StackRadar

cognative Helm chart

myaVerified publisher

Scored 14 Sept 2026

cognative is an opinionated, minimalistic approach to business intelligence 🧠 and operations 🚨. We strongly believe companies should be able to own their own data, and many solutions out there leave organizations to the whims of third-party providers. Our goal is to reduce the complexity of traditional business intelligence and operations stacks, while seeking to maximize the efforts of everyday operations staff. This not only simplifies the process for operators, but also enhances the experience for less infrastructure-aware developers. (BETA) This chart provides an early access preview to the cogantive stack. It currently not suitable for production. I'm hoping to iterate on this stack in the public, and am actively looking for help from others to push it forward.

Latest 0.2403.3 2 years agoApp version not verified against the render 0Artifact Hub

cognative 0.2403.3 deploys 3 container images: otel/opentelemetry-collector-contrib, grafana/grafana and clickhouse/clickhouse-server. Across them, 635 findings3 critical, 14 high. The highest contribution is UBUNTU-CVE-2022-2068 in openssl 1.1.1f-1ubuntu2.22, fixed in 1.1.1f-1ubuntu2.fips.16.

Radar Score

7,30931496522

635 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
otel/opentelemetry-collector-contrib×30.96.002191551,721
grafana/grafana10.4.004251592,030
clickhouse/clickhouse-server24.238522083,558

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

339 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2025-40909perl@5.30.0-9ubuntu0.5no fix listed
LowGHSA-9mj6-hxhv-w67jgithub.com/dvsekhvalnov/jose2go@v1.6.01.7.0
LowUBUNTU-CVE-2026-48961perl@5.30.0-9ubuntu0.5no fix listed
LowGO-2023-1987stdlib@go1.19.101.19.12
LowGHSA-hfvc-g4fc-pqhxgo.opentelemetry.io/otel/sdk@v1.22.01.43.0
LowGHSA-q9hv-hpm4-hj6xgithub.com/cloudflare/circl@v1.3.71.6.3
LowUBUNTU-CVE-2025-14831gnutls28@3.6.13-2ubuntu1.113.6.13-2ubuntu1.12+esm2
LowUBUNTU-CVE-2026-6238glibc@2.31-0ubuntu9.15no fix listed
LowGHSA-mh55-gqvf-xfwmgithub.com/rs/cors@v1.10.11.11.0
LowGO-2023-1878stdlib@go1.19.101.19.11
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.18.00.52.0
LowUBUNTU-CVE-2026-5435glibc@2.31-0ubuntu9.15no fix listed
LowGO-2024-2963stdlib@go1.21.81.21.12
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.20.00.55.0
LowUBUNTU-CVE-2026-7017perl@5.30.0-9ubuntu0.5no fix listed
LowALPINE-CVE-2026-40200musl@1.2.4_git20230717-r41.2.4_git20230717-r6
LowUBUNTU-CVE-2025-0395glibc@2.31-0ubuntu9.152.31-0ubuntu9.17
LowUBUNTU-CVE-2023-4039gcc-10@10.5.0-1ubuntu1~20.0410.5.0-1ubuntu1~20.04.1+esm1
LowUBUNTU-CVE-2026-76642util-linux@2.34-0.1ubuntu9.6no fix listed
LowGHSA-j5w8-q4qc-rx2xgolang.org/x/crypto@v0.18.00.45.0
LowUBUNTU-CVE-2025-4598systemd@245.4-4ubuntu3.23245.4-4ubuntu3.24+esm1
LowGO-2023-2375stdlib@go1.19.101.20.0
LowGHSA-vvgc-356p-c3xwgolang.org/x/net@v0.20.00.38.0
LowGHSA-m454-3xv7-qj85github.com/ClickHouse/ch-go@v0.58.20.65.0
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.60.11.83.1
LowGHSA-v6v8-xj6m-xwqhgithub.com/hashicorp/go-retryablehttp@v0.7.40.7.7
LowGO-2023-2382stdlib@go1.19.101.20.12
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.18.00.52.0
LowUBUNTU-CVE-2026-22796openssl@1.1.1f-1ubuntu2.221.1.1f-1ubuntu2.24+esm2
LowGHSA-f6x5-jh6r-wrfvgolang.org/x/crypto@v0.18.00.45.0
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.18.00.52.0
LowGO-2024-2599stdlib@go1.21.71.21.8
LowGHSA-prf6-xjxh-p698github.com/open-telemetry/opentelemetry-collector-contrib/receiver/awsfirehosereceiver@v0.96.00.108.0
LowGO-2024-3106stdlib@go1.21.81.22.7
LowALPINE-CVE-2024-2004curl@8.5.0-r08.7.1-r0
LowALPINE-CVE-2023-42364busybox@1.36.1-r151.36.1-r19
LowALPINE-CVE-2023-42363busybox@1.36.1-r151.36.1-r17
LowUBUNTU-CVE-2025-68973gnupg2@2.2.19-3ubuntu2.22.2.19-3ubuntu2.5+esm1
LowGHSA-337j-9hxr-rhxgreact-router@6.21.37.18.0
LowGO-2024-2600stdlib@go1.21.71.21.8
LowALPINE-CVE-2023-42366busybox@1.36.1-r151.36.1-r16
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.60.11.82.1
LowGO-2024-2609stdlib@go1.21.71.21.8
LowUBUNTU-CVE-2026-34743xz-utils@5.2.4-1ubuntu1.15.2.4-1ubuntu1.1+esm1
LowGO-2024-3107stdlib@go1.21.81.22.7
LowALPINE-CVE-2023-42365busybox@1.36.1-r151.36.1-r19
LowUBUNTU-CVE-2026-54411pam@1.3.1-5ubuntu4.7no fix listed
LowGHSA-ffqx-q65f-36jfgithub.com/grafana/tempo@v1.5.1-0.20230524121406-1dc1bfe7085b2.10.3
LowGHSA-cp6g-7hqx-qxhpgo.mongodb.org/mongo-driver@v1.13.11.17.7
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.6.11.7.8

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.2403.3latest2 years ago314965227,309

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/mya/cognative.svg)](https://charts.stackradar.io/charts/mya/cognative)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.