drogue-cloud-core Helm chart
drogue-iotVerified publisherScored 14 Sept 2026
Drogue IoT Cloud core installation
Latest 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub
drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings — 141 critical, 193 high — 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | RHSA-2024:0647 | rpm | 0:4.14.3-28.el8_9 |
| Low | RHSA-2025:7067 | krb5 | 0:1.21.1-6.el9 |
| Low | GHSA-794g-x443-36f7 | keycloak-services | no fix listed |
| Low | GHSA-w4p5-rfh6-cwrv | keycloak-services | 26.6.2 |
| Low | GHSA-32h4-44jj-c5vx | keycloak-services | 26.6.4 |
| Low | RHSA-2026:36733 | cups | 1:2.2.6-68.el8_10 |
| Low | GHSA-7xf9-4jfc-wgm4 | keycloak-services | 26.5.6 |
| Low | RHSA-2026:4772 | glibc | 0:2.28-251.el8_10.31 |
| Low | GHSA-cphf-4846-3xx9 | vertx-core | 4.5.24 |
| Low | GHSA-jpmx-996v-48fm | wildfly-elytron-http-oidc | 2.2.5.Final |
| Low | GHSA-wv3h-x6c4-r867 | keycloak-services | 26.4.9 |
| Low | RHSA-2026:16799 | krb5 | 0:1.18.2-34.el8_10 |
| Low | RHSA-2026:19357 | krb5 | 0:1.21.1-10.el9_8 |
| Low | GHSA-hq3p-w4xv-x7vp | keycloak-services | 26.6.2 |
| Low | GHSA-xxqh-mfjm-7mv9 | netty-codec-http | 4.1.133.Final |
| Low | GHSA-2326-hx7g-3m9r | sshd-common | 2.12.0 |
| Low | GHSA-h5fg-jpgr-rv9c | vertx-web | 4.5.22 |
| Low | GHSA-5cc8-pgp5-7mpm | keycloak-core | 21.1.2 |
| Low | GHSA-fccg-mwvh-qqg4 | netty-handler | 4.1.137.Final |
| Low | GHSA-4cx2-fc23-5wg6 | bcpkix-jdk15on | 1.79 |
| Low | GHSA-hr8g-6v94-x4m9 | bcprov-jdk15on | no fix listed |
| Low | RHSA-2024:2512 | file | 0:5.39-16.el9 |
| Low | ALPINE-CVE-2023-28322 | curl | 8.1.0-r0 |
| Low | RHSA-2026:6473 | python3 | 0:3.6.8-75.el8_10 |
| Low | GHSA-q4f6-jm68-57ww | netty-codec-http | 4.1.136.Final |
| Low | GHSA-4vc8-pg5c-vg4x | keycloak-services | 24.0.1 |
| Low | GHSA-3677-xxcr-wjqv | jose4j | 0.9.6 |
| Low | GHSA-9vm7-v8wj-3fqw | keycloak-core | 23.0.4 |
| Low | RHSA-2024:1784 | gnutls | 0:3.6.16-8.el8_9.3 |
| Low | RHSA-2024:1879 | gnutls | 0:3.7.6-23.el9_3.4 |
| Low | RHSA-2024:2570 | gnutls | 0:3.8.3-4.el9_4 |
| Low | RHSA-2026:39315 | libsolv | 0:0.7.24-6.el9_8 |
| Low | GHSA-mv64-86g8-cqq7 | resteasy-reactive | 3.2.11.Final |
| Low | RHSA-2023:7836 | avahi | 0:0.7-21.el8_9.1 |
| Low | RHSA-2026:20597 | glibc | 0:2.34-270.el9_8 |
| Low | GHSA-6cqp-g7gg-8hr5 | netty-codec-http | 4.1.136.Final |
| Low | RHSA-2023:0340 | bash | 0:5.1.8-6.el9_1 |
| Low | GHSA-53jx-vvf9-4x38 | vertx-web | 4.3.8 |
| Low | RHSA-2026:42733 | glibc | 0:2.28-251.el8_10.40 |
| Low | RHSA-2026:42952 | glibc | 0:2.34-274.el9_8 |
| Low | GHSA-rr5q-3xwr-f323 | keycloak-services | 26.6.3 |
| Low | GHSA-rr5q-3xwr-f323 | keycloak-server-spi-private | 26.6.3 |
| Low | GHSA-4x37-hw65-52w8 | keycloak-services | 26.6.2 |
| Low | GHSA-m4cv-j2px-7723 | netty-codec-http | 4.1.133.Final |
| Low | RHSA-2026:0596 | cups | 1:2.2.6-66.el8_10 |
| Low | GHSA-f8h5-v2vg-46rr | quarkus-core | 3.2.12.Final |
| Low | RHSA-2026:4188 | gnutls | 0:3.8.3-10.el9_7 |
| Low | RHSA-2026:5585 | gnutls | 0:3.6.16-8.el8_10.5 |
| Low | ALPINE-CVE-2022-35252 | curl | 7.80.0-r3 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.7.11latest | 3 years ago | 0.11.0 | 1411938501,639 | 55,666 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.