Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package helm3 for openSUSE:Factory checked 
in at 2026-09-21 12:13:28
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/helm3 (Old)
 and      /work/SRC/openSUSE:Factory/.helm3.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "helm3"

Mon Sep 21 12:13:28 2026 rev:24 rq:1379237 version:3.22.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/helm3/helm3.changes      2026-09-04 
12:40:02.591811547 +0200
+++ /work/SRC/openSUSE:Factory/.helm3.new.383539/helm3.changes  2026-09-21 
12:13:55.386974739 +0200
@@ -1,0 +2,66 @@
+Sun Sep 20 11:33:36 UTC 2026 - Dirk Müller <[email protected]>
+
+- Update to version 3.22.0 (
+      bsc#1281104, CVE-2026-85731,
+      bsc#1281112, CVE-2026-85732):
+  * chore(deps): bump the k8s-io group across 1 directory with 6 updates
+  * bump version to 3.22 (#32606)
+  * fix: set [pull,push] scope when helm push to a registry(use token auth) 
(backport) (#32362)
+  * chore(deps): bump the k8s-io group with 7 updates (#32573)
+  * chore(deps): bump github.com/stretchr/testify from 1.12.0 to 1.12.1 
(#32563)
+  * chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 
(#32554)
+  * chore(deps): bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#32542)
+  * [dev-v3 backport] deps: bump google.golang.org/[email protected] for 
GO-2026-6061 (#32536)
+  * fix: bump go.opentelemetry.io/[email protected] for GO-2026-5158 (#32535)
+  * chore(deps): bump github.com/santhosh-tekuri/jsonschema/v6
+  * fix(provenance): migrate to ProtonMail/go-crypto to resolve GO-2026-5932
+  * chore(deps): bump the k8s-io group with 7 updates
+  * chore(deps): bump github/codeql-action/upload-sarif (#32449)
+  * chore(deps): bump github/codeql-action/analyze from 4.37.1 to 4.37.2
+  * chore(deps): bump github/codeql-action/autobuild from 4.37.1 to 4.37.2
+  * chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.2
+  * chore(deps): bump github/codeql-action/autobuild from 4.37.0 to 4.37.1 
(#32381)
+  * chore(deps): bump github/codeql-action/upload-sarif (#32382)
+  * ci: auto-label PRs targeting dev-v3 (#32340)
+  * chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#32331)
+  * chore(deps): bump github.com/mattn/go-shellwords from 1.0.13 to 1.0.14 
(#32332)
+  * chore(deps): bump github/codeql-action/analyze from 3.26.6 to 4.37.0 
(#32357)
+  * chore(deps): bump github/codeql-action/upload-sarif (#32360)
+  * chore(deps): bump github/codeql-action/init from 3.26.6 to 4.37.0 (#32359)
+  * chore(deps): bump golang/govulncheck-action from 1.0.4 to 1.1.0 (#32356)
+  * chore(deps): bump golangci/golangci-lint-action from 6.1.1 to 9.3.0 
(#32354)
+  * chore(deps): bump ossf/scorecard-action from 2.4.0 to 2.4.3 (#32353)
+  * chore(deps): bump golang.org/x/text from 0.38.0 to 0.40.0 (#32310)
+  * chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#32308)
+  * chore(deps): bump golang.org/x/term from 0.44.0 to 0.45.0 (#32306)
+  * fix(engine): prevent Files.Lines panic on empty file
+  * Apply suggestions from code review
+  * fix: drop containerd v1 dep to resolve govulncheck CVEs
+  * chore(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33
+  * chore(deps): bump github.com/cyphar/filepath-securejoin
+  * chore(deps): bump the k8s-io group with 2 updates
+  * fixes
+  * chore(deps): bump the k8s-io group across 1 directory with 2 updates
+  * fix(registry): keep credentials on plain-HTTP fallback with oras-go v2.6.1
+  * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1
+  * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
+  * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
+  * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
+  * Update .github/env
+  * ci: bump golangci-lint to v2.11.3 for go 1.26
+  * chore: bump go to 1.26
+  * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3
+  * chore(deps): bump github.com/distribution/distribution/v3
+  * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32
+  * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0
+  * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13
+  * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0
+  * fix(deps): bump golang.org/x/net to v0.55.0 to address GO-2026-5026
+  * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0
+  * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0
+  * [v3] Bump to version v3.21 (#32103)
+  * [v3 backport] Fix rollback for missing resources
+  * fix(action): avoid nil REST client getter panic when installing CRDs
+- drop CVE-2026-63308.patch: merged upstream
+
+-------------------------------------------------------------------
@@ -768,2 +833,0 @@
-  * chore(deps): bump actions/setup-go from 4.1.0 to 5.0.0 cbab6d6
-    (dependabot[bot])
@@ -780,2 +843,0 @@
-  * chore(deps): bump actions/setup-go from 4.1.0 to 5.0.0 f980ad3
-    (dependabot[bot])

Old:
----
  CVE-2026-63308.patch
  helm3-3.21.3.obscpio

New:
----
  helm3-3.22.0.obscpio

----------(Old B)----------
  Old:  * fix(action): avoid nil REST client getter panic when installing CRDs
- drop CVE-2026-63308.patch: merged upstream
----------(Old E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ helm3.spec ++++++
--- /var/tmp/diff_new_pack.IUwRKw/_old  2026-09-21 12:13:56.709029999 +0200
+++ /var/tmp/diff_new_pack.IUwRKw/_new  2026-09-21 12:13:56.711030083 +0200
@@ -19,7 +19,7 @@
 %define goipath helm.sh/helm/v3
 %define git_dirty clean
 Name:           helm3
-Version:        3.21.3
+Version:        3.22.0
 Release:        0
 Summary:        The Kubernetes Package Manager
 License:        Apache-2.0
@@ -27,7 +27,6 @@
 URL:            https://github.com/helm/helm
 Source0:        %{name}-%{version}.tar.gz
 Source1:        vendor.tar.zst
-Patch1:         CVE-2026-63308.patch
 Provides:       helm = %{version}
 BuildRequires:  fish
 BuildRequires:  golang-packaging

++++++ _service ++++++
--- /var/tmp/diff_new_pack.IUwRKw/_old  2026-09-21 12:13:56.744031462 +0200
+++ /var/tmp/diff_new_pack.IUwRKw/_new  2026-09-21 12:13:56.748031630 +0200
@@ -5,7 +5,7 @@
     <param name="exclude">.git</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
-    <param name="revision">v3.21.3</param>
+    <param name="revision">v3.22.0</param>
     <param name="changesgenerate">enable</param>
     <param name="filename">helm3</param>
   </service>
@@ -14,12 +14,6 @@
   <service name="go_modules" mode="manual">
     <param name="compression">zst</param>
     <param name="replace">golang.org/x/mod=golang.org/x/[email protected]</param>
-    <param name="replace">golang.org/x/net=golang.org/x/[email protected]</param>
-    <param name="replace">golang.org/x/text=golang.org/x/[email protected]</param>
-    <param 
name="replace">oras.land/oras-go/v2=oras.land/oras-go/[email protected]</param>
-    <param 
name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param>
-    <param 
name="replace">go.opentelemetry.io/otel=go.opentelemetry.io/[email protected]</param>
-    <param 
name="replace">github.com/grpc-ecosystem/grpc-gateway/v2=github.com/grpc-ecosystem/grpc-gateway/[email protected]</param>
     <param 
name="replace">google.golang.org/grpc=google.golang.org/[email protected]</param>
   </service>
   <!-- services below are running at buildtime -->

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.IUwRKw/_old  2026-09-21 12:13:56.771032591 +0200
+++ /var/tmp/diff_new_pack.IUwRKw/_new  2026-09-21 12:13:56.774032716 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param name="url">https://github.com/helm/helm.git</param>
-              <param 
name="changesrevision">1ad6e68924fdf6fb0c7dcef8e9e1dfc0f36eaed6</param></service></servicedata>
+              <param 
name="changesrevision">144ca65f8501953fa8b41cd1d37c7223051c85b7</param></service></servicedata>
 (No newline at EOF)
 

++++++ helm3-3.21.3.obscpio -> helm3-3.22.0.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/helm3-3.21.3/cmd/helm/testdata/output/version-client-shorthand.txt 
new/helm3-3.22.0/cmd/helm/testdata/output/version-client-shorthand.txt
--- old/helm3-3.21.3/cmd/helm/testdata/output/version-client-shorthand.txt      
2026-07-09 22:58:46.000000000 +0200
+++ new/helm3-3.22.0/cmd/helm/testdata/output/version-client-shorthand.txt      
2026-09-10 00:21:05.000000000 +0200
@@ -1 +1 @@
-version.BuildInfo{Version:"v3.21", GitCommit:"", GitTreeState:"", GoVersion:""}
+version.BuildInfo{Version:"v3.22", GitCommit:"", GitTreeState:"", GoVersion:""}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/helm3-3.21.3/cmd/helm/testdata/output/version-client.txt 
new/helm3-3.22.0/cmd/helm/testdata/output/version-client.txt
--- old/helm3-3.21.3/cmd/helm/testdata/output/version-client.txt        
2026-07-09 22:58:46.000000000 +0200
+++ new/helm3-3.22.0/cmd/helm/testdata/output/version-client.txt        
2026-09-10 00:21:05.000000000 +0200
@@ -1 +1 @@
-version.BuildInfo{Version:"v3.21", GitCommit:"", GitTreeState:"", GoVersion:""}
+version.BuildInfo{Version:"v3.22", GitCommit:"", GitTreeState:"", GoVersion:""}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/helm3-3.21.3/cmd/helm/testdata/output/version-short.txt 
new/helm3-3.22.0/cmd/helm/testdata/output/version-short.txt
--- old/helm3-3.21.3/cmd/helm/testdata/output/version-short.txt 2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/cmd/helm/testdata/output/version-short.txt 2026-09-10 
00:21:05.000000000 +0200
@@ -1 +1 @@
-v3.21
+v3.22
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/helm3-3.21.3/cmd/helm/testdata/output/version-template.txt 
new/helm3-3.22.0/cmd/helm/testdata/output/version-template.txt
--- old/helm3-3.21.3/cmd/helm/testdata/output/version-template.txt      
2026-07-09 22:58:46.000000000 +0200
+++ new/helm3-3.22.0/cmd/helm/testdata/output/version-template.txt      
2026-09-10 00:21:05.000000000 +0200
@@ -1 +1 @@
-Version: v3.21
\ No newline at end of file
+Version: v3.22
\ No newline at end of file
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/cmd/helm/testdata/output/version.txt 
new/helm3-3.22.0/cmd/helm/testdata/output/version.txt
--- old/helm3-3.21.3/cmd/helm/testdata/output/version.txt       2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/cmd/helm/testdata/output/version.txt       2026-09-10 
00:21:05.000000000 +0200
@@ -1 +1 @@
-version.BuildInfo{Version:"v3.21", GitCommit:"", GitTreeState:"", GoVersion:""}
+version.BuildInfo{Version:"v3.22", GitCommit:"", GitTreeState:"", GoVersion:""}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/go.mod new/helm3-3.22.0/go.mod
--- old/helm3-3.21.3/go.mod     2026-07-09 22:58:46.000000000 +0200
+++ new/helm3-3.22.0/go.mod     2026-09-10 00:21:05.000000000 +0200
@@ -10,6 +10,7 @@
        github.com/Masterminds/sprig/v3 v3.3.0
        github.com/Masterminds/squirrel v1.5.4
        github.com/Masterminds/vcs v1.13.3
+       github.com/ProtonMail/go-crypto v1.4.1
        github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2
        github.com/cyphar/filepath-securejoin v0.7.0
        github.com/distribution/distribution/v3 v3.1.1
@@ -21,30 +22,29 @@
        github.com/hashicorp/go-multierror v1.1.1
        github.com/jmoiron/sqlx v1.4.0
        github.com/lib/pq v1.12.3
-       github.com/mattn/go-shellwords v1.0.13
+       github.com/mattn/go-shellwords v1.0.14
        github.com/mitchellh/copystructure v1.2.0
        github.com/moby/term v0.5.2
        github.com/opencontainers/image-spec v1.1.1
-       github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5
        github.com/pkg/errors v0.9.1
        github.com/rubenv/sql-migrate v1.8.1
-       github.com/santhosh-tekuri/jsonschema/v6 v6.0.2
+       github.com/santhosh-tekuri/jsonschema/v6 v6.0.3
        github.com/spf13/cobra v1.10.2
        github.com/spf13/pflag v1.0.10
-       github.com/stretchr/testify v1.11.1
-       golang.org/x/crypto v0.53.0
-       golang.org/x/term v0.44.0
-       golang.org/x/text v0.38.0
+       github.com/stretchr/testify v1.12.1
+       golang.org/x/crypto v0.55.0
+       golang.org/x/term v0.45.0
+       golang.org/x/text v0.41.0
        gopkg.in/yaml.v3 v3.0.1
-       k8s.io/api v0.36.2
-       k8s.io/apiextensions-apiserver v0.36.2
-       k8s.io/apimachinery v0.36.2
-       k8s.io/apiserver v0.36.2
-       k8s.io/cli-runtime v0.36.2
-       k8s.io/client-go v0.36.2
+       k8s.io/api v0.37.0
+       k8s.io/apiextensions-apiserver v0.37.0
+       k8s.io/apimachinery v0.37.0
+       k8s.io/apiserver v0.37.0
+       k8s.io/cli-runtime v0.37.0
+       k8s.io/client-go v0.37.0
        k8s.io/klog/v2 v2.140.0
-       k8s.io/kubectl v0.36.2
-       oras.land/oras-go/v2 v2.6.1
+       k8s.io/kubectl v0.37.0
+       oras.land/oras-go/v2 v2.6.2
        sigs.k8s.io/yaml v1.6.0
 )
 
@@ -59,6 +59,7 @@
        github.com/cenkalti/backoff/v5 v5.0.3 // indirect
        github.com/cespare/xxhash/v2 v2.3.0 // indirect
        github.com/chai2010/gettext-go v1.0.2 // indirect
+       github.com/cloudflare/circl v1.6.3 // indirect
        github.com/coreos/go-systemd/v22 v22.7.0 // indirect
        github.com/cpuguy83/go-md2man/v2 v2.0.6 // indirect
        github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // 
indirect
@@ -71,34 +72,44 @@
        github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // 
indirect
        github.com/fatih/color v1.13.0 // indirect
        github.com/felixge/httpsnoop v1.0.4 // indirect
-       github.com/fxamacker/cbor/v2 v2.9.0 // indirect
+       github.com/fxamacker/cbor/v2 v2.9.1 // indirect
        github.com/go-errors/errors v1.4.2 // indirect
        github.com/go-gorp/gorp/v3 v3.1.0 // indirect
+       github.com/go-jose/go-jose/v4 v4.1.4 // indirect
        github.com/go-logr/logr v1.4.3 // indirect
        github.com/go-logr/stdr v1.2.2 // indirect
-       github.com/go-openapi/jsonpointer v0.21.0 // indirect
-       github.com/go-openapi/jsonreference v0.20.2 // indirect
-       github.com/go-openapi/swag v0.23.0 // indirect
+       github.com/go-openapi/jsonpointer v1.0.0 // indirect
+       github.com/go-openapi/jsonreference v1.0.0 // indirect
+       github.com/go-openapi/swag v0.27.1 // indirect
+       github.com/go-openapi/swag/cmdutils v0.27.1 // indirect
+       github.com/go-openapi/swag/conv v0.27.1 // indirect
+       github.com/go-openapi/swag/fileutils v0.27.1 // indirect
+       github.com/go-openapi/swag/jsonutils v0.27.1 // indirect
+       github.com/go-openapi/swag/loading v0.27.1 // indirect
+       github.com/go-openapi/swag/mangling v0.27.1 // indirect
+       github.com/go-openapi/swag/netutils v0.27.1 // indirect
+       github.com/go-openapi/swag/pools v0.27.1 // indirect
+       github.com/go-openapi/swag/stringutils v0.27.1 // indirect
+       github.com/go-openapi/swag/typeutils v0.27.1 // indirect
+       github.com/go-openapi/swag/yamlutils v0.27.1 // indirect
        github.com/google/btree v1.1.3 // indirect
        github.com/google/gnostic-models v0.7.0 // indirect
        github.com/google/uuid v1.6.0 // indirect
        github.com/gorilla/handlers v1.5.2 // indirect
        github.com/gorilla/mux v1.8.1 // indirect
-       github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 // indirect
+       github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 // indirect
        github.com/hashicorp/errwrap v1.1.0 // indirect
        github.com/hashicorp/golang-lru/arc/v2 v2.0.5 // indirect
        github.com/hashicorp/golang-lru/v2 v2.0.5 // indirect
        github.com/huandu/xstrings v1.5.0 // indirect
        github.com/inconshreveable/mousetrap v1.1.0 // indirect
-       github.com/josharian/intern v1.0.0 // indirect
        github.com/json-iterator/go v1.1.12 // indirect
-       github.com/klauspost/compress v1.18.4 // indirect
+       github.com/klauspost/compress v1.19.0 // indirect
        github.com/lann/builder v0.0.0-20180802200727-47ae307949d0 // indirect
        github.com/lann/ps v0.0.0-20150810152359-62de8c46ede0 // indirect
        github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // 
indirect
-       github.com/mailru/easyjson v0.7.7 // indirect
        github.com/mattn/go-colorable v0.1.13 // indirect
-       github.com/mattn/go-isatty v0.0.17 // indirect
+       github.com/mattn/go-isatty v0.0.20 // indirect
        github.com/mattn/go-runewidth v0.0.9 // indirect
        github.com/miekg/dns v1.1.57 // indirect
        github.com/mitchellh/go-wordwrap v1.0.1 // indirect
@@ -110,11 +121,11 @@
        github.com/opencontainers/go-digest v1.0.0 // indirect
        github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
        github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // 
indirect
-       github.com/prometheus/client_golang v1.23.2 // indirect
+       github.com/prometheus/client_golang v1.24.0 // indirect
        github.com/prometheus/client_model v0.6.2 // indirect
-       github.com/prometheus/common v0.67.5 // indirect
+       github.com/prometheus/common v0.70.0 // indirect
        github.com/prometheus/otlptranslator v1.0.0 // indirect
-       github.com/prometheus/procfs v0.20.1 // indirect
+       github.com/prometheus/procfs v0.21.1 // indirect
        github.com/redis/go-redis/extra/rediscmd/v9 v9.0.5 // indirect
        github.com/redis/go-redis/extra/redisotel/v9 v9.0.5 // indirect
        github.com/redis/go-redis/v9 v9.7.3 // indirect
@@ -127,48 +138,48 @@
        go.opentelemetry.io/auto/sdk v1.2.1 // indirect
        go.opentelemetry.io/contrib/bridges/prometheus v0.67.0 // indirect
        go.opentelemetry.io/contrib/exporters/autoexport v0.67.0 // indirect
-       go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 
// indirect
-       go.opentelemetry.io/otel v1.43.0 // indirect
+       go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 
// indirect
+       go.opentelemetry.io/otel v1.44.0 // indirect
        go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 // 
indirect
        go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.19.0 // 
indirect
        go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc 
v1.43.0 // indirect
        go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp 
v1.43.0 // indirect
-       go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 // indirect
-       go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 
// indirect
+       go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 // indirect
+       go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0 
// indirect
        go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 
// indirect
        go.opentelemetry.io/otel/exporters/prometheus v0.65.0 // indirect
        go.opentelemetry.io/otel/exporters/stdout/stdoutlog v0.19.0 // indirect
        go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.43.0 // 
indirect
        go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0 // 
indirect
        go.opentelemetry.io/otel/log v0.19.0 // indirect
-       go.opentelemetry.io/otel/metric v1.43.0 // indirect
-       go.opentelemetry.io/otel/sdk v1.43.0 // indirect
+       go.opentelemetry.io/otel/metric v1.44.0 // indirect
+       go.opentelemetry.io/otel/sdk v1.44.0 // indirect
        go.opentelemetry.io/otel/sdk/log v0.19.0 // indirect
-       go.opentelemetry.io/otel/sdk/metric v1.43.0 // indirect
-       go.opentelemetry.io/otel/trace v1.43.0 // indirect
+       go.opentelemetry.io/otel/sdk/metric v1.44.0 // indirect
+       go.opentelemetry.io/otel/trace v1.44.0 // indirect
        go.opentelemetry.io/proto/otlp v1.10.0 // indirect
        go.yaml.in/yaml/v2 v2.4.4 // indirect
-       go.yaml.in/yaml/v3 v3.0.4 // indirect
-       golang.org/x/mod v0.36.0 // indirect
-       golang.org/x/net v0.55.0 // indirect
-       golang.org/x/oauth2 v0.35.0 // indirect
-       golang.org/x/sync v0.21.0 // indirect
-       golang.org/x/sys v0.46.0 // indirect
-       golang.org/x/time v0.14.0 // indirect
-       golang.org/x/tools v0.45.0 // indirect
-       google.golang.org/genproto/googleapis/api 
v0.0.0-20260401024825-9d38bb4040a9 // indirect
-       google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260406210006-6f92a3bedf2d // indirect
-       google.golang.org/grpc v1.80.0 // indirect
+       go.yaml.in/yaml/v3 v3.0.5 // indirect
+       golang.org/x/mod v0.38.0 // indirect
+       golang.org/x/net v0.57.0 // indirect
+       golang.org/x/oauth2 v0.36.0 // indirect
+       golang.org/x/sync v0.22.0 // indirect
+       golang.org/x/sys v0.47.0 // indirect
+       golang.org/x/time v0.15.0 // indirect
+       golang.org/x/tools v0.48.0 // indirect
+       google.golang.org/genproto/googleapis/api 
v0.0.0-20260526163538-3dc84a4a5aaa // indirect
+       google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260526163538-3dc84a4a5aaa // indirect
+       google.golang.org/grpc v1.82.1 // indirect
        google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // 
indirect
        gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect
        gopkg.in/inf.v0 v0.9.1 // indirect
        gopkg.in/yaml.v2 v2.4.0 // indirect
-       k8s.io/component-base v0.36.2 // indirect
-       k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a // indirect
-       k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2 // indirect
+       k8s.io/component-base v0.37.0 // indirect
+       k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect
+       k8s.io/utils v0.0.0-20260626114624-be93311217bd // indirect
        sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect
        sigs.k8s.io/kustomize/api v0.21.1 // indirect
        sigs.k8s.io/kustomize/kyaml v0.21.1 // indirect
        sigs.k8s.io/randfill v1.0.0 // indirect
-       sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect
+       sigs.k8s.io/structured-merge-diff/v6 v6.4.2 // indirect
 )
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/go.sum new/helm3-3.22.0/go.sum
--- old/helm3-3.21.3/go.sum     2026-07-09 22:58:46.000000000 +0200
+++ new/helm3-3.22.0/go.sum     2026-09-10 00:21:05.000000000 +0200
@@ -22,6 +22,8 @@
 github.com/Masterminds/squirrel v1.5.4/go.mod 
h1:NNaOrjSoIDfDA40n7sr2tPNZRfjzjA400rg+riTZj10=
 github.com/Masterminds/vcs v1.13.3 
h1:IIA2aBdXvfbIM+yl/eTnL4hb1XwdpvuQLglAix1gweE=
 github.com/Masterminds/vcs v1.13.3/go.mod 
h1:TiE7xuEjl1N4j016moRd6vezp6e6Lz23gypeXfzXeW8=
+github.com/ProtonMail/go-crypto v1.4.1 
h1:9RfcZHqEQUvP8RzecWEUafnZVtEvrBVL9BiF67IQOfM=
+github.com/ProtonMail/go-crypto v1.4.1/go.mod 
h1:e1OaTyu5SYVrO9gKOEhTc+5UcXtTUa+P3uLudwcgPqo=
 github.com/alecthomas/template v0.0.0-20160405071501-a0175ee3bccc/go.mod 
h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
 github.com/alecthomas/units v0.0.0-20151022065526-2efee857e7cf/go.mod 
h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
 github.com/alicebob/miniredis/v2 v2.35.0 
h1:QwLphYqCEAo1eu1TqPRN2jgVMPBweeQcR21jeqDCONI=
@@ -49,11 +51,12 @@
 github.com/cespare/xxhash/v2 v2.3.0/go.mod 
h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
 github.com/chai2010/gettext-go v1.0.2 
h1:1Lwwip6Q2QGsAdl/ZKPCwTe9fe0CjlUbqj5bFNSjIRk=
 github.com/chai2010/gettext-go v1.0.2/go.mod 
h1:y+wnP2cHYaVj19NZhYKAwEMH2CI1gNHeQQ+5AjwawxA=
+github.com/cloudflare/circl v1.6.3 
h1:9GPOhQGF9MCYUeXyMYlqTR6a5gTrgR/fBLXvUgtVcg8=
+github.com/cloudflare/circl v1.6.3/go.mod 
h1:2eXP6Qfat4O/Yhh8BznvKnJ+uzEoTQ6jVKJRn81BiS4=
 github.com/coreos/go-systemd/v22 v22.7.0 
h1:LAEzFkke61DFROc7zNLX/WA2i5J8gYqe0rSj9KI28KA=
 github.com/coreos/go-systemd/v22 v22.7.0/go.mod 
h1:xNUYtjHu2EDXbsxz1i41wouACIwT7Ybq9o0BQhMwD0w=
 github.com/cpuguy83/go-md2man/v2 v2.0.6 
h1:XJtiaUW6dEEqVuZiMTn1ldk455QWwEIsMIJlo5vtkx0=
 github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod 
h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g=
-github.com/creack/pty v1.1.9/go.mod 
h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E=
 github.com/creack/pty v1.1.18 h1:n56/Zwd5o6whRC5PMGretI4IdRLlmBXYNjScPaBgsbY=
 github.com/creack/pty v1.1.18/go.mod 
h1:MOBLtS5ELjhRRrroQr9kyvTxUAFNvYEK993ew/Vr4O4=
 github.com/cyphar/filepath-securejoin v0.7.0 
h1:s0Y3ITPy6sQn5xt54DuYvTF8hu134ooYLUb58DX/HjE=
@@ -90,12 +93,14 @@
 github.com/foxcpp/go-mockdns v1.2.0/go.mod 
h1:IhLeSFGed3mJIAXPH2aiRQB+kqz7oqu8ld2qVbOu7Wk=
 github.com/frankban/quicktest v1.14.6 
h1:7Xjx+VpznH+oBnejlPUj8oUpdxnVs4f8XU8WnHkI4W8=
 github.com/frankban/quicktest v1.14.6/go.mod 
h1:4ptaffx2x8+WTWXmUCuVU6aPUX1/Mz7zb5vbUoiM6w0=
-github.com/fxamacker/cbor/v2 v2.9.0 
h1:NpKPmjDBgUfBms6tr6JZkTHtfFGcMKsw3eGcmD/sapM=
-github.com/fxamacker/cbor/v2 v2.9.0/go.mod 
h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ=
+github.com/fxamacker/cbor/v2 v2.9.1 
h1:2rWm8B193Ll4VdjsJY28jxs70IdDsHRWgQYAI80+rMQ=
+github.com/fxamacker/cbor/v2 v2.9.1/go.mod 
h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ=
 github.com/go-errors/errors v1.4.2 
h1:J6MZopCL4uSllY1OfXM374weqZFFItUbrImctkmUxIA=
 github.com/go-errors/errors v1.4.2/go.mod 
h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og=
 github.com/go-gorp/gorp/v3 v3.1.0 
h1:ItKF/Vbuj31dmV4jxA1qblpSwkl9g1typ24xoe70IGs=
 github.com/go-gorp/gorp/v3 v3.1.0/go.mod 
h1:dLEjIyyRNiXvNZ8PSmzpt1GsWAUK8kjVhEpjH8TixEw=
+github.com/go-jose/go-jose/v4 v4.1.4 
h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
+github.com/go-jose/go-jose/v4 v4.1.4/go.mod 
h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
 github.com/go-kit/kit v0.8.0/go.mod 
h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
 github.com/go-logfmt/logfmt v0.3.0/go.mod 
h1:Qt1PoO58o5twSAckw1HlFXLmHsOX5/0LbT9GBnD5lWE=
 github.com/go-logfmt/logfmt v0.4.0/go.mod 
h1:3RMwSq7FuexP4Kalkev3ejPJsZTpXXBr9+V4qmtdjCk=
@@ -104,14 +109,40 @@
 github.com/go-logr/logr v1.4.3/go.mod 
h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
 github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag=
 github.com/go-logr/stdr v1.2.2/go.mod 
h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
-github.com/go-openapi/jsonpointer v0.19.6/go.mod 
h1:osyAmYz/mB/C3I+WsTTSgw1ONzaLJoLCyoi6/zppojs=
-github.com/go-openapi/jsonpointer v0.21.0 
h1:YgdVicSA9vH5RiHs9TZW5oyafXZFc6+2Vc1rr/O9oNQ=
-github.com/go-openapi/jsonpointer v0.21.0/go.mod 
h1:IUyH9l/+uyhIYQ/PXVA41Rexl+kOkAPDdXEYns6fzUY=
-github.com/go-openapi/jsonreference v0.20.2 
h1:3sVjiK66+uXK/6oQ8xgcRKcFgQ5KXa2KvnJRumpMGbE=
-github.com/go-openapi/jsonreference v0.20.2/go.mod 
h1:Bl1zwGIM8/wsvqjsOQLJ/SH+En5Ap4rVB5KVcIDZG2k=
-github.com/go-openapi/swag v0.22.3/go.mod 
h1:UzaqsxGiab7freDnrUUra0MwWfN/q7tE4j+VcZ0yl14=
-github.com/go-openapi/swag v0.23.0 
h1:vsEVJDUo2hPJ2tu0/Xc+4noaxyEffXNIs3cOULZ+GrE=
-github.com/go-openapi/swag v0.23.0/go.mod 
h1:esZ8ITTYEsH1V2trKHjAN8Ai7xHb8RV+YSZ577vPjgQ=
+github.com/go-openapi/jsonpointer v1.0.0 
h1:kR9tHqY0CtZaOPVFm622dPVNhrvYpwr4uCxgL3h1H8s=
+github.com/go-openapi/jsonpointer v1.0.0/go.mod 
h1:Z3rw7dWu1p9IgitXCFamSlA5lmDiklEB6vkaxcNZW5Y=
+github.com/go-openapi/jsonreference v1.0.0 
h1:jlmTr6torcd1YgDQvSfNmRtKzYDO4FGBkrAdlAVWnpY=
+github.com/go-openapi/jsonreference v1.0.0/go.mod 
h1:jtwdyGbJk0Xhe5Y+rwtglQP6Sb1WZST4rT32LWB+sv0=
+github.com/go-openapi/swag v0.27.1 
h1:VotvOLWW8q/EAxB0YdsBBGC8XYyeL1YwBj2ungAGPNg=
+github.com/go-openapi/swag v0.27.1/go.mod 
h1:GTkJPwHfhJp6MWr4/rCh64HVI3Ofu+tcsbfjfHmTxpE=
+github.com/go-openapi/swag/cmdutils v0.27.1 
h1:I7sYqaWVl5mq0NEmNQkAmFDyNin9ufvMX/p2zwtQaOE=
+github.com/go-openapi/swag/cmdutils v0.27.1/go.mod 
h1:Sm1MVFMkF6guJJ+pQqHnQA3N0j9qALV3NxzDSv6bETM=
+github.com/go-openapi/swag/conv v0.27.1 
h1:8wi9ZG+olmY1wXphl93EWniPtbSPkXM/feH7FgjsvrU=
+github.com/go-openapi/swag/conv v0.27.1/go.mod 
h1:QbqMivkpKhC3g1B1GGGOJ6ANewI3S62dbzYu3Duowqs=
+github.com/go-openapi/swag/fileutils v0.27.1 
h1:QQqBSoi5mW4XpU85nS0mLcA+zAE6vLzrb0QkmLKf9oM=
+github.com/go-openapi/swag/fileutils v0.27.1/go.mod 
h1:VvJFZLTZS0AI854gEQz5tk7dBESdLjiNUMSZ/th2ry8=
+github.com/go-openapi/swag/jsonutils v0.27.1 
h1:SVgK3i4USzCU5mibOOS/l4ea2h9UQXy7J7RNLTjuXjU=
+github.com/go-openapi/swag/jsonutils v0.27.1/go.mod 
h1:tdlEpZqdcQ17uj6J4YdK9vd8It5qWMwjWXOs0tjpRlk=
+github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.1 
h1:mJu3COL9WEaZVp/Kf2PRMi7tPszPEJfSr/OO75ynCs8=
+github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.1/go.mod 
h1:mofwUWx70wvskwESqRJ//k/9kURmCgyJl5m5Ppoh5kY=
+github.com/go-openapi/swag/loading v0.27.1 
h1:/DxUgDXKbBX4bcn7r9uEXfJyzN5XpiJmZplzQTjrRCY=
+github.com/go-openapi/swag/loading v0.27.1/go.mod 
h1:jvGh3iA2+zyUUycB5fgJWzeHnhrpvGnJJM0RVE9ZShE=
+github.com/go-openapi/swag/mangling v0.27.1 
h1:yC9D0HyUE8gbP+BfmGx9+AA89ikwZTMjESK3OnnoaqA=
+github.com/go-openapi/swag/mangling v0.27.1/go.mod 
h1:jtBE2+V+3pILxOR7Vgce+Cwp6A2PgZbvVqfNntbVs0w=
+github.com/go-openapi/swag/netutils v0.27.1 
h1:mICMFoS82F5TZ4Zy3cqmcQk+BFeCp3Uyq3Np7GI0/qU=
+github.com/go-openapi/swag/netutils v0.27.1/go.mod 
h1:J+WYyFMLtvtCGqa6jLv+YNUmIKI3ZRQRrvfNDMoQoEQ=
+github.com/go-openapi/swag/pools v0.27.1 
h1:9LeadcMyb2GJCbXX5hVQDbZ2Lq9TL4dCs/nx1j5DO0E=
+github.com/go-openapi/swag/pools v0.27.1/go.mod 
h1:kVQefhSK5RWuRe7BXsL8htgBPAMpN7HDGpGEknqugeE=
+github.com/go-openapi/swag/stringutils v0.27.1 
h1:ZXePZ0r2p1qSjo8tD3Un4vFj8+FqlCkczxDrJIhYUp8=
+github.com/go-openapi/swag/stringutils v0.27.1/go.mod 
h1:lzRN95CxXmA03XcDWHLOb6nOMcxCqR5rGY0lOgsfRoM=
+github.com/go-openapi/swag/typeutils v0.27.1 
h1:KSTdFlfnse4r6dP9IrEnwMldjE+zs71UeEB3//PtVXc=
+github.com/go-openapi/swag/typeutils v0.27.1/go.mod 
h1:Srm0xFNRZ1Y+vCxJclo5qzx8aj+1pAKda/YfFPrG0dQ=
+github.com/go-openapi/swag/yamlutils v0.27.1 
h1:ftxv6xvXb1E3zohUc+okZ9nSqNb9StQX/FXnKZ98sQA=
+github.com/go-openapi/swag/yamlutils v0.27.1/go.mod 
h1:bnxFIB1qewGRiZHypXGZ3fNgf13/0HfRgnS/iZBDrOo=
+github.com/go-openapi/testify/enable/yaml/v2 v2.6.0 
h1:gGHwAJ0R/5jU8BEGDbfRNR3hL68dAVi84WuOApp29B0=
+github.com/go-openapi/testify/enable/yaml/v2 v2.6.0/go.mod 
h1:tY+St1SGq4NFl0QIqdTY4aEdbChAHxhyB77XQi9iJCo=
+github.com/go-openapi/testify/v2 v2.6.0 
h1:5PKH2HE7YJ/LuRPQGvSxBRlFXNQhSetBLlGAgUEu3ug=
+github.com/go-openapi/testify/v2 v2.6.0/go.mod 
h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw=
 github.com/go-sql-driver/mysql v1.8.1 
h1:LedoTUt/eveggdHS9qUFC1EFSa8bU2+1pZjSRpvNJ1Y=
 github.com/go-sql-driver/mysql v1.8.1/go.mod 
h1:wEBSXgmK//2ZFJyE+qWnIsVGmvmEKlqwuVSjsCm7DZg=
 github.com/go-stack/stack v1.8.0/go.mod 
h1:v0f6uXyyMGvRgIKkXu+yp6POWl0qKG85gN/melR3HDY=
@@ -135,8 +166,8 @@
 github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
 github.com/google/go-cmp v0.7.0/go.mod 
h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
 github.com/google/gofuzz v1.0.0/go.mod 
h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg=
-github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83 
h1:z2ogiKUYzX5Is6zr/vP9vJGqPwcdqsWjOt+V8J7+bTc=
-github.com/google/pprof v0.0.0-20260115054156-294ebfa9ad83/go.mod 
h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI=
+github.com/google/pprof v0.0.0-20260402051712-545e8a4df936 
h1:EwtI+Al+DeppwYX2oXJCETMO23COyaKGP6fHVpkpWpg=
+github.com/google/pprof v0.0.0-20260402051712-545e8a4df936/go.mod 
h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI=
 github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
 github.com/google/uuid v1.6.0/go.mod 
h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
 github.com/gorilla/handlers v1.5.2 
h1:cLTUSsNkgcwhgRqvCNmdbRWG0A3N4F+M2nWKdScwyEE=
@@ -145,8 +176,8 @@
 github.com/gorilla/mux v1.8.1/go.mod 
h1:AKf9I4AEqPTmMytcMc0KkNouC66V3BtZ4qD5fmWSiMQ=
 github.com/gosuri/uitable v0.0.4 
h1:IG2xLKRvErL3uhY6e1BylFzG+aJiwQviDDTfOKeKTpY=
 github.com/gosuri/uitable v0.0.4/go.mod 
h1:tKR86bXuXPZazfOTG1FIzvjIdXzd0mo4Vtn16vt0PJo=
-github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 
h1:HWRh5R2+9EifMyIHV7ZV+MIZqgz+PMpZ14Jynv3O2Zs=
-github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0/go.mod 
h1:JfhWUomR1baixubs02l85lZYYOm7LV6om4ceouMv45c=
+github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 
h1:5VipnvEpbqr2gA2VbM+nYVbkIF28c5ZQfqCBQ5g2xfk=
+github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0/go.mod 
h1:Hyl3n6Twe1hvtd9XUXDec4pTvgMSEixRuQKPTMH2bNs=
 github.com/hashicorp/errwrap v1.0.0/go.mod 
h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
 github.com/hashicorp/errwrap v1.1.0 
h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I=
 github.com/hashicorp/errwrap v1.1.0/go.mod 
h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
@@ -162,23 +193,18 @@
 github.com/inconshreveable/mousetrap v1.1.0/go.mod 
h1:vpF70FUmC8bwa3OWnCshd2FqLfsEA9PFc4w1p2J65bw=
 github.com/jmoiron/sqlx v1.4.0 h1:1PLqN7S1UYp5t4SrVVnt4nUVNemrDAtxlulVe+Qgm3o=
 github.com/jmoiron/sqlx v1.4.0/go.mod 
h1:ZrZ7UsYB/weZdl2Bxg6jCRO9c3YHl8r3ahlKmRT4JLY=
-github.com/josharian/intern v1.0.0 
h1:vlS4z54oSdjm0bgjRigI+G1HpF+tI+9rE5LLzOg8HmY=
-github.com/josharian/intern v1.0.0/go.mod 
h1:5DoeVV0s6jJacbCEi61lwdGj/aVlrQvzHFFd8Hwg//Y=
 github.com/json-iterator/go v1.1.6/go.mod 
h1:+SdeFBvtyEkXs7REEP0seUULqWtbJapLOCVDaaPEHmU=
 github.com/json-iterator/go v1.1.7/go.mod 
h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
 github.com/json-iterator/go v1.1.12 
h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM=
 github.com/json-iterator/go v1.1.12/go.mod 
h1:e30LSqwooZae/UwlEbR2852Gd8hjQvJoHmT4TnhNGBo=
 github.com/julienschmidt/httprouter v1.2.0/go.mod 
h1:SYymIcj16QtmaHHD7aYtjjsJG7VTCxuUUipMqKk8s4w=
 github.com/kisielk/sqlstruct v0.0.0-20201105191214-5f3e10d3ab46/go.mod 
h1:yyMNCyc/Ib3bDTKd379tNMpB/7/H5TjM2Y9QJ5THLbE=
-github.com/klauspost/compress v1.18.4 
h1:RPhnKRAQ4Fh8zU2FY/6ZFDwTVTxgJ/EMydqSTzE9a2c=
-github.com/klauspost/compress v1.18.4/go.mod 
h1:R0h/fSBs8DE4ENlcrlib3PsXS61voFxhIs2DeRhCvJ4=
+github.com/klauspost/compress v1.19.0 
h1:sXLILfc9jV2QYWkzFOPWStmcUVH2RHEB1JCdY2oVvCQ=
+github.com/klauspost/compress v1.19.0/go.mod 
h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
 github.com/konsorten/go-windows-terminal-sequences v1.0.1/go.mod 
h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ=
 github.com/kr/logfmt v0.0.0-20140226030751-b84e30acd515/go.mod 
h1:+0opPa2QZZtGFBFZlji/RkVcI2GknAs/DXo4wKdlNEc=
-github.com/kr/pretty v0.2.1/go.mod 
h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI=
 github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
 github.com/kr/pretty v0.3.1/go.mod 
h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
-github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
-github.com/kr/text v0.1.0/go.mod 
h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
 github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
 github.com/kr/text v0.2.0/go.mod 
h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
 github.com/kylelemons/godebug v1.1.0 
h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc=
@@ -192,20 +218,18 @@
 github.com/lib/pq v1.12.3/go.mod 
h1:/p+8NSbOcwzAEI7wiMXFlgydTwcgTr3OSKMsD2BitpA=
 github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de 
h1:9TO3cAIGXtEhnIaL+V+BEER86oLrvS+kWobKpbJuye0=
 github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de/go.mod 
h1:zAbeS9B/r2mtpb6U+EI2rYA5OAXxsYw6wTamcNW+zcE=
-github.com/mailru/easyjson v0.7.7 
h1:UGYAvKxe3sBsEDzO8ZeWOSlIQfWFlxbzLZe7hwFURr0=
-github.com/mailru/easyjson v0.7.7/go.mod 
h1:xzfreul335JAWq5oZzymOObrkdz5UnU4kGfJJLY9Nlc=
 github.com/mattn/go-colorable v0.1.9/go.mod 
h1:u6P/XSegPjTcexA+o6vUJrdnUu04hMope9wVRipJSqc=
 github.com/mattn/go-colorable v0.1.13 
h1:fFA4WZxdEF4tXPZVKMLwD8oUnCTTo08duU7wxecdEvA=
 github.com/mattn/go-colorable v0.1.13/go.mod 
h1:7S9/ev0klgBDR4GtXTXX8a3vIGJpMovkB8vQcUbaXHg=
 github.com/mattn/go-isatty v0.0.12/go.mod 
h1:cbi8OIDigv2wuxKPP5vlRcQ1OAZbq2CE4Kysco4FUpU=
 github.com/mattn/go-isatty v0.0.14/go.mod 
h1:7GGIvUiUoEMVVmxf/4nioHXj79iQHKdU27kJ6hsGG94=
 github.com/mattn/go-isatty v0.0.16/go.mod 
h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM=
-github.com/mattn/go-isatty v0.0.17 
h1:BTarxUcIeDqL27Mc+vyvdWYSL28zpIhv3RoTdsLMPng=
-github.com/mattn/go-isatty v0.0.17/go.mod 
h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM=
+github.com/mattn/go-isatty v0.0.20 
h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
+github.com/mattn/go-isatty v0.0.20/go.mod 
h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
 github.com/mattn/go-runewidth v0.0.9 
h1:Lm995f3rfxdpd6TSmuVCHVb/QhupuXlYr8sCI/QdE+0=
 github.com/mattn/go-runewidth v0.0.9/go.mod 
h1:H031xJmbD/WCDINGzjvQ9THkh0rPKHF+m2gUSrubnMI=
-github.com/mattn/go-shellwords v1.0.13 
h1:DC0OMEpGjm6LfNFU4ckYcvbQKyp2vE8atyFGXNtDcf4=
-github.com/mattn/go-shellwords v1.0.13/go.mod 
h1:EZzvwXDESEeg03EKmM+RmDnNOPKG4lLtQsUlTZDWQ8Y=
+github.com/mattn/go-shellwords v1.0.14 
h1:yUKzIgsCnosndOASY6/enly1EAuaXeFSQ7cdyA3OuYg=
+github.com/mattn/go-shellwords v1.0.14/go.mod 
h1:EZzvwXDESEeg03EKmM+RmDnNOPKG4lLtQsUlTZDWQ8Y=
 github.com/mattn/go-sqlite3 v1.14.22 
h1:2gZY6PC6kBnID23Tichd1K+Z0oS6nE/XwU+Vz/5o4kU=
 github.com/mattn/go-sqlite3 v1.14.22/go.mod 
h1:Uh1q+B4BYcTPb+yiD3kU8Ct7aC0hY9fxUwlHK0RXw+Y=
 github.com/matttproud/golang_protobuf_extensions v1.0.1/go.mod 
h1:D8He9yQNgCq6Z5Ld7szi9bcBfOoFv/3dc6xSMkL2PC0=
@@ -232,18 +256,16 @@
 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 
h1:C3w9PqII01/Oq1c1nUAm88MOHcQC9l5mIlSMApZMrHA=
 github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822/go.mod 
h1:+n7T8mK8HuQTcFwEeznm/DIxMOiR9yIdICNftLE1DvQ=
 github.com/mwitkow/go-conntrack v0.0.0-20161129095857-cc309e4a2223/go.mod 
h1:qRWi+5nqEBWmkhHvq77mSJWrCKwh8bxhgT7d/eI7P4U=
-github.com/onsi/ginkgo/v2 v2.28.1 
h1:S4hj+HbZp40fNKuLUQOYLDgZLwNUVn19N3Atb98NCyI=
-github.com/onsi/ginkgo/v2 v2.28.1/go.mod 
h1:CLtbVInNckU3/+gC8LzkGUb9oF+e8W8TdUsxPwvdOgE=
-github.com/onsi/gomega v1.39.1 h1:1IJLAad4zjPn2PsnhH70V4DKRFlrCzGBNrNaru+Vf28=
-github.com/onsi/gomega v1.39.1/go.mod 
h1:hL6yVALoTOxeWudERyfppUcZXjMwIMLnuSfruD2lcfg=
+github.com/onsi/ginkgo/v2 v2.32.0 
h1:Hw7s2pVrQo/8Yz5N77qdnpHaoc+c6cC9WIV1Jce+J6E=
+github.com/onsi/ginkgo/v2 v2.32.0/go.mod 
h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44=
+github.com/onsi/gomega v1.40.0 h1:Vtol0e1MghCD2ZVIilPDIg44XSL9l2QAn8ZNaljWcJc=
+github.com/onsi/gomega v1.40.0/go.mod 
h1:M/Uqpu/8qTjtzCLUA2zJHX9Iilrau25x1PdoSRbWh5A=
 github.com/opencontainers/go-digest v1.0.0 
h1:apOUWs51W5PlhuyGyz9FCeeBIOUDA/6nW8Oi/yOhh5U=
 github.com/opencontainers/go-digest v1.0.0/go.mod 
h1:0JzlMkj0TRzQZfJkVvzbP0HBR3IKzErnv2BNG4W4MAM=
 github.com/opencontainers/image-spec v1.1.1 
h1:y0fUlFfIZhPF1W537XOLg0/fcx6zcHCJwooC2xJA040=
 github.com/opencontainers/image-spec v1.1.1/go.mod 
h1:qpqAh3Dmcf36wStyyWU+kCeDgrGnAve2nCC8+7h8Q0M=
 github.com/peterbourgon/diskv v2.0.1+incompatible 
h1:UBdAOUP5p4RWqPBg048CAvpKN+vxiaj6gdUUzhl4XmI=
 github.com/peterbourgon/diskv v2.0.1+incompatible/go.mod 
h1:uqqh8zWWbv1HBMNONnaR/tNboyR3/BZd58JJSHlUSCU=
-github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5 
h1:Ii+DKncOVM8Cu1Hc+ETb5K+23HdAMvESYE3ZJ5b5cMI=
-github.com/phayes/freeport v0.0.0-20220201140144-74d24b5ae9f5/go.mod 
h1:iIss55rKnNBTvrwdmkUpLnDpZoAHvWaiq5+iMmen4AE=
 github.com/pkg/errors v0.8.0/go.mod 
h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
 github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
 github.com/pkg/errors v0.9.1/go.mod 
h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
@@ -255,23 +277,23 @@
 github.com/prometheus/client_golang v0.9.1/go.mod 
h1:7SWBe2y4D6OKWSNQJUaRYU/AaXPKyh/dDVn+NZz0KFw=
 github.com/prometheus/client_golang v1.0.0/go.mod 
h1:db9x61etRT2tGnBNRi70OPL5FsnadC4Ky3P0J6CfImo=
 github.com/prometheus/client_golang v1.1.0/go.mod 
h1:I1FGZT9+L76gKKOs5djB6ezCbFQP1xR9D75/vuwEF3g=
-github.com/prometheus/client_golang v1.23.2 
h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o=
-github.com/prometheus/client_golang v1.23.2/go.mod 
h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg=
+github.com/prometheus/client_golang v1.24.0 
h1:5XStIklKuAtJSNpdD3s8XJj/Yv78IQmE1kbNk87JrAI=
+github.com/prometheus/client_golang v1.24.0/go.mod 
h1:QcsNdotprC2nS4BTM2ucbcqxd2CeXTEa9jW7zHO9iDE=
 github.com/prometheus/client_model v0.0.0-20180712105110-5c3871d89910/go.mod 
h1:MbSGuTsp3dbXC40dX6PRTWyKYBIrTGTE9sqQNg2J8bo=
 github.com/prometheus/client_model v0.0.0-20190129233127-fd36f4220a90/go.mod 
h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
 github.com/prometheus/client_model v0.6.2 
h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk=
 github.com/prometheus/client_model v0.6.2/go.mod 
h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE=
 github.com/prometheus/common v0.4.1/go.mod 
h1:TNfzLD0ON7rHzMJeJkieUDPYmFC7Snx/y86RQel1bk4=
 github.com/prometheus/common v0.6.0/go.mod 
h1:eBmuwkDJBwy6iBfxCBob6t6dR6ENT/y+J+Zk0j9GMYc=
-github.com/prometheus/common v0.67.5 
h1:pIgK94WWlQt1WLwAC5j2ynLaBRDiinoAb86HZHTUGI4=
-github.com/prometheus/common v0.67.5/go.mod 
h1:SjE/0MzDEEAyrdr5Gqc6G+sXI67maCxzaT3A2+HqjUw=
+github.com/prometheus/common v0.70.0 
h1:bcpru3tWPVnxGnETLgOV5jbp/JRXgYEyv65CuBLAMMI=
+github.com/prometheus/common v0.70.0/go.mod 
h1:S/SFasQmgGiYH6C81LKCtYa8QACgthGg5zxL2udV7SY=
 github.com/prometheus/otlptranslator v1.0.0 
h1:s0LJW/iN9dkIH+EnhiD3BlkkP5QVIUVEoIwkU+A6qos=
 github.com/prometheus/otlptranslator v1.0.0/go.mod 
h1:vRYWnXvI6aWGpsdY/mOT/cbeVRBlPWtBNDb7kGR3uKM=
 github.com/prometheus/procfs v0.0.0-20181005140218-185b4288413d/go.mod 
h1:c3At6R/oaqEKCNdg8wHV1ftS6bRYblBhIjjI8uT2IGk=
 github.com/prometheus/procfs v0.0.2/go.mod 
h1:TjEm7ze935MbeOT/UhFTIMYKhuLP4wbCsTZCD3I8kEA=
 github.com/prometheus/procfs v0.0.3/go.mod 
h1:4A/X28fw3Fc593LaREMrKMqOKvUAntwMDaekg4FpcdQ=
-github.com/prometheus/procfs v0.20.1 
h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc=
-github.com/prometheus/procfs v0.20.1/go.mod 
h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo=
+github.com/prometheus/procfs v0.21.1 
h1:GljZCt+zSTS+NZq88cyQ1LjZ+RCHp3uVuabBWA5+OJI=
+github.com/prometheus/procfs v0.21.1/go.mod 
h1:aB55Cww9pdSJVHk0hUf0inxWyyjPogFIjmHKYgMKmtY=
 github.com/redis/go-redis/extra/rediscmd/v9 v9.0.5 
h1:EaDatTxkdHG+U3Bk4EUr+DZ7fOGwTfezUiUJMaIcaho=
 github.com/redis/go-redis/extra/rediscmd/v9 v9.0.5/go.mod 
h1:fyalQWdtzDBECAQFBJuQe5bzQ02jGd5Qcbgb97Flm7U=
 github.com/redis/go-redis/extra/redisotel/v9 v9.0.5 
h1:EfpWLLCyXw8PSM2/XNJLjI3Pb27yVE+gIAfeqp8LUCc=
@@ -285,8 +307,8 @@
 github.com/rubenv/sql-migrate v1.8.1/go.mod 
h1:BTIKBORjzyxZDS6dzoiw6eAFYJ1iNlGAtjn4LGeVjS8=
 github.com/russross/blackfriday/v2 v2.1.0 
h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf35Ld67mk=
 github.com/russross/blackfriday/v2 v2.1.0/go.mod 
h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM=
-github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 
h1:KRzFb2m7YtdldCEkzs6KqmJw4nqEVZGK7IN2kJkjTuQ=
-github.com/santhosh-tekuri/jsonschema/v6 v6.0.2/go.mod 
h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
+github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 
h1:1EYB5IzjZawrrnELUi78f9fPu57HuXjmddZPjrls/28=
+github.com/santhosh-tekuri/jsonschema/v6 v6.0.3/go.mod 
h1:JXeL+ps8p7/KNMjDQk3TCwPpBy0wYklyWTfbkIzdIFU=
 github.com/sergi/go-diff v1.4.0 h1:n/SP9D5ad1fORl+llWyN+D6qoUETXNZARKjyY2/KVCw=
 github.com/sergi/go-diff v1.4.0/go.mod 
h1:A0bzQcvG0E7Rwjx0REVgAGH58e96+X0MeOfepqsbeW4=
 github.com/shopspring/decimal v1.4.0 
h1:bxl37RwXBklmTi0C79JfXCEBD1cqqHt0bbgBAGFp81k=
@@ -304,19 +326,14 @@
 github.com/spf13/pflag v1.0.10/go.mod 
h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg=
 github.com/stretchr/objx v0.1.0/go.mod 
h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
 github.com/stretchr/objx v0.1.1/go.mod 
h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
-github.com/stretchr/objx v0.4.0/go.mod 
h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw=
-github.com/stretchr/objx v0.5.0/go.mod 
h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo=
-github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY=
-github.com/stretchr/objx v0.5.2/go.mod 
h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
+github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4=
+github.com/stretchr/objx v0.5.3/go.mod 
h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0=
 github.com/stretchr/testify v1.2.2/go.mod 
h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
 github.com/stretchr/testify v1.3.0/go.mod 
h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
 github.com/stretchr/testify v1.6.1/go.mod 
h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
 github.com/stretchr/testify v1.7.0/go.mod 
h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
-github.com/stretchr/testify v1.7.1/go.mod 
h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg=
-github.com/stretchr/testify v1.8.0/go.mod 
h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU=
-github.com/stretchr/testify v1.8.1/go.mod 
h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4=
-github.com/stretchr/testify v1.11.1 
h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
-github.com/stretchr/testify v1.11.1/go.mod 
h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
+github.com/stretchr/testify v1.12.1 
h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE=
+github.com/stretchr/testify v1.12.1/go.mod 
h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg=
 github.com/x448/float16 v0.8.4 h1:qLwI1I70+NjRFUR3zs1JPUCgaCXSh3SW62uAKT1mSBM=
 github.com/x448/float16 v0.8.4/go.mod 
h1:14CWIYCyZA/cWjXOioeEpHeN/83MdbZDRQHoFcYsOfg=
 github.com/xlab/treeprint v1.2.0 
h1:HzHnuAF1plUN2zGlAFHbSQP2qJ0ZAD3XF5XD7OesXRQ=
@@ -330,10 +347,10 @@
 go.opentelemetry.io/contrib/bridges/prometheus v0.67.0/go.mod 
h1:Z5RIwRkZgauOIfnG5IpidvLpERjhTninpP1dTG2jTl4=
 go.opentelemetry.io/contrib/exporters/autoexport v0.67.0 
h1:4fnRcNpc6YFtG3zsFw9achKn3XgmxPxuMuqIL5rE8e8=
 go.opentelemetry.io/contrib/exporters/autoexport v0.67.0/go.mod 
h1:qTvIHMFKoxW7HXg02gm6/Wofhq5p3Ib/A/NNt1EoBSQ=
-go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0 
h1:CqXxU8VOmDefoh0+ztfGaymYbhdB/tT3zs79QaZTNGY=
-go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.68.0/go.mod 
h1:BuhAPThV8PBHBvg8ZzZ/Ok3idOdhWIodywz2xEcRbJo=
-go.opentelemetry.io/otel v1.43.0 
h1:mYIM03dnh5zfN7HautFE4ieIig9amkNANT+xcVxAj9I=
-go.opentelemetry.io/otel v1.43.0/go.mod 
h1:JuG+u74mvjvcm8vj8pI5XiHy1zDeoCS2LB1spIq7Ay0=
+go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 
h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo=
+go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod 
h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI=
+go.opentelemetry.io/otel v1.44.0 
h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
+go.opentelemetry.io/otel v1.44.0/go.mod 
h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0 
h1:Dn8rkudDzY6KV9dr/D/bTUuWgqDf9xe0rr4G2elrn0Y=
 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc v0.19.0/go.mod 
h1:gMk9F0xDgyN9M/3Ed5Y1wKcx/9mlU91NXY2SNq7RQuU=
 go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp v0.19.0 
h1:HIBTQ3VO5aupLKjC90JgMqpezVXwFuq6Ryjn0/izoag=
@@ -342,10 +359,10 @@
 go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc 
v1.43.0/go.mod h1:2lmweYCiHYpEjQ/lSJBYhj9jP1zvCvQW4BqL9dnT7FQ=
 go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp v1.43.0 
h1:w1K+pCJoPpQifuVpsKamUdn9U0zM3xUziVOqsGksUrY=
 go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp 
v1.43.0/go.mod h1:HBy4BjzgVE8139ieRI75oXm3EcDN+6GhD88JT1Kjvxg=
-go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0 
h1:88Y4s2C8oTui1LGM6bTWkw0ICGcOLCAI5l6zsD1j20k=
-go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.43.0/go.mod 
h1:Vl1/iaggsuRlrHf/hfPJPvVag77kKyvrLeD10kpMl+A=
-go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0 
h1:RAE+JPfvEmvy+0LzyUA25/SGawPwIUbZ6u0Wug54sLc=
-go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.43.0/go.mod 
h1:AGmbycVGEsRx9mXMZ75CsOyhSP6MFIcj/6dnG+vhVjk=
+go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 
h1:4YsVu3B8+3qtWYYrsUYgn0OG78pN0rnNPRGX4SbokQI=
+go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0/go.mod 
h1:+wnlSn0mD1ADVMe3v9Z/WIaiz6q6gL2J/ejaAmdmv80=
+go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0 
h1:qazEJlUOQzhCpzQpFETGby7EdqjI1wsd0W+6Gg1SCTU=
+go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0/go.mod 
h1:fOD2Yefuxixkx3ahVNf0O/PERb6r4OlbxfATVnYvzCo=
 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0 
h1:3iZJKlCZufyRzPzlQhUIWVmfltrXuGyfjREgGP3UUjc=
 go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.43.0/go.mod 
h1:/G+nUPfhq2e+qiXMGxMwumDrP5jtzU+mWN7/sjT2rak=
 go.opentelemetry.io/otel/exporters/prometheus v0.65.0 
h1:jOveH/b4lU9HT7y+Gfamf18BqlOuz2PWEvs8yM7Q6XE=
@@ -358,40 +375,43 @@
 go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.43.0/go.mod 
h1:PJnsC41lAGncJlPUniSwM81gc80GkgWJWr3cu2nKEtU=
 go.opentelemetry.io/otel/log v0.19.0 
h1:KUZs/GOsw79TBBMfDWsXS+KZ4g2Ckzksd1ymzsIEbo4=
 go.opentelemetry.io/otel/log v0.19.0/go.mod 
h1:5DQYeGmxVIr4n0/BcJvF4upsraHjg6vudJJpnkL6Ipk=
-go.opentelemetry.io/otel/metric v1.43.0 
h1:d7638QeInOnuwOONPp4JAOGfbCEpYb+K6DVWvdxGzgM=
-go.opentelemetry.io/otel/metric v1.43.0/go.mod 
h1:RDnPtIxvqlgO8GRW18W6Z/4P462ldprJtfxHxyKd2PY=
-go.opentelemetry.io/otel/sdk v1.43.0 
h1:pi5mE86i5rTeLXqoF/hhiBtUNcrAGHLKQdhg4h4V9Dg=
-go.opentelemetry.io/otel/sdk v1.43.0/go.mod 
h1:P+IkVU3iWukmiit/Yf9AWvpyRDlUeBaRg6Y+C58QHzg=
+go.opentelemetry.io/otel/metric v1.44.0 
h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
+go.opentelemetry.io/otel/metric v1.44.0/go.mod 
h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo=
+go.opentelemetry.io/otel/metric/x v0.66.0 
h1:YkCrx1zLOChi9ZcZ6euupOcsgzbVlec7D/xoEU1+cTA=
+go.opentelemetry.io/otel/metric/x v0.66.0/go.mod 
h1:d1+BDj9t96do0/1LoU1ayfCv79ZgNE41qbhBvnMOBZk=
+go.opentelemetry.io/otel/sdk v1.44.0 
h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58=
+go.opentelemetry.io/otel/sdk v1.44.0/go.mod 
h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0=
 go.opentelemetry.io/otel/sdk/log v0.19.0 
h1:scYVLqT22D2gqXItnWiocLUKGH9yvkkeql5dBDiXyko=
 go.opentelemetry.io/otel/sdk/log v0.19.0/go.mod 
h1:vFBowwXGLlW9AvpuF7bMgnNI95LiW10szrOdvzBHlAg=
 go.opentelemetry.io/otel/sdk/log/logtest v0.19.0 
h1:BEbF7ZBB6qQloV/Ub1+3NQoOUnVtcGkU3XX4Ws3GQfk=
 go.opentelemetry.io/otel/sdk/log/logtest v0.19.0/go.mod 
h1:Lua81/3yM0wOmoHTokLj9y9ADeA02v1naRrVrkAZuKk=
-go.opentelemetry.io/otel/sdk/metric v1.43.0 
h1:S88dyqXjJkuBNLeMcVPRFXpRw2fuwdvfCGLEo89fDkw=
-go.opentelemetry.io/otel/sdk/metric v1.43.0/go.mod 
h1:C/RJtwSEJ5hzTiUz5pXF1kILHStzb9zFlIEe85bhj6A=
-go.opentelemetry.io/otel/trace v1.43.0 
h1:BkNrHpup+4k4w+ZZ86CZoHHEkohws8AY+WTX09nk+3A=
-go.opentelemetry.io/otel/trace v1.43.0/go.mod 
h1:/QJhyVBUUswCphDVxq+8mld+AvhXZLhe+8WVFxiFff0=
+go.opentelemetry.io/otel/sdk/metric v1.44.0 
h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI=
+go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod 
h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA=
+go.opentelemetry.io/otel/trace v1.44.0 
h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk=
+go.opentelemetry.io/otel/trace v1.44.0/go.mod 
h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE=
 go.opentelemetry.io/proto/otlp v1.10.0 
h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g=
 go.opentelemetry.io/proto/otlp v1.10.0/go.mod 
h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk=
 go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto=
 go.uber.org/goleak v1.3.0/go.mod 
h1:CoHD4mav9JJNrW/WLlf7HGZPjdw8EucARQHekz1X6bE=
 go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ=
 go.yaml.in/yaml/v2 v2.4.4/go.mod 
h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ=
-go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc=
 go.yaml.in/yaml/v3 v3.0.4/go.mod 
h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
+go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw=
+go.yaml.in/yaml/v3 v3.0.5/go.mod 
h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg=
 golang.org/x/crypto v0.0.0-20180904163835-0709b304e793/go.mod 
h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4=
 golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod 
h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
 golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod 
h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
 golang.org/x/crypto v0.13.0/go.mod 
h1:y6Z2r+Rw4iayiXXAIxJIDAJ1zMW4yaTpebo8fPOliYc=
 golang.org/x/crypto v0.14.0/go.mod 
h1:MVFd36DqK4CsrnJYDkBA3VC4m2GkXAM0PvzMCn4JQf4=
 golang.org/x/crypto v0.15.0/go.mod 
h1:4ChreQoLWfG3xLDer1WdlH5NdlQ3+mwnQq1YTKY+72g=
-golang.org/x/crypto v0.53.0 h1:QZ4Muo8THX6CizN2vPPd5fBGHyogrdK9fG4wLPFUsto=
-golang.org/x/crypto v0.53.0/go.mod 
h1:DNLU434OwVakk9PzuwV8w62mAJpRJL3vsgcfp4Qnsio=
+golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
+golang.org/x/crypto v0.55.0/go.mod 
h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
 golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod 
h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
 golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
 golang.org/x/mod v0.12.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
 golang.org/x/mod v0.14.0/go.mod h1:hTbmBsO62+eylJbnUtE2MGJUyE7QWk4xUqPFrRgJ+7c=
-golang.org/x/mod v0.36.0 h1:JJjpVx6myfUsUdAzZuOSTTmRE0PfZeNWzzvKrP7amb4=
-golang.org/x/mod v0.36.0/go.mod h1:moc6ELqsWcOw5Ef3xVprK5ul/MvtVvkIXLziUOICjUQ=
+golang.org/x/mod v0.38.0 h1:MECBjubtXD7yj4HrhIUcywNaGeNVUdfVnxmPajOk4yk=
+golang.org/x/mod v0.38.0/go.mod h1:V6Xz0pq8TQ3dGqVQ1FVHuelZpAL0uNhSkk9ogYP3c40=
 golang.org/x/net v0.0.0-20181114220301-adae6a3d119a/go.mod 
h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
 golang.org/x/net v0.0.0-20190613194153-d28f0bde5980/go.mod 
h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
 golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod 
h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
@@ -402,10 +422,10 @@
 golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
 golang.org/x/net v0.17.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE=
 golang.org/x/net v0.18.0/go.mod h1:/czyP5RqHAH4odGYxBJ1qz0+CE5WZ+2j1YgoEo8F2jQ=
-golang.org/x/net v0.55.0 h1:bcvxaJn3e1U6InsFWt1JUq1aSjnRxLzT2rtD2KfkDF8=
-golang.org/x/net v0.55.0/go.mod h1:L5U2KuzuOe1lY7Z+aWVIKK6qEeJXnXV9yzGA+WCHJww=
-golang.org/x/oauth2 v0.35.0 h1:Mv2mzuHuZuY2+bkyWXIHMfhNdJAdwW3FuWeCPYN5GVQ=
-golang.org/x/oauth2 v0.35.0/go.mod 
h1:lzm5WQJQwKZ3nwavOZ3IS5Aulzxi68dUSgRHujetwEA=
+golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
+golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
+golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
+golang.org/x/oauth2 v0.36.0/go.mod 
h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
 golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod 
h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
 golang.org/x/sync v0.0.0-20181221193216-37e7f081c4d4/go.mod 
h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
 golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod 
h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
@@ -414,8 +434,8 @@
 golang.org/x/sync v0.3.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
 golang.org/x/sync v0.4.0/go.mod h1:FU7BRWz2tNW+3quACPkgCx/L+uEAv1htQ0V83Z9Rj+Y=
 golang.org/x/sync v0.5.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
-golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM=
-golang.org/x/sync v0.21.0/go.mod 
h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
+golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
+golang.org/x/sync v0.22.0/go.mod 
h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
 golang.org/x/sys v0.0.0-20180905080454-ebe1bf3edb33/go.mod 
h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
 golang.org/x/sys v0.0.0-20181116152217-5ac8a444bdc5/go.mod 
h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
 golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod 
h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
@@ -431,12 +451,13 @@
 golang.org/x/sys v0.0.0-20220722155257-8c9f86f7a55f/go.mod 
h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod 
h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.5.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.8.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.13.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
 golang.org/x/sys v0.14.0/go.mod h1:/VUhepiaJMQUp4+oa/7Zr1D23ma6VTLIYjOOTFZPUcA=
-golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw=
-golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
+golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
+golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
 golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod 
h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
 golang.org/x/term v0.0.0-20210927222741-03fcf44c2211/go.mod 
h1:jbD1KX2456YbFQfuXm/mYQcufACuNUgVhRMnK/tPxf8=
 golang.org/x/term v0.5.0/go.mod h1:jMB1sMXY+tzblOD4FWmEbocvup2/aLOaQEp7JmGp78k=
@@ -444,8 +465,8 @@
 golang.org/x/term v0.12.0/go.mod 
h1:owVbMEjm3cBLCHdkQu9b1opXd4ETQWc3BhuQGKgXgvU=
 golang.org/x/term v0.13.0/go.mod 
h1:LTmsnFJwVN6bCy1rVCoS+qHT1HhALEFxKncY3WNNh4U=
 golang.org/x/term v0.14.0/go.mod 
h1:TySc+nGkYR6qt8km8wUhuFRTVSMIX3XPR58y2lC8vww=
-golang.org/x/term v0.44.0 h1:0rLvDRCtNj0gZkyIXhCyOb2OAzEhLVqc4B+hrsBhrmc=
-golang.org/x/term v0.44.0/go.mod 
h1:7ze4MdzUzLXpSAoFP1H0bOI9aXDqveSvatT5vKcFh2Y=
+golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
+golang.org/x/term v0.45.0/go.mod 
h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
 golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
 golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
 golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ=
@@ -453,27 +474,27 @@
 golang.org/x/text v0.9.0/go.mod h1:e1OnstbJyHTd6l/uOt8jFFHp6TRDWZR/bV3emEE/zU8=
 golang.org/x/text v0.13.0/go.mod 
h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
 golang.org/x/text v0.14.0/go.mod 
h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU=
-golang.org/x/text v0.38.0 h1:sXmwo9DwP3OK9EZ7PqAdaooSGozfl/3a6/xJcbzPRhE=
-golang.org/x/text v0.38.0/go.mod 
h1:YXZt3QhHUKYT53r2lLKFIVi6Ao1jdzrTR/KQ09qyxF4=
-golang.org/x/time v0.14.0 h1:MRx4UaLrDotUKUdCIqzPC48t1Y9hANFKIRpNx+Te8PI=
-golang.org/x/time v0.14.0/go.mod 
h1:eL/Oa2bBBK0TkX57Fyni+NgnyQQN4LitPmob2Hjnqw4=
+golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
+golang.org/x/text v0.41.0/go.mod 
h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
+golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
+golang.org/x/time v0.15.0/go.mod 
h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
 golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod 
h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
 golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod 
h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
 golang.org/x/tools v0.1.12/go.mod 
h1:hNGJHUnrk76NpqgfD5Aqm5Crs+Hm0VOH/i9J2+nxYbc=
 golang.org/x/tools v0.6.0/go.mod 
h1:Xwgl3UAJ/d3gWutnCtw505GrjyAbvKui8lOU390QaIU=
 golang.org/x/tools v0.13.0/go.mod 
h1:HvlwmtVNQAhOuCjW7xxvovg8wbNq7LwfXh/k7wXUl58=
 golang.org/x/tools v0.15.0/go.mod 
h1:hpksKq4dtpQWS1uQ61JkdqWM3LscIS6Slf+VVkm+wQk=
-golang.org/x/tools v0.45.0 h1:18qN3FAooORvApf5XjCXgsuayZOEtXf6JK18I3+ONa8=
-golang.org/x/tools v0.45.0/go.mod 
h1:LuUGqqaXcXMEFEruIVJVm5mgDD8vww/z/SR1gQ4uE/0=
+golang.org/x/tools v0.48.0 h1:3+hClM1aLL5mjMKm5ovokw9epgRXPuu2tILgismM6RE=
+golang.org/x/tools v0.48.0/go.mod 
h1:08xX0orndb/F7jJxGDicx061tyd5pcMto75YMAXr6lk=
 golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod 
h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
 gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4=
 gonum.org/v1/gonum v0.17.0/go.mod 
h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E=
-google.golang.org/genproto/googleapis/api v0.0.0-20260401024825-9d38bb4040a9 
h1:VPWxll4HlMw1Vs/qXtN7BvhZqsS9cdAittCNvVENElA=
-google.golang.org/genproto/googleapis/api 
v0.0.0-20260401024825-9d38bb4040a9/go.mod 
h1:7QBABkRtR8z+TEnmXTqIqwJLlzrZKVfAUm7tY3yGv0M=
-google.golang.org/genproto/googleapis/rpc v0.0.0-20260406210006-6f92a3bedf2d 
h1:wT2n40TBqFY6wiwazVK9/iTWbsQrgk5ZfCSVFLO9LQA=
-google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260406210006-6f92a3bedf2d/go.mod 
h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
-google.golang.org/grpc v1.80.0 h1:Xr6m2WmWZLETvUNvIUmeD5OAagMw3FiKmMlTdViWsHM=
-google.golang.org/grpc v1.80.0/go.mod 
h1:ho/dLnxwi3EDJA4Zghp7k2Ec1+c2jqup0bFkw07bwF4=
+google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa 
h1:Kjn0N0tCrDgiAFW+lGO4JZ3ck44CehvJQMAwj9QF0G8=
+google.golang.org/genproto/googleapis/api 
v0.0.0-20260526163538-3dc84a4a5aaa/go.mod 
h1:q4lMZS6kskjT5HvCPrnnypcDPVJqT/f4nfxmkE7gryY=
+google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa 
h1:mZHHdPZl0dbGHCflZgAq/Q468DWVFcU2whhB2KAo8fk=
+google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260526163538-3dc84a4a5aaa/go.mod 
h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
+google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=
+google.golang.org/grpc v1.82.1/go.mod 
h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
 google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af 
h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI=
 google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod 
h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
 gopkg.in/alecthomas/kingpin.v2 v2.2.6/go.mod 
h1:FMv+mEhP44yOT+4EoQTLFTRgOQ1FBLkstjWtayDeSgw=
@@ -490,30 +511,30 @@
 gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod 
h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
 gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
 gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
-k8s.io/api v0.36.2 h1:TF6YDLIzKfccK7cq9YpTcGX8TJmEkHVRv78DM51fRYY=
-k8s.io/api v0.36.2/go.mod h1:F4LbMO4brjZYh7yFkXWhynSvtB7YauxV4c+HHkNRGNg=
-k8s.io/apiextensions-apiserver v0.36.2 
h1:3O5gqOj/dt2XWWbpMe+TXWpE9yU6pjM/tXxtHHJT/K4=
-k8s.io/apiextensions-apiserver v0.36.2/go.mod 
h1:cL1tBWe8XSaP1H30iWKGo7hf6iAUUUJPEU70dskmAnA=
-k8s.io/apimachinery v0.36.2 h1:0PE/W/WNy1UX61NLbXY5TMbJ6UwLL6E6lAPkYrKFxbQ=
-k8s.io/apimachinery v0.36.2/go.mod 
h1:fvf/HOLXq9RId0rnDIbN1OEBvHXdQbLMM8nu0LcBUf4=
-k8s.io/apiserver v0.36.2 h1:6vMnkmHZPeBloNkHUhmZYq7Ylv8WIB8xjyEl+eSt26E=
-k8s.io/apiserver v0.36.2/go.mod h1:9PoQ2ikCytrZyZg11mGhLEF5m8Rgsb5FJmYJ4Wvnl1k=
-k8s.io/cli-runtime v0.36.2 h1:CconTvEeV4DJs4ZX3HQKCFbFRGsm6OtuBM9yjmMP2VM=
-k8s.io/cli-runtime v0.36.2/go.mod 
h1:LddcjiMf4YlnHO7c1Y7rEtDqL84FyiYVLco7V679GUU=
-k8s.io/client-go v0.36.2 h1:bfgxmFKc9CgqsgX4xKLAAdmTQlWee7Ob/HlDOrJ5TBI=
-k8s.io/client-go v0.36.2/go.mod h1:1vgO4OAlfPnoLcb+Rze2GF5rAr14w8qjrYMoyXJzQj0=
-k8s.io/component-base v0.36.2 h1:Z0VH80O7Ng0HDZnZj3WRR3urEGa0kTwmO8CwEwjVK1w=
-k8s.io/component-base v0.36.2/go.mod 
h1:mGfFOA7Gwpdm1VW2cwSQYbiDIlz8GD2WGwH88QSeCyA=
+k8s.io/api v0.37.0 h1:Z//Vj9N7RA/yS2sDmxyeo7h+RR4zbUrd2vrd3Z0TbB4=
+k8s.io/api v0.37.0/go.mod h1:LKXgcJWMc+f4OLbP5SFR8rulEg07zZhpi/zMULiBImk=
+k8s.io/apiextensions-apiserver v0.37.0 
h1:zRMQ3+/LIE5oZ0tVvXwYHC+dIkSP5cjNWju7AZU1LOI=
+k8s.io/apiextensions-apiserver v0.37.0/go.mod 
h1:HU0PfSBwchHL5iDau6jjt9zU6ryWkDDlaVUiq91NK80=
+k8s.io/apimachinery v0.37.0 h1:Np2AbDtf8x6RDHiD8T9LbKJ9gaegeVNa8yNm5FuGKm0=
+k8s.io/apimachinery v0.37.0/go.mod 
h1:RN3nhprFSCxOi5Selxd7oMTXOe/c+ZbcE7Im+TS2zkE=
+k8s.io/apiserver v0.37.0 h1:TXg7OxsOWrAH8J4Zi/gBAZuMw1Dfdd+6cca2h4qjRqo=
+k8s.io/apiserver v0.37.0/go.mod h1:OddHDF4gy9qyIb8o/3+qaeP6S0vEObWLgOygVqXksv0=
+k8s.io/cli-runtime v0.37.0 h1:U3XakUeirBQJMz5688r04z74SIHSE7V5SIZ6Ho5JyBM=
+k8s.io/cli-runtime v0.37.0/go.mod 
h1:qiQMFkKwFFuPH6zy953On+nc3qfpEHAIDrJmAuRz5Vg=
+k8s.io/client-go v0.37.0 h1:nsN31fy8wBySuZ+QRnKmrjRSQLOG2rvoGN0tKd12zhQ=
+k8s.io/client-go v0.37.0/go.mod h1:FcGqw+Ll/gNQiq+nPGY1Oyt9y7SgDh1d3MW3RFDEbn0=
+k8s.io/component-base v0.37.0 h1:3SdSa4+itMdFTDFTeR8CxKGmSTSMXFlKL4ky8OqjguM=
+k8s.io/component-base v0.37.0/go.mod 
h1:LjOebp4R9y6LODWZQv102ZQxGheLcDO2ZJLAw6bbh4I=
 k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc=
 k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0=
-k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a 
h1:xCeOEAOoGYl2jnJoHkC3hkbPJgdATINPMAxaynU2Ovg=
-k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a/go.mod 
h1:uGBT7iTA6c6MvqUvSXIaYZo9ukscABYi2btjhvgKGZ0=
-k8s.io/kubectl v0.36.2 h1:rpUGGpeL09XVOLep2yle5jrtk//JA1L6ZHfkQQtVEwk=
-k8s.io/kubectl v0.36.2/go.mod h1:gVbQ3B/yb4bSR2ggQ7rd0W6icUSWs7sduH4e16Vii+0=
-k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2 
h1:AZYQSJemyQB5eRxqcPky+/7EdBj0xi3g0ZcxxJ7vbWU=
-k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2/go.mod 
h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk=
-oras.land/oras-go/v2 v2.6.1 h1:bonOEkjLfp8tt6qXWRRWP6p1F+9octchOf2EqnWB4Zs=
-oras.land/oras-go/v2 v2.6.1/go.mod 
h1:dhtFrFOuZuDtAVeZ9FUnaa5zfzplG3ZnFX9/uH1J/Yk=
+k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad 
h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A=
+k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod 
h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I=
+k8s.io/kubectl v0.37.0 h1:cici6hiofx93ASldmprDmZF55SfhVt4o3HniltVLjTc=
+k8s.io/kubectl v0.37.0/go.mod h1:RSeEl8e/yqDx6srG8Azr0uAtVPNIZljA0PNh9HCBcdg=
+k8s.io/utils v0.0.0-20260626114624-be93311217bd 
h1:Ea7fgQ5we8Y9T0OX5o0dAHzQOBRI07D/dEYRaB9ZZEs=
+k8s.io/utils v0.0.0-20260626114624-be93311217bd/go.mod 
h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk=
+oras.land/oras-go/v2 v2.6.2 h1:N04RXngAp1LJKTG6ifz3xHPipasEkWr+hFmInja5YKo=
+oras.land/oras-go/v2 v2.6.2/go.mod 
h1:PlTtg4JTDJkDe8yVHpM2wz7/YDc00GVas+i4jAW2TZ4=
 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 
h1:IpInykpT6ceI+QxKBbEflcR5EXP7sU1kvOlxwZh5txg=
 sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod 
h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg=
 sigs.k8s.io/kustomize/api v0.21.1 
h1:lzqbzvz2CSvsjIUZUBNFKtIMsEw7hVLJp0JeSIVmuJs=
@@ -522,7 +543,7 @@
 sigs.k8s.io/kustomize/kyaml v0.21.1/go.mod 
h1:hmxADesM3yUN2vbA5z1/YTBnzLJ1dajdqpQonwBL1FQ=
 sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU=
 sigs.k8s.io/randfill v1.0.0/go.mod 
h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY=
-sigs.k8s.io/structured-merge-diff/v6 v6.3.2 
h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8=
-sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod 
h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE=
+sigs.k8s.io/structured-merge-diff/v6 v6.4.2 
h1:qdOxHwrl2Kaag1aQEarlYcOA9vSyGCp3CIki3aW8c4Q=
+sigs.k8s.io/structured-merge-diff/v6 v6.4.2/go.mod 
h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE=
 sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs=
 sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4=
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/internal/version/version.go 
new/helm3-3.22.0/internal/version/version.go
--- old/helm3-3.21.3/internal/version/version.go        2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/internal/version/version.go        2026-09-10 
00:21:05.000000000 +0200
@@ -29,7 +29,7 @@
        //
        // Increment major number for new feature additions and behavioral 
changes.
        // Increment minor number for bug fixes and performance enhancements.
-       version = "v3.21"
+       version = "v3.22"
 
        // metadata is extra build time data
        metadata = ""
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/chartutil/capabilities_test.go 
new/helm3-3.22.0/pkg/chartutil/capabilities_test.go
--- old/helm3-3.21.3/pkg/chartutil/capabilities_test.go 2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/chartutil/capabilities_test.go 2026-09-10 
00:21:05.000000000 +0200
@@ -62,8 +62,8 @@
 func TestDefaultCapabilitiesHelmVersion(t *testing.T) {
        hv := DefaultCapabilities.HelmVersion
 
-       if hv.Version != "v3.21" {
-               t.Errorf("Expected default HelmVersion to be v3.21, got %q", 
hv.Version)
+       if hv.Version != "v3.22" {
+               t.Errorf("Expected default HelmVersion to be v3.22, got %q", 
hv.Version)
        }
 }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/engine/files.go 
new/helm3-3.22.0/pkg/engine/files.go
--- old/helm3-3.21.3/pkg/engine/files.go        2026-07-09 22:58:46.000000000 
+0200
+++ new/helm3-3.22.0/pkg/engine/files.go        2026-09-10 00:21:05.000000000 
+0200
@@ -154,7 +154,7 @@
 // {{ range .Files.Lines "foo/bar.html" }}
 // {{ . }}{{ end }}
 func (f files) Lines(path string) []string {
-       if f == nil || f[path] == nil {
+       if f == nil || len(f[path]) == 0 {
                return []string{}
        }
        s := string(f[path])
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/engine/files_test.go 
new/helm3-3.22.0/pkg/engine/files_test.go
--- old/helm3-3.21.3/pkg/engine/files_test.go   2026-07-09 22:58:46.000000000 
+0200
+++ new/helm3-3.22.0/pkg/engine/files_test.go   2026-09-10 00:21:05.000000000 
+0200
@@ -30,6 +30,8 @@
        {"story/author.txt", "Joseph Conrad"},
        {"multiline/test.txt", "bar\nfoo\n"},
        {"multiline/test_with_blank_lines.txt", "bar\nfoo\n\n\n"},
+       {"empty/empty.txt", ""},
+       {"empty/newline_only.txt", "\n"},
 }
 
 func getTestFiles() files {
@@ -109,3 +111,31 @@
        as.Equal("bar", out[0])
        as.Equal("", out[3])
 }
+
+func TestLinesEmptyFile(t *testing.T) {
+       as := assert.New(t)
+
+       f := getTestFiles()
+
+       out := f.Lines("empty/empty.txt")
+       as.Empty(out)
+}
+
+func TestLinesNewlineOnlyFile(t *testing.T) {
+       as := assert.New(t)
+
+       f := getTestFiles()
+
+       out := f.Lines("empty/newline_only.txt")
+       as.Len(out, 1)
+       as.Empty(out[0])
+}
+
+func TestLinesMissingFile(t *testing.T) {
+       as := assert.New(t)
+
+       f := getTestFiles()
+
+       out := f.Lines("nonexistent.txt")
+       as.Empty(out)
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/kube/client.go 
new/helm3-3.22.0/pkg/kube/client.go
--- old/helm3-3.21.3/pkg/kube/client.go 2026-07-09 22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/kube/client.go 2026-09-10 00:21:05.000000000 +0200
@@ -392,7 +392,8 @@
                }
 
                helper := resource.NewHelper(info.Client, 
info.Mapping).WithFieldManager(getManagedFieldsManager())
-               if _, err := helper.Get(info.Namespace, info.Name); err != nil {
+               currentObj, err := helper.Get(info.Namespace, info.Name)
+               if err != nil {
                        if !apierrors.IsNotFound(err) {
                                return errors.Wrap(err, "could not get 
information about the resource")
                        }
@@ -413,7 +414,18 @@
                originalInfo := original.Get(info)
                if originalInfo == nil {
                        kind := info.Mapping.GroupVersionKind.Kind
-                       return errors.Errorf("no %s with the name %q found", 
kind, info.Name)
+
+                       c.Log("resource %s %q in namespace %q exists on cluster 
but not in original release, using cluster state as baseline",
+                               kind, info.Name, info.Namespace)
+
+                       if err := updateResource(c, info, currentObj, force, 
threeWayMerge); err != nil {
+                               c.Log("error updating the resource %q:\n\t %v", 
info.Name, err)
+                               updateErrors = append(updateErrors, err.Error())
+                       }
+                       // Because we check for errors later, append the info 
regardless
+                       res.Updated = append(res.Updated, info)
+
+                       return nil
                }
 
                if err := updateResource(c, info, originalInfo.Object, force, 
threeWayMerge); err != nil {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/kube/client_test.go 
new/helm3-3.22.0/pkg/kube/client_test.go
--- old/helm3-3.21.3/pkg/kube/client_test.go    2026-07-09 22:58:46.000000000 
+0200
+++ new/helm3-3.22.0/pkg/kube/client_test.go    2026-09-10 00:21:05.000000000 
+0200
@@ -346,6 +346,90 @@
        testUpdate(t, true)
 }
 
+// TestUpdateRollbackMissingOriginal tests the rollback scenario where:
+//   - Revision 1 had "newpod"
+//   - Revision 2 removed "newpod" but the upgrade failed (original list is 
empty)
+//   - Cluster still has "newpod" from Revision 1, but with different spec 
than the rollback target
+//   - Rolling back to Revision 1 (target with "newpod") should succeed using 
cluster state as baseline
+//     and must issue a real PATCH to reconcile the diff, not silently skip 
due to an empty patch.
+func TestUpdateRollbackMissingOriginal(t *testing.T) {
+       // target is Revision 1: newpod with port 443 (https).
+       listTarget := newPodList("newpod")
+       listTarget.Items[0].Spec.Containers[0].Ports = []v1.ContainerPort{
+               {Name: "https", ContainerPort: 443},
+       }
+
+       // clusterPod is what the cluster currently has: newpod with port 80 
(http).
+       // It deliberately differs from listTarget so that createPatch produces 
a
+       // non-empty patch and the PATCH request is actually issued.
+       clusterPod := newPod("newpod")
+
+       var actions []string
+       c := newTestClient(t)
+       c.Factory.(*cmdtesting.TestFactory).UnstructuredClient = 
&fake.RESTClient{
+               NegotiatedSerializer: unstructuredSerializer,
+               Client: fake.CreateHTTPClient(func(req *http.Request) 
(*http.Response, error) {
+                       p, m := req.URL.Path, req.Method
+                       actions = append(actions, p+":"+m)
+                       t.Logf("got request %s %s", p, m)
+                       switch {
+                       case p == "/namespaces/default/pods/newpod" && m == 
"GET":
+                               // Return the cluster state (port 80), which 
differs from the
+                               // rollback target (port 443), ensuring a 
non-empty patch.
+                               return newResponse(200, &clusterPod)
+                       case p == "/namespaces/default/pods/newpod" && m == 
"PATCH":
+                               return newResponse(200, &listTarget.Items[0])
+                       default:
+                               t.Fatalf("unexpected request: %s %s", 
req.Method, req.URL.Path)
+                               return nil, nil
+                       }
+               }),
+       }
+
+       // original is empty (Revision 2 had removed "newpod" but upgrade 
failed)
+       original, err := c.Build(objBody(&v1.PodList{}), false)
+       if err != nil {
+               t.Fatal(err)
+       }
+       // target is Revision 1 which had "newpod"
+       target, err := c.Build(objBody(&listTarget), false)
+       if err != nil {
+               t.Fatal(err)
+       }
+
+       result, err := c.Update(original, target, false)
+       if err != nil {
+               t.Fatalf("expected no error during rollback, got: %v", err)
+       }
+
+       if len(result.Created) != 0 {
+               t.Errorf("expected 0 resources created, got %d", 
len(result.Created))
+       }
+       if len(result.Updated) != 1 {
+               t.Errorf("expected 1 resource updated, got %d", 
len(result.Updated))
+       }
+       if len(result.Deleted) != 0 {
+               t.Errorf("expected 0 resources deleted, got %d", 
len(result.Deleted))
+       }
+
+       // Assert that the rollback path issued at least one real PATCH (not 
just
+       // GETs), and that no POST or DELETE was issued.
+       var patchCount int
+       for _, a := range actions {
+               switch {
+               case strings.HasSuffix(a, ":POST"):
+                       t.Errorf("unexpected POST during rollback (actions: 
%v)", actions)
+               case strings.HasSuffix(a, ":DELETE"):
+                       t.Errorf("unexpected DELETE during rollback (actions: 
%v)", actions)
+               case strings.HasSuffix(a, ":PATCH"):
+                       patchCount++
+               }
+       }
+       if patchCount == 0 {
+               t.Errorf("expected at least one PATCH request during rollback, 
got actions: %v", actions)
+       }
+}
+
 func TestBuild(t *testing.T) {
        tests := []struct {
                name      string
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/provenance/sign.go 
new/helm3-3.22.0/pkg/provenance/sign.go
--- old/helm3-3.21.3/pkg/provenance/sign.go     2026-07-09 22:58:46.000000000 
+0200
+++ new/helm3-3.22.0/pkg/provenance/sign.go     2026-09-10 00:21:05.000000000 
+0200
@@ -24,10 +24,10 @@
        "path/filepath"
        "strings"
 
+       "github.com/ProtonMail/go-crypto/openpgp"
+       "github.com/ProtonMail/go-crypto/openpgp/clearsign"
+       "github.com/ProtonMail/go-crypto/openpgp/packet"
        "github.com/pkg/errors"
-       "golang.org/x/crypto/openpgp"           //nolint
-       "golang.org/x/crypto/openpgp/clearsign" //nolint
-       "golang.org/x/crypto/openpgp/packet"    //nolint
        "sigs.k8s.io/yaml"
 
        hapi "helm.sh/helm/v3/pkg/chart"
@@ -314,8 +314,9 @@
 func (s *Signatory) verifySignature(block *clearsign.Block) (*openpgp.Entity, 
error) {
        return openpgp.CheckDetachedSignature(
                s.KeyRing,
-               bytes.NewBuffer(block.Bytes),
+               bytes.NewReader(block.Bytes),
                block.ArmoredSignature.Body,
+               &defaultPGPConfig,
        )
 }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/provenance/sign_test.go 
new/helm3-3.22.0/pkg/provenance/sign_test.go
--- old/helm3-3.21.3/pkg/provenance/sign_test.go        2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/provenance/sign_test.go        2026-09-10 
00:21:05.000000000 +0200
@@ -24,7 +24,8 @@
        "strings"
        "testing"
 
-       pgperrors "golang.org/x/crypto/openpgp/errors" //nolint
+       pgperrors "github.com/ProtonMail/go-crypto/openpgp/errors"
+       "github.com/ProtonMail/go-crypto/openpgp/packet"
 )
 
 const (
@@ -56,6 +57,9 @@
        // testTamperedSigBlock is a tampered copy of msgblock.yaml.asc
        testTamperedSigBlock = "testdata/msgblock.yaml.tampered"
 
+       // testMixedKeyring points to a keyring containing RSA and ed25519 keys.
+       testMixedKeyring = "testdata/helm-mixed-keyring.pub"
+
        // testSumfile points to a SHA256 sum generated by an external tool.
        // We always want to validate against an external tool's representation 
to
        // verify that we haven't done something stupid. This file was generated
@@ -232,6 +236,56 @@
        }
 }
 
+func TestMixedKeyringRSASigningAndVerification(t *testing.T) {
+       signer, err := NewFromFiles(testKeyfile, testMixedKeyring)
+       if err != nil {
+               t.Fatal(err)
+       }
+
+       if signer.Entity == nil {
+               t.Fatal("expected signer entity to be loaded")
+       }
+
+       if signer.Entity.PrivateKey == nil {
+               t.Fatal("expected signer private key to be loaded")
+       }
+
+       if signer.Entity.PrivateKey.PubKeyAlgo != packet.PubKeyAlgoRSA {
+               t.Fatalf("expected RSA key but got %v", 
signer.Entity.PrivateKey.PubKeyAlgo)
+       }
+
+       sig, err := signer.ClearSign(testChartfile)
+       if err != nil {
+               t.Fatalf("failed to sign chart: %v", err)
+       }
+
+       sigpath := filepath.Join(t.TempDir(), "hashtest-1.2.3.tgz.prov")
+       if err := os.WriteFile(sigpath, []byte(sig), 0o644); err != nil {
+               t.Fatal(err)
+       }
+
+       verification, err := signer.Verify(testChartfile, sigpath)
+       if err != nil {
+               t.Fatalf("failed to verify chart signature: %v", err)
+       }
+
+       if verification.SignedBy == nil {
+               t.Fatal("expected verification to include signer")
+       }
+
+       if verification.SignedBy.PrimaryKey == nil {
+               t.Fatal("expected verification to include signer primary key")
+       }
+
+       if verification.SignedBy.PrimaryKey.PubKeyAlgo != packet.PubKeyAlgoRSA {
+               t.Fatalf("expected verification to report RSA key but got %v", 
verification.SignedBy.PrimaryKey.PubKeyAlgo)
+       }
+
+       if _, ok := verification.SignedBy.Identities[testKeyName]; !ok {
+               t.Fatalf("expected verification to be signed by %q", 
testKeyName)
+       }
+}
+
 // failSigner always fails to sign and returns an error
 type failSigner struct{}
 
Binary files old/helm3-3.21.3/pkg/provenance/testdata/helm-mixed-keyring.pub 
and new/helm3-3.22.0/pkg/provenance/testdata/helm-mixed-keyring.pub differ
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/registry/client.go 
new/helm3-3.22.0/pkg/registry/client.go
--- old/helm3-3.21.3/pkg/registry/client.go     2026-07-09 22:58:46.000000000 
+0200
+++ new/helm3-3.22.0/pkg/registry/client.go     2026-09-10 00:21:05.000000000 
+0200
@@ -810,6 +810,8 @@
        repository.PlainHTTP = c.plainHTTP
        repository.Client = c.authorizer
 
+       ctx = WithScopeHint(ctx, repository, auth.ActionPush, auth.ActionPull)
+
        manifestDescriptor, err = oras.ExtendedCopy(ctx, memoryStore, 
parsedRef.String(), repository, parsedRef.String(), 
oras.DefaultExtendedCopyOptions)
        if err != nil {
                return nil, err
@@ -1021,3 +1023,11 @@
        return oras.TagBytes(ctx, memoryStore, ocispec.MediaTypeImageManifest,
                manifestData, parsedRef.String())
 }
+
+// WithScopeHint adds a hinted scope to the context.
+func WithScopeHint(ctx context.Context, target any, actions ...string) 
context.Context {
+       if repo, ok := target.(*remote.Repository); ok {
+               return auth.AppendRepositoryScope(ctx, repo.Reference, 
actions...)
+       }
+       return ctx
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/registry/client_http_test.go 
new/helm3-3.22.0/pkg/registry/client_http_test.go
--- old/helm3-3.21.3/pkg/registry/client_http_test.go   2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/registry/client_http_test.go   2026-09-10 
00:21:05.000000000 +0200
@@ -33,7 +33,7 @@
 
 func (suite *HTTPRegistryClientTestSuite) SetupSuite() {
        // init test client
-       dockerRegistry := setup(&suite.TestSuite, false, false)
+       dockerRegistry := setup(&suite.TestSuite, false, false, "htpasswd")
 
        // Start Docker registry
        go dockerRegistry.ListenAndServe()
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/helm3-3.21.3/pkg/registry/client_insecure_tls_test.go 
new/helm3-3.22.0/pkg/registry/client_insecure_tls_test.go
--- old/helm3-3.21.3/pkg/registry/client_insecure_tls_test.go   2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/registry/client_insecure_tls_test.go   2026-09-10 
00:21:05.000000000 +0200
@@ -29,7 +29,7 @@
 
 func (suite *InsecureTLSRegistryClientTestSuite) SetupSuite() {
        // init test client
-       dockerRegistry := setup(&suite.TestSuite, true, true)
+       dockerRegistry := setup(&suite.TestSuite, true, true, "htpasswd")
 
        // Start Docker registry
        go dockerRegistry.ListenAndServe()
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/registry/client_scope_test.go 
new/helm3-3.22.0/pkg/registry/client_scope_test.go
--- old/helm3-3.21.3/pkg/registry/client_scope_test.go  1970-01-01 
01:00:00.000000000 +0100
+++ new/helm3-3.22.0/pkg/registry/client_scope_test.go  2026-09-10 
00:21:05.000000000 +0200
@@ -0,0 +1,112 @@
+/*
+Copyright The Helm Authors.
+
+Licensed under the Apache License, Version 2.0 (the "License");
+you may not use this file except in compliance with the License.
+You may obtain a copy of the License at
+
+    http://www.apache.org/licenses/LICENSE-2.0
+
+Unless required by applicable law or agreed to in writing, software
+distributed under the License is distributed on an "AS IS" BASIS,
+WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+See the License for the specific language governing permissions and
+limitations under the License.
+*/
+
+package registry
+
+import (
+       "context"
+       "fmt"
+       "log"
+       "net/http"
+       "os"
+       "testing"
+
+       "github.com/stretchr/testify/suite"
+)
+
+type RegistryScopeTestSuite struct {
+       TestSuite
+}
+
+func (suite *RegistryScopeTestSuite) SetupSuite() {
+       // set registry use token auth
+       dockerRegistry := setup(&suite.TestSuite, true, true, "token")
+       // Start Docker registry
+       go dockerRegistry.ListenAndServe()
+}
+func (suite *RegistryScopeTestSuite) TearDownSuite() {
+       teardown(&suite.TestSuite)
+       os.RemoveAll(suite.WorkspaceDir)
+}
+
+func (suite *RegistryScopeTestSuite) Test_1_Cehck_Push_Request_Scope() {
+
+       //set simple auth server to check the auth request scope
+       server := &http.Server{
+               Addr: suite.AuthServerHost,
+               Handler: http.HandlerFunc(func(w http.ResponseWriter, r 
*http.Request) {
+                       
suite.Equal(string("/auth?scope=repository%3Atestrepo%2Flocal-subchart%3Apull%2Cpush&service=testservice"),
 r.URL.String())
+                       w.WriteHeader(http.StatusOK)
+               }),
+       }
+       go func() {
+               err := server.ListenAndServe()
+               if err != nil && err != http.ErrServerClosed {
+                       log.Fatalf("http server failed to ListenAndServe:%v", 
err)
+               }
+       }()
+
+       // basic push, good ref
+       testingChartCreationTime := "1977-09-02T22:04:05Z"
+       chartData, err := 
os.ReadFile("../downloader/testdata/local-subchart-0.1.0.tgz")
+       suite.Nil(err, "no error loading test chart")
+       meta, err := extractChartMeta(chartData)
+       suite.Nil(err, "no error extracting chart meta")
+       ref := fmt.Sprintf("%s/testrepo/%s:%s", suite.DockerRegistryHost, 
meta.Name, meta.Version)
+       _, err = suite.RegistryClient.Push(chartData, ref, 
PushOptCreationTime(testingChartCreationTime))
+       suite.NotNil(err, "error pushing good ref because auth server don't 
give proper token")
+
+       //shutdown auth server
+       err = server.Shutdown(context.Background())
+       suite.Nil(err, "shutdown simple auth server")
+
+}
+
+func (suite *RegistryScopeTestSuite) Test_2_Cehck_Pull_Request_Scope() {
+
+       //set simple auth server to check the auth request scope
+       server := &http.Server{
+               Addr: suite.AuthServerHost,
+               Handler: http.HandlerFunc(func(w http.ResponseWriter, r 
*http.Request) {
+                       
suite.Equal(string("/auth?scope=repository%3Atestrepo%2Flocal-subchart%3Apull&service=testservice"),
 r.URL.String())
+                       w.WriteHeader(http.StatusOK)
+               }),
+       }
+       go func() {
+               err := server.ListenAndServe()
+               if err != nil && err != http.ErrServerClosed {
+                       log.Fatalf("http server failed to ListenAndServe:%v", 
err)
+               }
+       }()
+
+       // Load test chart (to build ref pushed in previous test)
+       // Simple pull, chart only
+       chartData, err := 
os.ReadFile("../downloader/testdata/local-subchart-0.1.0.tgz")
+       suite.Nil(err, "no error loading test chart")
+       meta, err := extractChartMeta(chartData)
+       suite.Nil(err, "no error extracting chart meta")
+       ref := fmt.Sprintf("%s/testrepo/%s:%s", suite.DockerRegistryHost, 
meta.Name, meta.Version)
+       _, err = suite.RegistryClient.Pull(ref)
+       suite.NotNil(err, "error pulling a simple chart because auth server 
don't give proper token")
+
+       //shutdown auth server
+       err = server.Shutdown(context.Background())
+       suite.Nil(err, "shutdown simple auth server")
+}
+
+func TestRegistryScopeTestSuite(t *testing.T) {
+       suite.Run(t, new(RegistryScopeTestSuite))
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/registry/client_tls_test.go 
new/helm3-3.22.0/pkg/registry/client_tls_test.go
--- old/helm3-3.21.3/pkg/registry/client_tls_test.go    2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/registry/client_tls_test.go    2026-09-10 
00:21:05.000000000 +0200
@@ -29,7 +29,7 @@
 
 func (suite *TLSRegistryClientTestSuite) SetupSuite() {
        // init test client
-       dockerRegistry := setup(&suite.TestSuite, true, false)
+       dockerRegistry := setup(&suite.TestSuite, true, false, "htpasswd")
 
        // Start Docker registry
        go dockerRegistry.ListenAndServe()
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/registry/utils_test.go 
new/helm3-3.22.0/pkg/registry/utils_test.go
--- old/helm3-3.21.3/pkg/registry/utils_test.go 2026-07-09 22:58:46.000000000 
+0200
+++ new/helm3-3.22.0/pkg/registry/utils_test.go 2026-09-10 00:21:05.000000000 
+0200
@@ -34,10 +34,10 @@
        "github.com/distribution/distribution/v3/configuration"
        "github.com/distribution/distribution/v3/registry"
        _ "github.com/distribution/distribution/v3/registry/auth/htpasswd"
+       _ "github.com/distribution/distribution/v3/registry/auth/token"
        _ 
"github.com/distribution/distribution/v3/registry/storage/driver/inmemory"
        "github.com/foxcpp/go-mockdns"
        ocispec "github.com/opencontainers/image-spec/specs-go/v1"
-       "github.com/phayes/freeport"
        "github.com/stretchr/testify/suite"
        "golang.org/x/crypto/bcrypt"
 
@@ -57,6 +57,8 @@
        testHtpasswdFileBasename = "authtest.htpasswd"
        testUsername             = "myuser"
        testPassword             = "mypass"
+       testIssuer               = "testissuer"
+       testService              = "testservice"
 )
 
 type TestSuite struct {
@@ -64,6 +66,7 @@
        Out                     io.Writer
        FakeRegistryHost        string
        DockerRegistryHost      string
+       AuthServerHost          string
        CompromisedRegistryHost string
        WorkspaceDir            string
        RegistryClient          *Client
@@ -73,7 +76,7 @@
        srv *mockdns.Server
 }
 
-func setup(suite *TestSuite, tlsEnabled, insecure bool) *registry.Registry {
+func setup(suite *TestSuite, tlsEnabled, insecure bool, auth string) 
*registry.Registry {
        suite.WorkspaceDir = testWorkspaceDir
        os.RemoveAll(suite.WorkspaceDir)
        os.Mkdir(suite.WorkspaceDir, 0700)
@@ -124,12 +127,14 @@
 
        // Registry config
        config := &configuration.Configuration{}
-       port, err := freeport.GetFreePort()
+       ln, err := net.Listen("tcp", "127.0.0.1:0")
        suite.Nil(err, "no error finding free port for test registry")
+       defer ln.Close()
 
        // Change the registry host to another host which is not localhost.
        // This is required because Docker enforces HTTP if the registry
        // host is localhost/127.0.0.1.
+       port := ln.Addr().(*net.TCPAddr).Port
        if suite.DockerRegistryHost == "" {
                suite.DockerRegistryHost = 
fmt.Sprintf("helm-test-registry:%d%s", port, suite.Repo)
        } else {
@@ -144,15 +149,33 @@
        suite.Nil(err, "no error creating mock DNS server")
        suite.srv.PatchNet(net.DefaultResolver)
 
-       config.HTTP.Addr = fmt.Sprintf(":%d", port)
+       config.HTTP.Addr = ln.Addr().String()
        config.HTTP.DrainTimeout = time.Duration(10) * time.Second
        config.Storage = map[string]configuration.Parameters{"inmemory": 
map[string]interface{}{}}
 
-       config.Auth = configuration.Auth{
-               "htpasswd": configuration.Parameters{
-                       "realm": "localhost",
-                       "path":  htpasswdPath,
-               },
+       if auth == "token" {
+               ln, err := net.Listen("tcp", "127.0.0.1:0")
+               suite.Nil(err, "no error finding free port for test auth 
server")
+               defer ln.Close()
+
+               //set test auth server host
+               suite.AuthServerHost = ln.Addr().String()
+
+               config.Auth = configuration.Auth{
+                       "token": configuration.Parameters{
+                               "realm":          "http://"; + 
suite.AuthServerHost + "/auth",
+                               "service":        testService,
+                               "issuer":         testIssuer,
+                               "rootcertbundle": tlsServerCert,
+                       },
+               }
+       } else {
+               config.Auth = configuration.Auth{
+                       "htpasswd": configuration.Parameters{
+                               "realm": "localhost",
+                               "path":  htpasswdPath,
+                       },
+               }
        }
 
        // config tls
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/helm3-3.21.3/pkg/repo/repotest/server.go 
new/helm3-3.22.0/pkg/repo/repotest/server.go
--- old/helm3-3.21.3/pkg/repo/repotest/server.go        2026-07-09 
22:58:46.000000000 +0200
+++ new/helm3-3.22.0/pkg/repo/repotest/server.go        2026-09-10 
00:21:05.000000000 +0200
@@ -18,6 +18,7 @@
 import (
        "context"
        "fmt"
+       "net"
        "net/http"
        "net/http/httptest"
        "os"
@@ -29,7 +30,6 @@
        "github.com/distribution/distribution/v3/registry"
        _ "github.com/distribution/distribution/v3/registry/auth/htpasswd"      
     // used for docker test registry
        _ 
"github.com/distribution/distribution/v3/registry/storage/driver/inmemory" // 
used for docker test registry
-       "github.com/phayes/freeport"
        "golang.org/x/crypto/bcrypt"
        "sigs.k8s.io/yaml"
 
@@ -108,12 +108,14 @@
 
        // Registry config
        config := &configuration.Configuration{}
-       port, err := freeport.GetFreePort()
+       ln, err := net.Listen("tcp", "127.0.0.1:0")
        if err != nil {
                t.Fatalf("error finding free port for test registry")
        }
+       defer ln.Close()
 
-       config.HTTP.Addr = fmt.Sprintf(":%d", port)
+       port := ln.Addr().(*net.TCPAddr).Port
+       config.HTTP.Addr = ln.Addr().String()
        config.HTTP.DrainTimeout = time.Duration(10) * time.Second
        config.Storage = map[string]configuration.Parameters{"inmemory": 
map[string]interface{}{}}
        config.Auth = configuration.Auth{

++++++ helm3.obsinfo ++++++
--- /var/tmp/diff_new_pack.IUwRKw/_old  2026-09-21 12:13:57.531064359 +0200
+++ /var/tmp/diff_new_pack.IUwRKw/_new  2026-09-21 12:13:57.535064526 +0200
@@ -1,5 +1,5 @@
 name: helm3
-version: 3.21.3
-mtime: 1783630726
-commit: 1ad6e68924fdf6fb0c7dcef8e9e1dfc0f36eaed6
+version: 3.22.0
+mtime: 1788992465
+commit: 144ca65f8501953fa8b41cd1d37c7223051c85b7
 

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/helm3/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.helm3.new.383539/vendor.tar.zst differ: char 7, 
line 1

Reply via email to