drogue-cloud-core Helm chart
drogue-iotVerified publisherScored 14 Sept 2026
Drogue IoT Cloud core installation
Latest 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub
drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings — 141 critical, 193 high — 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | RHSA-2023:7151 | python3 | 0:3.6.8-56.el8_9 |
| Medium | RHSA-2023:7176 | python-pip | 0:9.0.3-23.el8 |
| Medium | RHSA-2024:0889 | oniguruma | 0:6.8.2-2.1.el8_9 |
| Medium | RHSA-2023:0339 | sqlite | 0:3.34.1-6.el9_1 |
| Medium | RHSA-2022:8637 | krb5 | 0:1.19.1-24.el9_1 |
| Medium | ALPINE-CVE-2022-32221 | curl | 7.80.0-r4 |
| Medium | RHSA-2026:36331 | nginx | 2:1.20.1-28.el9_8.4 |
| Medium | GHSA-fhw8-8j55-vwgq | sshd-common | 2.9.2 |
| Medium | ALPINE-CVE-2022-4304 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2022-40304 | libxml2 | 2.9.14-r2 |
| Medium | RHSA-2023:0833 | python3 | 0:3.6.8-48.el8_7.1 |
| Medium | RHSA-2026:25239 | openssl | 1:3.5.5-4.el9_8 |
| Medium | ALPINE-CVE-2022-1586 | pcre2 | 10.40-r0 |
| Medium | ALPINE-CVE-2022-32205 | curl | 7.80.0-r2 |
| Medium | ALPINE-CVE-2022-1587 | pcre2 | 10.40-r0 |
| Medium | RHSA-2023:6699 | krb5 | 0:1.21.1-1.el9 |
| Medium | ALPINE-CVE-2023-0215 | openssl | 1.1.1t-r0 |
| Medium | RHSA-2026:26275 | openssl | 1:1.1.1k-16.el8_6 |
| Medium | RHSA-2024:2447 | openssl | 1:3.0.7-27.el9 |
| Medium | ALPINE-CVE-2022-42915 | curl | 7.80.0-r4 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r2 |
| Medium | RHSA-2026:66542 | nginx | 2:1.20.1-28.el9_8.6 |
| Medium | GHSA-2cww-fgmg-4jqc | keycloak-services | 24.0.5 |
| Medium | ALPINE-CVE-2023-32002 | nodejs | 16.20.2-r0 |
| Medium | ALPINE-CVE-2023-27534 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2022-32208 | curl | 7.80.0-r2 |
| Medium | ALPINE-CVE-2022-35255 | nodejs | 16.17.1-r0 |
| Medium | RHSA-2024:0310 | openssl | 1:3.0.7-25.el9_3 |
| Medium | ALPINE-CVE-2022-27406 | freetype | 2.11.1-r2 |
| Medium | GHSA-98qh-xjc8-98pq | postgresql | 42.7.11 |
| Medium | ALPINE-CVE-2023-27533 | curl | 8.0.1-r0 |
| Medium | RHSA-2023:7877 | openssl | 1:1.1.1k-12.el8_9 |
| Medium | GHSA-cx63-2mw6-8hw5 | setuptools | 70.0.0 |
| Medium | RHSA-2024:5530 | python-setuptools | 0:39.2.0-8.el8_10 |
| Medium | RHSA-2023:2523 | openssl | 1:3.0.7-6.el9_2 |
| Medium | GHSA-gpvv-69j7-gwj8 | pip | 19.2 |
| Medium | ALPINE-CVE-2022-27782 | curl | 7.80.0-r2 |
| Medium | ALPINE-CVE-2022-27405 | freetype | 2.11.1-r2 |
| Medium | GHSA-jjjh-jjxp-wpff | jackson-databind | 2.13.4.2 |
| Medium | GHSA-rgv9-q543-rqg4 | jackson-databind | 2.13.4 |
| Medium | ALPINE-CVE-2022-27781 | curl | 7.80.0-r2 |
| Medium | RHSA-2024:7848 | openssl | 1:1.1.1k-14.el8_6 |
| Medium | RHSA-2025:10698 | libxml2 | 0:2.9.7-21.el8_10.1 |
| Medium | RHSA-2025:10699 | libxml2 | 0:2.9.13-10.el9_6 |
| Medium | ALPINE-CVE-2022-2309 | libxml2 | 2.9.14-r1 |
| Medium | GHSA-r9hx-vwmv-q579 | setuptools | 65.5.1 |
| Medium | ALPINE-CVE-2023-32006 | nodejs | 16.20.2-r0 |
| Medium | ALPINE-CVE-2023-28319 | curl | 8.1.0-r0 |
| Medium | ALPINE-CVE-2022-27780 | curl | 7.80.0-r2 |
| Medium | RHSA-2023:0337 | expat | 0:2.4.9-1.el9_1.1 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.7.11latest | 3 years ago | 0.11.0 | 1411938501,639 | 55,666 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.