umami Helm chart
christianhuthVerified publisherScored 14 Sept 2026
Umami is a simple, fast, privacy-focused alternative to Google Analytics.
Latest 7.13.0 2 days agodeploys tag postgresql-v2.20.1 5Artifact Hub
umami 7.13.0 deploys 2 container images: ghcr.io/umami-software/umami and bitnami/postgresql. Across them, 187 findings — 0 critical, 2 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | postgresql-v2.20.1 | 0239146 | 2,367 |
| bitnami/ | latest | 0000 | 0 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | ALPINE-CVE-2025-15467 | openssl | 3.5.5-r0 |
| High | GHSA-c4j6-fc7j-m34r | next | 15.5.16 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-p293-qw3h-jr36 | next | 15.5.24 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | ALPINE-CVE-2026-19931 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2025-11187 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-9079 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-10536 | curl | 8.22.0-r0 |
| Medium | GHSA-m99w-x7hq-7vfj | next | 15.5.21 |
| Medium | GHSA-379q-355j-w6rj | pnpm | 10.26.0 |
| Medium | ALPINE-CVE-2026-18924 | curl | 8.22.0-r0 |
| Medium | GHSA-267c-6grr-h53f | next | 15.5.16 |
| Medium | ALPINE-CVE-2026-11856 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-8925 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-89xv-2m56-2m9x | next | 15.5.21 |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-p9j2-gv94-2wf4 | next | 15.5.21 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | GHSA-w7jw-789q-3m8p | shell-quote | 1.8.4 |
| Medium | GHSA-2phv-j68v-wwqx | pnpm | 10.27.0 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-8924 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-80231 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-80229 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-8927 | curl | 8.22.0-r0 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.5.5-r0 |
| Medium | GHSA-hwx4-2j3j-g496 | pnpm | 10.34.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |
| Medium | GHSA-492v-c6pp-mqqv | next | 15.5.16 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.5.5-r0 |
| Low | ALPINE-CVE-2026-8926 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Low | GHSA-mg66-mrh9-m8jx | next | 15.5.16 |
| Low | ALPINE-CVE-2026-3805 | curl | 8.19.0-r0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | GHSA-34x7-hfp2-rc4v | tar | 7.5.7 |
| Low | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-82209 | curl | 8.22.0-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 7.13.0latest | 2 days ago | postgresql-v2.20.1 | 0239146 | 2,367 |
| 7.12.0 | 4 days ago | postgresql-v2.20.1 | 0239146 | 2,367 |
| 7.11.6 | 7 days ago | postgresql-v2.20.1 | 0239146 | 2,367 |
| 7.11.5 | 22 days ago | postgresql-v2.20.1 | 0239146 | 2,367 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.