openbao 0.19.0 Helm chart
gitlabVerified publisherScored 24 Sept 2026
A Helm chart to deploy OpenBao for GitLab
Version 0.19.0 todayapp version v2.6.2-gitlab1 2Artifact Hub
openbao 0.19.0 deploys 1 container image: registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao. Across them, 143 findings — 0 critical, 0 high. The highest contribution is DEBIAN-CVE-2019-1010022 in glibc 2.41-12+deb13u4, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| registry.gitlab.com/ | v2.6.2-gitlab1 | 0021122 | 1,455 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-15534 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-56391 | coreutils | no fix listed |
| Low | DEBIAN-CVE-2025-14017 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-38753 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-50812 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2026-18938 | p11-kit | no fix listed |
| Low | GHSA-gcjh-h69q-9w9g | github.com/ | 0.29.0 |
| Low | DEBIAN-CVE-2025-5278 | coreutils | no fix listed |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | GO-2025-3783 | github.com/ | no fix listed |
| Low | GO-2022-0646 | github.com/ | no fix listed |
| Low | DEBIAN-CVE-2025-6141 | ncurses | no fix listed |
| Low | GO-2026-5158 | go.opentelemetry.io/ | 1.42.0 |
| Low | DEBIAN-CVE-2010-4756 | glibc | no fix listed |
| Low | GO-2026-6303 | golang.org/ | 0.55.0 |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | DEBIAN-CVE-2026-15059 | systemd | no fix listed |
| Low | DEBIAN-CVE-2024-56433 | shadow | no fix listed |
| Low | DEBIAN-CVE-2011-4116 | perl | no fix listed |
| Low | DEBIAN-CVE-2026-89092 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-18374 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-16742 | systemd | no fix listed |
| Low | GO-2022-0635 | github.com/ | no fix listed |
| Low | DEBIAN-CVE-2025-15224 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-22185 | openldap | no fix listed |
| Low | DEBIAN-CVE-2026-42250 | bzip2 | no fix listed |
| Low | DEBIAN-CVE-2026-39113 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2026-76014 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-18508 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-38752 | busybox | no fix listed |
| Low | DEBIAN-CVE-2026-38755 | busybox | no fix listed |
| Low | DEBIAN-CVE-2007-5686 | shadow | no fix listed |
| Low | DEBIAN-CVE-2026-18477 | tar | no fix listed |
| Low | DEBIAN-CVE-2025-46394 | busybox | no fix listed |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6061 | google.golang.org/ | 1.82.1 |
| Low | GO-2026-6094 | github.com/ | 0.30.0 |
| Low | DEBIAN-CVE-2026-40228 | systemd | no fix listed |
| Low | DEBIAN-CVE-2026-95818 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-53910 | diffutils | no fix listed |
| Low | DEBIAN-CVE-2024-58251 | busybox | no fix listed |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.19.0latest | today | v2.6.2-gitlab1 | 0021122 | 1,455 |
| 0.18.1 | 27 days ago | v2.5.5-gitlab2 | 0024156 | 1,845 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.