StackRadar

gitlab Helm chart

kubesphereVerified publisher

Scored 14 Sept 2026

Web-based Git-repository manager with wiki and issue-tracking features.

Latest 4.2.3 5 years agoapp version 13.2.2 0Artifact Hub

gitlab 4.2.3 deploys 17 container images: gitlab/gitlab-runner, mirrorgitlabcontainers/alpine-certificates, library/busybox, mirrorgitlabcontainers/gitlab-shell and 13 more. Across the 14 measured, 2,657 findings5 critical, 80 high 18 on CISA KEV. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1g-r0, fixed in 1.1.1l-r0.

Radar Score

38,1335807271,845

2,657 findings over 14 of 17 images measured

KEV ×18 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

17 images
ImageTagVulnerabilitiesRadar Score
gitlab/gitlab-runner×2alpine-v13.2.1211841974,526
mirrorgitlabcontainers/alpine-certificates×720171114-r3001029
library/busybox×91.31.100000
mirrorgitlabcontainers/gitlab-shellv13.3.007662163,823
mirrorgitlabcontainers/gitlab-sidekiq-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-task-runner-ce×2v13.2.21121131995,119
mirrorgitlabcontainers/gitlab-webservice-ce×2v13.2.21111051854,803
mirrorgitlabcontainers/gitlab-workhorse-cev13.2.206652143,719
minio/minioRELEASE.2017-12-28T01-21-00Z0490480
kubesphere/nginx-ingress-controller0.21.000000
mirrorgooglecontainers/defaultbackend-amd641.4not yet scanned
mirrorgitlabcontainers/gitlab-container-registryv2.9.1-gitlab05491963,122
mirrorgitlabcontainers/gitalyv13.2.20121052905,548
bitnami/postgresql11.7.0unmeasured
bitnami/redis5.0.7-debian-9-r50unmeasured
minio/mcRELEASE.2018-07-13T00-53-22Z001029
mirrorgitlabcontainers/kubectl1.13.1201241632,132

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Medium findings

214 distinct across the version’s images

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

SeverityAdvisoryPackageFixed in
MediumDLA-2907-1apache2@2.4.25-3+deb9u92.4.25-3+deb9u12
MediumALPINE-CVE-2018-0500curl@7.57.0-r07.61.0-r0
MediumGO-2024-2687stdlib@go1.13.91.21.9
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.52.0
MediumALPINE-CVE-2018-16839curl@7.57.0-r07.61.1-r1
MediumDLA-2544-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u7
MediumDLA-3008-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u6
MediumGHSA-22f2-v57c-j9cxrack@2.0.92.2.8.1
MediumGHSA-jw9f-hh49-cvp9nokogiri@1.10.91.11.4
MediumGHSA-cf3w-g86h-35x4carrierwave@1.3.11.3.2
MediumALPINE-CVE-2021-22945curl@7.69.1-r07.79.0-r0
MediumDLA-2952-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u5
MediumDLA-2953-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u7
MediumALPINE-CVE-2022-25235expat@2.2.9-r12.2.10-r2
MediumALPINE-CVE-2018-1000301curl@7.57.0-r07.60.0-r0
MediumALPINE-CVE-2022-22822expat@2.2.9-r12.2.10-r0
MediumALPINE-CVE-2022-25315expat@2.2.9-r12.2.10-r2
MediumALPINE-CVE-2018-1000300curl@7.57.0-r07.60.0-r0
MediumDLA-2960-1apache2@2.4.25-3+deb9u92.4.25-3+deb9u13
MediumDLA-2706-1apache2@2.4.25-3+deb9u92.4.25-3+deb9u10
MediumGHSA-fp4w-jxhp-m23pbundler@1.16.62.2.10
MediumALPINE-CVE-2022-23852expat@2.2.9-r12.2.10-r1
MediumGHSA-mqm2-cgpr-p4m6kramdown@2.2.12.3.0
MediumDLA-3017-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u9
MediumALPINE-CVE-2020-8285curl@7.69.1-r07.69.1-r3
MediumGHSA-r4mg-4433-c7g3activestorage@6.0.3.17.1.5.2
MediumDLA-2574-1openldap@2.4.44+dfsg-5+deb9u42.4.44+dfsg-5+deb9u8
MediumALPINE-CVE-2018-1000121curl@7.57.0-r07.59.0-r0
MediumALPINE-CVE-2018-1000005curl@7.57.0-r07.58.0-r0
MediumDLA-2968-1zlib@1:1.2.8.dfsg-51:1.2.8.dfsg-5+deb9u1
MediumDLA-2563-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u3
MediumDLA-2565-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u4
MediumDLA-2766-1openssl@1.1.0l-1~deb9u11.1.0l-1~deb9u4
MediumDLA-2774-1openssl1.0@1.0.2u-1~deb9u11.0.2u-1~deb9u6
MediumALPINE-CVE-2022-22823expat@2.2.9-r12.2.10-r0
MediumALPINE-CVE-2022-22824expat@2.2.9-r12.2.10-r0
MediumGHSA-83g2-8m93-v3w7golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa0.0.0-20210520170846-37e1c6afe023
MediumGHSA-c3xm-pvg7-gh7rgithub.com/opencontainers/runc@v1.0.0-rc6.0.20190115182101-c1e454b2a1bf1.0.0-rc95
MediumALPINE-CVE-2021-45960expat@2.2.9-r12.2.10-r0
MediumGHSA-jphg-qwrw-7w9gjson@2.1.02.3.0
MediumGHSA-w749-p3v6-hccqactivestorage@6.0.3.16.0.4.7
MediumGHSA-v222-6mr4-qj29asciidoctor-include-ext@0.3.10.4.0
MediumGHSA-52p9-v744-mwjjkramdown@2.2.12.3.1
MediumALPINE-CVE-2019-14697musl@1.1.18-r31.1.18-r4
MediumGHSA-cg3q-j54f-5p7pgithub.com/prometheus/client_golang@v1.0.01.11.1
MediumGHSA-g6wq-qcwm-j5g2websocket-extensions@0.1.40.1.5
MediumGHSA-v4f8-2847-rwm7nokogiri@1.10.91.11.4
MediumALPINE-CVE-2022-28391busybox@1.31.1-r161.31.1-r22
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.0.0-20191011191535-87dc89f015500.31.0
MediumDLA-2935-1expat@2.2.0-2+deb9u32.2.0-2+deb9u5

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
4.2.3latest5 years ago13.2.25807271,84538,133

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubesphere/gitlab.svg)](https://charts.stackradar.io/charts/kubesphere/gitlab)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.