argo-workflows 0.0.5 Helm chart
quench-argo-workflowsVerified publisherScored 20 Sept 2026
Argo Workflows: the container-native workflow engine for Kubernetes. Runs DAG and step-based pipelines as Kubernetes pods via the Workflow/CronWorkflow/WorkflowTemplate CRDs, with the argo-server providing the REST/gRPC API and the embedded web UI. Hardened by QuenchWorks as a minimal, nonroot, 0-CVE image, cosign-signed and pinned by digest. One image ships the controller, the server and the argoexec executor; the controller is told to inject that same pinned digest as the workflow-pod executor, so no upstream registry is ever pulled from.
Version 0.0.5app version 3.7.18 (not verified against the render) 0Artifact Hub
argo-workflows 0.0.5 deploys 1 container image: ghcr.io/quenchworks/images/argo-workflows. Across them, 2 findings — 0 critical, 0 high. The highest contribution is GO-2026-5932 in golang.org/x/crypto v0.56.0, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | digest-pinned | 0002 | 8 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6225 | github.com/ | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.5latest | — | 3.7.18 | 0002 | 8 |
| 0.0.3 | — | 3.7.18 | 0003 | 10 |
| 0.0.2 | — | 3.7.18 | 0002 | 8 |
| 0.0.1 | — | 3.7.15 | 0009 | 58 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.