StackRadar

nocodb Helm chart

one-acre-fundVerified publisher

Scored 14 Sept 2026

A Helm chart for Kubernetes

Latest 0.4.6 6 months agoapp version 0.258.0 0Artifact Hub

nocodb 0.4.6 deploys 3 container images: library/postgres, library/busybox and nocodb/nocodb. Across them, 420 findings0 critical, 2 high. The highest contribution is GHSA-4v7x-pqxf-cx7m in golang.org/x/net v0.19.0, fixed in 0.23.0.

Radar Score

4,2190253365

420 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
library/postgresalpine00861634
library/busybox×2latest00000
nocodb/nocodb0.258.002453043,585

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

319 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-vcc3-ghjq-m6frdecode-uri-component@0.2.20.5.0
LowGHSA-rhx6-c78j-4q9wpath-to-regexp@0.1.100.1.12
LowGHSA-44fp-w29j-9vj5multer@1.4.4-lts.12.0.0
LowGHSA-q5c6-h22r-qpwrnocodb@0.258.00.301.0
LowGHSA-89gr-r52h-f8rxgolang.org/x/crypto@v0.17.00.52.0
LowGHSA-62hf-57xw-28j9axios@1.7.71.15.1
LowGHSA-jppx-rxg9-jmrxgolang.org/x/crypto@v0.17.00.52.0
LowGHSA-x6wf-f3px-wcqx@xmldom/xmldom@0.8.100.8.13
LowALPINE-CVE-2026-14456openssl@3.5.7-r03.5.8-r0
LowGHSA-34x7-hfp2-rc4vtar@6.2.17.5.7
LowALPINE-CVE-2026-82209curl@8.21.0-r08.22.0-r0
LowGHSA-q8qp-cvcw-x6jjaxios@1.7.71.15.2
LowALPINE-CVE-2026-80255curl@8.21.0-r08.22.0-r0
LowGHSA-fjgf-rc76-4x9pmulter@1.4.4-lts.12.0.2
LowGHSA-g5hg-p3ph-g8qgmulter@1.4.4-lts.12.0.1
LowGHSA-3g43-6gmg-66jwaxios@1.7.71.15.2
LowGHSA-ph9p-34f9-6g65tmp@0.0.330.2.6
LowGHSA-777c-7fjr-54vfaxios@1.7.71.16.0
LowGHSA-hfxv-24rg-xrqfaxios@1.7.71.16.0
LowGHSA-j5f8-grm9-p9fcaxios@1.7.71.16.0
LowGHSA-vp52-pcj8-j9qcgoogle.golang.org/grpc@v1.60.11.83.1
LowGHSA-r635-g3xr-vw7xengine.io@6.6.26.6.7
LowGHSA-q3j6-qgpj-74h6fast-uri@3.0.33.1.1
LowGHSA-rgw5-rvv9-x895brace-expansion@1.1.111.1.18
LowALPINE-CVE-2026-13608curl@8.21.0-r08.22.0-r0
LowGHSA-9cx6-37pm-9jffhandlebars@4.7.84.7.9
LowALPINE-CVE-2026-63072openssl@3.5.7-r03.5.8-r0
LowGHSA-gr94-w7qr-f4j3engine.io@6.6.26.6.7
LowGHSA-pmwg-cvhr-8vh7axios@1.7.71.15.1
LowGHSA-8gc5-j5rx-235rfast-xml-parser@4.5.04.5.5
LowGHSA-qffp-2rhf-9h96tar@6.2.17.5.10
LowGHSA-j759-j44w-7fr8@xmldom/xmldom@0.8.100.8.13
LowALPINE-CVE-2026-80230curl@8.21.0-r08.22.0-r0
LowGHSA-hj85-ph9q-78jgnocodb@0.258.02026.05.1
LowGHSA-23hp-3jrh-7fpwtar@6.2.17.5.19
LowGHSA-93r5-fhx6-vmg9@xmldom/xmldom@0.8.100.8.15
LowGHSA-965w-775f-mr7g@xmldom/xmldom@0.8.100.8.15
LowGHSA-27p8-2357-5qqv@xmldom/xmldom@0.8.100.8.15
LowGHSA-4w3w-2rp5-g8jm@xmldom/xmldom@0.8.100.8.14
LowGHSA-c7q8-3ch8-vqpv@xmldom/xmldom@0.8.100.8.15
LowGHSA-w2rr-34g9-rvrj@xmldom/xmldom@0.8.100.8.14
LowGHSA-8344-3jmq-59r6@xmldom/xmldom@0.8.100.8.15
LowGHSA-hmw2-7cc7-3qxxform-data@2.3.32.5.6
LowALPINE-CVE-2026-54874openssl@3.5.7-r03.5.8-r0
LowGHSA-7r86-cg39-jmmjminimatch@3.1.23.1.3
LowGHSA-vghf-hv5q-vc2gvalidator@13.12.013.15.22
LowGHSA-2m8v-j782-fhvrsocket.io-parser@4.2.44.2.7
LowGHSA-8qq5-rm4j-mr97tar@6.2.17.5.3
LowGHSA-776f-qx25-q3ccxml2js@0.1.140.5.0
LowGHSA-fvcv-3m26-pcqxaxios@1.7.71.15.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.6latest6 months ago0.258.002533654,219

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/one-acre-fund/nocodb.svg)](https://charts.stackradar.io/charts/one-acre-fund/nocodb)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.