StackRadar

jenkins Helm chart

jenkins-x

Scored 14 Sept 2026

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Latest 0.10.38 7 years agoapp version 2.67 0Artifact Hub

jenkins 0.10.38 deploys 2 container images: jenkinsci/jenkins and gcr.io/jenkinsxio/jx. Across the 1 measured, 554 findings13 critical, 22 high 6 on CISA KEV. The highest contribution is GHSA-xvxq-hq48-xphm in script-security 1.18.1, fixed in 1.54.

Radar Score

10,6821322244275

554 findings over 1 of 2 images measured

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
jenkinsci/jenkins×22.67132224427510,682
gcr.io/jenkinsxio/jx2.0.645unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

554 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDLA-2372-1libproxy@0.4.14-20.4.14-2+deb9u1
LowGHSA-xjrf-8x4f-43h4spring-web@2.5.6.SEC033.2.2.RELEASE
LowDSA-4485-1openjdk-8@8u141-b15-1~deb9u18u222-b10-1~deb9u1
LowDLA-2325-1openjdk-8@8u141-b15-1~deb9u18u265-b01-0+deb9u1
LowGHSA-cwcf-5m5w-mq2wssh-credentials@1.101.14
LowGHSA-cwcf-5m5w-mq2wcredentials@2.1.22.1.17
LowGHSA-96jw-3xw4-mq9pmatrix-auth@1.12.6.6
LowGHSA-hr96-qfvm-52r6maven-plugin@2.143.4
LowGHSA-r9jf-hf9x-7hrvscript-security@1.18.11.37
LowDLA-2737-1openjdk-8@8u141-b15-1~deb9u18u302-b08-1~deb9u1
LowGHSA-279f-qwgh-h5mpjenkins-core@2.672.414.2
LowGHSA-frgr-c5f2-8qhhjenkins-core@2.672.375.4
LowGHSA-7qf3-c2q8-69m3jenkins-core@2.672.263.2
LowDSA-4241-1libsoup2.4@2.56.0-2+deb9u12.56.0-2+deb9u2
LowDSA-4268-1openjdk-8@8u141-b15-1~deb9u18u181-b13-1~deb9u1
LowDLA-2514-1flac@1.3.2-11.3.2-2+deb9u1
LowDLA-2931-1cyrus-sasl2@2.1.27~101-g0780600+dfsg-32.1.27~101-g0780600+dfsg-3+deb9u2
LowDLA-3044-1glib2.0@2.50.3-22.50.3-2+deb9u3
LowDLA-3006-1openjdk-8@8u141-b15-1~deb9u18u332-ga-1~deb9u1
LowDLA-3058-1libsndfile@1.0.27-31.0.27-3+deb9u3
LowDSA-4100-1tiff@4.0.8-2+deb9u14.0.8-2+deb9u2
LowGHSA-6q4g-84f3-mw74jenkins-core@2.672.303.2
LowDSA-4659-1git@1:2.11.0-3+deb9u11:2.11.0-3+deb9u7
LowDSA-3988-1libidn2-0@0.16-10.16-1+deb9u1
LowGHSA-6mv9-hcx5-7mhhjenkins-core@2.672.89.4
LowGHSA-fv42-mx39-6fpwscript-security@1.18.11190.v65867a_a_47126
LowDSA-4539-1openssl@1.1.0f-31.1.0l-1~deb9u1
LowDSA-4540-1openssl1.0@1.0.2l-21.0.2t-1~deb9u1
LowDLA-2382-1curl@7.52.1-57.52.1-5+deb9u12
LowDLA-2412-1openjdk-8@8u141-b15-1~deb9u18u272-b10-0+deb9u1
LowDLA-3012-1libxml2@2.9.4+dfsg1-2.2+deb9u12.9.4+dfsg1-2.2+deb9u7
LowDSA-4548-1openjdk-8@8u141-b15-1~deb9u18u232-b09-1~deb9u1
LowDLA-2837-1gmp@2:6.1.2+dfsg-12:6.1.2+dfsg-1+deb9u1
LowGHSA-9p56-p6mw-w8qcjenkins-core@2.672.528.3
LowGHSA-9p56-p6mw-w8qccli@2.672.528.3
LowDLA-2802-1elfutils@0.168-10.168-1+deb9u1
LowDLA-2340-2sqlite3@3.16.2-53.16.2-5+deb9u3
LowDLA-2634-1openjdk-8@8u141-b15-1~deb9u18u292-b10-0+deb9u1
LowDLA-2450-1libproxy@0.4.14-20.4.14-2+deb9u2
LowGHSA-m68x-cc2f-gr5hscript-security@1.18.11.29.1
LowGHSA-x9gm-m8pp-54vxjunit@1.61.26
LowDSA-4490-1subversion@1.9.5-1+deb9u11.9.5-1+deb9u4
LowDLA-2302-1libjpeg-turbo@1:1.5.1-21:1.5.1-2+deb9u1
LowGHSA-28p3-mchr-9frjjenkins-core@2.672.121.3
LowGHSA-pvwx-3jx5-24r2jenkins-core@2.672.277.2
LowDSA-4410-1openjdk-8@8u141-b15-1~deb9u18u212-b01-1~deb9u1
LowDLA-2513-1p11-kit@0.23.3-20.23.3-2+deb9u1
LowGHSA-r2jf-rc5v-vmpvjenkins-core@2.672.121.3
LowGHSA-g8m5-722r-8whqjetty-server@9.4.5.v201705029.4.56
LowDLA-2722-1libsndfile@1.0.27-31.0.27-3+deb9u2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.10.38latest7 years ago2.67132224427510,682

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/jenkins-x/jenkins.svg)](https://charts.stackradar.io/charts/jenkins-x/jenkins)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.