ghcr.io/bluesky-social/pds:0.4.208 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/bluesky-social/pds
ghcr.io/bluesky-social/pds:0.4.208 resolved to 637083d9369d, scanned 14 Sept 2026: 199 findings, 0 critical; deployed by 1 chart, among them bluesky-pds.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 637083d9369d as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-5cgq-3rg8-m6cv | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-2w6w-674q-4c4q | handlebars | 4.7.9 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-x527-x647-q7gg | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-vrm6-8vpv-qv8q | undici | 6.24.0 |
| Medium | GHSA-vgwf-h737-ff37 | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | GHSA-f5wc-c3c7-36mc | golang.org/ | 0.52.0 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | GHSA-rm3j-f69w-wqmq | golang.org/ | 0.52.0 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | GHSA-3mfm-83xf-c92r | handlebars | 4.7.9 |
| Medium | GHSA-xhpv-hc6g-r9c6 | handlebars | 4.7.9 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 5.3.5 |
| Medium | GHSA-v9p9-hfj2-hcw8 | undici | 6.24.0 |
| Medium | GHSA-3xgq-45jj-v275 | cross-spawn | 7.0.5 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 5.3.6 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.5.6-r0 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 1.15.1 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| bluesky-pdsbear | 0.4.208 | 0.4.208 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.