StackRadar

bpjstk-service Helm chart

openshift

Scored 14 Sept 2026

BPJSTK Multichannel Payment Gateway

Latest 1.0.0deploys tag latest 0Artifact Hub

bpjstk-service 1.0.0 deploys 6 container images: andrianrf/bpjstk-simulator, andrianrf/iso-server, andrianrf/iso-client, andrianrf/bpjstk-service and 2 more. Across them, 1,730 findings55 critical, 130 high 38 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-boot-starter-web 2.3.4.RELEASE, fixed in 2.5.12. Chart.yaml declares kubeVersion >=1.20.0; rendered for Kubernetes 1.20.0.

Radar Score

34,67155130646899

1,730 findings over 6 of 6 images measured

KEV ×38 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
andrianrf/bpjstk-simulatorlatest61254933,239
andrianrf/iso-serverlatest17201481857,310
andrianrf/iso-clientlatest815731054,066
andrianrf/bpjstk-servicelatest81463983,767
andrianrf/backoffice-belatest13181361946,645
andrianrf/backofficelatest3511722249,644

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

436 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowRHSA-2026:30851perl-Unicode-Normalize@1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Time-Local@1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-File-Temp@0.230.600-1.el81:0.231.100-1.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Data-Dumper@2.167-399.el80:2.174-440.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-threads-shared@1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-podlators@4.11-1.el81:4.14-457.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Socket@4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Text-ParseWords@3.30-395.el80:3.30-396.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-IO-Socket-IP@0.39-5.el80:0.41-2.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Text-Tabs+Wrap@2013.0523-395.el80:2013.0523-396.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-HTTP-Tiny@0.074-3.el80:0.078-1.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-libnet@3.11-3.el80:3.13-1.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Term-Cap@1.17-395.el80:1.17-396.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Term-ANSIColor@4.06-396.el80:5.01-458.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-File-Path@2.15-2.el80:2.16-439.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-threads@1:2.21-2.el81:2.25-457.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Pod-Simple@1:3.35-395.el81:3.42-1.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-parent@1:0.237-1.el81:0.238-457.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:28253libtasn1@4.16.0-8.el9_10:4.16.0-10.el9_8
LowGHSA-fv25-8xcx-gqjctomcat-embed-core@9.0.389.0.118
LowRHSA-2026:42089glib2@2.68.4-6.el90:2.68.4-19.el9_8.2
LowRHSA-2026:66348vim@2:8.0.1763-19.el8_6.42:8.0.1763-31.el8_10.7
LowRHSA-2024:9404libgcrypt@1.10.0-10.el9_20:1.10.0-11.el9
LowRHSA-2026:3042openssl@1:1.1.1k-12.el8_91:1.1.1k-15.el8_6
LowGHSA-23hv-mwm6-g8jftomcat-embed-core@9.0.389.0.106
LowRHSA-2026:15953glib2@2.56.4-162.el80:2.56.4-169.el8_10
LowRHSA-2026:15971glib2@2.68.4-6.el90:2.68.4-18.el9_7.2
LowRHSA-2026:19361glib2@2.68.4-6.el90:2.68.4-19.el9_8.1
LowRHSA-2026:19460glib2@2.68.4-6.el90:2.68.4-7.el9_2.5
LowRHSA-2024:0107nss@4.34.0-18.el9_10:4.35.0-4.el9_2
LowRHSA-2023:4349libxml2@2.9.13-3.el9_10:2.9.13-3.el9_2.1
LowRHBA-2024:6679nss@4.34.0-18.el9_10:4.35.0-14.el9_2
LowGHSA-563x-q5rq-57qptomcat-embed-core@9.0.389.0.116
LowRHSA-2026:38510vim@2:8.0.1763-19.el8_6.42:8.0.1763-27.el8_10
LowRHSA-2024:9541expat@2.5.0-1.el90:2.5.0-3.el9_5.1
LowRHSA-2026:2042brotli@1.0.9-6.el90:1.0.9-9.el9_7
LowRHSA-2026:19218openssl@1:3.0.7-6.el9_21:3.5.5-2.el9_8
LowRHSA-2023:6631glib2@2.68.4-6.el90:2.68.4-11.el9
LowRHSA-2023:5744java-11-openjdk@1:11.0.19.0.7-4.el91:11.0.21.0.9-2.el9
LowRHSA-2025:10027pam@1.3.1-34.el8_100:1.3.1-37.el8_10
LowRHSA-2025:14557pam@1.3.1-34.el8_100:1.3.1-38.el8_10
LowGHSA-hhhw-99gj-p3c3snakeyaml@1.261.31
LowRHSA-2025:23127curl@7.76.1-23.el9_2.10:7.76.1-23.el9_2.8
LowRHSA-2023:7747libxml2@2.9.13-3.el9_10:2.9.13-5.el9_3
LowRHSA-2024:4776cups@1:2.3.3op2-16.el91:2.3.3op2-27.el9_4
LowRHSA-2026:52674libarchive@3.5.3-4.el90:3.5.3-11.el9_8
LowGHSA-qv9r-c865-cp47log4j-api@2.13.32.25.5
LowRHSA-2025:14130libarchive@3.5.3-4.el90:3.5.3-6.el9_6
LowGHSA-6xx3-rg99-gc3pbcprov-jdk15on@1.511.66
LowGHSA-mgvc-8q2h-5pgcspring-boot-starter-actuator@2.2.5.RELEASEno fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latestlatest5513064689934,671

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/openshift/bpjstk-service.svg)](https://charts.stackradar.io/charts/openshift/bpjstk-service)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.