vcluster-pro-k0s Helm chart
loftVerified publisherScored 14 Sept 2026
vcluster-pro - Virtual Kubernetes Clusters (k0s)
Latest 0.0.0-ci-run.10 3 years agoApp version not verified against the render 0Artifact Hub
vcluster-pro-k0s 0.0.0-ci-run.10 deploys 2 container images: k0sproject/k0s and ghcr.io/loft-sh/vcluster-pro. Across them, 483 findings — 2 critical, 15 high — 3 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.83.1-r5, fixed in 8.4.0-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| k0sproject/ | v1.26.0-k0s.0 | 2941198 | 3,136 |
| ghcr.io/ | 0.0.0-ci-run.10 | 0635192 | 2,632 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-4x4m-3c2p-qppc | k8s.io/ | 1.31.12 |
| Low | GHSA-p436-gjf2-799p | github.com/ | 29.2.0 |
| Low | GHSA-qhmp-q7xh-99rh | github.com/ | 1.14.3 |
| Low | GHSA-c5q2-7r4c-mv6g | gopkg.in/ | no fix listed |
| Low | GHSA-rc4r-wh2q-q6c4 | github.com/ | 20.10.18 |
| Low | GHSA-mq39-4gv4-mvpx | github.com/ | 23.0.11 |
| Low | GHSA-vpvm-3wq2-2wvm | github.com/ | 1.1.5 |
| Low | GHSA-3wgm-2gw2-vh5m | k8s.io/ | no fix listed |
| Low | GHSA-v53g-5gjp-272r | helm.sh/ | 3.14.1 |
| Low | GO-2023-1703 | stdlib | 1.19.8 |
| Low | GHSA-93mf-426m-g6x9 | github.com/ | 1.12.4 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | GHSA-5xqw-8hwv-wg92 | helm.sh/ | 3.17.3 |
| Low | GHSA-hfmw-7g3m-gj6q | github.com/ | 1.11.0 |
| Low | GO-2024-2887 | stdlib | 1.21.11 |
| Low | GHSA-4hfp-h4cw-hj8p | helm.sh/ | 3.17.3 |
| Low | GHSA-53c4-hhmh-vw5q | helm.sh/ | 3.10.3 |
| Low | GHSA-67fx-wx78-jx33 | helm.sh/ | 3.10.3 |
| Low | GHSA-pxq6-2prw-chj9 | github.com/ | no fix listed |
| Low | GO-2023-1704 | stdlib | 1.19.8 |
| Low | ALPINE-CVE-2025-26519 | musl | 1.2.4-r3 |
| Low | GHSA-6wxm-mpqj-6jpf | github.com/ | 1.2.4 |
| Low | GHSA-6rx9-889q-vv2r | helm.sh/ | 3.10.3 |
| Low | GHSA-m9w6-wp3h-vq8g | github.com/ | 1.11.2 |
| Low | ALPINE-CVE-2023-28322 | curl | 8.1.0-r0 |
| Low | GO-2023-1568 | stdlib | 1.19.6 |
| Low | GO-2023-1987 | stdlib | 1.19.12 |
| Low | GO-2023-1752 | stdlib | 1.19.9 |
| Low | GO-2023-1705 | stdlib | 1.19.8 |
| Low | GO-2023-1878 | stdlib | 1.19.11 |
| Low | ALPINE-CVE-2023-2975 | openssl | 3.1.1-r2 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-9h84-qmv7-982p | helm.sh/ | 3.18.5 |
| Low | GHSA-f9f8-9pmf-xv68 | helm.sh/ | 3.18.5 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GO-2023-1702 | stdlib | 1.19.8 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | GHSA-jgfp-53c3-624w | k8s.io/ | 1.29.14 |
| Low | GHSA-xw73-rw38-6vjc | github.com/ | 24.0.9 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | GHSA-hmfx-3pcx-653p | github.com/ | 1.6.18 |
| Low | GO-2023-2375 | stdlib | 1.20.0 |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | GO-2023-1569 | stdlib | 1.19.6 |
| Low | GHSA-g2j6-57v7-gm8c | github.com/ | 1.1.5 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GO-2023-2382 | stdlib | 1.20.12 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-r6j8-c6r2-37rr | k8s.io/ | 1.32.10 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.0-ci-run.10latest | 3 years ago | — | 21576390 | 5,768 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.