grocy Helm chart
geek-cookbookVerified publisherScored 14 Sept 2026
ERP beyond your fridge - grocy is a web-based self-hosted groceries & household management solution for your home
Latest 8.5.2 4 years agoapp version version-v3.1.3 0Artifact Hub
grocy 8.5.2 deploys 1 container image: linuxserver/grocy. Across them, 58 findings — 0 critical, 4 high — 1 on CISA KEV. The highest contribution is GHSA-jpcq-cgw6-v4j6 in jquery 3.3.1, fixed in 3.5.0. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| linuxserver/ | version-v3.1.3 | 042430 | 1,043 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-jpcq-cgw6-v4j6KEV | jquery | 3.5.0 |
| High | GHSA-gxr4-xjj5-5px2 | jquery | 3.5.0 |
| High | GHSA-6c3j-c64m-qhgq | jquery | 3.4.0 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| Medium | GHSA-hrpp-h998-j3pp | qs | 6.5.3 |
| Medium | GHSA-9v3m-8fp8-mj99 | bootstrap | 4.3.1 |
| Medium | GHSA-896r-f27r-55mw | json-schema | 0.4.0 |
| Medium | GHSA-8hfj-j24r-96c4 | moment | 2.29.2 |
| Medium | GHSA-wc69-rhjr-hc9g | moment | 2.29.4 |
| Medium | GHSA-h68q-55jf-x68w | chart.js | 2.9.4 |
| Medium | GHSA-446m-mv8f-q348 | moment | 2.19.3 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 2.5.4 |
| Medium | GHSA-m7j4-fhg6-xf5v | datatables.net | 1.10.22 |
| Medium | GHSA-pj7m-g53m-7638 | bootstrap | 4.1.2 |
| Medium | GHSA-3wqf-4x89-9g79 | bootstrap | 4.1.2 |
| Medium | GHSA-7mvr-5x2g-wfc8 | bootstrap | 4.1.2 |
| Medium | GHSA-25mq-v84q-4j7r | guzzlehttp/ | 7.4.5 |
| Medium | GHSA-f2wf-25xc-69c9 | guzzlehttp/ | 7.4.4 |
| Medium | GHSA-w248-ffj2-4v5q | guzzlehttp/ | 7.4.4 |
| Medium | GHSA-xvf7-4v9q-58w6 | jpeg-js | 0.4.4 |
| Medium | GHSA-72xf-g2v4-qvf3 | tough-cookie | 4.1.3 |
| Medium | GHSA-q559-8m2m-g699 | guzzlehttp/ | 7.4.5 |
| Medium | GHSA-cwmx-hcrq-mhc3 | guzzlehttp/ | 7.4.3 |
| Medium | GHSA-h73q-5wmj-q8pj | datatables.net | 1.11.3 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-q7rv-6hp3-vh96 | guzzlehttp/ | 2.1.1 |
| Medium | GHSA-6c9x-mj3g-h47x | swagger-ui-dist | 4.1.3 |
| Low | GHSA-m4ch-4m5f-2gp6 | bootbox | no fix listed |
| Low | GHSA-hmw2-7cc7-3qxx | form-data | 2.5.6 |
| Low | GHSA-q2qj-628g-vhfw | slim/ | 1.5.1 |
| Low | GHSA-66hf-2p6w-jqfw | illuminate/ | 8.75.0 |
| Low | GHSA-wxmh-65f7-jcvw | guzzlehttp/ | 2.4.5 |
| Low | GHSA-j3f9-p6hm-5w6q | nesbot/ | 2.72.6 |
| Low | GHSA-2g4f-4pwh-qvx6 | ajv | 6.14.0 |
| Low | GHSA-p8p7-x288-28g6 | request | no fix listed |
| Low | GHSA-w5hq-g745-h8pq | uuid | 11.1.1 |
| Low | GHSA-cc55-mvqc-g9mg | summernote | no fix listed |
| Low | GHSA-v5mv-p594-2x33 | guzzlehttp/ | 7.15.2 |
| Low | GHSA-h95v-h523-3mw8 | guzzlehttp/ | 7.15.1 |
| Low | GHSA-wm3w-8rrp-j577 | guzzlehttp/ | 7.15.1 |
| Low | GHSA-cwxw-98qj-8qjx | guzzlehttp/ | 7.12.1 |
| Low | GHSA-4mjr-xmp4-gh2g | qs | 6.16.0 |
| Low | GHSA-53h4-8rc4-f539 | slim/ | 4.15.2 |
| Low | GHSA-f7vp-7xgx-4w4r | guzzlehttp/ | 7.15.2 |
| Low | GHSA-f283-ghqc-fg79 | guzzlehttp/ | 7.15.1 |
| Low | GHSA-94pj-82f3-465w | guzzlehttp/ | 7.14.2 |
| Low | GHSA-wpwq-4j6v-78m3 | guzzlehttp/ | 7.12.1 |
| Low | GHSA-34xg-wgjx-8xph | guzzlehttp/ | 2.10.2 |
| Low | GHSA-hq7v-mx3g-29hw | guzzlehttp/ | 2.10.2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 8.5.2latest | 4 years ago | version-v3.1.3 | 042430 | 1,043 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.