ghcr.io/umami-software/umami:3.1.0 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/umami-software/umami
ghcr.io/umami-software/umami:3.1.0 resolved to e3f80c0625aa, scanned 14 Sept 2026: 179 findings, 0 critical; deployed by 1 chart, among them umami.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
146 distinct on this digest
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest e3f80c0625aa as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | ALPINE-CVE-2026-8926 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-27135 | nghttp2 | 1.68.1 |
| Low | GHSA-mg66-mrh9-m8jx | next | 16.2.5 |
| Low | ALPINE-CVE-2026-3805 | curl | 8.19.0-r0 |
| Low | ALPINE-CVE-2026-14456 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-9076 | openssl | 3.5.7-r0 |
| Low | ALPINE-CVE-2026-82209 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-80255 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-11564 | curl | 8.22.0-r0 |
| Low | GHSA-rgw5-rvv9-x895 | brace-expansion | 2.1.4 |
| Low | GHSA-36qx-fr4f-26g5 | next | 16.2.5 |
| Low | ALPINE-CVE-2026-13608 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-5773 | curl | 8.20.0-r0 |
| Low | ALPINE-CVE-2026-63072 | openssl | 3.5.8-r0 |
| Low | GHSA-ggr8-5vv4-36mx | deepmerge-ts | 8.0.0 |
| Low | ALPINE-CVE-2026-11586 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-45445 | openssl | 3.5.7-r0 |
| Low | GHSA-26hh-7cqf-hhc6 | next | 16.2.6 |
| Low | ALPINE-CVE-2026-80230 | curl | 8.22.0-r0 |
| Low | GHSA-23hp-3jrh-7fpw | tar | 7.5.19 |
| Low | GHSA-qrv3-253h-g69c | pnpm | 10.34.4 |
| Low | ALPINE-CVE-2026-54874 | openssl | 3.5.8-r0 |
| Low | ALPINE-CVE-2026-42766 | openssl | 3.5.7-r0 |
| Low | GHSA-q5qw-h33p-qvwr | hono | 4.12.4 |
| Low | ALPINE-CVE-2026-63075 | openssl | 3.5.8-r0 |
| Low | GHSA-w466-c33r-3gjp | pnpm | 10.34.2 |
| Low | GHSA-mh99-v99m-4gvg | brace-expansion | 2.1.3 |
| Low | ALPINE-CVE-2026-33630 | c-ares | 1.34.8-r0 |
| Low | GHSA-8x88-c5mf-7j5w | tar | 7.5.18 |
| Low | ALPINE-CVE-2026-82208 | curl | 8.22.0-r0 |
| Low | GHSA-vq4v-j7r6-jq4m | pnpm | 10.34.5 |
| Low | GHSA-c2c7-rcm5-vvqj | picomatch | 4.0.4 |
| Low | GHSA-q8wf-6r8g-63ch | next | 16.2.11 |
| Low | ALPINE-CVE-2026-12064 | curl | 8.22.0-r0 |
| Low | GHSA-mwp4-54f8-5fhr | ip-address | 10.3.1 |
| Low | ALPINE-CVE-2026-8932 | curl | 8.22.0-r0 |
| Low | GHSA-rxhj-4m44-96r4 | pnpm | 10.34.0 |
| Low | ALPINE-CVE-2026-8286 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-75803 | openssl | 3.5.8-r0 |
| Low | GHSA-r292-9mhp-454m | tar | 7.5.21 |
| Low | GHSA-395f-4hp3-45gv | shell-quote | 1.9.0 |
| Low | GHSA-h64f-5h5j-jqjh | next | 16.2.5 |
| Low | ALPINE-CVE-2026-8458 | curl | 8.22.0-r0 |
| Low | ALPINE-CVE-2026-6253 | curl | 8.20.0-r0 |
| Low | GHSA-w4pp-8pjf-rmxw | pacote | 21.5.1 |
| Low | GHSA-cjhr-43r9-cfmw | pnpm | 10.34.0 |
| Low | GHSA-72r4-9c5j-mj57 | pnpm | 10.34.4 |
| Low | GHSA-fr4h-3cph-29xv | pnpm | 10.34.4 |
| Low | GHSA-c59q-g84q-2gj5 | pnpm | 10.34.5 |
| Low | GHSA-wc8c-qw6v-h7f6 | @hono/ | 1.19.10 |