kommander Helm chart
mesosphere-stableScored 14 Sept 2026
Kommander
Latest 0.39.2 3 years agodeploys tag 1.3.0 0Artifact Hub
kommander 0.39.2 deploys 29 container images: kiwigrid/k8s-sidecar, mesosphere/grafana-plugins, grafana/grafana, quay.io/kubernetes-multicluster/kubefed and 22 more. Across the 24 measured, 5,212 findings — 22 critical, 148 high — 21 on CISA KEV. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 1.1.1f-1ubuntu2, fixed in 1.1.1f-1ubuntu2.15.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-v86x-5fm3-5p7j | github.com/ | 0.25.1 |
| Low | UBUNTU-CVE-2025-14524 | curl | no fix listed |
| Low | UBUNTU-CVE-2025-14831 | gnutls28 | 3.6.13-2ubuntu1.12+esm2 |
| Low | ALPINE-CVE-2022-35252 | curl | 7.79.1-r3 |
| Low | UBUNTU-CVE-2022-35252 | curl | 7.68.0-1ubuntu2.13 |
| Low | UBUNTU-CVE-2026-6238 | glibc | no fix listed |
| Low | UBUNTU-CVE-2025-48386 | git | 1:2.25.1-1ubuntu3.14+esm1 |
| Low | GHSA-34jh-p97f-mpxf | urllib3 | 1.26.19 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | GHSA-w8wr-v893-vjvp | tar | 7.5.18 |
| Low | GO-2023-1705 | stdlib | 1.19.8 |
| Low | GHSA-m7pr-hjqh-92cm | axios | 0.31.1 |
| Low | UBUNTU-CVE-2021-20223 | sqlite3 | 3.31.1-4ubuntu0.4 |
| Low | UBUNTU-CVE-2026-3731 | libssh | 0.9.3-2ubuntu2.5+esm4 |
| Low | GO-2023-1878 | stdlib | 1.19.11 |
| Low | ALPINE-CVE-2021-42374 | busybox | 1.32.1-r7 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | UBUNTU-CVE-2026-5435 | glibc | no fix listed |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GO-2022-1039 | stdlib | 1.18.7 |
| Low | GHSA-869p-cjfg-cm3x | jws | 3.2.3 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GO-2023-1702 | stdlib | 1.19.8 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | GHSA-6gmq-8vp8-gcm6 | xmldom | no fix listed |
| Low | GHSA-jgfp-53c3-624w | k8s.io/ | 1.29.14 |
| Low | GHSA-mmx7-hfxf-jppx | axios | 0.33.0 |
| Low | UBUNTU-CVE-2026-7017 | perl | no fix listed |
| Low | GO-2022-0525 | stdlib | 1.17.12 |
| Low | GO-2022-0520 | stdlib | 1.17.12 |
| Low | GHSA-rrfw-hg9m-j47h | github.com/ | 0.4.2 |
| Low | MAL-2022-4691 | monorepo-symlink-test | no fix listed |
| Low | MAL-2022-4933 | npm-cli-docs | no fix listed |
| Low | GHSA-xw73-rw38-6vjc | github.com/ | 24.0.9 |
| Low | GHSA-xw73-rw38-6vjc | github.com/ | 24.0.9 |
| Low | UBUNTU-CVE-2025-0395 | glibc | 2.31-0ubuntu9.17 |
| Low | UBUNTU-CVE-2020-13844 | gcc-10 | 10.2.0-5ubuntu1~20.04 |
| Low | UBUNTU-CVE-2023-4039 | gcc-10 | 10.5.0-1ubuntu1~20.04.1+esm1 |
| Low | DLA-3850-1 | glibc | 2.28-10+deb10u4 |
| Low | UBUNTU-CVE-2026-76642 | util-linux | no fix listed |
| Low | DSA-4685-1 | apt | 1.8.2.1 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | UBUNTU-CVE-2026-11822 | sqlite3 | no fix listed |
| Low | UBUNTU-CVE-2026-11824 | sqlite3 | no fix listed |
| Low | GHSA-wf43-55jj-vwq8 | go.etcd.io/ | 3.4.0 |
| Low | UBUNTU-CVE-2025-4598 | systemd | 245.4-4ubuntu3.24+esm1 |
| Low | GHSA-f3fp-gc8g-vw66 | github.com/ | 1.1.2 |
| Low | GHSA-hmfx-3pcx-653p | github.com/ | 1.5.18 |
| Low | UBUNTU-CVE-2024-28085 | util-linux | 2.34-0.1ubuntu9.6 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.39.2latest | 3 years ago | 1.3.0 | 221481,0703,962 | 68,284 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.