StackRadar

temporal Helm chart

lemontechVerified publisher

Scored 14 Sept 2026

Temporal is a distributed, scalable, durable, and highly available orchestration engine to execute asynchronous long-running business logic in a scalable and resilient way.

Latest 0.37.0 2 years agodeploys tag 6.7.1 5Artifact Hub

temporal 0.37.0 deploys 13 container images: curlimages/curl, grafana/grafana, k8s.gcr.io/kube-state-metrics/kube-state-metrics, quay.io/prometheus/alertmanager and 9 more. Across the 9 measured, 1,257 findings1 critical, 32 high 7 on CISA KEV. The highest contribution is GHSA-mjmj-j48q-9wg2 in snakeyaml 1.11, fixed in 2.0.

Radar Score

14,8931321971,027

1,257 findings over 9 of 13 images measured

KEV ×7 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

13 images
ImageTagVulnerabilitiesRadar Score
curlimages/curl7.68.00352325
grafana/grafana6.7.108391842,910
k8s.gcr.io/kube-state-metrics/kube-state-metricsv2.3.0unmeasured
quay.io/prometheus/alertmanagerv0.23.003231561,972
jimmidyson/configmap-reload×2v0.5.00081251,260
prom/pushgatewayv1.4.203221511,925
quay.io/prometheus/prometheusv2.31.105301982,504
temporalio/admin-tools×121.25.0unmeasured
library/busybox×6latest00000
library/cassandra×113.11.31440711,926
temporalio/server×41.22.406301402,071
temporalio/ui2.24.2unmeasured
docker.elastic.co/elasticsearch/elasticsearch×27.17.3unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

449 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowDLA-3037-1libjpeg-turbo@1:1.5.1-21:1.5.1-2+deb9u2
LowGHSA-c5q2-7r4c-mv6ggopkg.in/square/go-jose.v2@v2.4.1no fix listed
LowGHSA-267v-3v32-g6q5github.com/crewjam/saml@v0.0.0-20191031171751-c42136edf9b10.4.14
LowGHSA-rc4r-wh2q-q6c4github.com/docker/docker@v20.10.9+incompatible20.10.18
LowGHSA-mq39-4gv4-mvpxgithub.com/docker/docker@v20.10.9+incompatible23.0.11
LowALPINE-CVE-2021-23839openssl@1.1.1d-r51.1.1j-r0
LowGO-2023-1703stdlib@go1.17.31.19.8
LowGO-2021-0241stdlib@go1.13.41.15.13
LowGO-2022-0521stdlib@go1.17.31.17.12
LowDLA-2425-1openldap@2.4.44+dfsg-5+deb9u22.4.44+dfsg-5+deb9u5
LowGO-2022-0477stdlib@go1.17.31.17.11
LowGO-2026-4341stdlib@go1.17.31.24.12
LowGO-2022-0533stdlib@go1.17.31.17.11
LowGHSA-q547-gmf8-8jr7github.com/russellhaering/goxmldsig@v0.0.0-20180430223755-7acd5e4a6ef71.1.0
LowGHSA-q98v-9f9w-f49qgo.temporal.io/server@v1.18.1-0.20230217005328-b313b7f586411.28.4
LowDSA-4393-1systemd@232-25+deb9u8232-25+deb9u9
LowGHSA-p768-c3pr-6459go.temporal.io/server@v1.18.1-0.20230217005328-b313b7f586411.26.3
LowGHSA-479m-364c-43vcgithub.com/russellhaering/goxmldsig@v0.0.0-20180430223755-7acd5e4a6ef71.6.0
LowGO-2022-0523stdlib@go1.17.31.17.12
LowGO-2024-2887stdlib@go1.17.31.21.11
LowGO-2022-0522stdlib@go1.17.31.17.12
LowGO-2022-0527stdlib@go1.17.31.17.12
LowGO-2022-0524stdlib@go1.17.31.17.12
LowGHSA-pxq6-2prw-chj9github.com/docker/docker@v20.10.9+incompatibleno fix listed
LowGO-2023-1704stdlib@go1.17.31.19.8
LowALPINE-CVE-2025-26519musl@1.2.4-r11.2.4-r3
LowGO-2022-0289stdlib@go1.17.31.16.12
LowDSA-4550-1file@1:5.30-1+deb9u21:5.30-1+deb9u3
LowGO-2020-0046github.com/russellhaering/goxmldsig@v0.0.0-20180430223755-7acd5e4a6ef71.1.1
LowGO-2021-0223stdlib@go1.13.41.13.13
LowGO-2022-0526stdlib@go1.17.31.17.12
LowALPINE-CVE-2020-28928musl@1.1.22-r31.1.22-r4
LowGO-2023-1568stdlib@go1.17.31.19.6
LowGHSA-xxxw-3j6h-q7h6github.com/grafana/grafana-plugin-sdk-go@v0.30.00.250.0
LowGHSA-c2h3-6mxw-7mvqgithub.com/containerd/containerd@v1.5.41.5.7
LowGO-2022-1037stdlib@go1.17.31.18.7
LowGO-2023-1987stdlib@go1.17.31.19.12
LowGHSA-2mm7-x5h6-5pvqgithub.com/docker/docker@v20.10.9+incompatible20.10.14
LowGHSA-hfvc-g4fc-pqhxgo.opentelemetry.io/otel/sdk@v1.16.01.43.0
LowGO-2023-1752stdlib@go1.17.31.19.9
LowGHSA-v86x-5fm3-5p7jgithub.com/prometheus/alertmanager@v0.23.00.25.1
LowGO-2023-1705stdlib@go1.17.31.19.8
LowGHSA-pr98-23f8-jwxvlogback-core@1.1.31.3.15
LowGO-2023-1878stdlib@go1.17.31.19.11
LowGHSA-jhq6-gfmj-v8fxlogback-core@1.1.31.5.34
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e0.52.0
LowGO-2022-1039stdlib@go1.17.31.18.7
LowDLA-2691-1libgcrypt20@1.7.6-2+deb9u31.7.6-2+deb9u4
LowGO-2024-2963stdlib@go1.17.31.21.12
LowGO-2023-1702stdlib@go1.17.31.19.8

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.37.0latest2 years ago6.7.11321971,02714,893

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/lemontech/temporal.svg)](https://charts.stackradar.io/charts/lemontech/temporal)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.