spinnaker 2.2.6 Helm chart
dwardu-helm-chartsScored 14 Sept 2026
Open source, multi-cloud continuous delivery platform for releasing software changes with high velocity and confidence.
Version 2.2.6 5 years agodeploys tag 5.0.7-debian-10-r0 1Artifact Hub
spinnaker 2.2.6 deploys 2 container images: bitnami/redis and gcr.io/spinnaker-marketplace/halyard. Across the 1 measured, 366 findings — 15 critical, 39 high — 9 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-webmvc 5.2.3.RELEASE, fixed in 5.2.20.RELEASE.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnami/ | 5.0.7-debian-10-r0 | — | unmeasured |
| gcr.io/ | 1.32.0 | 1539174138 | 8,752 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-rc42-6c7j-7h5r | spring-boot | no fix listed |
| Low | GHSA-wg6q-6289-32hp | bcpkix-jdk15on | 1.84 |
| Low | GHSA-4h8f-2wvx-gg5w | bcprov-jdk15on | 1.78 |
| Low | GHSA-42wg-hm62-jcwg | tomcat-embed-core | 9.0.106 |
| Low | GHSA-wjxj-5m7g-mg7q | bcprov-ext-jdk15on | 1.73 |
| Low | GHSA-wjxj-5m7g-mg7q | bcprov-jdk15on | no fix listed |
| Low | GHSA-r5w3-xv2f-j59q | spring-expression | no fix listed |
| Low | ALPINE-CVE-2021-23839 | openssl | 1.1.1j-r0 |
| Low | GHSA-m4p7-r5rc-7g4j | pyasn1 | 0.6.4 |
| Low | GHSA-269g-pwp5-87pp | junit | 4.13.1 |
| Low | GHSA-m8wh-mqgf-rr8g | client-java | 11.0.1 |
| Low | GHSA-8ppf-4f7h-5ppj | pyasn1 | 0.6.4 |
| Low | GHSA-hm4w-wwcw-mr6r | pyasn1 | 0.6.4 |
| Low | ALPINE-CVE-2020-14344 | libx11 | 1.6.10-r0 |
| Low | ALPINE-CVE-2021-22898 | curl | 7.67.0-r4 |
| Low | GHSA-2rmj-mq67-h97g | spring-web | 5.3.38 |
| Low | GHSA-xxqh-mfjm-7mv9 | netty-codec-http | 4.1.133.Final |
| Low | GHSA-9m3c-qcxr-9x87 | tomcat-embed-core | 9.0.116 |
| Low | GHSA-fccg-mwvh-qqg4 | netty-handler | 4.1.137.Final |
| Low | GHSA-4cx2-fc23-5wg6 | bcpkix-jdk15on | 1.79 |
| Low | GHSA-hw42-3568-wj87 | google-oauth-client | 1.33.3 |
| Low | GHSA-hr8g-6v94-x4m9 | bcprov-ext-jdk15on | no fix listed |
| Low | GHSA-hr8g-6v94-x4m9 | bcprov-jdk15on | no fix listed |
| Low | GHSA-775g-4xr8-78h8 | spring-expression | no fix listed |
| Low | GHSA-q4f6-jm68-57ww | netty-codec-http | 4.1.136.Final |
| Low | ALPINE-CVE-2020-28928 | musl | 1.1.24-r3 |
| Low | GHSA-rfmp-97jj-h8m6 | spring-core | 5.2.18 |
| Low | GHSA-x83m-pf6f-pf9g | hibernate-validator | 6.2.0.Final |
| Low | GHSA-6cqp-g7gg-8hr5 | netty-codec-http | 4.1.136.Final |
| Low | GHSA-m4cv-j2px-7723 | netty-codec-http | 4.1.133.Final |
| Low | GHSA-34jh-p97f-mpxf | urllib3 | 1.26.19 |
| Low | GHSA-pr98-23f8-jwxv | logback-core | 1.3.15 |
| Low | ALPINE-CVE-2021-42374 | busybox | 1.31.1-r11 |
| Low | GHSA-jhq6-gfmj-v8fx | logback-core | 1.5.34 |
| Low | GHSA-4gc7-5j7h-4qph | spring-web | no fix listed |
| Low | GHSA-4gc7-5j7h-4qph | spring-context | no fix listed |
| Low | GHSA-c2gf-v879-257j | netty-codec-http2 | 4.1.135.Final |
| Low | GHSA-hqvf-45jj-mccq | awscli | 1.45.28 |
| Low | GHSA-4g9r-vxhx-9pgx | commons-compress | 1.26.0 |
| Low | GHSA-84h7-rjj3-6jx4 | netty-codec-http | 4.1.129.Final |
| Low | GHSA-c69g-56f8-xwqj | netty-codec-http2 | 4.1.136.Final |
| Low | GHSA-72pg-x5f8-j25j | spring-webmvc | no fix listed |
| Low | GHSA-mq64-j8f9-9gcj | spring-webmvc | no fix listed |
| Low | GHSA-38f8-5428-x5cv | netty-codec-http | 4.1.133.Final |
| Low | GHSA-xq3w-v528-46rv | netty-common | 4.1.115.Final |
| Low | GHSA-6gf2-pvqw-37ph | spring-core | 5.2.19 |
| Low | GHSA-8c42-7qj2-3j46 | netty-codec-http | 4.1.137.Final |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.18.8 |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | GHSA-389x-839f-4rhx | netty-common | 4.1.118.Final |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.2.6latest | 5 years ago | 5.0.7-debian-10-r0 | 1539174138 | 8,752 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.