cert-manager Helm chart
quench-cert-managerVerified publisherScored 14 Sept 2026
cert-manager: automated X.509 certificate management for Kubernetes. Issues and renews certificates from ACME (Let's Encrypt), self-signed, CA, Vault and other Issuers via the Certificate/Issuer/ClusterIssuer CRDs. Hardened by QuenchWorks as minimal, nonroot, 0-CVE images, cosign-signed and pinned by digest. Runs the controller, webhook and cainjector as three deployments; the webhook self-bootstraps its serving CA and the cainjector injects that CA bundle into the admission webhooks, so no external cert-manager dependency is required.
Latest 0.0.7app version 1.21.2 (not verified against the render) 0Artifact Hub
cert-manager 0.0.7 deploys 3 container images: ghcr.io/quenchworks/images/cert-manager-cainjector, ghcr.io/quenchworks/images/cert-manager-controller and ghcr.io/quenchworks/images/cert-manager-webhook. Across them, 3 findings — 0 critical, 0 high. The highest contribution is GO-2026-5932 in golang.org/x/crypto v0.56.0, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | digest-pinned | 0001 | 4 |
| ghcr.io/ | digest-pinned | 0001 | 4 |
| ghcr.io/ | digest-pinned | 0001 | 4 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2026-5932 | golang.org/ | no fix listed |
Indexed versions
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.