pkg.sopackage field notes

brew / 順位 136

helm を Homebrew でインストール

helm のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

エージェント安全性

エージェント安全性の回答

helm manages Kubernetes release state and can deploy workloads into clusters.

認証情報アクセス

Uses kubeconfig, cluster tokens, chart repository credentials, and values files that may contain secrets.

リモート変更

Can install, upgrade, rollback, or delete cluster releases.

公開/成果物リスク

Can package charts and deploy application artifacts to production clusters.

推奨コントロール

Gate helm install, upgrade, rollback, uninstall, and repo credential changes.

エージェント利用ガイダンス

Allow template/lint reads; require approval before any cluster mutation or chart publication.

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install helm

provider-native install command

概要

パッケージ概要

Kubernetes package manager

コマンドとエイリアス

  • helm

履歴

プロジェクトの歴史と使われ方

Helm is the Kubernetes package manager. Its documentation defines charts as Helm packages, repositories as places where charts are collected and shared, and releases as chart instances installed into a Kubernetes cluster.

Helm is historically important because it brought package-manager ideas such as repositories, installable archives, dependency metadata, upgrades, rollbacks, and release history into Kubernetes application delivery.

プロジェクトの歴史

The Helm project traces its first version to November 2015 at the first KubeCon. The Helm team describes Helm 1, also known as Helm Classic, as modeled on Homebrew and aimed at helping individual developers package Kubernetes resources and deploy them into clusters.

In January 2016, Deis' Helm team joined forces with Google, Skippbox, and Bitnami to build a new version focused on teams and a growing Kubernetes user community. That work led to the Helm 2 architecture and the chart ecosystem that many Kubernetes users adopted.

Helm joined the Cloud Native Computing Foundation in June 2018. Helm 3 reached its first stable release in November 2019, removing Tiller, refactoring the Go SDK for broader use, and changing internals while preserving the chart-centered workflow for users familiar with Helm 2.

採用の歴史

Helm adoption tracked the growth of Kubernetes itself. Its docs describe chart repositories, `helm search`, `helm install`, `helm upgrade`, `helm rollback`, `helm get`, and `helm uninstall` as ordinary package operations for cluster workloads.

The Helm 3 release post describes a large contributor base and thousands of community members maintaining charts through Helm Hub-era infrastructure. The chart discovery story later centered on Artifact Hub, which the Helm docs use for `helm search hub`.

Package-manager adoption for the CLI is broad: the supplied metadata lists Homebrew, Alpine, Fedora, MacPorts, Nix, Arch, Scoop, winget, and openSUSE packaging for the Kubernetes-oriented Helm CLI.

使われ方

Users add chart repositories, search for charts, install a chart as a named release, pass values with YAML files or `--set`, upgrade releases, inspect status and values, roll back revisions, and uninstall releases.

Helm charts package Kubernetes resource definitions alongside metadata and default values. A chart can be installed many times into a cluster, producing separate releases with their own names and histories.

Helm's local repository configuration is stored in `repositories.yaml` under the user's Helm config directory. Because repository entries can include credentials, that file is also treated as a credentials location in the curation data.

パッケージ好きにとっての重要性

Helm is one of the clearest examples of package-manager culture crossing into infrastructure. It has packages, repositories, dependency declarations, install and upgrade verbs, versioned releases, rollback history, and a registry/discovery ecosystem, but the installed artifacts are Kubernetes resources rather than files under `/usr`.

The Helm 2 to Helm 3 transition is also package-history material: removing Tiller reduced cluster-side moving parts and aligned Helm more closely with Kubernetes RBAC and client-side release management expectations.

For maintainers, Helm created a new packaging discipline around chart metadata, values schema, generated documentation, provenance, OCI distribution, and chart repository layout.

タイムライン

  • 2015: Helm 1 released at the first KubeCon.
  • 2016: Deis, Google, Skippbox, and Bitnami collaborate on the next Helm generation.
  • 2018: Helm joins the Cloud Native Computing Foundation.
  • 2019: Helm 3.0.0 stable release published.
  • 2020: Helm celebrates CNCF graduation.
  • 2020s: Helm chart discovery and search workflows use Artifact Hub in official documentation.

Related projects

  • Kubernetes is the deployment platform Helm packages target.
  • Homebrew inspired Helm Classic's package-manager model.
  • Deis, Google, Skippbox, and Bitnami are named in the Helm 3 history as early collaborators.
  • Artifact Hub is the chart discovery service used by `helm search hub`.
  • helm-docs and helm-ls are neighboring tools for chart documentation and editor assistance.

セキュリティ状態

リスクレベル: orange

Kubernetes package manager.

リスク分類器

リスク orange · 信頼度 高 · infrastructure

理由

  • Kubernetes package manager

信号

  • override:helm

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

macOS
~/Library/Preferences/helm/repositories.yaml
Unix
~/.config/helm/repositories.yaml

Credential files

Credential-bearing paths to review before unattended agent runs.

macOS
~/Library/Preferences/helm/repositories.yaml
Unix
~/.config/helm/repositories.yaml

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
helm実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版4.2.3
マネージャ更新日2026-07-09
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:helm
バージョン4.2.3
パッケージマネージャHomebrew
ホームページhttps://helm.sh/
リポジトリhttps://github.com/helm/helm
最終更新2026-07-09T22:27:01Z
Pulseupdated
Bottle未記録
サービス宣言なし

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • curated agent safety answer
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation