shopware Helm chart
shopware-storeVerified publisherScored 14 Sept 2026
A Helm chart for deploying a Shopware shop on Kubernetes. Requires the Shopware Operator chart to be installed.
Latest 2.1.1 6 days agodeploys tag 1.14.0 0Artifact Hub
shopware 2.1.1 deploys 5 container images: percona/percona-xtradb-cluster-operator, library/busybox, rustfs/rustfs, valkey/valkey and 1 more. Across them, 437 findings — 3 critical, 8 high — 1 on CISA KEV. The highest contribution is RHSA-2024:3339 in glibc 2.34-83.el9_3.7, fixed in 0:2.34-100.el9_4.2.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| percona/ | 1.14.0 | 3728160 | 2,514 |
| library/ | latest | 0000 | 0 |
| rustfs/ | 1.0.0-alpha.73 | 011736 | 729 |
| valkey/ | 8 | 00879 | 807 |
| minio/ | latest | 00791 | 826 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | RHSA-2026:4188 | gnutls | 0:3.8.3-10.el9_7 |
| Low | DEBIAN-CVE-2026-6238 | glibc | no fix listed |
| Low | ALPINE-CVE-2026-34181 | openssl | 3.5.7-r0 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | DEBIAN-CVE-2026-5435 | glibc | no fix listed |
| Low | DEBIAN-CVE-2026-54369 | acl | no fix listed |
| Low | GO-2024-2963 | stdlib | 1.21.12 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | DEBIAN-CVE-2026-7017 | perl | 5.40.1-6+deb13u1 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r12 |
| Low | ALPINE-CVE-2025-62408 | c-ares | 1.34.6-r0 |
| Low | RHSA-2026:64800 | glib2 | 0:2.68.4-19.el9_8.10 |
| Low | DEBIAN-CVE-2026-54371 | attr | no fix listed |
| Low | ALPINE-CVE-2025-66199 | openssl | 3.5.5-r0 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | RHSA-2026:58936 | sqlite | 0:3.34.1-11.el9_8 |
| Low | RHSA-2025:22660 | systemd | 0:252-55.el9_7.7 |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | RHSA-2026:50147 | libgcrypt | 0:1.10.0-13.el9_8 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-22796 | openssl | 3.5.5-r0 |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GO-2024-2599 | stdlib | 1.21.8 |
| Low | RHSA-2026:61247 | libxml2 | 0:2.9.13-14.el9_8.4 |
| Low | GO-2024-3106 | stdlib | 1.22.7 |
| Low | DEBIAN-CVE-2022-0563 | util-linux | no fix listed |
| Low | RHSA-2025:9430 | krb5 | 0:1.21.1-8.el9_6 |
| Low | RHSA-2026:0719 | gnupg2 | 0:2.3.3-5.el9_7 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | GO-2024-2609 | stdlib | 1.21.8 |
| Low | GO-2024-3107 | stdlib | 1.22.7 |
| Low | DEBIAN-CVE-2026-5704 | tar | no fix listed |
| Low | DEBIAN-CVE-2026-3184 | util-linux | no fix listed |
| Low | GHSA-cp6g-7hqx-qxhp | go.mongodb.org/ | 1.17.7 |
| Low | RHSA-2026:33226 | glibc | 0:2.34-272.el9_8 |
| Low | DEBIAN-CVE-2026-7010 | perl | 5.40.1-6+deb13u1 |
| Low | DEBIAN-CVE-2026-19487 | perl | no fix listed |
| Low | RHSA-2026:12441 | libcap | 0:2.48-10.el9_7.1 |
| Low | GHSA-9m57-25v3-79x9 | golang.org/ | 0.52.0 |
| Low | DEBIAN-CVE-2026-89158 | pcre2 | 10.46-1~deb13u2 |
| Low | ALPINE-CVE-2026-42769 | openssl | 3.5.7-r0 |
| Low | RHSA-2025:4244 | glibc | 0:2.34-125.el9_5.8 |
| Low | GHSA-vffh-x6r8-xx99 | github.com/ | 0.311.2-0.20260410083055-07c6232d159b |
| Low | DEBIAN-CVE-2013-4392 | systemd | no fix listed |
| Low | RHSA-2026:13677 | systemd | 0:252-55.el9_7.9 |
| Low | GO-2024-3333 | golang.org/ | 0.33.0 |
| Low | DEBIAN-CVE-2026-78408 | util-linux | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 2.1.1latest | 6 days ago | 1.14.0 | 3860366 | 4,876 |
| 2.1.0 | 10 days ago | 1.14.0 | 3860366 | 4,876 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.