From 6034a54e0da2a1793cddbeb759ea2771fc5952e8 Mon Sep 17 00:00:00 2001 From: yxxhero <11087727+yxxhero@users.noreply.github.com> Date: Sun, 16 Aug 2026 10:47:19 +0800 Subject: [PATCH] refactor: drop empty-render workaround now that chartify handles it natively (#2747) Bump github.com/helmfile/chartify to v0.28.2, which fixes the empty-render crash upstream (helmfile/chartify#206, fixed in helmfile/chartify#207): when a chart renders zero resources, chartify now treats it as a no-op success itself - removing the chart's content dirs, cleaning Chart.yaml dependencies and the lock file, and skipping the kustomize step - instead of failing with: assertion failed: unexpected dir entry "" it must be the abs path to the output directory That makes the helmfile-side string-matching workaround from #2724 dead code: the error it matched can no longer be produced. Remove isChartifyEmptyRenderOutputError and the special-cased no-op branch in processChartification, so the empty-render case simply flows through the regular chartify path. Also bump github.com/helmfile/vals to v0.46.0 and refresh transitive dependencies. The regression test for #1757 is updated to assert the new direct behavior: processChartification succeeds, returns a chartified chart whose Chart.yaml no longer declares dependencies (so a subsequent "helm dep build"/"helm template" cannot fail with "found in Chart.yaml, but missing in charts/ directory"), renders empty output, and is cleaned up by CleanupChartifyTempDirs. Fixes #1757 (follow-up to #2724) Signed-off-by: yxxhero --- go.mod | 71 ++++++++--------- go.sum | 70 +++++++++++++++++ pkg/state/issue_1757_test.go | 144 +++++++++++++---------------------- pkg/state/state.go | 48 ------------ 4 files changed, 161 insertions(+), 172 deletions(-) diff --git a/go.mod b/go.mod index 4f6b76ec..5c18973a 100644 --- a/go.mod +++ b/go.mod @@ -18,8 +18,8 @@ require ( github.com/hashicorp/go-cty-funcs v0.1.0 github.com/hashicorp/go-getter/v2 v2.2.3 github.com/hashicorp/hcl/v2 v2.24.0 - github.com/helmfile/chartify v0.28.1 - github.com/helmfile/vals v0.45.0 + github.com/helmfile/chartify v0.28.2 + github.com/helmfile/vals v0.46.0 github.com/sashabaranov/go-openai v1.42.0 github.com/spf13/cobra v1.10.2 github.com/spf13/pflag v1.0.10 @@ -39,8 +39,8 @@ require ( gopkg.in/yaml.v3 v3.0.1 helm.sh/helm/v3 v3.21.4 helm.sh/helm/v4 v4.2.4 - k8s.io/apimachinery v0.36.2 - k8s.io/client-go v0.36.2 + k8s.io/apimachinery v0.36.3 + k8s.io/client-go v0.36.3 ) replace ( @@ -54,7 +54,7 @@ replace ( require ( cloud.google.com/go v0.123.0 // indirect cloud.google.com/go/iam v1.11.0 // indirect - cloud.google.com/go/storage v1.63.1 // indirect + cloud.google.com/go/storage v1.64.0 // indirect filippo.io/age v1.3.1 // indirect github.com/Azure/go-autorest v14.2.0+incompatible // indirect github.com/Azure/go-autorest/autorest/adal v0.9.23 // indirect @@ -107,12 +107,12 @@ require ( github.com/spf13/cast v1.7.0 // indirect github.com/ulikunitz/xz v0.5.15 // indirect go.uber.org/atomic v1.9.0 // indirect - golang.org/x/net v0.56.0 // indirect + golang.org/x/net v0.57.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sys v0.47.0 // indirect golang.org/x/text v0.40.0 // indirect golang.org/x/time v0.15.0 // indirect - google.golang.org/api v0.288.0 // indirect + google.golang.org/api v0.291.0 // indirect google.golang.org/genproto v0.0.0-20260622175928-b703f567277d // indirect google.golang.org/grpc v1.82.1 // indirect google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect @@ -124,13 +124,13 @@ require ( require ( al.essio.dev/pkg/shellescape v1.6.0 // indirect cel.dev/expr v0.25.2 // indirect - cloud.google.com/go/auth v0.20.0 // indirect + cloud.google.com/go/auth v0.22.0 // indirect cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect cloud.google.com/go/compute/metadata v0.9.0 // indirect - cloud.google.com/go/kms v1.32.0 // indirect + cloud.google.com/go/kms v1.33.0 // indirect cloud.google.com/go/longrunning v1.2.0 // indirect cloud.google.com/go/monitoring v1.29.0 // indirect - cloud.google.com/go/secretmanager v1.20.0 // indirect + cloud.google.com/go/secretmanager v1.21.0 // indirect filippo.io/edwards25519 v1.2.0 // indirect filippo.io/hpke v0.4.0 // indirect github.com/1Password/connect-sdk-go v1.5.3 // indirect @@ -158,7 +158,7 @@ require ( github.com/acarl005/stripansi v0.0.0-20180116102854-5a71ef0e047d // indirect github.com/agext/levenshtein v1.2.3 // indirect github.com/antchfx/jsonquery v1.3.7 // indirect - github.com/antchfx/xpath v1.3.6 // indirect + github.com/antchfx/xpath v1.3.8 // indirect github.com/apparentlymart/go-cidr v1.1.0 // indirect github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect github.com/apparentlymart/go-textseg/v17 v17.0.1 // indirect @@ -179,9 +179,9 @@ require ( github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.36 // indirect github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.37 // indirect github.com/aws/aws-sdk-go-v2/service/kms v1.54.1 // indirect - github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.43.1 // indirect + github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.44.1 // indirect github.com/aws/aws-sdk-go-v2/service/signin v1.5.5 // indirect - github.com/aws/aws-sdk-go-v2/service/ssm v1.72.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ssm v1.73.0 // indirect github.com/aws/aws-sdk-go-v2/service/sso v1.33.5 // indirect github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.5 // indirect github.com/aws/aws-sdk-go-v2/service/sts v1.45.5 // indirect @@ -198,7 +198,7 @@ require ( github.com/cloudflare/circl v1.6.4 // indirect github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 // indirect github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect - github.com/cyberark/conjur-api-go v0.15.3 // indirect + github.com/cyberark/conjur-api-go v0.15.5 // indirect github.com/cyphar/filepath-securejoin v0.7.0 // indirect github.com/danieljoos/wincred v1.2.2 // indirect github.com/dominikbraun/graph v0.23.0 // indirect @@ -221,30 +221,31 @@ require ( github.com/go-errors/errors v1.5.1 // indirect github.com/go-gorp/gorp/v3 v3.1.0 // indirect github.com/go-jose/go-jose/v4 v4.1.4 // indirect - github.com/go-logr/logr v1.4.3 // indirect + github.com/go-logr/logr v1.4.4 // indirect github.com/go-logr/stdr v1.2.2 // indirect - github.com/go-openapi/analysis v0.25.2 // indirect + github.com/go-openapi/analysis v0.25.5 // indirect github.com/go-openapi/errors v0.22.8 // indirect - github.com/go-openapi/jsonpointer v0.23.1 // indirect - github.com/go-openapi/jsonreference v0.21.6 // indirect - github.com/go-openapi/loads v0.24.0 // indirect - github.com/go-openapi/runtime v0.32.4 // indirect + github.com/go-openapi/jsonpointer v1.0.0 // indirect + github.com/go-openapi/jsonreference v1.0.0 // indirect + github.com/go-openapi/loads v0.25.0 // indirect + github.com/go-openapi/runtime v0.33.0 // indirect github.com/go-openapi/runtime/server-middleware v0.30.0 // indirect - github.com/go-openapi/spec v0.22.6 // indirect - github.com/go-openapi/strfmt v0.26.3 // indirect + github.com/go-openapi/spec v0.22.9 // indirect + github.com/go-openapi/strfmt v0.27.0 // indirect github.com/go-openapi/swag v0.24.1 // indirect github.com/go-openapi/swag/cmdutils v0.24.0 // indirect - github.com/go-openapi/swag/conv v0.26.1 // indirect - github.com/go-openapi/swag/fileutils v0.26.1 // indirect + github.com/go-openapi/swag/conv v0.27.3 // indirect + github.com/go-openapi/swag/fileutils v0.27.3 // indirect github.com/go-openapi/swag/jsonname v0.26.1 // indirect - github.com/go-openapi/swag/jsonutils v0.26.1 // indirect - github.com/go-openapi/swag/loading v0.26.1 // indirect - github.com/go-openapi/swag/mangling v0.26.1 // indirect + github.com/go-openapi/swag/jsonutils v0.27.3 // indirect + github.com/go-openapi/swag/loading v0.27.3 // indirect + github.com/go-openapi/swag/mangling v0.27.3 // indirect github.com/go-openapi/swag/netutils v0.24.0 // indirect - github.com/go-openapi/swag/stringutils v0.26.1 // indirect - github.com/go-openapi/swag/typeutils v0.26.1 // indirect - github.com/go-openapi/swag/yamlutils v0.26.1 // indirect - github.com/go-openapi/validate v0.26.0 // indirect + github.com/go-openapi/swag/pools v0.27.3 // indirect + github.com/go-openapi/swag/stringutils v0.27.3 // indirect + github.com/go-openapi/swag/typeutils v0.27.3 // indirect + github.com/go-openapi/swag/yamlutils v0.27.3 // indirect + github.com/go-openapi/validate v0.26.1 // indirect github.com/go-resty/resty/v2 v2.13.1 // indirect github.com/go-viper/mapstructure/v2 v2.5.0 // indirect github.com/gobwas/glob v0.2.3 // indirect @@ -256,7 +257,7 @@ require ( github.com/google/go-jsonnet v0.22.0 // indirect github.com/google/s2a-go v0.1.9 // indirect github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect - github.com/googleapis/enterprise-certificate-proxy v0.3.17 // indirect + github.com/googleapis/enterprise-certificate-proxy v0.3.19 // indirect github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect github.com/hashicorp/go-retryablehttp v0.7.8 // indirect github.com/hashicorp/go-safetemp v1.0.0 // indirect @@ -344,12 +345,12 @@ require ( golang.org/x/mod v0.37.0 // indirect golang.org/x/tools v0.47.0 // indirect google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260630182238-925bb5da69e7 // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260724162435-b2f20204f0df // indirect gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect gopkg.in/gookit/color.v1 v1.1.6 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect - k8s.io/api v0.36.2 // indirect + k8s.io/api v0.36.3 // indirect k8s.io/apiextensions-apiserver v0.36.2 // indirect k8s.io/apiserver v0.36.2 // indirect k8s.io/cli-runtime v0.36.2 // indirect @@ -363,5 +364,5 @@ require ( sigs.k8s.io/kustomize/api v0.21.1 // indirect sigs.k8s.io/kustomize/kyaml v0.21.1 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.3.3 // indirect ) diff --git a/go.sum b/go.sum index 8b069f6f..696ab90a 100644 --- a/go.sum +++ b/go.sum @@ -9,6 +9,8 @@ cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE= cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU= cloud.google.com/go/auth v0.20.0 h1:kXTssoVb4azsVDoUiF8KvxAqrsQcQtB53DcSgta74CA= cloud.google.com/go/auth v0.20.0/go.mod h1:942/yi/itH1SsmpyrbnTMDgGfdy2BUqIKyd0cyYLc5Q= +cloud.google.com/go/auth v0.22.0 h1:Xp9wAKkLoeaYb5pYZZoQGz4E9sdPxIbzS3gywZE3ciQ= +cloud.google.com/go/auth v0.22.0/go.mod h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s= cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc= cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c= cloud.google.com/go/compute/metadata v0.9.0 h1:pDUj4QMoPejqq20dK0Pg2N4yG9zIkYGdBtwLoEkH9Zs= @@ -17,6 +19,8 @@ cloud.google.com/go/iam v1.11.0 h1:KieQ9Pb+LLPak1O3Rv3GgCxhnmkYf7Xyh0P5HfF1jFM= cloud.google.com/go/iam v1.11.0/go.mod h1:KP+nKGugNJW4LcLx1uEZcq1ok5sQHFaQehQNl4QDgV4= cloud.google.com/go/kms v1.32.0 h1:s+rEluaaZKhLVjrIWG7uNBsnWbiitElzNzFGyp6+nIg= cloud.google.com/go/kms v1.32.0/go.mod h1:CSGvW6GnMQbY+1nOHcIzhMtHSbExXlOmCKjWtYVjcpA= +cloud.google.com/go/kms v1.33.0 h1:pG0X78m212b2pv9N4fdMoUO69LuZGQ9kSvn8sHBOFAo= +cloud.google.com/go/kms v1.33.0/go.mod h1:CSGvW6GnMQbY+1nOHcIzhMtHSbExXlOmCKjWtYVjcpA= cloud.google.com/go/logging v1.18.0 h1:KhzZq+1cSkPH9YUaKLLhLtQxIHitVayBmk0sGfoM9+k= cloud.google.com/go/logging v1.18.0/go.mod h1:ZGKnpBaURITh+g/uom2VhbiFoFWvejcrHPDhxFtU/gI= cloud.google.com/go/longrunning v1.2.0 h1:WjYH3YHBGCxGJP9M4dWGHBfXr/cFIjMkNgWcJj7/iMM= @@ -25,8 +29,12 @@ cloud.google.com/go/monitoring v1.29.0 h1:AHhDsFaSax1/4k+qlIDX/SDGe6hggnfXJ9dkgD cloud.google.com/go/monitoring v1.29.0/go.mod h1:72NOVjJXHY/HBfoLT0+qlCZBT059+9VXLeAnL2PeeVM= cloud.google.com/go/secretmanager v1.20.0 h1:GjE3NoyFXo7ipRPy26PMmg4oRX1Ra8fswH45r16rWV0= cloud.google.com/go/secretmanager v1.20.0/go.mod h1:9OmSuOeiiUicANglrbdKWSnT3gYkRcXuUQDk7dDW0zU= +cloud.google.com/go/secretmanager v1.21.0 h1:e56QQaKWRyzBdUz40AeZaio/ZHAl268cFx3QFAAw9CY= +cloud.google.com/go/secretmanager v1.21.0/go.mod h1:+nlV+GYqTD8DM+x7Kk3UF7ZPYgdYMowrkZxAmMXORQ8= cloud.google.com/go/storage v1.63.1 h1:CYXILV9G4CH0C18IQ9+V0h4XiqD2LhKnMLO0o7uJWNs= cloud.google.com/go/storage v1.63.1/go.mod h1:lWyAtwvDZHdL3k68WVKbESP6bmWaV23ZJJ/JEVw/ZaQ= +cloud.google.com/go/storage v1.64.0 h1:KLpxI/oX9LxeRsNqn877d2WyeT3ryiEwnGt8pwcSPZg= +cloud.google.com/go/storage v1.64.0/go.mod h1:lWyAtwvDZHdL3k68WVKbESP6bmWaV23ZJJ/JEVw/ZaQ= cloud.google.com/go/trace v1.16.0 h1:GmQovzFc5F0CNfl0VLgL64aoTtu7xsM0YajW2GlG9+E= cloud.google.com/go/trace v1.16.0/go.mod h1:r+bdAn16dKLSV1G2D5v3e58IlQlizfxWrUfjx7kM7X0= dario.cat/mergo v1.0.2 h1:85+piFYR1tMbRrLcDwR18y4UKJ3aH1Tbzi24VRW1TK8= @@ -98,6 +106,7 @@ github.com/DATA-DOG/go-sqlmock v1.5.2 h1:OcvFkGmslmlZibjAjaHm3L//6LiuBgolP7Oputl github.com/DATA-DOG/go-sqlmock v1.5.2/go.mod h1:88MAG/4G7SMwSE3CeA0ZKzrT5CiOU3OJ+JlNzwDqpNU= github.com/DelineaXPM/tss-sdk-go/v3 v3.0.2 h1:8wRzxlo6fujNoDbnp6PnawY3moxqQelxpJGzTHG7Qoo= github.com/DelineaXPM/tss-sdk-go/v3 v3.0.2/go.mod h1:VmyoHQ25FhSVHTI3/ptQNOviNEMfCy2ALAf/3E4Eqxg= +github.com/DopplerHQ/cli v0.5.10/go.mod h1:WmcigO8HEBBct6dWYfLwKKMDhpn3vWk3MNl60Co5JUw= github.com/DopplerHQ/cli v0.5.11-0.20230908185655-7aef4713e1a4 h1:s7/zwMi5w+KnlumDVbX1+P6mNAk5o7Wvx0VmvrQ7Bm0= github.com/DopplerHQ/cli v0.5.11-0.20230908185655-7aef4713e1a4/go.mod h1:ipnA9Lpn5YM+FDSQZ7VWNjcuVurchInoGKm+v7O0sGs= github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.33.0 h1:l7+6kwRMJNwdCvYdDl7Eax+wzEYHSnNY7zrrfbhDdTA= @@ -138,6 +147,8 @@ github.com/antchfx/jsonquery v1.3.7 h1:LUoue12xcCj6Q41kYUSAS0UJ+9s3XyxbP5uh7x8aM github.com/antchfx/jsonquery v1.3.7/go.mod h1:oGh95SRUXZfnma1B7Q0p1rhgDeSgghub4W+JwnUYv2o= github.com/antchfx/xpath v1.3.6 h1:s0y+ElRRtTQdfHP609qFu0+c6bglDv20pqOViQjjdPI= github.com/antchfx/xpath v1.3.6/go.mod h1:i54GszH55fYfBmoZXapTHN8T8tkcHfRgLyVwwqzXNcs= +github.com/antchfx/xpath v1.3.8 h1:RQlkLaJDKk1Ew1H6CUPUTKM+IQxm+6HTyOgcrfqOU9c= +github.com/antchfx/xpath v1.3.8/go.mod h1:i54GszH55fYfBmoZXapTHN8T8tkcHfRgLyVwwqzXNcs= github.com/apparentlymart/go-cidr v1.1.0 h1:2mAhrMoF+nhXqxTzSZMUzDHkLjmIHC+Zzn4tdgBZjnU= github.com/apparentlymart/go-cidr v1.1.0/go.mod h1:EBcsNrHc3zQeuaeCeCtQruQm+n9/YjEn/vI25Lg7Gwc= github.com/apparentlymart/go-textseg/v15 v15.0.0 h1:uYvfpb3DyLSCGWnctWKGj857c6ew1u1fNQOlOtuGxQY= @@ -186,10 +197,14 @@ github.com/aws/aws-sdk-go-v2/service/s3 v1.107.1 h1:VUTtUJMuRNMkb/7NIKmd8NQaeQLP github.com/aws/aws-sdk-go-v2/service/s3 v1.107.1/go.mod h1:WvUaO0lP5GNMs1R6cs6qvB3mqo16GLta8yfOuf55Rpc= github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.43.1 h1:ZI18/nuaDBwwMJ95paJrb4NT2TbqEvptj/rlMkEO7DI= github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.43.1/go.mod h1:oUyL28WfxY0RqPhFpkrWZx26Cu4JlyrWMMcWq8qqhi0= +github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.44.1 h1:TpALnO2Chp6wQOihK/v+qoPN80YOyu3hG/MQ9dG+DGo= +github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.44.1/go.mod h1:nfho2mqRsESddA8OHQiiqhNKaZtGW1Pe1sf6RJFYnfE= github.com/aws/aws-sdk-go-v2/service/signin v1.5.5 h1:0VTFBfOgPJrUSpGMgzoi8qLcXF5dbmiBuxpo14eBWUw= github.com/aws/aws-sdk-go-v2/service/signin v1.5.5/go.mod h1:sNZYlBxoohYMBYl47BO/bFtAM6I8HSsPa1qwwPPRGoQ= github.com/aws/aws-sdk-go-v2/service/ssm v1.72.0 h1:jl+7QcR+PEJVQXK1W5NSXw9EKd+w7Cu4Pwj/WvUIHb0= github.com/aws/aws-sdk-go-v2/service/ssm v1.72.0/go.mod h1:xabzRvdbMs3FG9kU5M6RUOuCW6wXDkpdIqoXXNzA1nQ= +github.com/aws/aws-sdk-go-v2/service/ssm v1.73.0 h1:8AE9z5vMHNC7tQuaje8fSsNZyvj+0ttiQ2Ed/8rLBsc= +github.com/aws/aws-sdk-go-v2/service/ssm v1.73.0/go.mod h1:004bP6yJs8vdEpZwBT3H25GzleBVJYgeT2pPXkU4t4g= github.com/aws/aws-sdk-go-v2/service/sso v1.33.5 h1:jDQARFp1mJ2PEnllQf01nfFXGfWMJ59e0/HCHUTTZCk= github.com/aws/aws-sdk-go-v2/service/sso v1.33.5/go.mod h1:OcT2AhgTuxGAwZk5hgxaNLGpS33W8s8dUQadGVDVY9I= github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.5 h1:8xo1q9ttkYqMJ6vOXX67FPSpVEI7BWKVTKh77g82w+8= @@ -248,6 +263,8 @@ github.com/creack/pty v1.1.21 h1:1/QdRyBaHHJP61QkWMXlOIBfsgdDeeKfK8SYVUWJKf0= github.com/creack/pty v1.1.21/go.mod h1:MOBLtS5ELjhRRrroQr9kyvTxUAFNvYEK993ew/Vr4O4= github.com/cyberark/conjur-api-go v0.15.3 h1:z6KxQzUTLLd7FsFOu3X/xELrELhCW3/S1pW3Zr1i8Kg= github.com/cyberark/conjur-api-go v0.15.3/go.mod h1:IxsTkDhEewa3iU/W7DMaJ6/snX208F4PYVTjzofRjzc= +github.com/cyberark/conjur-api-go v0.15.5 h1:dGf5QDtSmNX8LdIE3x3hGnOg5FdnwM/QTsBb5GtGi5I= +github.com/cyberark/conjur-api-go v0.15.5/go.mod h1:IxsTkDhEewa3iU/W7DMaJ6/snX208F4PYVTjzofRjzc= github.com/cyphar/filepath-securejoin v0.7.0 h1:s0Y3ITPy6sQn5xt54DuYvTF8hu134ooYLUb58DX/HjE= github.com/cyphar/filepath-securejoin v0.7.0/go.mod h1:ymLGms/u3BYaviIiuKFnUx8EkQEZeK6cInNoAPJA3o4= github.com/danieljoos/wincred v1.2.2 h1:774zMFJrqaeYCK2W57BgAem/MLi6mtSE47MB6BOJ0i0= @@ -337,60 +354,99 @@ github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9 github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A= github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI= github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8= +github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= github.com/go-logr/zapr v1.3.0 h1:XGdV8XW8zdwFiwOA2Dryh1gj2KRQyOOoNmBy4EplIcQ= github.com/go-logr/zapr v1.3.0/go.mod h1:YKepepNBd1u/oyhd/yQmtjVXmm9uML4IXUgMOwR8/Gg= github.com/go-openapi/analysis v0.25.2 h1:I0vy4n3alz+DHTiN1PRhCb7QZxkK6g5YmswZKv2TKuw= github.com/go-openapi/analysis v0.25.2/go.mod h1:Uhs1t/2XR10EnwONYILGEzw8gcfGIG5Xk5K2AxnhqDo= +github.com/go-openapi/analysis v0.25.5 h1:xPYEvTb90o1y0epuiOPAoG4QqahjP3cdp5xNlHeKJRI= +github.com/go-openapi/analysis v0.25.5/go.mod h1:d3UGtQC5uq5Kqqqis2VH09Km/v3vwsWrYkbp4gdm+Rc= github.com/go-openapi/errors v0.22.8 h1:oP7sW7TWc3wFFjrzzj0nI83H2qMBkNjNfSd+XRejk/I= github.com/go-openapi/errors v0.22.8/go.mod h1:BuUoHcYrU6E7V9gfj1I5wLQqgtIHnup/alXZ8KdgQ0w= github.com/go-openapi/jsonpointer v0.23.1 h1:1HBACs7XIwR2RcmItfdSFlALhGbe6S92p0ry4d1GWg4= github.com/go-openapi/jsonpointer v0.23.1/go.mod h1:iWRmZTrGn7XwYhtPt/fvdSFj1OfNBngqRT2UG3BxSqY= +github.com/go-openapi/jsonpointer v1.0.0 h1:kR9tHqY0CtZaOPVFm622dPVNhrvYpwr4uCxgL3h1H8s= +github.com/go-openapi/jsonpointer v1.0.0/go.mod h1:Z3rw7dWu1p9IgitXCFamSlA5lmDiklEB6vkaxcNZW5Y= github.com/go-openapi/jsonreference v0.21.6 h1:NZ5nGfnaM1n4I43Xjm1e5/M2GjOwQwndQz22uhxwD+Y= github.com/go-openapi/jsonreference v0.21.6/go.mod h1:xzbgtQ3ZbWxvET3AxdzCJlJt6vkovbf+IfSPJjD0tUY= +github.com/go-openapi/jsonreference v1.0.0 h1:jlmTr6torcd1YgDQvSfNmRtKzYDO4FGBkrAdlAVWnpY= +github.com/go-openapi/jsonreference v1.0.0/go.mod h1:jtwdyGbJk0Xhe5Y+rwtglQP6Sb1WZST4rT32LWB+sv0= github.com/go-openapi/loads v0.24.0 h1:4LLorXRPTzIN9V6ngMUZbAscsBOUBk3Oa8cClu/bFrQ= github.com/go-openapi/loads v0.24.0/go.mod h1:xQMgX+hw5xRAhGrcDXxeMw78IFqUpIzhleu3HqPhyF4= +github.com/go-openapi/loads v0.25.0 h1:74Bc2snfaVlsHzwdQj/3gsA9XJz3daXTJVs+4ZaK7jI= +github.com/go-openapi/loads v0.25.0/go.mod h1:JFBw4SIB9+PTIFHDfcXuSSy5h6aWzjtUCrPYyx3qWU8= github.com/go-openapi/runtime v0.32.4 h1:8ElGj/3goG0itt0nBPP6Cm57ehcYyuHoI3O20nxgvkw= github.com/go-openapi/runtime v0.32.4/go.mod h1:Bz6keOZw1NX4T6f+m42OoT1MBPDt6Re13dbccHyGH/4= +github.com/go-openapi/runtime v0.33.0 h1:Dd3Oj2ig+WH8ckK95l0Wn2V8a4bH/UqWPRZVT0vc8yU= +github.com/go-openapi/runtime v0.33.0/go.mod h1:+rsupH3+TFKqmFysqkmgBOTxpVJV8eV+j9myvvea2Xw= github.com/go-openapi/runtime/server-middleware v0.30.0 h1:8rPoJ/xv7JL8BsovaqboKETlpWBArVh8n+0L/GyePog= github.com/go-openapi/runtime/server-middleware v0.30.0/go.mod h1:OYNT/TxNvB/VK5oe4htM2jDTwlEXuejVJmu0DVZfAMs= github.com/go-openapi/spec v0.22.6 h1:Tyy1pLaNCM8GBCFLoGYLonjJi6zykqyLCjXLc19ZPic= github.com/go-openapi/spec v0.22.6/go.mod h1:HZvTHat+iH0PALQRWhrqIHtU/PEqxqd89fu0MxGlMeM= +github.com/go-openapi/spec v0.22.9 h1:/vKIFDcGKp0ktZWGbym/tJEWbk6/XOEmAVU0kqKMH+w= +github.com/go-openapi/spec v0.22.9/go.mod h1:b/mNUYIOQOyIiUzUzXEE8xzyZqf93KvM9hQGP91yfl0= github.com/go-openapi/strfmt v0.26.3 h1:rzmslHarJgBbf2qfGge+X3htclQfmXqBZMm0Too0HhU= github.com/go-openapi/strfmt v0.26.3/go.mod h1:a5nsUw0oRpQzZeOwx8bi6cKbzFZslpbCKt1LEot+KnQ= +github.com/go-openapi/strfmt v0.27.0 h1:kbcTeaD9TXuXD0hhMXzuYa1sdTo6+dWGvwjW93E80IM= +github.com/go-openapi/strfmt v0.27.0/go.mod h1:s/qhDqfY72irigXUGJmtgid2Rm+3tnz3k8hZaRmvWYc= github.com/go-openapi/swag v0.24.1 h1:DPdYTZKo6AQCRqzwr/kGkxJzHhpKxZ9i/oX0zag+MF8= github.com/go-openapi/swag v0.24.1/go.mod h1:sm8I3lCPlspsBBwUm1t5oZeWZS0s7m/A+Psg0ooRU0A= github.com/go-openapi/swag/cmdutils v0.24.0 h1:KlRCffHwXFI6E5MV9n8o8zBRElpY4uK4yWyAMWETo9I= github.com/go-openapi/swag/cmdutils v0.24.0/go.mod h1:uxib2FAeQMByyHomTlsP8h1TtPd54Msu2ZDU/H5Vuf8= github.com/go-openapi/swag/conv v0.26.1 h1:slr5FVkg9Wc3Y5zcwenD8Sd/PQ94b2I/QJI7N7KTBpg= github.com/go-openapi/swag/conv v0.26.1/go.mod h1:mvQXgPptZk9GTrFgGwWvT4q+dN+zQej9JfmGwnipz1A= +github.com/go-openapi/swag/conv v0.27.3 h1:iqJFmGEjmX3AY0lSszABFqRVqOSt99XS0LzNIMJYuhU= +github.com/go-openapi/swag/conv v0.27.3/go.mod h1:nPRmN6jgNme99hpf+nM0auDZGALWIqlwhisKPK/bQhQ= github.com/go-openapi/swag/fileutils v0.26.1 h1:K1XCM2CGhfNsc6YDt6v7Q5+1e59rftYWdcu/isZhvFw= github.com/go-openapi/swag/fileutils v0.26.1/go.mod h1:mYUgxQAKX4ShS3qvvySx+/9yrlUnDhjiD1CalaQl8lQ= +github.com/go-openapi/swag/fileutils v0.27.3 h1:3UVoZ2RLaIs1lt+2jcKzL8RM3Yk0rmsDE9FLA/HGxFE= +github.com/go-openapi/swag/fileutils v0.27.3/go.mod h1:VvJFZLTZS0AI854gEQz5tk7dBESdLjiNUMSZ/th2ry8= github.com/go-openapi/swag/jsonname v0.26.1 h1:VReupaV6WxlAsCn0e4DUfgV6bPmINnPpyJDLqSfNPcE= github.com/go-openapi/swag/jsonname v0.26.1/go.mod h1:OvdW6BoWoj33pTfi7x9vFrgmT+fk7aw0BRwvCE0YOuc= github.com/go-openapi/swag/jsonutils v0.26.1 h1:2hdBfFkHg+7Wrz2VsCbeyR6hzkRDs7AztnMR2u84yOY= github.com/go-openapi/swag/jsonutils v0.26.1/go.mod h1:U+RMJH3wa+6BRiphuRtIyI8fW9HPFqFQ4sHk2oRx0UQ= +github.com/go-openapi/swag/jsonutils v0.27.3 h1:1DEz+O82frtSMBcos/7XIn1GnpNTbsD4Bru4Dc/uhRc= +github.com/go-openapi/swag/jsonutils v0.27.3/go.mod h1:qiDCoQvzkMxrV3G8FLEdIU5L+EFYc0zcDOHWT3Yofvo= github.com/go-openapi/swag/jsonutils/fixtures_test v0.26.1 h1:1CD7NiLLb/TXl3tOnFYU4b+mNfb5rtgHkaA+q7RMYYQ= github.com/go-openapi/swag/jsonutils/fixtures_test v0.26.1/go.mod h1:ZWafc8nMdYzTE3uYY6W86f0n46+IF0g4uUyRhJw/kXc= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.27.3 h1:h/eT9kmGCDdFLJF29lOhzLtF0FmP1AX2MhLJWVebsb8= github.com/go-openapi/swag/loading v0.26.1 h1:E9K4wqXeROlhjFQ13K9zMz6ojFGXIggGe+ad1odrK9w= github.com/go-openapi/swag/loading v0.26.1/go.mod h1:3qvRIlWzWdq1HvmldwmuJ2ohpcAryN6xVt2OTKd0/7E= +github.com/go-openapi/swag/loading v0.27.3 h1:L9nQkEgzU7QgFQL+pLEMfGUKxeM4pWwGwbET9Z3weW0= +github.com/go-openapi/swag/loading v0.27.3/go.mod h1:rJ0NeaKsF4CVPnMGjPQl7JlSHzvD0bc2DKXLss1hiuE= github.com/go-openapi/swag/mangling v0.26.1 h1:gpYI4WuPKFJJVjV5cDLGlDVJhFIxYjQc7yN5eEb4CqM= github.com/go-openapi/swag/mangling v0.26.1/go.mod h1:POETDH01hqAdASXfw7ISEd9bCOE6xBHOt8NHmGZRmYM= +github.com/go-openapi/swag/mangling v0.27.3 h1:gRzzD1PAUoLTtGMgI3KpBmCSOlTuLTFWnviLxLcTnyg= +github.com/go-openapi/swag/mangling v0.27.3/go.mod h1:jtBE2+V+3pILxOR7Vgce+Cwp6A2PgZbvVqfNntbVs0w= github.com/go-openapi/swag/netutils v0.24.0 h1:Bz02HRjYv8046Ycg/w80q3g9QCWeIqTvlyOjQPDjD8w= github.com/go-openapi/swag/netutils v0.24.0/go.mod h1:WRgiHcYTnx+IqfMCtu0hy9oOaPR0HnPbmArSRN1SkZM= +github.com/go-openapi/swag/pools v0.27.3 h1:gXjImP3F6/56wRRcFgEPld084Y6u2gs21ikPBt8NKBk= +github.com/go-openapi/swag/pools v0.27.3/go.mod h1:kVQefhSK5RWuRe7BXsL8htgBPAMpN7HDGpGEknqugeE= github.com/go-openapi/swag/stringutils v0.26.1 h1:f88uYyTso7TnHrKM/bUBsQ5e2wKf37cpgo6pvbzd9yU= github.com/go-openapi/swag/stringutils v0.26.1/go.mod h1:Sc6d3bU8fgk5AyZR8/8jEQ+Is/Ald+TD/IIggPN8UJk= +github.com/go-openapi/swag/stringutils v0.27.3 h1:Ru28hnbAvN5wycALQYy8IobHvASq+FUFMlp1QzLM0JI= +github.com/go-openapi/swag/stringutils v0.27.3/go.mod h1:lzRN95CxXmA03XcDWHLOb6nOMcxCqR5rGY0lOgsfRoM= github.com/go-openapi/swag/typeutils v0.26.1 h1:yg42FgMzRR6PVQ3M3qHz1s+Y6/P4HoJ3cBarXa3OVnU= github.com/go-openapi/swag/typeutils v0.26.1/go.mod h1:VfnV+oUtSP2vCSCn2aJgnr8OevUYemyIzzS1VOzS10o= +github.com/go-openapi/swag/typeutils v0.27.3 h1:l6SSrx5eR5/WVwrGNzN6bQ9WqL04mrxNBl9YgQ3rcJ4= +github.com/go-openapi/swag/typeutils v0.27.3/go.mod h1:Srm0xFNRZ1Y+vCxJclo5qzx8aj+1pAKda/YfFPrG0dQ= github.com/go-openapi/swag/yamlutils v0.26.1 h1:0TSLK+lXs9vfIhAWzBeI/lOzEnIoot6WTCO1aAeWFTk= github.com/go-openapi/swag/yamlutils v0.26.1/go.mod h1:7W5b7PRX9MxwL7TjeG7H8HkyBGRsIDRObhyMWFgBI2M= +github.com/go-openapi/swag/yamlutils v0.27.3 h1:cRFCAoYtslYn9L9T0xWryHy1t7c1MACC+DMj3CLvwvs= +github.com/go-openapi/swag/yamlutils v0.27.3/go.mod h1:6JYBGj8sw/NawMllyZY+cTA8Mzk2etS3ZBASdcyPsiU= github.com/go-openapi/testify/enable/yaml/v2 v2.5.1 h1:q9NtHwK4qHF7yZziBPvZyv7zWAIk8ok88Gh2mR6Jpc8= github.com/go-openapi/testify/enable/yaml/v2 v2.5.1/go.mod h1:JW0MXIotCYps/XsgJnG3a8Q7rE5xAiBwoOD5OfaIQBk= +github.com/go-openapi/testify/enable/yaml/v2 v2.6.0 h1:gGHwAJ0R/5jU8BEGDbfRNR3hL68dAVi84WuOApp29B0= github.com/go-openapi/testify/v2 v2.5.1 h1:TMdhCaw8fUNraVSf3Omoob1dO/AzBfhtFAPW0an6sBo= github.com/go-openapi/testify/v2 v2.5.1/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw= +github.com/go-openapi/testify/v2 v2.6.0 h1:5PKH2HE7YJ/LuRPQGvSxBRlFXNQhSetBLlGAgUEu3ug= github.com/go-openapi/validate v0.26.0 h1:dxWzQ3F+vb1SajqUxHjwb5T4mTpSHmdrtv5Bi7+ZNhw= github.com/go-openapi/validate v0.26.0/go.mod h1:b4o00uq7fJeJA+wWhVFCJpKTctzeFwzZImGGmHsl2JA= +github.com/go-openapi/validate v0.26.1 h1:pZSbvtRO8G2R2FpWTYRn3w8LrsNwbtaVhP2dWiBa0Us= +github.com/go-openapi/validate v0.26.1/go.mod h1:B8UMgXiQiwwQWIbmuROlwJZDPGlikPuh7iHV1vPX9Oo= github.com/go-playground/assert/v2 v2.0.1/go.mod h1:VDjEfimB/XKnb+ZQfWdccd7VUvScMdVu0Titje2rxJ4= github.com/go-playground/locales v0.13.0/go.mod h1:taPMhCMXrRLJO55olJkUXHZBHCxTMfnGwq/HNwmWNS8= github.com/go-playground/universal-translator v0.17.0/go.mod h1:UkSxE5sNxxRwHyU+Scu5vgOQjsIJAF8j9muTVoKLVtA= @@ -469,6 +525,8 @@ github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/googleapis/enterprise-certificate-proxy v0.3.17 h1:73NfMHdiqo9JFU9+7a5ExpVa10/R29pXfZIaW559nrg= github.com/googleapis/enterprise-certificate-proxy v0.3.17/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k= +github.com/googleapis/enterprise-certificate-proxy v0.3.19 h1:mMOE7DN2+p76/EdIrmAy9B9bH+yC4563vmnJ34QR8i4= +github.com/googleapis/enterprise-certificate-proxy v0.3.19/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k= github.com/googleapis/gax-go/v2 v2.23.0 h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE= github.com/googleapis/gax-go/v2 v2.23.0/go.mod h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg= github.com/gookit/assert v0.1.1 h1:lh3GcawXe/p+cU7ESTZ5Ui3Sm/x8JWpIis4/1aF0mY0= @@ -538,8 +596,12 @@ github.com/hashicorp/vault/api v1.23.0 h1:gXgluBsSECfRWTSW9niY2jwg2e9mMJc4WoHNv4 github.com/hashicorp/vault/api v1.23.0/go.mod h1:zransKiB9ftp+kgY8ydjnvCU7Wk8i9L0DYWpXeMj9ko= github.com/helmfile/chartify v0.28.1 h1:dv7XfWT+OYtqSQ3f4SqXwUk6FyTuS6aH1M3+eF4DkLc= github.com/helmfile/chartify v0.28.1/go.mod h1:LKUELzZ2TaaCAD4EAFbaCkmRXNnt4uWlJts7GBdFVAQ= +github.com/helmfile/chartify v0.28.2 h1:Xi+KOAoPlAP0WraYPcMfJE9HYx9Pf01TRWL5kQFSDeM= +github.com/helmfile/chartify v0.28.2/go.mod h1:ATb9N7qzJMiJG6ZJMSAhDv6X0JEi/2SaBJG8pMksSCg= github.com/helmfile/vals v0.45.0 h1:j5e9enLhBfaiYKKPJWEFAzW0DQJlVXyvnKPWWP3gdJg= github.com/helmfile/vals v0.45.0/go.mod h1:dJ5VGNN0cbusJoAFFINFeimbLV19hhtJJ1328ZFLJzA= +github.com/helmfile/vals v0.46.0 h1:cxXqsKAtk1shtHX3tmmXxjlvAw8lN0l9zaHbbU7JBcw= +github.com/helmfile/vals v0.46.0/go.mod h1:ZRDi8e0oF1snqzaAOQ9AA8n8+pEJmJtc9jSV7LfzDxI= github.com/hinshun/vt10x v0.0.0-20220119200601-820417d04eec h1:qv2VnGeEQHchGaZ/u7lxST/RaJw+cv273q79D81Xbog= github.com/hinshun/vt10x v0.0.0-20220119200601-820417d04eec/go.mod h1:Q48J4R4DvxnHolD5P8pOtXigYlRuPLGl6moFx3ulM68= github.com/hokaccha/go-prettyjson v0.0.0-20211117102719-0474bc63780f h1:7LYC+Yfkj3CTRcShK0KOL/w6iTiKyqqBA9a41Wnggw8= @@ -936,6 +998,8 @@ golang.org/x/net v0.21.0/go.mod h1:bIjVDfnllIU7BJ2DNgfnXvpSvtn8VRwhlsaeUTyUS44= golang.org/x/net v0.25.0/go.mod h1:JkAGAh7GEvH74S6FOH42FLoXpXbE/aqXSrIQjXgsiwM= golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o= golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec= +golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE= +golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU= golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U= golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs= golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q= @@ -1020,6 +1084,8 @@ gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4= gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E= google.golang.org/api v0.288.0 h1:glhO/J88obKP5I269W3hB73dvBKrjU56ZfmNlNXpgTU= google.golang.org/api v0.288.0/go.mod h1:lM2kYRzYUCBY91P9h6VF1PYmvhxii3O5hji37qRvIcY= +google.golang.org/api v0.291.0 h1:wfPbbY+mr9c7wZLqqzrHJLft/q8iFKREd6IgTBUene0= +google.golang.org/api v0.291.0/go.mod h1:at7kwWbuonglBFEBoeMDAV1bguHqL3qf0BHFsv3coa0= google.golang.org/appengine v1.1.0/go.mod h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM= google.golang.org/appengine v1.4.0/go.mod h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4= google.golang.org/genproto v0.0.0-20180817151627-c66870c02cf8/go.mod h1:JiN7NxoALGmiZfu7CAH4rXhgtRTLTxftemlI0sWmxmc= @@ -1030,6 +1096,8 @@ google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 h1: google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7/go.mod h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA= google.golang.org/genproto/googleapis/rpc v0.0.0-20260630182238-925bb5da69e7 h1:eM/YSd5bBFagF51o1E745Ta7RwzpW0h+z+QDNZOgmQ8= google.golang.org/genproto/googleapis/rpc v0.0.0-20260630182238-925bb5da69e7/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260724162435-b2f20204f0df h1:O3ig1i5WDDzsVzRp+cCdgelT9vXnlnOFdlEeFtL4HCc= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260724162435-b2f20204f0df/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= google.golang.org/grpc v1.19.0/go.mod h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c= google.golang.org/grpc v1.23.0/go.mod h1:Y5yQAOtifL1yxbo5wqy6BxZv8vAUGQwXBOALyacEbxg= google.golang.org/grpc v1.25.1/go.mod h1:c3i+UQWmh7LiEpx4sFZnkU36qjEYZ0imhYfXVyQciAY= @@ -1105,5 +1173,7 @@ sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3 h1:u08YRbVUi59ri4YD6cg0UqNM4Dimn0sIl+wldcx5PYw= +sigs.k8s.io/structured-merge-diff/v6 v6.3.3/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/pkg/state/issue_1757_test.go b/pkg/state/issue_1757_test.go index c29dac4f..3789e44c 100644 --- a/pkg/state/issue_1757_test.go +++ b/pkg/state/issue_1757_test.go @@ -1,11 +1,11 @@ package state import ( - "errors" "os" "os/exec" "path/filepath" "runtime" + "strings" "testing" "github.com/helmfile/chartify" @@ -16,91 +16,40 @@ import ( "github.com/helmfile/helmfile/pkg/filesystem" ) -// TestIsChartifyEmptyRenderOutputError verifies that isChartifyEmptyRenderOutputError -// only matches chartify's specific "empty rendered output dir" assertion failure, not -// other, unrelated chartify errors. This is a regression test for issue #1757: a chart -// that renders zero resources (e.g. everything gated behind a falsy `if`) combined with +// TestProcessChartification_EmptyRender is an end-to-end regression test for +// issue #1757: a chart that renders zero resources (e.g. everything gated +// behind a falsy `{{- if .Values.enabled }}`) combined with // transformers/jsonPatches/strategicMergePatches used to crash helmfile with // // assertion failed: unexpected dir entry "" it must be the abs path to the output directory // -// because chartify expects exactly one rendered output directory and found none. -func TestIsChartifyEmptyRenderOutputError(t *testing.T) { - tests := []struct { - name string - err error - expected bool - }{ - { - name: "nil error", - err: nil, - expected: false, - }, - { - name: "chartify empty render assertion error", - err: errors.New(`assertion failed: unexpected dir entry "" it must be the abs path to the output directory`), - expected: true, - }, - { - // Same assertion, but chartOutputDir is a non-empty (merely - // relative) path rather than "" - a different, hypothetical - // chartify bug that happens to trip the same final assertion. - // This must NOT be treated as the empty-render no-op case: - // per review feedback (https://github.com/helmfile/helmfile/pull/2724), - // matching only on the trailing "...it must be the abs path to - // the output directory" phrase (without requiring the `""` - // empty-string dir entry) would have incorrectly matched this - // too, silently masking a genuinely different failure. - name: "same assertion with a non-empty dir entry is not the empty-render case", - err: errors.New(`assertion failed: unexpected dir entry "relative/path" it must be the abs path to the output directory`), - expected: false, - }, - { - name: "unrelated chartify error", - err: errors.New("exec: \"kustomize\": executable file not found in %PATH%"), - expected: false, - }, - { - name: "unrelated multiple-dir-entries assertion", - err: errors.New(`assertion failed: there should be only one dir entry under the helm output dir /tmp/foo`), - expected: false, - }, - { - name: "helm template failure", - err: errors.New("Error: template: mychart/templates/broken.yaml:3:5: executing..."), - expected: false, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - assert.Equal(t, tt.expected, isChartifyEmptyRenderOutputError(tt.err)) - }) - } -} - -// TestProcessChartification_EmptyRenderReturnsSurvivingPath is an end-to-end -// regression test for a bug found in review of the #1757 fix: the empty-render -// no-op path must return the chart's original path, not the temp copy that -// rewriteChartDependencies creates when the chart has relative file:// deps - -// that temp dir is removed by a deferred cleanup as soon as processChartification -// returns, so returning it would hand the caller a path to a directory that no -// longer exists on disk. +// because chartify (<= v0.28.1) expects exactly one rendered output directory +// and aborts when it finds none. The initial fix in helmfile (#2724) worked +// around this by string-matching that assertion error and skipping +// chartification entirely. Chartify v0.28.2 (see +// https://github.com/helmfile/chartify/issues/206 and its fix in +// https://github.com/helmfile/chartify/pull/207) now treats an empty render as +// a no-op success internally - it removes the chart's content dirs, cleans up +// Chart.yaml `dependencies` and the lock file, and skips the kustomize step - +// so the helmfile-side workaround was removed. This test guards the resulting +// direct behavior: processChartification must succeed on an empty render and +// hand back a chartified chart that is still usable by subsequent helm +// commands (`helm dep build`-safe Chart.yaml, empty `helm template` output). // -// This exercises the real processChartification -> chartify.Chartify wiring -// (unlike TestIsChartifyEmptyRenderOutputError above, which only tests the pure -// string-matching helper), so it needs real helm and kustomize binaries on PATH -// and is skipped if either is missing. Verified to pass on Linux; skipped on -// Windows because the file:// dependency URL this test needs (to make -// rewriteChartDependencies actually produce a temp copy) hits an unrelated, -// pre-existing Windows path-handling issue in chartify/helm's dependency -// resolution (a Windows drive letter embedded in a file:// URL gets -// mis-joined onto another path), independent of the fix under test here. -func TestProcessChartification_EmptyRenderReturnsSurvivingPath(t *testing.T) { +// It exercises the real processChartification -> chartify.Chartify wiring, so +// it needs real helm and kustomize binaries on PATH and is skipped if either +// is missing. Verified to pass on Linux; skipped on Windows because the +// file:// dependency URL this test needs (to make rewriteChartDependencies +// actually produce a temp copy) hits an unrelated, pre-existing Windows +// path-handling issue in chartify/helm's dependency resolution (a Windows +// drive letter embedded in a file:// URL gets mis-joined onto another path), +// independent of the code path under test here. +func TestProcessChartification_EmptyRender(t *testing.T) { if runtime.GOOS == "windows" { t.Skip("skipping on Windows: unrelated file:// dependency URL / drive letter handling issue in chartify's helm dependency resolution, not the code path under test; passes on Linux (CI)") } - if _, err := exec.LookPath("helm"); err != nil { + helmBin := "helm" + if _, err := exec.LookPath(helmBin); err != nil { t.Skip("helm not found on PATH, skipping") } if _, err := exec.LookPath("kustomize"); err != nil { @@ -134,8 +83,8 @@ dependencies: `), 0644)) require.NoError(t, os.WriteFile(filepath.Join(chartDir, "values.yaml"), []byte("enabled: false\n"), 0644)) // Every template is gated behind a falsy condition, so helm renders zero - // resources - the exact condition that triggers chartify's empty-output - // assertion. + // resources - the exact condition that used to trigger chartify's + // empty-output assertion. require.NoError(t, os.WriteFile(filepath.Join(chartDir, "templates", "deployment.yaml"), []byte(` {{- if .Values.enabled }} apiVersion: apps/v1 @@ -165,7 +114,7 @@ fieldSpecs: logger: zap.NewNop().Sugar(), fs: filesystem.DefaultFileSystem(), ReleaseSetSpec: ReleaseSetSpec{ - DefaultHelmBinary: "helm", + DefaultHelmBinary: helmBin, DefaultKustomizeBinary: "kustomize", }, } @@ -182,19 +131,36 @@ fieldSpecs: chartification, release, chartDir, ChartPrepareOptions{}, false, "template", ) + // The core #1757 regression: no "assertion failed: unexpected dir entry ..." + // error, chartify (>= v0.28.2) treats the empty render as a no-op. require.NoError(t, err) - assert.True(t, buildDeps, "buildDeps should be true (!skipDeps) for the no-op path") + assert.True(t, buildDeps, "buildDeps should be true (!skipDeps)") - // The returned path must still exist: it must be the original chart - // directory, not the deps-rewritten temp copy that gets deleted by - // rewriteChartDependencies' deferred cleanup on return. + // The returned path is chartify's output dir; it must exist and contain a Chart.yaml. info, statErr := os.Stat(resultPath) require.NoError(t, statErr, "returned chart path %q must still exist after processChartification returns", resultPath) assert.True(t, info.IsDir()) - - // It should specifically be the chart's own directory (or an - // equally-valid, not-yet-cleaned-up path to the same chart), not some - // other temp directory. Chart.yaml must be readable from it. _, err = os.Stat(filepath.Join(resultPath, "Chart.yaml")) assert.NoError(t, err, "Chart.yaml should be reachable from the returned path %q", resultPath) + + // On the empty-render path chartify removes the Chart.yaml `dependencies` + // field (together with charts/ and Chart.lock), so that a subsequent + // `helm dependency build`/`helm template` on the chartified output does not + // fail with "found in Chart.yaml, but missing in charts/ directory". + chartYaml, readErr := os.ReadFile(filepath.Join(resultPath, "Chart.yaml")) + require.NoError(t, readErr) + assert.NotContainsf(t, string(chartYaml), "dependencies:", + "Chart.yaml dependencies field should have been removed after an empty render; got:\n%s", chartYaml) + + // The chartified output must render to (empty) nothing without any further + // preparation, proving it is directly usable by subsequent helm commands. + tmplOut, tmplErr := exec.Command(helmBin, "template", release.Name, resultPath).CombinedOutput() + require.NoErrorf(t, tmplErr, "helm template on chartified output failed: %s", tmplOut) + assert.Empty(t, strings.TrimSpace(string(tmplOut)), "expected empty render, got:\n%s", tmplOut) + + // processChartification tracked the output dir for deferred cleanup; after + // cleanup the dir (and its parent temp dir) must be gone. + st.CleanupChartifyTempDirs() + _, statErr = os.Stat(resultPath) + assert.True(t, os.IsNotExist(statErr), "chartify temp dir %q should have been removed by CleanupChartifyTempDirs", resultPath) } diff --git a/pkg/state/state.go b/pkg/state/state.go index 00557081..1ca72ecf 100644 --- a/pkg/state/state.go +++ b/pkg/state/state.go @@ -1873,11 +1873,6 @@ func (st *HelmState) rewriteChartDependencies(chartPath string) (string, func(), // If exists, it will also patch resources by json patches, strategic-merge patches, and injectors. // processChartification handles the chartification process func (st *HelmState) processChartification(chartification *Chartify, release *ReleaseSpec, chartPath string, opts ChartPrepareOptions, skipDeps bool, helmfileCommand string) (string, bool, error) { - // Preserved so the empty-render no-op path below can return this instead of the - // deps-rewritten temp copy assigned to chartPath further down, which the deferred - // cleanupTempChart() removes as soon as this function returns. - originalChartPath := chartPath - // Rewrite relative file:// dependencies in Chart.yaml to absolute paths before chartify processes them // This prevents errors like "Error: directory /tmp/chartify.../argocd-application not found" // when Chart.yaml contains dependencies like "file://../argocd-application" @@ -1949,21 +1944,6 @@ func (st *HelmState) processChartification(chartification *Chartify, release *Re ) out, err := c.Chartify(release.Name, chartPath, chartify.WithChartifyOpts(chartifyOpts)) - if err != nil && isChartifyEmptyRenderOutputError(err) { - // The chart rendered zero resources (e.g. everything is gated behind a - // `{{- if .Values.enabled }}` that evaluated to false), so chartify has - // nothing to replace templates/charts/crds with and fails its internal - // "there must be exactly one rendered output dir" assertion. Treat this - // as a no-op: use the chart as-is, since there's nothing to chartify. - // See https://github.com/helmfile/helmfile/issues/1757 and the upstream - // tracking issue https://github.com/helmfile/chartify/issues/206. - st.logger.Debugf("release %q: chart rendered no resources, skipping chartification: %v", release.Name, err) - // Return originalChartPath, NOT chartPath: chartPath may have been reassigned - // above to the deps-rewritten temp copy, which the deferred cleanupTempChart() - // removes as soon as this function returns. Since chartify never actually ran, - // relative file:// deps resolve fine from the original location anyway. - return originalChartPath, !skipDeps, nil - } if err != nil { return "", false, err } @@ -1979,34 +1959,6 @@ func (st *HelmState) processChartification(chartification *Chartify, release *Re return chartPath, buildDeps, nil } -// chartifyEmptyRenderOutputErrSubstring is the distinctive part of the error that -// github.com/helmfile/chartify (as of v0.28.0, see replace.go) returns when `helm template` -// renders zero resources for a chart: it expects exactly one directory entry under its -// `--output-dir`, and an empty render leaves that directory empty, so the "must be the abs -// path to the output directory" assertion fails on the resulting empty string. Chartify does -// not expose a typed/sentinel error for this case, so we match on the error text. -// -// The matched string includes the `unexpected dir entry ""` prefix (not just the trailing -// "...it must be the abs path to the output directory" phrase) so this can only match when -// chartify's chartOutputDir was genuinely empty - i.e. the exact empty-render case - and not -// some other, hypothetical failure of the same assertion against a non-empty (but still -// relative) path, which would be a different bug that should still be surfaced as an error. -// -// If this substring ever stops matching a real chartify error, chartify's wording has -// changed and this check needs to be revisited. -// -// Tracked upstream at https://github.com/helmfile/chartify/issues/206 - once chartify -// exposes a sentinel error (or treats an empty render as a no-op itself) and this repo -// bumps to that version, this text match can be retired. -const chartifyEmptyRenderOutputErrSubstring = `unexpected dir entry "" it must be the abs path to the output directory` - -// isChartifyEmptyRenderOutputError reports whether err is chartify's assertion failure caused -// by a chart rendering zero resources, as opposed to some other, unrelated chartify failure -// that should still be surfaced to the user. -func isChartifyEmptyRenderOutputError(err error) bool { - return err != nil && strings.Contains(err.Error(), chartifyEmptyRenderOutputErrSubstring) -} - func (st *HelmState) appendSkipSchemaValidationFlagToChartifyTemplateArgs(templateArgs string, release *ReleaseSpec, skipSchemaValidation bool) string { if !st.shouldSkipSchemaValidation(release, skipSchemaValidation) || hasTemplateArg(templateArgs, "--skip-schema-validation") { return templateArgs