flomesh-console Helm chart
openshiftScored 14 Sept 2026
A Helm chart to install flomesh-console on Kubernetes
Latest 0.70.0-30-ubi8deploys tag 0.70.0-30 0Artifact Hub
flomesh-console 0.70.0-30-ubi8 deploys 2 container images: quay.io/flomesh/flomesh-console-ubi8 and quay.io/flomesh/pipy-repo-ubi8. Across them, 604 findings — 8 critical, 27 high — 6 on CISA KEV. The highest contribution is RHSA-2024:2722 in glibc 2.28-211.el8, fixed in 0:2.28-236.el8_9.13. Chart.yaml declares kubeVersion >= 1.19; rendered for Kubernetes 1.19.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| quay.io/ | 0.70.0-30 | 418146278 | 7,099 |
| quay.io/ | 0.70.0-46 | 495491 | 2,869 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | RHSA-2026:4772 | glibc | 0:2.28-251.el8_10.31 |
| Low | GHSA-3p68-rc4w-qgx5 | axios | 0.31.0 |
| Low | RHSA-2026:16799 | krb5 | 0:1.18.2-34.el8_10 |
| Low | GHSA-7fh5-64p2-3v2j | postcss | 8.4.31 |
| Low | GHSA-64mm-vxmg-q3vj | http-proxy-middleware | 2.0.10 |
| Low | GHSA-xwg4-73v4-xw9w | nanoid | 3.3.12 |
| Low | RHSA-2025:11042 | socat | 0:1.7.4.1-2.el8_10 |
| Low | GHSA-f886-m6hf-6m8v | brace-expansion | 1.1.13 |
| Low | GHSA-v923-w3x8-wh69 | passport | 0.6.0 |
| Low | GHSA-wpg9-53fq-2r8h | mongoose | 6.13.9 |
| Low | GHSA-fxqj-rqcc-2cmp | postcss | 8.5.23 |
| Low | RHSA-2026:6473 | python3 | 0:3.6.8-75.el8_10 |
| Low | RHSA-2024:1784 | gnutls | 0:3.6.16-8.el8_9.3 |
| Low | RHSA-2026:36730 | libsolv | 0:0.7.20-7.el8_10 |
| Low | GHSA-83g3-92jg-28cx | tar | 7.5.8 |
| Low | GHSA-gp95-ppv5-3jc5 | sharp | 0.30.5 |
| Low | GHSA-664h-wqgq-64gw | mongoose | 6.13.10 |
| Low | RHSA-2026:42733 | glibc | 0:2.28-251.el8_10.40 |
| Low | RHSA-2026:5585 | gnutls | 0:3.6.16-8.el8_10.5 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | GHSA-w8wr-v893-vjvp | tar | 7.5.18 |
| Low | GHSA-m7pr-hjqh-92cm | axios | 0.31.1 |
| Low | GHSA-hjrf-2m68-5959 | jsonwebtoken | 9.0.0 |
| Low | GHSA-h8hf-x3f4-xwgp | mongoose | 5.13.15 |
| Low | GHSA-9jgg-88mc-972h | webpack-dev-server | 5.2.1 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GHSA-49q7-c7j4-3p7m | elliptic | 6.5.7 |
| Low | GHSA-p6gq-j5cr-w38f | nodemailer | 9.0.1 |
| Low | GHSA-869p-cjfg-cm3x | jws | 3.2.3 |
| Low | RHSA-2026:65998 | gzip | 0:1.9-15.el8_10 |
| Low | GHSA-mmx7-hfxf-jppx | axios | 0.33.0 |
| Low | RHSA-2026:66451 | glib2 | 0:2.56.4-178.el8_10 |
| Low | GHSA-8c25-f3mj-v6h8 | sequelize | 6.28.1 |
| Low | GHSA-vvjj-xcjg-gr5g | nodemailer | 8.0.5 |
| Low | MAL-2022-4691 | monorepo-symlink-test | no fix listed |
| Low | MAL-2022-4933 | npm-cli-docs | no fix listed |
| Low | GHSA-4v9v-hfq4-rm2v | webpack-dev-server | 5.2.1 |
| Low | RHSA-2026:58938 | sqlite | 0:3.26.0-21.el8_10 |
| Low | GHSA-mcqm-6ff4-53qx | strapi | no fix listed |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-65ch-62r8-g69g | node-forge | 1.3.2 |
| Low | GHSA-mq26-g339-26xf | pip | 23.3 |
| Low | GHSA-cm22-4g7w-348p | serve-static | 1.16.0 |
| Low | RHSA-2023:3840 | sqlite | 0:3.26.0-18.el8_8 |
| Low | GHSA-m28w-2pqf-7qgj | webpack-dev-server | 5.2.6 |
| Low | RHSA-2026:47117 | libgcrypt | 0:1.8.5-8.el8_10 |
| Low | RHSA-2024:3163 | pam | 0:1.3.1-33.el8 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GHSA-434g-2637-qmqr | elliptic | 6.5.6 |
| Low | GHSA-9965-vmph-33xx | validator | 13.15.20 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.70.0-30-ubi8latest | — | 0.70.0-30 | 827200369 | 9,968 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.