StackRadar

ygdrassil-monitoring Helm chart

ygdrassilVerified publisher

Scored 14 Sept 2026

Metapackage to deploy Ygdrassil Project monitoring stack (Prometheus, Alertmanager, kube-static-metrics, Grafana)

Latest 0.4.0 7 months agodeploys tag v1.8.2 0Artifact Hub

ygdrassil-monitoring 0.4.0 deploys 10 container images: quay.io/prometheus/node-exporter, grafana/grafana, opensearchproject/opensearch-dashboards, registry.k8s.io/kube-state-metrics/kube-state-metrics and 6 more. Across them, 1,003 findings0 critical, 4 high. The highest contribution is ALPINE-CVE-2025-15467 in openssl 3.3.2-r0, fixed in 3.3.6-r0.

Radar Score

9,38104115884

1,003 findings over 10 of 10 images measured

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

10 images
ImageTagVulnerabilitiesRadar Score
quay.io/prometheus/node-exporterv1.8.200889817
grafana/grafana11.5.101251541,743
opensearchproject/opensearch-dashboards2.18.002261191,731
registry.k8s.io/kube-state-metrics/kube-state-metricsv2.14.000887786
quay.io/prometheus/pushgatewayv1.11.000888788
quay.io/prometheus-operator/prometheus-config-reloaderv0.79.200891809
quay.io/prometheus/prometheusv3.1.00010108980
library/busyboxlatest00000
opensearchproject/opensearch×22.18.0011557942
quay.io/prometheus/alertmanagerv0.28.000791785

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

420 distinct across the version’s images
SeverityAdvisoryPackageFixed in
LowGHSA-c2gf-v879-257jnetty-codec-http2@4.1.108.Final4.1.135.Final
LowGHSA-hpcv-96wg-7vj8dompurify@2.5.63.4.6
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.34.00.55.0
LowGHSA-mmx7-hfxf-jppxaxios@0.28.10.33.0
LowGHSA-rx8g-88g5-qh64min-document@2.19.02.19.1
LowALPINE-CVE-2026-40200musl@1.2.5-r01.2.5-r3
LowGHSA-84h7-rjj3-6jx4netty-codec-http@4.1.108.Final4.1.129.Final
LowGHSA-rcvq-m9j9-6f4g@hapi/inert@6.0.57.1.1
LowGHSA-32q6-rr98-cjqvgithub.com/openfga/openfga@v1.6.21.8.3
LowGHSA-vm32-vv63-w422jspdf@2.5.14.1.0
LowALPINE-CVE-2025-66199openssl@3.3.2-r03.3.6-r0
LowMAL-2025-9145@opensearch/datemath@5.0.3no fix listed
LowGHSA-3pjw-73gf-8qr5jackson-databind@2.17.22.18.8
LowGHSA-j5w8-q4qc-rx2xgolang.org/x/crypto@v0.32.00.45.0
LowGHSA-g4v5-6f5p-m38jgithub.com/openfga/openfga@v1.6.21.8.5
LowGHSA-r47g-fvhr-h676dompurify@2.5.63.4.6
LowGHSA-vvgc-356p-c3xwgolang.org/x/net@v0.34.00.38.0
LowGHSA-65ch-62r8-g69gnode-forge@1.3.11.3.2
LowALPINE-CVE-2025-4947curl@8.11.1-r08.14.0-r0
LowGHSA-68m9-983m-f3v5github.com/openfga/openfga@v1.6.21.14.0
LowGHSA-q7cg-457f-vx79joi@14.3.117.13.4
LowGHSA-crv5-9vww-q3g8dompurify@2.5.63.4.0
LowGHSA-qc2q-p7wx-3px3google.golang.org/grpc@v1.69.21.83.1
LowGHSA-v2wj-7wpq-c8vvdompurify@2.5.62.5.9
LowGHSA-22g5-r2x5-97cxshowdown@1.9.1no fix listed
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.32.00.52.0
LowGHSA-c69g-56f8-xwqjnetty-codec-http2@4.1.108.Final4.1.136.Final
LowALPINE-CVE-2026-22796openssl@3.3.2-r03.3.6-r0
LowGHSA-f6x5-jh6r-wrfvgolang.org/x/crypto@v0.32.00.45.0
LowGHSA-gvwx-54wh-qm9jtar@6.2.17.5.17
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.32.00.52.0
LowALPINE-CVE-2025-10148curl@8.11.1-r08.14.1-r2
LowGHSA-cr32-g25g-vxjjshowdown@1.9.1no fix listed
LowGHSA-v9jr-rg53-9pgpdompurify@3.1.53.4.0
LowGHSA-w222-m46c-mgh6github.com/openfga/openfga@v1.6.21.8.11
LowGO-2024-3106stdlib@go1.22.51.22.7
LowGHSA-v2v4-37r5-5v8gip-address@6.4.010.1.1
LowGHSA-378v-28hj-76wfbn.js@4.12.04.12.3
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.69.21.82.1
LowGHSA-38f8-5428-x5cvnetty-codec-http@4.1.108.Final4.1.133.Final
LowGHSA-h8r8-wccr-v5f2dompurify@2.5.63.3.2
LowGHSA-xq3w-v528-46rvnetty-common@4.1.114.Final4.1.115.Final
LowGHSA-h7mw-gpvr-xq4mdompurify@2.5.63.4.0
LowGHSA-w9j2-pvgh-6h63axios@0.28.10.31.1
LowGHSA-8c42-7qj2-3j46netty-codec-http@4.1.108.Final4.1.137.Final
LowGO-2024-3107stdlib@go1.22.51.22.7
LowGHSA-r7wm-3cxj-wff9jackson-core@2.17.22.18.8
LowGHSA-cjw8-79x6-5cj4jspdf@2.5.14.1.0
LowGHSA-ffqx-q65f-36jfgithub.com/grafana/tempo@v1.5.1-0.20241001135150-ed943d7a56b22.10.3
LowGHSA-389x-839f-4rhxnetty-common@4.1.114.Final4.1.118.Final

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
0.4.0latest7 months agov1.8.2041158849,381

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/ygdrassil/ygdrassil-monitoring.svg)](https://charts.stackradar.io/charts/ygdrassil/ygdrassil-monitoring)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 8 Sept 2026 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.