vcluster-k8s 0.0.0-ci.3 Helm chart
loftVerified publisherScored 14 Sept 2026
vcluster - Virtual Kubernetes Clusters (k8s)
Version 0.0.0-ci.3 3 years agoapp version 0.0.0-ci.3 2Artifact Hub
vcluster-k8s 0.0.0-ci.3 deploys 4 container images: registry.k8s.io/kube-apiserver, registry.k8s.io/kube-controller-manager, ghcr.io/loft-sh/vcluster and registry.k8s.io/etcd. Across the 3 measured, 526 findings — 0 critical, 11 high — 3 on CISA KEV. The highest contribution is GHSA-45x7-px36-x8w8 in golang.org/x/crypto v0.0.0-20220411220226-7b82a4e95df4, fixed in 0.0.0-20231218163308-9d2ee975ef9f.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| registry.k8s.io/ | v1.26.1 | 0420148 | 1,839 |
| registry.k8s.io/ | v1.26.1 | 0421148 | 1,855 |
| ghcr.io/ | 0.0.0-ci.3 | — | unmeasured |
| registry.k8s.io/ | 3.5.6-0 | 0320158 | 1,876 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | GHSA-qc2g-gmh6-95p4 | k8s.io/ | 1.26.6 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | GHSA-mh63-6h87-95cp | github.com/ | 4.5.2 |
| Low | GO-2023-1571 | stdlib | 1.19.6 |
| Low | GHSA-vv39-3w5q-974q | k8s.io/ | 1.29.13 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | GHSA-h7wq-jj8r-qm7p | k8s.io/ | 1.27.0-alpha.1 |
| Low | GO-2022-0435 | stdlib | 1.17.9 |
| Low | GO-2022-0288 | golang.org/ | 0.0.0-20211209124913-491a49abca63 |
| Low | GO-2023-2102 | stdlib | 1.20.10 |
| Low | GHSA-cgrx-mc8f-2prm | github.com/ | 1.13.0 |
| Low | GO-2022-0969 | stdlib | 1.18.6 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | GHSA-2wrh-6pvc-2jm9 | golang.org/ | 0.13.0 |
| Low | GO-2022-0493 | stdlib | 1.17.10 |
| Low | GO-2023-2185 | stdlib | 1.20.11 |
| Low | GHSA-4x4m-3c2p-qppc | k8s.io/ | 1.31.12 |
| Low | GO-2022-0537 | stdlib | 1.17.13 |
| Low | GHSA-c5q2-7r4c-mv6g | gopkg.in/ | no fix listed |
| Low | GHSA-3wgm-2gw2-vh5m | k8s.io/ | no fix listed |
| Low | GO-2023-1703 | stdlib | 1.19.8 |
| Low | GO-2022-0521 | stdlib | 1.17.12 |
| Low | GO-2022-0477 | stdlib | 1.17.11 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | GO-2022-0533 | stdlib | 1.17.11 |
| Low | GO-2022-0523 | stdlib | 1.17.12 |
| Low | GO-2024-2887 | stdlib | 1.21.11 |
| Low | GO-2022-0522 | stdlib | 1.17.12 |
| Low | GO-2022-0527 | stdlib | 1.17.12 |
| Low | GO-2022-0524 | stdlib | 1.17.12 |
| Low | GO-2023-1704 | stdlib | 1.19.8 |
| Low | GO-2022-0526 | stdlib | 1.17.12 |
| Low | GO-2023-1568 | stdlib | 1.19.6 |
| Low | GO-2022-1037 | stdlib | 1.18.7 |
| Low | GO-2023-1987 | stdlib | 1.19.12 |
| Low | GO-2023-1752 | stdlib | 1.19.9 |
| Low | GO-2023-1705 | stdlib | 1.19.8 |
| Low | GO-2023-1878 | stdlib | 1.19.11 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GO-2022-1039 | stdlib | 1.18.7 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GO-2023-1702 | stdlib | 1.19.8 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | GHSA-jgfp-53c3-624w | k8s.io/ | 1.29.14 |
| Low | GO-2022-0525 | stdlib | 1.17.12 |
| Low | GO-2022-0520 | stdlib | 1.17.12 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | GO-2023-2375 | stdlib | 1.20.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.0-ci.3latest | 3 years ago | 0.0.0-ci.3 | 01161454 | 5,570 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.