ghcr.io/tandoorrecipes/recipes:1.5.31 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/tandoorrecipes/recipes
ghcr.io/tandoorrecipes/recipes:1.5.31 resolved to 063eb446e298, scanned 14 Sept 2026: 176 findings, 2 critical; deployed by 1 chart, among them tandoor.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
176 distinct on this digest
Findings for digest 063eb446e298 as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-2vrm-gr82-f7m5 | aiohttp | 3.13.4 |
| Low | GHSA-p3fp-8748-vqfq | django | 4.2.20 |
| Low | GHSA-mq44-7p77-q5h7 | aiohttp | 3.14.2 |
| Low | GHSA-hg6j-4rv6-33pg | aiohttp | 3.14.0 |
| Low | ALPINE-CVE-2025-48386 | git | 2.43.7-r0 |
| Low | GHSA-g6cj-pr64-35w5 | cryptography | 50.0.0 |
| Low | GHSA-4xh5-x5gv-qwph | pip | 25.3 |
| Low | GHSA-mwh4-6h8g-pg8w | aiohttp | 3.13.4 |
| Low | GHSA-pwv6-vv43-88gr | pillow | 12.2.0 |
| Low | GHSA-h35f-9h28-mq5c | setuptools | 83.0.0 |
| Low | GHSA-mqqc-3gqh-h2x8 | aiohttp | 3.13.3 |
| Low | GHSA-fj7v-r99m-22gq | pillow | 12.3.0 |
| Low | ALPINE-CVE-2026-40200 | musl | 1.2.4_git20230717-r6 |
| Low | PYSEC-2026-3721 | pip | 26.2 |
| Low | GHSA-69f9-5gxw-wvc2 | aiohttp | 3.13.3 |
| Low | ALPINE-CVE-2025-4947 | curl | 8.14.0-r0 |
| Low | GHSA-cpwx-vrp4-4pq7 | jinja2 | 3.1.6 |
| Low | GHSA-9548-qrrj-x5pj | aiohttp | 3.12.14 |
| Low | GHSA-hpj7-wq8m-9hgp | aiohttp | 3.14.1 |
| Low | ALPINE-CVE-2025-10148 | curl | 8.14.1-r2 |
| Low | GHSA-8qcx-xf44-272x | django | 5.2.16 |
| Low | GHSA-rqw2-ghq9-44m7 | django | 4.2.27 |
| Low | GHSA-mf9w-mj56-hr94 | python-dotenv | 1.2.2 |
| Low | GHSA-c427-h43c-vf67 | aiohttp | 3.13.4 |
| Low | ALPINE-CVE-2025-12818 | postgresql16 | 16.11-r0 |
| Low | PYSEC-2026-2104 | aiohttp | 3.14.0 |
| Low | GHSA-pq67-6m6q-mj2v | urllib3 | 2.5.0 |
| Low | GHSA-65pc-fj4g-8rjx | idna | 3.15 |
| Low | GHSA-2m8g-3cmr-wg3w | djangorestframework | 3.17.2 |
| Low | GHSA-xvp8-3mhv-424c | lxml-html-clean | 0.4.4 |
| Low | PYSEC-2025-183 | pyjwt | no fix listed |
| Low | GHSA-w7vc-732c-9m39 | pyjwt | 2.13.0 |
| Low | GHSA-hw26-mmpg-fqfg | lxml-html-clean | 0.4.4 |
| Low | GHSA-966j-vmvw-g2g9 | aiohttp | 3.13.4 |
| Low | GHSA-qccp-gfcp-xxvc | urllib3 | 2.7.0 |
| Low | GHSA-crhf-3pfg-w68w | django | 5.2.16 |
| Low | GHSA-7xr5-9hcq-chf9 | django | 4.2.22 |
| Low | GHSA-fjrm-76x2-c4q4 | jwcrypto | 1.5.7 |
| Low | ALPINE-CVE-2024-13176 | openssl | 3.1.8-r0 |
| Low | GHSA-537c-gmf6-5ccf | cryptography | 48.0.1 |
| Low | PYSEC-2026-56 | django-allauth | 65.14.1 |
| Low | GHSA-27jp-wm6q-gp25 | sqlparse | 0.5.4 |
| Low | ALPINE-CVE-2025-5025 | curl | 8.14.0-r0 |
| Low | GHSA-3496-9g83-7v6x | sqlparse | 0.6.0 |
| Low | PYSEC-2026-2275 | requests | 2.33.0 |
| Low | GHSA-g47c-3xmw-q6m2 | djangorestframework | 3.17.2 |
| Low | GHSA-q95w-c7qg-hrff | django | 4.2.25 |
| Low | ALPINE-CVE-2025-0167 | curl | 8.12.0-r0 |
| Low | ALPINE-CVE-2026-6042 | musl | 1.2.4_git20230717-r6 |
| Low | GHSA-qhmc-3mvr-f2j4 | django-allauth | 65.13.0 |