librephotos 1.1.7 Helm chart
k8sonlabVerified publisherScored 6 Oct 2026
Helmchart used to install Librephotos in a microservice manner
Version 1.1.7 2 days agoapp version 1.2.1 0Artifact Hub
librephotos 1.1.7 deploys 7 container images: library/postgres, reallibrephotos/librephotos, reallibrephotos/librephotos-frontend, reallibrephotos/librephotos-proxy and 3 more. Across them, 1,291 findings — 11 critical, 20 high — 3 on CISA KEV. The highest contribution is DSA-4110-1 in exim4 4.84.2-2+deb8u4, fixed in 4.84.2-2+deb8u5. Chart.yaml declares kubeVersion >=1.16.0-0; rendered for Kubernetes 1.16.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 9.6.5 | 243227 | 1,446 |
| reallibrephotos/ | 1.2.1 | 001499 | 1,082 |
| reallibrephotos/ | 1.2.1 | 00326 | 340 |
| reallibrephotos/ | 1.2.1 | 0027153 | 1,855 |
| bitnamilegacy/ | latest | 1159228 | 3,385 |
| bitnamilegacy/ | latest | 2052194 | 3,009 |
| alpine/ | 1.22.6 | 615148198 | 6,353 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | DEBIAN-CVE-2026-34180 | openssl | 3.0.20-1~deb12u2 |
| Medium | DLA-1633-1 | sqlite3 | 3.8.7.1-1+deb8u4 |
| Medium | DEBIAN-CVE-2026-9079 | curl | no fix listed |
| Medium | ALPINE-CVE-2023-28320 | curl | 8.1.0-r0 |
| Medium | ALPINE-CVE-2023-35945 | nghttp2 | 1.46.0-r1 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | GHSA-8r3f-844c-mc37 | google.golang.org/ | 1.33.0 |
| Medium | GO-2023-2375 | stdlib | 1.20.0 |
| Medium | DEBIAN-CVE-2025-7424 | libxslt | 1.1.35-1+deb12u2 |
| Medium | GO-2023-1569 | stdlib | 1.19.6 |
| Medium | UBUNTU-CVE-2026-5260 | gnutls28 | 3.8.3-1.1ubuntu3.6+Fips1.2 |
| Medium | GO-2022-1143 | stdlib | 1.18.9 |
| Medium | BIT-postgresql-2025-8714 | postgresql | 13.22.0 |
| Medium | GHSA-pc3f-x583-g7j2 | github.com/ | 0.5.1 |
| Medium | ALPINE-CVE-2022-43552 | curl | 7.80.0-r5 |
| Medium | DEBIAN-CVE-2022-1210 | tiff | no fix listed |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | DEBIAN-CVE-2018-10126 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2026-28387 | openssl | 3.0.19-1~deb12u2 |
| Medium | DEBIAN-CVE-2026-8924 | curl | no fix listed |
| Medium | DEBIAN-CVE-2025-13151 | libtasn1-6 | no fix listed |
| Medium | GO-2022-1038 | stdlib | 1.18.7 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | DEBIAN-CVE-2026-66046 | expat | no fix listed |
| Medium | BIT-redis-2025-48367 | redis | 6.2.19 |
| Medium | DLA-2085-1 | zlib | 1:1.2.8.dfsg-2+deb8u1 |
| Medium | ALPINE-CVE-2023-23946 | git | 2.34.7-r0 |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | USN-8344-3 | python-pip | 24.0+dfsg-1ubuntu1.3+esm3 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | DEBIAN-CVE-2026-52490 | tiff | no fix listed |
| Medium | ALPINE-CVE-2022-29458 | ncurses | 6.3_p20211120-r1 |
| Medium | ALPINE-CVE-2022-24765 | git | 2.34.2-r0 |
| Medium | UBUNTU-CVE-2026-42009 | gnutls28 | 3.8.3-1.1ubuntu3.6+Fips1.2 |
| Medium | DLA-1580-1 | systemd | 215-17+deb8u8 |
| Medium | DEBIAN-CVE-2024-26461 | krb5 | no fix listed |
| Medium | GO-2024-3106 | stdlib | 1.22.7 |
| Medium | DEBIAN-CVE-2019-1010024 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2026-33846 | gnutls28 | 3.8.3-1.1ubuntu3.6+Fips1.2 |
| Medium | ALPINE-CVE-2022-41409 | pcre2 | 10.42-r0 |
| Medium | GHSA-gwc9-m7rh-j2ww | golang.org/ | 0.0.0-20211202192323-5770296d904e |
| Medium | GO-2023-1570 | stdlib | 1.19.6 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2023-23916 | curl | 7.80.0-r6 |
| Medium | DLA-1935-1 | e2fsprogs | 1.42.12-2+deb8u1 |
| Medium | BIT-postgresql-2026-16239 | postgresql | 14.24.0 |
| Medium | ALPINE-CVE-2023-46218 | curl | 8.5.0-r0 |
| Medium | GHSA-6wrf-mxfj-pf5p | github.com/ | 20.10.24 |
| Medium | DEBIAN-CVE-2026-8376 | perl | 5.36.0-7+deb12u4 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.1.7latest | 2 days ago | 1.2.1 | 1120335925 | 17,470 |
| 1.1.6 | 1 month ago | 1.0.3 | 1120335938 | 17,731 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.