planectl Helm chart
planectlVerified publisherScored 14 Sept 2026
One helm install. Four vanilla upstream CNCF charts (Gitea, ArgoCD, Crossplane, Pulumi Operator) pre-wired and ready to use as a GitOps management platform. All connections live in readable wiring/ YAML files. Optional: KEDA for event-driven autoscaling.
Latest 0.7.0 5 months agodeploys tag v2.14.11 0Artifact Hub
planectl 0.7.0 deploys 10 container images: quay.io/argoproj/argocd, public.ecr.aws/docker/library/redis, xpkg.upbound.io/crossplane/crossplane, docker.gitea.com/gitea and 6 more. Across the 8 measured, 2,457 findings — 7 critical, 15 high — 4 on CISA KEV. The highest contribution is BIT-valkey-2025-49844 in valkey 8.1.3-0, fixed in 7.2.11.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| quay.io/ | v2.14.11 | 2154406 | 4,578 |
| public.ecr.aws/ | 7.4.2-alpine | 0111124 | 1,288 |
| xpkg.upbound.io/ | v1.18.5 | — | unmeasured |
| docker.gitea.com/ | 1.25.4-rootless | — | unmeasured |
| pulumi/ | v2.5.1 | 00674 | 679 |
| gitea/ | 0.2.11 | 1227157 | 1,917 |
| library/ | 20 | 02102644 | 7,760 |
| bitnamilegacy/ | 17.6.0-debian-12-r4 | 1151218 | 3,056 |
| bitnamilegacy/ | 8.1.3-debian-12-r3 | 1141189 | 2,540 |
| alpine/ | 1.30.2 | 2771256 | 4,116 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | BIT-valkey-2025-49844 | valkey | 7.2.11 |
| Critical | ALPINE-CVE-2025-48384KEV | git | 2.45.4-r0 |
| Critical | UBUNTU-CVE-2025-48384KEV | git | 1:2.43.0-1ubuntu7.3 |
| Critical | ALPINE-CVE-2025-6965 | sqlite | 3.45.3-r3 |
| Critical | UBUNTU-CVE-2025-6965 | sqlite3 | 3.45.1-1ubuntu2.4 |
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | DEBIAN-CVE-2025-15467 | openssl | 3.0.18-1~deb12u2 |
| High | ALPINE-CVE-2024-6119 | openssl | 3.3.2-r0 |
| High | GHSA-45x7-px36-x8w8 | golang.org/ | 0.17.0 |
| High | GHSA-v23v-6jw2-98fq | github.com/ | 25.0.6 |
| High | GHSA-qppj-fm5r-hxr3KEV | golang.org/ | 0.17.0 |
| High | GHSA-4v7x-pqxf-cx7m | golang.org/ | 0.23.0 |
| High | GHSA-7fxm-f474-hf8w | k8s.io/ | 1.24.17 |
| High | DEBIAN-CVE-2023-34152 | imagemagick | no fix listed |
| High | DEBIAN-CVE-2019-6110 | openssh | no fix listed |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | DEBIAN-CVE-2020-15778 | openssh | no fix listed |
| Medium | GHSA-786q-9hcg-v9ff | github.com/ | 2.14.16 |
| Medium | ALPINE-CVE-2024-7264 | curl | 8.9.1-r0 |
| Medium | GHSA-f5f7-6478-qm6p | k8s.io/ | 1.19.15 |
| Medium | ALPINE-CVE-2024-5535 | openssl | 3.3.1-r1 |
| Medium | GHSA-gpx4-37g2-c8pv | github.com/ | 2.14.20 |
| Medium | DEBIAN-CVE-2018-6951 | patch | no fix listed |
| Medium | DEBIAN-CVE-2018-6952 | patch | no fix listed |
| Medium | DSA-6113-1 | openssl | 3.0.18-1~deb12u2 |
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | DEBIAN-CVE-2017-17740 | openldap | no fix listed |
| Medium | BIT-valkey-2025-46817 | valkey | 7.2.11 |
| Medium | GHSA-wqv3-8cm6-h6wg | k8s.io/ | 1.16.11 |
| Medium | GHSA-hq6q-c2x6-hmch | k8s.io/ | 1.25.16 |
| Medium | DEBIAN-CVE-2026-45447 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | UBUNTU-CVE-2025-26465 | openssh | 1:9.6p1-3ubuntu13.12+Fips1 |
| Medium | GHSA-v778-237x-gjrc | golang.org/ | 0.31.0 |
| Medium | DEBIAN-CVE-2017-16232 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2015-3276 | openldap | no fix listed |
| Medium | GHSA-34jx-wx69-9x8v | k8s.io/ | 1.11.9 |
| Medium | GHSA-q78c-gwqw-jcmc | k8s.io/ | 1.24.17 |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | GHSA-33c5-9fx5-fvjm | k8s.io/ | 1.16.13 |
| Medium | BIT-valkey-2026-23631 | valkey | 7.2.13 |
| Medium | BIT-valkey-2025-32023 | valkey | 7.2.10 |
| Medium | ALPINE-CVE-2024-6197 | curl | 8.9.0-r0 |
| Medium | DEBIAN-CVE-2018-16376 | openjpeg2 | no fix listed |
| Medium | DEBIAN-CVE-2009-3546 | libwmf | no fix listed |
| Medium | BIT-valkey-2026-25243 | valkey | 7.2.13 |
| Medium | GHSA-27wf-5967-98gx | k8s.io/ | 1.28.12 |
| Medium | GHSA-4374-p667-p6c8 | golang.org/ | 0.17.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.7.0latest | 5 months ago | v2.14.11 | 7153632,068 | 25,934 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.