StackRadar

ghcr.io/sigstore/scaffolding/createtree:v0.7.31 container image

GitHub Container Registry

Scanned 14 Sept 2026

Deployed by 3 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/sigstore/scaffolding/createtree

ghcr.io/sigstore/scaffolding/createtree:v0.7.31 resolved to e5232e8c9122, scanned 14 Sept 2026: 62 findings, 0 critical; deployed by 3 charts, among them fulcio, scaffold and ctlog.

Radar Score

44300161

62 findings on digest e5232e8c9122 · scanned 14 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Digests

1 digest
TagDigestUsed byLast seenVulnerabilitiesRadar Score
v0.7.31resolves toe5232e8c91223 charts8 days ago00161443

Digests this tag resolved to in indexed charts’ default renders. A tag can move; the digest is what was scanned.

Vulnerabilities

62 distinct on this digest

Findings for digest e5232e8c9122 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.

SeverityAdvisoryPackageFixed in
LowGO-2026-4865stdlib@go1.25.01.25.9
LowGO-2026-4869stdlib@go1.25.01.25.9
LowGO-2026-4340stdlib@go1.25.01.24.12
LowGO-2025-4175stdlib@go1.25.01.24.11
LowGO-2026-5025golang.org/x/net@v0.46.00.55.0
LowGO-2026-4970stdlib@go1.25.01.25.12
LowGO-2026-5027golang.org/x/net@v0.46.00.55.0
LowGO-2026-5029golang.org/x/net@v0.46.00.55.0
LowGO-2026-5030golang.org/x/net@v0.46.00.55.0
LowGO-2026-4602stdlib@go1.25.01.25.8
LowGO-2026-5024golang.org/x/sys@v0.37.00.44.0
LowGO-2026-6061google.golang.org/grpc@v1.76.01.82.1

Used by

3 charts
ChartVersionTagContainers
fulciosigstoreVerified publisher2.11.1v0.7.311
scaffoldsigstoreVerified publisher0.6.114v0.7.311
ctlogsigstoreVerified publisher0.2.68v0.7.311

Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.

syft 1.42.1 · scanned 14 Sept 2026 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.