apiVersion: "helm-expt.confighub.com/v1alpha1"
kind: "LatestCandidateReplacementDecisions"
metadata:
  name: "latest-top20-refresh-replacement-decisions"
  generatedBy: "scripts/generate-latest-candidate-replacement-decisions.mjs"
spec:
  claim: "retained proof-complete update candidates are visible for review, but do not replace supported catalog versions until a target-scoped replacement decision is written"
  rows:
    -
      chart: "argo-cd/argo-cd"
      currentVersion: "9.5.15"
      candidateVersion: "9.5.17"
      latestUpstreamVersion: "9.5.17"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "default"
      candidatePrimaryBase: "default"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/argo-cd-argo-cd-9.5.17.yaml"
      replacementDecisionSummary: "Keep argo-cd/argo-cd@9.5.15 as the supported public catalog version for now; retain argo-cd/argo-cd@9.5.17 as a proof-complete candidate."
      decisionTopics:
        - "CRD lifecycle and upgrade policy"
        - "cluster RBAC review"
        - "extension slot provenance and scan policy"
        - "generated fact ownership"
        - "hook and lifecycle phase policy"
        - "scan/gate warning disposition"
        - "storage backup restore and rollback policy"
      evidence:
        currentSupportDecision: "data/production-support-decisions/argo-cd-argo-cd/support-decision.yaml"
        candidateRecipe: "recipes/argo-cd/argo-cd/9.5.17"
        candidatePackage: "packages/argo-cd/argo-cd/9.5.17"
        configHubProofReceipt: "runs/latest-top20-refresh/argo-cd-9.5.17/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/argo-cd-9.5.17/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/argo-cd-9.5.17/live-parity/default/receipt.yaml"
      nextAction: "replacement decision defers argo-cd/argo-cd@9.5.17; keep 9.5.15 pinned and revisit after the recorded requirements are satisfied"
    -
      chart: "bitnami/mongodb"
      currentVersion: "19.0.7"
      candidateVersion: "19.1.0"
      latestUpstreamVersion: "19.1.0"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "static-passwords"
      candidatePrimaryBase: "static-passwords"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/bitnami-mongodb-19.1.0.yaml"
      replacementDecisionSummary: "Keep bitnami/mongodb@19.0.7 as the supported public catalog version for now; retain bitnami/mongodb@19.1.0 as a proof-complete candidate."
      decisionTopics:
        - "extension slot provenance and scan policy"
        - "generated fact ownership"
        - "hook and lifecycle phase policy"
        - "image digest support decision"
        - "scan/gate warning disposition"
        - "storage backup restore and rollback policy"
        - "target fact preflight"
      evidence:
        currentSupportDecision: "data/production-support-decisions/bitnami-mongodb/support-decision.yaml"
        candidateRecipe: "recipes/bitnami/mongodb/19.1.0"
        candidatePackage: "packages/bitnami/mongodb/19.1.0"
        configHubProofReceipt: "runs/latest-top20-refresh/mongodb-19.1.0/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/mongodb-19.1.0/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/mongodb-19.1.0/live-parity/static-passwords/receipt.yaml"
      nextAction: "replacement decision defers bitnami/mongodb@19.1.0; keep 19.0.7 pinned and revisit after the recorded requirements are satisfied"
    -
      chart: "bitnami/nginx"
      currentVersion: "24.0.2"
      candidateVersion: "25.0.0"
      latestUpstreamVersion: "25.0.0"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "http-clusterip"
      candidatePrimaryBase: "http-clusterip"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/bitnami-nginx-25.0.0.yaml"
      replacementDecisionSummary: "Keep bitnami/nginx@24.0.2 as the supported public catalog version for now; retain bitnami/nginx@25.0.0 as a proof-complete candidate."
      decisionTopics:
        - "extension slot provenance and scan policy"
        - "generated fact ownership"
        - "ingress and edge exposure policy"
        - "scan/gate warning disposition"
        - "target fact preflight"
      evidence:
        currentSupportDecision: "data/production-support-decisions/bitnami-nginx/support-decision.yaml"
        candidateRecipe: "recipes/bitnami/nginx/25.0.0"
        candidatePackage: "packages/bitnami/nginx/25.0.0"
        configHubProofReceipt: "runs/latest-top20-refresh/nginx-25.0.0/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/nginx-25.0.0/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/nginx-25.0.0/live-parity/http-clusterip/receipt.yaml"
      nextAction: "replacement decision defers bitnami/nginx@25.0.0; keep 24.0.2 pinned and revisit after the recorded requirements are satisfied"
    -
      chart: "bitnami/postgresql"
      currentVersion: "18.6.7"
      candidateVersion: "18.7.0"
      latestUpstreamVersion: "18.7.0"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "static-passwords"
      candidatePrimaryBase: "static-passwords"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/bitnami-postgresql-18.7.0.yaml"
      replacementDecisionSummary: "Keep bitnami/postgresql@18.6.7 as the supported public catalog version for now; retain bitnami/postgresql@18.7.0 as a proof-complete candidate."
      decisionTopics:
        - "extension slot provenance and scan policy"
        - "generated fact ownership"
        - "hook and lifecycle phase policy"
        - "image digest support decision"
        - "scan/gate warning disposition"
        - "storage backup restore and rollback policy"
        - "target fact preflight"
      evidence:
        currentSupportDecision: "data/production-support-decisions/bitnami-postgresql/support-decision.yaml"
        candidateRecipe: "recipes/bitnami/postgresql/18.7.0"
        candidatePackage: "packages/bitnami/postgresql/18.7.0"
        configHubProofReceipt: "runs/latest-top20-refresh/postgresql-18.7.0/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/postgresql-18.7.0/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/postgresql-18.7.0/live-parity/static-passwords/receipt.yaml"
      nextAction: "replacement decision defers bitnami/postgresql@18.7.0; keep 18.6.7 pinned and revisit after the recorded requirements are satisfied"
    -
      chart: "bitnami/redis"
      currentVersion: "25.5.3"
      candidateVersion: "27.0.0"
      latestUpstreamVersion: "27.0.0"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "default"
      candidatePrimaryBase: "default"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/bitnami-redis-27.0.0.yaml"
      replacementDecisionSummary: "Keep bitnami/redis@25.5.3 as the supported public catalog version for now; retain bitnami/redis@27.0.0 as a proof-complete candidate."
      decisionTopics:
        - "generated fact ownership"
        - "hook and lifecycle phase policy"
        - "image digest support decision"
        - "scan/gate warning disposition"
        - "target fact preflight"
      evidence:
        currentSupportDecision: "data/production-support-decisions/bitnami-redis/support-decision.yaml"
        candidateRecipe: "recipes/bitnami/redis/27.0.0"
        candidatePackage: "packages/bitnami/redis/27.0.0"
        configHubProofReceipt: "runs/latest-top20-refresh/redis-27.0.0/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/redis-27.0.0/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/redis-27.0.0/live-parity/default/receipt.yaml"
      nextAction: "replacement decision defers bitnami/redis@27.0.0; keep 25.5.3 pinned and revisit after the recorded requirements are satisfied"
    -
      chart: "prometheus-community/kube-prometheus-stack"
      currentVersion: "85.3.3"
      candidateVersion: "86.1.0"
      latestUpstreamVersion: "86.1.0"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "default"
      candidatePrimaryBase: "default"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/prometheus-community-kube-prometheus-stack-86.1.0.yaml"
      replacementDecisionSummary: "Keep prometheus-community/kube-prometheus-stack@85.3.3 as the supported public catalog version for now; retain prometheus-community/kube-prometheus-stack@86.1.0 as a proof-complete candidate."
      decisionTopics:
        - "CRD lifecycle and upgrade policy"
        - "cluster RBAC review"
        - "extension slot provenance and scan policy"
        - "generated fact ownership"
        - "scan/gate warning disposition"
        - "webhook readiness and failure policy"
      evidence:
        currentSupportDecision: "data/production-support-decisions/prometheus-community-kube-prometheus-stack/support-decision.yaml"
        candidateRecipe: "recipes/prometheus-community/kube-prometheus-stack/86.1.0"
        candidatePackage: "packages/prometheus-community/kube-prometheus-stack/86.1.0"
        configHubProofReceipt: "runs/latest-top20-refresh/kube-prometheus-stack-86.1.0/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/kube-prometheus-stack-86.1.0/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/kube-prometheus-stack-86.1.0/live-parity/default/receipt.yaml"
      nextAction: "replacement decision defers prometheus-community/kube-prometheus-stack@86.1.0; keep 85.3.3 pinned and revisit after the recorded requirements are satisfied"
    -
      chart: "prometheus-community/prometheus"
      currentVersion: "29.8.0"
      candidateVersion: "29.9.0"
      latestUpstreamVersion: "29.9.0"
      candidateFreshness: "latest-upstream-aligned"
      currentSupportedBase: "server-only-ephemeral"
      candidatePrimaryBase: "server-only-ephemeral"
      candidateCatalogStatus: "catalog-candidate"
      candidateProofStatus: "proof-complete-root-path-present"
      replacementDecision: "defer-replacement"
      replacementDecisionArtifact: "data/latest-top20-refresh/replacement-decisions/decision-artifacts/prometheus-community-prometheus-29.9.0.yaml"
      replacementDecisionSummary: "Keep prometheus-community/prometheus@29.8.0 as the supported public catalog version for now; retain prometheus-community/prometheus@29.9.0 as a proof-complete server-only candidate."
      decisionTopics:
        - "cluster RBAC review"
        - "extension slot provenance and scan policy"
        - "scan/gate warning disposition"
        - "storage backup restore and rollback policy"
      evidence:
        currentSupportDecision: "data/production-support-decisions/prometheus-community-prometheus/support-decision.yaml"
        candidateRecipe: "recipes/prometheus-community/prometheus/29.9.0"
        candidatePackage: "packages/prometheus-community/prometheus/29.9.0"
        configHubProofReceipt: "runs/latest-top20-refresh/prometheus-29.9.0/confighub-proof/latest/confighub-proof-receipt.yaml"
        localLiveReceipt: "runs/latest-top20-refresh/prometheus-29.9.0/local-kind/observation-receipt.json"
        liveParityReceipt: "runs/latest-top20-refresh/prometheus-29.9.0/live-parity/server-only-ephemeral/receipt.yaml"
      nextAction: "replacement decision defers prometheus-community/prometheus@29.9.0; keep 29.8.0 pinned and revisit after the recorded requirements are satisfied"
