Charts
19 chartsSecurity & supply chain charts
Hardened Helm charts in the security & supply chain category. Each deploys our hardened image pinned by its signed digest, with production defaults.
0 CVE
buildkit
BuildKit, the concurrent container image build engine behind docker build, as the rootless variant: buildkitd runs under rootlesskit as uid 1001 on…
chart v0.0.5 · app v0.33.1
Security & supply chainstandardApache-2.00 CVE
clamav
ClamAV antivirus engine built from the release tarball. clamd scans streams over TCP 3310 for apps that check uploads, freshclam keeps the signature…
chart v0.0.2 · app v1.5.4
Security & supply chainstandardGPL-2.00 CVE
connaisseur
Connaisseur, the Kubernetes admission controller that verifies container image signatures (Cosign/Sigstore, Notary v1 and v2) against trust roots…
chart v0.0.2 · app v3.13.0
Security & supply chainstandardApache-2.00 CVE
dependency-track
OWASP Dependency-Track API server, the SBOM analysis platform that tracks components across projects and flags known vulnerabilities, outdated and…
chart v0.0.8 · app v5.1.2
Security & supply chainstandardApache-2.00 CVE
external-secrets
External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into…
chart v · app v2.11.0
Security & supply chainstandardApache-2.00 CVE
fulcio
Fulcio, the Sigstore certificate authority: it issues short-lived code-signing certificates bound to OIDC identities, for keyless signing with…
chart v · app v1.8.8
Security & supply chainstandardApache-2.00 CVE
kyverno
Kubernetes-native policy engine for validating, mutating, and generating resources with no new language. Ships the controllers and CLI as static Go…
chart v · app v1.19.1
Security & supply chainstandardApache-2.00 CVE
opa
Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control,…
chart v · app v1.21.1
Security & supply chainstandardApache-2.00 CVE
opa-gatekeeper
OPA Gatekeeper, the Kubernetes admission controller for Rego policies (ConstraintTemplates and Constraints, validating and mutating webhooks, audit…
chart v · app v3.23.1
Security & supply chainstandardApache-2.00 CVE
polaris
Fairwinds Polaris, the Kubernetes configuration validator. Audits running workloads or YAML files against best-practice checks (security contexts,…
chart v · app v10.2.5
Security & supply chainstandardApache-2.00 CVE
policy-reporter
Policy Reporter, Kyverno's PolicyReport aggregator. Watches PolicyReport results from Kyverno and other engines, serves them over a REST API and…
chart v · app v3.10.0
Security & supply chainstandardMIT0 CVE
rekor-tiles
Rekor v2, the Sigstore transparency log, rebuilt on Trillian Tessera tiles: it needs no Trillian or MySQL. Built from source with the POSIX storage…
chart v · app v2.3.0
Security & supply chainstandardApache-2.0