StackRadar

dapr-agents 0.1.5 Helm chart

dapr-agents-devVerified publisher

Scored 14 Sept 2026

A comprehensive developer stack for working with Dapr Agents as well as Observability & Traceability of AI Agents.

Version 0.1.5 6 months agodeploys tag v1.10.2 0Artifact Hub

dapr-agents 0.1.5 deploys 31 container images: quay.io/prometheus/node-exporter, grafana/loki-canary, ghcr.io/dapr/operator, ghcr.io/dapr/sentry and 27 more. Across the 29 measured, 2,287 findings0 critical, 6 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.

Radar Score

22,193062901,991

2,287 findings over 29 of 31 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

31 images
ImageTagVulnerabilitiesRadar Score
quay.io/prometheus/node-exporterv1.10.200563574
grafana/loki-canary3.6.500768657
ghcr.io/dapr/operator1.17.0-rc.300665634
ghcr.io/dapr/sentry1.17.0-rc.300665634
ghcr.io/dapr/injector1.17.0-rc.300665634
mcp/grafanalatest00141111,181
ghcr.io/kagent-dev/kagent/tools0.0.1300171491,521
ghcr.io/kagent-dev/kmcp/controller0.2.200257440
ghcr.io/kagent-dev/doc2vec/mcp1.1.140118801,104
cr.kagent.dev/kagent-dev/kagent/controller0.7.14unmeasured
cr.kagent.dev/kagent-dev/kagent/ui0.7.14unmeasured
quay.io/kiwigrid/k8s-sidecar×22.5.0011951878
grafana/grafana12.3.300361532,075
registry.k8s.io/kube-state-metrics/kube-state-metricsv2.18.000665618
quay.io/prometheus-operator/prometheus-operatorv0.88.100145333
nginxinc/nginx-unprivileged1.29-alpine0021681,085
otel/opentelemetry-collector-contrib0.145.0001196954
public.ecr.aws/diagrid-dev/diagrid-dashboardlatest00030193
library/nginxalpine000434
library/redis×26.20014931,049
redis/redisinsightlatest0112751,038
ghcr.io/dapr/placement1.17.0-rc.300665634
ghcr.io/dapr/scheduler1.17.0-rc.300668652
library/memcached×21.6.39-alpine011730674
prom/memcached-exporter×2v0.15.400562561
grafana/loki3.6.500775724
kiwigrid/k8s-sidecar1.30.9012552999
grafana/tempo2.9.000898923
library/busyboxlatest00000
registry.k8s.io/kubectlv1.31.00115951,098
ghcr.io/jkroepke/kube-webhook-certgen×21.7.700043292

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

643 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-12064curl@8.17.0-r18.22.0-r0
LowGHSA-mwp4-54f8-5fhrip-address@9.0.510.3.1
LowALPINE-CVE-2026-8932curl@8.17.0-r18.22.0-r0
LowGHSA-8xwf-rjm4-xvhvoras.land/oras-go/v2@v2.6.02.6.1
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowALPINE-CVE-2026-8286curl@8.17.0-r18.22.0-r0
LowGHSA-wf93-45jw-7689pip@25.226.1.2
LowALPINE-CVE-2026-75803openssl@3.5.4-r03.5.8-r0
LowDEBIAN-CVE-2026-75803openssl@3.0.20-1~deb12u2no fix listed
LowGHSA-4x4m-3c2p-qppck8s.io/kubernetes@v1.29.31.31.12
LowGHSA-r6q2-hw4h-h46wtar@7.4.37.5.4
LowGHSA-2883-xcg3-v3hhjs-yaml@4.1.14.3.2
LowGHSA-p436-gjf2-799pgithub.com/docker/cli@v28.3.3+incompatible29.2.0
LowCGA-3m2c-2p7h-jh79glibc@2.42-r42.43-r6
LowGHSA-jxpm-75mh-9fp7oras.land/oras-go/v2@v2.6.02.6.1
LowCGA-2r44-vqvm-32fwnodejs-25@25.2.1-r025.3.0-r0
LowGHSA-r292-9mhp-454mtar@7.4.37.5.21
LowALPINE-CVE-2025-15468openssl@3.5.4-r03.5.5-r0
LowDEBIAN-CVE-2026-48959perl@5.36.0-7+deb12u3no fix listed
LowCGA-2gxw-5ffj-x2phglibc@2.42-r42.43-r7
LowDEBIAN-CVE-2026-5928glibc@2.36-9+deb12u14no fix listed
LowGHSA-pjcq-xvwq-hhpjgithub.com/Azure/go-ntlmssp@v0.0.0-20220621081337-cb9428e4ac1e0.1.1
LowGHSA-3wgm-2gw2-vh5mk8s.io/kubernetes@v1.29.3no fix listed
LowCGA-pg7p-jc78-5qw9glibc@2.42-r42.43-r10
LowDEBIAN-CVE-2026-6791glibc@2.36-9+deb12u14no fix listed
LowDEBIAN-CVE-2022-27943gcc-12@12.2.0-14+deb12u1no fix listed
LowGHSA-v53g-5gjp-272rhelm.sh/helm/v3@v0.0.0-20250905035149-3d8990f083663.14.1
LowALPINE-CVE-2026-8458curl@8.17.0-r18.22.0-r0
LowGHSA-wg65-39gg-5wfjgithub.com/prometheus/prometheus@v0.306.00.311.3
LowALPINE-CVE-2026-6253curl@8.17.0-r18.20.0-r0
LowGHSA-w5hq-g745-h8pquuid@8.3.211.1.1
LowGHSA-m4p7-r5rc-7g4jpyasn1@0.6.10.6.4
LowGHSA-w4pp-8pjf-rmxwpacote@20.0.021.5.1
LowGHSA-74j8-88mm-7496k8s.io/kubernetes@v0.0.0-20240813072848-9edcffcde559no fix listed
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.6.10.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.6.10.6.4
LowGHSA-9ppj-qmqm-q256tar@7.4.37.5.11
LowCGA-28jr-9938-gm2mglibc@2.42-r42.43-r4
LowGO-2026-4341stdlib@go1.24.111.24.12
LowCGA-4xwj-9j26-j9vvnodejs-25@25.2.1-r025.3.0-r0
LowGHSA-5xqw-8hwv-wg92helm.sh/helm/v3@v0.0.0-20250905035149-3d8990f083663.17.3
LowALPINE-CVE-2026-9547curl@8.17.0-r18.22.0-r0
LowDEBIAN-CVE-2025-8941pam@1.5.2-6+deb12u2no fix listed
LowGHSA-hcxc-wf8j-23hvgithub.com/openfga/openfga@v1.11.31.18.0
LowDEBIAN-CVE-2026-57432perl@5.36.0-7+deb12u3no fix listed
LowGHSA-jqh4-m9w3-8hp9axios@1.16.01.18.0
LowALPINE-CVE-2026-6276curl@8.17.0-r18.20.0-r0
LowGHSA-fxhp-mv3v-67qporas.land/oras-go/v2@v2.6.02.6.2
LowGHSA-4hfp-h4cw-hj8phelm.sh/helm/v3@v0.0.0-20250905035149-3d8990f083663.17.3
LowGHSA-wc9g-mqfw-jrwmmulter@2.0.22.3.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.5latest6 months agov1.10.2062901,99122,193

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/dapr-agents-dev/dapr-agents.svg)](https://charts.stackradar.io/charts/dapr-agents-dev/dapr-agents)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.