])
- chore(deps): bump actions/stale from 10.2.0 to 10.3.0 [`3892dc2`](https://github.com/helm/helm/commit/3892dc2a11b2e111acddcbc55d5a4733ba461f20) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.4 to 4.35.5 [`c4bbb62`](https://github.com/helm/helm/commit/c4bbb6263f59fe541acd75ce0b508034c65899e1) (dependabot\[bot])
- chore(deps): bump golang.org/x/crypto from 0.50.0 to 0.51.0 [`a0d7f16`](https://github.com/helm/helm/commit/a0d7f16b58aa4cb9dbaf8c37055faa28b1b350ae) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 [`8a3de05`](https://github.com/helm/helm/commit/8a3de054b5ab1b59f60c790fad39861e294671f1) (dependabot\[bot])
- fix(upstream): upgrade to cli-utils 1.2.1, controller-runtime 0.24.1 and k8s 1.36.1 [`57a4803`](https://github.com/helm/helm/commit/57a4803bd4953d8ef9d51d927f492ecaaf5df9db) (Matheus Pimenta)
- chore(deps): bump github.com/fluxcd/cli-utils from 1.2.0 to 1.2.1 [`b33ae02`](https://github.com/helm/helm/commit/b33ae02b9cd7fcba804391ab3d364739cb2a8780) (dependabot\[bot])

**Full Changelog**: <https://github.com/helm/helm/compare/v4.2.0...v4.2.1>

### [`v4.2.0`](https://github.com/helm/helm/releases/tag/v4.2.0): Helm v4.2.0

Helm v4.2.0 is a feature release. Users are encouraged to upgrade for the best experience.

The community keeps growing, and we'd love to see you there!

- Join the discussion in [Kubernetes Slack](https://kubernetes.slack.com):
  - for questions and just to hang out
  - for discussing PRs, code, and bugs
- Hang out at the Public Developer Call: Thursday, 9:30 Pacific via [Zoom](https://zoom.us/j/696660622)
- Test, debug, and contribute charts: [ArtifactHub/packages](https://artifacthub.io/packages/search?kind=0)

#### Notable Changes

- Switch to `goreleaser` for release builds
- Kubernetes client libraries to v1.36
- Add `mustToToml` template function
- deprecate unused `--hide-notes` and `--render-subchart-notes` flags
- `--dry-run=server` now respects `generateName:`

#### Installation and Upgrading

Download Helm v4.2.0. The common platform binaries are here:

- [MacOS amd64](https://get.helm.sh/helm-v4.2.0-darwin-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-darwin-amd64.tar.gz.sha256sum) / 1376ea697140e4db316736e760d5a47d12afc1524dce704476ef06fd7fdeddc6)
- [MacOS arm64](https://get.helm.sh/helm-v4.2.0-darwin-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-darwin-arm64.tar.gz.sha256sum) / f13f959015447b6bc309f9fd506509926543988a39035c088b52522ec95e2acb)
- [Linux amd64](https://get.helm.sh/helm-v4.2.0-linux-amd64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-amd64.tar.gz.sha256sum) / 97dbeb971be4ac4b27e3839976d9564c0fb35c6f3b1da89dd1e292d236af4096)
- [Linux arm](https://get.helm.sh/helm-v4.2.0-linux-arm.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-arm.tar.gz.sha256sum) / ae624870b2d50e655b6462daff117eb9d28c4bad45234ef24c1275113540fcb0)
- [Linux arm64](https://get.helm.sh/helm-v4.2.0-linux-arm64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-arm64.tar.gz.sha256sum) / 1f8de130dfbd04de64978e7b852a7a547be1404956a366608276d2520b678670)
- [Linux i386](https://get.helm.sh/helm-v4.2.0-linux-386.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-386.tar.gz.sha256sum) / 9cf44acc59081aca98b4d9f09138348836b26761258e02ad2b99616f66eead5c)
- [Linux loong64](https://get.helm.sh/helm-v4.2.0-linux-loong64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-loong64.tar.gz.sha256sum) / 5b04f0167b8b415a057c1f4f809ede86d5ead840e0aa560db097da5be19f86d0)
- [Linux ppc64le](https://get.helm.sh/helm-v4.2.0-linux-ppc64le.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-ppc64le.tar.gz.sha256sum) / 48f0637b93247717b725e8d4a8d2cf8df0e2fdea91bdd0e36e2426c2d5c76e4e)
- [Linux s390x](https://get.helm.sh/helm-v4.2.0-linux-s390x.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-s390x.tar.gz.sha256sum) / 328e9ed27904f9910026240c4311bb1b0bf91c6fde1634f212097694507a702f)
- [Linux riscv64](https://get.helm.sh/helm-v4.2.0-linux-riscv64.tar.gz) ([checksum](https://get.helm.sh/helm-v4.2.0-linux-riscv64.tar.gz.sha256sum) / 5d292d57ab1f40e47e373a87187bafa66e8daac4ddc4a1333421c174e8184755)
- [Windows amd64](https://get.helm.sh/helm-v4.2.0-windows-amd64.zip) ([checksum](https://get.helm.sh/helm-v4.2.0-windows-amd64.zip.sha256sum) / 614f68ddc567ac9bfb0c205f869b1f83ba4e0a9aacd26cbae47743ae6082a579)
- [Windows arm64](https://get.helm.sh/helm-v4.2.0-windows-arm64.zip) ([checksum](https://get.helm.sh/helm-v4.2.0-windows-arm64.zip.sha256sum) / e740e4c19b6e2a0b428f7a52c38b7f0b092f0c43ac49870537d7e7fac9cedc07)

This release was signed by [@&#8203;gjenkins8](https://github.com/gjenkins8) with key BF88 8333 D96A 1C18 E268 2AAE D79D 67C9 EC01 6739, which can be found at <https://keys.openpgp.org/vks/v1/by-fingerprint/BF888333D96A1C18E2682AAED79D67C9EC016739>. Please use the attached signatures for verifying this release using gpg.

The [Quickstart Guide](https://helm.sh/docs/intro/quickstart/) will get you going from there. For **upgrade instructions** or detailed installation notes, check the [install guide](https://helm.sh/docs/intro/install/). You can also use a [script to install](https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4) on any system with `bash`.

#### What's Next

- 4.2.1 will contain only bug fixes
- 4.3.0 is the next feature release

#### Changelog

- Bump to version v4.2 [`0646808`](https://github.com/helm/helm/commit/06468084e85c244c712834933d25ea232a4c2093) (George Jenkins)
- build: Clean up Goreleaser change ([#&#8203;32098](https://github.com/helm/helm/issues/32098)) [`e23bf3a`](https://github.com/helm/helm/commit/e23bf3af53c52185123278e83b7023c102707778) (Scott Rigby)
- fix: add -extldflags -static to dist target to match build-cross [`f60ab7c`](https://github.com/helm/helm/commit/f60ab7c31c81a73b8e0aade5aff41bfc01c08820) (Terry Howe)
- build: use goreleaser build with manual archive creation [`64aa46f`](https://github.com/helm/helm/commit/64aa46f2f1cf239cf6535c5e847e14dcb933a847) (Terry Howe)
- chore: remove build-cross dependency from test-acceptance [`d199a1a`](https://github.com/helm/helm/commit/d199a1a42c04bccb287f2c7d9c3f73b669412e5a) (Terry Howe)
- ci: add fetch-depth 0 to canary checkout for goreleaser [`8289940`](https://github.com/helm/helm/commit/82899404a68f3826389bb38cf67bf75085db6b2c) (Terry Howe)
- fix: address goreleaser build issues flagged in review [`c075022`](https://github.com/helm/helm/commit/c075022ce16489f5f7afd45a37b679cf58fa36ea) (Terry Howe)
- fix: pass VERSION as GORELEASER\_CURRENT\_TAG to preserve v-prefix in archive names [`04885dd`](https://github.com/helm/helm/commit/04885dd905b6f8a823733dbc9b9f5cb2843a975f) (Terry Howe)
- fix: disable goreleaser checksums.txt and restrict zip to windows only [`93103ce`](https://github.com/helm/helm/commit/93103ce66cb6374d9d7b552802f53b21ea2c2dd1) (Terry Howe)
- fix: use index for optional env var in version\_template [`e49a1dc`](https://github.com/helm/helm/commit/e49a1dc16eee526928d8928b8d96c01ee513ebd9) (Terry Howe)
- fix: canary build file names [`eaa0910`](https://github.com/helm/helm/commit/eaa09100b9b18175d878b1e114cbe9df2a3f70c2) (Terry Howe)
- Fix archive name [`5a75279`](https://github.com/helm/helm/commit/5a75279c1a017a60b97bd44986288af7399c6ff8) (Terry Howe)
- fix goreleaser archive [`37284a9`](https://github.com/helm/helm/commit/37284a9211972f7f41a2acc3c3313517596dd4b0) (Terry Howe)
- add support for loong64 [`45336cc`](https://github.com/helm/helm/commit/45336ccd5b2621357e3f785c1fe93627c5990a6e) (Terry Howe)
- fix artifact directory [`a9659b0`](https://github.com/helm/helm/commit/a9659b07e3eec20ab5b964fddae05f51f478f704) (Terry Howe)
- update configuration to v2 [`e368f17`](https://github.com/helm/helm/commit/e368f170af8a200e672adac5f765b8101db0c8fa) (Terry Howe)
- remove GOTOOLCHAIN [`e7bea85`](https://github.com/helm/helm/commit/e7bea8513c30475664919f031774e18fecdf1f66) (Terry Howe)
- chore: replace mitchellh/gox with goreleaser [`075c096`](https://github.com/helm/helm/commit/075c096afec70155bc43ac3587a119df1ae5fcc6) (Terry Howe)
- chore(deps): bump github.com/distribution/distribution/v3 [`12f2c41`](https://github.com/helm/helm/commit/12f2c41c0d7a74739c58a5995cbbb3125d9247e5) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.2 to 4.35.3 [`58e8ffd`](https://github.com/helm/helm/commit/58e8ffdc3302260b1b55718c9b72c6f169a76ee0) (dependabot\[bot])
- chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 [`e61bbfb`](https://github.com/helm/helm/commit/e61bbfbfff41958b0ba1984e4d6799fe131f325e) (dependabot\[bot])
- Upgrade kstatus to 1.2 and controller-runtime to 0.24 [`081c6df`](https://github.com/helm/helm/commit/081c6dff537087f52ec6e470d8986439e24e8e33) (Matheus Pimenta)
- fix: adds topLevel permissions to improve openSSF scores [`277d970`](https://github.com/helm/helm/commit/277d9702555532d13426119d31c70fffb389d589) (Gagan H R)
- Upgrade Go to 1.26, Kubernetes to 1.36, kstatus to 1.1 [`a4a9cc7`](https://github.com/helm/helm/commit/a4a9cc7a314d98456a2f23798a78e9ad05d96d0c) (Matheus Pimenta)
- fix(templating): hooks conflicting with templates in post-renderers ([#&#8203;32049](https://github.com/helm/helm/issues/32049)) [`8f56f24`](https://github.com/helm/helm/commit/8f56f24d638612a46f3e23265d06338c1f93bccb) (Matheus Pimenta)
- docs: fix grammar and spacing in CONTRIBUTING.md [`db40adb`](https://github.com/helm/helm/commit/db40adb1d13573280b65bc2002df7d75c009235a) (Mohit)
- chore(deps): bump the k8s-io group with 7 updates [`775e794`](https://github.com/helm/helm/commit/775e794319639f5c1e6b40448ce15ad3cc10d4e1) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.35.1 to 4.35.2 [`934ace3`](https://github.com/helm/helm/commit/934ace35dfaef9eeb9997bf1ee385db0986daecc) (dependabot\[bot])
- fix(templating): SplitManifests must preserve line endings for downstream YAML parsers ([#&#8203;31952](https://github.com/helm/helm/issues/31952)) [`265c5eb`](https://github.com/helm/helm/commit/265c5eb530a36ec651e79ecf4d37ba2f098b7e59) (Matheus Pimenta)
- chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 [`48e2b7d`](https://github.com/helm/helm/commit/48e2b7ddd4e960b768fe5daee34a33cb89852a6e) (dependabot\[bot])
- Update pkg/chart/common/util/coalesce.go [`a8e2497`](https://github.com/helm/helm/commit/a8e249714f5311b9aff44c4bd2bfc433ab1ab952) (Evans Mungai)
- test(values): Add test for nil cleanup in partially overridden subchart maps [`52fc971`](https://github.com/helm/helm/commit/52fc971da37cf34aa26e7d7c460f2430dfb01b26) (Johannes Lohmer)
- fix(values): do not copy chart-default nils into coalesced values [`0063877`](https://github.com/helm/helm/commit/00638773d1366dc962c785de3d297cf0279b9a0d) (Johannes Lohmer)
- test(values): add test for subchart nil producing %!s(<nil>) [`6eb4ebf`](https://github.com/helm/helm/commit/6eb4ebf0e1afb0c63d748bf116145a5b9e0842b7) (Johannes Lohmer)
- test(values): add tests for subchart nil value regressions [`5cb4e7d`](https://github.com/helm/helm/commit/5cb4e7d992d85d372f5d86c238330102d936bfe5) (Johannes Lohmer)
- chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 [`b5c7c80`](https://github.com/helm/helm/commit/b5c7c80de317643e383ca2926ebc0ad884021bba) (dependabot\[bot])
- fix(templating): fix wrong YAML separator parsing for post-renderers ([#&#8203;31941](https://github.com/helm/helm/issues/31941)) [`a27f1ad`](https://github.com/helm/helm/commit/a27f1add79c6c02459413dbb60f8438d8051cf06) (Matheus Pimenta)
- fix: add debug logging to HTTP getter for helm pull [`c26be60`](https://github.com/helm/helm/commit/c26be60d81e5cb6a147d6088477cf86fd5aaf1f0) (Cairon)
- chore(deps): bump golang.org/x/crypto from 0.49.0 to 0.50.0 [`953f5f0`](https://github.com/helm/helm/commit/953f5f031bb7fa8f3eccdea6520e09fd44fe3923) (dependabot\[bot])
- chore(deps): bump golang.org/x/term from 0.41.0 to 0.42.0 [`10fc5f3`](https://github.com/helm/helm/commit/10fc5f335b5fbb09f5d04cb0450839790ae15634) (dependabot\[bot])
- chore(deps): bump golang.org/x/text from 0.35.0 to 0.36.0 [`d89e7c6`](https://github.com/helm/helm/commit/d89e7c60762910204044c4215c7bb2f43ac3ef8f) (dependabot\[bot])
- chore: Update release notes script for Helm v4 [`8a95461`](https://github.com/helm/helm/commit/8a954619255a82890a08b7d1fa9e86a437c4cebb) (George Jenkins)
- refactor(cli): share RetryingRoundTripper via pkg/kubeenv [`213c869`](https://github.com/helm/helm/commit/213c869a988f2c7390c65673e3d677970d6220fd) (Sumit Solanki)
- chore(deps): bump github.com/lib/pq from 1.12.2 to 1.12.3 [`bd5027a`](https://github.com/helm/helm/commit/bd5027a9cf07993d7bfe4b60702b1a489fe8783e) (dependabot\[bot])
- fix: unnecessary-format lint issues from merge [`087736b`](https://github.com/helm/helm/commit/087736b66e97393ccaa0bdf1e5df13dcc9d88340) (George Jenkins)
- fix: Plugin missing provenance bypass [`586eb57`](https://github.com/helm/helm/commit/586eb57338d848e65686a3a9616e2776e87cfd1e) (George Jenkins)
- chore(deps): bump github.com/fluxcd/cli-utils [`c8c5dfa`](https://github.com/helm/helm/commit/c8c5dfad630cd7b238236c619c466488a547725c) (dependabot\[bot])
- chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp [`998466c`](https://github.com/helm/helm/commit/998466cfcfee189ce7e3df5be8ffe79ed5f1f097) (dependabot\[bot])
- chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp [`b0cec58`](https://github.com/helm/helm/commit/b0cec589f50a7e16d942ad3385598a6dda2b0a20) (dependabot\[bot])
- chore(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp [`6ebfb29`](https://github.com/helm/helm/commit/6ebfb29dbf006ce78e9af8878008bda3578dcd3e) (dependabot\[bot])
- test(kube): fix flaky WaitForDelete test by avoiding informer sync race [`a7f8443`](https://github.com/helm/helm/commit/a7f84439aacd3864b40055b60a3c3e54292d1646) (Terry Howe)
- test(kube): fix flaky WaitForDelete timing in status wait tests [`4c0d21f`](https://github.com/helm/helm/commit/4c0d21f53f2ca78b525e31dbbf9cc9cfb818a2e3) (Terry Howe)
- chore(deps): bump github.com/distribution/distribution/v3 [`08dea9c`](https://github.com/helm/helm/commit/08dea9c140084b5d9fecb59a45a05f417415b591) (dependabot\[bot])
- Minor nit: fix import instructions to comply with canonical import paths [`de58531`](https://github.com/helm/helm/commit/de58531ca7ff557342acaa2c906082e58521ef47) (Anmol Virdi)
- chore(deps): bump github.com/distribution/distribution/v3 [`9b1ad4c`](https://github.com/helm/helm/commit/9b1ad4cf027452b828affb07318db2e931e734a5) (dependabot\[bot])
- fix(action): return correct error variable in prepareUpgrade [`8ef2d45`](https://github.com/helm/helm/commit/8ef2d45934ba1b9ca341818f1157112fcf7cdf1d) (Rhys McNeill)
- chore(deps): bump github.com/lib/pq from 1.12.1 to 1.12.2 [`cd7cf76`](https://github.com/helm/helm/commit/cd7cf76a174e856fd171b391995d9a65f97a79d3) (dependabot\[bot])
- chore(deps): bump github/codeql-action from 4.30.7 to 4.35.1 [`45ee55b`](https://github.com/helm/helm/commit/45ee55b83f8ad23798c84560ff65686e2ab298af) (dependabot\[bot])
- chore(deps): bump github.com/lib/pq from 1.12.0 to 1.12.1 [`9a06741`](https://github.com/helm/helm/commit/9a0674188412d1dcb2e7f018730aaa71781bd03b) (dependabot\[bot])
- chore(deps): bump actions/setup-go from 6.2.0 to 6.4.0 [`d1e31ca`](https://github.com/helm/helm/commit/d1e31ca507412d770a602e722060e6d7379f4f1a) (dependabot\[bot])
- fix(kube): clarify server-side apply patch errors [`f257c95`](https://github.com/helm/helm/commit/f257c95c783f5595e36cb5a7dcc862cc1f6266b5) (abhay1999)
- fix: pin codeql-action/upload-sarif to commit SHA in scorecards workflow [`7025480`](https://github.com/helm/helm/commit/7025480397d8b6b7fd8cdb5e083dc37b62dbd3d8) (Terry Howe)
- refactor(cli): decouple EnvSettings from pkg/kube [`64f1d0a`](https://github.com/helm/helm/commit/64f1d0af5b53f0a9292af2ba1efc42a46a57ed00) (Sumit Solanki)
- docs(registry): fix incorrect and improve clarity of comments in client.go [`85bf56e`](https://github.com/helm/helm/commit/85bf56ea82fd21452e53cae91b380b0afb3e8b83) (Debasish Mohanty)
- refactor(cli): decouple EnvSettings from pkg/kube to avoid import cycles [`1549937`](https://github.com/helm/helm/commit/154993723aadf45601d124c6750e8f4ae3b9f2fd) (Sumit Solanki)
- chore(deps): bump github.com/ProtonMail/go-crypto from 1.3.0 to 1.4.1 [`c7a75b1`](https://github.com/helm/helm/commit/c7a75b16cb8b0859bf32bf74ae98300e5b55361b) (dependabot\[bot])
- chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.0 [`3a7573a`](https://github.com/helm/helm/commit/3a7573a81ed5be2e00dfb74fa8d95c0cbe1c4f0d) (dependabot\[bot])
- chore(deps): bump github.com/fatih/color from 1.18.0 to 1.19.0 [`0229da1`](https://github.com/helm/helm/commit/0229da1803a29671b1becc4561c77f85db609aac) (dependabot\[bot])
- docs(engine): fix misleading toTOML doc comment [`c1a5a6e`](https://github.com/helm/helm/commit/c1a5a6e260bd070bce9a8299795400340e10c468) (Ilya Kiselev)
- feat(engine): add mustToToml template function [`b075f7a`](https://github.com/helm/helm/commit/b075f7a35d25ec0a4414b011142744f8f1821b47) (Ilya Kiselev)
- chore: fix unnecessary-format issues from revive [`7edfff3`](https://github.com/helm/helm/commit/7edfff33ebcb0f5d961afec34393c222de92de12) (Matthieu MOREL)
- chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 [`37185d2`](https://github.com/helm/helm/commit/37185d2ea6a091b93d2e71cc55ab16b2c0f3f9e9) (dependabot\[bot])
- chore: fix bool-compare issues from testifylint [`071558d`](https://github.com/helm/helm/commit/071558d69ffbb408dcb56403d387a1aa90a7d3a8) (Matthieu MOREL)
- chore: enable perfsprint linter [`6249489`](https://github.com/helm/helm/commit/62494896e9a105b63df2c76c638c53304a37121e) (Matthieu MOREL)
- ignore error plugin loads (cli, getter) [`47a0840`](https://github.com/helm/helm/commit/47a084091eeb1c5de221e061866b319f5b5f99f5) (George Jenkins)
- chore(deps): bump golang.org/x/crypto from 0.48.0 to 0.49.0 [`3d06fd1`](https://github.com/helm/helm/commit/3d06fd1feb37f11d050e78f7c17df3c713fcd344) (dependabot\[bot])
- fix(kube): remove legacy import comments from test files [`e64d628`](https://github.com/helm/helm/commit/e64d628a139fab8c876a1d2f4c2928096b286bed) (Terry Howe)
- pkg/kube: remove legacy import comments [`d7cdc9e`](https://github.com/helm/helm/commit/d7cdc9e8fb20c42d19a2371f37ee719be6be6b94) (abhay1999)
- fix: Plugin version path traversal [`36dcc27`](https://github.com/helm/helm/commit/36dcc27ca3c0cd6d0d08713b03dca82f43d7c5f9) (George Jenkins)
- chore(deps): bump golang.org/x/term from 0.40.0 to 0.41.0 [`c4be7af`](https://github.com/helm/helm/commit/c4be7af2a14c1a01f21231ebb5dd41806fcb0797) (dependabot\[bot])
- chore: fix some minor issues in the comments [`259f181`](https://github.com/helm/helm/commit/259f181808f267493d56eccd7f6191f78225a6fa) (tsinglua)
- fix: Chart dot-name path bug [`6018499`](https://github.com/helm/helm/commit/60184996e5332d26e0b6390cefbf86776829dc46) (George Jenkins)
- chore(deps): bump sigs.k8s.io/controller-runtime from 0.23.1 to 0.23.3 [`74e7cf8`](https://github.com/helm/helm/commit/74e7cf877a4a674b65f7b7894d2dfde2832e39b1) (dependabot\[bot])
- fix: insert newline after doc separators glued to content by template trimming [`af94abf`](https://github.com/helm/helm/commit/af94abf976ce69dd635aaf086a0bb4b17bd95bc1) (Matheus Pimenta)
- chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 [`16073b1`](https://github.com/helm/helm/commit/16073b1e3c7b90cda41ed70c8192eb6d16816723) (dependabot\[bot])
- chore: enable modernize linter ([#&#8203;31860](https://github.com/helm/helm/issues/31860)) [`e31a078`](https://github.com/helm/helm/commit/e31a078e6e0667dde72ff3bf4b5dfb625127076f) (Matthieu MOREL)
- Restored --atomic flag on install command [`16573f8`](https://github.com/helm/helm/commit/16573f87f5aebf8c2f9c40e67cc3cbe5eb93e733) (Travis Leeden)
- fix: bump go.opentelemetry.io/otel/sdk to v1.40.0 for GO-2026-4394 [`b550ce9`](https://github.com/helm/helm/commit/b550ce90946b3b47cecd290fc5d0eee637ddb531) (Terry Howe)
- fix: bump fluxcd/cli-utils to v0.37.2-flux.1 [`1dfa77e`](https://github.com/helm/helm/commit/1dfa77ed8ba6f9e26542064248bc9eab40c1a662) (Terry Howe)
- Update pkg/cmd/status.go [`5d40f17`](https://github.com/helm/helm/commit/5d40f17011a477620841edb740d381a012716ae8) (Matthieu MOREL)
- chore(internal): enable perfsprint linter ([#&#8203;31871](https://github.com/helm/helm/issues/31871)) [`d4f6193`](https://github.com/helm/helm/commit/d4f6193a7ec7ae9ea479da3372eeaf22b445ebcc) (Matthieu MOREL)
- chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 [`82d9bed`](https://github.com/helm/helm/commit/82d9bedea7d3e342011d82e2e11ff83b396dffbe) (dependabot\[bot])
- chore(pkg): fix perfsprint linter issues part 6 [`dc0e3f1`](https://github.com/helm/helm/commit/dc0e3f10c3ba8f25aa71c523d2e273690d338a17) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`e3c74fd`](https://github.com/helm/helm/commit/e3c74fd9fae52c85899ee0ca9a0c1422d59e2bc2) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`1d2d63c`](https://github.com/helm/helm/commit/1d2d63cc4330fcac786e70926f805b69c0b49ca2) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`63f03c0`](https://github.com/helm/helm/commit/63f03c0f5c41b53de3d432b446da9430da99f5bd) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`c25c988`](https://github.com/helm/helm/commit/c25c988cfb7bbe3b139dec39cad1db4be33b13c6) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`0fecfd0`](https://github.com/helm/helm/commit/0fecfd04c2f9a748046a8421595f3b9da6c895c7) (Matthieu MOREL)
- chore(internal): enable perfsprint linter [`6524162`](https://github.com/helm/helm/commit/6524162a0e39bed187a16b692243703d78735471) (Matthieu MOREL)
- chore(pkg): enable perfsprint linter [`6c2cb2f`](https://github.com/helm/helm/commit/6c2cb2f54784b5ef6158dca0660f428a3baf75f5) (Matthieu MOREL)
- chore(internal): enable perfsprint linter [`9409226`](https://github.com/helm/helm/commit/9409226e15b26d05621f0b263f4ad6f597dfb7aa) (Matthieu MOREL)
- Replace unneeded use of t.Fatalf with t.Fatal [`36cb3a2`](https://github.com/helm/helm/commit/36cb3a2fe92a4564d2d7d79141f209af19b45d40) (Mads Jensen)
- fix: enable nolinlint linter [`5b6c6bb`](https://github.com/helm/helm/commit/5b6c6bbfc7ca9850c69d3823ca1e21b445e75c0d) (Matthieu MOREL)
- fixup `strings.Cut` variables [`b667317`](https://github.com/helm/helm/commit/b6673174220a2633fe97b5cd70a8386b79103464) (George Jenkins)
- chore: Improve `AGENTS.md` [`956c724`](https://github.com/helm/helm/commit/956c7245c346fc304c24ace930dada5f2c99f2b1) (George Jenkins)
- chore:  fixes [`92b64e8`](https://github.com/helm/helm/commit/92b64e87ad6245d64d5b49bbbbf8dead83faac22) (George Jenkins)
- fix: correct import comment in statuswait.go from v3 to v4 [`c59c140`](https://github.com/helm/helm/commit/c59c140ce07ce973f16fe50c0c5e991e1d6308a6) (rohansood10)
- fix: handle OCI digest algorithm prefix in chart downloader ([#&#8203;31601](https://github.com/helm/helm/issues/31601)) [`ee01860`](https://github.com/helm/helm/commit/ee018608f6fbf381fac1bae9759164a65c6a0b1f) (Evans Mungai)
- chore(deps): bump actions/stale from 10.1.1 to 10.2.0 [`304d25f`](https://github.com/helm/helm/commit/304d25ffd34fafccbcb81713cb3cfff1be595ae5) (dependabot\[bot])
- chore(deps): bump the k8s-io group with 7 updates [`0b13436`](https://github.com/helm/helm/commit/0b134362f442fec44ace35e9cfae6760a6b4e005) (dependabot\[bot])
- feat(release): add internal/release/v2 package for chart v3 support ([#&#8203;31709](https://github.com/helm/helm/issues/31709)) [`4a91f3a`](https://github.com/helm/helm/commit/4a91f3ad5cc0c1521f6d4dcb5681e2da4baaa157) (Evans Mungai)
- chore(deps): bump golang.org/x/crypto from 0.47.0 to 0.48.0 [`7823853`](https://github.com/helm/helm/commit/782385397ce1871f4c8a4d2e3c857937bd8988c9) (dependabot\[bot])
- chore(deps): bump golang.org/x/term from 0.39.0 to 0.40.0 [`aec7ace`](https://github.com/helm/helm/commit/aec7aced38d053a2df5d0973abdf21848778a722) (dependabot\[bot])
- chore(deps): bump github.com/lib/pq from 1.11.1 to 1.11.2 [`a23b638`](https://github.com/helm/helm/commit/a23b6388ac74984460fd4055de5120d2fc03d841) (dependabot\[bot])
- chore(deps): bump golang.org/x/text from 0.33.0 to 0.34.0 [`5cddc95`](https://github.com/helm/helm/commit/5cddc95bed0572b8d63a910843f0a70477a4ce33) (dependabot\[bot])
- chore(deps): bump sigs.k8s.io/kustomize/kyaml from 0.21.0 to 0.21.1 [`2e266c3`](https://github.com/helm/helm/commit/2e266c3ec9d70a6e656f8041bb31475e25e9eb22) (dependabot\[bot])
- fix(pkg): errorlint linter [`259f76a`](https://github.com/helm/helm/commit/259f76a849391e6ff60a9a2e95ce7310d958c602) (Matthieu MOREL)
- fix(internal): errorlint linter [`0254182`](https://github.com/helm/helm/commit/025418291a7911441e7962895ba4bc24b72b55b3) (Matthieu MOREL)
- fix(pkg): errorlint linter [`6d1490e`](https://github.com/helm/helm/commit/6d1490ed1ea5968235087658d03bb440e4014a36) (Matthieu MOREL)
- fix(pkg): errorlint linter [`4d0ae7f`](https://github.com/helm/helm/commit/4d0ae7f33a09093f8f52d02b952e3822c87b8c5f) (Matthieu MOREL)
- fix(internal): errorlint linter [`abecafa`](https://github.com/helm/helm/commit/abecafa0f507a69888877b9ddb714095714b64c8) (Matthieu MOREL)
- fix(pkg): errorlint linter [`4330bde`](https://github.com/helm/helm/commit/4330bdea0409f428e75145f15532bfa0e2bc945c) (Matthieu MOREL)
- fix(pkg): errorlint linter [`c8989d9`](https://github.com/helm/helm/commit/c8989d984ff69e8ad21b27d6ac6193dd3150b1a7) (Matthieu MOREL)
- fix(cmd): errorlint linter [`edbd705`](https://github.com/helm/helm/commit/edbd705bd034246700cc0998016caa303cff42dc) (Matthieu MOREL)
- chore: new KEYS entry for George Jenkins [`5638c35`](https://github.com/helm/helm/commit/5638c35399464b6432ba81b92a341218991efa5c) (George Jenkins)
- fix(downloader): safely handle concurrent file writes on Windows [`76eb37c`](https://github.com/helm/helm/commit/76eb37c01aaece271343039f44d7803017dd5c81) (Orgad Shaneh)
- fix(install): check nil for restClientGetter and fix tests [`9817a68`](https://github.com/helm/helm/commit/9817a68618245370e98e09d7f06c7cc1cefe8a62) (Manuel Alonso)
- feat(create): add --chart-api-version flag (when HELM\_EXPERIMENTAL\_CHART\_V3 env var is set) ([#&#8203;31592](https://github.com/helm/helm/issues/31592)) [`5aac320`](https://github.com/helm/helm/commit/5aac32077f87ed8cd80da1648abbd323320d4a0b) (Evans Mungai)
- chore(pkg): fix modernize linter [`0d75d86`](https://github.com/helm/helm/commit/0d75d8611d3daa6b820d94fc95347a069b062f72) (Matthieu MOREL)
- chore(internal): fix modernize linter [`859292e`](https://github.com/helm/helm/commit/859292e31bd4ceb170050eaa49e727bcd69572e2) (Matthieu MOREL)
- chore(pkg): fix modernize linter [`5cc2e55`](https://github.com/helm/helm/commit/5cc2e55714d20e6d1bd2663878a00571c084d6c2) (Matthieu MOREL)
- chore(pkg): fix modernize linter [`ba38159`](https://github.com/helm/helm/commit/ba38159313d4f09280591ba7f860ef0523716220) (Matthieu MOREL)
- chore(internal): fix modernize linter [`e2d184c`](https://github.com/helm/helm/commit/e2d184c79e9049c19bcc466bfe1289ccc6b73717) (Matthieu MOREL)
- chore(pkg): fix modernize linter [`111d4e6`](https://github.com/helm/helm/commit/111d4e6e0e86af6ba25a355be1a7599f5258ee58) (Matthieu MOREL)
- add image index test [`e8f386b`](https://github.com/helm/helm/commit/e8f386b5aac232c114a036598c2e3015fe296edc) (Pedro Tôrres)
- fix pulling charts from OCI indices [`d983696`](https://github.com/helm/helm/commit/d983696e354a9e0605cbb3034937dc84af42995c) (Pedro Tôrres)
- chore(deps): bump github.com/lib/pq from 1.10.9 to 1.11.1 [`9c9c3a6`](https://github.com/helm/helm/commit/9c9c3a6b5c0f1cd1e4c4e9f002aa411c58dd656a) (dependabot\[bot])
- Revert "Consider GroupVersionKind when matching resources" [`787b61c`](https://github.com/helm/helm/commit/787b61cedb933d22011e1da1368d0e615ea60ffe) (Matheus Pimenta)
- chore(deps): bump sigs.k8s.io/controller-runtime from 0.23.0 to 0.23.1 [`becf9bf`](https://github.com/helm/helm/commit/becf9bf7e33867a3f26affac34e9d51e277767bf) (dependabot\[bot])
- fix(template): deprecate unused --hide-notes and --render-subchart-notes flags [`6d5f56f`](https://github.com/helm/helm/commit/6d5f56fa6e7c8e4462d80895fcce87b926e4b8ce) (Scott Rigby)
- chore(deps): bump github.com/fluxcd/cli-utils [`b53198e`](https://github.com/helm/helm/commit/b53198e7eee04dab651c15cb7b3b6b77dd92553c) (dependabot\[bot])
- chore(deps): bump actions/checkout from 6.0.1 to 6.0.2 [`b59e533`](https://github.com/helm/helm/commit/b59e533b7675122631e0733adbfd6b35dd3515a6) (dependabot\[bot])
- whitespace [`ec07265`](https://github.com/helm/helm/commit/ec0726523e52448eb05c8b5b3faae969e3a79266) (Austin Abro)
- fix(copystructure): handle nil elements in slice copying [`e3829eb`](https://github.com/helm/helm/commit/e3829ebbbb833e159926c6193e474eb9d067ef75) (Philipp Born)
- use logger with waiter [`63b40a7`](https://github.com/helm/helm/commit/63b40a7a5e0d3f00ef2b4c1de9f50fb7d6df4ead) (Austin Abro)
- feat(kstatus): fine-grained context options for waiting [`b0b35f1`](https://github.com/helm/helm/commit/b0b35f1231b0b885b1624c5586938cfa69d30995) (Matheus Pimenta)
- Apply suggestions from code review [`26e28e8`](https://github.com/helm/helm/commit/26e28e846af1ceaf63e16c4f2e52bbfbab411ba1) (George Jenkins)
- Remove legacy sync-repo.sh script [`97fd007`](https://github.com/helm/helm/commit/97fd00786f16ebc3b68164bff7133592f19f70b6) (Jeevan Yewale)
- chore(deps): bump sigs.k8s.io/controller-runtime from 0.22.4 to 0.23.0 [`5262007`](https://github.com/helm/helm/commit/52620076e21ad6afd0f48df6772001b1466c966b) (dependabot\[bot])
- docs: document uninstall using cascade foreground flag [`e70d59d`](https://github.com/helm/helm/commit/e70d59de7cd7ea2a501d809b3245ebfa0412e0ec) (Evans Mungai)
- bugfix(kstatus): do not wait forever on failed resources [`bbec77c`](https://github.com/helm/helm/commit/bbec77c1f762c4d92678e7f455951757a2e036a3) (Matheus Pimenta)
- Modernize Helm v3 CONTRIBUTING.md [`443a2a6`](https://github.com/helm/helm/commit/443a2a6924fc384e87ff4251e5ac9c077d607f0f) (George Jenkins)
- chore(defaults): server-side apply SDK defaults should always match the CLI defaults [`c1cc625`](https://github.com/helm/helm/commit/c1cc6253232d697ad2ae29957cc49de223306b62) (Matheus Pimenta)
- chore: clarify --wait flag help text [`828038a`](https://github.com/helm/helm/commit/828038a8fe2142599ec557da2d12bb88b76fa0dd) (Evans Mungai)
- chore(deps): bump actions/setup-go from 6.1.0 to 6.2.0 [`e223771`](https://github.com/helm/helm/commit/e22377124dbca4b032c55f522358def0415a0e8a) (dependabot\[bot])
- chore(refactor): better testing and functionality for installing crd [`6501ef4`](https://github.com/helm/helm/commit/6501ef490a45e9b7edfed1432702532c5b11c6d2) (Manuel Alonso)
- bugfix(storage): fix storage not getting logger from driver [`a8eb527`](https://github.com/helm/helm/commit/a8eb5278478c940c615741312ca9f4fec0d84c1a) (Matheus Pimenta)
- chore(deps): bump golang.org/x/crypto from 0.46.0 to 0.47.0 [`da1d68a`](https://github.com/helm/helm/commit/da1d68adea91ab13b308c059c39381d48045a73a) (dependabot\[bot])
- fix(test): fix tests and check nil for restclient [`0f949a9`](https://github.com/helm/helm/commit/0f949a92c149cf11e5bb19caf4d19d05567be6eb) (Manuel Alonso)
- fix(test): merge fix correctly [`561410a`](https://github.com/helm/helm/commit/561410ae1d09c2aa289ff8d8cad5b7fa979cd135) (Manuel Alonso Gonzalez)
- Remove refactorring changes from coalesce\_test.go [`0298b2f`](https://github.com/helm/helm/commit/0298b2ffd0823eead74c75e1b890b0bf47d0db62) (Evans Mungai)
- Fix import [`b8937ad`](https://github.com/helm/helm/commit/b8937ad1922bca47be8bbf8e6274608ebc34a778) (Evans Mungai)
- Update pkg/chart/common/util/coalesce\_test.go [`a333bba`](https://github.com/helm/helm/commit/a333bbaf273645bf53fb873228040ca8edde849a) (Evans Mungai)
- Fix rollback for missing resources [`374aeb4`](https://github.com/helm/helm/commit/374aeb4b4e0463f72e3a0175138ed4bf7e87a156) (Feruzjon Muyassarov)
- fix(install): add more tests and check nil file data [`00f0a48`](https://github.com/helm/helm/commit/00f0a48a7dae379c2b6bd0dea43984d42b27a494) (Manuel Alonso)
- fix(test): no check empty resources [`0357e8d`](https://github.com/helm/helm/commit/0357e8d0f7eab074252ca49e1ca3aded834a001d) (Manuel Alonso)
- fix(install): check lenght and file nil, add tests [`52235cc`](https://github.com/helm/helm/commit/52235cc0bf7d0c8faf17c7dc8cddd77f93434aea) (Manuel Alonso)
- fix(action): crd resources can be empty [`268593b`](https://github.com/helm/helm/commit/268593bf2e9769ef4b75328b33dfb4195e6e9e5a) (Manuel Alonso)
- fix: casing issue fixed [`1709114`](https://github.com/helm/helm/commit/170911459bc4f2b5efea7e549e09bd45c7578cc4) (Mujib Ahasan)
- fix: error handled correctly [`9486062`](https://github.com/helm/helm/commit/94860626ce9c83a9227b5bce02a5c03a050816ac) (Mujib Ahasan)
- fix: doc string added [`12e8b71`](https://github.com/helm/helm/commit/12e8b715aa0732b613c3a9896fa6af29b3201536) (Mujib Ahasan)
- Fix lint warning [`3416dd5`](https://github.com/helm/helm/commit/3416dd5f215a6421a70c6ab22340a96312ce8c0b) (Evans Mungai)
- Preserve nil values in chart already [`679f051`](https://github.com/helm/helm/commit/679f0519804afeaa5ce8b930a30976ade2860fe0) (Evans Mungai)
- fix(values): preserve nil values when chart default is empty map [`292fe70`](https://github.com/helm/helm/commit/292fe702193e8ba9ce4c8ffffdd90cdfa761501c) (Evans Mungai)
- update: test coverage added for helper function validateNameAndGenerateName [`1154099`](https://github.com/helm/helm/commit/115409976b5c3fd94c893eabde114e655c01c573) (Mujib Ahasan)
- update: helper function added for the business logic [`522d2fe`](https://github.com/helm/helm/commit/522d2fe61508639cfe8f06a43235e7c3eaea3b9a) (Mujib Ahasan)
- generateName is also considered in logic [`6769fb6`](https://github.com/helm/helm/commit/6769fb6fb6704e29fe1215c802ecf0ea62b39715) (Mujib Ahasan)
- fxi: test concurrency download index [`64bae71`](https://github.com/helm/helm/commit/64bae717c58e80f05a60b84ddcd1f78387b4caee) (Terry Howe)
- update: business logic respected for skipping object missing name [`b357bca`](https://github.com/helm/helm/commit/b357bcae8640508f110b7e63a8dfacd865c27b6e) (Mujib Ahasan)
- fixed: --dry-run=server now respect generateName [`2820ebe`](https://github.com/helm/helm/commit/2820ebe8c97b7d7b8a447375b74c9cb3741a4ffa) (Mujib Ahasan)
- Make error message instructional for the case of lock file being out of date [`1836c59`](https://github.com/helm/helm/commit/1836c598f06377fd1571702fb2e0642f004cedef) (Andreas Sommer)

#### New Contributors

- [@&#8203;JeevanYewale](https://github.com/JeevanYewale) made their first contribution in [#&#8203;31742](https://github.com/helm/helm/pull/31742)
- [@&#8203;tamcore](https://github.com/tamcore) made their first contribution in [#&#8203;31751](https://github.com/helm/helm/pull/31751)
- [@&#8203;orgads](https://github.com/orgads) made their first contribution in [#&#8203;31128](https://github.com/helm/helm/pull/31128)
- [@&#8203;manute](https://github.com/manute) made their first contribution in [#&#8203;31578](https://github.com/helm/helm/pull/31578)
- [@&#8203;Mujib-Ahasan](https://github.com/Mujib-Ahasan) made their first contribution in [#&#8203;31563](https://github.com/helm/helm/pull/31563)
- [@&#8203;rohansood10](https://github.com/rohansood10) made their first contribution in [#&#8203;31852](https://github.com/helm/helm/pull/31852)
- [@&#8203;tleed5](https://github.com/tleed5) made their first contribution in [#&#8203;31901](https://github.com/helm/helm/pull/31901)
- [@&#8203;tsinglua](https://github.com/tsinglua) made their first contribution in [#&#8203;31921](https://github.com/helm/helm/pull/31921)
- [@&#8203;abhay1999](https://github.com/abhay1999) made their first contribution in [#&#8203;31931](https://github.com/helm/helm/pull/31931)
- [@&#8203;Mentigen](https://github.com/Mentigen) made their first contribution in [#&#8203;31957](https://github.com/helm/helm/pull/31957)
- [@&#8203;Debasish-87](https://github.com/Debasish-87) made their first contribution in [#&#8203;31973](https://github.com/helm/helm/pull/31973)
- [@&#8203;AnmolVirdi](https://github.com/AnmolVirdi) made their first contribution in [#&#8203;32014](https://github.com/helm/helm/pull/32014)
- [@&#8203;Y0-L0](https://github.com/Y0-L0) made their first contribution in [#&#8203;31979](https://github.com/helm/helm/pull/31979)
- [@&#8203;MohitSalvi16](https://github.com/MohitSalvi16) made their first contribution in [#&#8203;32057](https://github.com/helm/helm/pull/32057)
- [@&#8203;rhysmcneill](https://github.com/rhysmcneill) made their first contribution in [#&#8203;32008](https://github.com/helm/helm/pull/32008)
- [@&#8203;cairon-ab](https://github.com/cairon-ab) made their first contribution in [#&#8203;32034](https://github.com/helm/helm/pull/32034)
- [@&#8203;gaganhr94](https://github.com/gaganhr94) made their first contribution in [#&#8203;31923](https://github.com/helm/helm/pull/31923)
- [@&#8203;isumitsolanki](https://github.com/isumitsolanki) made their first contribution in [#&#8203;31970](https://github.com/helm/helm/pull/31970)

**Full Changelog**: <https://github.com/helm/helm/compare/v4.1.0...v4.2.0>

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/48
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 07:06:48 +00:00
ff7e4b8894 chore(deps): update actions/checkout action to v7 (#41)
scan.yaml / test (push) Successful in 13s
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://github.com/actions/checkout) | action | major | `v4` → `v7` |

---

### Release Notes

<details>
<summary>actions/checkout (actions/checkout)</summary>

### [`v7.0.1`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701)

[Compare Source](https://github.com/actions/checkout/compare/v7.0.0...v7.0.1)

- Skip running unsafe pr check if input is default by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2518](https://github.com/actions/checkout/pull/2518)
- Trim only ascii whitespace for branch by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2521](https://github.com/actions/checkout/pull/2521)
- Escape values passed to --unset by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2530](https://github.com/actions/checkout/pull/2530)
- Various dependency updates

### [`v7.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare Source](https://github.com/actions/checkout/compare/v6.1.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2454](https://github.com/actions/checkout/pull/2454)
- Various dependency updates

### [`v6.1.0`](https://github.com/actions/checkout/releases/tag/v6.1.0)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.3...v6.1.0)

#### What's Changed

- **\[BREAKING]** backport `allow-unsafe-pr-checkout` to v6 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2500](https://github.com/actions/checkout/pull/2500)
- backport fixes to releases-v6 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2527](https://github.com/actions/checkout/pull/2527)

<https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/> for more details about this breaking change

**Full Changelog**: <https://github.com/actions/checkout/compare/v6.0.3...v6.1.0>

### [`v6.0.3`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v603)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.2...v6.0.3)

- Fix checkout init for SHA-256 repositories by [@&#8203;yaananth](https://github.com/yaananth) in [#&#8203;2439](https://github.com/actions/checkout/pull/2439)
- fix: expand merge commit SHA regex and add SHA-256 test cases by [@&#8203;yaananth](https://github.com/yaananth) in [#&#8203;2414](https://github.com/actions/checkout/pull/2414)

### [`v6.0.2`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v602)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.1...v6.0.2)

- Fix tag handling: preserve annotations and explicit fetch-tags by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2356](https://github.com/actions/checkout/pull/2356)

### [`v6.0.1`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v601)

[Compare Source](https://github.com/actions/checkout/compare/v6.0.0...v6.0.1)

- Add worktree support for persist-credentials includeIf by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2327](https://github.com/actions/checkout/pull/2327)

### [`v6.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v600)

[Compare Source](https://github.com/actions/checkout/compare/v5.1.0...v6.0.0)

- Persist creds to a separate file by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2286](https://github.com/actions/checkout/pull/2286)
- Update README to include Node.js 24 support details and requirements by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;2248](https://github.com/actions/checkout/pull/2248)

### [`v5.1.0`](https://github.com/actions/checkout/releases/tag/v5.1.0)

[Compare Source](https://github.com/actions/checkout/compare/v5.0.1...v5.1.0)

#### What's Changed

- **\[BREAKING]** backport `allow-unsafe-pr-checkout` to v5 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2501](https://github.com/actions/checkout/pull/2501)
- backport fixes to releases-v5 by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2523](https://github.com/actions/checkout/pull/2523)

<https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/> for more details about this breaking change

**Full Changelog**: <https://github.com/actions/checkout/compare/v5.0.1...v5.1.0>

### [`v5.0.1`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v501)

[Compare Source](https://github.com/actions/checkout/compare/v5.0.0...v5.0.1)

- Port v6 cleanup to v5 by [@&#8203;ericsciple](https://github.com/ericsciple) in [#&#8203;2301](https://github.com/actions/checkout/pull/2301)

### [`v5.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v500)

[Compare Source](https://github.com/actions/checkout/compare/v4.4.0...v5.0.0)

- Update actions checkout to use node 24 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;2226](https://github.com/actions/checkout/pull/2226)

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #41
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 07:05:19 +00:00
danijel.simeunovic 5bb21167fd chore(deps): update dependency claude-code to v2
scan.yaml / test (push) Successful in 17s
AI Code Review / ai-review (pull_request) Skipped
scan.yaml / test (pull_request) Successful in 15s
commit 00efdd8cd2
Author: gitea_admin <admin@forteapps.net>
Date:   Tue Sep 29 07:00:47 2026 +0000

    chore(deps): update dependency github-cli to v2 (#47)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [github-cli](https://cli.github.com/) | major | `0.12.0` → `2.23.0` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: #47
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit d480daccc8
Author: gitea_admin <admin@forteapps.net>
Date:   Tue Sep 29 07:00:03 2026 +0000

    chore(deps): update dependency argocd to v3 (#43)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [argocd](https://argo-cd.readthedocs.io/en/stable/) | major | `2.14.11` → `3.4.6` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: #43
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>

commit 66f1dce46f
Author: gitea_admin <admin@forteapps.net>
Date:   Tue Sep 29 06:59:17 2026 +0000

    chore(deps): update dependency dotnet-sdk to v8 (#46)

    This PR contains the following updates:

    | Package | Update | Change |
    |---|---|---|
    | [dotnet-sdk](https://dotnet.github.io/) | major | `2.1.810` → `8.0.424` |

    ---

    ### Configuration

    📅 **Schedule**: (in timezone Europe/Oslo)

    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)

    🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

    🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

    ---

     - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

    ---

    This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
    <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

    ---------

    Co-authored-by: Renovate Bot <renovate@forteapps.net>
    Reviewed-on: #46
    Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
    Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 09:03:34 +02:00
00efdd8cd2 chore(deps): update dependency github-cli to v2 (#47)
scan.yaml / test (push) Successful in 14s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [github-cli](https://cli.github.com/) | major | `0.12.0` → `2.23.0` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #47
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 07:00:47 +00:00
d480daccc8 chore(deps): update dependency argocd to v3 (#43)
scan.yaml / test (push) Successful in 15s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [argocd](https://argo-cd.readthedocs.io/en/stable/) | major | `2.14.11` → `3.4.6` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #43
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 07:00:03 +00:00
66f1dce46f chore(deps): update dependency dotnet-sdk to v8 (#46)
scan.yaml / test (push) Successful in 17s
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [dotnet-sdk](https://dotnet.github.io/) | major | `2.1.810` → `8.0.424` |

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: #46
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
2026-09-29 06:59:17 +00:00
14 changed files with 55 additions and 19 deletions
+5 -4
View File
@@ -23,14 +23,15 @@ jobs:
REVIEW__INLINE_COMMENT_FALLBACK: "false" REVIEW__INLINE_COMMENT_FALLBACK: "false"
# LLM configuration # LLM configuration
LLM__PROVIDER: CLAUDE LLM__PROVIDER: CLAUDE
LLM__META__MODEL: claude-3-opus LLM__META__MODEL: claude-sonnet-5-5
LLM__META__REASONING__EFFORT: high
LLM__META__MAX_TOKENS: "4096" LLM__META__MAX_TOKENS: "4096"
LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com LLM__HTTP_CLIENT__API_URL: https://api.anthropic.com
LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }} LLM__HTTP_CLIENT__API_TOKEN: ${{ secrets.ANTHROPIC_API_KEY }}
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@v4 uses: actions/checkout@v7
with: with:
submodules: true submodules: true
fetch-depth: 0 fetch-depth: 0
@@ -40,11 +41,11 @@ jobs:
run: git submodule update --remote --merge run: git submodule update --remote --merge
- name: Run inline review - name: Run inline review
uses: docker://nikitafilonov/ai-review:v0.77.0 uses: docker://nikitafilonov/ai-review:v1.1.0
with: with:
args: ai-review run-inline args: ai-review run-inline
- name: Run summary review - name: Run summary review
uses: docker://nikitafilonov/ai-review:v0.77.0 uses: docker://nikitafilonov/ai-review:v1.1.0
with: with:
args: ai-review run-summary args: ai-review run-summary
+1 -1
View File
@@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout code - name: Checkout code
uses: actions/checkout@v4 uses: actions/checkout@v7
with: with:
fetch-depth: 0 fetch-depth: 0
- name: Install TruffleHog - name: Install TruffleHog
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
} }
} }
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
azuread = { azuread = {
source = "hashicorp/azuread" source = "hashicorp/azuread"
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
} }
} }
+1 -1
View File
@@ -4,7 +4,7 @@ terraform {
required_providers { required_providers {
azurerm = { azurerm = {
source = "hashicorp/azurerm" source = "hashicorp/azurerm"
version = "~> 4.0" version = "~> 5.0"
} }
random = { random = {
source = "hashicorp/random" source = "hashicorp/random"
+1 -1
View File
@@ -29,7 +29,7 @@ spec:
topologyKey: kubernetes.io/hostname topologyKey: kubernetes.io/hostname
initContainers: initContainers:
- name: gitea-dump - name: gitea-dump
image: gitea/gitea:1.27.3 image: gitea/gitea:28.0.0
command: command:
- sh - sh
- -c - -c
+4 -4
View File
@@ -5,7 +5,7 @@
"kubernetes-helm@4.2.4", "kubernetes-helm@4.2.4",
"k9s@0.51.0", "k9s@0.51.0",
"kubeseal@0.38.4", "kubeseal@0.38.4",
"argocd@2.14.11", "argocd@3.4.6",
"kubecm@0.35.1", "kubecm@0.35.1",
"kubectl-tree@0.6.0", "kubectl-tree@0.6.0",
"kind@0.32.0", "kind@0.32.0",
@@ -14,12 +14,12 @@
"syft@1.51.0", "syft@1.51.0",
"grype@0.118.0", "grype@0.118.0",
"traefik@3.7.10", "traefik@3.7.10",
"claude-code@0.2.122", "claude-code@2.1.245",
"go@latest", "go@latest",
"dotnet-sdk@2.1.810", "dotnet-sdk@8.0.424",
"opentofu@1.12.5", "opentofu@1.12.5",
"_1password@2.30.0", "_1password@2.30.0",
"github-cli@0.12.0", "github-cli@2.23.0",
"upcloud-cli@3.36.0", "upcloud-cli@3.36.0",
"awscli2@2.35.11" "awscli2@2.35.11"
], ],
+6
View File
@@ -1469,6 +1469,12 @@ ArgoCD will sync the Keycloak config, and the registrar CronJob will pick up the
| `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret | | `k8s.secret.client-id-key` | No | `client-id` | Field name for the client ID in the K8s Secret |
| `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret | | `k8s.secret.client-secret-key` | No | `client-secret` | Field name for the client secret in the K8s Secret |
#### Public CLI Client (Device-Code Login)
`forte-cli` is a shared **public** client (no secret) with the RFC 8628 device-authorization grant enabled (`oauth2.device.authorization.grant.enabled: "true"`, `standardFlowEnabled: false`, `directAccessGrantsEnabled: false`). Downloaded skills and CLI tools that log in through the Auth Sidecar (forte-drop first) use it with `<PREFIX>_CLIENT_ID=forte-cli`; nothing per-tool needs to be registered in Keycloak.
It must be defined in `forte-realm.json` (this legacy path): the self-service registrar hardcodes `publicClient: false` / `standardFlowEnabled: true` and drops `attributes`, so a `client-config` Secret cannot produce a public device-code client. It carries no `k8s.secret.sync` attribute (the registrar's secret sync skips it) and is listed in the cleanup CronJob's protected clients.
### Retrieving Secrets for External Deployments ### Retrieving Secrets for External Deployments
The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster: The registrar always writes a **central copy** of every synced secret to the `secrets` namespace, in addition to the target namespace. This allows operators to retrieve client credentials for applications deployed outside this cluster:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://fluent.github.io/helm-charts - repoURL: https://fluent.github.io/helm-charts
chart: fluent-bit chart: fluent-bit
targetRevision: 0.58.2 targetRevision: 0.58.3
helm: helm:
releaseName: fluent-bit releaseName: fluent-bit
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://opencost.github.io/opencost-helm-chart - repoURL: https://opencost.github.io/opencost-helm-chart
chart: opencost chart: opencost
targetRevision: "1.43.2" targetRevision: "2.5.32"
helm: helm:
releaseName: opencost releaseName: opencost
valueFiles: valueFiles:
+1 -1
View File
@@ -17,7 +17,7 @@ spec:
sources: sources:
- repoURL: https://prometheus-community.github.io/helm-charts - repoURL: https://prometheus-community.github.io/helm-charts
chart: prometheus chart: prometheus
targetRevision: "28.16.0" targetRevision: "29.35.0"
helm: helm:
releaseName: prometheus releaseName: prometheus
valueFiles: valueFiles:
+30 -1
View File
@@ -186,6 +186,35 @@ keycloakConfigCli:
} }
} }
] ]
},
{
"clientId": "forte-cli",
"name": "Forte CLI",
"description": "Shared public client for RFC 8628 device-code login from downloaded skills/CLI tools (forte-drop first) against services behind Auth Sidecar. No client secret.",
"enabled": true,
"protocol": "openid-connect",
"standardFlowEnabled": false,
"directAccessGrantsEnabled": false,
"publicClient": true,
"redirectUris": [],
"webOrigins": [],
"attributes": {
"oauth2.device.authorization.grant.enabled": "true"
},
"protocolMappers": [
{
"name": "audience-forte-drop-mcp",
"protocol": "openid-connect",
"protocolMapper": "oidc-audience-mapper",
"consentRequired": false,
"config": {
"included.custom.audience": "https://mcp.drop.forteapps.net/mcp",
"access.token.claim": "true",
"id.token.claim": "false",
"introspection.token.claim": "true"
}
}
]
} }
], ],
"browserFlow": "browser-auto-idp", "browserFlow": "browser-auto-idp",
@@ -671,7 +700,7 @@ extraDeploy:
MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400)) MIN_AGE_SEC=$((MIN_AGE_DAYS * 86400))
# Hardcoded protected clients (never delete these) # Hardcoded protected clients (never delete these)
PROTECTED_JSON='["gitea","grafana","argocd","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]' PROTECTED_JSON='["gitea","grafana","argocd","forte-cli","vaultwarden","account","account-console","admin-cli","broker","realm-management","security-admin-console"]'
echo "Fetching clients from realm '${REALM}'..." echo "Fetching clients from realm '${REALM}'..."
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \ CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \