ctlog 0.2.69 Helm chart
sigstoreVerified publisherScored 9 Oct 2026
Certificate Log
Version 0.2.69 yesterdayapp version 0.7.33 0Artifact Hub
ctlog 0.2.69 deploys 4 container images: ghcr.io/sigstore/scaffolding/ct_server, curlimages/curl, ghcr.io/sigstore/scaffolding/createctconfig and ghcr.io/sigstore/scaffolding/createtree. Across them, 330 findings — 1 critical, 0 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | v0.7.33 | 002082 | 1,104 |
| curlimages/ | 8.17.0 | 102133 | 784 |
| ghcr.io/ | v0.7.33 | 001381 | 974 |
| ghcr.io/ | v0.7.33 | 00970 | 793 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2025-15467 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-p77j-4mvh-x3m3 | google.golang.org/ | 1.79.3 |
| Medium | ALPINE-CVE-2025-11187 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | GO-2026-4341 | stdlib | 1.24.12 |
| Medium | GHSA-9jj7-4m8r-rfcm | github.com/ | 5.9.0 |
| Medium | GHSA-xgrm-4fwx-7qm8 | github.com/ | 5.9.0 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | GO-2026-4337 | stdlib | 1.24.13 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | GO-2026-5026 | golang.org/ | 0.55.0 |
| Medium | GO-2026-5026 | stdlib | 1.25.13 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-55200 | libssh2 | 1.11.1-r2 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | GO-2026-6107 | go.etcd.io/ | 3.5.33 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Medium | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.5.5-r0 |
| Medium | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Medium | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2025-69420 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | GHSA-mh2q-q3fh-2475 | go.opentelemetry.io/ | 1.41.0 |
| Medium | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Medium | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Medium | GO-2026-4601 | stdlib | 1.25.8 |
| Medium | GO-2026-4981 | stdlib | 1.25.10 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |
| Low | GO-2026-4977 | stdlib | 1.25.10 |
| Low | GO-2026-4986 | stdlib | 1.25.10 |
| Low | GO-2026-4918 | stdlib | 1.25.10 |
| Low | GO-2026-4918 | golang.org/ | 0.53.0 |
| Low | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.5.6-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.2.69latest | yesterday | 0.7.33 | 1063266 | 3,655 |
| 0.2.68 | 1 month ago | 0.7.31 | 1067225 | 3,629 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.