jenkins 0.0.11 Helm chart
quench-jenkinsVerified publisherScored 2 Oct 2026
Jenkins, the leading open-source automation server for building, testing, and deploying software (CI/CD pipelines, Pipeline-as-Code, and a vast plugin ecosystem). Hardened by QuenchWorks as a minimal, nonroot, read-only-rootfs, 0-CVE image, cosign-signed and pinned by digest. Runs as a single-replica StatefulSet with a persistent JENKINS_HOME volume.
Version 0.0.11app version 2.572 (not verified against the render) 0Artifact Hub
jenkins 0.0.11 deploys 1 container image: ghcr.io/quenchworks/images/jenkins. Across them, 23 findings — 0 critical, 0 high. The highest contribution is GHSA-j288-q9x7-2f5v in commons-lang 2.6, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | digest-pinned | 00221 | 218 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-j288-q9x7-2f5v | commons-lang | no fix listed |
| Medium | GHSA-v3pr-hxpr-mfm8 | mina-core | 2.2.8 |
| Low | GHSA-9pwp-9qqc-pr26 | bcprov-jdk18on | 1.85 |
| Low | GHSA-p6pp-m3f8-5c89 | jackson-core | 3.2.2 |
| Low | GHSA-q4xh-88c3-wmh7 | jackson-databind | 2.22.2 |
| Low | GHSA-7hhh-6rmp-j9qf | jackson-core | 3.2.3 |
| Low | GHSA-cxp5-3px4-pw24 | jackson-databind | 2.22.3 |
| Low | GHSA-wv8q-qhhj-9h54 | jackson-databind | 2.22.3 |
| Low | GHSA-qp49-qgx5-5m26 | bcprov-jdk18on | 1.85 |
| Low | GHSA-gx83-3vf8-gh7j | jackson-databind | 2.22.2 |
| Low | GHSA-5gvw-p9qm-jgwh | jackson-databind | 2.22.1 |
| Low | GHSA-wjgm-6hv5-3cvf | jackson-databind | 2.22.2 |
| Low | GHSA-5jmj-h7xm-6q6v | jackson-databind | 2.22.1 |
| Low | CGA-3p64-pj6v-586c | glibc-2.44 | no fix listed |
| Low | GHSA-vvgp-rfg2-7rr6 | jackson-databind | 2.22.1 |
| Low | CGA-3f6x-5fcp-398c | alsa-lib | no fix listed |
| Low | CGA-2727-9j94-3x3p | glibc-2.44 | no fix listed |
| Low | CGA-cvgw-3cr4-v3w5 | alsa-lib | no fix listed |
| Low | CGA-5mg5-hvq2-8763 | glibc-2.44 | no fix listed |
| Low | CGA-8grr-r22f-r3r2 | alsa-lib | no fix listed |
| Low | CGA-cvw6-9pj6-fx5j | openssl | no fix listed |
| Low | CGA-ww43-fhm7-mff3 | openssl | no fix listed |
| Low | CGA-37wc-rr96-hm3f | glibc-2.44 | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.11latest | — | 2.572 | 00221 | 218 |
| 0.0.10 | — | 2.572 | 00221 | 211 |
| 0.0.9 | — | 2.572 | 00221 | 211 |
| 0.0.8 | — | 2.572 | 00211 | 130 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.