opentelemetry-demo 0.42.2 Helm chart
opentelemetry-helmOfficialVerified publisherScored 3 Oct 2026
opentelemetry demo helm chart
Version 0.42.2 todayapp version 3.1.0 1Artifact Hub
opentelemetry-demo 0.42.2 deploys 34 container images: otel/opentelemetry-collector-contrib, quay.io/kiwigrid/k8s-sidecar, grafana/grafana, jaegertracing/jaeger and 7 more. Across the 33 measured, 2,335 findings — 3 critical, 2 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-wjgm-6hv5-3cvf | jackson-databind | 2.21.6 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | GHSA-9m57-25v3-79x9 | golang.org/ | 0.52.0 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | ALPINE-CVE-2026-6429 | curl | 8.20.0-r0 |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-5025 | golang.org/ | 0.55.0 |
| Low | DEBIAN-CVE-2026-86143 | libxml2 | no fix listed |
| Low | GHSA-r6x4-923q-g947 | pyjwt | 2.14.0 |
| Low | DEBIAN-CVE-2026-86140 | libxml2 | no fix listed |
| Low | DEBIAN-CVE-2026-86142 | libxml2 | no fix listed |
| Low | ALPINE-CVE-2026-78410 | util-linux | 2.41.6-r0 |
| Low | DEBIAN-CVE-2026-78410 | util-linux | no fix listed |
| Low | ALPINE-CVE-2026-34181 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-4873 | curl | 8.20.0-r0 |
| Low | ALPINE-CVE-2026-89160 | pcre2 | 10.48-r0 |
| Low | DEBIAN-CVE-2026-89160 | pcre2 | 10.46-1~deb13u2 |
| Low | GHSA-w6j9-cwv2-h6wq | pyjwt | 2.14.0 |
| Low | UBUNTU-CVE-2025-68973 | gnupg2 | 2.4.4-2ubuntu17.4 |
| Low | UBUNTU-CVE-2026-102633 | expat | no fix listed |
| Low | DEBIAN-CVE-2026-15588 | glib2.0 | no fix listed |
| Low | GHSA-vffh-x6r8-xx99 | github.com/ | 0.311.2-0.20260410083055-07c6232d159b |
| Low | DEBIAN-CVE-2022-0563 | util-linux | no fix listed |
| Low | GHSA-9j54-fg26-wv3r | pyjwt | 2.14.0 |
| Low | GHSA-p4g4-x82p-q773 | pyjwt | 2.14.0 |
| Low | GHSA-w2cx-738m-mc7w | pyjwt | 2.14.0 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | DEBIAN-CVE-2026-11979 | libxml2 | no fix listed |
| Low | GO-2025-4008 | stdlib | 1.24.8 |
| Low | GO-2025-4010 | stdlib | 1.24.8 |
| Low | GHSA-ffqx-q65f-36jf | github.com/ | 2.10.3 |
| Low | DEBIAN-CVE-2026-3441 | binutils | no fix listed |
| Low | DEBIAN-CVE-2026-3442 | binutils | no fix listed |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | DEBIAN-CVE-2026-89158 | pcre2 | 10.46-1~deb13u2 |
| Low | DEBIAN-CVE-2026-93542 | libxi | no fix listed |
| Low | GHSA-8c42-7qj2-3j46 | netty-codec-http | 4.2.17.Final |
| Low | DSA-6189-1 | libpng1.6 | 1.6.39-2+deb12u4 |
| Low | DEBIAN-CVE-2026-93541 | libxi | no fix listed |
| Low | DEBIAN-CVE-2026-93544 | libxi | no fix listed |
| Low | GHSA-9fxm-vc8v-hj55 | jackson-databind | 2.21.4 |
| Low | DEBIAN-CVE-2026-5704 | tar | no fix listed |
| Low | DEBIAN-CVE-2023-45913 | mesa | no fix listed |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.21.5 |
| Low | DEBIAN-CVE-2026-22693 | harfbuzz | no fix listed |
| Low | DEBIAN-CVE-2026-27447 | cups | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.42.2latest | today | 3.1.0 | 323461,981 | 24,359 |
| 0.42.1 | 7 days ago | 3.1.0 | 323461,981 | 24,359 |
| 0.42.0 | 14 days ago | 3.1.0 | 323461,981 | 24,359 |
| 0.41.2 | 17 days ago | 3.0.0 | 053821,922 | 24,544 |
| 0.41.1 | 21 days ago | 3.0.0 | 053821,922 | 24,544 |
| 0.41.0 | 2 months ago | 3.0.0 | 053821,922 | 24,544 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.