iteration-zero Helm chart
cloud-native-toolkitScored 14 Sept 2026
Helm chart to install the cli-tools image into a cluster so that the iteration-zero scripts can be run
Latest 0.2.0 4 years agoapp version v1.1-v1.8.2 0Artifact Hub
iteration-zero 0.2.0 deploys 1 container image: quay.io/cloudnativetoolkit/cli-tools. Across them, 483 findings — 5 critical, 21 high — 2 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38408 in openssh 9.0_p1-r1, fixed in 9.0_p1-r4.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| quay.io/ | v1.1-v1.8.2 | 521118337 | 6,921 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-4v98-7qmw-rqr8 | github.com/ | 0.12.5 |
| Medium | ALPINE-CVE-2022-1587 | pcre2 | 10.40-r0 |
| Medium | GHSA-vvpx-j8f3-3w6h | golang.org/ | 0.7.0 |
| Medium | ALPINE-CVE-2023-0215 | openssl | 1.1.1t-r0 |
| Medium | GHSA-hp87-p4gw-j4gq | gopkg.in/ | 3.0.1 |
| Medium | ALPINE-CVE-2022-42915 | curl | 7.83.1-r4 |
| Medium | GHSA-8c26-wmh5-6g9v | golang.org/ | 0.0.0-20220314234659-1baeb1ce4c0b |
| Medium | GHSA-4374-p667-p6c8 | golang.org/ | 0.17.0 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r1 |
| Medium | ALPINE-CVE-2023-27534 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2022-32208 | curl | 7.83.1-r2 |
| Medium | GHSA-449p-3h89-pw88 | github.com/ | 5.11.0 |
| Medium | GHSA-69cg-p879-7622 | golang.org/ | 0.0.0-20220906165146-f3363e06e74c |
| Medium | GHSA-3vm4-22fp-5rfm | golang.org/ | 0.0.0-20201216223049-8b5274cf687f |
| Medium | ALPINE-CVE-2023-27533 | curl | 8.0.1-r0 |
| Medium | GHSA-cx63-2mw6-8hw5 | setuptools | 70.0.0 |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | GHSA-q64h-39hv-4cf7 | github.com/ | 1.7.4 |
| Medium | GHSA-v725-9546-7q7m | github.com/ | 5.13.0 |
| Medium | ALPINE-CVE-2022-40674 | expat | 2.4.9-r0 |
| Medium | GHSA-p77j-4mvh-x3m3 | google.golang.org/ | 1.79.3 |
| Medium | ALPINE-CVE-2022-45061 | python3 | 3.10.9-r0 |
| Medium | GHSA-cjjc-xp8v-855w | golang.org/ | 0.0.0-20200124225646-8b5121be2f68 |
| Medium | ALPINE-CVE-2022-2309 | libxml2 | 2.9.14-r1 |
| Medium | GHSA-r9hx-vwmv-q579 | setuptools | 65.5.1 |
| Medium | GHSA-232p-vwff-86mp | github.com/ | 20.10.24 |
| Medium | ALPINE-CVE-2023-28319 | curl | 8.1.0-r0 |
| Medium | ALPINE-CVE-2022-43680 | expat | 2.5.0-r0 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | ALPINE-CVE-2023-3446 | openssl | 1.1.1u-r2 |
| Medium | GHSA-mvff-h3cj-wj9c | github.com/ | 1.5.9 |
| Medium | ALPINE-CVE-2024-28757 | expat | 2.6.2-r0 |
| Medium | GHSA-xrjj-mj9h-534m | golang.org/ | 0.4.0 |
| Medium | GHSA-5rcv-m4m3-hfh7 | golang.org/ | 0.3.3 |
| Medium | ALPINE-CVE-2023-52425 | expat | 2.6.0-r0 |
| Medium | ALPINE-CVE-2022-42916 | curl | 7.83.1-r4 |
| Medium | GHSA-h86h-8ppg-mxmh | golang.org/ | 0.0.0-20210428140749-89ef3d95e781 |
| Medium | GHSA-6wvf-f2vw-3425 | github.com/ | 5.29.3 |
| Medium | ALPINE-CVE-2022-2097 | openssl | 1.1.1q-r0 |
| Medium | GHSA-j8r2-6x86-q33q | requests | 2.31.0 |
| Medium | ALPINE-CVE-2023-5678 | openssl | 1.1.1w-r1 |
| Medium | PYSEC-2026-2269 | pyopenssl | 26.0.0 |
| Medium | GHSA-69ch-w2m2-3vjp | golang.org/ | 0.3.8 |
| Medium | ALPINE-CVE-2023-23914 | curl | 7.83.1-r6 |
| Medium | PYSEC-2023-192 | urllib3 | 2.0.6 |
| Medium | GO-2022-0433 | stdlib | 1.17.9 |
| Medium | ALPINE-CVE-2022-30065 | busybox | 1.35.0-r15 |
| Medium | GHSA-3fwx-pjgw-3558 | github.com/ | 20.10.9 |
| Medium | PYSEC-2024-60 | idna | 3.7 |
| Medium | GO-2026-4887 | github.com/ | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.2.0latest | 4 years ago | v1.1-v1.8.2 | 521118337 | 6,921 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.