StackRadar

gocd 1.9.2 Helm chart

cloudnativeapp

Scored 14 Sept 2026

GoCD is an open-source continuous delivery server to model and visualize complex workflows with ease.

Version 1.9.2 5 years agoapp version 19.3.0 0Artifact Hub

gocd 1.9.2 deploys 2 container images: gocd/gocd-agent-alpine-3.9 and gocd/gocd-server. Across them, 324 findings11 critical, 61 high 2 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-webmvc 4.3.22.RELEASE, fixed in 5.2.20.RELEASE.

Radar Score

9,144116116290

324 findings over 2 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
gocd/gocd-agent-alpine-3.9v19.3.021337181,966
gocd/gocd-serverv19.3.0948125727,178

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

High findings

48 distinct across the version’s images

High: findings whose contribution to the Radar Score is 40–69. Show every band

SeverityAdvisoryPackageFixed in
HighGHSA-9339-86wc-4qgfxalan@2.7.22.7.3
HighGHSA-4wrc-f8pq-fpqpspring-web@4.3.22.RELEASE6.0.0
HighALPINE-CVE-2019-9511nghttp2@1.35.1-r01.35.1-r1
HighGHSA-4w82-r329-3q67jackson-databind@2.9.42.9.10.3
HighALPINE-CVE-2019-5436curl@7.64.0-r17.64.0-r2
HighALPINE-CVE-2019-1349git@2.20.1-r02.20.2-r0
HighGHSA-g5vr-rgqm-vf78spring-webmvc@4.3.22.RELEASEno fix listed
HighGHSA-26vr-8j45-3r4wjetty-server@9.4.14.v201811149.4.39
HighALPINE-CVE-2021-23840openssl@1.1.1b-r11.1.1j-r0
HighGHSA-hfrx-6qgj-fp6ccommons-fileupload@1.41.5
HighGHSA-cggj-fvv3-cqwvjackson-databind@2.9.42.9.5
HighALPINE-CVE-2019-1350git@2.20.1-r02.20.2-r0
HighGHSA-q93h-jc49-78ggjackson-databind@2.9.42.9.10.4
HighGHSA-p43x-xfjf-5jhrjackson-databind@2.9.42.9.10.4
HighALPINE-CVE-2019-5482curl@7.64.0-r17.64.0-r3
HighALPINE-CVE-2019-1352git@2.20.1-r02.20.2-r0
HighGHSA-59j4-wjwp-mw9mvelocity@1.7no fix listed
HighALPINE-CVE-2019-1354git@2.20.1-r02.20.2-r0
HighGHSA-9qcf-c26r-x5rfquartz@2.3.12.3.2
HighALPINE-CVE-2021-3449openssl@1.1.1b-r11.1.1k-r0
HighGHSA-645p-88qh-w398jackson-databind@2.9.42.9.7
HighGHSA-gwcr-j4wh-j3cqjetty-servlets@9.4.14.v201811149.4.41
HighGHSA-hh32-7344-cg2fspring-security-core@4.2.11.RELEASE5.4.11
HighGHSA-hh32-7344-cg2fspring-security-web@4.2.11.RELEASE5.4.11
HighGHSA-m394-8rww-3jr7jetty-server@9.4.14.v201811149.4.37
HighGHSA-6phf-73q6-gh87commons-beanutils@1.8.31.9.4
HighGHSA-rvwf-54qp-4r6vsnakeyaml@1.181.26
HighGHSA-9gph-22xh-8x98jackson-databind@2.9.42.9.10.8
HighGHSA-9mxf-g3x6-wv74jackson-databind@2.9.42.9.7
HighGHSA-h822-r4r5-v8jgjackson-databind@2.9.42.9.10
HighGHSA-c8hm-7hpq-7jhgjackson-databind@2.9.42.9.8
HighGHSA-f9hv-mg5h-xcw9jackson-databind@2.9.42.9.8
HighGHSA-mx9v-gmh4-mgqwjackson-databind@2.9.42.9.8
HighGHSA-558x-2xjg-6232spring-expression@4.3.22.RELEASE5.2.20.RELEASE
HighGHSA-mph4-vhrx-mv67jackson-databind@2.9.42.9.9.1
HighGHSA-5ww9-j83m-q7qxjackson-databind@2.9.42.9.9
HighGHSA-4gq5-ch57-c2mgjackson-databind@2.9.42.9.7
HighALPINE-CVE-2019-9948python2@2.7.15-r32.7.16-r1
HighALPINE-CVE-2019-9636python2@2.7.15-r32.7.16-r1
HighGHSA-gww7-p5w4-wrfvjackson-databind@2.9.42.9.10.2
HighGHSA-6fpp-rgj9-8rwcjackson-databind@2.9.42.9.9.2
HighGHSA-288c-cq4h-88gqjackson-databind@2.9.42.9.10.7
HighALPINE-CVE-2019-12900bzip2@1.0.6-r61.0.6-r7
HighGHSA-x2w5-5m2g-7h5mjackson-databind@2.9.42.9.7
HighALPINE-CVE-2019-5481curl@7.64.0-r17.64.0-r3
HighGHSA-7qx4-pp76-vrqhcommons-configuration2@2.42.7
HighGHSA-hwj3-m3p6-hj38dom4j@1.6.12.0.3
HighGHSA-5r5r-6hpj-8gg9jackson-databind@2.9.42.9.10.8

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.9.2latest5 years ago19.3.01161162909,144

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloudnativeapp/gocd.svg)](https://charts.stackradar.io/charts/cloudnativeapp/gocd)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.