StackRadar

flagsmith Helm chart

one-acre-fundVerified publisher

Scored 14 Sept 2026

Flagsmith - a Feature flag and remote configuration solution

Latest 0.1.5 4 years agoApp version not verified against the render 2Artifact Hub

flagsmith 0.1.5 deploys 6 container images: jwilder/dockerize, flagsmith/flagsmith-api, flagsmith/flagsmith-frontend, bitnami/postgresql and 1 more. Across the 5 measured, 449 findings0 critical, 14 high. The highest contribution is GHSA-phwq-j96m-2c2q in ejs 2.7.1, fixed in 3.1.7.

Radar Score

6,868014164271

449 findings over 5 of 6 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
jwilder/dockerize0.6.100000
flagsmith/flagsmith-api×2v2.6.00352922,216
jwilder/dockerizelatest00554502
flagsmith/flagsmith-frontendv2.6.00874982,984
bitnami/postgresql14.4.0-debian-11-r23unmeasured
blacktop/httpielatest0333271,166

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

417 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-v3c5-jqr6-7qm8future@0.18.20.18.3
MediumGHSA-f8q6-p94x-37v3minimatch@3.0.43.0.5
MediumGHSA-95rw-fx8r-36v6django@2.2.172.2.27
MediumGHSA-qm57-vhq3-3fwfdjango@2.2.172.2.22
MediumGHSA-72xf-g2v4-qvf3tough-cookie@2.4.34.1.3
MediumGHSA-5955-9wpr-37jhtar@4.4.134.4.18
MediumGHSA-rc47-6667-2j5jhttp-cache-semantics@3.8.14.1.1
MediumGHSA-j8r2-6x86-q33qrequests@2.19.12.31.0
MediumGHSA-p28h-cc7q-c4fgcss-what@2.1.02.1.3
MediumPYSEC-2023-192urllib3@1.222.0.6
MediumGHSA-wqvq-5m8c-6g24urllib3@1.221.25.9
MediumGHSA-grv7-fg5c-xmjgbraces@3.0.23.0.3
MediumGHSA-pp7h-53gx-mx7rbl@1.2.21.2.3
MediumPYSEC-2024-60idna@2.73.7
MediumGHSA-xgxc-v2qg-chmhdjango@2.2.172.2.20
MediumGHSA-3h5v-q93c-6h6qws@6.2.16.2.3
MediumGHSA-g6ww-v8xp-vmwgpathval@1.1.01.1.1
MediumGHSA-8x94-hmjh-97hqdjango@2.2.173.2.15
MediumDLA-2715-1systemd@232-25+deb9u12232-25+deb9u13
MediumGHSA-ffqj-6fqr-9h24pyjwt@1.7.12.4.0
MediumGHSA-43f8-2h32-f4cjhosted-git-info@2.6.02.8.9
MediumGHSA-g3rq-g295-4j3mjinja2@2.11.22.11.3
MediumGHSA-hwj9-h5mp-3pm3postcss@7.0.147.0.36
MediumALPINE-CVE-2019-19242sqlite@3.28.0-r03.28.0-r2
MediumGHSA-8gq9-2x98-w8hfprotobuf@3.14.03.18.3
MediumGHSA-95m3-7q98-8xr5sha.js@2.4.112.4.12
MediumGHSA-x527-x647-q7gggolang.org/x/crypto@v0.45.00.52.0
MediumGHSA-wr3j-pwj9-hqq6webpack-dev-middleware@3.4.05.3.4
MediumGHSA-pfq8-rq6v-vf5mhtml-minifier@3.5.21no fix listed
MediumGHSA-2xpw-w6gg-jr37urllib3@1.222.6.0
MediumGHSA-gm62-xv2j-4w53urllib3@1.25.112.6.0
MediumGHSA-r64q-w8jr-g9qpurllib3@1.221.24.3
MediumGHSA-4q6p-r6v2-jvc5get-func-name@2.0.02.0.1
MediumGHSA-vgwf-h737-ff37golang.org/x/crypto@v0.45.00.52.0
MediumGHSA-257v-vj4p-3w2hcolor-string@1.5.31.5.5
MediumGHSA-9w4w-cpc8-h2fqhttpie@1.0.23.1.0
MediumGHSA-f5wc-c3c7-36mcgolang.org/x/crypto@v0.45.00.52.0
MediumGHSA-f23m-r3pf-42rhlodash@4.17.154.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.154.17.23
MediumGHSA-c7qv-q95q-8v27http-proxy-middleware@1.0.62.0.7
MediumGHSA-6fc8-4gx4-v693ws@6.2.16.2.2
MediumGHSA-67hx-6x53-jw92@babel/traverse@7.4.37.23.2
MediumDLA-3530-1openssl@1.1.1d-0+deb10u61.1.1n-0+deb10u6
MediumPYSEC-2026-3717django@2.2.175.2.17
MediumGHSA-v88g-cgmw-v5xwajv@6.4.06.12.3
MediumGHSA-rm3j-f69w-wqmqgolang.org/x/crypto@v0.45.00.52.0
MediumGHSA-37ch-88jc-xwx2path-to-regexp@0.1.70.1.13
MediumGHSA-9wv6-86v2-598jpath-to-regexp@0.1.70.1.10
MediumGHSA-r9p9-mrjm-926welliptic@6.4.16.5.4
MediumGHSA-qjx8-664m-686jjs-cookie@2.2.13.0.7

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.1.5latest4 years ago0141642716,868

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/one-acre-fund/flagsmith.svg)](https://charts.stackradar.io/charts/one-acre-fund/flagsmith)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 5 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.