chore(helm): update chart cert-manager v1.16.1 → v1.16.2 (#29640)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [cert-manager](https://cert-manager.io)
([source](https://redirect.github.com/cert-manager/cert-manager)) |
patch | `v1.16.1` -> `v1.16.2` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>cert-manager/cert-manager (cert-manager)</summary>

###
[`v1.16.2`](https://redirect.github.com/cert-manager/cert-manager/releases/tag/v1.16.2)

[Compare
Source](https://redirect.github.com/cert-manager/cert-manager/compare/v1.16.1...v1.16.2)

cert-manager is the easiest way to automatically manage certificates in
Kubernetes and OpenShift clusters.

This patch release of cert-manager 1.16 makes [several
changes](https://redirect.github.com/cert-manager/cert-manager/pull/7401)
to how PEM input is validated, adding maximum sizes appropriate to the
type of PEM data which is being parsed.

This is to prevent an unacceptable slow-down in parsing specially
crafted PEM data. The issue was found by Google's OSS-Fuzz project.

The issue is low severity; to exploit the PEM issue would require
privileged access which would likely allow Denial-of-Service through
other methods.

Note also that since most PEM data parsed by cert-manager comes from
`ConfigMap` or `Secret` resources which have a max size limit of
approximately 1MB, it's difficult to force cert-manager to parse large
amounts of PEM data.

Further information is available in
https://github.com/cert-manager/cert-manager/security/advisories/GHSA-r4pg-vg54-wxx4

In addition, the version of Go used to build cert-manager 1.16 was
updated along with the base images.

#### Changes by Kind

##### Bug or Regression

- Set a maximum size for PEM inputs which cert-manager will accept to
remove possibility of taking a long time to process an input
([#&#8203;7401](https://redirect.github.com/cert-manager/cert-manager/issues/7401),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))

##### Other (Cleanup or Flake)

- Bump go to 1.23.3 and bump base images to latest available
([#&#8203;7431](https://redirect.github.com/cert-manager/cert-manager/issues/7431),
[@&#8203;SgtCoDFish](https://redirect.github.com/SgtCoDFish))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC4xNDIuNyIsInVwZGF0ZWRJblZlciI6IjM4LjE0Mi43IiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInJlbm92YXRlL2hlbG0iLCJ0eXBlL3BhdGNoIl19-->

---------

Signed-off-by: alfi0812 <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: alfi0812 <43101280+alfi0812@users.noreply.github.com>
This commit is contained in:
TrueCharts Bot
2025-01-10 09:55:32 +00:00
committed by GitHub
co-authored by alfi0812
parent 1119d25f2b
commit c3066b0e43
+2 -2
View File
@@ -16,7 +16,7 @@ dependencies:
tags: []
import-values: []
- name: cert-manager
version: v1.16.1
version: v1.16.2
repository: https://charts.jetstack.io
condition: ""
alias: certmanager
@@ -42,4 +42,4 @@ sources:
- https://github.com/truecharts/charts/tree/master/charts/system/cert-manager
- https://github.com/truecharts/containers/tree/master/apps/scratch
type: application
version: 6.4.0
version: 6.4.1