csgship Helm chart
csghubVerified publisherScored 15 Sept 2026
AI-based code intelligent generation
Latest 0.4.6 7 days agoapp version v0.4.0 0Artifact Hub
csgship 0.4.6 deploys 10 container images: envoyproxy/gateway, opencsghq/stakater-reloader, opencsghq/csgship-agentic, opencsghq/psql and 6 more. Across them, 1,042 findings — 3 critical, 9 high — 5 on CISA KEV. The highest contribution is GHSA-7488-6r32-c95q in litellm 1.60.4, fixed in 1.84.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| envoyproxy/ | v1.7.5 | 00946 | 520 |
| opencsghq/ | v1.4.19 | 00012 | 81 |
| opencsghq/ | v0.4.0 | 1318100 | 1,551 |
| opencsghq/ | latest | 111759 | 1,018 |
| casbin/ | 3.62.1 | 0026152 | 1,798 |
| opencsghq/ | v1.2.1 | 011659 | 840 |
| opencsghq/ | v0.4.0 | 1438193 | 2,936 |
| library/ | latest | 0000 | 0 |
| opencsghq/ | 15.19 | 0018160 | 1,597 |
| library/ | 7.4.11 | 001493 | 1,061 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-89161 | pcre2 | 10.46-1~deb13u2 |
| Low | GO-2026-5026 | golang.org/ | 0.55.0 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | DEBIAN-CVE-2025-14104 | util-linux | no fix listed |
| Low | ALPINE-CVE-2025-64505 | libpng | 1.6.53-r0 |
| Low | DEBIAN-CVE-2026-86142 | libxml2 | no fix listed |
| Low | GHSA-428g-f7cq-pgp5 | marshmallow | 3.26.2 |
| Low | GO-2026-4342 | stdlib | 1.24.12 |
| Low | DEBIAN-CVE-2026-78409 | util-linux | no fix listed |
| Low | DLA-4492-1 | gnutls28 | 3.7.1-5+deb11u9 |
| Low | ALPINE-CVE-2024-13176 | openssl | 3.3.2-r5 |
| Low | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Low | GHSA-537c-gmf6-5ccf | cryptography | 48.0.1 |
| Low | GHSA-pcgw-qcv5-h8ch | github.com/ | 0.11.0 |
| Low | GHSA-mf24-chxh-hmvj | github.com/ | 1.2.7 |
| Low | ALPINE-CVE-2026-45446 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-7009 | curl | 8.20.0-r0 |
| Low | GHSA-22xc-xg2r-9j7v | github.com/ | 1.7.4 |
| Low | GHSA-rrqc-c2jx-6jgv | django | 5.0.9 |
| Low | GO-2026-4870 | stdlib | 1.25.9 |
| Low | GO-2025-4009 | stdlib | 1.24.8 |
| Low | DEBIAN-CVE-2026-86138 | libxml2 | no fix listed |
| Low | GO-2026-4947 | stdlib | 1.25.9 |
| Low | DEBIAN-CVE-2026-86143 | libxml2 | no fix listed |
| Low | GO-2026-5061 | golang.org/ | 0.43.0 |
| Low | GO-2026-5062 | golang.org/ | 0.43.0 |
| Low | GHSA-rg2x-37c3-w2rh | github.com/ | no fix listed |
| Low | GO-2025-4006 | stdlib | 1.24.8 |
| Low | ALPINE-CVE-2026-56412 | expat | 2.8.2-r0 |
| Low | GO-2026-5037 | stdlib | 1.25.11 |
| Low | GO-2026-4971 | stdlib | 1.25.10 |
| Low | ALPINE-CVE-2026-14672 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-50219 | expat | 2.8.2-r0 |
| Low | GHSA-fpwr-67px-3qhx | transformers | 4.50.0 |
| Low | ALPINE-CVE-2026-56409 | expat | 2.8.2-r0 |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | ALPINE-CVE-2026-27171 | zlib | 1.3.2-r0 |
| Low | DEBIAN-CVE-2026-27171 | zlib | no fix listed |
| Low | DEBIAN-CVE-2017-14159 | openldap | no fix listed |
| Low | DEBIAN-CVE-2026-50813 | sqlite3 | no fix listed |
| Low | PYSEC-2026-56 | django-allauth | 65.14.1 |
| Low | ALPINE-CVE-2026-32777 | expat | 2.7.5-r0 |
| Low | GO-2026-5038 | stdlib | 1.25.11 |
| Low | DEBIAN-CVE-2017-18018 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2026-86139 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-13757 | p11-kit | no fix listed |
| Low | GO-2026-5942 | stdlib | 1.26.6 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.4.6latest | 7 days ago | v0.4.0 | 39156874 | 11,402 |
| 0.4.5 | 11 days ago | v0.4.0 | 39157880 | 11,478 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.