StackRadar

nublado 0.9.23 Helm chart

lsst-sqre

Scored 14 Sept 2026

A Helm chart for Kubernetes

Version 0.9.23 5 years agodeploys tag v0.2 0Artifact Hub

nublado 0.9.23 deploys 5 container images: ericmandel/js9server, lsstsqre/sciplat-hub, jupyterhub/configurable-http-proxy, lsstsqre/wfdispatcher and 1 more. Across the 4 measured, 440 findings0 critical, 4 high. The highest contribution is GHSA-x4qr-2fvf-3mr5 in cryptography 3.4.7, fixed in 39.0.1.

Radar Score

5,78604131305

440 findings over 4 of 5 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
ericmandel/js9serverv0.2unmeasured
lsstsqre/sciplat-hublatest02631102,482
jupyterhub/configurable-http-proxylatest001447756
lsstsqre/wfdispatcherlatest0127741,274
lsstsqre/prepullerlatest0127741,274

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

157 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-8926curl@8.19.0-r08.22.0-r0
LowGHSA-7cx3-6m66-7c5mtornado@6.16.5
LowALPINE-CVE-2026-14456openssl@3.5.7-r03.5.8-r0
LowGHSA-34x7-hfp2-rc4vtar@2.2.17.5.7
LowALPINE-CVE-2026-11352curl@8.19.0-r08.22.0-r0
LowGHSA-rrvg-cxh4-qhrvoauthenticator@0.13.017.4.0
LowALPINE-CVE-2026-82209curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-80255curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-11564curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-32316jq@1.8.1-r01.8.2-r0
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.61.1.18
LowALPINE-CVE-2026-13608curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-5773curl@8.19.0-r08.20.0-r0
LowGHSA-hj3f-6gcp-jg8jtornado@6.16.3.2
LowALPINE-CVE-2026-63072openssl@3.5.7-r03.5.8-r0
LowALPINE-CVE-2026-11586curl@8.19.0-r08.22.0-r0
LowGHSA-f5x3-32g6-xq36tar@2.2.16.2.1
LowGHSA-55m3-44xf-hg4hoauthenticator@0.13.016.3.0
LowGHSA-q2x7-8rv6-6q7hjinja2@2.11.33.1.5
LowGHSA-qffp-2rhf-9h96tar@2.2.17.5.10
LowGHSA-mgf9-4vpg-hj56tornado@6.16.5.6
LowGHSA-xqr8-7jwr-rhp7certifi@2020.12.52023.7.22
LowALPINE-CVE-2026-80230curl@8.19.0-r08.22.0-r0
LowGHSA-c98p-7wgm-6p64tornado@6.16.5.3
LowGHSA-23hp-3jrh-7fpwtar@2.2.17.5.19
LowGHSA-hmw2-7cc7-3qxxform-data@2.0.02.5.6
LowGHSA-jhmp-mqwm-3gq8tornado@6.16.5.3
LowALPINE-CVE-2026-54874openssl@3.5.7-r03.5.8-r0
LowGHSA-9x4q-3gxw-849fjupyterhub@1.3.04.1.6
LowGHSA-7r86-cg39-jmmjminimatch@3.0.33.1.3
LowGHSA-gprj-3p75-f996oauthenticator@0.13.016.3.1
LowGHSA-8qq5-rm4j-mr97tar@2.2.17.5.3
LowALPINE-CVE-2026-9546curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-63075openssl@3.5.7-r03.5.8-r0
LowGHSA-23c5-xmqv-rm74minimatch@3.0.33.1.4
LowGHSA-mh99-v99m-4gvgbrace-expansion@1.1.61.1.17
LowGHSA-r6ph-v2qm-q3c2cryptography@3.4.746.0.5
LowALPINE-CVE-2026-33630c-ares@1.34.6-r01.34.8-r0
LowGHSA-3cwm-7jmm-774wbeaker@1.5.4no fix listed
LowGHSA-8x88-c5mf-7j5wtar@2.2.17.5.18
LowALPINE-CVE-2026-82208curl@8.19.0-r08.22.0-r0
LowGHSA-4hpf-3wq7-5rpris-my-json-valid@2.15.02.17.2
LowGHSA-7r3h-4ph8-w38gjupyterhub@1.3.04.1.0
LowALPINE-CVE-2026-12064curl@8.19.0-r08.22.0-r0
LowGHSA-43fp-rhv2-5gv8certifi@2020.12.52022.12.07
LowALPINE-CVE-2026-8932curl@8.19.0-r08.22.0-r0
LowGHSA-3x9g-8vmp-wqvftornado@6.16.5.6
LowPYSEC-2026-3553cryptography@3.4.749.0.0
LowALPINE-CVE-2026-8286curl@8.19.0-r08.22.0-r0
LowGHSA-wf93-45jw-7689pip@21.0.126.1.2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.9.23latest5 years agov0.2041313055,786

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/lsst-sqre/nublado.svg)](https://charts.stackradar.io/charts/lsst-sqre/nublado)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.