rekor 1.8.7 Helm chart
sigstoreVerified publisherScored 9 Oct 2026
Part of the sigstore project, Rekor is a timestamping server and transparency log for storing signatures, as well as an API based server for validation
Version 1.8.7 yesterdayapp version 1.5.4 4Artifact Hub
rekor 1.8.7 deploys 9 container images: gcr.io/trillian-opensource-ci/db_server, library/busybox, ghcr.io/sigstore/scaffolding/trillian_log_server, ghcr.io/sigstore/scaffolding/trillian_log_signer and 5 more. Across them, 631 findings — 6 critical, 3 high — 2 on CISA KEV. The highest contribution is DSA-5570-1 in nghttp2 1.43.0-1, fixed in 1.43.0-1+deb11u1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| gcr.io/ | digest-pinned | 3350120 | 2,518 |
| library/ | digest-pinned | 0000 | 0 |
| ghcr.io/ | digest-pinned | 00021 | 94 |
| ghcr.io/ | digest-pinned | 00021 | 94 |
| library/ | digest-pinned | 2058107 | 2,277 |
| curlimages/ | digest-pinned | 102133 | 784 |
| ghcr.io/ | v1.5.4 | 00334 | 291 |
| ghcr.io/ | digest-pinned | 00669 | 731 |
| ghcr.io/ | digest-pinned | 00970 | 793 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GO-2025-3420 | stdlib | 1.22.11 |
| Low | GO-2025-3956 | stdlib | 1.23.12 |
| Low | GO-2026-4946 | stdlib | 1.25.9 |
| Low | GO-2024-2598 | stdlib | 1.21.8 |
| Low | GO-2023-2186 | stdlib | 1.20.11 |
| Low | ALPINE-CVE-2026-2673 | openssl | 3.5.6-r0 |
| Low | GO-2025-3849 | stdlib | 1.23.12 |
| Low | DLA-4259-1 | systemd | 247.3-7+deb11u7 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | GO-2026-6180 | golang.org/ | 0.40.0 |
| Low | GO-2023-1621 | stdlib | 1.19.7 |
| Low | ALPINE-CVE-2026-63074 | openssl | 3.5.8-r0 |
| Low | DSA-5726-1 | krb5 | 1.18.3-6+deb11u5 |
| Low | DLA-3893-1 | expat | 2.2.10-2+deb11u6 |
| Low | GHSA-fw7p-63qq-7hpr | filippo.io/ | 1.1.1 |
| Low | GO-2026-4970 | stdlib | 1.25.12 |
| Low | GO-2025-3373 | stdlib | 1.22.11 |
| Low | DLA-3926-1 | perl | 5.32.1-4+deb11u4 |
| Low | GO-2025-4012 | stdlib | 1.24.8 |
| Low | ALPINE-CVE-2025-66199 | openssl | 3.3.6-r0 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r11 |
| Low | GO-2026-4980 | stdlib | 1.25.10 |
| Low | DLA-4267-1 | gnutls28 | 3.7.1-5+deb11u8 |
| Low | ALPINE-CVE-2026-42767 | openssl | 3.5.7-r0 |
| Low | GO-2024-2600 | stdlib | 1.21.8 |
| Low | ALPINE-CVE-2026-22796 | openssl | 3.3.6-r0 |
| Low | DLA-4143-1 | glibc | 2.31-13+deb11u12 |
| Low | DSA-5678-1 | glibc | 2.31-13+deb11u10 |
| Low | GO-2025-4011 | stdlib | 1.24.8 |
| Low | GO-2025-4015 | stdlib | 1.24.8 |
| Low | GHSA-f3fp-gc8g-vw66 | github.com/ | 1.1.2 |
| Low | DSA-5650-1 | util-linux | 2.36.1-8+deb11u2 |
| Low | GO-2026-4603 | stdlib | 1.25.8 |
| Low | GO-2025-4175 | stdlib | 1.24.11 |
| Low | GHSA-g2j6-57v7-gm8c | github.com/ | 1.1.5 |
| Low | GHSA-qc2q-p7wx-3px3 | google.golang.org/ | 1.83.1 |
| Low | GO-2026-4864 | stdlib | 1.25.9 |
| Low | GO-2026-6179 | golang.org/ | 0.40.0 |
| Low | GO-2026-4865 | stdlib | 1.25.9 |
| Low | GO-2026-4982 | stdlib | 1.25.10 |
| Low | GO-2026-5025 | golang.org/ | 0.55.0 |
| Low | ALPINE-CVE-2026-34181 | openssl | 3.5.7-r0 |
| Low | DLA-4437-1 | gnupg2 | 2.2.27-2+deb11u3 |
| Low | DLA-4195-1 | krb5 | 1.18.3-6+deb11u7 |
| Low | GO-2026-6091 | stdlib | 1.25.13 |
| Low | GO-2025-4008 | stdlib | 1.24.8 |
| Low | GO-2025-4010 | stdlib | 1.24.8 |
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | DLA-4031-1 | git | 1:2.30.2-1+deb11u4 |
| Low | GO-2024-2888 | stdlib | 1.21.11 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.8.7latest | yesterday | 1.5.4 | 63147475 | 7,582 |
| 1.8.6 | 24 days ago | 1.5.4 | 63161487 | 8,420 |
| 1.8.5 | 1 month ago | 1.5.4 | 64161488 | 8,489 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.