gcr.io/spinnaker-marketplace/halyard:1.32.0 container image
Google Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.all tags of gcr.io/spinnaker-marketplace/halyard
gcr.io/spinnaker-marketplace/halyard:1.32.0 resolved to 0ee5f968d2ab, scanned 14 Sept 2026: 366 findings, 15 critical, 9 on KEV; deployed by 1 chart, among them spinnaker.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
366 distinct on this digest
Findings for digest 0ee5f968d2ab as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | GHSA-hvv8-336g-rx3m | xstream | 1.4.16 |
| High | GHSA-27hp-xhwr-wr2m | tomcat-embed-core | 9.0.98 |
| High | GHSA-xw4p-crpj-vjx2 | xstream | 1.4.18 |
| High | GHSA-74cv-f58x-f9wf | xstream | 1.4.16 |
| Medium | GHSA-8q59-q68h-6hv4 | pyyaml | 5.4 |
| Medium | GHSA-4jrv-ppp4-jm57 | gson | 2.8.9 |
| Medium | GHSA-mc84-pj99-q6hh | commons-compress | 1.21 |
| Medium | GHSA-3f7h-mf4q-vrm4 | woodstox-core | 6.4.0 |
| Medium | GHSA-crv7-7245-f45f | commons-compress | 1.21 |
| Medium | GHSA-6757-jp84-gxfx | pyyaml | 5.3.1 |
| Medium | ALPINE-CVE-2021-22945 | curl | 7.79.0-r0 |
| Medium | GHSA-7hfm-57qf-j43q | commons-compress | 1.21 |
| Medium | GHSA-j563-grx4-pjpv | xstream | 1.4.20 |
| Medium | GHSA-2rvv-w9r2-rg7m | tomcat-embed-core | 9.0.40 |
| Medium | GHSA-xqfj-vm6h-2x34 | commons-compress | 1.21 |
| Medium | ALPINE-CVE-2021-22926 | curl | 7.67.0-r5 |
| Medium | ALPINE-CVE-2020-8285 | curl | 7.67.0-r3 |
| Medium | GHSA-mm9x-g8pc-w292 | netty-handler | 4.1.46 |
| Medium | GHSA-wm47-8v5p-wjpj | netty-codec-http2 | 4.1.60.Final |
| Medium | GHSA-f62v-xpxf-3v68 | ant | 1.10.9 |
| Medium | GHSA-rmr5-cpv2-vgjf | xstream | 1.4.19 |
| Medium | GHSA-jgwr-3qm3-26f3 | tomcat-embed-core | 9.0.41 |
| Medium | GHSA-qpfq-ph7r-qv6f | xstream | 1.4.16 |
| Medium | GHSA-3ccq-5vw3-2p6x | xstream | 1.4.18 |
| Medium | GHSA-6w62-hx7r-mw68 | xstream | 1.4.18 |
| Medium | GHSA-h7v4-7xg3-hxcc | xstream | 1.4.18 |
| Medium | GHSA-hph2-m3g5-xxv4 | xstream | 1.4.18 |
| Medium | GHSA-qrx8-8545-4wg2 | xstream | 1.4.18 |
| Medium | GHSA-m72m-mhq2-9p6c | jsoup | 1.14.2 |
| Medium | GHSA-9vjp-v76f-g363 | netty-codec | 4.1.68.Final |
| Medium | ALPINE-CVE-2019-15903 | python2 | 2.7.17-r0 |
| Medium | GHSA-64xx-cq4q-mf44 | xstream | 1.4.18 |
| Medium | GHSA-2q8x-2p7f-574v | xstream | 1.4.18 |
| Medium | GHSA-w9jg-gvgr-354m | spring-security-core | 5.2.11 |
| Medium | GHSA-8jrj-525p-826v | xstream | 1.4.18 |
| Medium | GHSA-grg4-wf29-r9vv | netty-codec | 4.1.68.Final |
| Medium | GHSA-g5mm-vmx4-3rg7 | spring-context | 5.2.21.RELEASE |
| Medium | GHSA-43gc-mjxg-gvrq | xstream | 1.4.16 |
| Medium | ALPINE-CVE-2020-11080 | nghttp2 | 1.40.0-r1 |
| Medium | GHSA-gq28-h5vg-8prx | spring-security-web | 5.2.9 |
| Medium | GHSA-f4qf-m5gf-8jm8 | tomcat-embed-core | 9.0.44 |
| Medium | GHSA-cxfm-5m4g-x7xp | xstream | 1.4.18 |
| Medium | GHSA-ccgv-vj62-xf9h | spring-web | no fix listed |
| Medium | GHSA-56p8-3fh9-4cvq | xstream | 1.4.16 |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.12.6.1 |
| Medium | ALPINE-CVE-2021-36159 | apk-tools | 2.10.7-r0 |
| Medium | ALPINE-CVE-2020-8286 | curl | 7.67.0-r3 |
| Medium | GHSA-wm9w-rjj3-j356 | tomcat-embed-core | 9.0.90 |
| Medium | ALPINE-CVE-2021-22946 | curl | 7.79.0-r0 |
| Medium | ALPINE-CVE-2020-28196 | krb5 | 1.17.2-r0 |