StackRadar

ygdrassil-monitoring Helm chart

ygdrassilVerified publisher

Scored 14 Sept 2026

Metapackage to deploy Ygdrassil Project monitoring stack (Prometheus, Alertmanager, kube-static-metrics, Grafana)

Latest 0.4.0 7 months agodeploys tag v1.8.2 0Artifact Hub

ygdrassil-monitoring 0.4.0 deploys 10 container images: quay.io/prometheus/node-exporter, grafana/grafana, opensearchproject/opensearch-dashboards, registry.k8s.io/kube-state-metrics/kube-state-metrics and 6 more. Across them, 1,003 findings0 critical, 4 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.3.2-r0, fixed in 3.3.6-r0.

Radar Score

9,38104115884

1,003 findings over 10 of 10 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
quay.io/prometheus/node-exporterv1.8.200889817
grafana/grafana11.5.101251541,743
opensearchproject/opensearch-dashboards2.18.002261191,731
registry.k8s.io/kube-state-metrics/kube-state-metricsv2.14.000887786
quay.io/prometheus/pushgatewayv1.11.000888788
quay.io/prometheus-operator/prometheus-config-reloaderv0.79.200891809
quay.io/prometheus/prometheusv3.1.00010108980
library/busyboxlatest00000
opensearchproject/opensearch×22.18.0011557942
quay.io/prometheus/alertmanagerv0.28.000791785

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Low findings

348 distinct across the version’s images

Low: findings whose contribution to the Radar Score is 1–14. Show every band

SeverityAdvisoryPackageFixed in
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.69.21.83.1
LowGHSA-v2wj-7wpq-c8vvdompurify@2.5.62.5.9
LowGHSA-22g5-r2x5-97cxshowdown@1.9.1no fix listed
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.32.00.52.0
LowGHSA-c69g-56f8-xwqjnetty-codec-http2@4.1.108.Final4.1.136.Final
LowALPINE-CVE-2026-22796openssl@3.3.2-r03.3.6-r0
LowGHSA-f6x5-jh6r-wrfvgolang.org/x/crypto@v0.32.00.45.0
LowGHSA-gvwx-54wh-qm9jtar@6.2.17.5.17
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.32.00.52.0
LowALPINE-CVE-2025-10148curl@8.11.1-r08.14.1-r2
LowGHSA-cr32-g25g-vxjjshowdown@1.9.1no fix listed
LowGHSA-v9jr-rg53-9pgpdompurify@3.1.53.4.0
LowGHSA-w222-m46c-mgh6github.com/openfga/openfga@v1.6.21.8.11
LowGO-2024-3106stdlib@go1.22.51.22.7
LowGHSA-v2v4-37r5-5v8gip-address@6.4.010.1.1
LowGHSA-378v-28hj-76wfbn.js@4.12.04.12.3
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.69.21.82.1
LowGHSA-38f8-5428-x5cvnetty-codec-http@4.1.108.Final4.1.133.Final
LowGHSA-h8r8-wccr-v5f2dompurify@2.5.63.3.2
LowGHSA-xq3w-v528-46rvnetty-common@4.1.114.Final4.1.115.Final
LowGHSA-h7mw-gpvr-xq4mdompurify@2.5.63.4.0
LowGHSA-w9j2-pvgh-6h63axios@0.28.10.31.1
LowGHSA-8c42-7qj2-3j46netty-codec-http@4.1.108.Final4.1.137.Final
LowGO-2024-3107stdlib@go1.22.51.22.7
LowGHSA-r7wm-3cxj-wff9jackson-core@2.17.22.18.8
LowGHSA-cjw8-79x6-5cj4jspdf@2.5.14.1.0
LowGHSA-ffqx-q65f-36jfgithub.com/grafana/tempo@v1.5.1-0.20241001135150-ed943d7a56b22.10.3
LowGHSA-389x-839f-4rhxnetty-common@4.1.114.Final4.1.118.Final
LowGHSA-cp6g-7hqx-qxhpgo.mongodb.org/mongo-driver@v1.16.11.17.7
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.6.31.7.8
LowGHSA-xmrv-pmrh-hhx2github.com/aws/aws-sdk-go-v2/service/s3@v1.58.31.97.3
LowGHSA-58qx-3vcg-4xpxws@8.18.08.20.1
LowGHSA-4mp9-239f-g9hgnetty-codec-http@4.1.108.Final4.1.136.Final
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.32.00.52.0
LowGHSA-3v7f-55p6-f55ppicomatch@2.3.12.3.2
LowGHSA-497x-rrr9-68jpgithub.com/grafana/loki/v3@v3.2.13.6.4
LowGHSA-mh29-5h37-fv8mjs-yaml@3.14.13.14.2
LowGHSA-x86f-5xw2-fm2rgithub.com/docker/docker@v27.4.1+incompatibleno fix listed
LowGHSA-7q8q-rj6j-mhjqaxios@0.28.10.33.0
LowGHSA-vffh-x6r8-xx99github.com/prometheus/prometheus@v0.52.00.311.2-0.20260410083055-07c6232d159b
LowGHSA-2c64-vmv2-hgfcgithub.com/openfga/openfga@v1.6.21.11.1
LowGHSA-h67p-54hq-rp68js-yaml@3.14.13.15.0
LowGO-2024-3333golang.org/x/net@v0.32.00.33.0
LowGHSA-9h8m-3fm2-qjrqgo.opentelemetry.io/otel/sdk@v1.33.01.40.0
LowGHSA-9w9f-6mg8-jp7wgithub.com/blevesearch/bleve/v2@v2.4.32.5.0
LowGHSA-v8jm-5vwx-cfxmdompurify@2.5.6no fix listed
LowGHSA-jpcw-4wr7-c3vqgithub.com/getkin/kin-openapi@v0.126.00.144.0
LowGHSA-6v7q-wjvx-w8wgbasic-ftp@5.0.55.2.2
LowGHSA-vhxf-7vqr-mrjgdompurify@2.5.63.2.4
LowGHSA-hgj6-7826-r7m5jackson-databind@2.17.22.18.8

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.0latest7 months agov1.8.2041158849,381

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ygdrassil/ygdrassil-monitoring.svg)](https://charts.stackradar.io/charts/ygdrassil/ygdrassil-monitoring)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.