kommander 0.39.2 Helm chart
mesosphere-stableScored 15 Sept 2026
Kommander
Version 0.39.2 3 years agodeploys tag 1.3.0 0Artifact Hub
kommander 0.39.2 deploys 29 container images: kiwigrid/k8s-sidecar, mesosphere/grafana-plugins, grafana/grafana, quay.io/kubernetes-multicluster/kubefed and 22 more. Across the 24 measured, 5,219 findings — 21 critical, 149 high — 21 on CISA KEV. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 1.1.1f-1ubuntu2, fixed in 1.1.1f-1ubuntu2.15.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | UBUNTU-CVE-2026-72522 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56403 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56404 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56405 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56408 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56406 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56407 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56410 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-56411 | expat | no fix listed |
| Low | UBUNTU-CVE-2026-78410 | util-linux | no fix listed |
| Low | GHSA-q6x5-8v7m-xcrf | @protobufjs/ | 1.1.1 |
| Low | UBUNTU-CVE-2026-89161 | pcre2 | no fix listed |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GO-2026-5026 | golang.org/ | 0.55.0 |
| Low | UBUNTU-CVE-2025-14104 | util-linux | no fix listed |
| Low | GHSA-pxhw-596r-rwq5 | k8s.io/ | 1.27.13 |
| Low | UBUNTU-CVE-2026-42014 | gnutls28 | 3.6.13-2ubuntu1.12+esm3 |
| Low | GO-2025-3420 | stdlib | 1.22.11 |
| Low | GO-2026-4342 | stdlib | 1.24.12 |
| Low | GO-2024-2598 | stdlib | 1.21.8 |
| Low | GO-2025-3751 | stdlib | 1.23.10 |
| Low | UBUNTU-CVE-2026-78409 | util-linux | no fix listed |
| Low | UBUNTU-CVE-2024-13176 | openssl | 1.1.1f-1ubuntu2.24 |
| Low | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Low | GHSA-5p4m-2wfm-xmqj | js-yaml | 3.15.1 |
| Low | GHSA-74fp-r6jw-h4mp | k8s.io/ | 0.0.0-20190927203648-9ce6eca90e73 |
| Low | GHSA-m425-mq94-257g | google.golang.org/ | 1.56.3 |
| Low | GHSA-pcgw-qcv5-h8ch | github.com/ | 0.11.0 |
| Low | GHSA-qm7x-rc44-rrqw | apollo-server | 2.25.3 |
| Low | UBUNTU-CVE-2025-52099 | sqlite3 | 3.31.1-4ubuntu0.7 |
| Low | GO-2024-2961 | golang.org/ | 0.0.0-20220525230936-793ad666bf5e |
| Low | GHSA-g4mx-q9vg-27p4 | urllib3 | 1.26.18 |
| Low | GO-2025-4116 | golang.org/ | 0.43.0 |
| Low | UBUNTU-CVE-2026-58055 | nghttp2 | no fix listed |
| Low | GO-2026-4870 | stdlib | 1.25.9 |
| Low | GO-2022-0532 | stdlib | 1.17.11 |
| Low | GO-2025-4009 | stdlib | 1.24.8 |
| Low | GO-2026-4947 | stdlib | 1.25.9 |
| Low | UBUNTU-CVE-2021-20193 | tar | 1.30+dfsg-7ubuntu0.20.04.2 |
| Low | GHSA-4mjr-xmp4-gh2g | qs | 6.16.0 |
| Low | GHSA-rg2x-37c3-w2rh | github.com/ | no fix listed |
| Low | GHSA-rg2x-37c3-w2rh | github.com/ | no fix listed |
| Low | GO-2025-4006 | stdlib | 1.24.8 |
| Low | GHSA-2c4m-59x9-fr2g | github.com/ | 1.9.1 |
| Low | GO-2024-2780 | k8s.io/ | 1.13.7 |
| Low | GHSA-6jvc-q2x7-pchv | github.com/ | 1.34.0 |
| Low | UBUNTU-CVE-2025-29088 | sqlite3 | 3.31.1-4ubuntu0.7 |
| Low | GO-2026-5037 | stdlib | 1.25.11 |
| Low | UBUNTU-CVE-2026-40225 | systemd | 245.4-4ubuntu3.24+esm3 |
| Low | GO-2026-4971 | stdlib | 1.25.10 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.39.2latest | 3 years ago | 1.3.0 | 211491,0703,969 | 68,330 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.