opentelemetry-demo 0.33.8 Helm chart
gpg-devScored 14 Sept 2026
opentelemetry demo helm chart
Version 0.33.8 1 month agoapp version 1.12.0 0Artifact Hub
opentelemetry-demo 0.33.8 deploys 27 container images: grafana/grafana, jaegertracing/all-in-one, otel/opentelemetry-collector-contrib, quay.io/prometheus/prometheus and 5 more. Across them, 4,398 findings — 13 critical, 39 high — 4 on CISA KEV. The highest contribution is GHSA-f82v-jwr5-mffw in next 14.2.5, fixed in 14.2.25.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | GHSA-f82v-jwr5-mffw | next | 14.2.25 |
| Critical | GHSA-5rrx-jjjq-q2r5 | Microsoft.AspNetCore.App.Runtime.linux-x64 | 8.0.21 |
| Critical | DEBIAN-CVE-2025-27363KEV | freetype | 2.12.1+dfsg-5+deb12u4 |
| Critical | DEBIAN-CVE-2023-44487KEV | nginx | no fix listed |
| Critical | DEBIAN-CVE-2023-50387 | systemd | 252.23-1~deb12u1 |
| Critical | DEBIAN-CVE-2025-6965 | sqlite3 | 3.40.1-2+deb12u2 |
| Critical | DEBIAN-CVE-2023-50868 | systemd | 252.23-1~deb12u1 |
| Critical | DEBIAN-CVE-2024-2961 | glibc | 2.36-9+deb12u6 |
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | DEBIAN-CVE-2025-15467 | openssl | 3.0.18-1~deb12u2 |
| High | GHSA-vgq5-3255-v292 | kafka-clients | 3.9.1 |
| High | ALPINE-CVE-2024-6119 | openssl | 3.1.7-r0 |
| High | DEBIAN-CVE-2024-6119 | openssl | 3.0.14-1~deb12u2 |
| High | GHSA-gp8f-8m3g-qvj9 | next | 14.2.10 |
| High | GHSA-c4j6-fc7j-m34r | next | 15.5.16 |
| High | GHSA-4v7x-pqxf-cx7m | golang.org/ | 0.23.0 |
| High | DEBIAN-CVE-2024-28182 | nghttp2 | 1.52.0-1+deb12u2 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| High | ALPINE-CVE-2024-2511 | openssl | 3.1.4-r6 |
| High | DEBIAN-CVE-2024-2511 | openssl | 3.0.14-1~deb12u1 |
| High | UBUNTU-CVE-2024-3596 | krb5 | 1.20.1-6ubuntu2.3 |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | GHSA-22f2-v57c-j9cx | rack | 2.2.8.1 |
| Medium | DEBIAN-CVE-2024-7264 | curl | 7.88.1-10+deb12u7 |
| Medium | ALPINE-CVE-2024-5535 | openssl | 3.1.6-r0 |
| Medium | DEBIAN-CVE-2024-5535 | openssl | 3.0.15-1~deb12u1 |
| Medium | DEBIAN-CVE-2018-6951 | patch | no fix listed |
| Medium | DEBIAN-CVE-2026-42533 | nginx | no fix listed |
| Medium | DEBIAN-CVE-2018-6952 | patch | no fix listed |
| Medium | DSA-6113-1 | openssl | 3.0.18-1~deb12u2 |
| Medium | GHSA-rxg9-xrhp-64gj | System.Drawing.Common | 4.7.2 |
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | DEBIAN-CVE-2017-17740 | openldap | no fix listed |
| Medium | DEBIAN-CVE-2014-8166 | cups | no fix listed |
| Medium | DEBIAN-CVE-2026-45447 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | GHSA-v778-237x-gjrc | golang.org/ | 0.31.0 |
| Medium | DEBIAN-CVE-2023-6246 | glibc | 2.36-9+deb12u4 |
| Medium | DEBIAN-CVE-2017-16232 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2015-3276 | openldap | no fix listed |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | GHSA-p293-qw3h-jr36 | next | 15.5.24 |
| Medium | GHSA-7gfc-8cq8-jh5f | next | 14.2.15 |
| Medium | UBUNTU-CVE-2021-46848 | libtasn1-6 | 4.18.0-4ubuntu0.2 |
| Medium | GHSA-gjf6-3w4p-7xfh | Microsoft.NETCore.App.Runtime.linux-x64 | 8.0.12 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 2.5.4 |
| Medium | GHSA-2g68-c3qc-8985 | werkzeug | 3.0.3 |
| Medium | DEBIAN-CVE-2024-37371 | krb5 | 1.20.1-2+deb12u2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.33.8latest | 1 month ago | 1.12.0 | 13397603,583 | 49,025 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.