opentelemetry-demo Helm chart
gpg-devScored 14 Sept 2026
opentelemetry demo helm chart
Latest 0.33.8 1 month agoapp version 1.12.0 0Artifact Hub
opentelemetry-demo 0.33.8 deploys 27 container images: grafana/grafana, jaegertracing/all-in-one, otel/opentelemetry-collector-contrib, quay.io/prometheus/prometheus and 5 more. Across them, 4,398 findings — 13 critical, 39 high — 4 on CISA KEV. The highest contribution is GHSA-f82v-jwr5-mffw in next 14.2.5, fixed in 14.2.25.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DLA-4275-1 | openjdk-17 | 17.0.16+8-1~deb11u1 |
| Low | DEBIAN-CVE-2023-25433 | tiff | 4.5.0-6+deb12u2 |
| Low | DEBIAN-CVE-2026-86140 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-41069 | libheif | no fix listed |
| Low | DEBIAN-CVE-2023-26966 | tiff | 4.5.0-6+deb12u2 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | ALPINE-CVE-2023-42366 | busybox | 1.36.1-r16 |
| Low | DSA-5998-1 | cups | 2.4.2-3+deb12u9 |
| Low | UBUNTU-CVE-2026-59847 | libssh | 0.10.6-2ubuntu0.5 |
| Low | GHSA-g94r-2vxg-569j | OpenTelemetry.Api | 1.15.3 |
| Low | GHSA-g94r-2vxg-569j | OpenTelemetry.Extensions.Propagators | 1.15.3 |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | GHSA-38f8-5428-x5cv | netty-codec-http | 4.1.133.Final |
| Low | GHSA-xq3w-v528-46rv | netty-common | 4.1.115.Final |
| Low | GHSA-28wg-ghj8-5hjv | nanoid | 3.3.16 |
| Low | UBUNTU-CVE-2026-3783 | curl | 8.5.0-2ubuntu10.8 |
| Low | UBUNTU-CVE-2026-4873 | curl | 8.5.0-2ubuntu10.9 |
| Low | DEBIAN-CVE-2023-39804 | tar | 1.34+dfsg-1.2+deb12u1 |
| Low | DEBIAN-CVE-2026-50257 | xorg-server | 2:21.1.7-3+deb12u13 |
| Low | DSA-6189-1 | libpng1.6 | 1.6.39-2+deb12u4 |
| Low | GHSA-8c42-7qj2-3j46 | netty-codec-http | 4.1.137.Final |
| Low | GO-2024-2609 | stdlib | 1.21.8 |
| Low | DEBIAN-CVE-2026-34743 | xz-utils | 5.4.1-1+deb12u1 |
| Low | GO-2024-3107 | stdlib | 1.22.7 |
| Low | DEBIAN-CVE-2026-5704 | tar | no fix listed |
| Low | GHSA-vc24-j8c5-2vw4 | OpenTelemetry.Resources.Azure | 1.15.1-beta.1 |
| Low | DEBIAN-CVE-2023-45913 | mesa | no fix listed |
| Low | ALPINE-CVE-2023-42365 | busybox | 1.36.1-r19 |
| Low | GHSA-r7wm-3cxj-wff9 | jackson-core | 2.18.8 |
| Low | DEBIAN-CVE-2026-22693 | harfbuzz | no fix listed |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | GHSA-2v37-7h3g-55p8 | nanoid | 3.3.18 |
| Low | DEBIAN-CVE-2026-3441 | binutils | no fix listed |
| Low | GHSA-ffqx-q65f-36jf | github.com/ | 2.10.3 |
| Low | GHSA-389x-839f-4rhx | netty-common | 4.1.118.Final |
| Low | DEBIAN-CVE-2026-3184 | util-linux | no fix listed |
| Low | DLA-4043-1 | openjdk-17 | 17.0.14+7-1~deb11u1 |
| Low | DEBIAN-CVE-2026-41079 | cups | no fix listed |
| Low | GHSA-2pr8-phx7-x9h3 | protobufjs | 7.5.6 |
| Low | GHSA-cp6g-7hqx-qxhp | go.mongodb.org/ | 1.17.7 |
| Low | GHSA-xmrv-pmrh-hhx2 | github.com/ | 1.97.3 |
| Low | GHSA-xmrv-pmrh-hhx2 | github.com/ | 1.43.5 |
| Low | GHSA-xmrv-pmrh-hhx2 | github.com/ | 1.7.8 |
| Low | DEBIAN-CVE-2026-58055 | nghttp2 | no fix listed |
| Low | DEBIAN-CVE-2023-26965 | tiff | 4.5.0-6+deb12u2 |
| Low | DEBIAN-CVE-2026-7010 | perl | no fix listed |
| Low | GHSA-4mp9-239f-g9hg | netty-codec-http | 4.1.136.Final |
| Low | DEBIAN-CVE-2026-19487 | perl | no fix listed |
| Low | DLA-4481-1 | libpng1.6 | 1.6.37-3+deb11u2 |
| Low | DEBIAN-CVE-2026-22801 | libpng1.6 | 1.6.39-2+deb12u2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.33.8latest | 1 month ago | 1.12.0 | 13397603,583 | 49,025 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.