StackRadar

servicex Helm chart

ssl-hep

Scored 15 Sept 2026

Install ServiceX deployment - HEP Columnar Data Delivery Service

Latest 1.8.5 1 month agoapp version 1.8.5 0Artifact Hub

servicex 1.8.5 deploys 16 container images: bitnamilegacy/minio, sslhep/servicex_app, sslhep/servicex_code_gen_atlas_xaod, sslhep/servicex_code_gen_python and 12 more. Across them, 6,345 findings2 critical, 20 high 7 on CISA KEV. The highest contribution is BIT-minio-2023-28434 in minio 2022.12.12-0, fixed in 2023.03.20.

Radar Score

65,1302209845,299

6,345 findings over 16 of 16 images measured

KEV ×7 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

16 images
ImageTagVulnerabilitiesRadar Score
bitnamilegacy/minio2022.12.12-debian-11-r927332323,349
sslhep/servicex_appv1.8.501894915,928
sslhep/servicex_code_gen_atlas_xaod×3v1.8.501904855,907
sslhep/servicex_code_gen_python×2v1.8.501904855,907
sslhep/servicex_code_gen_topcpv1.8.501904855,907
sslhep/servicex_code_gen_func_adl_uprootv1.8.501904855,907
sslhep/servicex_code_gen_raw_uprootv1.8.501904855,907
ncsa/checks×3main01321371,851
sslhep/servicex-did-finder-atlasopenmagicv1.8.501894785,841
sslhep/servicex-did-finder-cernopendatav1.8.501904835,886
sslhep/servicex-did-finderv1.8.5001152506
sslhep/servicex-did-finder-xrootdv1.8.501894875,896
bitnamilegacy/rabbitmq3.11.18-debian-11-r002639596
library/python×23.1001844235,236
library/alpine×23.600000
sslhep/x509-secrets×2v1.8.5001152506

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

814 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowALSA-2026:64815pam@1.5.1-28.el91.5.1-28.el9_8.1
LowALSA-2026:66366vim@2:8.2.2637-26.el9_8.62:8.2.2637-26.el9_8.21
LowALSA-2026:66403coreutils@8.32-41.el9_88.32-41.el9_8.1
LowDEBIAN-CVE-2026-36849tiff@4.7.0-3+deb13u3no fix listed
LowDEBIAN-CVE-2026-53612util-linux@2.41-52.41.5-0+deb13u1
LowDEBIAN-CVE-2026-53613util-linux@2.41-52.41.5-0+deb13u1
LowDEBIAN-CVE-2026-53614util-linux@2.41-52.41.5-0+deb13u1
LowDEBIAN-CVE-2026-53615util-linux@2.41-52.41.5-0+deb13u1
LowDEBIAN-CVE-2026-77117glibc@2.41-12no fix listed
LowDEBIAN-CVE-2026-80489glibc@2.41-12no fix listed
LowDEBIAN-CVE-2026-84450libheif@1.19.8-1no fix listed
LowDEBIAN-CVE-2026-84451libheif@1.19.8-1no fix listed
LowDEBIAN-CVE-2026-85218bluez@5.82-1.1no fix listed
LowDLA-3972-1tzdata@2021a-1+deb11u102024b-0+deb11u1
LowDLA-4085-1tzdata@2021a-1+deb11u102025a-0+deb11u1
LowDLA-4105-1tzdata@2021a-1+deb11u102025b-0+deb11u1
LowDLA-4213-1curl@7.74.0-1.3+deb11u77.74.0-1.3+deb11u15
LowDLA-4403-1tzdata@2021a-1+deb11u102025b-0+deb11u2
LowDLA-4485-1ca-certificates@2021011920230311+deb12u1~deb11u1
LowGO-2023-1859github.com/lestrrat-go/jwx@v1.2.251.2.26
LowGO-2023-2153google.golang.org/grpc@v1.50.11.56.3
LowGO-2026-5932golang.org/x/crypto@v0.3.0no fix listed
LowGO-2026-6061google.golang.org/grpc@v1.50.11.82.1
LowGO-2026-6278github.com/gorilla/websocket@v1.5.01.5.3
LowDEBIAN-CVE-2026-40228systemd@257.7-1no fix listed
LowDEBIAN-CVE-2026-50243unbound@1.22.0-2+deb13u3no fix listed
LowDEBIAN-CVE-2025-50422cairo@1.18.4-1+b1no fix listed
LowDEBIAN-CVE-2026-61081mariadb@1:11.8.6-0+deb13u1no fix listed
LowGHSA-555p-6grf-mh7fdulwich@0.25.21.2.5
LowGHSA-m8cg-xc2p-r3fcgithub.com/opencontainers/runc@v1.1.01.1.5
LowDEBIAN-CVE-2026-14681postgresql-17@17.10-0+deb13u117.11-0+deb13u1
LowDEBIAN-CVE-2023-37769pixman@0.44.0-3no fix listed
LowDEBIAN-CVE-2026-55708unbound@1.22.0-2+deb13u3no fix listed
LowDEBIAN-CVE-2024-52005git@1:2.47.3-0+deb13u1no fix listed
LowGHSA-73h3-mf4w-8647poetry@2.1.12.3.4
LowDEBIAN-CVE-2026-57062gnupg2@2.4.7-21+deb13u1+b4no fix listed
LowDEBIAN-CVE-2026-66011imagemagick@8:7.1.1.43+dfsg1-1+deb13u11no fix listed
LowGHSA-6vgw-5pg2-w6jppip@24.026.0
LowDEBIAN-CVE-2026-15310python3.13@3.13.5-2+deb13u4no fix listed
LowDEBIAN-CVE-2026-53910diffutils@1:3.10-4no fix listed
LowDEBIAN-CVE-2026-6879python3.13@3.13.5-2+deb13u43.13.5-2+deb13u5
LowDEBIAN-CVE-2026-86137libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowDEBIAN-CVE-2026-86141libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix listed
LowDEBIAN-CVE-2023-31439systemd@257.7-1no fix listed
LowDEBIAN-CVE-2023-31437systemd@257.7-1no fix listed
LowDEBIAN-CVE-2023-31438systemd@257.7-1no fix listed
LowDEBIAN-CVE-2026-89162pcre2@10.45-110.46-1~deb13u2
LowDEBIAN-CVE-2026-89156pcre2@10.45-110.46-1~deb13u2
LowDEBIAN-CVE-2024-25260elfutils@0.192-4no fix listed
LowDEBIAN-CVE-2025-66861binutils@2.44-3no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
1.8.5latest1 month ago1.8.52209845,29965,130

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ssl-hep/servicex.svg)](https://charts.stackradar.io/charts/ssl-hep/servicex)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 15 Sept 2026 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.