StackRadar

amundsen Helm chart

duyet

Scored 14 Sept 2026

Amundsen is a metadata driven application for improving the productivity of data analysts, data scientists and engineers when interacting with data.

Latest 1.1.0 1 month agodeploys tag 2.1.1 0Artifact Hub

amundsen 1.1.0 deploys 7 container images: amundsendev/amundsen-frontend, amundsendev/amundsen-metadata, appropriate/curl, library/neo4j and 3 more. Across the 5 measured, 684 findings2 critical, 22 high 2 on CISA KEV. The highest contribution is ALPINE-CVE-2020-15999 in freetype 2.9.1-r2, fixed in 2.9.1-r3.

Radar Score

11,174222245415

684 findings over 5 of 7 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

7 images
ImageTagVulnerabilitiesRadar Score
amundsendev/amundsen-frontend2.1.1091141934,917
amundsendev/amundsen-metadata2.5.401391072,039
appropriate/curllatest0591551
library/neo4j3.3.02643241,758
amundsendev/amundsen-search2.4.00140901,909
bitnami/os-shell×412-debian-12-r16unmeasured
bitnami/elasticsearch×88.12.2-debian-12-r0unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

451 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalALPINE-CVE-2020-15999KEVfreetype@2.9.1-r22.9.1-r3
CriticalALPINE-CVE-2019-8457sqlite@3.26.0-r33.28.0-r0
HighGHSA-jpcq-cgw6-v4j6KEVjquery@3.4.13.5.0
HighGHSA-gxr4-xjj5-5px2jquery@3.4.13.5.0
HighGHSA-c4w7-xm78-47vhy18n@3.2.13.2.2
HighGHSA-x4qr-2fvf-3mr5cryptography@2.939.0.1
HighGHSA-j544-7q9p-6xp8werkzeug@0.15.30.15.5
HighGHSA-26vr-8j45-3r4wjetty-server@9.2.22.v201706069.4.39
HighALPINE-CVE-2021-23840openssl@1.1.1b-r11.1.1j-r0
HighALPINE-CVE-2018-0732libressl@2.6.3-r02.6.5-r0
HighGHSA-6x9x-8qw9-9pp6jetty-server@9.2.22.v201706069.2.25.v20180606
HighALPINE-CVE-2019-5482curl@7.59.0-r07.61.1-r3
HighGHSA-vgg8-72f2-qm23jetty-server@9.2.22.v201706069.2.25.v20180606
HighALPINE-CVE-2021-3449openssl@1.1.1b-r11.1.1k-r0
HighALPINE-CVE-2019-3822curl@7.59.0-r07.61.1-r2
HighGHSA-r5fr-rjxr-66jclodash@4.17.154.18.0
HighALPINE-CVE-2018-14618curl@7.59.0-r07.61.1-r0
HighGHSA-w573-4hg7-7wgqdecode-uri-component@0.2.00.2.1
HighGHSA-3jfq-g458-7qm9tar@2.2.23.2.2
HighGHSA-35jh-r3h4-6jhmlodash@4.17.154.17.21
HighALPINE-CVE-2019-12900bzip2@1.0.6-r61.0.6-r7
HighALPINE-CVE-2019-5481curl@7.59.0-r07.61.1-r3
HighGHSA-f2jv-r9rf-7988handlebars@4.5.34.7.7
MediumGHSA-hrpp-h998-j3ppqs@6.5.26.5.3
MediumDSA-5169-1openssl@1.1.1d-0+deb10u31.1.1n-0+deb10u3
MediumALPINE-CVE-2018-0500curl@7.59.0-r07.61.0-r0
MediumDLA-3807-1glibc@2.28-102.28-10+deb10u3
MediumGHSA-8q59-q68h-6hv4pyyaml@5.3.15.4
MediumDSA-4963-1openssl@1.1.1d-0+deb10u31.1.1d-0+deb10u7
MediumGHSA-mc84-pj99-q6hhcommons-compress@1.121.21
MediumALPINE-CVE-2018-16839curl@7.59.0-r07.61.1-r1
MediumDSA-5139-1openssl@1.1.1d-0+deb10u31.1.1n-0+deb10u2
MediumGHSA-crv7-7245-f45fcommons-compress@1.121.21
MediumGHSA-7hfm-57qf-j43qcommons-compress@1.121.21
MediumDLA-3449-1openssl@1.1.1d-0+deb10u31.1.1n-0+deb10u5
MediumDSA-5103-1openssl@1.1.1d-0+deb10u31.1.1d-0+deb10u8
MediumALPINE-CVE-2018-1000301curl@7.59.0-r07.60.0-r0
MediumALPINE-CVE-2018-1000300curl@7.59.0-r07.60.0-r0
MediumGHSA-xqfj-vm6h-2x34commons-compress@1.121.21
MediumGHSA-xvch-5gv4-984hminimist@1.2.01.2.6
MediumGHSA-765h-qjxv-5f44handlebars@4.5.34.7.7
MediumGHSA-www2-v7xj-xrc6urllib3@1.221.23
MediumDSA-4875-1openssl@1.1.1d-0+deb10u31.1.1d-0+deb10u6
MediumDLA-3325-1openssl@1.1.1d-0+deb10u31.1.1n-0+deb10u4
MediumGHSA-896r-f27r-55mwjson-schema@0.2.30.4.0
MediumGHSA-cph5-m8f7-6c5xaxios@0.19.00.21.2
MediumALPINE-CVE-2019-5018sqlite@3.26.0-r33.28.0-r0
MediumGHSA-p979-4mfw-53vgnetty-all@4.1.15.Final4.1.42.Final
MediumDSA-4661-1openssl@1.1.1d-0+deb10u21.1.1d-0+deb10u3
MediumGHSA-9c47-m6qq-7p4hjson5@1.0.11.0.2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.0latest1 month ago2.1.122224541511,174

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/duyet/amundsen.svg)](https://charts.stackradar.io/charts/duyet/amundsen)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.