countly Helm chart
christianhuthVerified publisherScored 14 Sept 2026
Countly is a product analytics platform that helps teams track, analyze and act-on their user actions and behaviour on mobile, web and desktop applications.
Latest 5.2.1 2 days agoapp version 25.05.4 0Artifact Hub
countly 5.2.1 deploys 3 container images: countly/api, countly/frontend and bitnami/mongodb. Across them, 702 findings — 0 critical, 5 high — 3 on CISA KEV. The highest contribution is GHSA-r5fr-rjxr-66jc in lodash 4.17.21, fixed in 4.18.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| countly/ | 25.05.4 | 0348312 | 3,819 |
| countly/ | 25.05.4 | 0240284 | 3,394 |
| bitnami/ | latest | 00013 | 82 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-p6gq-j5cr-w38f | nodemailer | 9.0.1 |
| Low | GHSA-869p-cjfg-cm3x | jws | 4.0.1 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GO-2023-1702 | stdlib | 1.19.8 |
| Low | DLA-4432-1 | curl | 7.74.0-1.3+deb11u16 |
| Low | DLA-3910-1 | e2fsprogs | 1.46.2-2+deb11u1 |
| Low | GHSA-mmx7-hfxf-jppx | axios | 1.18.0 |
| Low | GHSA-rx8g-88g5-qh64 | min-document | 2.19.1 |
| Low | DLA-4064-1 | libxml2 | 2.9.10+dfsg-6.7+deb11u6 |
| Low | GHSA-vvjj-xcjg-gr5g | nodemailer | 8.0.5 |
| Low | MAL-2022-4691 | monorepo-symlink-test | no fix listed |
| Low | DLA-4267-1 | gnutls28 | 3.7.1-5+deb11u8 |
| Low | DLA-4063-1 | gnutls28 | 3.7.1-5+deb11u7 |
| Low | DLA-3937-1 | nss | 2:3.61-1+deb11u4 |
| Low | DLA-3962-1 | glib2.0 | 2.66.8-1+deb11u5 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-52v5-jr5w-gjxr | sigstore | 4.1.1 |
| Low | GO-2023-2375 | stdlib | 1.20.0 |
| Low | GHSA-65ch-62r8-g69g | node-forge | 1.3.2 |
| Low | GO-2023-1569 | stdlib | 1.19.6 |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | GHSA-cm22-4g7w-348p | serve-static | 1.16.0 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | DLA-4344-1 | gdk-pixbuf | 2.42.2+dfsg-1+deb11u4 |
| Low | GO-2024-3106 | stdlib | 1.22.7 |
| Low | GO-2023-1570 | stdlib | 1.19.6 |
| Low | DLA-4061-1 | libtasn1-6 | 4.16.0-2+deb11u2 |
| Low | GHSA-v2v4-37r5-5v8g | ip-address | 10.1.1 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | DLA-4298-1 | cups | 2.3.3op2-3+deb11u10 |
| Low | GHSA-28wg-ghj8-5hjv | nanoid | 3.3.16 |
| Low | DLA-4031-1 | git | 1:2.30.2-1+deb11u4 |
| Low | GHSA-m6fv-jmcg-4jfg | send | 0.19.0 |
| Low | GHSA-w9j2-pvgh-6h63 | axios | 1.15.1 |
| Low | GO-2024-2609 | stdlib | 1.21.8 |
| Low | GO-2024-3107 | stdlib | 1.22.7 |
| Low | GO-2023-1751 | stdlib | 1.19.9 |
| Low | GO-2023-1753 | stdlib | 1.19.9 |
| Low | DLA-4145-1 | expat | 2.2.10-2+deb11u7 |
| Low | GHSA-mp7j-qc5w-4988 | websocket-driver | 0.7.5 |
| Low | GHSA-2v37-7h3g-55p8 | nanoid | 3.3.18 |
| Low | GHSA-2pr8-phx7-x9h3 | protobufjs | 7.5.6 |
| Low | GHSA-58qx-3vcg-4xpx | ws | 8.20.1 |
| Low | DLA-4481-1 | libpng1.6 | 1.6.37-3+deb11u2 |
| Low | DLA-4140-1 | libsoup2.4 | 2.72.0-2+deb11u2 |
| Low | GHSA-3v7f-55p6-f55p | picomatch | 2.3.2 |
| Low | DLA-4472-1 | sudo | 1.9.5p2-3+deb11u3 |
| Low | GHSA-qw6h-vgh9-j6wx | express | 4.20.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 5.2.1latest | 2 days ago | 25.05.4 | 0588609 | 7,295 |
| 5.2.0 | 3 days ago | 25.05.4 | 0588609 | 7,295 |
| 5.1.26 | 5 days ago | 25.05.4 | 0588609 | 7,295 |
| 5.1.25 | 10 days ago | 25.05.4 | 0588609 | 7,295 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.