Remote Dependency Closure

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This generated report joins public top-100 source-scan dependency risk to the dependency locks in maintained recipe artifacts.

It answers:

Which popular charts depend on remote or vendored subcharts, and what exact
dependency closure evidence do we already have?

This is not a live dependency resolver and not a support claim. It uses the committed source scan, maintained recipe metadata, and dependency-lock.yaml files.

Current Reading

source top-100 rows with remote, vendored, or non-exact dependencies: 49
rows with a maintained dependency lock:                         19/49
source-only rows without a maintained recipe:                   30/49
locked rows with dependencies but no dependency provenance:      0/49
non-exact dependency rows frozen to Chart.lock:                  9/49
frozen range rows with refresh-survival evidence:                4/9
P0 source rows:                                                  33
active P0 work rows:                                             21
keep-current rows:                                               14
P1 source rows:                                                  14
P2 source rows:                                                  2

Closure Status

StatusRowsMeaning
source-only-no-maintained-recipe30The source chart is not currently represented by a maintained recipe row.
source-version-lock-present15A maintained dependency lock matches the source-scan chart version.
modeled-version-lock-present4A maintained dependency lock exists for the modeled/catalog version; source scan and model may differ.

Workstreams

WorkstreamRowsFirst actionDone when
create-recipe-import-candidate30create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offerrecipe candidate exists with source lock, dependency lock, first base variant, render parity, and an explicit catalog decision
dependency-range-policy5record dependency range policy and refresh-survival check for non-exact dependency constraintsnon-exact dependency constraints have a recorded policy plus refresh-survival evidence for the supported version
keep-current14keep dependency lock evidence current with the supported recipe versiondependency evidence is still current for the supported recipe version

Highest Priority Active Work Rows

Source rankChartWorkstreamLock statusLocked dependenciesNext action
9k8s-dashboard/kubernetes-dashboard@7.14.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
13gitlab/gitlab@10.0.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
15bitnami/keycloak@25.2.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
23bitnami/kafka@32.4.3create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
25bitnami/external-dns@9.0.3create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
26apache-airflow/airflow@1.21.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
29nextcloud/nextcloud@9.1.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
32bitnami/minio@17.0.21create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
34metallb/metallb@0.16.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
38kyverno/kyverno@3.8.1dependency-range-policysource-version-lock-present5record dependency range policy and refresh-survival check for non-exact dependency constraints
39gitea/gitea@12.6.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
40sonarqube/sonarqube@2026.3.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
41cloudnative-pg/cloudnative-pg@0.28.2dependency-range-policysource-version-lock-present1record dependency range policy and refresh-survival check for non-exact dependency constraints
43datadog/datadog@3.214.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
44bitnami/thanos@17.3.1create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
46oauth2-proxy/oauth2-proxy@10.6.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
47bitnami/wordpress@31.0.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
49goauthentik/authentik@2026.5.0create-recipe-import-candidatesource-only-no-maintained-recipe0create recipe/import candidate and write dependency-lock.yaml before treating the chart as a catalog offer
66bitnami/elasticsearch@22.1.6dependency-range-policysource-version-lock-present2record dependency range policy and refresh-survival check for non-exact dependency constraints
70jaegertracing/jaeger@4.8.0dependency-range-policysource-version-lock-present1record dependency range policy and refresh-survival check for non-exact dependency constraints

Most Common Locked Repositories

RepositoryLocked rows
oci://registry-1.docker.io/bitnamicharts7
https://dandydeveloper.github.io/charts/2
https://prometheus-community.github.io/helm-charts2
https://charts.bitnami.com/bitnami1
https://charts.min.io/1
https://cloudnative-pg.github.io/grafana-dashboards1
https://falcosecurity.github.io/charts1
https://grafana-community.github.io/helm-charts1
https://grafana.github.io/helm-charts1
https://kyverno.github.io/api1
https://kyverno.github.io/reports-server/1
https://openreports.github.io/reports-api1

How To Use This

Files

FilePurpose
top100.csvOne row per top-100 source chart with remote, vendored, or non-exact dependency risk.
recipes/*/*/*/dependency-lock.yamlMaintained recipe dependency locks joined into this report.
data/quirk-work-queue/top100-queue.csvSource quirk priority used to rank dependency work.
data/top500-catalog-analysis/source/source-feature-scan.raw.jsonSource-scan input.

Regenerate:

npm run remote-deps:closure
npm run remote-deps:closure:verify