scaffold 0.6.117 Helm chart
sigstoreVerified publisherScored 9 Oct 2026
Scaffolding the components of the sigstore architecture
Version 0.6.117 yesterdayApp version not verified against the render 1Artifact Hub
scaffold 0.6.117 deploys 15 container images: ghcr.io/sigstore/scaffolding/ct_server, ghcr.io/sigstore/fulcio, library/redis, curlimages/curl and 9 more. Across them, 938 findings — 6 critical, 3 high — 2 on CISA KEV. The highest contribution is DSA-5570-1 in nghttp2 1.43.0-1, fixed in 1.43.0-1+deb11u1.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| ghcr.io/ | v0.7.33 | 002082 | 1,104 |
| ghcr.io/ | v1.9.0 | 00019 | 76 |
| library/ | digest-pinned | 2058107 | 2,277 |
| curlimages/ | digest-pinned | 102133 | 784 |
| ghcr.io/ | v1.5.4 | 00334 | 291 |
| gcr.io/ | digest-pinned | 3350120 | 2,518 |
| library/ | digest-pinned | 0000 | 0 |
| ghcr.io/ | digest-pinned | 00021 | 94 |
| ghcr.io/ | digest-pinned | 00021 | 94 |
| curlimages/ | 8.17.0 | 102133 | 784 |
| ghcr.io/ | v0.7.33 | 001381 | 974 |
| ghcr.io/ | v0.7.33 | 00970 | 793 |
| ghcr.io/ | digest-pinned | 001379 | 955 |
| ghcr.io/ | digest-pinned | 00970 | 793 |
| ghcr.io/ | digest-pinned | 00669 | 731 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | GO-2023-2375 | stdlib | 1.20.0 |
| Medium | GO-2023-1569 | stdlib | 1.19.6 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | GO-2022-1038 | stdlib | 1.18.7 |
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | GO-2024-3106 | stdlib | 1.22.7 |
| Medium | ALPINE-CVE-2026-55200 | libssh2 | 1.11.1-r2 |
| Medium | GO-2023-1570 | stdlib | 1.19.6 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | DSA-5587-1 | curl | 7.74.0-1.3+deb11u11 |
| Medium | GO-2026-6107 | go.etcd.io/ | 3.5.33 |
| Medium | GO-2024-2609 | stdlib | 1.21.8 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | GO-2024-3107 | stdlib | 1.22.7 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2026-9076 | openssl | 3.3.7-r1 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | GO-2023-1751 | stdlib | 1.19.9 |
| Medium | GO-2023-1753 | stdlib | 1.19.9 |
| Medium | GHSA-vp52-pcj8-j9qc | google.golang.org/ | 1.83.1 |
| Medium | GO-2023-1878 | stdlib | 1.19.11 |
| Medium | GO-2022-0525 | stdlib | 1.17.12 |
| Medium | GO-2022-0520 | stdlib | 1.17.12 |
| Medium | ALPINE-CVE-2026-63072 | openssl | 3.3.7-r1 |
| Medium | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Medium | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | GHSA-mh2q-q3fh-2475 | go.opentelemetry.io/ | 1.41.0 |
| Medium | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Medium | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Medium | GO-2026-4601 | stdlib | 1.25.8 |
| Medium | GO-2026-4981 | stdlib | 1.25.10 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.6.117latest | yesterday | — | 63193736 | 10,691 |
| 0.6.116 | 3 days ago | — | 63211709 | 11,521 |
| 0.6.115 | 23 days ago | — | 63214709 | 11,683 |
| 0.6.114 | 1 month ago | — | 64214710 | 11,752 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.