matrix 3.31.0 Helm chart
zekker6Verified publisherNot scored yet
A Helm chart to deploy a Matrix homeserver stack into Kubernetes
Version 3.31.0 todayapp version v1.161.0 3Artifact Hub
matrix 3.31.0 deploys 4 container images: instrumentisto/coturn, devture/exim-relay, vectorim/riot-web and matrixdotorg/synapse. The highest contribution is ALPINE-CVE-2021-3711 in openssl 1.1.1k-r0, fixed in 1.1.1l-r0.
Radar Score
Not yet scored
The daily scoring run has not folded the 4 images into a score yet.
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| instrumentisto/ | 4.5 | 182712 | 1,308 |
| devture/ | 4.98-r0-4 | 011116 | 382 |
| vectorim/ | v1.7.33 | 1124311 | 1,890 |
| matrixdotorg/ | v1.161.0 | — | not yet scanned |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2021-3711 | openssl | 1.1.1l-r0 |
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | ALPINE-CVE-2022-0778 | openssl | 1.1.1n-r0 |
| High | ALPINE-CVE-2022-0778 | libretls | 3.3.3p1-r3 |
| High | ALPINE-CVE-2021-27212 | openldap | 2.4.50-r2 |
| High | ALPINE-CVE-2023-0286 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2018-25032 | zlib | 1.2.12-r0 |
| High | ALPINE-CVE-2021-23840 | openssl | 1.1.1j-r0 |
| High | ALPINE-CVE-2021-3712 | openssl | 1.1.1l-r0 |
| High | ALPINE-CVE-2022-37434 | zlib | 1.2.12-r2 |
| High | ALPINE-CVE-2021-30560 | libxslt | 1.1.35-r0 |
| High | ALPINE-CVE-2021-3449 | openssl | 1.1.1k-r0 |
| High | ALPINE-CVE-2022-40303 | libxml2 | 2.9.14-r2 |
| High | ALPINE-CVE-2022-32206 | curl | 7.79.1-r2 |
| High | ALPINE-CVE-2022-4450 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2021-3450 | openssl | 1.1.1k-r0 |
| High | ALPINE-CVE-2022-43551 | curl | 7.79.1-r4 |
| High | ALPINE-CVE-2022-32207 | curl | 7.79.1-r2 |
| Medium | ALPINE-CVE-2021-22945 | curl | 7.79.0-r0 |
| Medium | ALPINE-CVE-2022-1271 | xz | 5.2.5-r1 |
| Medium | ALPINE-CVE-2022-4304 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2022-40304 | libxml2 | 2.9.14-r2 |
| Medium | ALPINE-CVE-2022-24407 | cyrus-sasl | 2.1.28-r0 |
| Medium | ALPINE-CVE-2022-27404 | freetype | 2.10.4-r2 |
| Medium | ALPINE-CVE-2022-23308 | libxml2 | 2.9.13-r0 |
| Medium | ALPINE-CVE-2022-28391 | busybox | 1.33.1-r7 |
| Medium | ALPINE-CVE-2022-32205 | curl | 7.79.1-r2 |
| Medium | ALPINE-CVE-2021-36159 | apk-tools | 2.12.6-r0 |
| Medium | ALPINE-CVE-2021-22946 | curl | 7.79.0-r0 |
| Medium | ALPINE-CVE-2023-0215 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r1 |
| Medium | ALPINE-CVE-2021-23841 | openssl | 1.1.1j-r0 |
| Medium | ALPINE-CVE-2023-27534 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2022-32208 | curl | 7.79.1-r2 |
| Medium | ALPINE-CVE-2022-27406 | freetype | 2.10.4-r3 |
| Medium | ALPINE-CVE-2023-27533 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2021-32027 | postgresql | 12.7-r0 |
| Medium | ALPINE-CVE-2022-27775 | curl | 7.79.1-r1 |
| Medium | ALPINE-CVE-2022-27782 | curl | 7.79.1-r2 |
| Medium | ALPINE-CVE-2022-27405 | freetype | 2.10.4-r3 |
| Medium | ALPINE-CVE-2021-22922 | curl | 7.78.0-r0 |
| Medium | ALPINE-CVE-2022-27781 | curl | 7.79.1-r2 |
| Medium | ALPINE-CVE-2021-42380 | busybox | 1.33.1-r6 |
| Medium | ALPINE-CVE-2022-22576 | curl | 7.79.1-r1 |
| Medium | ALPINE-CVE-2022-2309 | libxml2 | 2.9.14-r1 |
| Medium | ALPINE-CVE-2022-27776 | curl | 7.79.1-r1 |
| Medium | ALPINE-CVE-2021-42379 | busybox | 1.33.1-r6 |
| Medium | ALPINE-CVE-2021-42381 | busybox | 1.33.1-r6 |
| Medium | ALPINE-CVE-2021-42385 | busybox | 1.33.1-r6 |
| Medium | ALPINE-CVE-2022-29824 | libxml2 | 2.9.14-r0 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 3.31.0latest | today | v1.161.0 | — | — |
| 3.30.0 | 14 days ago | v1.160.0 | 221105220 | 5,595 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.