StackRadar

tdsf 5.7.0 Helm chart

kubebb

Scored 14 Sept 2026

一个统一管理微服务应用流量、兼容Istio&envoy的托管式平台

Version 5.7.0 2 years agoapp version v5.7.0 0Artifact Hub

tdsf 5.7.0 deploys 3 container images: kubebb/mesh-api, kubebb/mesh-operator and kubebb/tdsf-portal. Across them, 410 findings6 critical, 21 high 3 on CISA KEV. The highest contribution is GHSA-83qj-6fr2-vhqg in tomcat-embed-core 10.1.12, fixed in 10.1.35.

Radar Score

6,490621107276

410 findings over 3 of 3 images measured

KEV ×3 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
kubebb/mesh-apiv5.7.051040502,379
kubebb/mesh-operatorv5.7.006351862,555
kubebb/tdsf-portalv5.7.01532401,556

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

410 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-w33c-445m-f8w7okio-jvm@3.0.03.4.0
LowGHSA-f5x3-32g6-xq36tar@4.4.136.2.1
LowGHSA-3vjf-82ff-p4r3urijs@1.19.71.19.11
LowGHSA-xwx5-5c9g-x68xistio.io/istio@v0.0.0-20230719200609-00136097767e1.12.18
LowGO-2023-2102stdlib@go1.18.41.20.10
LowGHSA-qffp-2rhf-9h96tar@4.4.137.5.10
LowGHSA-23hp-3jrh-7fpwtar@4.4.137.5.19
LowGHSA-fv25-8xcx-gqjctomcat-embed-core@10.1.1210.1.55
LowGHSA-557j-xg8c-q2mmhelm.sh/helm/v3@v3.10.33.17.4
LowGHSA-23hv-mwm6-g8jftomcat-embed-core@10.1.1210.1.42
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.22.5.6
LowGHSA-g694-m8vq-gv9hurijs@1.19.71.19.11
LowGHSA-563x-q5rq-57qptomcat-embed-core@10.1.1210.1.52
LowGHSA-7r86-cg39-jmmjminimatch@3.0.43.1.3
LowGHSA-33pg-m6jh-5237github.com/docker/docker@v20.10.17+incompatible20.10.24
LowGHSA-8qq5-rm4j-mr97tar@4.4.137.5.3
LowGHSA-mgp5-rv84-w37qtomcat-embed-core@10.1.1210.1.52
LowGO-2022-0969stdlib@go1.18.41.18.6
LowGHSA-qv9r-c865-cp47log4j-api@2.17.12.25.5
LowGHSA-6xx3-rg99-gc3pbcprov-jdk15on@1.581.66
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa0.52.0
LowGHSA-23c5-xmqv-rm74minimatch@3.0.43.1.4
LowGHSA-gmg8-593g-7mv3poi-ooxml@4.1.25.4.0
LowGHSA-5mp6-jrq3-r938tomcat-embed-core@10.1.1210.1.55
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa0.52.0
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.111.1.17
LowGHSA-jmp9-x22r-554xspring-core@6.0.11no fix listed
LowGHSA-rv64-5gf8-9qq8tomcat-embed-core@10.1.1210.1.54
LowGHSA-2wrh-6pvc-2jm9golang.org/x/net@v0.7.00.13.0
LowGHSA-2qjp-425j-52j9github.com/containerd/containerd@v1.6.61.6.12
LowGHSA-x4m4-345f-5h5gtomcat-embed-core@10.1.1210.1.54
LowGHSA-v435-xc8x-wvr9bcprov-jdk15on@1.581.78
LowGHSA-8x88-c5mf-7j5wtar@4.4.137.5.18
LowGHSA-jjfh-589g-3hjxspring-boot-actuator@3.1.33.1.6
LowGHSA-qxrj-hx23-xp82@koa/cors@3.3.05.0.0
LowGHSA-fpj8-gq4v-p354tomcat-embed-core@10.1.1210.1.50
LowGO-2023-2185stdlib@go1.18.41.20.11
LowGHSA-hgrr-935x-pq79tomcat-embed-core@10.1.1210.1.47
LowALPINE-CVE-2024-4603openssl@3.1.1-r13.1.5-r0
LowGHSA-2g4f-4pwh-qvx6ajv@6.12.66.14.0
LowGHSA-6r3c-xf4w-jxjmspring-web@6.0.11no fix listed
LowGHSA-8xfc-gm6g-vgpvbcprov-jdk15on@1.581.78
LowGHSA-8h2f-7jc4-7m3murijs@1.19.71.19.10
LowGHSA-p8p7-x288-28g6request@2.88.0no fix listed
LowGHSA-r6q2-hw4h-h46wtar@4.4.137.5.4
LowGHSA-p436-gjf2-799pgithub.com/docker/cli@v20.10.18+incompatible29.2.0
LowGHSA-rc42-6c7j-7h5rspring-boot@3.1.3no fix listed
LowGHSA-r292-9mhp-454mtar@4.4.137.5.21
LowGHSA-wg6q-6289-32hpbcpkix-jdk15on@1.581.84
LowGO-2022-0537stdlib@go1.18.41.17.13

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
5.7.0latest2 years agov5.7.06211072766,490

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubebb/tdsf.svg)](https://charts.stackradar.io/charts/kubebb/tdsf)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.