clowder2 Helm chart
ncsaVerified publisherScored 15 Sept 2026
Open Source Data Management for Long Tail Data. Clowder is a customizable and scalable data management framework to support any data format and multiple research domains.
Latest 1.9.7 9 months agoapp version 2.0.0-beta.4 1Artifact Hub
clowder2 1.9.7 deploys 12 container images: bitnamilegacy/minio, bitnamilegacy/mongodb, clowder/clowder2-backend, clowder/clowder2-frontend and 8 more. Across them, 3,295 findings — 14 critical, 33 high — 12 on CISA KEV. The highest contribution is GHSA-f58c-gq56-vjjf in tika-core 2.7.0, fixed in 3.2.2.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnamilegacy/ | 2023.12.23 | 0226180 | 2,291 |
| bitnamilegacy/ | 5.0.10 | 1631206 | 2,886 |
| clowder/ | 2.0.0-beta.4 | 0246242 | 3,257 |
| clowder/ | 2.0.0-beta.4 | 012074 | 1,092 |
| clowder/ | 2.0.0-beta.4 | 0246242 | 3,257 |
| clowder/ | 2.0.0-beta.4 | 0246242 | 3,257 |
| bitnamilegacy/ | 12-debian-12-r16 | 3663307 | 4,478 |
| bitnamilegacy/ | 8.12.2 | 76100533 | 7,621 |
| bitnamilegacy/ | 15.5.0 | 2025125 | 1,897 |
| library/ | 1.28 | 0000 | 0 |
| bitnamilegacy/ | 20.0.5 | 1359452 | 5,466 |
| bitnamilegacy/ | 3.10.8 | 0315165 | 1,939 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DLA-4319-1 | libxml2 | 2.9.10+dfsg-6.7+deb11u9 |
| Low | ALPINE-CVE-2026-41080 | expat | 2.8.1-r0 |
| Low | BIT-postgresql-2026-14673 | postgresql | 14.24.0 |
| Low | BIT-postgresql-2026-14673 | PostgreSQL | 14.24.0 |
| Low | DEBIAN-CVE-2023-4016 | procps | no fix listed |
| Low | GHSA-22rm-wp4x-v5cx | keycloak-services | 26.4.13 |
| Low | GHSA-m2w5-7xhv-w6fh | keycloak-services | no fix listed |
| Low | GHSA-w573-9ffj-6ff9 | netty-transport-native-epoll | 4.1.135.Final |
| Low | ALPINE-CVE-2025-69418 | openssl | 3.5.5-r0 |
| Low | DEBIAN-CVE-2025-69418 | openssl | 3.0.18-1~deb12u2 |
| Low | DEBIAN-CVE-2007-5686 | shadow | no fix listed |
| Low | GHSA-g78x-7vwx-9f58 | keycloak-services | 26.4.9 |
| Low | GHSA-j75r-vf64-6rrh | resteasy-reactive-common | 3.0.0.Alpha4 |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | GHSA-6q37-7866-h27j | keycloak-services | 26.5.0 |
| Low | GHSA-6g26-7cx5-mrrg | keycloak-services | 26.7.0 |
| Low | DEBIAN-CVE-2026-18477 | tar | no fix listed |
| Low | BIT-postgresql-2025-12817 | PostgreSQL | 13.23.0 |
| Low | BIT-postgresql-2025-12817 | postgresql | 13.23.0 |
| Low | BIT-postgresql-2025-8713 | postgresql | 13.22.0 |
| Low | BIT-postgresql-2025-8713 | PostgreSQL | 13.22.0 |
| Low | GHSA-xjvp-4fhw-gc47 | github.com/ | 1.3.6 |
| Low | GHSA-594w-2fwp-jwrc | keycloak-services | no fix listed |
| Low | GHSA-xh32-c9wx-phrp | keycloak-services | no fix listed |
| Low | DEBIAN-CVE-2026-53613 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-53615 | util-linux | no fix listed |
| Low | DEBIAN-CVE-2026-77117 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-80489 | glibc | no fix listed |
| Low | DLA-3972-1 | tzdata | 2024b-0+deb11u1 |
| Low | DLA-4085-1 | tzdata | 2025a-0+deb11u1 |
| Low | DLA-4105-1 | tzdata | 2025b-0+deb11u1 |
| Low | DLA-4213-1 | curl | 7.74.0-1.3+deb11u15 |
| Low | DLA-4403-1 | tzdata | 2025b-0+deb11u2 |
| Low | DLA-4485-1 | ca-certificates | 20230311+deb12u1~deb11u1 |
| Low | GO-2026-5841 | github.com/ | 1.18.7 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6061 | google.golang.org/ | 1.82.1 |
| Low | GO-2026-6278 | github.com/ | 1.5.3 |
| Low | ALPINE-CVE-2025-46394 | busybox | 1.37.0-r20 |
| Low | DEBIAN-CVE-2026-40228 | systemd | no fix listed |
| Low | BIT-keycloak-2025-12150 | keycloak | 26.4.4 |
| Low | GHSA-7g5x-9c4v-4w5r | keycloak-services | 26.4.4 |
| Low | GHSA-fghv-69vj-qj49 | netty-codec-http | 4.1.125.Final |
| Low | GHSA-8hc5-rmgf-qx6p | keycloak-services | 23.0.1 |
| Low | GHSA-8hc5-rmgf-qx6p | keycloak-ldap-federation | 23.0.1 |
| Low | GHSA-m8cg-xc2p-r3fc | github.com/ | 1.1.5 |
| Low | DEBIAN-CVE-2026-57062 | gnupg2 | no fix listed |
| Low | GHSA-6vgw-5pg2-w6jp | pip | 26.0 |
| Low | DEBIAN-CVE-2026-53910 | diffutils | no fix listed |
| Low | BIT-java-2026-22007 | Java | 1.8.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.9.7latest | 9 months ago | 2.0.0-beta.4 | 14334772,768 | 37,441 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.