threat_intelligence1856 wordsRead on Huntaegis

Securing the Kubernetes Supply Chain: Introducing WizOS Helm Charts

Securing the Kubernetes Supply Chain: Introducing WizOS Helm Charts Secure your Kubernetes supply chain with WizOS Helm Charts. Eliminate hidden CI/CD risks and unmaintained dependencies with hardened, signed, and CVE-scanned charts for seamless Kubernetes deployment. Kubernetes changed how teams ship software. Applications now run anywhere, scale on demand, and roll out many times a day, and Helm made that speed even more accessible. Charts package an application with everything it needs to run, so installs are repeatable, versions are tracked, and upgrades or rollbacks take one command. Instead of writing every Kubernetes manifest by hand, you install an ingress controller, a monitoring stack, or a database with a single helm install, often from one of the thousands of community charts on Artifact Hub that someone else maintains. But every one of those installs runs on trust. Helm expands the software supply chain Every chart you install brings its maintainers' decisions with it, including what their projects depend on, how they build and publish releases, and who can change their code. Those decisions sit outside your repositories and your pipelines, which is exactly where traditional supply chain security tools stop looking. Software composition analysis checks your source code and dependency manifests, like go.mod, package.json, and requirements.txt, for vulnerable open source packages. Container image scanning checks the images you build for vulnerable operating system packages and libraries. SBOMs give you a record of what's inside what you ship. Those controls cover the code you own, but a community Helm chart adds gaps they weren't built to cover. You deploy images you never built. A chart pulls images from someone else's registry. Those images never pass through your repositories, so SCA on your source code never sees them. Some risks don't have a CVE. Image scanning looks for known vulnerabilities. It won't tell you that an upstream dependency points to an account anyone can register, or that a maintainer's CI workflow runs code from strangers with access to release credentials. Tags can move. Charts often reference image tags rather than fixed digests, so the image you reviewed last month might not be the image you pull today. Put together, you can do everything right in your own code and still run software whose supply chain you've never had a chance to examine. Introducing secured Helm charts for WizOS Those additional blind spots are why we built secured Helm charts for WizOS. Each chart is ready to deploy, and Wiz maintains it to the same hardening and remediation standards as the WizOS base images your teams already build on. To see how big that gap is in practice, Wiz Research looked at the charts teams use most. What Wiz Research found behind 1,500 popular Helm charts Wiz Research examined the source repositories and build pipelines behind 1,500 of the most popular Helm charts on Artifact Hub. Many charts share a source repository, so those charts map to 814 unique repositories on GitHub. The goal wasn't to review the charts themselves. It was to look one layer down, at the projects that produce the images each chart deploys. 61 source repositories (7.5%) had at least one confirmed supply chain risk 9 findings were rated critical or high severity 20 charts had weaknesses in their CI/CD workflows 25 charts depended on upstream projects that are unmaintained or archived Two patterns stood out: Build pipelines that trust outside contributors too much. In some projects, opening a pull request, or even leaving a comment, is enough to run an outsider's code inside the project's CI workflow, with access to the project's secrets. When a pull request triggers it, security researchers call this pattern a PWN Request. An attacker who exploits it could steal credentials and use them to change the project or ship a tampered release. Dependencies that nobody owns. Some projects pull code from accounts or namespaces that don't exist. Anyone could register that name, publish malicious code under it, and have that code included in the project's builds. In both cases, the chart itself looks clean. The risk sits in the project behind it, where a team installing the chart has no easy way to see it. Two findings, both now fixed, show what each pattern looks like in practice. A closer look at KubeView KubeView is a popular open source tool that draws a live map of the resources in a Kubernetes cluster. One developer maintains it, teams install it through a Helm chart, and it needs visibility across the cluster to do its job. Wiz Research found that KubeView's go.mod file referenced a Go module hosted under a GitHub username that didn't exist. An attacker could have registered that username, published a malicious version of the module, and had it pulled into KubeView builds. Teams that installed or upgraded the chart after that could have deployed the attacker's code into their clusters. Wiz Research reported the issue, and the maintainer removed the dependency in version 2.2.1 within days. A closer look at Meilisearch Meilisearch is an open source search engine, and its official Helm chart lives in the meilisearch-kubernetes repository on GitHub. That repository had a GitHub Actions workflow that ran when someone commented on an issue or pull request. The workflow checked out code from the commenter's fork using a bot token that could push to the repository, and it placed the fork's branch name directly into a shell command, a flaw known as “script injection.” The workflow also skipped author association checks, which GitHub uses to tell maintainers apart from outsiders. That meant anyone on GitHub could have used a crafted branch name, or code in their own fork, to run commands with push access to the repository where the chart is maintained. After our disclosure, Meilisearch quickly patched the workflow, adding maintainer-only authorization, preventing credential persistence, and sanitizing the branch name input. Two findings stood out. KubeView had a hijackable Go dependency, because the GitHub username in its go.mod didn't exist. Anyone who registered it could have owned every build. Meilisearch had a workflow where any GitHub user could comment on a pull request and run code with a privileged bot token. Both maintainers fixed the issues within days. CI/CD misconfigurations are a leading vulnerability class across Helm charts. Shay Berkovich, Wiz Research How WizOS Helm charts help you avoid this risk WizOS Helm charts change where your trust sits. Instead of inheriting every decision an upstream project makes, you deploy software that Wiz builds, tests, and signs. Wiz rebuilds every chart in its own pipeline, so a compromised upstream workflow like the one in Meilisearch has no path into what you deploy. Minimal and hardened by default. WizOS strips out what applications don't need, runs them without root privileges by default, and keeps CVEs near zero. Patched on a schedule you can count on. Once a stable upstream patch exists, Wiz fixes critical CVEs within 7 days and high and medium CVEs within 14 days, backed by an SLA. Ready for compliance. Wiz signs every image and ships it with provenance and an SBOM, so you can verify where it came from and what's inside. Find the charts worth swapping first Knowing WizOS Helm charts exist is one step. Knowing which charts in your clusters to replace first is another. That's the job of the Secure Architecture Opportunities page in Wiz. Secure Architecture Opportunities looks across the container images in your environment and shows where a WizOS alternative is available. It groups opportunities by technology or project, ranks them by how much risk each swap removes, and estimates the effort involved. A summary at the top shows how many swaps it would take to eliminate your critical and high vulnerabilities, so you can see the size of the job before you start. WizOS Helm charts show up on the same page. For charts already in your clusters, Wiz shows which images each chart pulled and the risk they carry, then points to the matching WizOS chart. Instead of auditing charts one at a time, your team starts with the swaps that remove the most risk. Because the list comes from the images Wiz sees in your environment, it reflects what you actually run. Helm charts and base images, working together WizOS base images and Helm charts cover the two halves of what runs in your clusters. Base images cover the applications you build yourself. Your Dockerfile starts from a WizOS base or language image, and your teams add their code on top. Helm charts cover the software you install rather than build, like ingress controllers, observability stacks, and secrets management. Used together, both come from one hardened, signed catalog with one set of remediation commitments. Your teams pull everything from the same registry with the same credentials, and your security team gets one consistent standard across the software you write and the software you adopt. The WizOS catalog keeps expanding Helm charts join a steady stream of hardened images that teams rely on every day. Recent additions span five areas: Delivery and GitOps. Argo Rollouts for canary and blue/green deployments, with a FIPS variant. Sealed Secrets for storing encrypted secrets safely in git. KEDA for scaling workloads based on events, including scaling to zero. Observability. Grafana Loki and Alloy for a hardened log and telemetry pipeline, with anonymous usage reporting turned off by default. Redis Exporter for Redis and Valkey metrics in Prometheus. Signing and compliance. Cosign for signing and verifying images and artifacts, including keyless signing. OpenSCAP for compliance scanning, bundled with the DISA general purpose operating system baseline. Data. Valkey Bundle with search, JSON, Bloom, and LDAP modules built in. Redis Operator for managing Redis topologies through Kubernetes resources. Access and automation. OpenSSH Server for bastion hosts and SFTP endpoints. Ansible for a hardened control node with major cloud collections included. You can explore the full list in the Secured Image Catalog in the Wiz portal. Build fast, and know what you deploy Helm charts are one of the fastest ways to get software running on Kubernetes, and that speed depends on trusting everything behind them. Wiz Research found confirmed supply chain issues in about one in 13 of the source repositories behind the most popular charts, in places that standard scanning isn't built to reach. WizOS Helm charts let your teams keep the speed of a single helm install, with charts that Wiz maintains to the same standards as the rest of the WizOS catalog. See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling Wiz Research analyzes NordStellar data to map the credentials targeted by infostealer families and assess their potential impact across cloud, code, and AI environments. Get a personalized demo Ready to see Wiz in action? "Best User Experience I have ever seen, provides full visibility to cloud workloads." David EstlickCISO "Wiz provides a single pane of glass to see what is going on in our cloud environments." Adam FletcherChief Security Officer "We know that if Wiz identifies something as critical, it actually is." Greg PoniatowskiHead of Threat and Vulnerability Management

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.