StackRadar

ghcr.io/comet-ml/opik/opik-python-backend:2.2.55 container image

GitHub Container Registry

Scanned 9 Sept 2026

Deployed by 0 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/comet-ml/opik/opik-python-backend

ghcr.io/comet-ml/opik/opik-python-backend:2.2.55 resolved to fe86d8605376, scanned 9 Sept 2026: 169 findings, 0 critical; deployed by 0 charts.

Radar Score

1,6570022147

169 findings on digest fe86d8605376 · scanned 9 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.2.55resolves tofe86d86053765 days ago00221471,657

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

169 distinct on this digest

Findings for digest fe86d8605376 as scanned on 9 Sept 2026 for linux/amd64, advisories as of 9 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-75803openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-8458curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-6253curl@8.19.0-r08.20.0-r0
LowGHSA-29vq-49wr-vm6xwerkzeug@3.1.33.1.6
LowGHSA-47q9-m4ww-924mgithub.com/sigstore/rekor@v1.5.01.5.2
LowALPINE-CVE-2026-9547curl@8.19.0-r08.22.0-r0
LowGHSA-hgf8-39gv-g3f2werkzeug@3.1.33.1.4
LowALPINE-CVE-2026-6276curl@8.19.0-r08.20.0-r0
LowGHSA-pxq6-2prw-chj9github.com/docker/docker@v28.5.2+incompatibleno fix listed
LowGHSA-hfg8-hc9c-6c3hgithub.com/moby/go-archive@v0.2.00.3.0
LowALPINE-CVE-2026-9080curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-42767openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-5545curl@8.19.0-r08.20.0-r0
LowALPINE-CVE-2026-9545curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-76642util-linux@2.41.4-r02.41.6-r0
LowGHSA-xhf5-7wjv-pqxpgithub.com/containerd/containerd/v2@v2.2.32.2.5
LowGHSA-hfvc-g4fc-pqhxgo.opentelemetry.io/otel/sdk@v1.38.01.43.0
LowALPINE-CVE-2026-63074openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-34181openssl@3.5.6-r03.5.7-r0
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.45.00.52.0
LowGHSA-9c54-x2g4-v92jgithub.com/sigstore/timestamp-authority/v2@v2.0.62.1.0
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.35.00.55.0
LowGHSA-jpcc-p29g-p8mqgithub.com/containerd/containerd/v2@v2.2.32.2.5
LowGHSA-fqw6-gf59-qr4wgithub.com/containerd/containerd/v2@v2.2.32.2.4
LowALPINE-CVE-2026-6429curl@8.19.0-r08.20.0-r0
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.45.00.52.0
LowGHSA-vvgc-356p-c3xwgolang.org/x/net@v0.35.00.38.0
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.45.00.52.0
LowGHSA-87hc-h4r5-73f7werkzeug@3.1.33.1.5
LowALPINE-CVE-2026-7168curl@8.19.0-r08.20.0-r0
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.80.01.82.1
LowALPINE-CVE-2026-4873curl@8.19.0-r08.20.0-r0
LowGHSA-rgh6-rfwx-v388github.com/containerd/containerd/v2@v2.2.32.2.5
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.45.00.52.0
LowGHSA-65pc-fj4g-8rjxidna@3.113.15
LowGHSA-x86f-5xw2-fm2rgithub.com/docker/docker@v28.5.2+incompatibleno fix listed
LowALPINE-CVE-2026-42769openssl@3.5.6-r03.5.7-r0
LowGHSA-9h8m-3fm2-qjrqgo.opentelemetry.io/otel/sdk@v1.38.01.40.0
LowALPINE-CVE-2026-78408util-linux@2.41.4-r02.41.6-r1
LowGHSA-7236-3392-c5c6github.com/moby/buildkit@v0.30.00.31.1
LowGO-2026-4981stdlib@go1.25.81.25.10
LowGO-2026-4977stdlib@go1.25.81.25.10
LowGO-2026-4986stdlib@go1.25.81.25.10
LowGO-2026-4918golang.org/x/net@v0.35.00.53.0
LowGO-2026-4918stdlib@go1.25.81.25.10
LowGO-2026-5026golang.org/x/net@v0.35.00.55.0
LowGO-2026-5026stdlib@go1.26.31.25.13
LowGHSA-2v4p-qf9q-27wjgoogle.golang.org/grpc@v1.80.01.82.2
LowALPINE-CVE-2026-45446openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-7009curl@8.19.0-r08.20.0-r0

Used by

0 charts

No indexed chart deploys this repository in its latest version.

Also in older indexed versions (1)

Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the index.

ChartVersionTagContainers
opikopikOfficialVerified publisher2.2.552.2.552

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 9 Sept 2026 · advisories as of 9 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.