ghcr.io/cosmo-workspace/dev-code-server:v0.0.3 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/cosmo-workspace/dev-code-server
ghcr.io/cosmo-workspace/dev-code-server:v0.0.3 resolved to 16fda01ae58a, scanned 14 Sept 2026: 1,307 findings, 2 critical, 1 on KEV; deployed by 1 chart, among them dev-code-server.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 16fda01ae58a as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | DEBIAN-CVE-2020-15778 | openssh | no fix listed |
| Medium | DEBIAN-CVE-2025-8677 | bind9 | 1:9.18.41-1~deb12u1 |
| Medium | GHSA-765h-qjxv-5f44 | handlebars | 4.7.7 |
| Medium | GHSA-f5f7-6478-qm6p | k8s.io/ | 1.19.15 |
| Medium | DEBIAN-CVE-2025-13878 | bind9 | 1:9.18.44-1~deb12u1 |
| Medium | DEBIAN-CVE-2018-6951 | patch | no fix listed |
| Medium | DEBIAN-CVE-2018-6952 | patch | no fix listed |
| Medium | DSA-6113-1 | openssl | 3.0.18-1~deb12u2 |
| Medium | DEBIAN-CVE-2019-1010022 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2023-45853 | zlib | no fix listed |
| Medium | DEBIAN-CVE-2025-55298 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u4 |
| Medium | DEBIAN-CVE-2017-17740 | openldap | no fix listed |
| Medium | DEBIAN-CVE-2025-32462 | sudo | 1.9.13p3-1+deb12u2 |
| Medium | GHSA-m5h6-hr3q-22h5 | npm | 2.15.1 |
| Medium | GHSA-wqv3-8cm6-h6wg | k8s.io/ | 1.16.11 |
| Medium | GHSA-hq6q-c2x6-hmch | k8s.io/ | 1.25.16 |
| Medium | DEBIAN-CVE-2026-45447 | openssl | 3.0.20-1~deb12u2 |
| Medium | DEBIAN-CVE-2018-20796 | glibc | no fix listed |
| Medium | DEBIAN-CVE-2017-16232 | tiff | no fix listed |
| Medium | DEBIAN-CVE-2015-3276 | openldap | no fix listed |
| Medium | GHSA-34jx-wx69-9x8v | k8s.io/ | 1.11.9 |
| Medium | GHSA-q78c-gwqw-jcmc | k8s.io/ | 1.24.17 |
| Medium | DEBIAN-CVE-2019-1010023 | glibc | no fix listed |
| Medium | GHSA-33c5-9fx5-fvjm | k8s.io/ | 1.16.13 |
| Medium | DEBIAN-CVE-2019-16227 | lmdb | no fix listed |
| Medium | DEBIAN-CVE-2018-16376 | openjpeg2 | no fix listed |
| Medium | DEBIAN-CVE-2019-16224 | lmdb | no fix listed |
| Medium | DEBIAN-CVE-2019-16225 | lmdb | no fix listed |
| Medium | DEBIAN-CVE-2009-3546 | libwmf | no fix listed |
| Medium | GHSA-3cqr-58rm-57f8 | handlebars | 3.0.8 |
| Medium | GHSA-27wf-5967-98gx | k8s.io/ | 1.28.12 |
| Medium | GHSA-x8qc-rrcw-4r46 | npm | 6.13.3 |
| Medium | GHSA-m6cx-g6qm-p2cx | npm | 6.13.3 |
| Medium | GHSA-g42g-737j-qx6j | k8s.io/ | 1.18.18 |
| Medium | DEBIAN-CVE-2026-49261 | mariadb | 1:10.11.18-0+deb12u1 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 4.0.4 |
| Medium | DEBIAN-CVE-2018-15607 | imagemagick | no fix listed |
| Medium | GHSA-qqgx-2p2h-9c37 | ini | 1.3.6 |
| Medium | DEBIAN-CVE-2016-9580 | openjpeg2 | no fix listed |
| Medium | GHSA-p493-635q-r6gr | pug | 3.0.1 |
| Medium | DEBIAN-CVE-2016-9581 | openjpeg2 | no fix listed |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | DEBIAN-CVE-2016-9114 | openjpeg2 | no fix listed |
| Medium | DEBIAN-CVE-2017-11164 | pcre3 | no fix listed |
| Medium | DEBIAN-CVE-2016-9113 | openjpeg2 | no fix listed |
| Medium | DEBIAN-CVE-2017-7246 | pcre3 | no fix listed |
| Medium | DEBIAN-CVE-2019-20838 | pcre3 | no fix listed |
| Medium | GHSA-3c6g-pvg8-gqw2 | json | 10.0.0 |
| Medium | GHSA-j9wf-vvm6-4r9w | k8s.io/ | no fix listed |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| dev-code-servercosmoVerified publisher | 0.0.7 | v0.0.3 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.