ghcr.io/formancehq/portal:v1.16.0 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/formancehq/portal
ghcr.io/formancehq/portal:v1.16.0 resolved to 6efef5d19d56, scanned 14 Sept 2026: 349 findings, 0 critical; deployed by 1 chart, among them cloudprem.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 6efef5d19d56 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | ALPINE-CVE-2026-45447 | openssl | 3.5.7-r0 |
| Medium | GHSA-p9ff-h696-f583 | vite | 6.4.2 |
| Medium | GHSA-2w6w-674q-4c4q | handlebars | 4.7.9 |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | GHSA-mw96-cpmx-2vgc | rollup | 4.59.0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 1.13.5 |
| Medium | ALPINE-CVE-2025-11187 | openssl | 3.5.5-r0 |
| Medium | ALPINE-CVE-2026-63073 | openssl | 3.5.8-r0 |
| Medium | GHSA-xq3m-2v4x-88gg | protobufjs | 7.5.5 |
| Medium | GHSA-379q-355j-w6rj | pnpm | 10.26.0 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.5.4-r0 |
| Medium | GHSA-rf6f-7fwh-wjgh | flatted | 3.4.2 |
| Medium | ALPINE-CVE-2026-18798 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.5.4-r0 |
| Medium | ALPINE-CVE-2026-63076 | openssl | 3.5.8-r0 |
| Medium | GHSA-5rq4-664w-9x2c | basic-ftp | 5.2.0 |
| Medium | ALPINE-CVE-2026-42764 | openssl | 3.5.7-r0 |
| Medium | GHSA-vrm6-8vpv-qv8q | undici | 6.24.0 |
| Medium | ALPINE-CVE-2026-34182 | openssl | 3.5.7-r0 |
| Medium | GHSA-2w69-qvjg-hvjx | @remix-run/ | 1.23.2 |
| Medium | GHSA-2w69-qvjg-hvjx | react-router | 7.12.0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-f23m-r3pf-42rh | lodash-es | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash-es | 4.17.23 |
| Medium | GHSA-2phv-j68v-wwqx | pnpm | 10.27.0 |
| Medium | ALPINE-CVE-2026-34183 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-6100 | python3 | 3.12.14-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-34180 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-7383 | openssl | 3.5.7-r0 |
| Medium | ALPINE-CVE-2026-14457 | openssl | 3.5.8-r0 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.5.4-r0 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | ALPINE-CVE-2026-66046 | expat | 2.8.4-r0 |
| Medium | GHSA-3mfm-83xf-c92r | handlebars | 4.7.9 |
| Medium | GHSA-xhpv-hc6g-r9c6 | handlebars | 4.7.9 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.5.6-r0 |
| Medium | GHSA-99f4-grh7-6pcq | @grpc/ | 1.13.5 |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 5.3.5 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.5.5-r0 |
| Medium | GHSA-v9p9-hfj2-hcw8 | undici | 6.24.0 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | GHSA-3qcw-2rhx-2726 | turbo | 2.9.14 |
| Medium | GHSA-hwx4-2j3j-g496 | pnpm | 10.34.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.5.6-r0 |
| Medium | ALPINE-CVE-2026-11940 | python3 | 3.12.14-r0 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 5.3.6 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| cloudpremcloudprem | 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad | v1.16.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.