StackRadar

gitlab Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Latest 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

High findings

29 distinct across the version’s images

High: findings whose contribution to the Radar Score is 40–69. Show every band

SeverityAdvisoryPackageFixed in
HighALPINE-CVE-2022-25236expat@2.2.9-r12.2.10-r2
HighALPINE-CVE-2022-0778openssl@1.1.1g-r01.1.1n-r0
HighGHSA-x4qr-2fvf-3mr5cryptography@3.039.0.1
HighGHSA-xr9x-r78c-5hrmactivestorage@6.0.3.17.2.3.2
HighALPINE-CVE-2018-25032zlib@1.2.11-r31.2.12-r0
HighGHSA-jc36-42cf-vqwjnokogiri@1.10.91.13.4
HighALPINE-CVE-2021-23840openssl@1.1.1g-r01.1.1j-r0
HighALPINE-CVE-2021-3712openssl@1.1.1g-r01.1.1l-r0
HighGHSA-8877-prq4-9xfwactionpack@6.0.3.16.0.3.5
HighGHSA-4vc4-m8qh-g8jmruby-saml@1.7.21.12.4
HighGHSA-45x7-px36-x8w8golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.0.0-20231218163308-9d2ee975ef9f
HighALPINE-CVE-2022-37434zlib@1.2.11-r31.2.12-r2
HighGHSA-35mm-cc6r-8fjpactionpack@6.0.3.16.0.3.4
HighGHSA-qppj-fm5r-hxr3KEVgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.17.0
HighGHSA-59gp-qqm7-cw4jnokogiri@1.10.91.13.2
HighGHSA-4v7x-pqxf-cx7mgolang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.23.0
HighALPINE-CVE-2021-3449openssl@1.1.1g-r01.1.1k-r0
HighALPINE-CVE-2019-3822curl@7.57.0-r07.61.1-r2
HighALPINE-CVE-2018-1000120curl@7.57.0-r07.59.0-r0
HighGHSA-jw9c-mfg7-9rx2ruby-saml@1.7.21.12.3
HighALPINE-CVE-2018-14618curl@7.57.0-r07.61.1-r0
HighGHSA-ffhg-7mh4-33c4golang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.0.0-20200220183623-bac4c82f6975
HighGHSA-jvgm-pfqv-887xbundler@1.16.62.0.0
HighGHSA-pg8v-g4xq-hww9rails-html-sanitizer@1.3.01.4.3
HighALPINE-CVE-2018-1000122curl@7.57.0-r07.59.0-r0
HighDLA-2534-1KEVsudo@1.8.19p1-2.1+deb9u21.8.19p1-2.1+deb9u3
HighDLA-2663-1KEVlibimage-exiftool-perl@10.40-110.40-1+deb9u1
HighDLA-2776-1KEVapache2@2.4.25-3+deb9u92.4.25-3+deb9u11
HighGO-2022-0535KEVstdlib@go1.13.31.12.16

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.