dependency-track 1.5.5 Helm chart
evryfs-ossVerified publisherScored 14 Sept 2026
Dependency-Track is an intelligent Software Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill-of-Materials (SBOM). This approach provides capabilities that traditional Software Composition Analysis (SCA) solutions cannot achieve.
Version 1.5.5 3 years agoapp version 4.6.3 9Artifact Hub
dependency-track 1.5.5 deploys 3 container images: dependencytrack/apiserver, dependencytrack/frontend and bitnami/postgresql. Across the 2 measured, 137 findings — 4 critical, 6 high — 3 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.83.1-r3, fixed in 8.4.0-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| dependencytrack/ | 4.6.3 | 113065 | 1,393 |
| dependencytrack/ | 4.6.1 | 35239 | 1,110 |
| bitnami/ | 11.13.0-debian-10-r40 | — | unmeasured |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Critical findings
Critical: findings whose contribution to the Radar Score is 70–100. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2023-38545 | curl | 8.4.0-r0 |
| Critical | ALPINE-CVE-2023-4863KEV | libwebp | 1.2.3-r2 |
| Critical | GHSA-mjmj-j48q-9wg2 | snakeyaml | 2.0 |
| Critical | ALPINE-CVE-2023-44487KEV | nghttp2 | 1.47.0-r2 |
Indexed versions
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.