aperag 0.0.0-nightly Helm chart
kubeblocksVerified publisherScored 14 Sept 2026
A Helm chart for Kubernetes
Version 0.0.0-nightly 1 year agodeploys tag v0.0.0-nightly 0Artifact Hub
aperag 0.0.0-nightly deploys 3 container images: apecloud/aperag, apecloud/doc-ray and apecloud/aperag-frontend. Across the 2 measured, 699 findings — 3 critical, 7 high — 3 on CISA KEV. The highest contribution is GHSA-7488-6r32-c95q in litellm 1.80.0, fixed in 1.84.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| apecloud/ | v0.0.0-nightly | 3498481 | 6,947 |
| apecloud/ | v0.2.0 | — | not yet scanned |
| apecloud/ | v0.0.0-nightly | 032585 | 1,458 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-2h4p-vjrc-8xpq | mako | 1.3.12 |
| Medium | GHSA-284h-m62q-gf8w | gitpython | 3.1.59 |
| Medium | GHSA-m4rf-3fr8-xwx3 | nltk | 3.10.3 |
| Medium | DEBIAN-CVE-2026-5260 | gnutls28 | 3.8.9-3+deb13u4 |
| Medium | GHSA-hx9q-6w63-j58v | orjson | 3.11.6 |
| Medium | GHSA-4jcj-7x88-m979 | litellm | 1.84.0 |
| Medium | GHSA-jm66-cg57-jjv5 | azure-core | 1.38.0 |
| Medium | GHSA-wvpp-8hx9-p66j | gitpython | 3.1.58 |
| Medium | DEBIAN-CVE-2026-55199 | libssh2 | 1.11.1-1+deb13u1 |
| Medium | DEBIAN-CVE-2026-66033 | libssh2 | 1.11.1-1+deb13u2 |
| Medium | GHSA-7gcm-g887-7qv7 | protobuf | 5.29.6 |
| Medium | DEBIAN-CVE-2026-80229 | curl | no fix listed |
| Medium | DEBIAN-CVE-2026-8927 | curl | no fix listed |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | DEBIAN-CVE-2026-28388 | openssl | 3.5.5-1~deb13u2 |
| Medium | GHSA-x5ph-mj9p-rfr8 | nltk | 3.10.0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | DEBIAN-CVE-2025-69421 | openssl | 3.5.4-1~deb13u2 |
| Medium | GHSA-hvx9-hwr7-wjj9 | systeminformation | 5.31.6 |
| Medium | GHSA-3xgq-45jj-v275 | cross-spawn | 7.0.5 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | DEBIAN-CVE-2026-28387 | openssl | 3.5.5-1~deb13u2 |
| Medium | GHSA-58pv-8j8x-9vj2 | jaraco-context | 6.1.0 |
| Medium | GHSA-6vqw-3v5j-54x4 | cryptography | 42.0.4 |
| Medium | GHSA-63hf-3vf5-4wqf | aiohttp | 3.13.4 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 7.5.11 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Medium | DEBIAN-CVE-2026-28389 | openssl | 3.5.5-1~deb13u2 |
| Medium | DEBIAN-CVE-2026-28390 | openssl | 3.5.5-1~deb13u2 |
| Medium | GHSA-492v-c6pp-mqqv | next | 15.5.16 |
| Medium | DEBIAN-CVE-2019-1010025 | glibc | no fix listed |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Low | DEBIAN-CVE-2025-69420 | openssl | 3.5.4-1~deb13u2 |
| Low | DEBIAN-CVE-2026-57433 | perl | 5.40.1-6+deb13u1 |
| Low | PYSEC-2026-2132 | click | 8.3.3 |
| Low | DEBIAN-CVE-2026-8926 | curl | no fix listed |
| Low | GHSA-jm78-9fvv-mhgr | gitpython | 3.1.58 |
| Low | DEBIAN-CVE-2026-27135 | nghttp2 | 1.64.0-1.1+deb13u1 |
| Low | DEBIAN-CVE-2026-13221 | perl | 5.40.1-6+deb13u1 |
| Low | DEBIAN-CVE-2026-42496 | perl | 5.40.1-6+deb13u1 |
| Low | PYSEC-2026-3750 | nltk | 3.10.0 |
| Low | GHSA-mg66-mrh9-m8jx | next | 15.5.16 |
| Low | DEBIAN-CVE-2026-3805 | curl | 8.14.1-2+deb13u4 |
| Low | GHSA-7cx3-6m66-7c5m | tornado | 6.5 |
| Low | GHSA-pp6c-gr5w-3c5g | python-multipart | 0.0.27 |
| Low | GHSA-j37q-q7p9-vpwm | litellm | no fix listed |
| Low | DEBIAN-CVE-2026-14456 | openssl | 3.5.7-1~deb13u2 |
| Low | PYSEC-2026-2237 | nltk | 3.9.4 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.0-nightlylatest | 1 year ago | v0.0.0-nightly | 37123566 | 8,405 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.