galaxy 6.8.6 Helm chart
cloudveScored 15 Sept 2026
Chart for Galaxy, an open, web-based platform for accessible, reproducible, and transparent computational biomedical research.
Version 6.8.6 3 days agoapp version 26.1.1 0Artifact Hub
galaxy 6.8.6 deploys 3 container images: quay.io/galaxyproject/galaxy-min, library/nginx and tusproject/tusd. Across them, 516 findings — 0 critical, 9 high — 5 on CISA KEV. The highest contribution is ALPINE-CVE-2024-6119 in openssl 3.1.2-r0, fixed in 3.1.7-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| quay.io/ | 26.1.1 | 0026271 | 2,951 |
| library/ | 1.22.0 | 041059 | 967 |
| tusproject/ | v1.13.0 | 0520120 | 1,634 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2026-5029 | golang.org/ | 0.55.0 |
| Low | GO-2026-5030 | golang.org/ | 0.55.0 |
| Low | GHSA-58qw-9mgm-455v | pip | 26.1 |
| Low | DEBIAN-CVE-2026-42250 | bzip2 | no fix listed |
| Low | DEBIAN-CVE-2026-39113 | sqlite3 | no fix listed |
| Low | GHSA-6jv3-5f52-599m | python-multipart | 0.0.30 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | DEBIAN-CVE-2026-27456 | util-linux | 2.41.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-18508 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-89160 | pcre2 | 10.46-1~deb13u2 |
| Low | DLA-4319-1 | libxml2 | 2.9.10+dfsg-6.7+deb11u9 |
| Low | DLA-4437-1 | gnupg2 | 2.2.27-2+deb11u3 |
| Low | DEBIAN-CVE-2024-26461 | krb5 | no fix listed |
| Low | GHSA-g75f-g53v-794x | bleach | no fix listed |
| Low | DEBIAN-CVE-2007-5686 | shadow | no fix listed |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | DEBIAN-CVE-2026-18477 | tar | no fix listed |
| Low | DEBIAN-CVE-2024-26458 | krb5 | no fix listed |
| Low | DEBIAN-CVE-2026-53612 | util-linux | 2.41.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-53613 | util-linux | 2.41.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-53614 | util-linux | 2.41.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-53615 | util-linux | 2.41.5-0+deb13u1 |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | DLA-3972-1 | tzdata | 2024b-0+deb11u1 |
| Low | DLA-4016-1 | ucf | 3.0043+deb11u2 |
| Low | DLA-4085-1 | tzdata | 2025a-0+deb11u1 |
| Low | DLA-4105-1 | tzdata | 2025b-0+deb11u1 |
| Low | DLA-4213-1 | curl | 7.74.0-1.3+deb11u15 |
| Low | DLA-4403-1 | tzdata | 2025b-0+deb11u2 |
| Low | DLA-4485-1 | ca-certificates | 20230311+deb12u1~deb11u1 |
| Low | GO-2023-2153 | google.golang.org/ | 1.56.3 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6061 | google.golang.org/ | 1.82.1 |
| Low | RUSTSEC-2026-0173 | proc-macro-error2 | no fix listed |
| Low | RUSTSEC-2026-0186 | memmap2 | 0.9.11 |
| Low | RUSTSEC-2026-0204 | crossbeam-epoch | 0.9.20 |
| Low | RUSTSEC-2026-0221 | event-listener | 5.4.2 |
| Low | RUSTSEC-2026-0258 | h2 | 0.4.16 |
| Low | DEBIAN-CVE-2026-40228 | systemd | no fix listed |
| Low | GHSA-6vgw-5pg2-w6jp | pip | 26.0 |
| Low | DEBIAN-CVE-2026-53910 | diffutils | no fix listed |
| Low | DEBIAN-CVE-2023-31439 | systemd | no fix listed |
| Low | DEBIAN-CVE-2023-31437 | systemd | no fix listed |
| Low | DEBIAN-CVE-2023-31438 | systemd | no fix listed |
| Low | DEBIAN-CVE-2026-89162 | pcre2 | 10.46-1~deb13u2 |
| Low | DEBIAN-CVE-2026-89156 | pcre2 | 10.46-1~deb13u2 |
| Low | DEBIAN-CVE-2026-28422 | vim | no fix listed |
| Low | GHSA-wwv5-g3v4-889x | tornado | 6.5.8 |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 6.8.6latest | 3 days ago | 26.1.1 | 0956450 | 5,552 |
| 6.8.5 | 6 days ago | 26.1.1 | 0956450 | 5,552 |
| 6.8.4 | 17 days ago | 26.1.1 | 0956450 | 5,552 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.