librephotos 1.1.7 Helm chart
k8sonlabVerified publisherScored 5 Oct 2026
Helmchart used to install Librephotos in a microservice manner
Version 1.1.7 2 days agoapp version 1.2.1 0Artifact Hub
librephotos 1.1.7 deploys 7 container images: library/postgres, reallibrephotos/librephotos, reallibrephotos/librephotos-frontend, reallibrephotos/librephotos-proxy and 3 more. Across them, 1,289 findings — 11 critical, 20 high — 3 on CISA KEV. The highest contribution is DSA-4110-1 in exim4 4.84.2-2+deb8u4, fixed in 4.84.2-2+deb8u5. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 9.6.5 | 243227 | 1,446 |
| reallibrephotos/ | 1.2.1 | 001499 | 1,082 |
| reallibrephotos/ | 1.2.1 | 00326 | 340 |
| reallibrephotos/ | 1.2.1 | 0027153 | 1,855 |
| bitnamilegacy/ | latest | 1159228 | 3,385 |
| bitnamilegacy/ | latest | 2052194 | 3,009 |
| alpine/ | 1.22.6 | 615148198 | 6,353 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | DSA-4110-1KEV | exim4 | 4.84.2-2+deb8u5 |
| Critical | BIT-redis-2025-49844 | redis | 6.2.20 |
| Critical | ALPINE-CVE-2023-38545 | curl | 8.4.0-r0 |
| Critical | DLA-2176-1 | inetutils | 2:1.9.2.39.3a460-3+deb8u1 |
| Critical | ALPINE-CVE-2022-23521 | git | 2.34.6-r0 |
| Critical | ALPINE-CVE-2023-44487KEV | nghttp2 | 1.46.0-r2 |
| Critical | ALPINE-CVE-2022-41903 | git | 2.34.6-r0 |
| Critical | GO-2024-2687 | golang.org/ | 0.23.0 |
| Critical | GO-2024-2687 | stdlib | 1.21.9 |
| Critical | DEBIAN-CVE-2025-15467 | openssl | 3.0.18-1~deb12u2 |
| High | DLA-1911-1 | exim4 | 4.84.2-2+deb8u6 |
| High | DEBIAN-CVE-2025-6965 | sqlite3 | 3.40.1-2+deb12u2 |
| High | ALPINE-CVE-2023-0286 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2023-25652 | git | 2.34.8-r0 |
| High | ALPINE-CVE-2023-2650 | openssl | 1.1.1u-r0 |
| High | GHSA-45x7-px36-x8w8 | golang.org/ | 0.0.0-20231218163308-9d2ee975ef9f |
| High | ALPINE-CVE-2022-37434 | zlib | 1.2.12-r2 |
| High | GO-2024-2521 | github.com/ | 20.10.0-beta1+incompatible |
| High | ALPINE-CVE-2022-40303 | libxml2 | 2.9.14-r2 |
| High | GHSA-v23v-6jw2-98fq | github.com/ | 23.0.15 |
| High | GHSA-qppj-fm5r-hxr3KEV | golang.org/ | 0.17.0 |
| High | GHSA-xr7r-f8xq-vfvv | github.com/ | 1.1.12 |
| High | GHSA-crp2-qrr5-8pq7 | github.com/ | 1.5.10 |
| High | DLA-1601-1 | perl | 5.20.2-3+deb8u12 |
| High | DSA-4172-1 | perl | 5.20.2-3+deb8u10 |
| High | ALPINE-CVE-2022-32206 | curl | 7.80.0-r2 |
| High | ALPINE-CVE-2022-4450 | openssl | 1.1.1t-r0 |
| High | DLA-1637-1 | apt | 1.0.9.8.5 |
| High | ALPINE-CVE-2022-32207 | curl | 7.80.0-r2 |
| High | ALPINE-CVE-2022-43551 | curl | 7.80.0-r5 |
| Medium | DSA-4157-1 | openssl | 1.0.1t-1+deb8u8 |
| Medium | DLA-1756-1 | libxslt | 1.1.28-2+deb8u4 |
| Medium | ALPINE-CVE-2022-32221 | curl | 7.80.0-r4 |
| Medium | GO-2022-0433 | stdlib | 1.17.9 |
| Medium | DSA-4224-1 | gnupg | 1.4.18-7+deb8u5 |
| Medium | DLA-1701-1 | openssl | 1.0.1t-1+deb8u11 |
| Medium | ALPINE-CVE-2022-1271 | xz | 5.2.5-r1 |
| Medium | DLA-2044-1 | cyrus-sasl2 | 2.1.26.dfsg1-13+deb8u2 |
| Medium | DSA-6113-1 | openssl | 3.0.18-1~deb12u2 |
| Medium | ALPINE-CVE-2022-4304 | openssl | 1.1.1t-r0 |
| Medium | GHSA-83g2-8m93-v3w7 | golang.org/ | 0.0.0-20210520170846-37e1c6afe023 |
| Medium | DLA-1449-1 | openssl | 1.0.1t-1+deb8u9 |
| Medium | DSA-4226-1 | perl | 5.20.2-3+deb8u11 |
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DLA-2052-1 | libbsd | 0.7.0-2+deb8u1 |
| Medium | DLA-1839-1 | expat | 2.1.0-6+deb8u5 |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | DEBIAN-CVE-2017-17740 | openldap | no fix listed |
| Medium | ALPINE-CVE-2023-29007 | git | 2.34.8-r0 |
| Medium | BIT-redis-2025-32023 | redis | 6.2.19 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.1.7latest | 2 days ago | 1.2.1 | 1120335923 | 17,468 |
| 1.1.6 | 1 month ago | 1.0.3 | 1120335936 | 17,725 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.