StackRadar

drogue-cloud-examples Helm chart

drogue-iotVerified publisher

Scored 14 Sept 2026

Installation of examples on top of Drogue IoT Cloud

Latest 0.7.11 3 years agodeploys tag 9.2.4 0Artifact Hub

drogue-cloud-examples 0.7.11 deploys 6 container images: ghcr.io/ctron/kubectl, grafana/grafana, ghcr.io/drogue-iot/postgresql-pusher, ghcr.io/drogue-iot/drogue-event-source and 2 more. Across the 5 measured, 2,299 findings21 critical, 56 high 12 on CISA KEV. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 3.0.2-0ubuntu1.2, fixed in 3.0.2-0ubuntu1.5. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.

Radar Score

30,69921564671,755

2,299 findings over 5 of 6 images measured

KEV ×12 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/ctron/kubectl1.2526321632,528
grafana/grafana9.2.406371982,839
ghcr.io/drogue-iot/postgresql-pusher0.2.141145662,637
ghcr.io/drogue-iot/drogue-event-source0.2.141145662,637
timescale/timescaledb-ha×2pg14-ts2.6-latest11223081,26220,058
bitnami/postgresql14unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

1,869 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2019-20005netcdf@1:4.8.1-1no fix listed
LowUBUNTU-CVE-2019-20198netcdf@1:4.8.1-1no fix listed
LowUBUNTU-CVE-2019-20199netcdf@1:4.8.1-1no fix listed
LowUBUNTU-CVE-2019-20200netcdf@1:4.8.1-1no fix listed
LowUBUNTU-CVE-2019-20201netcdf@1:4.8.1-1no fix listed
LowUBUNTU-CVE-2019-20202netcdf@1:4.8.1-1no fix listed
LowUBUNTU-CVE-2022-37050poppler@22.02.0-222.02.0-2ubuntu0.3
LowUBUNTU-CVE-2026-82209curl@7.81.0-1ubuntu1.2no fix listed
LowUBUNTU-CVE-2022-38784poppler@22.02.0-222.02.0-2ubuntu0.1
LowUBUNTU-CVE-2025-21518mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.41-0ubuntu0.22.04.1
LowUBUNTU-CVE-2026-14664postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2026-14670postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2026-15742postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2023-21980mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.33-0ubuntu0.22.04.1
LowGHSA-mw99-9chc-xw7rgithub.com/go-git/go-git/v5@v5.4.25.11.0
LowUBUNTU-CVE-2026-6664pgbouncer@1.17.0-3.pgdg22.04+1no fix listed
LowUBUNTU-CVE-2022-25972hdf5@1.10.7+repack-4ubuntu2no fix listed
LowRHSA-2022:5311libgcrypt@1.8.5-6.el80:1.8.5-7.el8_6
LowUBUNTU-CVE-2018-15671hdf5@1.10.7+repack-4ubuntu2no fix listed
LowUBUNTU-CVE-2022-37052poppler@22.02.0-222.02.0-2ubuntu0.3
LowUBUNTU-CVE-2022-38349poppler@22.02.0-222.02.0-2ubuntu0.3
LowGO-2023-1571stdlib@go1.19.31.19.6
LowUBUNTU-CVE-2023-2283libssh@0.9.6-2build10.9.6-2ubuntu0.22.04.1
LowUBUNTU-CVE-2026-4224python3.10@3.10.4-33.10.12-1~22.04.16
LowUBUNTU-CVE-2026-19385postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2024-20973mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.36-0ubuntu0.22.04.1
LowUBUNTU-CVE-2024-20977mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.36-0ubuntu0.22.04.1
LowUBUNTU-CVE-2024-25269libheif@1.12.0-2build11.12.0-2ubuntu0.1~esm2
LowUBUNTU-CVE-2025-21574mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.42-0ubuntu0.22.04.1
LowUBUNTU-CVE-2026-14671postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2026-14677postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2026-14680postgresql-14@14.3-1.pgdg22.04+114.24-0ubuntu0.22.04.1
LowUBUNTU-CVE-2025-66418python-urllib3@1.26.5-1~exp11.26.5-1~exp1ubuntu0.4
LowUBUNTU-CVE-2025-66471python-urllib3@1.26.5-1~exp11.26.5-1~exp1ubuntu0.4
LowUBUNTU-CVE-2022-25942hdf5@1.10.7+repack-4ubuntu2no fix listed
LowUBUNTU-CVE-2025-21522mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.41-0ubuntu0.22.04.1
LowGHSA-7rg2-cxvp-9p7pgithub.com/prometheus/exporter-toolkit@v0.7.10.7.2
LowUBUNTU-CVE-2026-7210python3.10@3.10.4-3no fix listed
LowUBUNTU-CVE-2026-12087perl@5.34.0-3ubuntu15.34.0-3ubuntu1.8
LowGHSA-vv39-3w5q-974qk8s.io/kubernetes@v1.25.161.29.13
LowUBUNTU-CVE-2025-8715postgresql-14@14.3-1.pgdg22.04+114.19-0ubuntu0.22.04.1
LowUBUNTU-CVE-2025-21500mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.41-0ubuntu0.22.04.1
LowUBUNTU-CVE-2025-21501mysql-8.0@8.0.29-0ubuntu0.22.04.28.0.41-0ubuntu0.22.04.1
LowUBUNTU-CVE-2023-47038perl@5.34.0-3ubuntu15.34.0-3ubuntu1.3
LowUBUNTU-CVE-2022-3599tiff@4.3.0-64.3.0-6ubuntu0.2
LowUBUNTU-CVE-2022-3598tiff@4.3.0-64.3.0-6ubuntu0.2
LowUBUNTU-CVE-2023-29469libxml2@2.9.13+dfsg-1ubuntu0.12.9.13+dfsg-1ubuntu0.3
LowRHSA-2023:4524libcap@2.26-5.el80:2.48-5.el8_8
LowUBUNTU-CVE-2023-2603libcap2@1:2.44-1build31:2.44-1ubuntu0.22.04.1
LowGHSA-jqcq-xjh3-6g23github.com/jackc/pgproto3/v2@v2.0.0no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.11latest3 years ago9.2.421564671,75530,699

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/drogue-iot/drogue-cloud-examples.svg)](https://charts.stackradar.io/charts/drogue-iot/drogue-cloud-examples)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.