drogue-cloud-core 0.7.11 Helm chart
drogue-iotVerified publisherScored 14 Sept 2026
Drogue IoT Cloud core installation
Version 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub
drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings — 141 critical, 193 high — 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-v897-pv23-r8cw | keycloak-quarkus-server | no fix listed |
| Low | RHSA-2025:20559 | shadow-utils | 2:4.9-15.el9 |
| Low | GHSA-vjr8-56p3-fmqq | keycloak-quarkus-server | 26.4.4 |
| Low | GHSA-8g9r-9wjw-37j4 | keycloak-services | no fix listed |
| Low | GHSA-5565-3c98-g6jc | wildfly-elytron-http-oidc | 2.2.9.Final |
| Low | GHSA-5565-3c98-g6jc | wildfly-elytron | 2.2.9.Final |
| Low | GHSA-gv3v-2cpp-3pmq | keycloak-quarkus-server | 26.5.6 |
| Low | RHSA-2026:61355 | dbus-broker | 0:28-9.el9_8 |
| Low | GHSA-fjf4-6f34-w64q | keycloak-services | no fix listed |
| Low | GHSA-4q93-v92x-p89f | keycloak-server-spi-private | no fix listed |
| Low | GHSA-4q93-v92x-p89f | keycloak-services | no fix listed |
| Low | GHSA-jgvc-jfgh-rjvv | jose4j | 0.9.3 |
| Low | GHSA-q4xq-445g-g6ch | keycloak-core | no fix listed |
| Low | RHSA-2026:61248 | libxml2 | 0:2.9.7-21.el8_10.7 |
| Low | GHSA-4pgc-gfrr-wcmg | keycloak-services | no fix listed |
| Low | GHSA-rhgq-f8x5-j2jc | keycloak-services | 26.4.12 |
| Low | GHSA-58qw-9mgm-455v | pip | 26.1 |
| Low | GHSA-5545-r4hg-rj4m | keycloak-quarkus-server | 26.0.6 |
| Low | GHSA-5v8v-xvjv-57x7 | keycloak-services | 26.4.13 |
| Low | GHSA-c25h-c27q-5qpv | keycloak-ldap-federation | 22.0.12 |
| Low | RHSA-2026:66403 | coreutils | 0:8.32-41.el9_8.1 |
| Low | RHSA-2025:12748 | glibc | 0:2.34-168.el9_6.23 |
| Low | GHSA-7fpj-9hr8-28vh | keycloak-services | 22.0.10 |
| Low | GHSA-63v5-26vq-m4vm | keycloak-services | no fix listed |
| Low | GHSA-gg57-587f-h5v6 | infinispan-core | 14.0.25.Final |
| Low | GHSA-gg57-587f-h5v6 | infinispan-client-hotrod | 14.0.25.Final |
| Low | GHSA-gg57-587f-h5v6 | infinispan-cachestore-remote | 14.0.25.Final |
| Low | GHSA-gg57-587f-h5v6 | infinispan-commons | 14.0.25.Final |
| Low | GHSA-22rm-wp4x-v5cx | keycloak-services | 26.4.13 |
| Low | GHSA-m2w5-7xhv-w6fh | keycloak-services | no fix listed |
| Low | GHSA-w573-9ffj-6ff9 | netty-transport-native-epoll | 4.1.135.Final |
| Low | GHSA-g78x-7vwx-9f58 | keycloak-services | 26.4.9 |
| Low | GHSA-j75r-vf64-6rrh | resteasy-reactive-common | 3.0.0.Alpha4 |
| Low | GHSA-6q37-7866-h27j | keycloak-services | 26.5.0 |
| Low | GHSA-6g26-7cx5-mrrg | keycloak-services | 26.7.0 |
| Low | GHSA-594w-2fwp-jwrc | keycloak-services | no fix listed |
| Low | GHSA-xh32-c9wx-phrp | keycloak-services | no fix listed |
| Low | GHSA-7g5x-9c4v-4w5r | keycloak-services | 26.4.4 |
| Low | GHSA-fghv-69vj-qj49 | netty-codec-http | 4.1.125.Final |
| Low | GHSA-8hc5-rmgf-qx6p | keycloak-services | 23.0.1 |
| Low | GHSA-8hc5-rmgf-qx6p | keycloak-ldap-federation | 23.0.1 |
| Low | RHSA-2026:39317 | libxml2 | 0:2.9.13-14.el9_8.2 |
| Low | GHSA-6vgw-5pg2-w6jp | pip | 26.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.7.11latest | 3 years ago | 0.11.0 | 1411938501,639 | 55,666 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.