StackRadar

osdfir-infrastructure Helm chart

osdfir-infrastructureVerified publisher

Scored 14 Sept 2026

A Helm chart for Open Source Digital Forensics Kubernetes deployments.

Latest 2.15.0 10 days agoApp version not verified against the render 0Artifact Hub

osdfir-infrastructure 2.15.0 deploys 40 container images: library/bash, library/busybox, bitnamilegacy/git, ghcr.io/google/grr and 35 more. Across the 38 measured, 7,089 findings5 critical, 48 high 19 on CISA KEV. The highest contribution is UBUNTU-CVE-2024-12084 in rsync 3.2.7-0ubuntu0.22.04.2, fixed in 3.2.7-0ubuntu0.22.04.3.

Radar Score

71,2085488996,129

7,089 findings over 38 of 40 images measured

KEV ×19 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

40 images
ImageTagVulnerabilitiesRadar Score
library/bash×25.2.2102811364
library/busybox1.37.000000
bitnamilegacy/git×9latest12602793,754
ghcr.io/google/grr×3v3.4.9.1-releasenot yet scanned
library/mariadb11.3.224593074,200
ghcr.io/google/fleetspeak×2v0.1.17271004816,696
ghcr.io/openrelik/openrelik-ui×2latest0230831,509
registry.k8s.io/e2e-test-images/agnhost×132.4004181441,781
ghcr.io/openrelik/openrelik-serverlatest01171171,381
ghcr.io/openrelik/openrelik-mediatorlatest01171171,381
ghcr.io/openrelik/openrelik-metricslatest01341742,234
library/nginx×21.25.5-alpine-slim01511263
prom/prometheusv3.0.100111081,008
ghcr.io/openrelik/openrelik-worker-analyzer-configlatest01332452,667
ghcr.io/openrelik/openrelik-worker-analyzer-logslatest01312012,306
ghcr.io/openrelik/openrelik-worker-bulkextractorlatest01182042,047
ghcr.io/openrelik/openrelik-worker-capalatest00131021,069
ghcr.io/openrelik/openrelik-worker-chromecredslatest01131091,204
ghcr.io/openrelik/openrelik-worker-cloud-logslatest00131021,069
ghcr.io/openrelik/openrelik-worker-containerslatest01353153,167
ghcr.io/openrelik/openrelik-worker-dfindexeddblatest00131311,290
ghcr.io/openrelik/openrelik-worker-extractionlatest02292942,941
ghcr.io/openrelik/openrelik-worker-flosslatest00131311,290
ghcr.io/openrelik/openrelik-worker-greplatest01131101,208
ghcr.io/openrelik/openrelik-worker-plasolatest02372813,151
ghcr.io/openrelik/openrelik-worker-os-credslatest01352462,723
ghcr.io/openrelik/openrelik-worker-stringslatest01131361,400
ghcr.io/openrelik/openrelik-worker-timesketchlatest01182042,047
ghcr.io/openrelik/openrelik-worker-yaralatest01141741,649
us-docker.pkg.dev/osdfir-registry/timesketch/timesketch×620260209unmeasured
yetiplatform/yeti×42.9.003462573,337
yetiplatform/yeti-frontend2.9.000341511,976
library/postgres17.2-alpine01181341,524
library/postgres×217.5-alpine01251491,806
library/redis×37.4.2-alpine01111241,288
opensearchproject/opensearch3.1.0001453819
library/arangodb3.11.802121321,418
yetiplatform/bloomcheckdev01967694
chromadb/chroma1.5.700231131,370
gcr.io/kaniko-project/executorlatest0071321,177

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

1,463 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalUBUNTU-CVE-2024-12084rsync@3.2.7-0ubuntu0.22.04.23.2.7-0ubuntu0.22.04.3
CriticalBIT-git-2025-48384KEVgit@2.50.0-12.50.1
CriticalDEBIAN-CVE-2025-48384KEVgit@1:2.39.2-1.11:2.39.5-0+deb12u3
CriticalDEBIAN-CVE-2025-6965sqlite3@3.40.1-23.40.1-2+deb12u2
HighALPINE-CVE-2025-15467openssl@3.5.1-r03.5.5-r0
HighDEBIAN-CVE-2025-15467openssl@3.0.16-1~deb12u13.0.18-1~deb12u2
HighALPINE-CVE-2024-6119openssl@3.1.4-r23.1.7-r0
HighDEBIAN-CVE-2024-6119openssl@3.0.13-1~deb12u13.0.14-1~deb12u2
HighGHSA-86qp-5c8j-p5mrKEVstarlette@0.46.21.0.1
HighDEBIAN-CVE-2023-25652git@1:2.39.2-1.11:2.39.5-0+deb12u1
HighDEBIAN-CVE-2024-32002git@1:2.39.2-1.11:2.39.5-0+deb12u1
HighGHSA-45x7-px36-x8w8golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd0.0.0-20231218163308-9d2ee975ef9f
HighALPINE-CVE-2022-37434zlib@1.2.12-r01.2.12-r2
HighGHSA-v23v-6jw2-98fqgithub.com/docker/docker@v24.0.7+incompatible25.0.6
HighGHSA-qppj-fm5r-hxr3KEVgolang.org/x/net@v0.0.0-20220225172249-27dd8689420f0.17.0
HighALPINE-CVE-2026-49975nginx@1.28.3-r11.28.3-r3
HighGHSA-4v7x-pqxf-cx7mgolang.org/x/net@v0.0.0-20220225172249-27dd8689420f0.23.0
HighDEBIAN-CVE-2024-28182nghttp2@1.52.0-1+deb12u11.52.0-1+deb12u2
HighGHSA-f4j7-r4q5-qw2cchromadb@1.5.7no fix listed
HighGHSA-r5fr-rjxr-66jclodash@4.17.214.18.0
HighALPINE-CVE-2024-2511openssl@3.1.4-r23.1.4-r6
HighDEBIAN-CVE-2024-2511openssl@3.0.13-1~deb12u13.0.14-1~deb12u1
HighUBUNTU-CVE-2024-3596krb5@1.19.2-2ubuntu0.31.19.2-2ubuntu0.5
HighUBUNTU-CVE-2025-110017zip@23.01+dfsg-11no fix listed
HighALPINE-CVE-2026-9256nginx@1.28.3-r11.28.3-r2
HighDEBIAN-CVE-2019-6110openssh@1:9.2p1-2+deb12u6no fix listed
MediumGO-2024-2687stdlib@go1.18.21.21.9
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.38.00.52.0
MediumDEBIAN-CVE-2020-15778openssh@1:9.2p1-2+deb12u6no fix listed
MediumALPINE-CVE-2026-42055nginx@1.28.3-r11.28.3-r4
MediumDEBIAN-CVE-2024-7264curl@7.88.1-10+deb12u67.88.1-10+deb12u7
MediumALPINE-CVE-2024-5535openssl@3.1.4-r23.1.6-r0
MediumDEBIAN-CVE-2024-5535openssl@3.0.13-1~deb12u13.0.15-1~deb12u1
MediumUBUNTU-CVE-2024-12085rsync@3.2.7-0ubuntu0.22.04.23.2.7-0ubuntu0.22.04.3
MediumGHSA-jwp6-cvj8-fw65spark-core_2.13@3.5.43.5.7
MediumDEBIAN-CVE-2018-6951patch@2.8-2no fix listed
MediumALPINE-CVE-2026-42533nginx@1.28.3-r11.28.3-r6
MediumUBUNTU-CVE-2018-6952patch@2.7.6-7build3no fix listed
MediumDSA-5769-1git@1:2.39.2-1.11:2.39.5-0+deb12u1
MediumDSA-6113-1openssl@3.0.16-1~deb12u13.0.18-1~deb12u2
MediumDEBIAN-CVE-2019-1010022glibc@2.36-9+deb12u14no fix listed
MediumDEBIAN-CVE-2023-45853zlib@1:1.2.13.dfsg-1no fix listed
MediumDEBIAN-CVE-2017-17740openldap@2.5.13+dfsg-5no fix listed
MediumDEBIAN-CVE-2023-29007git@1:2.39.2-1.11:2.39.5-0+deb12u1
MediumALPINE-CVE-2026-45447openssl@3.5.1-r03.5.7-r0
MediumDEBIAN-CVE-2026-45447openssl@3.5.5-1~deb13u13.5.6-1~deb13u2
MediumDEBIAN-CVE-2018-20796glibc@2.36-9+deb12u14no fix listed
MediumDEBIAN-CVE-2025-26465openssh@1:9.2p1-2+deb12u31:9.2p1-2+deb12u5
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.28.00.31.0
MediumDEBIAN-CVE-2017-16232tiff@4.7.0-3+deb13u3no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.15.0latest10 days ago5488996,12971,208

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/osdfir-infrastructure/osdfir-infrastructure.svg)](https://charts.stackradar.io/charts/osdfir-infrastructure/osdfir-infrastructure)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 6 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.