servicex 1.8.6 Helm chart
ssl-hepScored 24 Sept 2026
Install ServiceX deployment - HEP Columnar Data Delivery Service
Version 1.8.6 yesterdayapp version 1.8.6 0Artifact Hub
servicex 1.8.6 deploys 16 container images: bitnamilegacy/minio, sslhep/servicex_app, sslhep/servicex_code_gen_atlas_xaod, sslhep/servicex_code_gen_python and 12 more. Across them, 5,222 findings — 2 critical, 30 high — 7 on CISA KEV. The highest contribution is BIT-minio-2023-28434 in minio 2022.12.12-0, fixed in 2023.03.20.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| bitnamilegacy/ | 2022.12.12-debian-11-r9 | 2734242 | 3,499 |
| sslhep/ | v1.8.6 | 0275377 | 4,729 |
| sslhep/ | v1.8.6 | 0276379 | 4,765 |
| sslhep/ | v1.8.6 | 0276379 | 4,765 |
| sslhep/ | v1.8.6 | 0276379 | 4,765 |
| sslhep/ | v1.8.6 | 0276379 | 4,765 |
| sslhep/ | v1.8.6 | 0276379 | 4,765 |
| ncsa/ | main | 0133140 | 1,930 |
| sslhep/ | v1.8.6 | 0275372 | 4,697 |
| sslhep/ | v1.8.6 | 0276377 | 4,743 |
| sslhep/ | v1.8.6 | 001154 | 509 |
| sslhep/ | v1.8.6 | 0275381 | 4,757 |
| bitnamilegacy/ | 3.11.18-debian-11-r0 | 02639 | 597 |
| library/ | 3.10 | 0275374 | 4,706 |
| library/ | 3.6 | 0000 | 0 |
| sslhep/ | v1.8.6 | 001158 | 547 |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-cwq8-g58r-32hg | github.com/ | 0.0.0-20241213221912-68b004a48f41 |
| Low | GHSA-9277-mp7x-85jf | dulwich | 1.2.5 |
| Low | DEBIAN-CVE-2026-85091 | zlib | no fix listed |
| Low | DEBIAN-CVE-2021-31879 | wget | no fix listed |
| Low | DEBIAN-CVE-2026-60002 | openssh | no fix listed |
| Low | BIT-minio-2023-27589 | minio | 2023.03.13 |
| Low | GHSA-82r6-8w77-94w6 | anyio | 4.14.2 |
| Low | GO-2023-2102 | stdlib | 1.20.10 |
| Low | DEBIAN-CVE-2026-80230 | curl | no fix listed |
| Low | DEBIAN-CVE-2026-34545 | openexr | no fix listed |
| Low | DEBIAN-CVE-2025-69419 | openssl | 3.5.4-1~deb13u2 |
| Low | DEBIAN-CVE-2017-13716 | binutils | no fix listed |
| Low | DEBIAN-CVE-2026-0861 | glibc | 2.41-12+deb13u2 |
| Low | DEBIAN-CVE-2026-58469 | wget | no fix listed |
| Low | DEBIAN-CVE-2017-7275 | imagemagick | no fix listed |
| Low | DEBIAN-CVE-2024-2236 | libgcrypt20 | no fix listed |
| Low | DEBIAN-CVE-2026-34588 | openexr | no fix listed |
| Low | DEBIAN-CVE-2026-31789 | openssl | 3.5.5-1~deb13u2 |
| Low | DEBIAN-CVE-2026-93990 | expat | no fix listed |
| Low | GHSA-rm6m-hrcw-jw33 | github.com/ | 1.13.0 |
| Low | GHSA-6c5v-hqjr-5xxp | github.com/ | 1.13.0 |
| Low | DEBIAN-CVE-2026-54874 | openssl | 3.5.7-1~deb13u2 |
| Low | DEBIAN-CVE-2026-84384 | libheif | no fix listed |
| Low | DEBIAN-CVE-2026-84447 | libheif | no fix listed |
| Low | GHSA-qw9x-cqr3-wc7r | github.com/ | 1.2.8 |
| Low | GHSA-cgrx-mc8f-2prm | github.com/ | 1.2.8 |
| Low | DEBIAN-CVE-2026-42766 | openssl | 3.5.6-1~deb13u2 |
| Low | DEBIAN-CVE-2026-74860 | libxml2 | no fix listed |
| Low | GHSA-vp29-5652-4fw9 | github.com/ | 1.14.3 |
| Low | DEBIAN-CVE-2025-69720 | ncurses | no fix listed |
| Low | DEBIAN-CVE-2025-69650 | binutils | no fix listed |
| Low | DEBIAN-CVE-2025-15281 | glibc | 2.41-12+deb13u2 |
| Low | DEBIAN-CVE-2018-9996 | binutils | no fix listed |
| Low | GO-2022-0969 | stdlib | 1.18.6 |
| Low | DEBIAN-CVE-2026-14164 | libarchive | no fix listed |
| Low | DEBIAN-CVE-2021-32256 | binutils | no fix listed |
| Low | DEBIAN-CVE-2026-86145 | pcre2 | 10.46-1~deb13u2 |
| Low | DEBIAN-CVE-2026-34543 | openexr | no fix listed |
| Low | DEBIAN-CVE-2026-63075 | openssl | 3.5.7-1~deb13u2 |
| Low | DEBIAN-CVE-2025-1178 | binutils | no fix listed |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GHSA-2wpx-qpw2-g5h5 | github.com/ | 1.14.3 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | DEBIAN-CVE-2026-24882 | gnupg2 | no fix listed |
| Low | DEBIAN-CVE-2026-84446 | libheif | no fix listed |
| Low | GHSA-2wrh-6pvc-2jm9 | golang.org/ | 0.13.0 |
| Low | GHSA-33mj-cw25-m34h | github.com/ | 1.13.0 |
| Low | DEBIAN-CVE-2026-9538 | perl | no fix listed |
| Low | GHSA-gfhv-vqv2-4544 | dulwich | 1.2.5 |
| Low | DEBIAN-CVE-2020-15719 | openldap | no fix listed |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 1.8.6latest | yesterday | 1.8.6 | 2308514,309 | 54,539 |
| 1.8.5 | yesterday | 1.8.5 | 2301,0465,634 | 70,558 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.