Skip to content

Revert "release: move chart to the v1.2.2 image" - #496

Merged
raunak-nirmata merged 1 commit into
mainfrom
revert/chart-v1.2.2
Sep 21, 2026
Merged

raunak-nirmata merged 1 commit into
mainfrom
revert/chart-v1.2.2

Conversation

@raunak-nirmata

Copy link
Copy Markdown
Contributor

Reverts fcc952b (#494).

The v1.2.2 chart artifacts have been unpublished and the v1.2.0, v1.2.1 and v1.2.2 images are being deleted from the registry, ahead of archiving this repository.

With those images gone, leaving appVersion: v1.2.2 would point the chart at a tag that no longer resolves, so a default helm install from the archived repo would fail with ImagePullBackOff. appVersion returns to v1.1, which is still published (sha256:578d5e1e…).

Verified

$ helm template knaws ./charts/kyverno-notation-aws
      - image: "ghcr.io/nirmata/kyverno-notation-aws:v1.1"

README.md reverts alongside it, since it is generated from Chart.yaml by make codegen-helm-docs.

Please read before merging

This puts the chart back on ghcr.io/nirmata/kyverno-notation-aws:v1.1 — the image reported in #488 carrying 156 unique CVEs, 6 CRITICAL and 75 HIGH. That is a deliberate trade: a vulnerable-but-present image over a tag that 404s.

Anyone who needs the remediated build should use the successor repository rather than this chart. It would be worth saying so in the README or a pinned issue before archiving, since an archived repo cannot accept that correction later.

Not reverted

The CVE work itself stays on main — the Go toolchain bump to 1.26.8, the 139 dependency upgrades, and building the AWS signer plugin from source. Only the release pointer moves back. git log remains the record of what was fixed, even though no published artifact carries it.

Sequencing

Merge this before archiving. An archived repository is read-only and will not accept the change afterwards.

This reverts commit fcc952b.

The v1.2.2 chart artifacts have been unpublished and the v1.2.0, v1.2.1 and
v1.2.2 images are being removed from the registry, ahead of archiving this
repository. Leaving appVersion at v1.2.2 would point the chart at an image that
no longer exists, so a default helm install from an archived repo would fail
with ImagePullBackOff.

appVersion returns to v1.1, which is still published.

Note what this means: the chart again resolves to
ghcr.io/nirmata/kyverno-notation-aws:v1.1, the image reported in #488 with 156
unique CVEs, 6 CRITICAL and 75 HIGH. That is deliberate. The alternative is a
tag that 404s. Anyone needing the remediated build should use the successor
repository rather than this chart.

The CVE fixes themselves stay on main. Only the release pointer is reverted.
@raunak-nirmata
raunak-nirmata merged commit b0677e4 into main Sep 21, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants