Hacker News new | ask | show | jobs
by romaaeterna 340 days ago
> You place malicious binaries outside the helm directory

No, helm is the one doing this part in the vuln. Chart.lock is made a symlink to some important file, and helm will happily write to it.