elchi-stack 2.0.4 Helm chart
elchiScored 11 Oct 2026
A comprehensive Helm chart for deploying Elchi proxy management platform with UI, controller, control plane and registry components
Version 2.0.4 todayapp version v1.6.20 1Artifact Hub
elchi-stack 2.0.4 deploys 10 container images: library/busybox, jhonbrownn/elchi-backend, jhonbrownn/elchi-collector, jhonbrownn/elchi and 6 more. Across them, 1,331 findings — 12 critical, 24 high — 1 on CISA KEV. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 1.1.1f-1ubuntu2.23, fixed in 1.1.1f-1ubuntu2.fips.16. Chart.yaml declares kubeVersion >=1.21.0-0; rendered for Kubernetes 1.21.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.28 | 0000 | 0 |
| jhonbrownn/ | v1.6.20-v0.14.0-envoy1.39.3 | 0001 | 4 |
| jhonbrownn/ | v0.1.15 | 0001 | 4 |
| jhonbrownn/ | v1.5.35 | 0005 | 57 |
| envoyproxy/ | v1.39.3 | 123483 | 1,571 |
| grafana/ | 12.2.0 | 1052160 | 2,571 |
| otel/ | 0.89.0 | 2340149 | 2,521 |
| clickhouse/ | 24.8 | 3850147 | 3,095 |
| library/ | 6.0.12 | 38112341 | 6,032 |
| victoriametrics/ | v1.93.5 | 232793 | 1,819 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GO-2023-1753 | stdlib | 1.19.9 |
| Medium | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Medium | GO-2023-1878 | stdlib | 1.19.11 |
| Medium | GO-2022-0525 | stdlib | 1.17.12 |
| Medium | GHSA-hcg3-q754-cr77 | golang.org/ | 0.35.0 |
| Medium | USN-8093-1 | libssh | 0.9.6-2ubuntu0.22.04.7 |
| Medium | GO-2022-0520 | stdlib | 1.17.12 |
| Medium | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Medium | UBUNTU-CVE-2026-63072 | openssl | no fix listed |
| Medium | UBUNTU-CVE-2024-6873 | clickhouse | no fix listed |
| Medium | ALPINE-CVE-2025-69420 | openssl | 3.5.5-r0 |
| Medium | UBUNTU-CVE-2025-69420 | openssl | no fix listed |
| Medium | UBUNTU-CVE-2025-32988 | gnutls28 | no fix listed |
| Medium | UBUNTU-CVE-2026-8927 | curl | 7.81.0-1ubuntu1.25 |
| Medium | GHSA-8rm2-7qqf-34qm | github.com/ | 0.305.2 |
| Medium | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Medium | UBUNTU-CVE-2026-27135 | nghttp2 | 1.43.0-1ubuntu0.3 |
| Medium | UBUNTU-CVE-2026-33845 | gnutls28 | no fix listed |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | UBUNTU-CVE-2026-28388 | openssl | no fix listed |
| Medium | GHSA-mh2q-q3fh-2475 | go.opentelemetry.io/ | 1.41.0 |
| Medium | GHSA-6v2p-p543-phr9 | golang.org/ | 0.27.0 |
| Medium | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Medium | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | UBUNTU-CVE-2026-28387 | openssl | no fix listed |
| Medium | ALPINE-CVE-2026-33630 | c-ares | 1.34.8-r0 |
| Medium | GO-2026-4601 | stdlib | 1.25.8 |
| Medium | GO-2023-2409 | github.com/ | 1.5.1-0.20231206184617-48ba0b76bc88 |
| Medium | GHSA-xhj3-7xw9-vr34 | github.com/ | 0.142.0 |
| Medium | GO-2026-4981 | stdlib | 1.25.10 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |
| Medium | UBUNTU-CVE-2026-28389 | openssl | no fix listed |
| Medium | UBUNTU-CVE-2026-28390 | openssl | no fix listed |
| Medium | UBUNTU-CVE-2026-42010 | gnutls28 | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.0.4latest | today | v1.6.20 | 1224315980 | 17,674 |
| 2.0.2 | yesterday | v1.6.19 | 12243151,016 | 17,922 |
| 2.0.0 | 16 days ago | v1.6.16 | 12243221,040 | 18,376 |
| 1.13.0 | 2 months ago | v1.6.14 | 11263321,092 | 19,016 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.