lgtm-stack 0.0.21 Helm chart
quench-lgtm-stackVerified publisherNot scored yet
Hardened, operator-free LGTM observability superset in one install: Loki (logs) + Grafana (the single pane) + Tempo (traces) + VictoriaMetrics (Prometheus-compatible metrics) + an OpenTelemetry Collector (OTLP ingest) + Alertmanager. Grafana gets three pre-provisioned datasources — VictoriaMetrics (default), Loki, Tempo — so metrics, logs and traces are explorable side by side out of the box. VictoriaMetrics scrapes pods via annotation-based service discovery; Vector ships every pod's logs to Loki; apps send OTLP traces to the collector, which forwards to Tempo. No operator, no CRDs. All component images are QuenchWorks-hardened, nonroot, 0-CVE, pinned by digest and cosign-signed. node-exporter and Vector take host access by design (cluster metrics + logs); both are toggleable.
Version 0.0.21app version 1.0.0 (not verified against the render) 0Artifact Hub
lgtm-stack 0.0.21 deploys 9 container images: ghcr.io/quenchworks/images/node-exporter, ghcr.io/quenchworks/images/vector, ghcr.io/quenchworks/images/kube-state-metrics, ghcr.io/quenchworks/images/otel-collector and 5 more. The highest contribution is GHSA-2v4p-qf9q-27wj in google.golang.org/grpc v1.82.1, fixed in 1.82.2.
Radar Score
Not yet scored
The daily scoring run has not folded the 9 images into a score yet.
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | digest-pinned | 0001 | 4 |
| ghcr.io/ | digest-pinned | 0005 | 33 |
| ghcr.io/ | digest-pinned | 0005 | 15 |
| ghcr.io/ | digest-pinned | — | not yet scanned |
| ghcr.io/ | digest-pinned | 0008 | 39 |
| ghcr.io/ | digest-pinned | 00025 | 177 |
| ghcr.io/ | digest-pinned | — | not yet scanned |
| ghcr.io/ | digest-pinned | 00019 | 133 |
| ghcr.io/ | digest-pinned | 0004 | 30 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Low | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Low | GHSA-p4r4-xvrq-gvmc | github.com/ | 2.8.4 |
| Low | GHSA-8wv5-x4w7-5gww | github.com/ | 0.24.0 |
| Low | CGA-35fq-7ggc-gcf2 | glibc-2.44 | no fix listed |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GHSA-ffqx-q65f-36jf | github.com/ | 2.10.3 |
| Low | GHSA-g3pg-frfm-pr2m | github.com/ | 1.18.1 |
| Low | GHSA-w34q-cm8f-9c5x | go.opentelemetry.io/ | 0.21.0 |
| Low | CGA-6mw4-h5gw-xj38 | glibc-2.44 | no fix listed |
| Low | GO-2026-6107 | go.etcd.io/ | 3.5.33 |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | GO-2022-0646 | github.com/ | no fix listed |
| Low | GO-2026-6303 | golang.org/ | 0.55.0 |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | CGA-3g3j-42jj-77j3 | glibc-2.44 | no fix listed |
| Low | GO-2022-0635 | github.com/ | no fix listed |
| Low | CGA-2w63-hvq4-f4pc | glibc-2.44 | 2.44-r6 |
| Low | CGA-cvw6-9pj6-fx5j | openssl | no fix listed |
| Low | CGA-ww43-fhm7-mff3 | openssl | no fix listed |
| Low | GO-2026-5841 | github.com/ | 1.18.7 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6094 | github.com/ | 0.30.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.21latest | — | 1.0.0 | — | — |
| 0.0.19 | — | 1.0.0 | 000100 | 657 |
| 0.0.17 | — | 1.0.0 | 001114 | 862 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.