Artifact Hub Chart Release and Security-Report Drift Watch
Pricing
from $2.00 / 1,000 package baselineds
Artifact Hub Chart Release and Security-Report Drift Watch
Watches a list of Artifact Hub packages and reports each new chart version, application-version change, and change in the Artifact Hub security report summary, against a stored baseline. Each change record also gives the signature and deprecation state. P
Pricing
from $2.00 / 1,000 package baselineds
Rating
0.0
(0)
Developer
kingii98
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
9 days ago
Last modified
Categories
Share
Know when a Helm chart that you pin ships a new version, changes its application version, or gets a worse Artifact Hub security report. Each change record also gives you the signature and the deprecation state of the chart.
You pin chart versions. Artifact Hub knows the current version of each chart, the application version inside it, the signature and deprecation state, and the counts of the security report by severity. This Actor polls that public API for the packages that you watch, compares each answer with a stored baseline, and writes one row for each change.
The Actor needs no cluster access, no kubeconfig, no Helm binary, no chart download, and no browser. It reads one public JSON API.
What the Actor does
- It reads the Artifact Hub package record of each watched package.
- It compares the answer with the baseline of that package from the last run.
- It writes one dataset record for each detected change, one record for each watched package, and one summary record.
- It writes the new state back to a named key-value store.
The first run of a package writes the baseline and reports no change. From the second run on, you get only what moved. Run the Actor on a daily Apify schedule: chart publishers release on their own cadence, and Artifact Hub re-scans a chart after its release, so the watch must be standing.
Input
| Field | Type | Default | Description |
|---|---|---|---|
packages | array | three demo charts | 1 to 150 packages, each as repository/package. A full Artifact Hub package URL works too, and kind:repository/package names another package kind for one entry. |
kind | string | helm | The Artifact Hub package kind of an entry that does not name one. |
major_changes_only | boolean | false | Report a package only when the new version crosses a major version. |
state_name | string | DEFAULT | The name of the baseline set. Use one name for each watch list. |
request_timeout_seconds | integer | 30 | Timeout for each Artifact Hub request. |
concurrency | integer | 4 | The largest number of packages polled at the same time. |
max_run_seconds | integer | 240 | Wall-clock deadline for the watch list. |
Every field has a default, so a run with an empty input works and watches the three demo charts:
{"packages": ["prometheus-community/kube-prometheus-stack","ingress-nginx/ingress-nginx","grafana/grafana"]}
The Actor needs no API key and no secret. It speaks to one host,
artifacthub.io, and it builds every URL itself, so no input can point it at a
private or reserved address.
An entry that is not a usable package reference does not stop the run: it gets
the INVALID_PACKAGE reason code, it is not polled, and it is not charged.
Output
One record for each detected change
A change record is written when the version, the application version or the
security report summary moved. A package where only the signature or the
deprecation state moved keeps that fact in its package record, with the field
suppressed_reason, and gets no change record.
| Field | Description |
|---|---|
package | The watched package, as kind/repository/package. |
previous_version, new_version | The chart version before and after. |
previous_app_version, new_app_version | The application version inside the chart, before and after. |
released_at | The release date of the new version, in UTC. |
signed, previous_signed, signatures | The signature state, and the signature kinds that Artifact Hub knows. |
deprecated, previous_deprecated | The deprecation state. |
security_critical … security_unknown | The counts of the Artifact Hub security report summary, by severity. |
security_delta_critical … security_delta_unknown | The change in each count since the baseline. A negative number means fewer findings. |
security_total, security_total_delta | The counts added up, and their change. |
change_types | Which fields moved: version, app_version, security_report, signature, deprecation. |
major_change | The new version crosses a major version. |
package_url, repository_url | The Artifact Hub page, and the chart repository. |
One record for each watched package
The package record holds the reason code, the state of the baseline
(created, compared or unavailable), the current version, the current
security counts, and, when a change was found but not reported, the field
suppressed_reason.
One summary record
The summary record holds the packages polled, the baselines written, the changes detected, the major changes, the new critical and high findings, the deprecated and unsigned packages, and the packages whose poll failed.
Reason codes
| Code | Meaning |
|---|---|
OK | Artifact Hub answered and the record was read. |
PACKAGE_NOT_FOUND | Artifact Hub does not know this repository and package. |
SOURCE_HTTP_ERROR | Artifact Hub answered with another status. |
SOURCE_BAD_JSON | The answer is not a usable package record. |
SOURCE_TOO_LARGE | The answer is above the byte cap of the Actor. |
TIMEOUT, CONNECT_FAIL | The request did not finish. |
RUN_DEADLINE | The run reached max_run_seconds before this package. |
INVALID_PACKAGE | The input entry is not a usable package reference. |
A failed poll, an unknown package and a run with no change are results, not faults. The run succeeds, the dataset holds the rows, and the status message says what happened. A run fails only when the Actor itself malfunctions.
State
The Actor keeps one record for each package in the named key-value store
artifact-hub-chart-baseline. The record holds the version, the application
version, the release date, the signature and deprecation state, and the
security counts of the last run. Without this baseline there is no change and
no charge.
The record is not written when the run could not read the package, and not written when the charge limit of the run stops the report, so the next run still reports that change.
To start a watch again from zero, use another state_name.
Pricing: pay per event
| Event | When it is charged | Count |
|---|---|---|
package-baselined | The first run of a package writes its baseline. No change is reported. | One for each package baselined |
release-or-security-change-detected | A later run finds a new version, a new application version, or a changed security report summary. | One for each changed package |
A package that did not change is not charged. A package where only the
signature or the deprecation state moved is not charged either: that move is
not in the billing unit, so the run keeps it in the package record, writes the
new baseline, and makes no change record. A poll that failed, a package that
Artifact Hub does not know and a rejected input entry are not charged either. When major_changes_only is on, a change that does not cross a major
version is neither reported nor charged.
A watch list of 50 charts therefore costs 50 baseline events on the first run, and after that only the charts that actually moved.
Limits
- 150 packages for each run, the contract limit of the watch list.
- One request for each package, with one retry for an answer that a retry can change.
- Redirects are not followed, and each answer is read up to 8 MB.
- The whole poll stops at
max_run_seconds.
Development
uv syncuv run pytestuv run ruff check .