StackRadar

gocd Helm chart

cloudnativeapp

Scored 14 Sept 2026

GoCD is an open-source continuous delivery server to model and visualize complex workflows with ease.

Latest 1.9.2 5 years agoapp version 19.3.0 0Artifact Hub

gocd 1.9.2 deploys 2 container images: gocd/gocd-agent-alpine-3.9 and gocd/gocd-server. Across them, 324 findings11 critical, 61 high 2 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-webmvc 4.3.22.RELEASE, fixed in 5.2.20.RELEASE.

Radar Score

9,144116116290

324 findings over 2 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
gocd/gocd-agent-alpine-3.9v19.3.021337181,966
gocd/gocd-serverv19.3.0948125727,178

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

125 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumGHSA-9w3m-gqgf-c4p9snakeyaml@1.181.32
MediumALPINE-CVE-2018-11782subversion@1.11.1-r01.12.2-r0
MediumGHSA-2wrp-6fg6-hmc5spring-web@4.3.22.RELEASE5.3.34
MediumGHSA-j288-q9x7-2f5vcommons-lang@2.6no fix listed
MediumGHSA-j288-q9x7-2f5vcommons-lang3@3.8.13.18.0
MediumGHSA-r28m-g6j9-r2h5jetty-server@9.4.14.v201811149.4.17.v20190418
MediumALPINE-CVE-2020-8177curl@7.64.0-r17.64.0-r4
MediumGHSA-8grg-q944-cch5hibernate-core@3.6.10.Final5.3.18
MediumGHSA-c4r9-r8fh-9vj2snakeyaml@1.181.31
MediumGHSA-xjp4-hw94-mvp5commons-configuration2@2.42.10.1
MediumGHSA-cgp8-4m63-fhh5commons-net@2.03.9.0
MediumGHSA-78wr-2p64-hpwjcommons-io@2.62.14.0
MediumGHSA-v33x-prhc-gph5spring-security-core@4.2.11.RELEASE4.2.13
MediumGHSA-355h-qmc2-wpwfjetty-http@9.4.14.v201811149.4.60
MediumGHSA-f3jh-qvm4-mg39spring-security-core@4.2.11.RELEASE5.7.12
MediumALPINE-CVE-2019-19242sqlite@3.26.0-r33.28.0-r2
MediumGHSA-98wm-3w3q-mw94snakeyaml@1.181.31
MediumGHSA-qw69-rqj8-6qw8jetty-server@9.4.14.v201811149.4.51.v20230217
MediumGHSA-9w38-p64v-xpmvcommons-configuration2@2.42.10.1
MediumGHSA-wxqc-pxw9-g2p8spring-expression@4.3.22.RELEASE5.2.24.RELEASE
MediumALPINE-CVE-2019-5094e2fsprogs@1.44.5-r01.44.5-r1
MediumGHSA-h46c-h94j-95f3jackson-core@2.9.62.15.0
MediumGHSA-2ppp-9496-p23qspring-security-core@4.2.11.RELEASE4.2.16
MediumGHSA-w37g-rhq8-7m4jsnakeyaml@1.181.32
MediumGHSA-mf92-479x-3373spring-security-web@4.2.11.RELEASEno fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.9.2latest5 years ago19.3.01161162909,144

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloudnativeapp/gocd.svg)](https://charts.stackradar.io/charts/cloudnativeapp/gocd)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.