immich 0.1.1 Helm chart
bearNot scored yet
A Helm chart for Immich with separate API and microservices roles
Version 0.1.1 todayapp version v3.1.0 0Artifact Hub
immich 0.1.1 deploys 2 container images: ghcr.io/immich-app/immich-machine-learning and ghcr.io/immich-app/immich-server. The highest contribution is GHSA-86qp-5c8j-p5mr in starlette 0.50.0, fixed in 1.0.1.
Radar Score
Not yet scored
The daily scoring run has not folded the 2 images into a score yet.
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | v3.1.0 | 0128219 | 2,521 |
| ghcr.io/ | v3.1.0 | 0059351 | 4,319 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2026-58016 | glib2.0 | no fix listed |
| Medium | DEBIAN-CVE-2018-18064 | cairo | no fix listed |
| Medium | DEBIAN-CVE-2026-40393 | mesa | 22.3.6-1+deb12u2 |
| Medium | DEBIAN-CVE-2026-66046 | expat | no fix listed |
| Medium | DEBIAN-CVE-2025-29070 | lcms2 | no fix listed |
| Medium | GHSA-58pv-8j8x-9vj2 | jaraco-context | 6.1.0 |
| Medium | GHSA-3r9x-f23j-gc73 | onnx | 1.21.0 |
| Medium | DEBIAN-CVE-2026-66033 | libssh2 | 1.11.1-1+deb13u2 |
| Medium | GHSA-7gcm-g887-7qv7 | protobuf | 6.33.5 |
| Medium | DEBIAN-CVE-2026-52490 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2026-80229 | curl | no fix listed |
| Medium | DEBIAN-CVE-2026-8927 | curl | no fix listed |
| Medium | DEBIAN-CVE-2026-42217 | openexr | no fix listed |
| Medium | DEBIAN-CVE-2026-16239 | postgresql-17 | 17.11-0+deb13u1 |
| Medium | DEBIAN-CVE-2026-42216 | openexr | no fix listed |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
| Medium | DEBIAN-CVE-2019-1010025 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-57433 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-8926 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-6653 | libxml2 | no fix listed |
| Low | GHSA-vxpw-j846-p89q | undici | 6.27.0 |
| Low | DEBIAN-CVE-2026-13221 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-42496 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-3805 | curl | 8.14.1-2+deb13u4 |
| Low | DEBIAN-CVE-2026-14662 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-14456 | openssl | 3.5.7-1~deb13u2 |
| Low | DEBIAN-CVE-2017-7475 | cairo | no fix listed |
| Low | DEBIAN-CVE-2026-41142 | openexr | no fix listed |
| Low | GHSA-62p4-gmf7-7g93 | pillow | 12.3.0 |
| Low | DEBIAN-CVE-2026-82209 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-14664 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-14670 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-15742 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-66032 | libssh2 | 1.11.1-1+deb13u2 |
| Low | DEBIAN-CVE-2026-19385 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-80255 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-14671 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-14677 | postgresql-17 | 17.11-0+deb13u1 |
| Low | DEBIAN-CVE-2026-14680 | postgresql-17 | 17.11-0+deb13u1 |
| Low | GHSA-mf9v-mfxr-j63j | urllib3 | 2.7.0 |
| Low | DEBIAN-CVE-2026-63072 | openssl | no fix listed |
| Low | DEBIAN-CVE-2026-12087 | perl | no fix listed |
| Low | DEBIAN-CVE-2025-1352 | elfutils | no fix listed |
| Low | DEBIAN-CVE-2026-58015 | glib2.0 | no fix listed |
| Low | PYSEC-2026-3452 | pillow | 12.3.0 |
| Low | DEBIAN-CVE-2026-58013 | glib2.0 | no fix listed |
| Low | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.8 |
| Low | DEBIAN-CVE-2026-58010 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2026-58012 | glib2.0 | no fix listed |
| Low | DEBIAN-CVE-2023-50495 | ncurses | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.1.1latest | today | v3.1.0 | — | — |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.