rook-ceph 1.20.8 Helm chart
rookOfficialVerified publisherScored 30 Sept 2026
File, Block, and Object Storage Services for your Cloud-Native Environment
Version 1.20.8 todayapp version v1.20.8 51Artifact Hub
rook-ceph 1.20.8 deploys 2 container images: quay.io/cephcsi/ceph-csi-operator and rook/ceph. Across them, 155 findings — 0 critical, 1 high. The highest contribution is GHSA-x4qr-2fvf-3mr5 in cryptography 36.0.1, fixed in 39.0.1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| quay.io/ | v1.0.4 | 00320 | 171 |
| rook/ | v1.20.8 | 0125106 | 1,330 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-x4qr-2fvf-3mr5 | cryptography | 39.0.1 |
| Medium | GHSA-2g68-c3qc-8985 | werkzeug | 3.0.3 |
| Medium | GHSA-cx63-2mw6-8hw5 | setuptools | 70.0.0 |
| Medium | GHSA-38jv-5279-wg99 | urllib3 | 2.6.3 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | GHSA-j8r2-6x86-q33q | requests | 2.31.0 |
| Medium | PYSEC-2023-192 | urllib3 | 2.0.6 |
| Medium | GHSA-8gq9-2x98-w8hf | protobuf | 3.18.3 |
| Medium | GHSA-xg9f-g7g7-2323 | werkzeug | 2.2.3 |
| Medium | PYSEC-2024-60 | idna | 3.7 |
| Medium | GHSA-m2qf-hxjv-5gpq | flask | 2.2.5 |
| Medium | GHSA-9v9h-cgj8-h64p | cryptography | 42.0.2 |
| Medium | PYSEC-2022-203 | werkzeug | 2.1.1 |
| Medium | GHSA-2xpw-w6gg-jr37 | urllib3 | 2.6.0 |
| Medium | GHSA-gm62-xv2j-4w53 | urllib3 | 2.6.0 |
| Medium | GHSA-3ww4-gg4f-jr7f | cryptography | 42.0.0 |
| Medium | GHSA-q34m-jh98-gwm2 | werkzeug | 3.0.6 |
| Medium | GHSA-c35q-ffpf-5qpm | asyncssh | 2.14.1 |
| Medium | PYSEC-2023-221 | werkzeug | 2.3.8 |
| Medium | PYSEC-2024-230 | certifi | 2024.7.4 |
| Medium | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Medium | PYSEC-2023-254 | cryptography | 41.0.6 |
| Medium | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Medium | GHSA-7gcm-g887-7qv7 | protobuf | 5.29.6 |
| Medium | GHSA-58pv-8j8x-9vj2 | jaraco-context | 6.1.0 |
| Medium | GHSA-mh2q-q3fh-2475 | go.opentelemetry.io/ | 1.41.0 |
| Medium | GHSA-wrxv-2j5q-m38w | lxml | 4.9.1 |
| Medium | GHSA-w7pp-m8wf-vj6r | cryptography | 39.0.1 |
| Medium | PYSEC-2026-2132 | click | 8.3.3 |
| Low | GHSA-3pgj-pg6c-r5p7 | oauthlib | 3.2.2 |
| Low | GHSA-2wxc-x7rj-hg8f | asyncssh | 2.23.1 |
| Low | GHSA-q2x7-8rv6-6q7h | jinja2 | 3.1.5 |
| Low | GHSA-xqr8-7jwr-rhp7 | certifi | 2023.7.22 |
| Low | GHSA-496j-2rq6-j6cc | grpcio | 1.53.2 |
| Low | GHSA-f9vj-2wh5-fj8j | werkzeug | 3.0.6 |
| Low | GHSA-r6ph-v2qm-q3c2 | cryptography | 46.0.5 |
| Low | PYSEC-2026-3554 | cryptography | 49.0.0 |
| Low | GHSA-vfmq-68hx-4jfw | lxml | 6.1.0 |
| Low | PYSEC-2022-48 | protobuf | 3.15.0 |
| Low | PYSEC-2026-3553 | cryptography | 49.0.0 |
| Low | GHSA-h75v-3vvj-5mfj | jinja2 | 3.1.4 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | GHSA-9hjg-9r4m-mvj7 | requests | 2.32.4 |
| Low | GHSA-8qvm-5x2c-j2w7 | protobuf | 4.25.8 |
| Low | GHSA-h5c8-rqwp-cp95 | jinja2 | 3.1.3 |
| Low | GHSA-29vq-49wr-vm6x | werkzeug | 3.1.6 |
| Low | GHSA-hgf8-39gv-g3f2 | werkzeug | 3.1.4 |
| Low | PYSEC-2023-237 | asyncssh | 2.14.1 |
| Low | GHSA-rw4j-r22c-9gc3 | asyncssh | 2.24.0 |
| Low | GHSA-vp96-hxj8-p424 | pyopenssl | 26.0.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.20.8latest | today | v1.20.8 | 0128126 | 1,501 |
| 1.20.7 | 27 days ago | v1.20.7 | 0128124 | 1,486 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.