StackRadar

planectl Helm chart

planectlVerified publisher

Scored 14 Sept 2026

One helm install. Four vanilla upstream CNCF charts (Gitea, ArgoCD, Crossplane, Pulumi Operator) pre-wired and ready to use as a GitOps management platform. All connections live in readable wiring/ YAML files. Optional: KEDA for event-driven autoscaling.

Latest 0.7.0 5 months agodeploys tag v2.14.11 0Artifact Hub

planectl 0.7.0 deploys 10 container images: quay.io/argoproj/argocd, public.ecr.aws/docker/library/redis, xpkg.upbound.io/crossplane/crossplane, docker.gitea.com/gitea and 6 more. Across the 8 measured, 2,457 findings7 critical, 15 high 4 on CISA KEV. The highest contribution is BIT-valkey-2025-49844 in valkey 8.1.3-0, fixed in 7.2.11.

Radar Score

25,9347153632,068

2,457 findings over 8 of 10 images measured

KEV ×4 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
quay.io/argoproj/argocd×6v2.14.1121544064,578
public.ecr.aws/docker/library/redis7.4.2-alpine01111241,288
xpkg.upbound.io/crossplane/crossplane×4v1.18.5unmeasured
docker.gitea.com/gitea×41.25.4-rootlessunmeasured
pulumi/pulumi-kubernetes-operatorv2.5.100674679
gitea/act_runner0.2.1112271571,917
library/node×220021026447,760
bitnamilegacy/postgresql17.6.0-debian-12-r411512183,056
bitnamilegacy/valkey8.1.3-debian-12-r311411892,540
alpine/k8s×21.30.227712564,116

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

1,333 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalBIT-valkey-2025-49844valkey@8.1.3-07.2.11
CriticalALPINE-CVE-2025-48384KEVgit@2.45.2-r02.45.4-r0
CriticalUBUNTU-CVE-2025-48384KEVgit@1:2.43.0-1ubuntu7.21:2.43.0-1ubuntu7.3
CriticalALPINE-CVE-2025-6965sqlite@3.45.3-r13.45.3-r3
CriticalUBUNTU-CVE-2025-6965sqlite3@3.45.1-1ubuntu2.13.45.1-1ubuntu2.4
HighALPINE-CVE-2025-15467openssl@3.3.1-r03.3.6-r0
HighDEBIAN-CVE-2025-15467openssl@3.0.17-1~deb12u13.0.18-1~deb12u2
HighALPINE-CVE-2024-6119openssl@3.3.1-r03.3.2-r0
HighGHSA-45x7-px36-x8w8golang.org/x/crypto@v0.5.00.17.0
HighGHSA-v23v-6jw2-98fqgithub.com/docker/docker@v24.0.9+incompatible25.0.6
HighGHSA-qppj-fm5r-hxr3KEVgolang.org/x/net@v0.9.00.17.0
HighGHSA-4v7x-pqxf-cx7mgolang.org/x/net@v0.9.00.23.0
HighGHSA-7fxm-f474-hf8wk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.24.17
HighDEBIAN-CVE-2023-34152imagemagick@8:6.9.11.60+dfsg-1.6+deb12u8no fix listed
HighDEBIAN-CVE-2019-6110openssh@1:9.2p1-2+deb12u9no fix listed
MediumGO-2024-2687stdlib@go1.20.51.21.9
MediumGHSA-5cgq-3rg8-m6cvgolang.org/x/crypto@v0.47.00.52.0
MediumDEBIAN-CVE-2020-15778openssh@1:9.2p1-2+deb12u9no fix listed
MediumGHSA-786q-9hcg-v9ffgithub.com/argoproj/argo-cd/v2@v2.14.112.14.16
MediumALPINE-CVE-2024-7264curl@8.8.0-r08.9.1-r0
MediumGHSA-f5f7-6478-qm6pk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.19.15
MediumALPINE-CVE-2024-5535openssl@3.3.1-r03.3.1-r1
MediumGHSA-gpx4-37g2-c8pvgithub.com/argoproj/argo-cd/v2@v2.14.112.14.20
MediumDEBIAN-CVE-2018-6951patch@2.7.6-7no fix listed
MediumDEBIAN-CVE-2018-6952patch@2.7.6-7no fix listed
MediumDSA-6113-1openssl@3.0.17-1~deb12u13.0.18-1~deb12u2
MediumDEBIAN-CVE-2019-1010022glibc@2.36-9+deb12u13no fix listed
MediumDEBIAN-CVE-2023-45853zlib@1:1.2.13.dfsg-1no fix listed
MediumDEBIAN-CVE-2017-17740openldap@2.5.13+dfsg-5no fix listed
MediumBIT-valkey-2025-46817valkey@8.1.3-07.2.11
MediumGHSA-wqv3-8cm6-h6wgk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.16.11
MediumGHSA-hq6q-c2x6-hmchk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.25.16
MediumDEBIAN-CVE-2026-45447openssl@3.0.19-1~deb12u23.0.20-1~deb12u2
MediumDEBIAN-CVE-2018-20796glibc@2.36-9+deb12u13no fix listed
MediumUBUNTU-CVE-2025-26465openssh@1:9.6p1-3ubuntu13.91:9.6p1-3ubuntu13.12+Fips1
MediumGHSA-v778-237x-gjrcgolang.org/x/crypto@v0.24.00.31.0
MediumDEBIAN-CVE-2017-16232tiff@4.5.0-6+deb12u4no fix listed
MediumDEBIAN-CVE-2015-3276openldap@2.5.13+dfsg-5no fix listed
MediumGHSA-34jx-wx69-9x8vk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.11.9
MediumGHSA-q78c-gwqw-jcmck8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.24.17
MediumDEBIAN-CVE-2019-1010023glibc@2.36-9+deb12u13no fix listed
MediumGHSA-33c5-9fx5-fvjmk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.16.13
MediumBIT-valkey-2026-23631valkey@8.1.3-07.2.13
MediumBIT-valkey-2025-32023valkey@8.1.3-07.2.10
MediumALPINE-CVE-2024-6197curl@8.8.0-r08.9.0-r0
MediumDEBIAN-CVE-2018-16376openjpeg2@2.5.0-2+deb12u2no fix listed
MediumDEBIAN-CVE-2009-3546libwmf@0.2.12-5.1no fix listed
MediumBIT-valkey-2026-25243valkey@8.1.3-07.2.13
MediumGHSA-27wf-5967-98gxk8s.io/kubernetes@v0.0.0-20240611202059-39683505b6301.28.12
MediumGHSA-4374-p667-p6c8golang.org/x/net@v0.9.00.17.0

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.7.0latest5 months agov2.14.117153632,06825,934

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/planectl/planectl.svg)](https://charts.stackradar.io/charts/planectl/planectl)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.