StackRadar

dependency-track 0.0.5 Helm chart

quench-dependency-trackVerified publisher

Scored 2 Oct 2026

OWASP Dependency-Track, the SBOM analysis platform: the API server, the web UI behind one address, and a bundled PostgreSQL. Hardened by QuenchWorks, nonroot, 0-CVE, cosign-signed and pinned by digest.

Version 0.0.5app version 5.1.1 (not verified against the render) 0Artifact Hub

dependency-track 0.0.5 deploys 3 container images: ghcr.io/quenchworks/images/postgresql, ghcr.io/quenchworks/images/dependency-track and ghcr.io/quenchworks/images/dependency-track-frontend. Across them, 27 findings — 0 critical, 0 high. The highest contribution is GHSA-p6pp-m3f8-5c89 in jackson-core 2.22.2, fixed in 2.22.3.

Radar Score

16000027

27 findings over 3 of 3 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

3 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/quenchworks/images/postgresql×2digest-pinned0001059
ghcr.io/quenchworks/images/dependency-trackdigest-pinned0001171
ghcr.io/quenchworks/images/dependency-track-frontenddigest-pinned000630

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

15 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-p6pp-m3f8-5c89jackson-core@2.22.22.22.3
LowGHSA-7hhh-6rmp-j9qfjackson-core@2.22.22.22.3
LowCGA-hrv7-pwqg-466jpython-3.13@3.13.15_git20260925-r0no fix listed
LowCGA-8fx3-25f8-fh5xpython-3.13@3.13.15_git20260925-r0no fix listed
LowCGA-3p64-pj6v-586cglibc-2.44@2.44-r7no fix listed
LowCGA-36r3-9m2m-pwvxpython-3.13@3.13.15_git20260925-r0no fix listed
LowCGA-3f6x-5fcp-398calsa-lib@1.2.16.1-r2no fix listed
LowCGA-2727-9j94-3x3pglibc-2.44@2.44-r7no fix listed
LowCGA-cvgw-3cr4-v3w5alsa-lib@1.2.16.1-r2no fix listed
LowCGA-84qm-pxw8-f58fglibc-2.44@2.44-r7no fix listed
LowCGA-8grr-r22f-r3r2alsa-lib@1.2.16.1-r2no fix listed
LowCGA-cvw6-9pj6-fx5jopenssl@3.6.5-r0no fix listed
LowCGA-ww43-fhm7-mff3openssl@3.6.5-r0no fix listed
LowCGA-37wc-rr96-hm3fglibc-2.44@2.44-r7no fix listed
LowCGA-5p62-38p7-f47cpython-3.13@3.13.15_git20260925-r0no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.0.5latest—5.1.100027160
0.0.4—5.1.100029178
0.0.3—5.1.100029181
0.0.2—5.1.100029181

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/quench-dependency-track/dependency-track.svg)](https://charts.stackradar.io/charts/quench-dependency-track/dependency-track)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 2 Oct 2026 · scanned 2 Oct 2026 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.