StackRadar

finops-stack 0.0.5 Helm chart

cert-managerVerified publisher

Scored 14 Sept 2026

A FinOps Stack for Kubernetes

Version 0.0.5 2 years agoapp version 0.0.3 1Artifact Hub

finops-stack 0.0.5 deploys 12 container images: quay.io/kiwigrid/k8s-sidecar, grafana/grafana, ghcr.io/kyverno/kyvernopre, ghcr.io/kyverno/kyverno and 8 more. Across the 8 measured, 1,279 findings1 critical, 16 high. The highest contribution is ALPINE-CVE-2025-6965 in sqlite 3.45.3-r1, fixed in 3.45.3-r3.

Radar Score

12,5621161191,143

1,279 findings over 8 of 12 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

12 images
ImageTagVulnerabilitiesRadar Score
quay.io/kiwigrid/k8s-sidecar1.27.41225471,081
grafana/grafana11.1.302211511,738
ghcr.io/kyverno/kyvernoprev1.12.502121551,601
ghcr.io/kyverno/kyvernov1.12.502121551,601
ghcr.io/kyverno/background-controllerv1.12.502121551,601
ghcr.io/kyverno/cleanup-controllerv1.12.502121551,601
ghcr.io/kyverno/reports-controllerv1.12.502121551,601
ghcr.io/jetstack/finops-toolkit/limit-ranger0.0.3unmeasured
ghcr.io/jetstack/finops-toolkit/office-hours0.0.3unmeasured
ghcr.io/jetstack/finops-toolkit/vpatron0.0.3unmeasured
bitnami/kubectl×81.28.5unmeasured
ghcr.io/kyverno/kyverno-cliv1.12.502131701,738

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

45 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.22.00.52.0
MediumALPINE-CVE-2024-7264curl@8.9.0-r08.9.1-r0
MediumALPINE-CVE-2024-5535openssl@3.3.0-r23.3.1-r1
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.22.00.31.0
MediumALPINE-CVE-2024-45492expat@2.6.2-r02.6.3-r0
MediumGHSA-38jv-5279-wg99urllib3@2.2.12.6.3
MediumALPINE-CVE-2024-4741openssl@3.3.0-r23.3.0-r3
MediumGHSA-v725-9546-7q7mgithub.com/go-git/go-git/v5@v5.11.05.13.0
MediumGHSA-p77j-4mvh-x3m3google.golang.org/grpc@v1.62.11.79.3
MediumALPINE-CVE-2024-45491expat@2.6.2-r02.6.3-r0
MediumPYSEC-2025-49setuptools@70.0.078.1.1
MediumALPINE-CVE-2024-45490expat@2.6.2-r02.6.3-r0
MediumALPINE-CVE-2025-9230openssl@3.3.0-r23.3.5-r0
MediumALPINE-CVE-2024-12797openssl@3.3.0-r23.3.3-r0
MediumALPINE-CVE-2025-9231openssl@3.3.0-r23.3.5-r0
MediumGO-2026-4887github.com/docker/docker@v25.0.5+incompatibleno fix listed
MediumALPINE-CVE-2025-59375expat@2.6.2-r02.7.2-r0
MediumALPINE-CVE-2024-8176expat@2.6.2-r02.7.0-r0
MediumALPINE-CVE-2024-9681curl@8.9.0-r08.11.0-r0
MediumGHSA-8p9x-46gm-qfx2github.com/kyverno/kyverno@v0.0.0-20240712090659-b7fb616a6db31.15.3
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.22.00.52.0
MediumALPINE-CVE-2025-0725curl@8.9.0-r08.12.0-r0
MediumGHSA-wf45-q9ch-q8ghgithub.com/apache/thrift@v0.18.10.23.0
MediumGHSA-2xpw-w6gg-jr37urllib3@2.2.12.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@2.2.12.6.0
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.22.00.52.0
MediumALPINE-CVE-2024-9143openssl@3.3.0-r23.3.2-r1
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.22.00.52.0
MediumALPINE-CVE-2025-0665curl@8.9.0-r08.12.0-r0
MediumGHSA-jrr2-x33p-6hvcgithub.com/kyverno/kyverno@v0.0.0-20240712090659-b7fb616a6db31.13.5
MediumPYSEC-2024-230certifi@2024.6.22024.7.4
MediumALPINE-CVE-2026-31790openssl@3.3.0-r23.3.7-r0
MediumGHSA-pc3f-x583-g7j2github.com/moby/spdystream@v0.2.00.5.1
MediumALPINE-CVE-2025-31115xz@5.6.1-r35.6.2-r1
MediumALPINE-CVE-2025-9232openssl@3.3.0-r23.3.5-r0
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.22.00.52.0
MediumGHSA-hcg3-q754-cr77golang.org/x/crypto@v0.22.00.35.0
MediumALPINE-CVE-2026-28388openssl@3.3.0-r23.3.7-r0
MediumALPINE-CVE-2025-69421openssl@3.3.0-r23.3.6-r0
MediumGHSA-6v2p-p543-phr9golang.org/x/oauth2@v0.19.00.27.0
MediumALPINE-CVE-2026-28387openssl@3.3.0-r23.3.7-r0
MediumGHSA-8rm2-7qqf-34qmgithub.com/prometheus/prometheus@v0.52.00.305.2
MediumALPINE-CVE-2026-28389openssl@3.3.0-r23.3.7-r0
MediumALPINE-CVE-2026-28390openssl@3.3.0-r23.3.7-r0
MediumGHSA-jr27-m4p2-rc6rpyasn1@0.6.00.6.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.0.5latest2 years ago0.0.31161191,14312,562

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cert-manager/finops-stack.svg)](https://charts.stackradar.io/charts/cert-manager/finops-stack)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.