ghcr.io/conductionnl/commonground-gateway-php:latest container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 5 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/conductionnl/commonground-gateway-php
ghcr.io/conductionnl/commonground-gateway-php:latest resolved to 947882bf2c37, scanned 14 Sept 2026: 140 findings, 2 critical, 1 on KEV; deployed by 5 charts, among them commonground-gateway, opencatalogi and commonground-gateway.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
Findings for digest 947882bf2c37 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2023-38545 | curl | 8.4.0-r0 |
| Critical | ALPINE-CVE-2023-44487KEV | nghttp2 | 1.47.0-r2 |
| High | GHSA-x8vp-gf4q-mw5j | symfony/ | 5.4.46 |
| High | ALPINE-CVE-2023-0286 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2023-2650 | openssl | 1.1.1u-r0 |
| High | ALPINE-CVE-2018-18312 | perl | 5.26.3-r0 |
| High | ALPINE-CVE-2018-18311 | perl | 5.26.3-r0 |
| High | ALPINE-CVE-2022-4450 | openssl | 1.1.1t-r0 |
| High | ALPINE-CVE-2022-43551 | curl | 7.83.1-r5 |
| Medium | GHSA-3cw5-7cxw-v5qg | dompdf/ | 2.0.2 |
| Medium | ALPINE-CVE-2022-4304 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2023-0215 | openssl | 1.1.1t-r0 |
| Medium | ALPINE-CVE-2023-0464 | openssl | 1.1.1t-r1 |
| Medium | ALPINE-CVE-2023-27534 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2023-27533 | curl | 8.0.1-r0 |
| Medium | GHSA-6hwr-6v2f-3m88 | phpoffice/ | 1.29.1 |
| Medium | ALPINE-CVE-2023-28319 | curl | 8.1.0-r0 |
| Medium | ALPINE-CVE-2023-3446 | openssl | 1.1.1u-r2 |
| Medium | ALPINE-CVE-2024-28757 | expat | 2.6.2-r0 |
| Medium | GHSA-h7vf-5wrv-9fhv | symfony/ | 5.4.20 |
| Medium | ALPINE-CVE-2023-5678 | openssl | 1.1.1w-r1 |
| Medium | ALPINE-CVE-2023-23914 | curl | 7.83.1-r6 |
| Medium | GHSA-q4q6-r8wh-5cgh | phpoffice/ | 1.30.3 |
| Medium | GHSA-7p85-w9px-jpjp | twig/ | 3.26.0 |
| Medium | ALPINE-CVE-2023-28320 | curl | 8.1.0-r0 |
| Medium | ALPINE-CVE-2023-35945 | nghttp2 | 1.47.0-r1 |
| Medium | GHSA-m7v2-7gxm-vc2v | symfony/ | 5.4.52 |
| Medium | GHSA-rx7m-68vc-ppxh | phpoffice/ | 1.30.0 |
| Medium | GHSA-6j75-5wfj-gh66 | twig/ | 3.11.1 |
| Medium | ALPINE-CVE-2022-43552 | curl | 7.83.1-r5 |
| Medium | GHSA-3rg7-wf37-54rm | symfony/ | 5.4.50 |
| Medium | ALPINE-CVE-2023-7104 | sqlite | 3.40.1-r1 |
| Medium | ALPINE-CVE-2023-23916 | curl | 7.83.1-r6 |
| Medium | ALPINE-CVE-2023-46218 | curl | 8.5.0-r0 |
| Medium | ALPINE-CVE-2023-29491 | ncurses | 6.3_p20220521-r1 |
| Medium | GHSA-ghg6-32f9-2jp7 | phpoffice/ | 1.29.1 |
| Medium | ALPINE-CVE-2023-27537 | curl | 8.0.1-r0 |
| Medium | ALPINE-CVE-2023-28321 | curl | 8.1.0-r0 |
| Medium | GHSA-87m4-826x-3crx | phpoffice/ | 1.30.5 |
| Low | GHSA-xx3c-qf5g-hc39 | symfony/ | 5.4.52 |
| Low | ALPINE-CVE-2023-27535 | curl | 8.0.1-r0 |
| Low | ALPINE-CVE-2023-27536 | curl | 8.0.1-r0 |
| Low | ALPINE-CVE-2023-38546 | curl | 8.4.0-r0 |
| Low | GHSA-jw4x-v69f-hh5w | phpoffice/ | 1.29.4 |
| Low | GHSA-7cc9-j4mv-vcjp | phpoffice/ | 1.29.4 |
| Low | GHSA-f3qr-qr4x-j273 | phenx/ | 0.5.2 |
| Low | GHSA-5gpr-w2p5-6m37 | phpoffice/ | 1.29.2 |
| Low | GHSA-vr2x-7687-h6qv | api-platform/ | 2.7.10 |
| Low | GHSA-cg23-qf8f-62rr | symfony/ | 5.4.47 |
| Low | GHSA-428q-q3vv-3fq3 | api-platform/ | 3.4.17 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| commonground-gatewaycommonground-gateway | 1.5.4 | latest | 6 |
| opencatalogiopencatalogi | 1.0.6 | latest | 6 |
| commonground-gatewaycommonground-gateway-frontend | 0.1.5 | latest | 1 |
| commonground-gatewayopencatalogi | 1.5.3 | latest | 6 |
| commonground-gatewayskeleton-pip | 0.1.7 | latest | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.