rook-ceph 1.20.8 Helm chart
rookOfficialVerified publisherScored 30 Sept 2026
File, Block, and Object Storage Services for your Cloud-Native Environment
Version 1.20.8 todayapp version v1.20.8 51Artifact Hub
rook-ceph 1.20.8 deploys 2 container images: quay.io/cephcsi/ceph-csi-operator and rook/ceph. Across them, 155 findings — 0 critical, 1 high. The highest contribution is GHSA-x4qr-2fvf-3mr5 in cryptography 36.0.1, fixed in 39.0.1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| quay.io/ | v1.0.4 | 00320 | 171 |
| rook/ | v1.20.8 | 0125106 | 1,330 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-3pgj-pg6c-r5p7 | oauthlib | 3.2.2 |
| Low | GHSA-2wxc-x7rj-hg8f | asyncssh | 2.23.1 |
| Low | GHSA-q2x7-8rv6-6q7h | jinja2 | 3.1.5 |
| Low | GHSA-xqr8-7jwr-rhp7 | certifi | 2023.7.22 |
| Low | GHSA-496j-2rq6-j6cc | grpcio | 1.53.2 |
| Low | GHSA-f9vj-2wh5-fj8j | werkzeug | 3.0.6 |
| Low | GHSA-r6ph-v2qm-q3c2 | cryptography | 46.0.5 |
| Low | PYSEC-2026-3554 | cryptography | 49.0.0 |
| Low | GHSA-vfmq-68hx-4jfw | lxml | 6.1.0 |
| Low | PYSEC-2022-48 | protobuf | 3.15.0 |
| Low | PYSEC-2026-3553 | cryptography | 49.0.0 |
| Low | GHSA-h75v-3vvj-5mfj | jinja2 | 3.1.4 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | GHSA-9hjg-9r4m-mvj7 | requests | 2.32.4 |
| Low | GHSA-8qvm-5x2c-j2w7 | protobuf | 4.25.8 |
| Low | GHSA-h5c8-rqwp-cp95 | jinja2 | 3.1.3 |
| Low | GHSA-29vq-49wr-vm6x | werkzeug | 3.1.6 |
| Low | GHSA-hgf8-39gv-g3f2 | werkzeug | 3.1.4 |
| Low | PYSEC-2023-237 | asyncssh | 2.14.1 |
| Low | GHSA-rw4j-r22c-9gc3 | asyncssh | 2.24.0 |
| Low | GHSA-vp96-hxj8-p424 | pyopenssl | 26.0.0 |
| Low | GHSA-34jh-p97f-mpxf | urllib3 | 1.26.19 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GHSA-qr67-gv47-xwwh | asyncssh | 2.23.1 |
| Low | GHSA-hfvc-g4fc-pqhx | go.opentelemetry.io/ | 1.43.0 |
| Low | GHSA-cpwx-vrp4-4pq7 | jinja2 | 3.1.6 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GHSA-87hc-h4r5-73f7 | werkzeug | 3.1.5 |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | GHSA-65pc-fj4g-8rjx | idna | 3.15 |
| Low | GHSA-9wx4-h78v-vm56 | requests | 2.32.0 |
| Low | GO-2026-4986 | stdlib | 1.25.10 |
| Low | GO-2026-4337 | stdlib | 1.24.13 |
| Low | GO-2026-4981 | stdlib | 1.25.10 |
| Low | GO-2025-3563 | stdlib | 1.23.8 |
| Low | GO-2026-4601 | stdlib | 1.25.8 |
| Low | GO-2026-4977 | stdlib | 1.25.10 |
| Low | GHSA-qccp-gfcp-xxvc | urllib3 | 2.7.0 |
| Low | GO-2026-4918 | stdlib | 1.25.10 |
| Low | GO-2026-4342 | stdlib | 1.24.12 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GO-2025-3420 | stdlib | 1.22.11 |
| Low | GO-2025-3751 | stdlib | 1.23.10 |
| Low | GO-2025-4009 | stdlib | 1.24.8 |
| Low | GHSA-537c-gmf6-5ccf | cryptography | 48.0.1 |
| Low | GO-2025-4006 | stdlib | 1.24.8 |
| Low | GO-2026-5942 | golang.org/ | 0.56.0 |
| Low | GHSA-g4mx-q9vg-27p4 | urllib3 | 1.26.18 |
| Low | GO-2026-4870 | stdlib | 1.25.9 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.20.8latest | today | v1.20.8 | 0128126 | 1,501 |
| 1.20.7 | 27 days ago | v1.20.7 | 0128124 | 1,486 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.