rekor 1.8.6 Helm chart
sigstoreVerified publisherNot scored yet
Part of the sigstore project, Rekor is a timestamping server and transparency log for storing signatures, as well as an API based server for validation
Version 1.8.6 todayapp version 1.5.4 4Artifact Hub
rekor 1.8.6 deploys 9 container images: gcr.io/trillian-opensource-ci/db_server, library/busybox, ghcr.io/sigstore/scaffolding/trillian_log_server, ghcr.io/sigstore/scaffolding/trillian_log_signer and 5 more. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.3.3-r0, fixed in 3.3.6-r0.
Radar Score
Not yet scored
The daily scoring run has not folded the 9 images into a score yet.
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| gcr.io/ | digest-pinned | 037153 | 1,608 |
| library/ | digest-pinned | 0000 | 0 |
| ghcr.io/ | digest-pinned | 00151 | 378 |
| ghcr.io/ | digest-pinned | 00151 | 378 |
| library/ | digest-pinned | 0112123 | 1,288 |
| curlimages/ | digest-pinned | 012033 | 753 |
| ghcr.io/ | v1.5.4 | 00018 | 131 |
| ghcr.io/ | digest-pinned | 00057 | 387 |
| ghcr.io/ | digest-pinned | 00161 | 450 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | ALPINE-CVE-2026-22795 | openssl | 3.3.6-r0 |
| Low | GO-2026-5856 | stdlib | 1.25.12 |
| Low | GO-2025-4007 | stdlib | 1.24.9 |
| Low | GO-2026-6355 | golang.org/ | 0.56.0 |
| Low | GO-2026-4980 | stdlib | 1.25.10 |
| Low | ALPINE-CVE-2026-42770 | openssl | 3.5.7-r0 |
| Low | GO-2026-5039 | stdlib | 1.25.11 |
| Low | GO-2025-3849 | stdlib | 1.23.12 |
| Low | DLA-4143-1 | glibc | 2.31-13+deb11u12 |
| Low | GO-2025-4013 | stdlib | 1.24.8 |
| Low | GO-2026-4946 | stdlib | 1.25.9 |
| Low | GO-2026-4600 | stdlib | 1.26.1 |
| Low | GO-2022-0646 | github.com/ | no fix listed |
| Low | DLA-4195-1 | krb5 | 1.18.3-6+deb11u7 |
| Low | GO-2026-4866 | stdlib | 1.26.2 |
| Low | GO-2025-3955 | stdlib | 1.25.1 |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | GO-2026-6303 | golang.org/ | 0.55.0 |
| Low | GO-2026-6354 | golang.org/ | 0.56.0 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | GO-2026-6180 | golang.org/ | 0.40.0 |
| Low | GO-2025-3750 | stdlib | 1.23.10 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | GO-2025-3447 | stdlib | 1.22.12 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4869 | stdlib | 1.25.9 |
| Low | GO-2026-4340 | stdlib | 1.24.12 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | ALPINE-CVE-2025-68160 | openssl | 3.3.6-r0 |
| Low | GO-2026-4403 | stdlib | 1.23.9 |
| Low | GO-2026-5025 | golang.org/ | 0.55.0 |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GHSA-jfvp-7x6p-h2pv | github.com/ | 1.1.14 |
| Low | GO-2022-0635 | github.com/ | no fix listed |
| Low | GO-2026-5027 | golang.org/ | 0.55.0 |
| Low | GO-2026-5029 | golang.org/ | 0.55.0 |
| Low | GO-2026-5030 | golang.org/ | 0.55.0 |
| Low | GO-2026-4602 | stdlib | 1.25.8 |
| Low | DLA-4437-1 | gnupg2 | 2.2.27-2+deb11u3 |
| Low | ALPINE-CVE-2025-69418 | openssl | 3.3.6-r0 |
| Low | GO-2026-5024 | golang.org/ | 0.44.0 |
| Low | GO-2026-6179 | golang.org/ | 0.40.0 |
| Low | GHSA-xjvp-4fhw-gc47 | github.com/ | 1.3.6 |
| Low | DLA-3972-1 | tzdata | 2024b-0+deb11u1 |
| Low | DLA-4085-1 | tzdata | 2025a-0+deb11u1 |
| Low | DLA-4105-1 | tzdata | 2025b-0+deb11u1 |
| Low | DLA-4213-1 | curl | 7.74.0-1.3+deb11u15 |
| Low | DLA-4403-1 | tzdata | 2025b-0+deb11u2 |
| Low | DLA-4485-1 | ca-certificates | 20230311+deb12u1~deb11u1 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.8.6latest | today | 1.5.4 | — | — |
| 1.8.5 | 13 days ago | 1.5.4 | 0640550 | 5,416 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.