rybbit 1.3.2 Helm chart
rybbit-helmScored 20 Sept 2026
A Helm chart for Rybbit self-hosted analytics
Version 1.3.2deploys tag 9.1.1 0Artifact Hub
rybbit 1.3.2 deploys 7 container images: valkey/valkey, library/busybox, library/postgres, ghcr.io/rybbit-io/rybbit-backend and 2 more. Across them, 633 findings — 0 critical, 1 high. The highest contribution is GHSA-4v7x-pqxf-cx7m in golang.org/x/net v0.19.0, fixed in 0.23.0. Chart.yaml declares kubeVersion >=1.19.0-0; rendered for Kubernetes 1.19.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| valkey/ | 9.1.1 | 00881 | 861 |
| valkey/ | 9.1.1-alpine | 0004 | 34 |
| library/ | 1.35 | 0000 | 0 |
| library/ | 15-alpine | 00046 | 311 |
| ghcr.io/ | latest | 0014163 | 1,721 |
| ghcr.io/ | latest | 00923 | 417 |
| alpine/ | 1.32.12 | 0138246 | 2,881 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | DEBIAN-CVE-2026-16742 | systemd | no fix listed |
| Low | ALPINE-CVE-2026-54679 | jq | 1.8.2-r0 |
| Low | GHSA-x5fp-wj9c-mxmx | qs | 6.16.0 |
| Low | GO-2026-4403 | stdlib | 1.23.9 |
| Low | GO-2026-5025 | golang.org/ | 0.55.0 |
| Low | GHSA-67mh-4wv8-2f99 | esbuild | 0.25.0 |
| Low | GHSA-v3rj-xjv7-4jmq | smol-toml | 1.6.1 |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GHSA-m8rv-5g2x-5cg5 | undici | 6.28.0 |
| Low | GO-2026-5027 | golang.org/ | 0.55.0 |
| Low | GO-2026-5029 | golang.org/ | 0.55.0 |
| Low | GO-2026-5030 | golang.org/ | 0.55.0 |
| Low | GHSA-58qw-9mgm-455v | pip | 26.1 |
| Low | DEBIAN-CVE-2026-42250 | bzip2 | no fix listed |
| Low | DEBIAN-CVE-2026-39113 | sqlite3 | no fix listed |
| Low | ALPINE-CVE-2026-43895 | jq | 1.8.2-r0 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | DEBIAN-CVE-2026-18508 | tar | no fix listed |
| Low | GHSA-79qm-7rj5-m7r9 | hono | 4.12.34 |
| Low | GO-2026-5622 | github.com/ | no fix listed |
| Low | ALPINE-CVE-2026-41080 | expat | 2.8.0-r0 |
| Low | DEBIAN-CVE-2007-5686 | shadow | no fix listed |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | DEBIAN-CVE-2026-18477 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-82560 | perl | no fix listed |
| Low | GO-2026-5841 | github.com/ | 1.18.7 |
| Low | GO-2026-5884 | oras.land/ | 2.6.1 |
| Low | GO-2026-5932 | golang.org/ | no fix listed |
| Low | GO-2026-6061 | google.golang.org/ | 1.82.1 |
| Low | GO-2026-6278 | github.com/ | 1.5.3 |
| Low | RUSTSEC-2024-0436 | paste | no fix listed |
| Low | RUSTSEC-2026-0097 | rand | 0.8.6 |
| Low | RUSTSEC-2026-0105 | core2 | no fix listed |
| Low | RUSTSEC-2026-0190 | anyhow | 1.0.103 |
| Low | RUSTSEC-2026-0204 | crossbeam-epoch | 0.9.20 |
| Low | DEBIAN-CVE-2026-40228 | systemd | no fix listed |
| Low | DEBIAN-CVE-2026-89162 | pcre2 | 10.46-1~deb13u2 |
| Low | DEBIAN-CVE-2026-53910 | diffutils | no fix listed |
| Low | ALPINE-CVE-2026-6879 | python3 | 3.14.7-r0 |
| Low | GHSA-xf85-363p-868w | oras.land/ | 2.6.1 |
| Low | GHSA-8wmf-6v46-5gfg | go.opentelemetry.io/ | 1.45.0 |
| Low | DEBIAN-CVE-2026-6368 | glibc | no fix listed |
| Low | GHSA-cq8v-f236-94qc | rand | 0.9.3 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.3.2latest | — | 9.1.1 | 0169563 | 6,225 |
| 1.3.0 | — | 9.1.1 | 0169517 | 5,914 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.