Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gha-lab-8aba6b05dc — Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of CloudPirates-io/helm-charts @ 9f5a7186 | Kitploit
Tools/GitHubGitHub/pvharmo2/gha-lab-8aba6b05dc
Vulnerability AnalysisCloud SecuritySupply Chain SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubpvharmo2/gha-lab-8aba6b05dc

gha-lab-8aba6b05dc

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of CloudPirates-io/helm-charts @ 9f5a7186

View Repository
7h 54m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Automated research artifact — not the upstream project.

This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of CloudPirates-io/helm-charts at commit 9f5a7186b46070ceae3e80740ab64955b88fc65a (2026-04-27), redistributed under that project's own licence, whose file is included unchanged in this snapshot.

The upstream project is not involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-04-27; see pinning.md in the harness output for every change made to the snapshot.

Questions or objections: [email protected]


CloudPirates Open Source Helm Charts

A curated collection of production-ready Helm charts for open-source cloud-native applications. This repository provides secure, well-documented, and configurable Helm charts following cloud-native best practices.

⚠️ IMPORTANT: As of April 15, 2026, all changelogs only exist in the github release description. Old changelogs are kept for the sake of backwards compatiblity.

Available Charts

ChartDescriptionVersion
ClusterPirateClient agent for the CloudPirates Managed Observability Platform to connect your Kubernetes cluster to our infrastructureVersion
CommonA library chart for common templates and helper functionsVersion
EtcdA distributed reliable key-value storeVersion
GhostA simple, powerful publishing platform that allows you to share your stories with the world.Version
KeycloakOpen Source Identity and Access Management solutionVersion
MariaDB

Quick Start

Prerequisites

  • Kubernetes 1.24+
  • Helm 3.2.0+
  • PV provisioner support in the underlying infrastructure (if persistence is enabled)

Installing Charts

root@kitploit:~
# From Docker Hub registry
helm install my-release oci://registry-1.docker.io/cloudpirates/<chartname>

# From GitHub Container Registry (GHCR)
helm install my-release oci://ghcr.io/cloudpirates-io/helm-charts/<chartname>

# From local clone
helm install my-release ./charts/<chart-name>

Chart Features

All charts in this repository provide:

Security First

  • Cryptographically Signed: All charts are signed with Cosign for supply chain security
  • Non-root containers by default
  • Read-only root filesystems where possible
  • Dropped Linux capabilities
  • Security contexts configured
  • No hardcoded credentials

Production Ready

  • Comprehensive health checks (liveness, readiness, startup probes)
  • Resource requests and limits support
  • Persistent storage configurations
  • Rolling update strategies
  • Health check endpoints

Highly Configurable

  • Extensive values.yaml with detailed documentation
  • Support for existing secrets and ConfigMaps
  • Flexible ingress configurations
  • Service account customization
  • Common labels and annotations support

Configuration

Each chart provides extensive configuration options through values.yaml. Key configuration areas include:

  • Authentication & Security: User credentials, existing secrets, security contexts
  • Storage: Persistent volumes, storage classes, backup configurations
  • Networking: Services, ingress, network policies
  • Scaling: Replica counts, autoscaling, resource limits
  • Monitoring: Metrics, service monitors, health checks

Refer to individual chart READMEs for detailed configuration options.

Get Involved

Want to contribute? Awesome! The most basic way to show your support is to star the project, or to raise issues.

⚠️ IMPORTANT: As of January 22, 2026, all commits must be signed and verified. PRs with unsigned commits will not be merged.

If you want to open a PR, read our contributing guidelines for information about setting up your environment and instructions on the signature verification that we require.

Chat with us and the community on our Discord server!
Everyone is welcome, wether you have a question, need help with a chart, want to contribute, know what's coming next or just have a talk with us.

Discord

This project is built and maintained by our growing community of contributors!

Made with contrib.rocks.

Chart Issues

For issues specific to these Helm charts:

  • Check individual chart README files for troubleshooting
  • Review chart documentation and examples
  • Verify configuration values
  • Open an issue on GitHub
Download Tool
High-performance, open-source relational database server that is a drop-in replacement for MySQL
Version
MemcachedHigh-performance, distributed memory object caching systemVersion
MinIOHigh-Performance Object Storage compatible with Amazon S3 APIsVersion
MongoDBMongoDB a flexible NoSQL database for scalable, real-time data managementVersion
NginxHigh-performance HTTP server and reverse proxyVersion
PostgreSQLThe World's Most Advanced Open Source Relational DatabaseVersion
RabbitMQA messaging broker that implements the Advanced Message Queuing Protocol (AMQP)Version
RabbitMQ Cluster OperatorKubernetes operator to deploy and manage RabbitMQ clustersVersion
RedisIn-memory data structure store, used as a database, cache, and message brokerVersion
RustFSHigh-performance distributed object storage with S3-compatible API (MinIO alternative) [ALPHA]Version
TimescaleDBTimescaleDB is a PostgreSQL extension for high-performance real-time analytics on time-series and event dataVersion
ValkeyHigh-performance in-memory data structure store, fork of RedisVersion
ZookeeperCentralized service for maintaining configuration information, naming, providing distributed synchronization, and group servicesVersion