kommander Helm chart
mesosphere-stableScored 15 Sept 2026
Kommander
Latest 0.39.2 3 years agodeploys tag 1.3.0 0Artifact Hub
kommander 0.39.2 deploys 29 container images: kiwigrid/k8s-sidecar, mesosphere/grafana-plugins, grafana/grafana, quay.io/kubernetes-multicluster/kubefed and 22 more. Across the 24 measured, 5,219 findings — 21 critical, 149 high — 21 on CISA KEV. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 1.1.1f-1ubuntu2, fixed in 1.1.1f-1ubuntu2.15.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2022-0493 | stdlib | 1.17.10 |
| Low | GO-2021-0224 | stdlib | 1.13.13 |
| Low | UBUNTU-CVE-2025-6395 | gnutls28 | 3.6.13-2ubuntu1.12+esm1 |
| Low | UBUNTU-CVE-2025-24528 | krb5 | 1.17-6ubuntu4.9 |
| Low | GHSA-8x88-c5mf-7j5w | tar | 7.5.18 |
| Low | GO-2021-0317 | stdlib | 1.16.14 |
| Low | GHSA-jchw-25xp-jwwc | follow-redirects | 1.15.4 |
| Low | UBUNTU-CVE-2026-85091 | zlib | no fix listed |
| Low | GHSA-35c7-w35f-xwgh | k8s.io/ | 1.21.0 |
| Low | GHSA-rv95-896h-c2vc | express | 4.19.2 |
| Low | GO-2023-2185 | stdlib | 1.20.11 |
| Low | UBUNTU-CVE-2026-42497 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-41992 | gzip | no fix listed |
| Low | UBUNTU-CVE-2023-7008 | systemd | no fix listed |
| Low | DSA-4933-1 | nettle | 3.4.1-1+deb10u1 |
| Low | GO-2021-0235 | stdlib | 1.14.14 |
| Low | GHSA-2mj3-vfvx-fc43 | github.com/ | 26.0.0 |
| Low | ALPINE-CVE-2020-15358 | sqlite | 3.32.1-r1 |
| Low | UBUNTU-CVE-2019-20633 | patch | no fix listed |
| Low | GHSA-q8m4-xhhv-38mg | go.etcd.io/ | no fix listed |
| Low | GO-2022-0229 | stdlib | 1.12.16 |
| Low | UBUNTU-CVE-2020-29562 | glibc | 2.31-0ubuntu9.7 |
| Low | GHSA-j2g6-362q-6qc6 | github.com/ | 1.18.1 |
| Low | GHSA-43fp-rhv2-5gv8 | certifi | 2022.12.07 |
| Low | UBUNTU-CVE-2026-8932 | curl | 7.68.0-1ubuntu2.25+esm7 |
| Low | UBUNTU-CVE-2024-12133 | libtasn1-6 | 4.16.0-2ubuntu0.1 |
| Low | GHSA-qw64-3x98-g7q2 | github.com/ | 5.9.0 |
| Low | GHSA-2g4f-4pwh-qvx6 | ajv | 6.14.0 |
| Low | UBUNTU-CVE-2026-8286 | curl | 7.68.0-1ubuntu2.25+esm4 |
| Low | GHSA-wf93-45jw-7689 | pip | 26.1.2 |
| Low | GHSA-4x4m-3c2p-qppc | k8s.io/ | 1.31.12 |
| Low | GHSA-6chq-wfr3-2hj9 | axios | 0.31.1 |
| Low | UBUNTU-CVE-2024-33602 | glibc | 2.31-0ubuntu9.16 |
| Low | GHSA-p8p7-x288-28g6 | request | no fix listed |
| Low | GHSA-r6q2-hw4h-h46w | tar | 7.5.4 |
| Low | GHSA-2883-xcg3-v3hh | js-yaml | 3.15.2 |
| Low | UBUNTU-CVE-2026-4046 | glibc | no fix listed |
| Low | GHSA-r292-9mhp-454m | tar | 7.5.21 |
| Low | UBUNTU-CVE-2026-0966 | libssh | 0.9.3-2ubuntu2.5+esm3 |
| Low | GHSA-r4q5-vmmm-2653 | follow-redirects | 1.16.0 |
| Low | ALPINE-CVE-2021-22890 | curl | 7.76.0-r0 |
| Low | UBUNTU-CVE-2021-22890 | curl | 7.68.0-1ubuntu2.5 |
| Low | GO-2022-0537 | stdlib | 1.17.13 |
| Low | GHSA-3vp4-m3rf-835h | github.com/ | 1.9.0 |
| Low | GO-2021-0234 | stdlib | 1.15.9 |
| Low | UBUNTU-CVE-2026-48959 | perl | no fix listed |
| Low | UBUNTU-CVE-2026-59843 | libssh | no fix listed |
| Low | UBUNTU-CVE-2026-5928 | glibc | no fix listed |
| Low | GHSA-c5q2-7r4c-mv6g | gopkg.in/ | no fix listed |
| Low | GHSA-267v-3v32-g6q5 | github.com/ | 0.4.14 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.39.2latest | 3 years ago | 1.3.0 | 211491,0703,969 | 68,330 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.