StackRadar

ghcr.io/comet-ml/opik/opik-python-backend:2.2.58 container image

GitHub Container Registry

Scanned 11 Sept 2026

Deployed by 0 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/comet-ml/opik/opik-python-backend

ghcr.io/comet-ml/opik/opik-python-backend:2.2.58 resolved to aef4560fd8d6, scanned 11 Sept 2026: 170 findings, 0 critical; deployed by 0 charts.

Radar Score

1,7000022148

170 findings on digest aef4560fd8d6 · scanned 11 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
2.2.58resolves toaef4560fd8d63 days ago00221481,700

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

170 distinct on this digest

Findings for digest aef4560fd8d6 as scanned on 11 Sept 2026 for linux/amd64, advisories as of 11 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowALPINE-CVE-2026-75803openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-8458curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-6253curl@8.19.0-r08.20.0-r0
LowGHSA-29vq-49wr-vm6xwerkzeug@3.1.33.1.6
LowGHSA-47q9-m4ww-924mgithub.com/sigstore/rekor@v1.5.01.5.2
LowALPINE-CVE-2026-9547curl@8.19.0-r08.22.0-r0
LowGHSA-hgf8-39gv-g3f2werkzeug@3.1.33.1.4
LowALPINE-CVE-2026-6276curl@8.19.0-r08.20.0-r0
LowGHSA-pxq6-2prw-chj9github.com/docker/docker@v28.5.2+incompatibleno fix listed
LowGHSA-hfg8-hc9c-6c3hgithub.com/moby/go-archive@v0.2.00.3.0
LowALPINE-CVE-2026-9080curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-42767openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-5545curl@8.19.0-r08.20.0-r0
LowALPINE-CVE-2026-9545curl@8.19.0-r08.22.0-r0
LowALPINE-CVE-2026-76642util-linux@2.41.4-r02.41.6-r0
LowGHSA-xhf5-7wjv-pqxpgithub.com/containerd/containerd/v2@v2.2.32.2.5
LowGHSA-hfvc-g4fc-pqhxgo.opentelemetry.io/otel/sdk@v1.38.01.43.0
LowALPINE-CVE-2026-63074openssl@3.5.6-r03.5.8-r0
LowALPINE-CVE-2026-34181openssl@3.5.6-r03.5.7-r0
LowALPINE-CVE-2026-19931curl@8.19.0-r08.22.0-r0
LowGHSA-45gg-vh54-h5m9golang.org/x/crypto@v0.51.00.52.0
LowGHSA-9c54-x2g4-v92jgithub.com/sigstore/timestamp-authority/v2@v2.0.62.1.0
LowGHSA-5cv4-jp36-h3mwgolang.org/x/net@v0.54.00.55.0
LowGHSA-jpcc-p29g-p8mqgithub.com/containerd/containerd/v2@v2.2.32.2.5
LowGHSA-fqw6-gf59-qr4wgithub.com/containerd/containerd/v2@v2.2.32.2.4
LowALPINE-CVE-2026-6429curl@8.19.0-r08.20.0-r0
LowGHSA-qpw4-5x99-6vjpgolang.org/x/crypto@v0.51.00.52.0
LowGHSA-vvgc-356p-c3xwgolang.org/x/net@v0.35.00.38.0
LowALPINE-CVE-2026-18924curl@8.19.0-r08.22.0-r0
LowGHSA-78mq-xcr3-xm33golang.org/x/crypto@v0.51.00.52.0
LowGHSA-87hc-h4r5-73f7werkzeug@3.1.33.1.5
LowALPINE-CVE-2026-7168curl@8.19.0-r08.20.0-r0
LowGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc@v1.80.01.82.1
LowALPINE-CVE-2026-4873curl@8.19.0-r08.20.0-r0
LowGHSA-rgh6-rfwx-v388github.com/containerd/containerd/v2@v2.2.32.2.5
LowGHSA-9m57-25v3-79x9golang.org/x/crypto@v0.51.00.52.0
LowGHSA-65pc-fj4g-8rjxidna@3.113.15
LowGHSA-x86f-5xw2-fm2rgithub.com/docker/docker@v28.5.2+incompatibleno fix listed
LowALPINE-CVE-2026-42769openssl@3.5.6-r03.5.7-r0
LowGHSA-9h8m-3fm2-qjrqgo.opentelemetry.io/otel/sdk@v1.38.01.40.0
LowALPINE-CVE-2026-78408util-linux@2.41.4-r02.41.6-r1
LowALPINE-CVE-2026-82209curl@8.19.0-r08.22.0-r0
LowGHSA-7236-3392-c5c6github.com/moby/buildkit@v0.30.00.31.1
LowGO-2026-4981stdlib@go1.25.81.25.10
LowGO-2026-4977stdlib@go1.25.81.25.10
LowGO-2026-4986stdlib@go1.25.81.25.10
LowGO-2026-4918golang.org/x/net@v0.47.00.53.0
LowGO-2026-4918stdlib@go1.25.81.25.10
LowGO-2026-5026golang.org/x/net@v0.54.00.55.0
LowGO-2026-5026stdlib@go1.26.31.25.13

Used by

0 charts

No indexed chart deploys this repository in its latest version.

Also in older indexed versions (1)

Not counted above: the chart’s latest version no longer references it, or the chart is no longer in the index.

ChartVersionTagContainers
opikopikOfficialVerified publisher2.2.582.2.582

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 11 Sept 2026 · advisories as of 11 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.