StackRadar

jenkins Helm chart

jenkins-x

Scored 14 Sept 2026

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Latest 0.10.38 7 years agoapp version 2.67 0Artifact Hub

jenkins 0.10.38 deploys 2 container images: jenkinsci/jenkins and gcr.io/jenkinsxio/jx. Across the 1 measured, 554 findings13 critical, 22 high 6 on CISA KEV. The highest contribution is GHSA-xvxq-hq48-xphm in script-security 1.18.1, fixed in 1.54.

Radar Score

10,6821322244275

554 findings over 1 of 2 images measured

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
jenkinsci/jenkins×22.67132224427510,682
gcr.io/jenkinsxio/jx2.0.645unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

554 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-fmjp-mw89-c6h6ldap@1.11807.809.vd3a
LowDLA-2784-1icu@57.1-657.1-6+deb9u5
LowGHSA-76q7-r3g4-wvm4script-security@1.18.11.63
LowGHSA-9fp8-64xf-w957script-security@1.18.11.63
LowGHSA-hvmx-5hv4-f235script-security@1.18.11.63
LowGHSA-m26f-w3h5-62fjscript-security@1.18.11.63
LowDSA-4428-1systemd@232-25+deb9u1232-25+deb9u11
LowGHSA-85rq-hp8x-ghjqmailer@1.201.34.2
LowGHSA-72pg-x5f8-j25jspring-webmvc@2.5.6.SEC03no fix listed
LowGHSA-xm94-9jw8-p6hwcredentials@2.1.22.1.19
LowGHSA-2pp9-r4rv-6p6jjenkins-core@2.672.121.2
LowGHSA-wmr8-25ff-ggpjjenkins-core@2.672.121.2
LowGHSA-x9v8-p946-5pwcldap@1.11807.809.vd3a
LowDSA-4535-1e2fsprogs@1.43.4-21.43.4-2+deb9u1
LowDLA-2518-1cairo@1.14.8-11.14.8-1+deb9u1
LowGHSA-mq64-j8f9-9gcjspring-webmvc@2.5.6.SEC03no fix listed
LowGHSA-7g95-jmg9-h524jenkins-core@2.672.492.2
LowGHSA-cjgm-9vc9-56mxmatrix-project@1.4.1822.824.v14451b
LowDLA-2800-1cups@2.2.1-82.2.1-8+deb9u7
LowGHSA-p8x8-p473-mmmvjenkins-core@2.672.73.2
LowDLA-2290-1e2fsprogs@1.43.4-21.43.4-2+deb9u2
LowGHSA-pj95-ph4q-4qm4jenkins-core@2.672.462.3
LowGHSA-p566-wpxx-574mwindows-slaves@1.01.8.1
LowGHSA-c33w-24p9-8m24configobj@5.0.65.0.9
LowGHSA-p34j-r3ch-c985jenkins-core@2.672.492.2
LowGHSA-p265-xr98-3vmrjenkins-core@2.672.121.2
LowGHSA-cj6r-8pxj-5jv6jenkins-core@2.672.375.4
LowGHSA-3chg-m5w7-qfv5spring-webmvc@2.5.6.SEC03no fix listed
LowDSA-4231-1libgcrypt20@1.7.6-2+deb9u21.7.6-2+deb9u3
LowGHSA-jcwr-x25h-x5fhplexus-utils@3.0.173.0.24
LowDSA-4243-1cups@2.2.1-82.2.1-8+deb9u2
LowGHSA-7xp8-7wqx-5hqxjenkins-core@2.672.204.2
LowGHSA-qrh5-jg98-cr48jenkins-core@2.672.516.3
LowGHSA-f9qj-77q2-h5c5jenkins-core@2.672.462.3
LowGHSA-6p4f-wcwh-5vvmspring-webmvc@2.5.6.SEC03no fix listed
LowGHSA-qwgx-mrv5-87j8script-security@1.18.11172.v35f6a
LowGHSA-qh8g-58pp-2wxhjetty-http@9.4.5.v2017050212.0.12
LowGHSA-8hmv-92wm-39chjenkins-core@2.672.492.2
LowGHSA-62jv-j4w7-5hh8credentials@2.1.21371.1373.v4eb
LowGHSA-7p3p-8qv8-m2vhjetty-server@9.4.5.v20170502no fix listed
LowGHSA-m6cp-vxjx-65j6jetty-server@9.4.5.v201705029.4.41
LowGHSA-7g45-4rm6-3mm3guava@11.0.132.0.0-android
LowDLA-2898-1nss@2:3.26.2-1.12:3.26.2-1.1+deb9u5
LowGHSA-223m-4rfp-646hjenkins-core@2.672.516.3
LowGHSA-hq87-h4jg-vxfwjenkins-core@2.672.414.2
LowGHSA-qv64-w99c-qcr9jenkins-core@2.672.414.2
LowGHSA-463r-5m89-4xfrjenkins-core@2.672.555.3
LowDLA-3029-1cups@2.2.1-82.2.1-8+deb9u8
LowDLA-2361-1libx11@2:1.6.4-32:1.6.4-3+deb9u3
LowDSA-4462-1dbus@1.10.18-11.10.28-0+deb9u1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.10.38latest7 years ago2.67132224427510,682

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/jenkins-x/jenkins.svg)](https://charts.stackradar.io/charts/jenkins-x/jenkins)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.