StackRadar

orchestra 3.1.57 Helm chart

tremolo

Scored 7 Oct 2026

A Helm chart for Kubernetes

Version 3.1.57 yesterdayapp version 1.0.53 0Artifact Hub

orchestra 3.1.57 deploys 5 container images: ghcr.io/openunison/openunison-k8s, ghcr.io/headlamp-k8s/headlamp, ghcr.io/tremolosecurity/kube-oidc-proxy, ghcr.io/openunison/openunison-kubernetes-operator and 1 more. Across them, 300 findings — 1 critical, 0 high. The highest contribution is DLA-3807-1 in glibc 2.28-10+deb10u2, fixed in 2.28-10+deb10u3.

Radar Score

2,8131035264

300 findings over 5 of 5 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/openunison/openunison-k8s1.0.5300786799
ghcr.io/headlamp-k8s/headlampv0.45.000820326
ghcr.io/tremolosecurity/kube-oidc-proxy1.0.1300748477
ghcr.io/openunison/openunison-kubernetes-operator1.0.1300792868
ghcr.io/tremolosecurity/python-slim-nonroot/python31.0.010618343

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

157 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-vvgp-rfg2-7rr6jackson-databind@2.22.02.22.1
LowUBUNTU-CVE-2026-86138libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-3832gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowUBUNTU-CVE-2026-70907openjdk-21@21.0.12.1+1-1~24.04.4no fix listed
LowUBUNTU-CVE-2026-105326cups@2.4.7-1.2ubuntu7.14no fix listed
LowUBUNTU-CVE-2026-86144libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-5419gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowUBUNTU-CVE-2026-87875cups@2.4.7-1.2ubuntu7.14no fix listed
LowUBUNTU-CVE-2026-86805glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2025-59529avahi@0.8-13ubuntu6.2no fix listed
LowUSN-8881-1freetype@2.13.2+dfsg-1ubuntu0.12.13.2+dfsg-1ubuntu0.2
LowUBUNTU-CVE-2026-76781libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-54370acl@2.3.2-1build1.1no fix listed
LowUBUNTU-CVE-2024-10041pam@1.5.3-5ubuntu5.7no fix listed
LowGHSA-jp4c-xjxw-mgf9pip@23.1.226.1
LowGO-2026-6094github.com/google/cel-go@v0.29.20.30.0
LowUBUNTU-CVE-2026-102473dash@0.5.12-6ubuntu5no fix listed
LowUBUNTU-CVE-2026-86469glib2.0@2.80.0-6ubuntu3.9no fix listed
LowGHSA-3x3v-w654-m28mundertow-core@2.4.3.Finalno fix listed
LowUBUNTU-CVE-2024-56433shadow@1:4.13+dfsg1-4ubuntu3.2no fix listed
LowUBUNTU-CVE-2026-89092glibc@2.39-0ubuntu8.9no fix listed
LowGHSA-58qw-9mgm-455vpip@23.1.226.1
LowUBUNTU-CVE-2026-18374glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2026-46675libpng1.6@1.6.43-5ubuntu0.6no fix listed
LowUBUNTU-CVE-2026-55453cups@2.4.7-1.2ubuntu7.14no fix listed
LowUBUNTU-CVE-2026-55480cups@2.4.7-1.2ubuntu7.14no fix listed
LowUBUNTU-CVE-2026-61702cups@2.4.7-1.2ubuntu7.14no fix listed
LowUBUNTU-CVE-2026-77214expat@2.6.1-2ubuntu0.6no fix listed
LowUBUNTU-CVE-2026-97399glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2026-90781alsa-lib@1.2.11-1ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-89160pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-60589openjdk-21@21.0.12.1+1-1~24.04.4no fix listed
LowUBUNTU-CVE-2026-18508tar@1.35+dfsg-3ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-41990libgcrypt20@1.10.3-2ubuntu0.21.12.0-2ubuntu0.1~Fips1~rc11
LowUBUNTU-CVE-2022-3219gnupg2@2.4.4-2ubuntu17.6no fix listed
LowUBUNTU-CVE-2026-96674alsa-lib@1.2.11-1ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-102474dash@0.5.12-6ubuntu5no fix listed
LowUBUNTU-CVE-2026-87876cups@2.4.7-1.2ubuntu7.14no fix listed
LowUBUNTU-CVE-2026-89156pcre2@10.42-4ubuntu2.1no fix listed
LowUBUNTU-CVE-2026-18477tar@1.35+dfsg-3ubuntu0.4no fix listed
LowDLA-3482-1debian-archive-keyring@2019.1+deb10u12019.1+deb10u2
LowDLA-3684-1tzdata@2021a-0+deb10u112021a-0+deb10u12
LowDLA-3788-1tzdata@2021a-0+deb10u112024a-0+deb10u1
LowGO-2026-5932golang.org/x/crypto@v0.56.0no fix listed
LowUBUNTU-CVE-2026-95818glibc@2.39-0ubuntu8.9no fix listed
LowUBUNTU-CVE-2025-66382expat@2.6.1-2ubuntu0.6no fix listed
LowUBUNTU-CVE-2026-86137libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-86141libxml2@2.9.14+dfsg-1.3ubuntu3.9no fix listed
LowUBUNTU-CVE-2026-96675alsa-lib@1.2.11-1ubuntu0.3no fix listed
LowUBUNTU-CVE-2026-89162pcre2@10.42-4ubuntu2.1no fix listed

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.1.57latestyesterday1.0.5310352642,813
3.1.5623 days ago1.0.5110383103,307
3.1.551 month ago1.0.50001026917,637

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/tremolo/orchestra.svg)](https://charts.stackradar.io/charts/tremolo/orchestra)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Oct 2026 · scanned 7 Oct 2026 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.