mealie Helm chart
geek-cookbookVerified publisherScored 14 Sept 2026
Mealie is a self hosted recipe manager and meal planner with a RestAPI backend and a reactive frontend application built in Vue for a pleasant user experience for the whole family.
Latest 5.1.2 4 years agodeploys tag frontend-v1.0.0beta-2 2Artifact Hub
mealie 5.1.2 deploys 2 container images: hkotel/mealie. Across them, 573 findings — 2 critical, 16 high — 6 on CISA KEV. The highest contribution is GHSA-j7hp-h8jx-5ppr in pillow 8.4.0, fixed in 10.0.1. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| hkotel/ | frontend-v1.0.0beta-2 | 01272299 | 4,842 |
| hkotel/ | api-v1.0.0beta-2 | 2450133 | 2,737 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-34jh-p97f-mpxf | urllib3 | 1.26.19 |
| Low | GHSA-qj8w-gfj5-8c6v | serialize-javascript | 7.0.5 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | GHSA-w8wr-v893-vjvp | tar | 7.5.18 |
| Low | GO-2023-1705 | stdlib | 1.19.8 |
| Low | GHSA-m7pr-hjqh-92cm | axios | 0.31.1 |
| Low | GHSA-cfw5-2vxh-hr84 | devalue | 5.6.4 |
| Low | GO-2023-1878 | stdlib | 1.19.11 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GHSA-49q7-c7j4-3p7m | elliptic | 6.5.7 |
| Low | GHSA-hpcv-96wg-7vj8 | dompurify | 3.4.6 |
| Low | GO-2022-1039 | stdlib | 1.18.7 |
| Low | DSA-5349-1 | gnutls28 | 3.7.1-5+deb11u3 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GO-2023-1702 | stdlib | 1.19.8 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | DLA-4432-1 | curl | 7.74.0-1.3+deb11u16 |
| Low | GHSA-fj7v-r99m-22gq | pillow | 12.3.0 |
| Low | DLA-3910-1 | e2fsprogs | 1.46.2-2+deb11u1 |
| Low | GHSA-894q-wpg5-mf2h | pyrdfa3 | 3.6.2 |
| Low | GHSA-mmx7-hfxf-jppx | axios | 0.33.0 |
| Low | GO-2022-0525 | stdlib | 1.17.12 |
| Low | GO-2022-0520 | stdlib | 1.17.12 |
| Low | MAL-2022-4691 | monorepo-symlink-test | no fix listed |
| Low | DSA-5678-1 | glibc | 2.31-13+deb11u10 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | GHSA-r47g-fvhr-h676 | dompurify | 3.4.6 |
| Low | DLA-4267-1 | gnutls28 | 3.7.1-5+deb11u8 |
| Low | GHSA-2c2j-9gv5-cj73 | starlette | 0.47.2 |
| Low | DLA-4063-1 | gnutls28 | 3.7.1-5+deb11u7 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GO-2023-2375 | stdlib | 1.20.0 |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | GO-2023-1569 | stdlib | 1.19.6 |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | GHSA-cm22-4g7w-348p | serve-static | 1.16.0 |
| Low | GHSA-cpwx-vrp4-4pq7 | jinja2 | 3.1.6 |
| Low | GHSA-crv5-9vww-q3g8 | dompurify | 3.4.0 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | GO-2022-1143 | stdlib | 1.18.9 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | PYSEC-2022-42980 | pillow | 9.3.0 |
| Low | GHSA-434g-2637-qmqr | elliptic | 6.5.6 |
| Low | GO-2022-1038 | stdlib | 1.18.7 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 5.1.2latest | 4 years ago | frontend-v1.0.0beta-2 | 216122432 | 7,579 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.