Wiz Finds Supply-Chain Risks in Projects Behind Popular Helm Charts

· Original article ↗

Summary

Wiz Research found confirmed supply-chain risks in 61 of 814 GitHub repositories behind 1,500 popular Helm charts, including hijackable dependencies and vulnerable CI workflows. The two detailed issues were fixed after disclosure.

Key points

  • Wiz examined the source repositories and build pipelines behind 1,500 popular Artifact Hub charts, mapping them to 814 unique GitHub repositories.
  • 61 repositories (7.5%) had at least one confirmed supply-chain risk; nine findings were rated critical or high.
  • Wiz identified CI/CD weaknesses in 20 charts and unmaintained or archived upstream dependencies in 25.
  • KubeView referenced a Go module under a nonexistent GitHub username, creating a risk that an attacker could register the account and inject code into builds. The dependency was removed in version 2.2.1.
  • Meilisearch’s GitHub Actions workflow let outside contributors run injected commands with a privileged bot token; the project patched the workflow after disclosure.
  • Wiz announced secured Helm charts for WizOS, which it says it rebuilds, tests, signs, and maintains in its own pipeline.

Article Details

Event Type
Software supply chain research findings and secured Helm chart launch
Impact
Wiz Research found at least one confirmed supply chain risk in 61 of 814 repositories behind 1,500 popular Helm charts; nine findings were rated critical or high. The risks could have allowed malicious code into builds or exposed release credentials. The cited KubeView and Meilisearch issues were fixed after disclosure.

Vendors

Products

Related Articles