StackRadar

hiver 0.1.45 Helm chart

hiverVerified publisher

Scored 14 Sept 2026

Hiver control plane (controller + Envoy gateway) plus the per-service sandbox pools. The gateway's per-service Envoy routes/clusters and the Deployment+Service are both generated from a single .Values.sandboxServices map, so adding a service is one entry. Each service selects its runtime isolation (microvm or container) with a per-service isolation field.

Version 0.1.45 1 month agoapp version 0.1.45 1Artifact Hub

hiver 0.1.45 deploys 10 container images: hiversh/controller, hiversh/gateway, hiversh/antigravity, hiversh/browser and 6 more. Across them, 2,317 findings0 critical, 3 high. The highest contribution is UBUNTU-CVE-2025-15467 in openssl 3.0.2-0ubuntu1.20, fixed in 3.0.2-0ubuntu1.21.

Radar Score

21,672032322,082

2,317 findings over 10 of 10 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
hiversh/controller0.1.4500192092,082
hiversh/gateway0.1.4503371131,878
hiversh/antigravity0.1.45-microvm00222202,214
hiversh/browser0.1.45-microvm00222202,214
hiversh/claude0.1.45-microvm00222202,214
hiversh/codex0.1.45-microvm00222202,214
hiversh/copilot0.1.45-microvm00222202,214
hiversh/node0.1.45-alpine-microvm00222202,214
hiversh/openclaw0.1.45-microvm00222202,214
hiversh/python0.1.45-3.13-alpine-microvm00222202,214

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

341 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumUBUNTU-CVE-2025-32988gnutls28@3.7.3-4ubuntu1.7no fix listed
MediumDEBIAN-CVE-2017-11695nss@2:3.87.1-1+deb12u3no fix listed
MediumDEBIAN-CVE-2017-11696nss@2:3.87.1-1+deb12u3no fix listed
MediumDEBIAN-CVE-2017-11698nss@2:3.87.1-1+deb12u3no fix listed
MediumDEBIAN-CVE-2024-36623docker.io@20.10.24+dfsg1-1+deb12u1+b6no fix listed
MediumUBUNTU-CVE-2026-28389openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.23
MediumUBUNTU-CVE-2026-28390openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.23
MediumUBUNTU-CVE-2026-33845gnutls28@3.7.3-4ubuntu1.73.7.3-4ubuntu1.9
MediumDEBIAN-CVE-2019-1010025glibc@2.36-9+deb12u14no fix listed
LowUBUNTU-CVE-2025-69420openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.21
LowDEBIAN-CVE-2026-57433perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-13221perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2026-42496perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2024-29018docker.io@20.10.24+dfsg1-1+deb12u1+b6no fix listed
LowUBUNTU-CVE-2026-9076openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.25
LowDEBIAN-CVE-2026-12087perl@5.36.0-7+deb12u3no fix listed
LowDEBIAN-CVE-2025-1352elfutils@0.188-2.1no fix listed
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.80.01.83.1
LowUBUNTU-CVE-2026-0915glibc@2.35-0ubuntu3.112.35-0ubuntu3.13
LowDEBIAN-CVE-2023-50495ncurses@6.4-4no fix listed
LowGHSA-r277-6w6q-xmqwgithub.com/getkin/kin-openapi@v0.135.00.144.0
LowDEBIAN-CVE-2026-63072openssl@3.0.20-1~deb12u2no fix listed
LowUBUNTU-CVE-2026-45445openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.25
LowDEBIAN-CVE-2026-85091zlib@1:1.2.13.dfsg-1no fix listed
LowDEBIAN-CVE-2017-11697nss@2:3.87.1-1+deb12u3no fix listed
LowGO-2023-2102stdlib@go1.19.81.20.10
LowDEBIAN-CVE-2025-52565runc@1.1.5+ds1-1+deb12u1no fix listed
LowDEBIAN-CVE-2025-52881runc@1.1.5+ds1-1+deb12u1no fix listed
LowUBUNTU-CVE-2026-42013gnutls28@3.7.3-4ubuntu1.73.7.3-4ubuntu1.9
LowUBUNTU-CVE-2026-0861glibc@2.35-0ubuntu3.112.35-0ubuntu3.13
LowDEBIAN-CVE-2024-2236libgcrypt20@1.10.1-3+deb12u1no fix listed
LowUBUNTU-CVE-2026-31789openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.23
LowUBUNTU-CVE-2025-69419openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.21
LowDEBIAN-CVE-2023-5388nss@2:3.87.1-1+deb12u3no fix listed
LowDEBIAN-CVE-2026-54874openssl@3.0.20-1~deb12u2no fix listed
LowUBUNTU-CVE-2026-42766openssl@3.0.2-0ubuntu1.203.0.2-0ubuntu1.25
LowUBUNTU-CVE-2025-32990gnutls28@3.7.3-4ubuntu1.7no fix listed
LowDEBIAN-CVE-2026-33997docker.io@20.10.24+dfsg1-1+deb12u1+b6no fix listed
LowDEBIAN-CVE-2026-86145pcre2@10.42-110.42-1+deb12u1
LowGHSA-xhj3-7xw9-vr34github.com/getkin/kin-openapi@v0.135.00.142.0
LowUBUNTU-CVE-2023-47039perl@5.34.0-3ubuntu1.5no fix listed
LowUBUNTU-CVE-2025-15281glibc@2.35-0ubuntu3.112.35-0ubuntu3.13
LowDEBIAN-CVE-2026-33748docker.io@20.10.24+dfsg1-1+deb12u1+b6no fix listed
LowUBUNTU-CVE-2026-42011gnutls28@3.7.3-4ubuntu1.73.7.3-4ubuntu1.9
LowUBUNTU-CVE-2024-12243gnutls28@3.7.3-4ubuntu1.7no fix listed
LowUBUNTU-CVE-2025-32989gnutls28@3.7.3-4ubuntu1.7no fix listed
LowDEBIAN-CVE-2026-9538perl@5.36.0-7+deb12u3no fix listed
LowUBUNTU-CVE-2025-6395gnutls28@3.7.3-4ubuntu1.7no fix listed
LowDEBIAN-CVE-2025-7458sqlite3@3.40.1-2+deb12u2no fix listed
LowGHSA-mmfr-pmjx-hw9wgithub.com/getkin/kin-openapi@v0.135.00.141.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.45latest1 month ago0.1.45032322,08221,672

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/hiver/hiver.svg)](https://charts.stackradar.io/charts/hiver/hiver)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.