StackRadar

psono Helm chart

ankra-chartsVerified publisher

Scored 14 Sept 2026

Helm chart for Psono — self-hosted password manager. Packages the Psono server, web client and (optional) admin client. Brings your own PostgreSQL, secret-keys Secret and (optional) ingress.

Latest 1.2.0 13 days agoapp version 5.0.0 1Artifact Hub

psono 1.2.0 deploys 2 container images: psono/psono-server and psono/psono-client. Across them, 179 findings2 critical, 4 high. The highest contribution is ALPINE-CVE-2025-1094 in postgresql16 16.3-r0, fixed in 16.8-r0. Chart.yaml declares kubeVersion >=1.20.0-0; rendered for Kubernetes 1.20.0.

Radar Score

2,3882446127

179 findings over 2 of 2 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
psono/psono-server5.0.024461272,388
psono/psono-client3.6.200000

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

179 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.6.00.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.6.00.6.4
LowPYSEC-2026-213daphne@4.1.24.2.2
LowGHSA-6426-9fv3-65x8django@4.2.164.2.28
LowALPINE-CVE-2026-6638postgresql16@16.3-r016.14-r0
LowALPINE-CVE-2024-10976postgresql16@16.3-r016.5-r0
LowALPINE-CVE-2025-26519musl@1.2.5-r01.2.5-r1
LowGHSA-prg7-hcfm-mfcrsqlparse@0.5.00.6.0
LowGHSA-8rrh-rw8j-w5fxwheel@0.44.00.46.2
LowPYSEC-2026-3554cryptography@43.0.149.0.0
LowGHSA-p3fp-8748-vqfqdjango@4.2.164.2.20
LowGHSA-4xh5-x5gv-qwphpip@24.225.3
LowGHSA-pwv6-vv43-88grpillow@10.3.012.2.0
LowALPINE-CVE-2026-25210expat@2.6.3-r02.7.4-r0
LowGHSA-h35f-9h28-mq5csetuptools@65.5.183.0.0
LowGHSA-fj7v-r99m-22gqpillow@10.3.012.3.0
LowALPINE-CVE-2026-40200musl@1.2.5-r01.2.5-r3
LowALPINE-CVE-2025-66199openssl@3.3.2-r03.3.6-r0
LowPYSEC-2026-3721pip@24.226.2
LowALPINE-CVE-2025-4947curl@8.10.1-r08.14.0-r0
LowALPINE-CVE-2026-22796openssl@3.3.2-r03.3.6-r0
LowGHSA-8qcx-xf44-272xdjango@4.2.165.2.16
LowGHSA-rqw2-ghq9-44m7django@4.2.164.2.27
LowALPINE-CVE-2025-12818postgresql16@16.3-r016.11-r0
LowALPINE-CVE-2026-34743xz@5.6.2-r05.8.3-r0
LowGHSA-pq67-6m6q-mj2vurllib3@1.26.192.5.0
LowGHSA-65pc-fj4g-8rjxidna@3.73.15
LowGHSA-vp96-hxj8-p424pyopenssl@24.2.126.0.0
LowGHSA-2m8g-3cmr-wg3wdjangorestframework@3.15.23.17.2
LowALPINE-CVE-2024-11053curl@8.10.1-r08.11.1-r0
LowALPINE-CVE-2024-10978postgresql16@16.3-r016.5-r0
LowGHSA-qccp-gfcp-xxvcurllib3@1.26.192.7.0
LowGHSA-crhf-3pfg-w68wdjango@4.2.165.2.16
LowGHSA-7xr5-9hcq-chf9django@4.2.164.2.22
LowALPINE-CVE-2024-13176openssl@3.3.2-r03.3.2-r2
LowGHSA-537c-gmf6-5ccfcryptography@43.0.148.0.1
LowALPINE-CVE-2026-27171zlib@1.3.1-r11.3.2-r0
LowALPINE-CVE-2026-32777expat@2.6.3-r02.7.5-r0
LowGHSA-27jp-wm6q-gp25sqlparse@0.5.00.5.4
LowALPINE-CVE-2025-5025curl@8.10.1-r08.14.0-r0
LowGHSA-3496-9g83-7v6xsqlparse@0.5.00.6.0
LowPYSEC-2026-2275requests@2.32.32.33.0
LowALPINE-CVE-2026-32778expat@2.6.3-r02.7.5-r0
LowGHSA-g47c-3xmw-q6m2djangorestframework@3.15.23.17.2
LowALPINE-CVE-2026-32776expat@2.6.3-r02.7.5-r0
LowGHSA-q95w-c7qg-hrffdjango@4.2.164.2.25
LowALPINE-CVE-2025-0167curl@8.10.1-r08.12.0-r0
LowALPINE-CVE-2026-6042musl@1.2.5-r01.2.5-r2
LowPYSEC-2026-214daphne@4.1.24.2.2
LowALPINE-CVE-2026-6472postgresql16@16.3-r016.14-r0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.2.0latest13 days ago5.0.024461272,388

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ankra-charts/psono.svg)](https://charts.stackradar.io/charts/ankra-charts/psono)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.