StackRadar

kubiya-runner 0.9.4 Helm chart

kubiya-helm-chartsOfficialVerified publisher

Scored 14 Sept 2026

A Helm chart for Kubiya Runner deployment

Version 0.9.4 10 months agodeploys tag v1.5.1 0Artifact Hub

kubiya-runner 0.9.4 deploys 9 container images: grafana/alloy, ghcr.io/jimmidyson/configmap-reload, registry.k8s.io/kube-state-metrics/kube-state-metrics, ghcr.io/kubiyabot/agent-manager and 5 more. Across them, 2,020 findings1 critical, 8 high 2 on CISA KEV. The highest contribution is DEBIAN-CVE-2025-48384 in git 1:2.39.5-0+deb12u1, fixed in 1:2.39.5-0+deb12u3. Chart.yaml declares kubeVersion >=1.19.0-0; rendered for Kubernetes 1.19.0.

Radar Score

20,204182701,738

2,020 findings over 9 of 9 images measured

KEV ×2 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

9 images
ImageTagVulnerabilitiesRadar Score
grafana/alloyv1.5.101372762,987
ghcr.io/jimmidyson/configmap-reloadv0.12.000275588
registry.k8s.io/kube-state-metrics/kube-state-metricsv2.14.000887786
ghcr.io/kubiyabot/agent-managerv0.4.1303834795,951
ghcr.io/kubiyabot/kubiya-operatorrunner_v200877725
ghcr.io/kubiyabot/tool-manager0.5.801161531,582
ghcr.io/kubiyabot/sdk-pyv1.20.001934547
ghcr.io/kubiyabot/workflow-enginev1.46.200171421,497
ghcr.io/kubiyabot/kubernetes1.32.012904155,541

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

954 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-qgqw-h4xq-7w8w@anthropic-ai/claude-code@1.0.1172.0.72
LowGHSA-h7wq-jj8r-qm7pk8s.io/kubernetes@v0.0.0-20241211175915-70d3cc986aa81.27.0-alpha.1
LowDEBIAN-CVE-2025-8194python3.13@3.13.5-23.13.5-2+deb13u1
LowDEBIAN-CVE-2026-48619nodejs@18.20.8-1nodesource1no fix listed
LowGHSA-7f5h-v6xp-fcq8starlette@0.39.20.49.1
LowDEBIAN-CVE-2026-15308python3.13@3.13.5-2no fix listed
LowDEBIAN-CVE-2026-32316jq@1.6-2.11.6-2.1+deb12u2
LowDEBIAN-CVE-2025-32415libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u2
LowDEBIAN-CVE-2026-0915glibc@2.41-122.41-12+deb13u2
LowDEBIAN-CVE-2025-4802glibc@2.36-9+deb12u92.36-9+deb12u11
LowDEBIAN-CVE-2023-50495ncurses@6.4-4no fix listed
LowGHSA-rgw5-rvv9-x895brace-expansion@2.0.12.1.4
LowDEBIAN-CVE-2026-13608curl@8.14.1-2no fix listed
LowDEBIAN-CVE-2026-5773curl@8.14.1-28.14.1-2+deb13u4
LowGHSA-r277-6w6q-xmqwgithub.com/getkin/kin-openapi@v0.127.00.144.0
LowDEBIAN-CVE-2026-63072openssl@3.5.1-1+deb13u13.5.7-1~deb13u2
LowDEBIAN-CVE-2026-40355krb5@1.21.3-51.21.3-5+deb13u1
LowGHSA-8wv5-x4w7-5gwwgithub.com/apache/thrift@v0.21.00.24.0
LowGHSA-f5x3-32g6-xq36tar@6.2.06.2.1
LowDEBIAN-CVE-2026-40356krb5@1.21.3-51.21.3-5+deb13u1
LowDEBIAN-CVE-2026-45445openssl@3.5.1-1+deb13u13.5.6-1~deb13u2
LowGHSA-93mq-9ffx-83m2github.com/expr-lang/expr@v1.16.91.17.0
LowDEBIAN-CVE-2026-85091zlib@1:1.3.dfsg+really1.3.1-1+b1no fix listed
LowDEBIAN-CVE-2026-60002openssh@1:10.0p1-7no fix listed
LowDEBIAN-CVE-2026-11972python3.13@3.13.5-23.13.5-2+deb13u5
LowGO-2023-2102stdlib@go1.21.11.20.10
LowGHSA-qffp-2rhf-9h96tar@6.2.07.5.10
LowDEBIAN-CVE-2026-48937nodejs@18.20.8-1nodesource1no fix listed
LowDSA-6166-1nodejs@18.20.8-1nodesource120.19.2+dfsg-1+deb13u1
LowDEBIAN-CVE-2026-80230curl@8.14.1-2no fix listed
LowALPINE-CVE-2025-27614git@2.43.6-r02.43.7-r0
LowGHSA-23hp-3jrh-7fpwtar@6.2.07.5.19
LowDEBIAN-CVE-2026-42013gnutls28@3.8.9-33.8.9-3+deb13u4
LowDEBIAN-CVE-2017-13716binutils@2.44-3no fix listed
LowDEBIAN-CVE-2026-0861glibc@2.41-122.41-12+deb13u2
LowGHSA-557j-xg8c-q2mmhelm.sh/helm/v3@v0.0.0-20241216182912-7877b45b63f93.17.4
LowGHSA-56hp-xqp3-w2jfhelm.sh/helm/v3@v0.0.0-20241216182912-7877b45b63f93.6.1
LowDEBIAN-CVE-2026-3833gnutls28@3.8.9-33.8.9-3+deb13u4
LowDEBIAN-CVE-2024-2236libgcrypt20@1.11.0-7no fix listed
LowDEBIAN-CVE-2026-31789openssl@3.5.1-1+deb13u13.5.5-1~deb13u2
LowDEBIAN-CVE-2025-69419openssl@3.5.1-1+deb13u13.5.4-1~deb13u2
LowDEBIAN-CVE-2023-45322libxml2@2.9.14+dfsg-1.3~deb12u12.9.14+dfsg-1.3~deb12u2
LowDEBIAN-CVE-2025-48060jq@1.6-2.11.6-2.1+deb12u1
LowGHSA-ff64-7w26-62rf@anthropic-ai/claude-code@1.0.1172.1.2
LowDEBIAN-CVE-2026-54874openssl@3.5.1-1+deb13u13.5.7-1~deb13u2
LowGHSA-q728-gf8j-w49r@anthropic-ai/claude-code@1.0.1172.0.74
LowGHSA-qw9x-cqr3-wc7rgithub.com/opencontainers/runc@v1.2.01.2.8
LowGHSA-cgrx-mc8f-2prmgithub.com/opencontainers/selinux@v1.11.11.13.0
LowGHSA-cgrx-mc8f-2prmgithub.com/opencontainers/runc@v1.2.01.2.8
LowGHSA-65xw-vw82-r86xgithub.com/antchfx/xpath@v1.3.21.3.6

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.9.4latest10 months agov1.5.1182701,73820,204

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/kubiya-helm-charts/kubiya-runner.svg)](https://charts.stackradar.io/charts/kubiya-helm-charts/kubiya-runner)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.