StackRadar

gitlab 4.2.3 Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Version 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

652 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGO-2021-0240stdlib@go1.13.91.15.13
LowGHSA-qw9x-cqr3-wc7rgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.2.8
LowGHSA-cgrx-mc8f-2prmgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.2.8
LowDLA-2302-1libjpeg-turbo@1:1.5.1-21:1.5.1-2+deb9u1
LowGO-2021-0242stdlib@go1.13.91.15.13
LowDLA-2513-1p11-kit@0.23.3-20.23.3-2+deb9u1
LowGHSA-h4h5-3hr4-j3g2google-protobuf@3.8.03.16.3
LowGO-2021-0264stdlib@go1.13.91.16.10
LowGO-2022-0969stdlib@go1.13.91.18.6
LowDLA-3022-1dpkg@1.18.251.18.26
LowGO-2021-0239stdlib@go1.13.91.15.13
LowDLA-2657-1lz4@0.0~r131-2+b10.0~r131-2+deb9u1
LowGO-2021-0347stdlib@go1.13.91.16.15
LowGHSA-496j-2rq6-j6ccgrpc@1.24.01.53.2
LowGO-2021-0245stdlib@go1.13.91.15.15
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
LowGO-2021-0319stdlib@go1.13.91.16.14
LowALPINE-CVE-2020-8284curl@7.69.1-r07.74.0-r0
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
LowGHSA-mcvf-2q2m-x72mrails-html-sanitizer@1.3.01.4.4
LowGHSA-gxhx-g4fq-49hjcarrierwave@1.3.12.2.5
LowGHSA-2wrh-6pvc-2jm9golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.13.0
LowGHSA-cgx6-hpwq-fhv5nokogiri@1.10.91.13.5
LowGHSA-r6ph-v2qm-q3c2cryptography@3.046.0.5
LowGO-2022-0493stdlib@go1.13.91.17.10
LowGHSA-x4h9-gwv3-r4m4ruby-saml@1.7.21.18.0
LowGHSA-fq42-c5rg-92c2nokogiri@1.10.91.13.2
LowGO-2021-0224stdlib@go1.13.91.13.13
LowDLA-2481-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u6
LowGHSA-g98m-96g9-wfjqbundler@1.16.62.1.0
LowGHSA-v569-hp3g-36wrrack@2.0.92.2.23
LowGO-2021-0317stdlib@go1.13.91.16.14
LowGHSA-228g-948r-83gxloofah@2.5.02.19.1
LowDLA-2566-1libbsd@0.8.3-10.8.3-1+deb9u1
LowGHSA-j5g9-f88f-gfj3httplib2@0.18.10.32.0
LowGO-2023-2185stdlib@go1.13.91.20.11
LowDLA-2614-1busybox@1:1.22.0-19+b31:1.22.0-19+deb9u2
LowDLA-2760-1nettle@3.3-1+b23.3-1+deb9u1
LowGO-2021-0235stdlib@go1.13.91.14.14
LowDLA-2596-1shadow@1:4.4-4.11:4.4-4.1+deb9u1
LowGO-2022-0229stdlib@go1.13.31.12.16
LowGHSA-8h22-8cf7-hq6gactivestorage@6.0.3.16.1.7.7
LowPYSEC-2026-3553cryptography@3.049.0.0
LowDLA-2771-1krb5@1.15-1+deb9u11.15-1+deb9u3
LowGHSA-wf93-45jw-7689pip@20.1.126.1.2
LowGHSA-cg4j-q9v8-6v38activesupport@6.0.3.17.2.3.1
LowGHSA-h2jq-g4cq-5ppqrack@2.0.92.2.23
LowGHSA-hm5p-x4rq-38w4httparty@0.16.40.24.0
LowALPINE-CVE-2021-22890curl@7.69.1-r07.76.0-r0
LowGO-2022-0537stdlib@go1.13.91.17.13

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.