StackRadar

vela-core Helm chart

kubevela

Scored 19 Sept 2026

A Helm chart for KubeVela core

Latest 1.11.0 2 months agoapp version 1.11.0 12Artifact Hub

vela-core 1.11.0 deploys 3 container images: oamdev/cluster-gateway, oamdev/vela-core and oamdev/kube-webhook-certgen. Across them, 450 findings0 critical, 9 high 2 on CISA KEV. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.0.8-r3, fixed in 3.0.19-r0.

Radar Score

4,6020950391

450 findings over 3 of 3 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
oamdev/cluster-gateway×2v1.9.0-alpha.207271352,010
oamdev/vela-corev1.11.00081311,157
oamdev/kube-webhook-certgen×3v2.4.102151251,435

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

210 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.40.00.52.0
LowGHSA-6g7g-w4f8-9c9xgithub.com/buger/jsonparser@v1.1.11.1.2
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.40.00.52.0
LowGO-2023-1571stdlib@go1.17.111.19.6
LowGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.67.11.82.2
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.67.11.83.1
LowGHSA-r277-6w6q-xmqwgithub.com/getkin/kin-openapi@v0.131.00.144.0
LowGO-2022-0288golang.org/x/net@v0.0.0-20210428140749-89ef3d95e7810.0.0-20211209124913-491a49abca63
LowGO-2023-2102stdlib@go1.17.111.20.10
LowALPINE-CVE-2025-69419openssl@3.0.8-r33.0.19-r0
LowGHSA-557j-xg8c-q2mmhelm.sh/helm/v3@v3.14.43.17.4
LowGO-2022-0969stdlib@go1.17.111.18.6
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.40.00.52.0
LowGHSA-xhj3-7xw9-vr34github.com/getkin/kin-openapi@v0.131.00.142.0
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.40.00.52.0
LowALPINE-CVE-2023-1255openssl@3.0.8-r33.0.8-r4
LowGHSA-2wrh-6pvc-2jm9golang.org/x/net@v0.0.0-20210428140749-89ef3d95e7810.13.0
LowGHSA-mmfr-pmjx-hw9wgithub.com/getkin/kin-openapi@v0.131.00.141.0
LowGO-2023-2185stdlib@go1.17.111.20.11
LowALPINE-CVE-2024-4603openssl@3.0.8-r33.0.13-r0
LowGHSA-qw64-3x98-g7q2github.com/go-git/go-billy/v5@v5.6.25.9.0
LowGHSA-p436-gjf2-799pgithub.com/docker/cli@v24.0.9+incompatible29.2.0
LowGO-2022-0537stdlib@go1.17.111.17.13
LowGO-2023-1703stdlib@go1.17.111.19.8
LowGO-2022-0521stdlib@go1.17.111.17.12
LowGO-2026-4341stdlib@go1.17.111.24.12
LowGHSA-5xqw-8hwv-wg92helm.sh/helm/v3@v3.14.43.17.3
LowGHSA-hc8v-wwc9-vgxmgithub.com/go-git/go-git/v5@v5.16.05.19.2
LowGO-2022-0523stdlib@go1.17.111.17.12
LowGO-2024-2887stdlib@go1.17.111.21.11
LowGO-2022-0522stdlib@go1.17.111.17.12
LowGO-2022-0527stdlib@go1.17.111.17.12
LowGO-2022-0524stdlib@go1.17.111.17.12
LowGHSA-4hfp-h4cw-hj8phelm.sh/helm/v3@v3.14.43.17.3
LowGHSA-pxq6-2prw-chj9github.com/docker/docker@v28.3.3+incompatibleno fix listed
LowGO-2023-1704stdlib@go1.17.111.19.8
LowALPINE-CVE-2025-26519musl@1.2.3-r41.2.3-r6
LowGHSA-xhf5-7wjv-pqxpgithub.com/containerd/containerd@v1.7.271.7.33
LowGO-2022-0526stdlib@go1.17.111.17.12
LowGO-2023-1568stdlib@go1.17.111.19.6
LowGHSA-m3xc-h892-ggx6github.com/go-git/go-billy/v5@v5.6.25.9.0
LowGO-2022-1037stdlib@go1.17.111.18.7
LowGHSA-qgq7-7hm3-q39jgithub.com/go-git/go-git/v5@v5.16.05.19.2
LowGO-2023-1987stdlib@go1.17.111.19.12
LowGHSA-hfvc-g4fc-pqhxgo.opentelemetry.io/otel/sdk@v1.28.01.43.0
LowGO-2023-1752stdlib@go1.17.111.19.9
LowGHSA-q9hv-hpm4-hj6xgithub.com/cloudflare/circl@v1.6.11.6.3
LowGO-2023-1705stdlib@go1.17.111.19.8
LowGO-2023-1878stdlib@go1.17.111.19.11
LowALPINE-CVE-2023-2975openssl@3.0.8-r33.0.9-r2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.11.0latest2 months ago1.11.009503914,602

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubevela/vela-core.svg)](https://charts.stackradar.io/charts/kubevela/vela-core)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 19 Sept 2026 · scanned 19 Sept 2026 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.