PageSourceSearch

https://helm.sh/assets/js/904077d6.a21929ae.js

js helm.sh collected 2026-09-24 07:25:34 UTC 4,509 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkhelm_www=self.webpackChunkhelm_www||[]).push([["1409"],{6960(e,t,i){i.r(t),i.d(t,{assets:()=>l,contentTitle:()=>n,default:()=>m,frontMatter:()=>r,metadata:()=>a,toc:()=>h});var a=i(45282),s=i(74848),o=i(28453);let r={title:"Helm 2nd Security Audit",slug:"helm-2nd-security-audit",authors:["mattfarina"],date:"2021-03-05"},n,l={authorsImageUrls:[void 0]},h=[];function c(e){let t={a:"a",img:"img",p:"p",...(0,o.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(t.p,{children:["Helm has now completed a second security audit, funded by the ",(0,s.jsx)(t.a,{href:"https://cncf.io",children:"CNCF"}),". The ",(0,s.jsx)(t.a,{href:"https://helm.sh/blog/2019-11-04-helm-security-audit-results/",children:"first audit"})," focused on the source code for the Helm client along with the process Helm uses to handle security. The second audit, performed by ",(0,s.jsx)(t.a,{href:"https://www.trailofbits.com/",children:"Trail of Bits"}),", looked at the source code for the Helm client along with a threat model for the use of Helm."]}),"\n",(0,s.jsxs)(t.p,{children:["The following diagram is from the ",(0,s.jsx)(t.a,{href:"https://github.com/helm/community/blob/main/security-audit/Helm%20Threat%20Model%202020.pdf",children:"threat model"})," and looks at the connections Helm makes along with how it stores files on the local filesystem."]}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.img,{alt:"Thread model diagram",src:i(79868).A+"",width:"1792",height:"1336"})}),"\n",(0,s.jsxs)(t.p,{children:["As a result of the audit, the Helm security team worked on ",(0,s.jsx)(t.a,{href:"https://github.com/helm/helm/releases/tag/v3.3.2",children:"a release"}),"."]}),"\n",(0,s.jsx)(t.p,{children:"We want to thank the CNCF for providing these security assessments. They provide an expert and outside look at projects, like Helm, so that we can have more security cloud native tooling. We also want to thank Trail of Bits for the assessment. It was a pleasure working with them."}),"\n",(0,s.jsxs)(t.p,{children:["You can get the full reports for the ",(0,s.jsx)(t.a,{href:"https://github.com/helm/community/blob/main/security-audit/Helm%20Threat%20Model%202020.pdf",children:"threat model"})," and ",(0,s.jsx)(t.a,{href:"https://github.com/helm/community/blob/main/security-audit/Helm%20Final%20Report%202020.pdf",children:"security assessment"})," in the ",(0,s.jsx)(t.a,{href:"https://github.com/helm/community/tree/main/security-audit",children:"Helm community repository"}),"."]})]})}function m(e={}){let{wrapper:t}={...(0,o.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(c,{...e})}):c(e)}},79868(e,t,i){i.d(t,{A:()=>a});let a=i.p+"assets/images/arch-90389951764c1bc21bd4a98f902b9c77.png"},28453(e,t,i){i.d(t,{R:()=>r,x:()=>n});var a=i(96540);let s={},o=a.createContext(s);function r(e){let t=a.useContext(o);return a.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function n(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),a.createElement(o.Provider,{value:t},e.children)}},45282(e){e.exports=JSON.parse('{"permalink":"/blog/helm-2nd-security-audit","editUrl":"https://github.com/helm/helm-www/blob/main/blog/2021-03-05-second-security-audit/index.md","source":"@site/blog/2021-03-05-second-security-audit/index.md","title":"Helm 2nd Security Audit","description":"Helm has now completed a second security audit, funded by the CNCF. The first audit focused on the source code for the Helm client along with the process Helm uses to handle security. The second audit, performed by Trail of Bits, looked at the source code for the Helm client along with a threat model for the use of Helm.","date":"2021-03-05T00:00:00.000Z","tags":[],"readingTime":1.2,"hasTruncateMarker":true,"authors":[{"name":"Matt Farina","page":{"permalink":"/blog/authors/mattfarina"},"socials":{"github":"https://github.com/mattfarina","linkedin":"https://www.linkedin.com/in/matthewfarina/","website":"https://mattfarina.com/"},"imageURL":"https://github.com/mattfarina.png","key":"mattfarina"}],"frontMatter":{"title":"Helm 2nd Security Audit","slug":"helm-2nd-security-audit","authors":["mattfarina"],"date":"2021-03-05"},"unlisted":false,"prevItem":{"title":"Martin Hickey Joins Helm Org Maintainers","permalink":"/blog/welcome-martin-hickey"},"nextItem":{"title":"Helm 2 and the Charts Project Are Now Unsupported","permalink":"/blog/helm-2-becomes-unsupported"}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.