StackRadar

bpjstk-service Helm chart

openshift

Scored 14 Sept 2026

BPJSTK Multichannel Payment Gateway

Latest 1.0.0deploys tag latest 0Artifact Hub

bpjstk-service 1.0.0 deploys 6 container images: andrianrf/bpjstk-simulator, andrianrf/iso-server, andrianrf/iso-client, andrianrf/bpjstk-service and 2 more. Across them, 1,730 findings55 critical, 130 high 38 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-boot-starter-web 2.3.4.RELEASE, fixed in 2.5.12. Chart.yaml declares kubeVersion >=1.20.0; rendered for Kubernetes 1.20.0.

Radar Score

34,67155130646899

1,730 findings over 6 of 6 images measured

KEV ×38 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
andrianrf/bpjstk-simulatorlatest61254933,239
andrianrf/iso-serverlatest17201481857,310
andrianrf/iso-clientlatest815731054,066
andrianrf/bpjstk-servicelatest81463983,767
andrianrf/backoffice-belatest13181361946,645
andrianrf/backofficelatest3511722249,644

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

436 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-34jh-p97f-mpxfurllib3@1.24.21.26.19
LowRHSA-2023:4838cups@1:2.3.3op2-16.el91:2.3.3op2-16.el9_2.1
LowGHSA-pr98-23f8-jwxvlogback-core@1.2.31.3.15
LowGHSA-wf66-mphr-4c4rkafka-clients@3.1.23.9.2
LowGHSA-jhq6-gfmj-v8fxlogback-core@1.2.31.5.34
LowGHSA-h35f-9h28-mq5csetuptools@39.2.083.0.0
LowGHSA-4gc7-5j7h-4qphspring-web@5.2.9.RELEASEno fix listed
LowGHSA-4gc7-5j7h-4qphspring-context@5.2.9.RELEASEno fix listed
LowDSA-5349-1gnutls28@3.7.1-5+deb11u13.7.1-5+deb11u3
LowRHSA-2026:65998gzip@1.9-13.el8_50:1.9-15.el8_10
LowDLA-3910-1e2fsprogs@1.46.2-21.46.2-2+deb11u1
LowRHSA-2026:64800glib2@2.68.4-6.el90:2.68.4-19.el9_8.10
LowRHSA-2026:4442vim@2:8.0.1763-19.el8_6.42:8.0.1763-22.el8_10
LowDSA-5678-1glibc@2.31-13+deb11u32.31-13+deb11u10
LowRHSA-2025:11402avahi@0.8-12.el90:0.8-22.el9_6.1
LowRHSA-2026:58936sqlite@3.34.1-6.el9_10:3.34.1-11.el9_8
LowRHSA-2026:58938sqlite@3.26.0-19.el8_90:3.26.0-21.el8_10
LowRHSA-2026:62232sqlite@3.34.1-6.el9_10:3.34.1-6.el9_2.3
LowDLA-4267-1gnutls28@3.7.1-5+deb11u13.7.1-5+deb11u8
LowDLA-4063-1gnutls28@3.7.1-5+deb11u13.7.1-5+deb11u7
LowRHSA-2025:22660systemd@252-13.el9_20:252-55.el9_7.7
LowGHSA-xvfq-4q6q-gxx7spring-kafka@2.8.11no fix listed
LowGHSA-4773-3jfm-qmx3spring-webmvc@5.3.27no fix listed
LowRHSA-2026:0067tar@2:1.34-6.el9_12:1.34-9.el9_7
LowRHSA-2024:2433avahi@0.8-12.el90:0.8-20.el9
LowRHSA-2026:50147libgcrypt@1.10.0-10.el9_20:1.10.0-13.el9_8
LowGHSA-72pg-x5f8-j25jspring-webmvc@5.2.9.RELEASEno fix listed
LowRHSA-2026:61247libxml2@2.9.13-3.el9_10:2.9.13-14.el9_8.4
LowRHSA-2026:5581nginx@1:1.20.1-1.module+el8.8.0+20359+9bd89172.11:1.24.0-2.module+el8.10.0+24013+f603d2af
LowDLA-4061-1libtasn1-6@4.16.0-24.16.0-2+deb11u2
LowRHSA-2025:13777krb5@1.20.1-8.el90:1.20.1-9.el9_2.3
LowRHSA-2026:0719gnupg2@2.3.3-2.el9_00:2.3.3-5.el9_7
LowGHSA-mq64-j8f9-9gcjspring-webmvc@5.2.9.RELEASEno fix listed
LowRHSA-2024:1822java-11-openjdk@1:11.0.19.0.7-4.el91:11.0.23.0.9-3.el9
LowRHSA-2026:48703vim@2:8.0.1763-19.el8_6.42:8.0.1763-31.el8_10
LowGHSA-5m4m-73w9-8433spring-data-commons@2.3.4.RELEASEno fix listed
LowRHSA-2026:36732python-urllib3@1.24.2-8.el8_100:1.24.2-10.el8_10
LowGHSA-6gf2-pvqw-37phspring-core@5.2.9.RELEASE5.2.19
LowDLA-4145-1expat@2.2.10-2+deb11u52.2.10-2+deb11u7
LowGHSA-53w6-v7cv-fc9hspring-kafka@2.8.11no fix listed
LowGHSA-r7wm-3cxj-wff9jackson-core@2.11.22.18.8
LowGHSA-pq67-6m6q-mj2vurllib3@1.24.22.5.0
LowRHSA-2025:8958libxml2@2.9.7-18.el8_10.10:2.9.7-20.el8_10
LowRHSA-2026:33226glibc@2.34-60.el90:2.34-272.el9_8
LowGHSA-5vpf-xvv7-c8vhspring-data-commons@2.3.4.RELEASEno fix listed
LowDLA-4481-1libpng1.6@1.6.37-31.6.37-3+deb11u2
LowRHSA-2026:12441libcap@2.48-8.el90:2.48-10.el9_7.1
LowGHSA-65pc-fj4g-8rjxidna@2.53.15
LowRHSA-2026:54290python-idna@2.5-7.el8_100:2.5-8.el8_10
LowGHSA-9wx4-h78v-vm56requests@2.20.02.32.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latestlatest5513064689934,671

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/openshift/bpjstk-service.svg)](https://charts.stackradar.io/charts/openshift/bpjstk-service)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.