StackRadar

gocd Helm chart

cloudnativeapp

Scored 14 Sept 2026

GoCD is an open-source continuous delivery server to model and visualize complex workflows with ease.

Latest 1.9.2 5 years agoapp version 19.3.0 0Artifact Hub

gocd 1.9.2 deploys 2 container images: gocd/gocd-agent-alpine-3.9 and gocd/gocd-server. Across them, 324 findings11 critical, 61 high 2 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-webmvc 4.3.22.RELEASE, fixed in 5.2.20.RELEASE.

Radar Score

9,144116116290

324 findings over 2 of 2 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
gocd/gocd-agent-alpine-3.9v19.3.021337181,966
gocd/gocd-serverv19.3.0948125727,178

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

254 distinct across the version’s images
SeverityAdvisoryPackageFixed in
HighGHSA-288c-cq4h-88gqjackson-databind@2.9.42.9.10.7
HighALPINE-CVE-2019-12900bzip2@1.0.6-r61.0.6-r7
HighGHSA-x2w5-5m2g-7h5mjackson-databind@2.9.42.9.7
HighALPINE-CVE-2019-5481curl@7.64.0-r17.64.0-r3
HighGHSA-7qx4-pp76-vrqhcommons-configuration2@2.42.7
HighGHSA-hwj3-m3p6-hj38dom4j@1.6.12.0.3
HighGHSA-5r5r-6hpj-8gg9jackson-databind@2.9.42.9.10.8
MediumALPINE-CVE-2019-13115libssh2@1.8.2-r01.9.0-r0
MediumGHSA-f9xh-2qgp-cq57jackson-databind@2.9.42.9.10.8
MediumGHSA-4jrv-ppp4-jm57gson@2.8.52.8.9
MediumGHSA-m6x4-97wx-4q27jackson-databind@2.9.42.9.10.8
MediumGHSA-fqwf-pjwf-7vqvjackson-databind@2.9.42.9.10.4
MediumGHSA-qr7j-h6gg-jmgcjackson-databind@2.9.42.9.6
MediumGHSA-mx7p-6679-8g3qjackson-databind@2.9.42.9.10.1
MediumGHSA-r3gr-cxrf-hg25jackson-databind@2.9.42.9.10.8
MediumGHSA-gjmw-vf9h-g25vjackson-databind@2.9.42.9.10.1
MediumGHSA-h3cw-g4mq-c5x2jackson-databind@2.9.42.9.10.6
MediumGHSA-85cw-hj65-qqv9jackson-databind@2.9.42.9.10
MediumGHSA-fmmc-742q-jg75jackson-databind@2.9.42.9.10.1
MediumALPINE-CVE-2018-14647python2@2.7.15-r32.7.16-r0
MediumGHSA-gwp4-hfv6-p7hwjackson-databind@2.9.42.9.9.2
MediumGHSA-j823-4qch-3rgmjackson-databind@2.9.42.9.10.5
MediumGHSA-4446-656p-f54gbcprov-jdk15on@1.591.60
MediumGHSA-f3j5-rmmp-3fc5jackson-databind@2.9.42.9.10
MediumGHSA-5p34-5m6p-p58gjackson-databind@2.9.42.9.10.4
MediumGHSA-c265-37vj-cwccjackson-databind@2.9.42.9.10.5
MediumGHSA-9vvp-fxw6-jcxrjackson-databind@2.9.42.9.10.4
MediumGHSA-wh8g-3j2c-rqj5jackson-databind@2.9.42.9.10.8
MediumGHSA-5949-rw7g-wx7wjackson-databind@2.9.42.9.10.7
MediumGHSA-qjw2-hr98-qgfhjackson-databind@2.9.42.9.10.6
MediumGHSA-6wqp-v4v6-c87cjackson-databind@2.9.42.9.6
MediumALPINE-CVE-2019-1351git@2.20.1-r02.20.2-r0
MediumALPINE-CVE-2019-5018sqlite@3.26.0-r33.28.0-r0
MediumALPINE-CVE-2019-19906cyrus-sasl@2.1.27-r12.1.27-r2
MediumGHSA-cjjf-94ff-43w7jackson-databind@2.9.42.9.6
MediumGHSA-h4rc-386g-6m85jackson-databind@2.9.42.9.10.4
MediumALPINE-CVE-2019-1387git@2.20.1-r02.20.2-r0
MediumALPINE-CVE-2018-20843expat@2.2.6-r02.2.7-r0
MediumALPINE-CVE-2019-15903expat@2.2.6-r02.2.7-r1
MediumALPINE-CVE-2019-15903python2@2.7.15-r32.7.17-r0
MediumGHSA-8w26-6f25-cm9xjackson-databind@2.9.42.9.10.8
MediumGHSA-v585-23hc-c647jackson-databind@2.9.42.9.10.8
MediumGHSA-6pcc-3rfx-4gpmdom4j@1.6.12.0.3
MediumGHSA-r695-7vr9-jgc2jackson-databind@2.9.42.9.10.8
MediumGHSA-8c4j-34r4-xr8gjackson-databind@2.9.42.9.10.8
MediumGHSA-89qr-369f-5m5xjackson-databind@2.9.42.9.10.8
MediumGHSA-cvm9-fjm9-3572jackson-databind@2.9.42.9.10.8
MediumGHSA-vfqx-33qm-g869jackson-databind@2.9.42.9.10.8
MediumGHSA-9m6f-7xcq-8vf8jackson-databind@2.9.42.9.10.8
MediumALPINE-CVE-2019-14697musl@1.1.20-r41.1.20-r5

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.9.2latest5 years ago19.3.01161162909,144

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/cloudnativeapp/gocd.svg)](https://charts.stackradar.io/charts/cloudnativeapp/gocd)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.