shopware Helm chart
robjuzScored 14 Sept 2026
Web publishing platform for building blogs and websites.
Latest 2.0.0 4 years agodeploys tag 2021.12.10-debian-10-r0 0Artifact Hub
shopware 2.0.0 deploys 6 container images: bitnami/minio, bitnami/bitnami-shell, bitnami/elasticsearch, bitnami/mariadb and 2 more. Across the 1 measured, 239 findings — 5 critical, 1 high — 3 on CISA KEV. The highest contribution is GHSA-x752-qjv4-c4hc in dompdf/dompdf v1.0.2, fixed in 1.2.1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnami/ | 2021.12.10-debian-10-r0 | — | unmeasured |
| bitnami/ | 10-debian-10-r273 | — | unmeasured |
| bitnami/ | 7.16.0-debian-10-r0 | — | unmeasured |
| bitnami/ | 10.5.13-debian-10-r0 | — | unmeasured |
| bitnami/ | 6.2.6-debian-10-r53 | — | unmeasured |
| shyim/ | 6.4.6.0 | 5143190 | 2,972 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-4h9w-7vfp-px8m | shopware/ | 6.5.8.17 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GHSA-4j38-f5cw-54h7 | twig/ | 3.26.0 |
| Low | GO-2025-3420 | stdlib | 1.22.11 |
| Low | GO-2026-4342 | stdlib | 1.24.12 |
| Low | GO-2024-2598 | stdlib | 1.21.8 |
| Low | GO-2025-3751 | stdlib | 1.23.10 |
| Low | GHSA-cwxw-98qj-8qjx | guzzlehttp/ | 7.12.1 |
| Low | GO-2026-4870 | stdlib | 1.25.9 |
| Low | GO-2025-4009 | stdlib | 1.24.8 |
| Low | GO-2026-4947 | stdlib | 1.25.9 |
| Low | GHSA-gjfg-22fp-rrxx | composer/ | 2.2.29 |
| Low | GO-2025-4006 | stdlib | 1.24.8 |
| Low | GO-2026-5037 | stdlib | 1.25.11 |
| Low | GO-2026-4971 | stdlib | 1.25.10 |
| Low | GHSA-2x45-7fc3-mxwq | firebase/ | 7.0.0 |
| Low | GHSA-f7vp-7xgx-4w4r | guzzlehttp/ | 7.15.2 |
| Low | GHSA-59qg-93jg-236f | shopware/ | 6.4.18.1 |
| Low | GHSA-f283-ghqc-fg79 | guzzlehttp/ | 7.15.1 |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | GO-2026-5038 | stdlib | 1.25.11 |
| Low | GHSA-94pj-82f3-465w | guzzlehttp/ | 7.14.2 |
| Low | GO-2025-4012 | stdlib | 1.24.8 |
| Low | GO-2025-3956 | stdlib | 1.23.12 |
| Low | GO-2025-4011 | stdlib | 1.24.8 |
| Low | GO-2025-4015 | stdlib | 1.24.8 |
| Low | GO-2026-6218 | stdlib | 1.25.13 |
| Low | GHSA-9v5m-39wh-5chq | shopware/ | 6.6.10.18 |
| Low | GHSA-gqc5-xv7m-gcjq | shopware/ | 6.6.10.15 |
| Low | GHSA-x8cp-jf6f-r4xh | aws/ | 3.368.0 |
| Low | GO-2025-3373 | stdlib | 1.22.11 |
| Low | GHSA-wpwq-4j6v-78m3 | guzzlehttp/ | 7.12.1 |
| Low | GHSA-34xg-wgjx-8xph | guzzlehttp/ | 2.10.2 |
| Low | GO-2025-4155 | stdlib | 1.24.11 |
| Low | GO-2024-2888 | stdlib | 1.21.11 |
| Low | GHSA-hq7v-mx3g-29hw | guzzlehttp/ | 2.10.2 |
| Low | GO-2025-4008 | stdlib | 1.24.8 |
| Low | GO-2025-4010 | stdlib | 1.24.8 |
| Low | GO-2025-4014 | stdlib | 1.24.8 |
| Low | GO-2025-3503 | stdlib | 1.23.7 |
| Low | GHSA-vm85-hxw5-5432 | guzzlehttp/ | 2.12.1 |
| Low | GO-2026-4976 | stdlib | 1.25.10 |
| Low | GO-2026-5856 | stdlib | 1.25.12 |
| Low | GO-2025-4007 | stdlib | 1.24.9 |
| Low | GO-2026-4980 | stdlib | 1.25.10 |
| Low | GO-2026-5039 | stdlib | 1.25.11 |
| Low | GHSA-c2w2-prh8-qm98 | guzzlehttp/ | 2.12.3 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.0.0latest | 4 years ago | 2021.12.10-debian-10-r0 | 5143190 | 2,972 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.