ghcr.io/cosmo-workspace/dev-code-server:v0.0.3 container image
GitHub Container RegistryScanned 15 Sept 2026
Deployed by 1 of 17,787 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/cosmo-workspace/dev-code-server
ghcr.io/cosmo-workspace/dev-code-server:v0.0.3 resolved to 16fda01ae58a, scanned 15 Sept 2026: 1,310 findings, 1 critical, 1 on KEV; deployed by 1 chart, among them dev-code-server.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
1,310 distinct on this digest
Findings for digest 16fda01ae58a as scanned on 15 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 15 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-fr4h-3cph-29xv | pnpm | 10.34.4 |
| Low | DEBIAN-CVE-2026-63387 | libevent | no fix listed |
| Low | GHSA-c59q-g84q-2gj5 | pnpm | 10.34.5 |
| Low | DEBIAN-CVE-2026-13321 | bind9 | 1:9.18.49-1~deb12u2 |
| Low | DEBIAN-CVE-2026-45382 | libde265 | no fix listed |
| Low | DEBIAN-CVE-2026-18220 | binutils | no fix listed |
| Low | GHSA-rp42-5vxx-qpwr | basic-ftp | 5.3.0 |
| Low | DEBIAN-CVE-2026-45383 | libde265 | no fix listed |
| Low | GHSA-9ppj-qmqm-q256 | tar | 7.5.11 |
| Low | DEBIAN-CVE-2026-26066 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u7 |
| Low | DEBIAN-CVE-2026-26283 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u7 |
| Low | DEBIAN-CVE-2026-4437 | glibc | 2.36-9+deb12u14 |
| Low | DEBIAN-CVE-2026-44656 | vim | no fix listed |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | DEBIAN-CVE-2026-86420 | imagemagick | no fix listed |
| Low | GHSA-2mjp-6q6p-2qxm | undici | 6.24.0 |
| Low | DEBIAN-CVE-2018-1000021 | git | no fix listed |
| Low | GHSA-m733-5w8f-5ggw | pnpm | 10.28.2 |
| Low | DEBIAN-CVE-2025-66866 | binutils | no fix listed |
| Low | DEBIAN-CVE-2025-5244 | binutils | no fix listed |
| Low | DEBIAN-CVE-2025-5245 | binutils | no fix listed |
| Low | DEBIAN-CVE-2026-9547 | curl | no fix listed |
| Low | GHSA-968p-4wvh-cqc8 | @babel/ | 7.26.10 |
| Low | DEBIAN-CVE-2026-17084 | python3.11 | no fix listed |
| Low | DEBIAN-CVE-2025-8177 | tiff | no fix listed |
| Low | DEBIAN-CVE-2026-63379 | libevent | no fix listed |
| Low | DEBIAN-CVE-2021-45346 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2025-8941 | pam | no fix listed |
| Low | DSA-6015-1 | openssl | 3.0.17-1~deb12u3 |
| Low | GHSA-xpqm-wm3m-f34h | pnpm | 10.28.1 |
| Low | DEBIAN-CVE-2025-7545 | binutils | no fix listed |
| Low | DEBIAN-CVE-2025-70873 | sqlite3 | no fix listed |
| Low | DEBIAN-CVE-2025-66293 | libpng1.6 | 1.6.39-2+deb12u1 |
| Low | DEBIAN-CVE-2026-42012 | gnutls28 | 3.7.9-2+deb12u7 |
| Low | DEBIAN-CVE-2022-49043 | libxml2 | 2.9.14+dfsg-1.3~deb12u2 |
| Low | DEBIAN-CVE-2026-56209 | aom | 3.6.0-1+deb12u3 |
| Low | DEBIAN-CVE-2026-57432 | perl | no fix listed |
| Low | GO-2024-2887 | stdlib | 1.21.11 |
| Low | DEBIAN-CVE-2026-26269 | vim | no fix listed |
| Low | DEBIAN-CVE-2026-6276 | curl | no fix listed |
| Low | DEBIAN-CVE-2024-38950 | libde265 | no fix listed |
| Low | GHSA-6x96-7vc8-cm3p | pnpm | 10.28.1 |
| Low | GHSA-4gxm-v5v7-fqc4 | pnpm | 10.34.2 |
| Low | DEBIAN-CVE-2026-56378 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u12 |
| Low | DEBIAN-CVE-2026-32741 | libheif | no fix listed |
| Low | DEBIAN-CVE-2026-3276 | python3.11 | no fix listed |
| Low | DEBIAN-CVE-2024-26458 | krb5 | no fix listed |
| Low | DEBIAN-CVE-2024-38949 | libde265 | no fix listed |
| Low | DEBIAN-CVE-2025-11083 | binutils | no fix listed |
| Low | DEBIAN-CVE-2026-49295 | libde265 | no fix listed |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| dev-code-servercosmoVerified publisher | 0.0.7 | v0.0.3 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.