StackRadar

marge-bot Helm chart

netpositiveVerified publisher

Scored 14 Sept 2026

Marge-bot is a merge-bot for GitLab

Latest 1.1.0 2 years agoapp version 0.12.1 1Artifact Hub

marge-bot 1.1.0 deploys 1 container image: hiboxsystems/marge-bot. Across them, 88 findings0 critical, 4 high 4 on CISA KEV. The highest contribution is DLA-4104-1 in freetype 2.10.4+dfsg-1+deb11u1, fixed in 2.10.4+dfsg-1+deb11u2.

Radar Score

1,253042163

88 findings over 1 of 1 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
hiboxsystems/marge-bot0.12.10421631,253

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

88 distinct across the version’s images
SeverityAdvisoryPackageFixed in
HighDLA-4104-1KEVfreetype@2.10.4+dfsg-1+deb11u12.10.4+dfsg-1+deb11u2
HighDLA-4323-1KEVgit@1:2.30.2-1+deb11u21:2.30.2-1+deb11u5
HighDSA-5514-1KEVglibc@2.31-13+deb11u52.31-13+deb11u7
HighDSA-5570-1KEVnghttp2@1.43.0-11.43.0-1+deb11u1
MediumDLA-3859-1systemd@247.3-7+deb11u1247.3-7+deb11u6
MediumDSA-5586-1openssh@1:8.4p1-5+deb11u11:8.4p1-5+deb11u3
MediumDSA-5673-1glibc@2.31-13+deb11u52.31-13+deb11u9
MediumGHSA-8q59-q68h-6hv4pyyaml@5.3.15.4
MediumDLA-3898-1nghttp2@1.43.0-11.43.0-1+deb11u2
MediumDSA-5523-1curl@7.74.0-1.3+deb11u77.74.0-1.3+deb11u10
MediumDSA-5417-1openssl@1.1.1n-0+deb11u31.1.1n-0+deb11u5
MediumDSA-5343-1openssl@1.1.1n-0+deb11u31.1.1n-0+deb11u4
MediumDLA-3942-1openssl@1.1.1n-0+deb11u31.1.1n-0+deb11u6
MediumDLA-3942-2openssl@1.1.1n-0+deb11u31.1.1w-0+deb11u2
MediumDLA-3867-1git@1:2.30.2-1+deb11u21:2.30.2-1+deb11u3
MediumGHSA-cx63-2mw6-8hw5setuptools@65.5.070.0.0
MediumGHSA-38jv-5279-wg99urllib3@2.0.42.6.3
MediumGHSA-r9hx-vwmv-q579setuptools@65.5.065.5.1
MediumPYSEC-2025-49setuptools@65.5.078.1.1
MediumPYSEC-2023-192urllib3@2.0.42.0.6
MediumPYSEC-2024-60idna@3.43.7
MediumDLA-4057-1openssh@1:8.4p1-5+deb11u11:8.4p1-5+deb11u4
MediumGHSA-2xpw-w6gg-jr37urllib3@2.0.42.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@2.0.42.6.0
MediumPYSEC-2024-230certifi@2023.7.222024.7.4
LowDLA-3907-1sqlite3@3.34.1-33.34.1-3+deb11u1
LowGHSA-wf93-45jw-7689pip@22.3.126.1.2
LowGHSA-9hjg-9r4m-mvj7requests@2.31.02.32.4
LowDSA-5650-1util-linux@2.36.1-8+deb11u12.36.1-8+deb11u2
LowDLA-4026-1tiff@4.2.0-1+deb11u44.2.0-1+deb11u6
LowDLA-4411-1libgd2@2.3.0-22.3.0-2+deb11u1
LowDSA-5726-1krb5@1.18.3-6+deb11u31.18.3-6+deb11u5
LowDLA-3893-1expat@2.2.10-2+deb11u52.2.10-2+deb11u6
LowDSA-5587-1curl@7.74.0-1.3+deb11u77.74.0-1.3+deb11u11
LowDLA-4321-1openssl@1.1.1n-0+deb11u31.1.1w-0+deb11u4
LowDLA-3926-1perl@5.32.1-4+deb11u25.32.1-4+deb11u4
LowGHSA-34jh-p97f-mpxfurllib3@2.0.42.2.2
LowGHSA-4xh5-x5gv-qwphpip@22.3.125.3
LowGHSA-h35f-9h28-mq5csetuptools@65.5.083.0.0
LowDSA-5349-1gnutls28@3.7.1-5+deb11u23.7.1-5+deb11u3
LowDSA-5567-1tiff@4.2.0-1+deb11u44.2.0-1+deb11u5
LowDLA-4432-1curl@7.74.0-1.3+deb11u77.74.0-1.3+deb11u16
LowDLA-3910-1e2fsprogs@1.46.2-21.46.2-2+deb11u1
LowDSA-5678-1glibc@2.31-13+deb11u52.31-13+deb11u10
LowDLA-4267-1gnutls28@3.7.1-5+deb11u23.7.1-5+deb11u8
LowDLA-4063-1gnutls28@3.7.1-5+deb11u23.7.1-5+deb11u7
LowPYSEC-2026-3721pip@22.3.126.2
LowGHSA-mq26-g339-26xfpip@22.3.123.3
LowDLA-4061-1libtasn1-6@4.16.0-2+deb11u14.16.0-2+deb11u2
LowDSA-5679-1less@551-2551-2+deb11u2

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.1.0latest2 years ago0.12.10421631,253

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/netpositive/marge-bot.svg)](https://charts.stackradar.io/charts/netpositive/marge-bot)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.