StackRadar

jenkins 0.0.11 Helm chart

quench-jenkinsVerified publisher

Scored 2 Oct 2026

Jenkins, the leading open-source automation server for building, testing, and deploying software (CI/CD pipelines, Pipeline-as-Code, and a vast plugin ecosystem). Hardened by QuenchWorks as a minimal, nonroot, read-only-rootfs, 0-CVE image, cosign-signed and pinned by digest. Runs as a single-replica StatefulSet with a persistent JENKINS_HOME volume.

Version 0.0.11app version 2.572 (not verified against the render) 0Artifact Hub

jenkins 0.0.11 deploys 1 container image: ghcr.io/quenchworks/images/jenkins. Across them, 23 findings — 0 critical, 0 high. The highest contribution is GHSA-j288-q9x7-2f5v in commons-lang 2.6, with no fix listed.

Radar Score

21800221

23 findings over 1 of 1 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

1 image
ImageTagVulnerabilitiesRadar Score
ghcr.io/quenchworks/images/jenkinsdigest-pinned00221218

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

23 distinct across the version’s images
SeverityAdvisoryPackageFixed in
MediumGHSA-j288-q9x7-2f5vcommons-lang@2.6no fix listed
MediumGHSA-v3pr-hxpr-mfm8mina-core@2.2.72.2.8
LowGHSA-9pwp-9qqc-pr26bcprov-jdk18on@1.841.85
LowGHSA-p6pp-m3f8-5c89jackson-core@3.2.03.2.2
LowGHSA-q4xh-88c3-wmh7jackson-databind@2.22.02.22.2
LowGHSA-7hhh-6rmp-j9qfjackson-core@3.2.03.2.3
LowGHSA-cxp5-3px4-pw24jackson-databind@2.22.02.22.3
LowGHSA-wv8q-qhhj-9h54jackson-databind@2.22.02.22.3
LowGHSA-qp49-qgx5-5m26bcprov-jdk18on@1.841.85
LowGHSA-gx83-3vf8-gh7jjackson-databind@2.22.02.22.2
LowGHSA-5gvw-p9qm-jgwhjackson-databind@2.22.02.22.1
LowGHSA-wjgm-6hv5-3cvfjackson-databind@2.22.02.22.2
LowGHSA-5jmj-h7xm-6q6vjackson-databind@2.22.02.22.1
LowCGA-3p64-pj6v-586cglibc-2.44@2.44-r7no fix listed
LowGHSA-vvgp-rfg2-7rr6jackson-databind@2.22.02.22.1
LowCGA-3f6x-5fcp-398calsa-lib@1.2.16.1-r2no fix listed
LowCGA-2727-9j94-3x3pglibc-2.44@2.44-r7no fix listed
LowCGA-cvgw-3cr4-v3w5alsa-lib@1.2.16.1-r2no fix listed
LowCGA-5mg5-hvq2-8763glibc-2.44@2.44-r7no fix listed
LowCGA-8grr-r22f-r3r2alsa-lib@1.2.16.1-r2no fix listed
LowCGA-cvw6-9pj6-fx5jopenssl@3.6.5-r0no fix listed
LowCGA-ww43-fhm7-mff3openssl@3.6.5-r0no fix listed
LowCGA-37wc-rr96-hm3fglibc-2.44@2.44-r7no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.0.11latest—2.57200221218
0.0.10—2.57200221211
0.0.9—2.57200221211
0.0.8—2.57200211130

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/quench-jenkins/jenkins.svg)](https://charts.stackradar.io/charts/quench-jenkins/jenkins)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 2 Oct 2026 · scanned 2 Oct 2026 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.