cf-operator Helm chart
quarksScored 14 Sept 2026
A Helm chart for cf-operator, the k8s operator for deploying BOSH releases
Latest 2.3.0+0.g27a91cdf 6 years agodeploys tag v0.0.0-0.g70ae34b 0Artifact Hub
cf-operator 2.3.0+0.g27a91cdf deploys 2 container images: cfcontainerization/quarks-job and cfcontainerization/cf-operator. Across them, 964 findings — 0 critical, 18 high — 12 on CISA KEV. The highest contribution is GHSA-45x7-px36-x8w8 in golang.org/x/crypto v0.0.0-20190820162420-60c769a6c586, fixed in 0.0.0-20231218163308-9d2ee975ef9f.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| cfcontainerization/ | v0.0.0-0.g70ae34b | 0991382 | 5,971 |
| cfcontainerization/ | v2.3.0-0.g27a91cdf | 0991382 | 5,971 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2025-3503 | stdlib | 1.23.7 |
| Low | openSUSE-SU-2025:15757-1 | curl | 8.17.0-1.1 |
| Low | GO-2026-4976 | stdlib | 1.25.10 |
| Low | GO-2026-5856 | stdlib | 1.25.12 |
| Low | openSUSE-SU-2026:10722-1 | glibc | 2.43-2.1 |
| Low | GO-2025-4007 | stdlib | 1.24.9 |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | GO-2026-4980 | stdlib | 1.25.10 |
| Low | GO-2026-5039 | stdlib | 1.25.11 |
| Low | openSUSE-SU-2025:15363-1 | libxml2 | 2.13.8-3.1 |
| Low | openSUSE-SU-2026:11140-1 | glibc | 2.43-4.1 |
| Low | GO-2025-4013 | stdlib | 1.24.8 |
| Low | openSUSE-SU-2025:14851-1 | glibc | 2.41-1.1 |
| Low | GO-2025-3849 | stdlib | 1.23.12 |
| Low | GO-2026-4946 | stdlib | 1.25.9 |
| Low | openSUSE-SU-2026:10171-1 | sqlite3 | 3.51.2-1.1 |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | GO-2026-6303 | golang.org/ | 0.55.0 |
| Low | openSUSE-SU-2024:12245-1 | rpm | 4.17.1-1.1 |
| Low | openSUSE-SU-2026:11201-1 | pam | 1.7.2+git12-2.1 |
| Low | openSUSE-SU-2020:0302-1 | permissions | 20181116-lp151.4.12.1 |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | openSUSE-SU-2024:11749-1 | shadow | 4.11.1-1.1 |
| Low | openSUSE-SU-2020:1534-1 | openldap2 | 2.4.46-lp151.10.18.1 |
| Low | openSUSE-SU-2020:0255-1 | libsolv | 0.7.10-lp151.2.10.1 |
| Low | openSUSE-SU-2020:0255-1 | zypper | 1.14.33-lp151.2.10.1 |
| Low | openSUSE-SU-2020:0255-1 | libzypp | 17.19.0-lp151.2.10.1 |
| Low | openSUSE-SU-2026:10406-1 | sqlite3 | 3.51.3-1.1 |
| Low | openSUSE-SU-2025:15176-1 | curl | 8.14.0-1.1 |
| Low | GO-2025-3750 | stdlib | 1.23.10 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | GO-2025-3447 | stdlib | 1.22.12 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4869 | stdlib | 1.25.9 |
| Low | openSUSE-SU-2025:15327-1 | coreutils | 9.7-3.1 |
| Low | GO-2026-4340 | stdlib | 1.24.12 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | openSUSE-SU-2026:11177-1 | krb5 | 1.22.2-4.1 |
| Low | openSUSE-SU-2025:15021-1 | augeas | 1.14.1-2.1 |
| Low | openSUSE-SU-2025:15477-1 | pam | 1.7.1-3.1 |
| Low | openSUSE-SU-2026:11156-1 | nghttp2 | 1.69.0-2.1 |
| Low | openSUSE-SU-2026:10081-1 | shadow | 4.19.2-2.1 |
| Low | GO-2026-4403 | stdlib | 1.23.9 |
| Low | GO-2026-5025 | golang.org/ | 0.55.0 |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GO-2026-5027 | golang.org/ | 0.55.0 |
| Low | GO-2026-5029 | golang.org/ | 0.55.0 |
| Low | GO-2026-5030 | golang.org/ | 0.55.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.3.0+0.g27a91cdflatest | 6 years ago | v0.0.0-0.g70ae34b | 018182764 | 11,942 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.