Context
Jira: HELM-832
We need to do a final re-release of Helm 3.13 for OCP Tools 4.12 to address outstanding CVEs. The release-3.13 branch already has the initial FIPS enablement commit (e3cc3f0 — TAGS=no_openssl + GODEBUG=fips140=auto env var on build-cross), but it is missing the two follow-up refinements that landed on release-3.21.
Changes needed on release-3.13
1. Move fips140=auto from Makefile env var to go.mod godebug directive
Add to go.mod:
This embeds the FIPS auto-mode directive into the binary itself (not just at build time), matching the approach in commit d9ead43 on release-3.21.
Remove the now-redundant GODEBUG=fips140=auto env var from the build-cross target in Makefile.
2. Add GOFIPS140=certified to Makefile build targets
Add the GOFIPS140 variable and prepend it to build commands, matching commit 1cc9984 on release-3.21:
Prepend GOFIPS140=$(GOFIPS140) to both build and build-cross targets so the certified FIPS 140 crypto module is selected at build time.
3. (Optional) Replace gox with individual go build in build-cross
release-3.13 still uses gox for cross-compilation while release-3.21 switched to individual go build commands per architecture. Consider adapting this as well for consistency, though not strictly required for FIPS compliance.
4. Update Go dependencies for CVE fixes
Update go.mod dependencies cited in the CVEs with fixed versions, retaining the current go directive version and Kubernetes API version.
Reference commits on release-3.21
9f8ec87 — Initial FIPS enablement (already adapted in e3cc3f0 on release-3.13)
d9ead43 — Move fips140=auto to go.mod godebug directive
1cc9984 — Add GOFIPS140=certified to Makefile
Acceptance criteria
Context
Jira: HELM-832
We need to do a final re-release of Helm 3.13 for OCP Tools 4.12 to address outstanding CVEs. The
release-3.13branch already has the initial FIPS enablement commit (e3cc3f0—TAGS=no_openssl+GODEBUG=fips140=autoenv var on build-cross), but it is missing the two follow-up refinements that landed onrelease-3.21.Changes needed on
release-3.131. Move
fips140=autofrom Makefile env var togo.modgodebug directiveAdd to
go.mod:This embeds the FIPS auto-mode directive into the binary itself (not just at build time), matching the approach in commit
d9ead43onrelease-3.21.Remove the now-redundant
GODEBUG=fips140=autoenv var from thebuild-crosstarget inMakefile.2. Add
GOFIPS140=certifiedto Makefile build targetsAdd the
GOFIPS140variable and prepend it to build commands, matching commit1cc9984onrelease-3.21:GOFIPS140 ?= certifiedPrepend
GOFIPS140=$(GOFIPS140)to bothbuildandbuild-crosstargets so the certified FIPS 140 crypto module is selected at build time.3. (Optional) Replace gox with individual
go buildin build-crossrelease-3.13still uses gox for cross-compilation whilerelease-3.21switched to individualgo buildcommands per architecture. Consider adapting this as well for consistency, though not strictly required for FIPS compliance.4. Update Go dependencies for CVE fixes
Update
go.moddependencies cited in the CVEs with fixed versions, retaining the currentgodirective version and Kubernetes API version.Reference commits on
release-3.219f8ec87— Initial FIPS enablement (already adapted ine3cc3f0on release-3.13)d9ead43— Move fips140=auto to go.mod godebug directive1cc9984— Add GOFIPS140=certified to MakefileAcceptance criteria
go.modcontainsgodebug fips140=autoGODEBUG=fips140=autoas env varGOFIPS140=certifiedon build targetshelm versionoutput is valid SemVer