ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/ncsa/jupyterhub-metrics/collector
ghcr.io/ncsa/jupyterhub-metrics/collector:1.3.0 resolved to dcb8c731bb1b, scanned 14 Sept 2026: 136 findings, 0 critical; deployed by 1 chart, among them jupyterhub-metrics.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest dcb8c731bb1b as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-mh2q-q3fh-2475 | go.opentelemetry.io/ | 1.41.0 |
| Low | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Low | ALPINE-CVE-2026-14662 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-6477 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-14664 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14670 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-15742 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14676 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-19385 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14671 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14677 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14680 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-16238 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-32316 | jq | 1.8.2-r0 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-45445 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-6637 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-18408 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-15741 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-31789 | openssl | 3.5.6-r0 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-6475 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-42766 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-22184 | zlib | 1.3.2-r0 |
| Low | ALPINE-CVE-2026-6479 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-33630 | c-ares | 1.34.8-r0 |
| Low | ALPINE-CVE-2026-6464 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-14668 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-14679 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-40164 | jq | 1.8.2-r0 |
| Low | ALPINE-CVE-2026-39979 | jq | 1.8.2-r0 |
| Low | ALPINE-CVE-2026-6478 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-6638 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-2673 | openssl | 3.5.6-r0 |
| Low | ALPINE-CVE-2026-42767 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-5545 | curl | 8.14.1-r3 |
| Low | ALPINE-CVE-2026-6476 | postgresql17 | 17.10-r0 |
| Low | ALPINE-CVE-2026-6471 | postgresql17 | 17.11-r0 |
| Low | ALPINE-CVE-2026-63074 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-34181 | openssl | 3.5.7-r0 |
| Low | GHSA-5cv4-jp36-h3mw | golang.org/ | 0.55.0 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.5-r12 |
| Low | ALPINE-CVE-2026-42769 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-49839 | jq | 1.8.2-r0 |
| Low | GO-2026-4981 | stdlib | 1.25.10 |
| Low | GO-2026-4977 | stdlib | 1.25.10 |
Used by
| Chart | Version | Tag | Containers |
|---|---|---|---|
| jupyterhub-metricsncsaVerified publisher | 1.3.0 | 1.3.0 | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.