Cybersecurity Research

Why Popular Helm Charts Could Be a Hidden Supply Chain Risk

Wiz Research · 1 Oct 2026
Key Takeaway Businesses using Kubernetes should treat third-party Helm charts as an extension of their supply chain and verify image sources, pinned versions, and maintainer practices, not just scan their own code.

Helm charts have made deploying complex applications on Kubernetes fast and simple, letting businesses install tools like databases or monitoring stacks with a single command using community-maintained packages. However, Wiz Research highlights that this convenience comes with hidden trust issues: each chart brings along its maintainers' decisions about dependencies, build processes, and code access, none of which are visible to the business installing it.

Traditional security tools were not built to catch these problems. Software composition analysis checks your own code for vulnerable dependencies, and image scanning looks for known vulnerabilities in container images, but neither can see images pulled from external registries, nor can they flag risks without a formal vulnerability record, such as an unclaimed dependency account or an insecure maintainer build process. Compounding this, charts often reference image tags rather than fixed versions, meaning the software you approved last month may not be what actually gets deployed today.

To address this, Wiz has introduced secured Helm charts for its WizOS platform, maintained to the same hardening standards as its base container images. Wiz Research examined some of the most widely used community charts to illustrate the scale of this supply chain blind spot.

Kubernetes Supply Chain Security Helm Charts
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from Wiz Research. We link back to every original so you can read it yourself.