StackRadar

gitlab Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Latest 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

406 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-h2jq-g4cq-5ppqrack@2.0.92.2.23
LowGHSA-hm5p-x4rq-38w4httparty@0.16.40.24.0
LowALPINE-CVE-2021-22890curl@7.69.1-r07.76.0-r0
LowGO-2022-0537stdlib@go1.13.91.17.13
LowGO-2021-0234stdlib@go1.13.91.15.9
LowDLA-3037-1libjpeg-turbo@1:1.5.1-21:1.5.1-2+deb9u2
LowDLA-2777-1tiff@4.0.8-2+deb9u54.0.8-2+deb9u7
LowGHSA-8vqr-qjwx-82mwrack@2.0.92.2.23
LowGHSA-xp5h-f8jf-rc8qactionview@6.0.3.16.1.7.3
LowGHSA-h27x-rffw-24p4addressable@2.7.02.9.0
LowALPINE-CVE-2021-23839openssl@1.1.1g-r01.1.1j-r0
LowGHSA-m4p7-r5rc-7g4jpyasn1@0.4.80.6.4
LowGO-2023-1703stdlib@go1.13.91.19.8
LowGO-2021-0241stdlib@go1.13.91.15.13
LowGO-2022-0521stdlib@go1.13.91.17.12
LowDLA-2425-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u5
LowGHSA-8ppf-4f7h-5ppjpyasn1@0.4.80.6.4
LowGHSA-hm4w-wwcw-mr6rpyasn1@0.4.80.6.4
LowGO-2022-0477stdlib@go1.13.91.17.11
LowGHSA-3qc2-v3hp-6cv8sidekiq@5.2.96.5.10
LowGHSA-vfmv-jfc5-pjjwcarrierwave@1.3.12.2.6
LowGHSA-pj73-v5mw-pm9jactivesupport@6.0.3.16.1.7.3
LowGO-2026-4341stdlib@go1.13.91.24.12
LowGO-2022-0533stdlib@go1.13.91.17.11
LowALPINE-CVE-2021-22898curl@7.69.1-r07.77.0-r0
LowGHSA-jm35-h8q2-73mpdevise-two-factor@3.1.04.0.2
LowGHSA-rrqh-93c8-j966ruby-saml@1.7.21.18.1
LowDLA-2669-1libxml2@2.9.4+dfsg1-2.2+deb9u22.9.4+dfsg1-2.2+deb9u5
LowGO-2022-0523stdlib@go1.13.91.17.12
LowGO-2024-2887stdlib@go1.13.91.21.11
LowGO-2022-0522stdlib@go1.13.91.17.12
LowGO-2022-0527stdlib@go1.13.91.17.12
LowGO-2022-0524stdlib@go1.13.91.17.12
LowDLA-2694-1tiff@4.0.8-2+deb9u54.0.8-2+deb9u6
LowGHSA-r995-q44h-hr64webrick@1.4.21.8.2
LowGO-2023-1704stdlib@go1.13.91.19.8
LowGHSA-p9fm-f462-ggrgactivestorage@6.0.3.17.2.3.1
LowGO-2022-0289stdlib@go1.13.91.16.12
LowGHSA-4xqq-m2hx-25v8rexml@3.1.93.3.2
LowGHSA-2m96-52r3-2f3gfugit@1.2.11.11.1
LowGHSA-3m6q-jj5j-38c9oj@3.10.63.17.3
LowGHSA-c4rq-3m3g-8wgxnokogiri@1.10.91.19.3
LowGHSA-48rx-c7pg-q66rexcon@0.71.11.5.0
LowGHSA-9cv2-cfxc-v4v2nokogiri@1.10.91.19.4
LowGHSA-phwj-rprq-35ppnokogiri@1.10.91.19.4
LowGHSA-ghhp-3qvg-889pwebsocket-driver@0.7.10.8.1
LowGO-2021-0223stdlib@go1.13.91.13.13
LowDLA-2897-1apr@1.5.2-51.5.2-5+deb9u1
LowGHSA-33ph-fccm-39pjwebsocket-driver@0.7.10.8.1
LowGHSA-9ppp-w3g4-fh4qoj@3.10.63.17.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.