StackRadar

ghcr.io/data-fair/simple-directory:4 container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/data-fair/simple-directory

ghcr.io/data-fair/simple-directory:4 resolved to 38a4f32fad82, scanned 14 Sept 2026: 231 findings, 0 critical; deployed by 1 chart, among them data-fair.

Radar Score

3,56801172148

231 findings on digest 38a4f32fad82 · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
4resolves to38a4f32fad821 chart8 days ago011721483,568

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Medium findings

72 distinct on this digest

Medium: findings whose contribution to the Radar Score is 15–39. Show every band

Findings for digest 38a4f32fad82 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
MediumGHSA-2p57-rm9w-gvfpip@1.1.5no fix listed
MediumGHSA-xvch-5gv4-984hminimist@1.2.51.2.6
MediumGHSA-9c47-m6qq-7p4hjson5@2.2.02.2.2
MediumALPINE-CVE-2022-4304openssl@1.1.1n-r01.1.1t-r0
MediumALPINE-CVE-2022-40304libxml2@2.9.13-r02.9.14-r2
MediumGHSA-76p3-8jx3-jpfqloader-utils@2.0.22.0.3
MediumALPINE-CVE-2022-27404freetype@2.10.4-r12.10.4-r2
MediumALPINE-CVE-2022-28391busybox@1.33.1-r61.33.1-r7
MediumGHSA-8hfj-j24r-96c4moment@2.29.12.29.2
MediumGHSA-wc69-rhjr-hc9gmoment@2.29.12.29.4
MediumGHSA-48ww-j4fc-435pnodemailer@5.0.06.4.16
MediumALPINE-CVE-2023-0215openssl@1.1.1n-r01.1.1t-r0
MediumGHSA-hj9c-8jmm-8c52npm@8.1.28.11.0
MediumGHSA-7f3x-x4pr-wqhjparse-url@6.0.06.0.1
MediumALPINE-CVE-2023-0464openssl@1.1.1n-r01.1.1t-r1
MediumGHSA-93q8-gq69-wqmwansi-regex@5.0.05.0.1
MediumGHSA-fjxv-7rqg-78g4form-data@4.0.04.0.4
MediumGHSA-wm7h-9275-46v2dicer@0.2.5no fix listed
MediumALPINE-CVE-2022-27406freetype@2.10.4-r12.10.4-r3
MediumGHSA-j4f2-536g-r55mengine.io@3.3.23.6.0
MediumGHSA-4wf5-vphf-c2xcterser@4.8.04.8.1
MediumALPINE-CVE-2022-27405freetype@2.10.4-r12.10.4-r3
MediumALPINE-CVE-2022-40674expat@2.4.7-r02.4.9-r0
MediumGHSA-c2qf-rxjj-qqgwsemver@7.3.57.5.2
MediumGHSA-43fc-jf86-j433axios@0.21.40.30.3
MediumGHSA-qm95-pgcg-qqfqsocket.io-parser@3.3.23.3.3
MediumALPINE-CVE-2022-2309libxml2@2.9.13-r02.9.14-r1
MediumALPINE-CVE-2022-43680expat@2.4.7-r02.5.0-r0
MediumALPINE-CVE-2022-29824libxml2@2.9.13-r02.9.14-r0
MediumGHSA-hhq3-ff78-jv3gloader-utils@2.0.22.0.4
MediumGHSA-j9fq-vwqv-2fm2parse-url@6.0.08.1.0
MediumGHSA-3rfm-jhwj-7488loader-utils@2.0.22.0.4
MediumALPINE-CVE-2022-3970tiff@4.3.0-r04.4.0-r1
MediumGHSA-f8q6-p94x-37v3minimatch@3.0.43.0.5
MediumGHSA-fhg7-m89q-25r3ua-parser-js@0.7.310.7.33
MediumALPINE-CVE-2022-2097openssl@1.1.1n-r01.1.1q-r0
MediumGHSA-rc47-6667-2j5jhttp-cache-semantics@4.1.04.1.1
MediumGHSA-grv7-fg5c-xmjgbraces@2.3.23.0.3
MediumGHSA-3h5v-q93c-6h6qws@6.1.46.2.3
MediumGHSA-pjwm-pj3p-43mvaxios@0.21.40.32.0
MediumGHSA-r7qp-cfhv-p84wengine.io@3.3.23.6.1
MediumGHSA-jr5f-v2jv-69x6axios@0.21.40.30.0
MediumGHSA-95m3-7q98-8xr5sha.js@2.4.112.4.12
MediumGHSA-4p35-cfcx-8653parse-url@6.0.06.0.1
MediumGHSA-pfq8-rq6v-vf5mhtml-minifier@4.0.0no fix listed
MediumGHSA-5528-5vmv-3xc2multer@1.4.42.1.1
MediumGHSA-w7jw-789q-3m8pshell-quote@1.7.31.8.4
MediumGHSA-f23m-r3pf-42rhlodash@4.17.214.18.0
MediumGHSA-xxjr-mmjv-4gpglodash@4.17.214.17.23
MediumGHSA-v52c-386h-88mcmulter@1.4.42.1.0

Used by

1 chart
ChartVersionTagContainers
data-fairdata354-helmVerified publisher1.1.241

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.