StackRadar

kubiya-runner 0.9.4 Helm chart

kubiya-helm-chartsOfficialVerified publisher

Scored 14 Sept 2026

A Helm chart for Kubiya Runner deployment

Version 0.9.4 10 months agodeploys tag v1.5.1 0Artifact Hub

kubiya-runner 0.9.4 deploys 9 container images: grafana/alloy, ghcr.io/jimmidyson/configmap-reload, registry.k8s.io/kube-state-metrics/kube-state-metrics, ghcr.io/kubiyabot/agent-manager and 5 more. Across them, 2,020 findings1 critical, 8 high 2 on CISA KEV. The highest contribution is DEBIAN-CVE-2025-48384 in git 1:2.39.5-0+deb12u1, fixed in 1:2.39.5-0+deb12u3. Chart.yaml declares kubeVersion >=1.19.0-0; rendered for Kubernetes 1.19.0.

Radar Score

20,204182701,738

2,020 findings over 9 of 9 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

9 images
ImageTagVulnerabilitiesRadar Score
grafana/alloyv1.5.101372762,987
ghcr.io/jimmidyson/configmap-reloadv0.12.000275588
registry.k8s.io/kube-state-metrics/kube-state-metricsv2.14.000887786
ghcr.io/kubiyabot/agent-managerv0.4.1303834795,951
ghcr.io/kubiyabot/kubiya-operatorrunner_v200877725
ghcr.io/kubiyabot/tool-manager0.5.801161531,582
ghcr.io/kubiyabot/sdk-pyv1.20.001934547
ghcr.io/kubiyabot/workflow-enginev1.46.200171421,497
ghcr.io/kubiyabot/kubernetes1.32.012904155,541

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

793 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGO-2026-6061google.golang.org/grpc@v1.73.01.82.1
LowGO-2026-6278github.com/gorilla/websocket@v1.5.01.5.3
LowUSN-7412-2gnupg2@2.4.4-2ubuntu172.4.4-2ubuntu17.3
LowUSN-8091-1util-linux@2.39.3-9ubuntu6.12.39.3-9ubuntu6.5
LowUSN-8436-1ca-certificates@2024020320260601~24.04.1
LowUSN-8625-1openssl@3.0.13-0ubuntu3.43.0.13-0ubuntu3.12
LowUSN-8688-1pam@1.5.3-5ubuntu5.11.5.3-5ubuntu5.7
LowALPINE-CVE-2025-46394busybox@1.36.1-r191.36.1-r21
LowDEBIAN-CVE-2026-40228systemd@257.8-1~deb13u2no fix listed
LowDEBIAN-CVE-2025-13462python3.13@3.13.5-23.13.5-2+deb13u1
LowDEBIAN-CVE-2025-61985openssh@1:10.0p1-71:10.0p1-7+deb13u1
LowDEBIAN-CVE-2026-21715nodejs@18.20.8-1nodesource120.19.2+dfsg-1+deb13u2
LowGHSA-5239-wwwm-4pmqpygments@2.18.02.20.0
LowGHSA-4vq8-7jfc-9cvpgithub.com/docker/docker@v27.4.1+incompatible28.0.0
LowDEBIAN-CVE-2026-58039nodejs@18.20.8-1nodesource1no fix listed
LowGHSA-66m2-gx93-v996@anthropic-ai/claude-code@1.0.1171.0.120
LowDEBIAN-CVE-2026-21716nodejs@18.20.8-1nodesource120.19.2+dfsg-1+deb13u2
LowGHSA-4q92-rfm6-2cqx@anthropic-ai/claude-code@1.0.1172.1.7
LowDEBIAN-CVE-2025-6170libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u3
LowGHSA-6jgm-j7h2-2fqggithub.com/snowflakedb/gosnowflake@v1.7.2-0.20240103203018-f1d625f174081.13.3
LowGHSA-m7cr-m3pv-hgrpgithub.com/go-git/go-git/v5@v5.11.05.19.1
LowGHSA-j88v-2chj-qfwxgithub.com/jackc/pgx/v4@v4.18.2no fix listed
LowDEBIAN-CVE-2011-4116perl@5.40.1-6no fix listed
LowDEBIAN-CVE-2026-57062gnupg2@2.4.7-21+b3no fix listed
LowGHSA-gm2x-2g9h-ccm8github.com/go-git/go-git/v5@v5.11.05.17.1
LowGHSA-6vgw-5pg2-w6jppip@24.026.0
LowDEBIAN-CVE-2026-15310python3.13@3.13.5-2no fix listed
LowDEBIAN-CVE-2026-53910diffutils@1:3.10-4no fix listed
LowDEBIAN-CVE-2026-6879python3.13@3.13.5-23.13.5-2+deb13u5
LowDEBIAN-CVE-2026-86137libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowDEBIAN-CVE-2026-86141libxml2@2.9.14+dfsg-1.3~deb12u1no fix listed
LowDEBIAN-CVE-2005-1119sudo@1.9.16p2-3no fix listed
LowDEBIAN-CVE-2026-24515expat@2.7.1-22.8.2-1~deb13u1
LowALPINE-CVE-2024-58251busybox@1.36.1-r191.36.1-r21
LowDEBIAN-CVE-2026-89162pcre2@10.46-1~deb13u110.46-1~deb13u2
LowDEBIAN-CVE-2026-89156pcre2@10.46-1~deb13u110.46-1~deb13u2
LowGHSA-xf85-363p-868woras.land/oras-go@v1.2.5no fix listed
LowDEBIAN-CVE-2025-66861binutils@2.44-3no fix listed
LowDEBIAN-CVE-2026-35388openssh@1:10.0p1-71:10.0p1-7+deb13u3
LowDEBIAN-CVE-2026-18503python3.13@3.13.5-2no fix listed
LowDEBIAN-CVE-2026-73283openssh@1:10.0p1-7no fix listed
LowDEBIAN-CVE-2026-5958sed@4.9-24.9-2+deb13u1
LowDEBIAN-CVE-2026-6368glibc@2.41-12no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.9.4latest10 months agov1.5.1182701,73820,204

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubiya-helm-charts/kubiya-runner.svg)](https://charts.stackradar.io/charts/kubiya-helm-charts/kubiya-runner)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.