StackRadar

bpjstk-service Helm chart

openshift

Scored 14 Sept 2026

BPJSTK Multichannel Payment Gateway

Latest 1.0.0deploys tag latest 0Artifact Hub

bpjstk-service 1.0.0 deploys 6 container images: andrianrf/bpjstk-simulator, andrianrf/iso-server, andrianrf/iso-client, andrianrf/bpjstk-service and 2 more. Across them, 1,730 findings55 critical, 130 high 38 on CISA KEV. The highest contribution is GHSA-36p3-wjmg-h94x in spring-boot-starter-web 2.3.4.RELEASE, fixed in 2.5.12. Chart.yaml declares kubeVersion >=1.20.0; rendered for Kubernetes 1.20.0.

Radar Score

34,67155130646899

1,730 findings over 6 of 6 images measured

KEV ×38 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
andrianrf/bpjstk-simulatorlatest61254933,239
andrianrf/iso-serverlatest17201481857,310
andrianrf/iso-clientlatest815731054,066
andrianrf/bpjstk-servicelatest81463983,767
andrianrf/backoffice-belatest13181361946,645
andrianrf/backofficelatest3511722249,644

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

871 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowRHSA-2026:30851perl-threads-shared@1.58-2.el80:1.61-457.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-Unicode-Normalize@1.25-396.el80:1.27-458.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:30851perl-URI@1.73-3.el80:1.76-5.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:28253libtasn1@4.16.0-8.el9_10:4.16.0-10.el9_8
LowGHSA-fv25-8xcx-gqjctomcat-embed-core@9.0.389.0.118
LowRHSA-2026:42089glib2@2.68.4-6.el90:2.68.4-19.el9_8.2
LowRHSA-2026:66348vim@2:8.0.1763-19.el8_6.42:8.0.1763-31.el8_10.7
LowRHSA-2024:9404libgcrypt@1.10.0-10.el9_20:1.10.0-11.el9
LowRHSA-2026:3042openssl@1:1.1.1k-12.el8_91:1.1.1k-15.el8_6
LowGHSA-23hv-mwm6-g8jftomcat-embed-core@9.0.389.0.106
LowRHSA-2026:15953glib2@2.56.4-162.el80:2.56.4-169.el8_10
LowRHSA-2026:15971glib2@2.68.4-6.el90:2.68.4-18.el9_7.2
LowRHSA-2026:19361glib2@2.68.4-6.el90:2.68.4-19.el9_8.1
LowRHSA-2026:19460glib2@2.68.4-6.el90:2.68.4-7.el9_2.5
LowRHSA-2024:0107nss@4.34.0-18.el9_10:4.35.0-4.el9_2
LowRHSA-2023:4349libxml2@2.9.13-3.el9_10:2.9.13-3.el9_2.1
LowRHBA-2024:6679nss@4.34.0-18.el9_10:4.35.0-14.el9_2
LowGHSA-563x-q5rq-57qptomcat-embed-core@9.0.389.0.116
LowRHSA-2026:38510vim@2:8.0.1763-19.el8_6.42:8.0.1763-27.el8_10
LowRHSA-2024:9541expat@2.5.0-1.el90:2.5.0-3.el9_5.1
LowRHSA-2026:2042brotli@1.0.9-6.el90:1.0.9-9.el9_7
LowRHSA-2026:19218openssl@1:3.0.7-6.el9_21:3.5.5-2.el9_8
LowRHSA-2023:6631glib2@2.68.4-6.el90:2.68.4-11.el9
LowRHSA-2023:5744java-11-openjdk@1:11.0.19.0.7-4.el91:11.0.21.0.9-2.el9
LowRHSA-2025:10027pam@1.3.1-34.el8_100:1.3.1-37.el8_10
LowRHSA-2025:14557pam@1.3.1-34.el8_100:1.3.1-38.el8_10
LowGHSA-hhhw-99gj-p3c3snakeyaml@1.261.31
LowRHSA-2025:23127curl@7.76.1-23.el9_2.10:7.76.1-23.el9_2.8
LowRHSA-2023:7747libxml2@2.9.13-3.el9_10:2.9.13-5.el9_3
LowRHSA-2024:4776cups@1:2.3.3op2-16.el91:2.3.3op2-27.el9_4
LowRHSA-2026:52674libarchive@3.5.3-4.el90:3.5.3-11.el9_8
LowGHSA-qv9r-c865-cp47log4j-api@2.13.32.25.5
LowRHSA-2025:14130libarchive@3.5.3-4.el90:3.5.3-6.el9_6
LowGHSA-6xx3-rg99-gc3pbcprov-jdk15on@1.511.66
LowGHSA-mgvc-8q2h-5pgcspring-boot-starter-actuator@2.2.5.RELEASEno fix listed
LowGHSA-5mp6-jrq3-r938tomcat-embed-core@9.0.389.0.118
LowRHSA-2025:22175expat@2.5.0-1.el90:2.5.0-5.el9_7.1
LowRHSA-2026:28553vim@2:8.0.1763-19.el8_6.42:8.0.1763-24.el8_10
LowRHSA-2026:2128python3@3.6.8-62.el8_100:3.6.8-73.el8_10
LowRHSA-2026:4168python3.9@3.9.16-1.el90:3.9.25-3.el9_7.1
LowRHSA-2026:5225python3.9@3.9.16-1.el90:3.9.16-1.el9_2.12
LowGHSA-jmp9-x22r-554xspring-core@5.3.27no fix listed
LowGHSA-rv64-5gf8-9qq8tomcat-embed-core@9.0.759.0.116
LowRHSA-2026:23230expat@2.5.0-1.el90:2.5.0-6.el9_8.1
LowRHSA-2025:7076gnutls@3.7.6-20.el9_20:3.8.3-6.el9
LowRHSA-2025:8655glibc@2.34-60.el90:2.34-168.el9_6.19
LowRHSA-2024:9371python3.9@3.9.16-1.el90:3.9.19-8.el9
LowRHSA-2026:48225perl-Socket@4:2.027-3.el84:2.031-1.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:48225perl-Time-Local@1:1.280-1.el82:1.300-4.module+el8.10.0+21354+3ad137bb
LowRHSA-2026:48225perl-Digest-MD5@2.55-396.el80:2.58-1.module+el8.10.0+21354+3ad137bb

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.0.0latestlatest5513064689934,671

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/openshift/bpjstk-service.svg)](https://charts.stackradar.io/charts/openshift/bpjstk-service)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.