StackRadar

jenkins Helm chart

jenkins-x

Scored 14 Sept 2026

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Latest 0.10.38 7 years agoapp version 2.67 0Artifact Hub

jenkins 0.10.38 deploys 2 container images: jenkinsci/jenkins and gcr.io/jenkinsxio/jx. Across the 1 measured, 554 findings13 critical, 22 high 6 on CISA KEV. The highest contribution is GHSA-xvxq-hq48-xphm in script-security 1.18.1, fixed in 1.54.

Radar Score

10,6821322244275

554 findings over 1 of 2 images measured

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
jenkinsci/jenkins×22.67132224427510,682
gcr.io/jenkinsxio/jx2.0.645unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

275 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-jcwr-x25h-x5fhplexus-utils@3.0.173.0.24
LowDSA-4243-1cups@2.2.1-82.2.1-8+deb9u2
LowGHSA-7xp8-7wqx-5hqxjenkins-core@2.672.204.2
LowGHSA-qrh5-jg98-cr48jenkins-core@2.672.516.3
LowGHSA-f9qj-77q2-h5c5jenkins-core@2.672.462.3
LowGHSA-6p4f-wcwh-5vvmspring-webmvc@2.5.6.SEC03no fix listed
LowGHSA-qwgx-mrv5-87j8script-security@1.18.11172.v35f6a
LowGHSA-qh8g-58pp-2wxhjetty-http@9.4.5.v2017050212.0.12
LowGHSA-8hmv-92wm-39chjenkins-core@2.672.492.2
LowGHSA-62jv-j4w7-5hh8credentials@2.1.21371.1373.v4eb
LowGHSA-7p3p-8qv8-m2vhjetty-server@9.4.5.v20170502no fix listed
LowGHSA-m6cp-vxjx-65j6jetty-server@9.4.5.v201705029.4.41
LowGHSA-7g45-4rm6-3mm3guava@11.0.132.0.0-android
LowDLA-2898-1nss@2:3.26.2-1.12:3.26.2-1.1+deb9u5
LowGHSA-223m-4rfp-646hjenkins-core@2.672.516.3
LowGHSA-hq87-h4jg-vxfwjenkins-core@2.672.414.2
LowGHSA-qv64-w99c-qcr9jenkins-core@2.672.414.2
LowGHSA-463r-5m89-4xfrjenkins-core@2.672.555.3
LowDLA-3029-1cups@2.2.1-82.2.1-8+deb9u8
LowDLA-2361-1libx11@2:1.6.4-32:1.6.4-3+deb9u3
LowDSA-4462-1dbus@1.10.18-11.10.28-0+deb9u1
LowGHSA-5mg8-w23w-74h3guava@11.0.132.0.0-android
LowDLA-2830-1tar@1.29b-1.11.29b-1.1+deb9u1
LowGHSA-6x63-hrxg-2hjxexternal-monitor-job@1.4192.ve979ca_8b_3ccd
LowGHSA-957g-f97v-vppcspring-webmvc@2.5.6.SEC03no fix listed
LowGHSA-565r-pf5q-45v6jenkins-core@2.672.492.3
LowGHSA-wr6w-jxg7-qpfhjenkins-core@2.672.492.3
LowDLA-2312-1libx11@2:1.6.4-32:1.6.4-3+deb9u2
LowDLA-2951-1flac@1.3.2-11.3.2-2+deb9u2
LowDLA-3063-1systemd@232-25+deb9u1232-25+deb9u14
LowDLA-3047-1avahi@0.6.32-20.6.32-2+deb9u1
LowGHSA-jv82-75fh-23r7script-security@1.18.11368.vb
LowGHSA-cjpg-rgq5-fr37spring-webmvc@2.5.6.SEC03no fix listed
LowDSA-4134-1util-linux@2.29.2-12.29.2-1+deb9u1
LowGHSA-m6wv-wh8g-64xcjenkins-core@2.672.555.3
LowGHSA-rfh6-9r2q-98vfjenkins-core@2.672.492.2
LowGHSA-wfhp-qgm8-5p5cjenkins-core@2.672.541.2
LowGHSA-cj7v-27pg-wf7qjetty-http@9.4.5.v201705029.4.47
LowDLA-2487-1apt@1.4.71.4.11
LowGHSA-c9qp-6556-jwwpldap@1.11676.vfa
LowGHSA-3rqh-hch3-jhpcjenkins-core@2.672.555.3
LowGHSA-rrgp-c2w8-6vg6jenkins-core@2.672.375.4
LowGHSA-p3f5-98cv-562jjenkins-core@2.672.528.3
LowGHSA-92m7-4fpw-2wxmjenkins-core@2.672.555.3
LowGHSA-p26g-97m4-6q7cjetty-server@9.4.5.v201705029.4.51.v20230217
LowGHSA-g28p-6mcc-v4rvjenkins-core@2.672.555.3
LowGHSA-mw82-xcg6-gx79jenkins-core@2.672.555.3
LowGHSA-659m-px2c-25wjspring-core@2.5.6.SEC03no fix listed
LowGHSA-fxj7-6v9w-xc76jenkins-core@2.672.528.3
LowGHSA-p334-gfhq-c7w6script-security@1.18.11402.v94c9ce464861

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.10.38latest7 years ago2.67132224427510,682

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/jenkins-x/jenkins.svg)](https://charts.stackradar.io/charts/jenkins-x/jenkins)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.