StackRadar

jenkins Helm chart

jenkins-x

Scored 14 Sept 2026

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Latest 0.10.38 7 years agoapp version 2.67 0Artifact Hub

jenkins 0.10.38 deploys 2 container images: jenkinsci/jenkins and gcr.io/jenkinsxio/jx. Across the 1 measured, 554 findings13 critical, 22 high 6 on CISA KEV. The highest contribution is GHSA-xvxq-hq48-xphm in script-security 1.18.1, fixed in 1.54.

Radar Score

10,6821322244275

554 findings over 1 of 2 images measured

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
jenkinsci/jenkins×22.67132224427510,682
gcr.io/jenkinsxio/jx2.0.645unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

554 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-cpw3-x7gf-p872jenkins-core@2.672.107.2
LowGHSA-qpg9-83fv-x9chjenkins-core@2.672.164.2
LowGHSA-fj6f-6933-839jjenkins-core@2.672.204.2
LowDLA-3022-1dpkg@1.18.241.18.26
LowGHSA-9grj-j43m-mjqrjenkins-core@2.672.332.4
LowGHSA-53jp-gmwc-jwf6jenkins-core@2.672.138.2
LowDLA-2657-1lz4@0.0~r131-2+b10.0~r131-2+deb9u1
LowGHSA-w7jr-wqw6-54xcjenkins-core@2.672.204.2
LowGHSA-6xx3-rg99-gc3pbcprov-jdk15on@1.541.66
LowDSA-3998-1nss@2:3.26.2-1.12:3.26.2-1.1+deb9u1
LowGHSA-q4rv-gq96-w7c5jetty-server@9.4.5.v201705029.4.57.v20241219
LowGHSA-g8pg-qrvm-wgh2jenkins-core@2.672.228
LowGHSA-4625-q52w-39cxjenkins-core@2.672.263.2
LowDSA-4367-1systemd@232-25+deb9u1232-25+deb9u7
LowGHSA-rr6r-p7rw-369cjenkins-core@2.672.138.2
LowDSA-4086-1libxml2@2.9.4+dfsg1-2.2+deb9u12.9.4+dfsg1-2.2+deb9u2
LowGHSA-v435-xc8x-wvr9bcprov-jdk15on@1.541.78
LowDLA-2481-1openldap@2.4.44+dfsg-52.4.44+dfsg-5+deb9u6
LowGHSA-2xcm-h7vv-g8m9jenkins-core@2.672.228
LowGHSA-crg2-6xv3-qg5fjenkins-core@2.672.228
LowDLA-2566-1libbsd@0.8.3-10.8.3-1+deb9u1
LowGHSA-rcjj-h6gh-jf3rgroovy-all@2.4.112.4.21
LowDLA-2760-1nettle@3.3-1+b13.3-1+deb9u1
LowDSA-4646-1icu@57.1-657.1-6+deb9u4
LowDLA-2596-1shadow@1:4.4-4.11:4.4-4.1+deb9u1
LowGHSA-x23c-287f-qqv5spring-webmvc@2.5.6.SEC03no fix listed
LowGHSA-g4c3-4f3v-84x8external-monitor-job@1.4207.v98a
LowDLA-2771-1krb5@1.15-11.15-1+deb9u3
LowGHSA-rgmj-mccj-h9mxjenkins-core@2.672.107.3
LowGHSA-8xfc-gm6g-vgpvbcprov-jdk15on@1.541.78
LowGHSA-7cjc-xppr-xj6xjenkins-core@2.672.176.4
LowGHSA-9qgf-4fpf-cmh2jenkins-core@2.672.176.4
LowGHSA-hg6g-jj7g-x6v2jenkins-core@2.672.176.4
LowGHSA-q6q9-83xw-mp6pjenkins-core@2.672.176.4
LowGHSA-mjmq-gwgm-5qhmsshd-core@1.2.02.1.0
LowGHSA-98gq-6hxg-52r6jenkins-core@2.672.275
LowGHSA-mj7q-cmf3-mg7hjenkins-core@2.672.263.2
LowGHSA-wv63-gwr9-5c55jenkins-core@2.672.275
LowGHSA-wg6q-6289-32hpbcpkix-jdk15on@1.541.84
LowGHSA-hmr7-m48g-48f6jetty-http@9.4.5.v201705029.4.52
LowDLA-2418-1libsndfile@1.0.27-31.0.27-3+deb9u1
LowDSA-4150-1icu@57.1-657.1-6+deb9u2
LowGHSA-q4wp-8c99-69pwjenkins-core@2.672.289.2
LowDLA-3037-1libjpeg-turbo@1:1.5.1-21:1.5.1-2+deb9u2
LowDLA-2777-1tiff@4.0.8-2+deb9u14.0.8-2+deb9u7
LowGHSA-wjxj-5m7g-mg7qbcprov-jdk15on@1.54no fix listed
LowGHSA-9m48-54pj-h248jenkins-core@2.672.176.3
LowGHSA-w2hv-rcqr-2h7rjenkins-core@2.672.277.2
LowGHSA-m5cw-c64p-77h6subversion@1.542.15.4
LowGHSA-x3pr-fcgm-wjgcsubversion@1.542.13.1

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.10.38latest7 years ago2.67132224427510,682

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/jenkins-x/jenkins.svg)](https://charts.stackradar.io/charts/jenkins-x/jenkins)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.