This generated report is the final review surface for the retained proof-complete update candidates.
The candidates have proof-complete root paths. They are visible in the catalog as catalog-candidate entries. They do not replace the current supported versions until a target-scoped replacement decision chooses that outcome. If a candidate is already behind the latest upstream chart version, refresh or explicitly retain it before making a replacement decision.
Result
candidate charts: 7
proof-complete root paths: 7 / 7
latest-upstream aligned: 7 / 7
superseded by newer upstream: 0 / 7
replacement decisions not written: 0 / 7
latest-aligned decisions not written: 0 / 7
superseded candidates without final decision: 0 / 0
replacement decisions written: 7 / 7
support-promoted candidates: 0 / 7
Candidates
| Chart | Current supported | Candidate | Latest upstream | Freshness | Candidate base | Proof status | Replacement decision | Topics | Next action |
|---|---|---|---|---|---|---|---|---|---|
argo-cd/argo-cd | 9.5.15 | 9.5.17 | 9.5.17 | latest-upstream-aligned | default | proof-complete-root-path-present | defer-replacement | 7 | replacement decision defers argo-cd/argo-cd@9.5.17; keep 9.5.15 pinned and revisit after the recorded requirements are satisfied |
bitnami/mongodb | 19.0.7 | 19.1.0 | 19.1.0 | latest-upstream-aligned | static-passwords | proof-complete-root-path-present | defer-replacement | 7 | replacement decision defers bitnami/mongodb@19.1.0; keep 19.0.7 pinned and revisit after the recorded requirements are satisfied |
bitnami/nginx | 24.0.2 | 25.0.0 | 25.0.0 | latest-upstream-aligned | http-clusterip | proof-complete-root-path-present | defer-replacement | 5 | replacement decision defers bitnami/nginx@25.0.0; keep 24.0.2 pinned and revisit after the recorded requirements are satisfied |
bitnami/postgresql | 18.6.7 | 18.7.0 | 18.7.0 | latest-upstream-aligned | static-passwords | proof-complete-root-path-present | defer-replacement | 7 | replacement decision defers bitnami/postgresql@18.7.0; keep 18.6.7 pinned and revisit after the recorded requirements are satisfied |
bitnami/redis | 25.5.3 | 27.0.0 | 27.0.0 | latest-upstream-aligned | default | proof-complete-root-path-present | defer-replacement | 5 | replacement decision defers bitnami/redis@27.0.0; keep 25.5.3 pinned and revisit after the recorded requirements are satisfied |
prometheus-community/kube-prometheus-stack | 85.3.3 | 86.1.0 | 86.1.0 | latest-upstream-aligned | default | proof-complete-root-path-present | defer-replacement | 6 | replacement decision defers prometheus-community/kube-prometheus-stack@86.1.0; keep 85.3.3 pinned and revisit after the recorded requirements are satisfied |
prometheus-community/prometheus | 29.8.0 | 29.9.0 | 29.9.0 | latest-upstream-aligned | server-only-ephemeral | proof-complete-root-path-present | defer-replacement | 4 | replacement decision defers prometheus-community/prometheus@29.9.0; keep 29.8.0 pinned and revisit after the recorded requirements are satisfied |
Decision Rule
A proof-complete candidate can still be the wrong replacement for a given target. Replacement needs a target-scoped decision that records:
- whether to replace, defer, or keep both versions;
- the supported base and target scope;
- accepted lifecycle, scan, image, storage, RBAC, CRD, webhook, and target-fact boundaries;
- fresh live evidence requirements after replacement.
Until that decision exists, the current supported version remains pinned.
Files
| File | Role |
|---|---|
| decisions.csv | Spreadsheet replacement queue. |
| decisions.yaml | Machine-readable replacement queue. |
| decision-artifacts/ | Target-scoped replacement decisions that close individual rows. |
| ../promotion-work-orders.md | Closed proof-lane work orders for these candidates. |
| ../production-disposition/summary.md | Candidate production-disposition boundary. |
Verify
npm run top20:latest-replacement-decisions:verify