cf-operator Helm chart
quarksScored 14 Sept 2026
A Helm chart for cf-operator, the k8s operator for deploying BOSH releases
Latest 2.3.0+0.g27a91cdf 6 years agodeploys tag v0.0.0-0.g70ae34b 0Artifact Hub
cf-operator 2.3.0+0.g27a91cdf deploys 2 container images: cfcontainerization/quarks-job and cfcontainerization/cf-operator. Across them, 964 findings — 0 critical, 18 high — 12 on CISA KEV. The highest contribution is GHSA-45x7-px36-x8w8 in golang.org/x/crypto v0.0.0-20190820162420-60c769a6c586, fixed in 0.0.0-20231218163308-9d2ee975ef9f.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| cfcontainerization/ | v0.0.0-0.g70ae34b | 0991382 | 5,971 |
| cfcontainerization/ | v2.3.0-0.g27a91cdf | 0991382 | 5,971 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2022-1095 | stdlib | 1.18.8 |
| Low | openSUSE-SU-2024:13426-1 | libxml2 | 2.11.5-2.1 |
| Low | openSUSE-SU-2026:10895-1 | libsolv | 0.7.38-1.1 |
| Low | GO-2023-1621 | stdlib | 1.19.7 |
| Low | openSUSE-SU-2024:13479-1 | perl | 5.38.2-1.1 |
| Low | GO-2026-4981 | stdlib | 1.25.10 |
| Low | GO-2025-3563 | stdlib | 1.23.8 |
| Low | GO-2026-4977 | stdlib | 1.25.10 |
| Low | GO-2024-2610 | stdlib | 1.21.8 |
| Low | openSUSE-SU-2025:15299-1 | systemd | 257.7-1.1 |
| Low | GO-2026-4986 | stdlib | 1.25.10 |
| Low | GO-2026-4918 | golang.org/ | 0.53.0 |
| Low | GO-2026-4918 | stdlib | 1.25.10 |
| Low | openSUSE-SU-2024:14563-1 | pam | 1.7.0-2.1 |
| Low | GO-2026-4337 | stdlib | 1.24.13 |
| Low | openSUSE-SU-2026:10437-1 | nghttp2 | 1.68.1-1.1 |
| Low | openSUSE-SU-2020:0381-1 | glibc | 2.26-lp151.19.3.1 |
| Low | openSUSE-SU-2024:13192-1 | libxml2 | 2.10.4-3.1 |
| Low | openSUSE-SU-2026:10371-1 | curl | 8.19.0-1.1 |
| Low | openSUSE-SU-2026:10017-1 | curl | 8.18.0-1.1 |
| Low | openSUSE-SU-2024:14333-1 | curl | 8.10.0-1.1 |
| Low | GO-2026-4601 | stdlib | 1.25.8 |
| Low | openSUSE-SU-2024:13806-1 | gnutls | 3.8.4-1.1 |
| Low | openSUSE-SU-2026:10674-1 | curl | 8.20.0-1.1 |
| Low | openSUSE-SU-2026:10140-1 | patch | 2.8-2.1 |
| Low | GO-2026-5026 | golang.org/ | 0.55.0 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | openSUSE-SU-2019:2596-1 | cpio | 2.12-lp151.3.3.1 |
| Low | openSUSE-SU-2024:11305-1 | rpm | 4.16.1.3-3.2 |
| Low | GO-2025-3420 | stdlib | 1.22.11 |
| Low | GO-2026-4342 | stdlib | 1.24.12 |
| Low | GO-2024-2598 | stdlib | 1.21.8 |
| Low | GO-2025-3751 | stdlib | 1.23.10 |
| Low | GHSA-6f62-3596-g6w7 | webrick | 1.8.2 |
| Low | GHSA-74fp-r6jw-h4mp | k8s.io/ | 0.0.0-20190927203648-9ce6eca90e73 |
| Low | openSUSE-SU-2025:14984-1 | xz | 5.8.1-1.1 |
| Low | GO-2024-2961 | golang.org/ | 0.0.0-20220525230936-793ad666bf5e |
| Low | openSUSE-SU-2024:11784-1 | util-linux | 2.37.3-1.1 |
| Low | openSUSE-SU-2025:15019-1 | libxml2 | 2.13.8-1.1 |
| Low | openSUSE-SU-2026:10662-1 | glibc | 2.43-1.1 |
| Low | GO-2025-4116 | golang.org/ | 0.43.0 |
| Low | GO-2026-4870 | stdlib | 1.25.9 |
| Low | GO-2022-0532 | stdlib | 1.17.11 |
| Low | GO-2025-4009 | stdlib | 1.24.8 |
| Low | GO-2026-4947 | stdlib | 1.25.9 |
| Low | openSUSE-SU-2026:10729-1 | krb5 | 1.22.2-3.1 |
| Low | GO-2025-4006 | stdlib | 1.24.8 |
| Low | openSUSE-SU-2026:10896-1 | libzypp | 17.38.10-1.1 |
| Low | GO-2026-5037 | stdlib | 1.25.11 |
| Low | GO-2026-4971 | stdlib | 1.25.10 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.3.0+0.g27a91cdflatest | 6 years ago | v0.0.0-0.g70ae34b | 018182764 | 11,942 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.