StackRadar

spark-shuffle 0.2.0 Helm chart

duyet

Scored 14 Sept 2026

A Helm chart to deploy Spark shuffle service daemon set for Kubernetes

Version 0.2.0 1 month agodeploys tag v2.2.0-kubernetes-0.5.1 0Artifact Hub

spark-shuffle 0.2.0 deploys 1 container image: snappydatainc/spark-shuffle. Across them, 195 findings8 critical, 28 high. The highest contribution is GHSA-2qrg-x229-3v8q in log4j 1.2.17, with no fix listed.

Radar Score

5,63982812336

195 findings over 1 of 1 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
snappydatainc/spark-shufflev2.2.0-kubernetes-0.5.1828123365,639

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

195 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumALPINE-CVE-2018-5710krb5@1.15.2-r11.15.3-r0
MediumGHSA-qw69-rqj8-6qw8jetty-server@9.3.11.v201607219.4.51.v20230217
MediumALPINE-CVE-2019-5094e2fsprogs@1.43.7-r01.43.7-r1
MediumGHSA-h46c-h94j-95f3jackson-core@2.4.02.15.0
MediumGHSA-hxp5-8pgq-mgv9calcite-core@1.2.0-incubating1.26.0
MediumGHSA-w37g-rhq8-7m4jsnakeyaml@1.151.32
MediumGHSA-5mcr-gq6c-3hq2netty@3.9.9.Finalno fix listed
MediumGHSA-c8xf-m4ff-jcxjbcprov-jdk15on@1.541.56
MediumGHSA-3cqm-mf7h-prrjokhttp@3.8.14.9.2
LowALPINE-CVE-2018-1000654libtasn1@4.12-r24.12-r4
LowGHSA-77pm-w3hx-f8mjspark-hive-thriftserver_2.11@2.2.0-k8s-0.5.0no fix listed
LowGHSA-w33c-445m-f8w7okio@1.13.01.17.6
LowGHSA-8wv5-x4w7-5gwwlibthrift@0.9.30.24.0
LowGHSA-43xg-8wmj-cw8hspark-core_2.11@2.2.0-k8s-0.5.0no fix listed
LowGHSA-7pwc-h2j2-rjgjlibthrift@0.9.30.23.0
LowALPINE-CVE-2018-20217krb5@1.15.2-r11.15.4-r0
LowGHSA-h4h5-3hr4-j3g2protobuf-java@2.5.03.16.3
LowGHSA-hhhw-99gj-p3c3snakeyaml@1.151.31
LowGHSA-6xx3-rg99-gc3pbcprov-jdk15on@1.541.66
LowGHSA-v435-xc8x-wvr9bcprov-jdk15on@1.541.78
LowGHSA-8xfc-gm6g-vgpvbcprov-jdk15on@1.541.78
LowGHSA-wg6q-6289-32hpbcpkix-jdk15on@1.541.84
LowGHSA-hmr7-m48g-48f6jetty-http@9.3.11.v201607219.4.52
LowGHSA-wjxj-5m7g-mg7qbcprov-jdk15on@1.54no fix listed
LowGHSA-j26w-f9rq-mr2qjetty-servlets@9.3.11.v201607219.4.54
LowGHSA-72m5-fvvv-55m6bcprov-jdk15on@1.541.61
LowGHSA-fjqm-246c-mwqgbcprov-jdk15on@1.541.56
LowGHSA-4cx2-fc23-5wg6bcpkix-jdk15on@1.541.79
LowGHSA-hr8g-6v94-x4m9bcprov-jdk15on@1.54no fix listed
LowALPINE-CVE-2018-0495libressl@2.6.3-r02.6.5-r0
LowGHSA-4g9r-vxhx-9pgxcommons-compress@1.4.11.26.0
LowGHSA-8wh2-6qhj-h7j9snappy@0.20.5
LowGHSA-r7wm-3cxj-wff9jackson-core@2.4.02.18.8
LowGHSA-hgj6-7826-r7m5jackson-databind@2.6.52.18.8
LowGHSA-6mqq-8r44-vmjcspark-core_2.11@2.2.0-k8s-0.5.02.2.2
LowGHSA-qh8g-58pp-2wxhjetty-http@9.3.11.v2016072112.0.12
LowGHSA-3gh6-v5v9-6v9jjetty-servlets@9.3.11.v201607219.4.52
LowGHSA-m6cp-vxjx-65j6jetty-server@9.3.11.v201607219.4.41
LowGHSA-7g45-4rm6-3mm3guava@14.0.132.0.0-android
LowGHSA-5mg8-w23w-74h3guava@14.0.132.0.0-android
LowGHSA-wf8f-6423-gfxgjackson-core@2.4.02.13.0
LowGHSA-cj7v-27pg-wf7qjetty-http@9.3.11.v201607219.4.47
LowGHSA-p26g-97m4-6q7cjetty-server@9.3.11.v201607219.4.51.v20230217
LowGHSA-f5fw-25gw-5m92hadoop-common@2.7.33.4.0
LowALPINE-CVE-2018-10754ncurses@6.0_p20171125-r06.0_p20171125-r1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.2.0latest1 month agov2.2.0-kubernetes-0.5.1828123365,639

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/duyet/spark-shuffle.svg)](https://charts.stackradar.io/charts/duyet/spark-shuffle)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.