cf-operator Helm chart
quarksScored 14 Sept 2026
A Helm chart for cf-operator, the k8s operator for deploying BOSH releases
Latest 2.3.0+0.g27a91cdf 6 years agodeploys tag v0.0.0-0.g70ae34b 0Artifact Hub
cf-operator 2.3.0+0.g27a91cdf deploys 2 container images: cfcontainerization/quarks-job and cfcontainerization/cf-operator. Across them, 964 findings — 0 critical, 18 high — 12 on CISA KEV. The highest contribution is GHSA-45x7-px36-x8w8 in golang.org/x/crypto v0.0.0-20190820162420-60c769a6c586, fixed in 0.0.0-20231218163308-9d2ee975ef9f.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| cfcontainerization/ | v0.0.0-0.g70ae34b | 0991382 | 5,971 |
| cfcontainerization/ | v2.3.0-0.g27a91cdf | 0991382 | 5,971 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | openSUSE-SU-2024:10755-1 | file | 5.40-1.14 |
| Medium | GHSA-5rcv-m4m3-hfh7 | golang.org/ | 0.3.3 |
| Medium | openSUSE-SU-2024:11158-1 | perl | 5.34.0-1.1 |
| Medium | GHSA-h86h-8ppg-mxmh | golang.org/ | 0.0.0-20210428140749-89ef3d95e781 |
| Medium | openSUSE-SU-2020:0850-1 | perl | 5.26.1-lp151.9.6.1 |
| Medium | GHSA-69ch-w2m2-3vjp | golang.org/ | 0.3.8 |
| Medium | GO-2022-0433 | stdlib | 1.17.9 |
| Medium | openSUSE-SU-2020:2249-1 | curl | 7.60.0-lp151.5.18.1 |
| Medium | openSUSE-SU-2024:11034-1 | lz4 | 1.9.3-1.5 |
| Medium | openSUSE-SU-2024:11195-1 | procps | 3.3.17-5.2 |
| Medium | GHSA-ppp9-7jff-5vj2 | golang.org/ | 0.3.7 |
| Medium | openSUSE-SU-2024:11016-1 | libxml2 | 2.9.12-1.2 |
| Medium | openSUSE-SU-2024:10815-1 | gpg2 | 2.2.27-2.4 |
| Medium | openSUSE-SU-2024:11151-1 | patch | 2.7.6-3.43 |
| Medium | GHSA-g857-hhfv-j68w | zlib | 3.0.1 |
| Medium | openSUSE-SU-2024:12060-1 | patch | 2.7.6-5.1 |
| Medium | openSUSE-SU-2024:10709-1 | cyrus-sasl | 2.1.27-5.7 |
| Medium | openSUSE-SU-2024:11400-1 | sqlite3 | 3.36.0-1.2 |
| Medium | GHSA-ggxm-pgc9-g7fp | rdoc | 6.1.2.1 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | openSUSE-SU-2020:0681-1 | libxml2 | 2.9.7-lp151.5.9.1 |
| Medium | GHSA-jmrx-5g74-6v2f | k8s.io/ | 0.17.0 |
| Medium | GHSA-gwc9-m7rh-j2ww | golang.org/ | 0.0.0-20211202192323-5770296d904e |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | openSUSE-SU-2024:10143-1 | cpio | 2.12-3.90 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | openSUSE-SU-2020:2245-1 | openssl-1_1 | 1.1.0i-lp151.8.12.2 |
| Medium | GO-2021-0243 | stdlib | 1.15.14 |
| Medium | GO-2022-0273 | stdlib | 1.16.8 |
| Medium | GHSA-p782-xgp4-8hr8 | golang.org/ | 0.0.0-20220412211240-33da011f77ad |
| Medium | openSUSE-SU-2020:0586-1 | ruby2.5 | 2.5.8-lp151.4.9.1 |
| Medium | openSUSE-SU-2024:13064-1 | openssl-1_1 | 1.1.1u-5.1 |
| Medium | openSUSE-SU-2024:12524-1 | krb5 | 1.20.1-1.1 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | GHSA-hcg3-q754-cr77 | golang.org/ | 0.35.0 |
| Medium | openSUSE-SU-2024:11950-1 | libxml2 | 2.9.13-1.1 |
| Medium | GO-2022-1144 | stdlib | 1.18.9 |
| Medium | GHSA-6v2p-p543-phr9 | golang.org/ | 0.27.0 |
| Medium | openSUSE-SU-2024:14219-1 | openssl-1_1 | 1.1.1w-11.1 |
| Medium | GHSA-jppv-gw3r-w3q8 | rake | 12.3.3 |
| Medium | openSUSE-SU-2020:0781-1 | libxml2 | 2.9.7-lp151.5.12.1 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.3.0+0.g27a91cdflatest | 6 years ago | v0.0.0-0.g70ae34b | 018182764 | 11,942 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.