StackRadar

orchestra Helm chart

tremolo

Scored 14 Sept 2026

A Helm chart for Kubernetes

Latest 3.1.55 10 days agoapp version 1.0.50 0Artifact Hub

orchestra 3.1.55 deploys 5 container images: ghcr.io/openunison/openunison-k8s, ghcr.io/headlamp-k8s/headlamp, ghcr.io/tremolosecurity/kube-oidc-proxy, ghcr.io/openunison/openunison-kubernetes-operator and 1 more. Across them, 793 findings0 critical, 0 high. The highest contribution is DLA-3807-1 in glibc 2.28-10+deb10u2, fixed in 2.28-10+deb10u3.

Radar Score

7,63700102691

793 findings over 5 of 5 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

5 images
ImageTagVulnerabilitiesRadar Score
ghcr.io/openunison/openunison-k8s1.0.5000342342,580
ghcr.io/headlamp-k8s/headlampv0.42.00020831,061
ghcr.io/tremolosecurity/kube-oidc-proxy1.0.1200191401,474
ghcr.io/openunison/openunison-kubernetes-operator1.0.1100252022,126
ghcr.io/tremolosecurity/python-slim-nonroot/python31.0.000432396

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

356 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowUBUNTU-CVE-2026-85091zlib@1:1.3.dfsg-3.1ubuntu2.1no fix listed
LowGHSA-mvh2-crg5-v77cnetty-codec-http@4.2.13.Final4.2.16.Final
LowUBUNTU-CVE-2026-42497perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.3
LowUBUNTU-CVE-2026-41992gzip@1.12-1ubuntu3.11.12-1ubuntu3.2
LowGHSA-558v-64gr-wgg4netty-codec-compression@4.2.13.Final4.2.16.Final
LowUBUNTU-CVE-2026-8932curl@8.5.0-2ubuntu10.98.5.0-2ubuntu10.13
LowGHSA-8xwf-rjm4-xvhvoras.land/oras-go/v2@v2.6.02.6.1
LowUBUNTU-CVE-2026-8286curl@8.5.0-2ubuntu10.98.5.0-2ubuntu10.10
LowGHSA-wf93-45jw-7689pip@23.1.226.1.2
LowALPINE-CVE-2026-75803openssl@3.5.5-r03.5.8-r0
LowUBUNTU-CVE-2026-75803openssl@3.0.13-0ubuntu3.93.0.13-0ubuntu3.15
LowGHSA-jxpm-75mh-9fp7oras.land/oras-go/v2@v2.6.02.6.1
LowUBUNTU-CVE-2026-4046glibc@2.39-0ubuntu8.72.39-0ubuntu8.8
LowUBUNTU-CVE-2026-58014glib2.0@2.80.0-6ubuntu3.8no fix listed
LowUBUNTU-CVE-2026-48959perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.4
LowUBUNTU-CVE-2026-59843libssh@0.10.6-2ubuntu0.40.10.6-2ubuntu0.5
LowUBUNTU-CVE-2026-5928glibc@2.39-0ubuntu8.72.39-0ubuntu8.8
LowUBUNTU-CVE-2026-3833gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowUBUNTU-CVE-2026-6791glibc@2.39-0ubuntu8.72.39-0ubuntu8.9
LowUBUNTU-CVE-2026-47058openjdk-21@21.0.11+10-1~24.04.2no fix listed
LowUBUNTU-CVE-2026-8458curl@8.5.0-2ubuntu10.98.5.0-2ubuntu10.10
LowUBUNTU-CVE-2026-76641expat@2.6.1-2ubuntu0.4no fix listed
LowUBUNTU-CVE-2026-58469wget@1.21.4-1ubuntu4.11.21.4-1ubuntu4.3
LowUBUNTU-CVE-2025-5222icu@74.2-1ubuntu3.1no fix listed
LowDLA-3782-1util-linux@2.33.1-0.12.33.1-0.1+deb10u1
LowDLA-3586-1ncurses@6.1+20181013-2+deb10u36.1+20181013-2+deb10u4
LowUBUNTU-CVE-2026-58013glib2.0@2.80.0-6ubuntu3.8no fix listed
LowUBUNTU-CVE-2026-34990cups@2.4.7-1.2ubuntu7.92.4.7-1.2ubuntu7.13
LowUBUNTU-CVE-2026-4437glibc@2.39-0ubuntu8.72.39-0ubuntu8.8
LowUBUNTU-CVE-2026-58015glib2.0@2.80.0-6ubuntu3.8no fix listed
LowUBUNTU-CVE-2026-58010glib2.0@2.80.0-6ubuntu3.8no fix listed
LowUBUNTU-CVE-2026-58012glib2.0@2.80.0-6ubuntu3.8no fix listed
LowUBUNTU-CVE-2026-9547curl@8.5.0-2ubuntu10.98.5.0-2ubuntu10.10
LowUBUNTU-CVE-2026-58011glib2.0@2.80.0-6ubuntu3.8no fix listed
LowGHSA-j92g-9f8w-j867postgresql@42.7.1142.7.12
LowUBUNTU-CVE-2026-42012gnutls28@3.8.3-1.1ubuntu3.63.8.3-1.1ubuntu3.6+Fips1.2
LowUBUNTU-CVE-2026-40355krb5@1.20.1-6ubuntu2.61.20.1-6ubuntu2.7
LowUBUNTU-CVE-2026-57432perl@5.38.2-3.2ubuntu0.25.38.2-3.2ubuntu0.4
LowUBUNTU-CVE-2026-40356krb5@1.20.1-6ubuntu2.61.20.1-6ubuntu2.7
LowGHSA-fxhp-mv3v-67qporas.land/oras-go/v2@v2.6.02.6.2
LowALPINE-CVE-2026-2673openssl@3.5.5-r03.5.6-r0
LowPYSEC-2026-2113aiohttp@3.14.03.14.1
LowPYSEC-2026-2112aiohttp@3.14.03.14.1
LowUBUNTU-CVE-2016-2781coreutils@9.4-3ubuntu6.2no fix listed
LowDLA-3783-1expat@2.2.6-2+deb10u62.2.6-2+deb10u7
LowGHSA-8rrh-rw8j-w5fxwheel@0.40.00.46.2
LowGHSA-xhf5-7wjv-pqxpgithub.com/containerd/containerd@v1.7.301.7.33
LowGHSA-fccg-mwvh-qqg4netty-handler@4.1.130.Final4.1.137.Final
LowALPINE-CVE-2026-42767openssl@3.5.5-r03.5.7-r0
LowUBUNTU-CVE-2026-42767openssl@3.0.13-0ubuntu3.93.0.13-0ubuntu3.11

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
3.1.55latest10 days ago1.0.50001026917,637

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/tremolo/orchestra.svg)](https://charts.stackradar.io/charts/tremolo/orchestra)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 7 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.