mealie Helm chart
geek-cookbookVerified publisherScored 14 Sept 2026
Mealie is a self hosted recipe manager and meal planner with a RestAPI backend and a reactive frontend application built in Vue for a pleasant user experience for the whole family.
Latest 5.1.2 4 years agodeploys tag frontend-v1.0.0beta-2 2Artifact Hub
mealie 5.1.2 deploys 2 container images: hkotel/mealie. Across them, 573 findings — 2 critical, 16 high — 6 on CISA KEV. The highest contribution is GHSA-j7hp-h8jx-5ppr in pillow 8.4.0, fixed in 10.0.1. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| hkotel/ | frontend-v1.0.0beta-2 | 01272299 | 4,842 |
| hkotel/ | api-v1.0.0beta-2 | 2450133 | 2,737 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 4.0.4 |
| Medium | GHSA-69cg-p879-7622 | golang.org/ | 0.0.0-20220906165146-f3363e06e74c |
| Medium | GHSA-wp53-j4wj-2cfg | python-multipart | 0.0.22 |
| Medium | GHSA-4wf5-vphf-c2xc | terser | 5.14.2 |
| Medium | GHSA-cx63-2mw6-8hw5 | setuptools | 70.0.0 |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | GHSA-74fj-2j2h-c42q | follow-redirects | 1.14.7 |
| Medium | GHSA-p77j-4mvh-x3m3 | google.golang.org/ | 1.79.3 |
| Medium | GHSA-c2qf-rxjj-qqgw | semver | 6.3.1 |
| Medium | GHSA-43fc-jf86-j433 | axios | 0.30.3 |
| Medium | DSA-5218-1 | zlib | 1:1.2.11.dfsg-2+deb11u2 |
| Medium | GHSA-qwmp-2cf2-g9g6 | wheel | 0.38.1 |
| Medium | GHSA-r683-j2x4-v87g | node-fetch | 2.6.7 |
| Medium | GHSA-r9hx-vwmv-q579 | setuptools | 65.5.1 |
| Medium | GHSA-gx9m-whjm-85jf | dompurify | 2.5.0 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | ALPINE-CVE-2023-3446 | openssl | 1.1.1u-r2 |
| Medium | GHSA-hhq3-ff78-jv3g | loader-utils | 2.0.4 |
| Medium | GHSA-j9fq-vwqv-2fm2 | parse-url | 8.1.0 |
| Medium | GHSA-3rfm-jhwj-7488 | loader-utils | 2.0.4 |
| Medium | GHSA-rp65-9cf3-cjxr | nth-check | 2.0.1 |
| Medium | GHSA-v973-fxgf-6xhp | mako | 1.2.2 |
| Medium | GHSA-3f63-hfp8-52jq | pillow | 10.2.0 |
| Medium | GHSA-p3vf-v8qc-cwcr | dompurify | 2.4.2 |
| Medium | GHSA-xrjj-mj9h-534m | golang.org/ | 0.4.0 |
| Medium | GHSA-f8q6-p94x-37v3 | minimatch | 3.0.5 |
| Medium | GHSA-fhg7-m89q-25r3 | ua-parser-js | 0.7.33 |
| Medium | GHSA-pw3c-h7wp-cvhx | pillow | 9.0.0 |
| Medium | GHSA-72xf-g2v4-qvf3 | tough-cookie | 4.1.3 |
| Medium | ALPINE-CVE-2022-2097 | openssl | 1.1.1q-r0 |
| Medium | GHSA-rc47-6667-2j5j | http-cache-semantics | 4.1.1 |
| Medium | GHSA-j8r2-6x86-q33q | requests | 2.31.0 |
| Medium | ALPINE-CVE-2023-5678 | openssl | 1.1.1w-r1 |
| Medium | GHSA-69ch-w2m2-3vjp | golang.org/ | 0.3.8 |
| Medium | PYSEC-2023-192 | urllib3 | 2.0.6 |
| Medium | GHSA-2jv5-9r88-3w3p | python-multipart | 0.0.7 |
| Medium | PYSEC-2024-38 | fastapi | 0.109.1 |
| Medium | GHSA-grv7-fg5c-xmjg | braces | 3.0.3 |
| Medium | PYSEC-2024-60 | idna | 3.7 |
| Medium | GHSA-3h5v-q93c-6h6q | ws | 8.17.1 |
| Medium | GHSA-pjwm-pj3p-43mv | axios | 0.32.0 |
| Medium | GHSA-74m5-2c7w-9w3x | starlette | 0.25.0 |
| Medium | GHSA-8r3f-844c-mc37 | google.golang.org/ | 1.33.0 |
| Medium | GHSA-9v9h-cgj8-h64p | cryptography | 42.0.2 |
| Medium | GHSA-m2vv-5vj5-2hm7 | pillow | 9.2.0 |
| Medium | GHSA-xrcv-f9gm-v42c | pillow | 9.0.0 |
| Medium | GHSA-9xgj-fcgf-x6mw | poetry | 1.1.9 |
| Medium | GHSA-jr5f-v2jv-69x6 | axios | 0.30.0 |
| Medium | GHSA-95m3-7q98-8xr5 | sha.js | 2.4.12 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 5.1.2latest | 4 years ago | frontend-v1.0.0beta-2 | 216122432 | 7,579 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.