|
|
|
|
|
by ajross
337 days ago
|
|
I can only repeat the assertion: if you have a victim pulling and installing untrusted tarballs, there is no security boundary being crossed. It doesn't matter whether it's "from a repo". If you can't trust the repo it can feed you whatever it wants. |
|
(Those templates, once rendered, might then refer to pods, etc. that might be put into a k8s cluster (or perhaps we merely render then YAML, and never `apply` it), and in that sense, one might imagine that that is an install, but that's not the security boundary being crossed here; this would presumably result in execution on the host running helm, which would definitely be surprising.)