Skip to content

fix(openhands): bump rancher/kubectl to v1.33.13 - #1385

Draft
dylan-openhands wants to merge 1 commit into
mainfrom
dj/c3-0713-kubectl-main
Draft

dylan-openhands wants to merge 1 commit into
mainfrom
dj/c3-0713-kubectl-main

Conversation

@dylan-openhands

Copy link
Copy Markdown
Contributor

Bumps rancher/kubectl from v1.33.0 to v1.33.13 (latest v1.33.x on Docker Hub, published 2026-06-24). Same minor, so the kubectl client/apiserver skew policy is unchanged. It is used only by the crd-check pre-install/pre-upgrade hook (crdCheck.image) in the openhands and infra charts.

Sites changed: charts/openhands/values.yaml crdCheck.image.tag, charts/infra/values.yaml crdCheck.image.tag, and the example block in charts/crd-check/templates/_hook.tpl. crd-check is consumed as a remote OCI dependency (oci://ghcr.io/openhands/helm-charts 0.1.0), so the _hook.tpl edit is documentation only; the rendered tag comes from the consumer's values. replicated/openhands.yaml and replicated/infra-trust-manager.yaml override only the repository, so they need no change.

Scans (Trivy, DB 2026-10-09T19:06Z, linux/amd64, HIGH/CRITICAL, by digest):

Tag Digest Fixable C Fixable H
v1.33.0 (current) sha256:fbd00b08...8217 1 33
v1.33.11 sha256:c95f0578...6bdf93 0 25
v1.33.12 sha256:01f9febd...970393 0 25
v1.33.13 (chosen) sha256:e4a764a4...2834 0 18

No new fixable C/H versus v1.33.0 (16 resolved, 0 new). The residual 18 HIGH are Go stdlib 1.25.11 and golang.org/x/net/x/text inside the kubectl binary, with no newer v1.33.x to pick up.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: fix A bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant