ghcr.io/bluesky-social/pds:0.4 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/bluesky-social/pds
ghcr.io/bluesky-social/pds:0.4 resolved to d95725b24dbe, scanned 14 Sept 2026: 84 findings, 0 critical; deployed by 1 chart, among them bluesky-pds.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
84 distinct on this digest
Findings for digest d95725b24dbe as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Low | GHSA-vxpw-j846-p89q | undici | 6.27.0 |
| Low | GHSA-45rx-2jwx-cxfr | @opentelemetry/ | 2.9.0 |
| Low | GHSA-89gr-r52h-f8rx | golang.org/ | 0.52.0 |
| Low | GHSA-jppx-rxg9-jmrx | golang.org/ | 0.52.0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.9 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | GHSA-23hp-3jrh-7fpw | tar | 7.5.19 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | GHSA-rcmh-qjqh-p98v | nodemailer | 7.0.11 |
| Low | GHSA-q4h4-gmj2-qvw2 | golang.org/ | 0.52.0 |
| Low | GHSA-w879-237q-wc7r | golang.org/ | 0.52.0 |
| Low | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.8 |
| Low | GHSA-8x88-c5mf-7j5w | tar | 7.5.18 |
| Low | GHSA-mm7p-fcc7-pg87 | nodemailer | 7.0.7 |
| Low | GHSA-mwp4-54f8-5fhr | ip-address | 10.3.1 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-r292-9mhp-454m | tar | 7.5.21 |
| Low | GHSA-w4pp-8pjf-rmxw | pacote | 21.5.1 |
| Low | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.2 |
| Low | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.1 |
| Low | ALPINE-CVE-2026-63074 | openssl | 3.5.8-r0 |
| Low | GHSA-w8wr-v893-vjvp | tar | 7.5.18 |
| Low | GHSA-45gg-vh54-h5m9 | golang.org/ | 0.52.0 |
| Low | GHSA-p6gq-j5cr-w38f | nodemailer | 9.0.1 |
| Low | GHSA-vvjj-xcjg-gr5g | nodemailer | 8.0.5 |
| Low | GHSA-j5w8-q4qc-rx2x | golang.org/ | 0.45.0 |
| Low | GHSA-v6v8-xj6m-xwqh | github.com/ | 0.7.7 |
| Low | GHSA-qpw4-5x99-6vjp | golang.org/ | 0.52.0 |
| Low | GHSA-f6x5-jh6r-wrfv | golang.org/ | 0.45.0 |
| Low | GHSA-gvwx-54wh-qm9j | tar | 7.5.17 |
| Low | GHSA-78mq-xcr3-xm33 | golang.org/ | 0.52.0 |
| Low | GHSA-9m57-25v3-79x9 | golang.org/ | 0.52.0 |
| Low | GHSA-3jxr-9vmj-r5cp | brace-expansion | 5.0.7 |
| Low | GHSA-p88m-4jfj-68fv | undici | 6.27.0 |
| Low | GHSA-vmf3-w455-68vh | tar | 7.5.16 |
| Low | GHSA-5v7r-6r5c-r473 | file-type | 21.3.1 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GHSA-2x7j-588g-ccc2 | nodemailer | 9.1.0 |
| Low | GO-2025-4116 | golang.org/ | 0.43.0 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| bluesky-pdsijmacd | 1.0.0 | 0.4 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.