StackRadar

nublado Helm chart

lsst-sqre

Scored 14 Sept 2026

A Helm chart for Kubernetes

Latest 0.9.23 5 years agodeploys tag v0.2 0Artifact Hub

nublado 0.9.23 deploys 5 container images: ericmandel/js9server, lsstsqre/sciplat-hub, jupyterhub/configurable-http-proxy, lsstsqre/wfdispatcher and 1 more. Across the 4 measured, 440 findings0 critical, 4 high. The highest contribution is GHSA-x4qr-2fvf-3mr5 in cryptography 3.4.7, fixed in 39.0.1.

Radar Score

5,78604131305

440 findings over 4 of 5 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
ericmandel/js9serverv0.2unmeasured
lsstsqre/sciplat-hublatest02631102,482
jupyterhub/configurable-http-proxylatest001447756
lsstsqre/wfdispatcherlatest0127741,274
lsstsqre/prepullerlatest0127741,274

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

236 distinct across the version’s images
SeverityAdvisoryPackageFixed in
HighGHSA-x4qr-2fvf-3mr5cryptography@3.4.739.0.1
HighGHSA-3jfq-g458-7qm9tar@2.2.13.2.2
MediumGHSA-hrpp-h998-j3ppqs@6.2.16.2.4
MediumGHSA-xvch-5gv4-984hminimist@0.0.80.2.4
MediumGHSA-896r-f27r-55mwjson-schema@0.2.30.4.0
MediumGHSA-887w-45rq-vxgfsqlalchemy@0.9.81.3.0b3
MediumGHSA-jp4x-w63m-7wgmhoek@2.16.34.2.1
MediumGHSA-8hfj-j24r-96c4moment@2.29.12.29.2
MediumGHSA-wc69-rhjr-hc9gmoment@2.29.12.29.4
MediumGHSA-p28m-34f6-967qpyopenssl@0.13.117.5.0
MediumGHSA-x8qc-rrcw-4r46npm@3.10.106.13.3
MediumGHSA-m6cx-g6qm-p2cxnpm@3.10.106.13.3
MediumGHSA-fjxv-7rqg-78g4form-data@2.0.02.5.4
MediumGHSA-pw54-mh39-w3hcnpm-user-validate@0.1.51.0.1
MediumGHSA-qqgx-2p2h-9c37ini@1.3.41.3.6
MediumGHSA-g7q5-pjjr-gqvptough-cookie@2.3.12.3.3
MediumGHSA-q2q7-5pp4-w6pgurllib3@1.26.41.26.5
MediumGHSA-j44m-qm6p-hp7mtar@2.2.12.2.2
MediumGHSA-cx63-2mw6-8hw5setuptools@39.2.070.0.0
MediumGHSA-gpvv-69j7-gwj8pip@9.0.319.2
MediumGHSA-38jv-5279-wg99urllib3@1.26.42.6.3
MediumGHSA-c2qf-rxjj-qqgwsemver@5.3.05.7.2
MediumGHSA-qwmp-2cf2-g9g6wheel@0.36.20.38.1
MediumGHSA-r9hx-vwmv-q579setuptools@39.2.065.5.1
MediumALPINE-CVE-2026-19931curl@8.19.0-r08.22.0-r0
MediumGHSA-832h-xg76-4gv6brace-expansion@1.1.61.1.7
MediumPYSEC-2025-49setuptools@39.2.078.1.1
MediumGHSA-xf7w-r453-m56cfstream@1.0.101.0.12
MediumGHSA-gqgv-6jq5-jjj9qs@6.2.16.2.3
MediumALPINE-CVE-2026-9079curl@8.19.0-r08.22.0-r0
MediumGHSA-4328-8hgf-7wjrnpm@3.10.106.13.4
MediumGHSA-v973-fxgf-6xhpmako@1.1.41.2.2
MediumALPINE-CVE-2026-63073openssl@3.5.7-r03.5.8-r0
MediumGHSA-9vvw-cc9w-f27hdebug@2.2.02.6.9
MediumGHSA-38fc-9xqv-7f7qsqlalchemy@0.9.81.2.19
MediumALPINE-CVE-2026-10536curl@8.19.0-r08.22.0-r0
MediumGHSA-m678-f26j-3hrpjupyter-core@4.7.14.11.2
MediumGHSA-f8q6-p94x-37v3minimatch@3.0.33.0.5
MediumGHSA-x3m3-4wpv-5vgcrequirejs@2.3.62.3.7
MediumGHSA-2m39-62fm-q8r3sshpk@1.10.11.13.2
MediumGHSA-72xf-g2v4-qvf3tough-cookie@2.3.14.1.3
MediumGHSA-5955-9wpr-37jhtar@2.2.14.4.18
MediumALPINE-CVE-2026-18924curl@8.19.0-r08.22.0-r0
MediumGHSA-j8r2-6x86-q33qrequests@2.25.12.31.0
MediumALPINE-CVE-2026-11856curl@8.19.0-r08.22.0-r0
MediumPYSEC-2023-192urllib3@1.26.42.0.6
MediumALPINE-CVE-2026-8925curl@8.19.0-r08.22.0-r0
MediumALPINE-CVE-2026-18798openssl@3.5.7-r03.5.8-r0
MediumGHSA-mf6x-7mm4-x2g7stringstream@0.0.50.0.6
MediumGHSA-pp7h-53gx-mx7rbl@1.1.21.2.3

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.9.23latest5 years agov0.2041313055,786

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/lsst-sqre/nublado.svg)](https://charts.stackradar.io/charts/lsst-sqre/nublado)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.