logging-stack 0.0.14 Helm chart
quench-logging-stackVerified publisherScored 26 Sept 2026
Hardened, operator-free logging stack: Loki + Grafana + Vector, wired together for cluster log aggregation and browsing. Vector ships every pod's logs to Loki; Grafana queries Loki through a pre-provisioned datasource with a ready-made logs dashboard. No CRDs, no logging operator. All components are QuenchWorks-hardened, nonroot, 0-CVE images pinned by digest and cosign-signed. Vector runs as a host DaemonSet (read-only node log dirs) by design — that is the deliberate, toggleable trade-off for a log shipper.
Version 0.0.14app version 0.58.0 (not verified against the render) 0Artifact Hub
logging-stack 0.0.14 deploys 3 container images: ghcr.io/quenchworks/images/vector, ghcr.io/quenchworks/images/grafana and ghcr.io/quenchworks/images/loki. Across them, 64 findings — 0 critical, 0 high. The highest contribution is GO-2025-3704 in github.com/grafana/grafana v13.1.6, with no fix listed.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | digest-pinned | 0006 | 32 |
| ghcr.io/ | digest-pinned | 00645 | 550 |
| ghcr.io/ | digest-pinned | 0007 | 40 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | CGA-cvw6-9pj6-fx5j | openssl | no fix listed |
| Low | CGA-ww43-fhm7-mff3 | openssl | no fix listed |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.0.14latest | — | 0.58.0 | 00658 | 622 |
| 0.0.13 | — | 0.58.0 | 00037 | 241 |
| 0.0.12 | — | 0.58.0 | 00047 | 313 |
| 0.0.11 | — | 1.0.0 | 00041 | 281 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.