Artifact Hub Chart Release and Security-Report Drift Watch avatar

Artifact Hub Chart Release and Security-Report Drift Watch

Pricing

from $2.00 / 1,000 package baselineds

Go to Apify Store
Artifact Hub Chart Release and Security-Report Drift Watch

Artifact Hub Chart Release and Security-Report Drift Watch

Watches a list of Artifact Hub packages and reports each new chart version, application-version change, and change in the Artifact Hub security report summary, against a stored baseline. Each change record also gives the signature and deprecation state. P

Pricing

from $2.00 / 1,000 package baselineds

Rating

0.0

(0)

Developer

kingii98

kingii98

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

9 days ago

Last modified

Categories

Share

Know when a Helm chart that you pin ships a new version, changes its application version, or gets a worse Artifact Hub security report. Each change record also gives you the signature and the deprecation state of the chart.

You pin chart versions. Artifact Hub knows the current version of each chart, the application version inside it, the signature and deprecation state, and the counts of the security report by severity. This Actor polls that public API for the packages that you watch, compares each answer with a stored baseline, and writes one row for each change.

The Actor needs no cluster access, no kubeconfig, no Helm binary, no chart download, and no browser. It reads one public JSON API.

What the Actor does

  1. It reads the Artifact Hub package record of each watched package.
  2. It compares the answer with the baseline of that package from the last run.
  3. It writes one dataset record for each detected change, one record for each watched package, and one summary record.
  4. It writes the new state back to a named key-value store.

The first run of a package writes the baseline and reports no change. From the second run on, you get only what moved. Run the Actor on a daily Apify schedule: chart publishers release on their own cadence, and Artifact Hub re-scans a chart after its release, so the watch must be standing.

Input

FieldTypeDefaultDescription
packagesarraythree demo charts1 to 150 packages, each as repository/package. A full Artifact Hub package URL works too, and kind:repository/package names another package kind for one entry.
kindstringhelmThe Artifact Hub package kind of an entry that does not name one.
major_changes_onlybooleanfalseReport a package only when the new version crosses a major version.
state_namestringDEFAULTThe name of the baseline set. Use one name for each watch list.
request_timeout_secondsinteger30Timeout for each Artifact Hub request.
concurrencyinteger4The largest number of packages polled at the same time.
max_run_secondsinteger240Wall-clock deadline for the watch list.

Every field has a default, so a run with an empty input works and watches the three demo charts:

{
"packages": [
"prometheus-community/kube-prometheus-stack",
"ingress-nginx/ingress-nginx",
"grafana/grafana"
]
}

The Actor needs no API key and no secret. It speaks to one host, artifacthub.io, and it builds every URL itself, so no input can point it at a private or reserved address.

An entry that is not a usable package reference does not stop the run: it gets the INVALID_PACKAGE reason code, it is not polled, and it is not charged.

Output

One record for each detected change

A change record is written when the version, the application version or the security report summary moved. A package where only the signature or the deprecation state moved keeps that fact in its package record, with the field suppressed_reason, and gets no change record.

FieldDescription
packageThe watched package, as kind/repository/package.
previous_version, new_versionThe chart version before and after.
previous_app_version, new_app_versionThe application version inside the chart, before and after.
released_atThe release date of the new version, in UTC.
signed, previous_signed, signaturesThe signature state, and the signature kinds that Artifact Hub knows.
deprecated, previous_deprecatedThe deprecation state.
security_critical … security_unknownThe counts of the Artifact Hub security report summary, by severity.
security_delta_critical … security_delta_unknownThe change in each count since the baseline. A negative number means fewer findings.
security_total, security_total_deltaThe counts added up, and their change.
change_typesWhich fields moved: version, app_version, security_report, signature, deprecation.
major_changeThe new version crosses a major version.
package_url, repository_urlThe Artifact Hub page, and the chart repository.

One record for each watched package

The package record holds the reason code, the state of the baseline (created, compared or unavailable), the current version, the current security counts, and, when a change was found but not reported, the field suppressed_reason.

One summary record

The summary record holds the packages polled, the baselines written, the changes detected, the major changes, the new critical and high findings, the deprecated and unsigned packages, and the packages whose poll failed.

Reason codes

CodeMeaning
OKArtifact Hub answered and the record was read.
PACKAGE_NOT_FOUNDArtifact Hub does not know this repository and package.
SOURCE_HTTP_ERRORArtifact Hub answered with another status.
SOURCE_BAD_JSONThe answer is not a usable package record.
SOURCE_TOO_LARGEThe answer is above the byte cap of the Actor.
TIMEOUT, CONNECT_FAILThe request did not finish.
RUN_DEADLINEThe run reached max_run_seconds before this package.
INVALID_PACKAGEThe input entry is not a usable package reference.

A failed poll, an unknown package and a run with no change are results, not faults. The run succeeds, the dataset holds the rows, and the status message says what happened. A run fails only when the Actor itself malfunctions.

State

The Actor keeps one record for each package in the named key-value store artifact-hub-chart-baseline. The record holds the version, the application version, the release date, the signature and deprecation state, and the security counts of the last run. Without this baseline there is no change and no charge.

The record is not written when the run could not read the package, and not written when the charge limit of the run stops the report, so the next run still reports that change.

To start a watch again from zero, use another state_name.

Pricing: pay per event

EventWhen it is chargedCount
package-baselinedThe first run of a package writes its baseline. No change is reported.One for each package baselined
release-or-security-change-detectedA later run finds a new version, a new application version, or a changed security report summary.One for each changed package

A package that did not change is not charged. A package where only the signature or the deprecation state moved is not charged either: that move is not in the billing unit, so the run keeps it in the package record, writes the new baseline, and makes no change record. A poll that failed, a package that Artifact Hub does not know and a rejected input entry are not charged either. When major_changes_only is on, a change that does not cross a major version is neither reported nor charged.

A watch list of 50 charts therefore costs 50 baseline events on the first run, and after that only the charts that actually moved.

Limits

  • 150 packages for each run, the contract limit of the watch list.
  • One request for each package, with one retry for an answer that a retry can change.
  • Redirects are not followed, and each answer is read up to 8 MB.
  • The whole poll stops at max_run_seconds.

Development

uv sync
uv run pytest
uv run ruff check .