StackRadar

fulcio 2.11.4 Helm chart

sigstoreVerified publisher

Scored 9 Oct 2026

Fulcio is a free code signing Certificate Authority, built to make short-lived certificates available to anyone.

Version 2.11.4 yesterdayapp version 1.9.0 3Artifact Hub

fulcio 2.11.4 deploys 6 container images: ghcr.io/sigstore/scaffolding/ct_server, ghcr.io/sigstore/fulcio, curlimages/curl, ghcr.io/sigstore/scaffolding/createctconfig and 2 more. Across them, 441 findings — 1 critical, 0 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.5.4-r0, fixed in 3.5.5-r0.

Radar Score

4,6861076364

441 findings over 6 of 6 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

6 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/sigstore/scaffolding/ct_serverv0.7.330020821,104
ghcr.io/sigstore/fulciov1.9.00001976
curlimages/curl8.17.0102133784
ghcr.io/sigstore/scaffolding/createctconfigv0.7.33001381974
ghcr.io/sigstore/scaffolding/createtreev0.7.3300970793
ghcr.io/sigstore/scaffolding/createcertsdigest-pinned001379955

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

118 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGO-2026-4977stdlib@go1.25.01.25.10
LowGO-2026-4986stdlib@go1.25.01.25.10
LowGO-2026-4918golang.org/x/net@v0.47.00.53.0
LowGO-2026-4918stdlib@go1.25.01.25.10
LowALPINE-CVE-2026-42764openssl@3.5.4-r03.5.7-r0
LowALPINE-CVE-2026-63075openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-14456openssl@3.5.4-r03.5.8-r0
LowALPINE-CVE-2026-31789openssl@3.5.4-r03.5.6-r0
LowALPINE-CVE-2026-45445openssl@3.5.4-r03.5.7-r0
LowALPINE-CVE-2026-55199libssh2@1.11.1-r01.11.1-r2
LowGO-2025-4009stdlib@go1.25.01.24.8
LowGO-2025-4006stdlib@go1.25.01.24.8
LowALPINE-CVE-2026-7598libssh2@1.11.1-r01.11.1-r1
LowGO-2026-5942golang.org/x/net@v0.47.00.56.0
LowGHSA-w879-237q-wc7rgolang.org/x/crypto@v0.46.00.52.0
LowALPINE-CVE-2026-54874openssl@3.5.4-r03.5.8-r0
LowGO-2026-4870stdlib@go1.25.01.25.9
LowGHSA-q4h4-gmj2-qvw2golang.org/x/crypto@v0.46.00.52.0
LowGO-2026-4971stdlib@go1.25.01.25.10
LowGO-2026-4947stdlib@go1.25.01.25.9
LowALPINE-CVE-2025-69419openssl@3.5.4-r03.5.5-r0
LowGO-2026-5037stdlib@go1.25.01.25.11
LowGO-2026-5972stdlib@go1.25.01.25.13
LowGO-2026-6088stdlib@go1.25.01.25.13
LowGO-2026-6089stdlib@go1.25.01.25.13
LowGO-2026-6090stdlib@go1.25.01.25.13
LowGO-2026-5038stdlib@go1.25.01.25.11
LowGO-2026-6218stdlib@go1.25.01.25.13
LowALPINE-CVE-2026-42766openssl@3.5.4-r03.5.7-r0
LowGO-2026-6355golang.org/x/crypto@v0.46.00.56.0
LowGO-2026-4342stdlib@go1.25.01.24.12
LowALPINE-CVE-2026-85091zlib@1.3.1-r21.3.2-r1
LowGO-2026-5970golang.org/x/text@v0.32.00.39.0
LowALPINE-CVE-2026-22184zlib@1.3.1-r21.3.2-r0
LowGO-2025-4155stdlib@go1.25.01.24.11
LowGO-2025-4014stdlib@go1.25.01.24.8
LowGHSA-f5mr-q85p-6hh6github.com/sigstore/fulcio@v1.8.31.8.6
LowGO-2026-6303golang.org/x/crypto@v0.46.00.55.0
LowGO-2026-6354golang.org/x/crypto@v0.46.00.56.0
LowALPINE-CVE-2026-75803openssl@3.5.4-r03.5.8-r0
LowGO-2025-4007stdlib@go1.25.01.24.9
LowALPINE-CVE-2025-15468openssl@3.5.4-r03.5.5-r0
LowGO-2025-4013stdlib@go1.25.01.24.8
LowGO-2026-4946stdlib@go1.25.01.25.9
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.46.00.52.0
LowALPINE-CVE-2026-2673openssl@3.5.4-r03.5.6-r0
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.47.00.55.0
LowALPINE-CVE-2026-63074openssl@3.5.4-r03.5.8-r0
LowGHSA-fw7p-63qq-7hprfilippo.io/edwards25519@v1.1.01.1.1
LowGO-2026-4970stdlib@go1.25.01.25.12

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
2.11.4latestyesterday1.9.010763644,686
2.11.33 days ago1.9.010803074,606
2.11.212 days ago1.8.810833074,768
2.11.11 month ago1.8.810833074,768

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/sigstore/fulcio.svg)](https://charts.stackradar.io/charts/sigstore/fulcio)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 9 Oct 2026 · scanned 9 Oct 2026 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.