StackRadar

jenkins Helm chart

jenkins-x

Scored 14 Sept 2026

Open source continuous integration server. It supports multiple SCM tools including CVS, Subversion and Git. It can execute Apache Ant and Apache Maven-based projects as well as arbitrary scripts.

Latest 0.10.38 7 years agoapp version 2.67 0Artifact Hub

jenkins 0.10.38 deploys 2 container images: jenkinsci/jenkins and gcr.io/jenkinsxio/jx. Across the 1 measured, 554 findings13 critical, 22 high 6 on CISA KEV. The highest contribution is GHSA-xvxq-hq48-xphm in script-security 1.18.1, fixed in 1.54.

Radar Score

10,6821322244275

554 findings over 1 of 2 images measured

KEV ×6 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
jenkinsci/jenkins×22.67132224427510,682
gcr.io/jenkinsxio/jx2.0.645unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

554 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDSA-4071-1sensible-utils@0.0.90.0.9+deb9u1
LowGHSA-p92q-7fhh-mq35jenkins-core@2.672.319.2
LowDLA-2425-1openldap@2.4.44+dfsg-52.4.44+dfsg-5+deb9u5
LowGHSA-6456-xjm5-g3pgjenkins-core@2.672.121.2
LowGHSA-pgxv-h967-fw2qjenkins-core@2.672.121.2
LowGHSA-9jcv-v4jp-w3cqjenkins-core@2.672.107.2
LowGHSA-72m5-fvvv-55m6bcprov-jdk15on@1.541.61
LowGHSA-q4cq-r7hg-pxqqjenkins-core@2.672.121.3
LowDLA-2285-1librsvg@2.40.16-1+b12.40.21-0+deb9u1
LowGHSA-xhw3-wmx2-76wfwindows-slaves@1.01.8.1
LowGHSA-qxp6-27gw-99cjjenkins-core@2.672.263.3
LowGHSA-w9gq-8q35-3jccsubversion@1.542.10.3
LowGHSA-6jfc-mc97-c7wgjenkins-core@2.672.176.2
LowDSA-4393-1systemd@232-25+deb9u1232-25+deb9u9
LowDSA-4088-1gdk-pixbuf@2.36.5-22.36.5-2+deb9u2
LowGHSA-2rmj-mq67-h97gspring-web@2.5.6.SEC035.3.38
LowDLA-2669-1libxml2@2.9.4+dfsg1-2.2+deb9u12.9.4+dfsg1-2.2+deb9u5
LowGHSA-5ppx-rgw2-xg23jenkins-core@2.672.73.3
LowDLA-2694-1tiff@4.0.8-2+deb9u14.0.8-2+deb9u6
LowGHSA-q87g-7mp5-765qscript-security@1.18.11.73
LowGHSA-x3rc-cxv7-6xp6jenkins-core@2.672.94
LowGHSA-fjqm-246c-mwqgbcprov-jdk15on@1.541.56
LowGHSA-4cx2-fc23-5wg6bcpkix-jdk15on@1.541.79
LowGHSA-hr8g-6v94-x4m9bcprov-jdk15on@1.54no fix listed
LowDSA-4284-1lcms2@2.8-42.8-4+deb9u1
LowDLA-2897-1apr@1.5.2-51.5.2-5+deb9u1
LowGHSA-ph74-8rgx-64c5junit@1.61166.1168.vd6b_8042a_06de
LowGHSA-hw55-f8wc-82m6jenkins-core@2.672.176.4
LowGHSA-hph9-9vcq-f7gpjenkins-core@2.672.138.4
LowGHSA-ghq2-m3pq-qf3pcvs@2.112.19.1
LowGHSA-6fr3-286q-q3crmailer@1.201.29.1
LowGHSA-wqv4-9gr3-3qghjenkins-core@2.672.73.2
LowGHSA-fq9f-9wv9-rfmgjenkins-core@2.672.73.2
LowGHSA-qhxw-54m9-6wwcmaven-plugin@2.143.0
LowGHSA-667q-vj58-rj88jenkins-core@2.672.121.3
LowGHSA-f585-9fw3-rj2mjenkins-core@2.672.263.2
LowGHSA-4gc7-5j7h-4qphspring-web@2.5.6.SEC03no fix listed
LowGHSA-4gc7-5j7h-4qphspring-context@2.5.6.SEC03no fix listed
LowDLA-2691-1libgcrypt20@1.7.6-2+deb9u21.7.6-2+deb9u4
LowGHSA-4g9r-vxhx-9pgxcommons-compress@1.101.26.0
LowGHSA-2w4x-rxp7-grg7jenkins-core@2.672.107.3
LowGHSA-558x-h7rg-997vmailer@1.201.34.2
LowDLA-2932-1tiff@4.0.8-2+deb9u14.0.8-2+deb9u8
LowGHSA-r78q-qgx6-64ppjenkins-core@2.672.204.2
LowDSA-4685-1apt@1.4.71.4.10
LowGHSA-7592-93rm-6gpxjenkins-core@2.672.107.3
LowGHSA-g78x-xmv8-23xpjenkins-core@2.672.73.2
LowGHSA-h972-cwjv-2v39jenkins-core@2.672.73.2
LowDLA-2295-1curl@7.52.1-57.52.1-5+deb9u11
LowGHSA-hf9h-vv4m-2f33jenkins-core@2.672.375.4

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.10.38latest7 years ago2.67132224427510,682

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/jenkins-x/jenkins.svg)](https://charts.stackradar.io/charts/jenkins-x/jenkins)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.