| 1 | k8s-dashboard/kubernetes-dashboard@7.14.0 | apiservice | APIService aggregation can pass render parity while failing at API aggregation or TLS/runtime readiness. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 2 | gitlab/gitlab@10.0.0 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 3 | datadog/datadog@3.214.0 | apiservice | APIService aggregation can pass render parity while failing at API aggregation or TLS/runtime readiness. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 4 | kong/kong@3.2.0 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 5 | bitnami/kafka@32.4.3 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 6 | bitnami/minio@17.0.21 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 7 | bitnami/thanos@17.3.1 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 8 | prometheus-community/kube-prometheus-stack@85.3.0 | semver-compare | version-conditional templates can change rendered objects under a different Kubernetes, chart, or dependency version. | promote version-conditional rendering into chart facts and variant-path coverage |
| 9 | grafana/loki@7.0.0 | semver-compare | version-conditional templates can change rendered objects under a different Kubernetes, chart, or dependency version. | promote version-conditional rendering into chart facts and variant-path coverage |
| 10 | apache-airflow/airflow@1.21.0 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |
| 11 | kyverno/kyverno@3.8.1 | dependency-range-policy | non-exact dependency ranges can silently change the rendered dependency closure during refresh. | record dependency range policy and refresh-survival check for non-exact dependency constraints |
| 12 | bitnami/keycloak@25.2.0 | create-recipe-import-candidate | source-only charts have no maintained recipe path, so catalog claims would be disconnected from proof artifacts. | create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer |