librephotos 1.1.7 Helm chart
k8sonlabVerified publisherScored 6 Oct 2026
Helmchart used to install Librephotos in a microservice manner
Version 1.1.7 2 days agoapp version 1.2.1 0Artifact Hub
librephotos 1.1.7 deploys 7 container images: library/postgres, reallibrephotos/librephotos, reallibrephotos/librephotos-frontend, reallibrephotos/librephotos-proxy and 3 more. Across them, 1,291 findings — 11 critical, 20 high — 3 on CISA KEV. The highest contribution is DSA-4110-1 in exim4 4.84.2-2+deb8u4, fixed in 4.84.2-2+deb8u5. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 9.6.5 | 243227 | 1,446 |
| reallibrephotos/ | 1.2.1 | 001499 | 1,082 |
| reallibrephotos/ | 1.2.1 | 00326 | 340 |
| reallibrephotos/ | 1.2.1 | 0027153 | 1,855 |
| bitnamilegacy/ | latest | 1159228 | 3,385 |
| bitnamilegacy/ | latest | 2052194 | 3,009 |
| alpine/ | 1.22.6 | 615148198 | 6,353 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GO-2022-0435 | stdlib | 1.17.9 |
| Medium | GHSA-hp87-p4gw-j4gq | gopkg.in/ | 3.0.1 |
| Medium | BIT-redis-2026-25243 | redis | 6.2.22 |
| Medium | GO-2022-0288 | stdlib | 1.16.12 |
| Medium | GO-2022-0288 | golang.org/ | 0.0.0-20211209124913-491a49abca63 |
| Medium | GHSA-8c26-wmh5-6g9v | golang.org/ | 0.0.0-20220314234659-1baeb1ce4c0b |
| Medium | GHSA-4374-p667-p6c8 | golang.org/ | 0.17.0 |
| Medium | GO-2023-2102 | stdlib | 1.20.10 |
| Medium | ALPINE-CVE-2022-42915 | curl | 7.80.0-r4 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r2 |
| Medium | GHSA-j249-ghv5-7mxv | github.com/ | 18.09.8 |
| Medium | ALPINE-CVE-2022-32208 | curl | 7.80.0-r2 |
| Medium | DSA-4071-1 | sensible-utils | 0.0.9+deb8u1 |
| Medium | ALPINE-CVE-2023-27534 | curl | 8.0.1-r0 |
| Medium | GHSA-6635-c626-vj4r | github.com/ | 1.13.2 |
| Medium | GO-2023-1752 | stdlib | 1.19.9 |
| Medium | GHSA-69cg-p879-7622 | golang.org/ | 0.0.0-20220906165146-f3363e06e74c |
| Medium | GO-2022-0969 | stdlib | 1.18.6 |
| Medium | GO-2021-0264 | stdlib | 1.16.10 |
| Medium | GO-2021-0347 | stdlib | 1.16.15 |
| Medium | ALPINE-CVE-2023-27533 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2022-27775 | curl | 7.80.0-r1 |
| Medium | DLA-1834-1 | python2.7 | 2.7.9-2+deb8u3 |
| Medium | GHSA-cx63-2mw6-8hw5 | setuptools | 70.0.0 |
| Medium | DEBIAN-CVE-2017-11164 | pcre3 | no fix listed |
| Medium | DLA-1519-1 | python2.7 | 2.7.9-2+deb8u2 |
| Medium | GO-2022-0278 | github.com/ | 1.5.9 |
| Medium | ALPINE-CVE-2022-27782 | curl | 7.80.0-r2 |
| Medium | DEBIAN-CVE-2017-7246 | pcre3 | no fix listed |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | UBUNTU-CVE-2026-21441 | python-pip | no fix listed |
| Medium | GHSA-p77j-4mvh-x3m3 | google.golang.org/ | 1.79.3 |
| Medium | GO-2021-0317 | stdlib | 1.16.14 |
| Medium | ALPINE-CVE-2022-40674 | expat | 2.4.9-r0 |
| Medium | DEBIAN-CVE-2025-49796 | libxml2 | 2.9.14+dfsg-1.3~deb12u3 |
| Medium | DEBIAN-CVE-2019-20838 | pcre3 | no fix listed |
| Medium | GO-2023-2185 | stdlib | 1.20.11 |
| Medium | ALPINE-CVE-2022-27781 | curl | 7.80.0-r2 |
| Medium | ALPINE-CVE-2022-22576 | curl | 7.80.0-r1 |
| Medium | DEBIAN-CVE-2017-7245 | pcre3 | no fix listed |
| Medium | ALPINE-CVE-2022-45061 | python3 | 3.9.16-r0 |
| Medium | GO-2022-0537 | stdlib | 1.17.13 |
| Medium | GHSA-232p-vwff-86mp | github.com/ | 20.10.24 |
| Medium | GHSA-r9hx-vwmv-q579 | setuptools | 65.5.1 |
| Medium | DEBIAN-CVE-2026-28388 | openssl | 3.0.19-1~deb12u2 |
| Medium | ALPINE-CVE-2023-28319 | curl | 8.1.0-r0 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | ALPINE-CVE-2022-27780 | curl | 7.80.0-r2 |
| Medium | ALPINE-CVE-2022-27776 | curl | 7.80.0-r1 |
| Medium | ALPINE-CVE-2022-43680 | expat | 2.5.0-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.1.7latest | 2 days ago | 1.2.1 | 1120335925 | 17,470 |
| 1.1.6 | 1 month ago | 1.0.3 | 1120335938 | 17,731 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.