Worth stating plainly, because a tool that reads Helm charts and Kubernetes Secrets deserves the question:
- It never writes to your cluster.
idemshells out tokubectland makes exactly two kinds of call:kubectl get … -o json, andkubectl apply --dry-run=server, which the API server evaluates and discards without storing. There is no create, update, patch or delete anywhere in the codebase. - Bare
idem doctorreads no Secrets. It makes two cluster-wide reads —deployments,statefulsets,daemonsetsandapplications.argoproj.io— and nothing else. idem doctor --namespace <ns>additionally readssecretsandconfigmaps, in that one namespace. That is the privilege-sensitive call, and it is opt-in: finding what a controller writes after apply means comparing live objects against their ownlast-appliedrecord, and for Secrets there is no other evidence. It is scoped to the namespace you name —kubectl get -n <ns>, never--all-namespaces.- It never writes to your repository. Subchart dependencies resolve in a temporary directory
that is removed afterwards, unless you explicitly pass
--dependency-update. - It sends nothing anywhere. No telemetry, no analytics.
idemimports no HTTP client at all — the only outbound traffic ishelmfetching a chart you asked for, using your existing helm and registry configuration. - It runs three external binaries and no others:
helmto render,kubectlfor--contextanddoctor, andgitfor--new-from-rev. All are taken from yourPATH;--helmlets you pin which one. - It reads Secrets, and it prints field names.
idemcompares rendered objects, so Secret data passes through it. Output names paths (.data.password) and never prints Secret values — but-o jsonoutput is still derived from your rendered manifests, so treat it with the same care as the manifests themselves.
-
Argument injection into
gitvia--new-from-rev(2026-08-22, pre-release, never published).git diff --name-only <rev>let a value beginning with-be read by git as an option, andgit diff --output=FILEtruncates FILE — soidem --new-from-rev=--output=/path/to/anythingdestroyed that file while printing an ordinary report and exiting 0. A value naming a path also silently disabled the ratchet, hiding every finding behind "No charts changed since …" and exit 0. Revisions are now validated withgit rev-parse --verifyand every git invocation passes--end-of-options. -
Script injection through the GitHub Action's
args(2026-08-25, never in a published release;v0.1.0was rebuilt with the fix before anyone could consume it).action.ymlinterpolated${{ inputs.args }}directly into arun:block, so anargsvalue containing$(...)or a backtick executed on the runner. Wiringargsfrom a pull-request title or a branch name — an ordinary thing to do — was therefore arbitrary command execution in the calling repository. Inputs now reach the script throughenv:, where bash expands them as data and does not re-parse the result.
Pre-1.0 and unreleased. Fixes land on main; there are no backports yet.
Please report privately through GitHub Security Advisories rather than opening a public issue.
Include what you can reproduce and what an attacker would gain. You will get an acknowledgement within a week.