ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 2 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/grafana/helm-chart-toolbox-kubectl
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1 resolved to c137478627cc, scanned 14 Sept 2026: 188 findings, 0 critical; deployed by 2 charts, among them grafana-cloud-onboarding and pyroscope-monitoring.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
Findings for digest c137478627cc as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-45445 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2025-49795 | libxml2 | 2.13.9-r0 |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.5.6-r0 |
| Low | ALPINE-CVE-2025-69419 | openssl | 3.5.5-r0 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-42766 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-22184 | zlib | 1.3.2-r0 |
| Low | ALPINE-CVE-2026-33630 | c-ares | 1.34.8-r0 |
| Low | GHSA-35c7-w35f-xwgh | k8s.io/ | 1.21.0 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-4x4m-3c2p-qppc | k8s.io/ | 1.31.12 |
| Low | ALPINE-CVE-2025-15468 | openssl | 3.5.5-r0 |
| Low | ALPINE-CVE-2026-40164 | jq | 1.8.2-r0 |
| Low | ALPINE-CVE-2026-39979 | jq | 1.8.2-r0 |
| Low | GHSA-3wgm-2gw2-vh5m | k8s.io/ | no fix listed |
| Low | GHSA-74j8-88mm-7496 | k8s.io/ | no fix listed |
| Low | GO-2026-4341 | stdlib | 1.24.12 |
| Low | ALPINE-CVE-2026-2673 | openssl | 3.5.6-r0 |
| Low | ALPINE-CVE-2026-42767 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-5545 | curl | 8.14.1-r3 |
| Low | ALPINE-CVE-2025-49014 | jq | 1.8.1-r0 |
| Low | ALPINE-CVE-2026-63074 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-34181 | openssl | 3.5.7-r0 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | GHSA-jgfp-53c3-624w | k8s.io/ | 1.29.14 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r12 |
| Low | ALPINE-CVE-2025-62408 | c-ares | 1.34.6-r0 |
| Low | ALPINE-CVE-2025-66199 | openssl | 3.5.5-r0 |
| Low | GHSA-vvgc-356p-c3xw | golang.org/ | 0.38.0 |
| Low | ALPINE-CVE-2026-22796 | openssl | 3.5.5-r0 |
| Low | GHSA-r6j8-c6r2-37rr | k8s.io/ | 1.32.10 |
| Low | ALPINE-CVE-2025-10148 | curl | 8.14.1-r2 |
| Low | GHSA-82m2-cv7p-4m75 | k8s.io/ | 1.27.16 |
| Low | ALPINE-CVE-2026-34743 | xz | 5.8.3-r0 |
| Low | ALPINE-CVE-2026-42769 | openssl | 3.5.7-r0 |
| Low | GHSA-vw47-mr44-3jf9 | k8s.io/ | no fix listed |
| Low | GO-2024-3333 | golang.org/ | 0.33.0 |
| Low | GHSA-8cfg-vx93-jvxw | k8s.io/ | 1.20.0-alpha.2 |
| Low | ALPINE-CVE-2026-49839 | jq | 1.8.2-r0 |
| Low | GO-2026-4981 | stdlib | 1.25.10 |
| Low | GO-2025-3563 | stdlib | 1.23.8 |
| Low | GO-2026-4977 | stdlib | 1.25.10 |
| Low | GO-2026-4986 | stdlib | 1.25.10 |
| Low | GO-2026-4918 | golang.org/ | 0.53.0 |
| Low | GO-2026-4918 | stdlib | 1.25.10 |
| Low | GO-2026-4337 | stdlib | 1.24.13 |
| Low | GHSA-8mjg-8c8g-6h85 | k8s.io/ | 1.20.0-alpha.1 |
| Low | GO-2026-4601 | stdlib | 1.25.8 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| grafana-cloud-onboardinggrafana | 0.4.7 | 0.1.1 | 2 |
| pyroscope-monitoringgrafana | 0.1.1 | 0.1.1 | 2 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.