ccx-monitoring Helm chart
severalninesScored 14 Sept 2026
An Umbrella Chart for observability components in CCX
Latest 0.6.21 7 days agodeploys tag 2.5.0 0Artifact Hub
ccx-monitoring 0.6.21 deploys 7 container images: library/busybox, quay.io/kiwigrid/k8s-sidecar, grafana/grafana, registry.k8s.io/kube-state-metrics/kube-state-metrics and 3 more. Across them, 737 findings — 0 critical, 11 high — 1 on CISA KEV. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.0-r0, fixed in 3.5.5-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| library/ | 1.31.1 | 0000 | 0 |
| quay.io/ | 2.5.0 | 011951 | 878 |
| grafana/ | 12.3.1 | 0138170 | 2,330 |
| registry.k8s.io/ | v2.10.1 | 0210103 | 1,084 |
| victoriametrics/ | v1.96.0 | 031092 | 1,037 |
| quay.io/ | v0.26.0 | 0311110 | 1,239 |
| victoriametrics/ | v1.120.0 | 012092 | 1,140 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2023-2185 | stdlib | 1.20.11 |
| Low | ALPINE-CVE-2024-4603 | openssl | 3.1.5-r0 |
| Low | ALPINE-CVE-2026-12064 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-8932 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-8286 | curl | 8.22.0-r0 |
| Low | GHSA-wf93-45jw-7689 | pip | 26.1.2 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2025-15468 | openssl | 3.5.5-r0 |
| Low | GHSA-pjcq-xvwq-hhpj | github.com/ | 0.1.1 |
| Low | ALPINE-CVE-2026-8458 | curl | 8.22.0-r0 |
| Low | GHSA-wg65-39gg-5wfj | github.com/ | 0.311.3 |
| Low | ALPINE-CVE-2026-6253 | curl | 8.20.0-r0 |
| Low | GHSA-m4p7-r5rc-7g4j | pyasn1 | 0.6.4 |
| Low | GHSA-8ppf-4f7h-5ppj | pyasn1 | 0.6.4 |
| Low | GHSA-hm4w-wwcw-mr6r | pyasn1 | 0.6.4 |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | ALPINE-CVE-2026-9547 | curl | 8.22.0-r0 |
| Low | GHSA-hcxc-wf8j-23hv | github.com/ | 1.18.0 |
| Low | GO-2024-2887 | stdlib | 1.21.11 |
| Low | ALPINE-CVE-2026-6276 | curl | 8.20.0-r0 |
| Low | GHSA-pxq6-2prw-chj9 | github.com/ | no fix listed |
| Low | ALPINE-CVE-2025-26519 | musl | 1.2.4_git20230717-r5 |
| Low | ALPINE-CVE-2026-2673 | openssl | 3.5.6-r0 |
| Low | GHSA-8rrh-rw8j-w5fx | wheel | 0.46.2 |
| Low | ALPINE-CVE-2026-9080 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-42767 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-5545 | curl | 8.20.0-r0 |
| Low | ALPINE-CVE-2026-3784 | curl | 8.19.0-r0 |
| Low | ALPINE-CVE-2026-9545 | curl | 8.22.0-r0 |
| Low | GHSA-6xff-cpcq-vpw2 | github.com/ | 1.5.1-0.20260303204923-b13f74291d48 |
| Low | ALPINE-CVE-2025-14819 | curl | 8.18.0-r0 |
| Low | ALPINE-CVE-2026-76642 | util-linux | 2.41.6-r0 |
| Low | GHSA-hfvc-g4fc-pqhx | go.opentelemetry.io/ | 1.43.0 |
| Low | ALPINE-CVE-2026-63074 | openssl | 3.5.8-r0 |
| Low | GHSA-v86x-5fm3-5p7j | github.com/ | 0.25.1 |
| Low | ALPINE-CVE-2025-4575 | openssl | 3.5.1-r0 |
| Low | GHSA-q9hv-hpm4-hj6x | github.com/ | 1.6.3 |
| Low | ALPINE-CVE-2025-14524 | curl | 8.18.0-r0 |
| Low | ALPINE-CVE-2026-34181 | openssl | 3.5.7-r0 |
| Low | GHSA-mh55-gqvf-xfwm | github.com/ | 1.11.0 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r12 |
| Low | ALPINE-CVE-2025-66199 | openssl | 3.5.5-r0 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | GHSA-68m9-983m-f3v5 | github.com/ | 1.14.0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.6.21latest | 7 days ago | 2.5.0 | 011108618 | 7,708 |
| 0.6.10 | 1 month ago | 2.5.0 | 0998515 | 6,624 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.