Why Popular Helm Charts Could Be a Hidden Supply Chain Risk
Helm charts have made deploying complex applications on Kubernetes fast and simple, letting businesses install tools like databases or monitoring stacks with a single command using community-maintained packages. However, Wiz Research highlights that this convenience comes with hidden trust issues: each chart brings along its maintainers' decisions about dependencies, build processes, and code access, none of which are visible to the business installing it.
Traditional security tools were not built to catch these problems. Software composition analysis checks your own code for vulnerable dependencies, and image scanning looks for known vulnerabilities in container images, but neither can see images pulled from external registries, nor can they flag risks without a formal vulnerability record, such as an unclaimed dependency account or an insecure maintainer build process. Compounding this, charts often reference image tags rather than fixed versions, meaning the software you approved last month may not be what actually gets deployed today.
To address this, Wiz has introduced secured Helm charts for its WizOS platform, maintained to the same hardening standards as its base container images. Wiz Research examined some of the most widely used community charts to illustrate the scale of this supply chain blind spot.