{
  "apiVersion": "v1",
  "resource": "images",
  "total": 200,
  "data": [
    {
      "slug": "adminer",
      "name": "adminer",
      "category": "Apps & productivity",
      "summary": "vrana's single-file PHP database manager, a web UI for MySQL/MariaDB, PostgreSQL, and SQLite, served by a hardened PHP runtime. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.5.1, 5.4.4, 5.3.0",
      "versions": [
        {
          "version": "5.5.1",
          "size": "15.6 MB",
          "published": "2026-07-22T11:26:16Z",
          "digest": "sha256:c04641391a4020a55e83bfd44ee32ef68463ffc8905c33c3200b4ce4d0d8fdd3"
        },
        {
          "version": "5.4.4",
          "size": "15.6 MB",
          "published": "2026-07-22T11:26:11Z",
          "digest": "sha256:7d1f03de987addb467acad816b420a4f37f5fda2c29d09bb92f47a2e53880f5c"
        },
        {
          "version": "5.3.0",
          "size": "15.6 MB",
          "published": "2026-07-22T11:26:10Z",
          "digest": "sha256:68c345372078a7325e75d60ca5364f9c202683fa49eef93aebec2baf70ac26f5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.adminer.org",
      "source": "https://github.com/vrana/adminer",
      "image": "ghcr.io/quenchworks/images/adminer",
      "security": {
        "image": "ghcr.io/quenchworks/images/adminer",
        "version": "5.5.1",
        "tag": "ghcr.io/quenchworks/images/adminer:5.5.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.5.1",
            "tag": "ghcr.io/quenchworks/images/adminer:5.5.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.4.4",
            "tag": "ghcr.io/quenchworks/images/adminer:5.4.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.3.0",
            "tag": "ghcr.io/quenchworks/images/adminer:5.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "airflow",
      "name": "airflow",
      "category": "Workflow",
      "summary": "Apache Airflow, the programmatic workflow orchestration platform for authoring, scheduling, and monitoring DAGs. Built clean-room from source as a Python venv on Wolfi (python-3.12, official constraints), nonroot on a hardened read-only-rootfs base. Ships the 3.2 line (older lines carry unfixed CVEs in Airflow itself). Runs api-server + scheduler + dag-processor + triggerer (and Celery workers) from one image; needs PostgreSQL (and Redis for CeleryExecutor), provided by the chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.3.0, 3.2.2",
      "versions": [
        {
          "version": "3.3.0",
          "size": "113.6 MB",
          "published": "2026-07-28T06:16:52Z",
          "digest": "sha256:8142a61a094858e3c063c6c0d8c64f8fb60c41603b0684d568fe5104dc071aad"
        },
        {
          "version": "3.2.2",
          "size": "111.8 MB",
          "published": "2026-07-28T06:16:14Z",
          "digest": "sha256:4e6e24c4d061ac3b50be6c673221156b60b26dad14f6e7df5045986c9da2971b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://airflow.apache.org",
      "source": "https://github.com/apache/airflow",
      "image": "ghcr.io/quenchworks/images/airflow",
      "security": {
        "image": "ghcr.io/quenchworks/images/airflow",
        "version": "3.3.0",
        "tag": "ghcr.io/quenchworks/images/airflow:3.3.0",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "D",
        "score": 85,
        "cves": [
          {
            "id": "CVE-2026-69247",
            "severity": "HIGH",
            "pkg": "cryptography",
            "installed": "49.0.0",
            "fixed": "50.0.0",
            "title": "cryptography is a package designed to expose cryptographic primitives  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.3.0",
            "tag": "ghcr.io/quenchworks/images/airflow:3.3.0",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "D",
            "score": 85,
            "cves": [
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "49.0.0",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              }
            ]
          },
          {
            "version": "3.2.2",
            "tag": "ghcr.io/quenchworks/images/airflow:3.2.2",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "D",
            "score": 85,
            "cves": [
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "49.0.0",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "alertmanager",
      "name": "Alertmanager",
      "category": "Observability",
      "summary": "Companion to Prometheus that routes, groups, deduplicates, and silences alerts and dispatches them to email, Slack, PagerDuty, and more.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.33.1",
      "versions": [
        {
          "version": "0.33.1",
          "size": "24.2 MB",
          "published": "2026-07-22T08:26:58Z",
          "digest": "sha256:f9f5f7260be1d324024cf782f1f5e5cb465a942a70896e5b142197e1988df651"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/alertmanager",
      "source": "https://github.com/prometheus/alertmanager",
      "image": "ghcr.io/quenchworks/images/alertmanager",
      "security": {
        "image": "ghcr.io/quenchworks/images/alertmanager",
        "version": "0.33.1",
        "tag": "ghcr.io/quenchworks/images/alertmanager:0.33.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/alertmanager",
              "usr/bin/amtool"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.33.1",
            "tag": "ghcr.io/quenchworks/images/alertmanager:0.33.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/alertmanager",
                  "usr/bin/amtool"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ansible",
      "name": "ansible",
      "category": "CI/CD & registry",
      "summary": "Ansible — agentless IT automation and configuration management (the community `ansible` package plus ansible-core and curated collections) with ssh/git/rsync/sshpass tooling, ready to run playbooks. Built from source into a venv on a hardened nonroot Wolfi base. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0+",
      "licenseClean": "agpl",
      "version": "14.1.0, 14.2.0",
      "versions": [
        {
          "version": "14.1.0",
          "size": "126.6 MB",
          "published": "2026-07-26T12:19:26Z",
          "digest": "sha256:1c27197ae13e6c9f7391a263ebba7846646c70c9591dd8a5ad8107aeb4f4402c"
        },
        {
          "version": "14.2.0",
          "size": "127.0 MB",
          "published": "2026-07-26T12:19:09Z",
          "digest": "sha256:0a24f0269b8691d6679b4f976bdc376babebc160e1da02b2301603e797fda911"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.ansible.com",
      "source": "https://github.com/ansible/ansible",
      "image": "ghcr.io/quenchworks/images/ansible",
      "security": {
        "image": "ghcr.io/quenchworks/images/ansible",
        "version": "14.2.0",
        "tag": "ghcr.io/quenchworks/images/ansible:14.2.0",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 2,
        "fixable": 2,
        "grade": "D",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-69247",
            "severity": "HIGH",
            "pkg": "cryptography",
            "installed": "49.0.0",
            "fixed": "50.0.0",
            "title": "cryptography is a package designed to expose cryptographic primitives  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/ansible@sha256:0a24f0269b8691d6679b4f976bdc376babebc160e1da02b2301603e797fda911 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "14.2.0",
            "tag": "ghcr.io/quenchworks/images/ansible:14.2.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 2,
            "fixable": 2,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "49.0.0",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/ansible@sha256:0a24f0269b8691d6679b4f976bdc376babebc160e1da02b2301603e797fda911 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "14.1.0",
            "tag": "ghcr.io/quenchworks/images/ansible:14.1.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 2,
            "fixable": 2,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "49.0.0",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/ansible@sha256:1c27197ae13e6c9f7391a263ebba7846646c70c9591dd8a5ad8107aeb4f4402c (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "argo-workflows",
      "name": "argo-workflows",
      "category": "Workflow",
      "summary": "Kubernetes-native workflow engine for orchestrating parallel jobs as DAGs. Ships the workflow-controller and the argo CLI/API server with an embedded React UI, built from source on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.7.15",
      "versions": [
        {
          "version": "3.7.15",
          "size": "64.4 MB",
          "published": "2026-07-22T06:42:59Z",
          "digest": "sha256:d4f98e5766509fe5701ae37adb58b29664ead214cac2d6bbcc2363f7a6d2ebb8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://argoproj.github.io/workflows",
      "source": "https://github.com/argoproj/argo-workflows",
      "image": "ghcr.io/quenchworks/images/argo-workflows",
      "security": {
        "image": "ghcr.io/quenchworks/images/argo-workflows",
        "version": "3.7.15",
        "tag": "ghcr.io/quenchworks/images/argo-workflows:3.7.15",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 2,
        "total": 4,
        "fixable": 2,
        "grade": "D",
        "score": 72,
        "cves": [
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/argo"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/argo"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/argo",
              "usr/bin/workflow-controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.15",
            "tag": "ghcr.io/quenchworks/images/argo-workflows:3.7.15",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 2,
            "total": 4,
            "fixable": 2,
            "grade": "D",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/argo"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/argo"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/argo",
                  "usr/bin/workflow-controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "argocd",
      "name": "argocd",
      "category": "GitOps",
      "summary": "Argo CD, the CNCF declarative GitOps continuous-delivery controller for Kubernetes. One multi-call binary serves every component (server, repo-server, application-controller, applicationset-controller, commit-server, notifications, cmp-server), selected by argv[0] exactly as upstream does, so the chart picks a role with a single command. Built from source with upstream's own asset pipeline, so the server really serves its React web console instead of 404ing every UI route. Ships git, git-lfs, openssh-client and gnupg for private and signature-verified repos, plus Helm 3 built from source and the Wolfi Kustomize, both of which the repo-server execs by bare name.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.4.6, 3.3.13, 3.2.12",
      "versions": [
        {
          "version": "3.4.6",
          "size": "106.0 MB",
          "published": "2026-08-02T09:28:03Z",
          "digest": "sha256:e9f3d4132747b3813115a18eb744c5466d06ebcc8c3b5cdbb8536edf3c6dcdc7"
        },
        {
          "version": "3.3.13",
          "size": "105.4 MB",
          "published": "2026-08-02T09:28:03Z",
          "digest": "sha256:1f3655b7bc3d100465ead6976fd42dfecfa68f05c4dd5f553babb173538528dc"
        },
        {
          "version": "3.2.12",
          "size": "105.0 MB",
          "published": "2026-08-02T09:27:59Z",
          "digest": "sha256:dbf8acba889c5fbfa340702d12fa0d4cf2d138887e04c4b96067f1f5192b45e1"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://argo-cd.readthedocs.io",
      "source": "https://github.com/argoproj/argo-cd",
      "image": "ghcr.io/quenchworks/images/argocd",
      "security": {
        "image": "ghcr.io/quenchworks/images/argocd",
        "version": "3.4.6",
        "tag": "ghcr.io/quenchworks/images/argocd:3.4.6",
        "critical": 0,
        "high": 3,
        "medium": 1,
        "low": 0,
        "unknown": 6,
        "total": 10,
        "fixable": 6,
        "grade": "D",
        "score": 24,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/argocd",
              "usr/bin/helm"
            ]
          },
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/argocd"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/argocd"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/git-lfs",
              "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/argocd",
              "usr/bin/helm"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.52.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/git-lfs",
              "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.4.6",
            "tag": "ghcr.io/quenchworks/images/argocd:3.4.6",
            "critical": 0,
            "high": 3,
            "medium": 1,
            "low": 0,
            "unknown": 6,
            "total": 10,
            "fixable": 6,
            "grade": "D",
            "score": 24,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/argocd",
                  "usr/bin/helm"
                ]
              },
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/argocd"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/argocd"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/argocd",
                  "usr/bin/helm"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              }
            ]
          },
          {
            "version": "3.3.13",
            "tag": "ghcr.io/quenchworks/images/argocd:3.3.13",
            "critical": 0,
            "high": 3,
            "medium": 1,
            "low": 0,
            "unknown": 6,
            "total": 10,
            "fixable": 6,
            "grade": "D",
            "score": 24,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/argocd",
                  "usr/bin/helm"
                ]
              },
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/argocd"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/argocd"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/argocd",
                  "usr/bin/helm"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              }
            ]
          },
          {
            "version": "3.2.12",
            "tag": "ghcr.io/quenchworks/images/argocd:3.2.12",
            "critical": 0,
            "high": 3,
            "medium": 1,
            "low": 0,
            "unknown": 6,
            "total": 10,
            "fixable": 6,
            "grade": "D",
            "score": 24,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/argocd",
                  "usr/bin/helm"
                ]
              },
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/argocd"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/argocd"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/argocd",
                  "usr/bin/helm"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "aspnet",
      "name": "aspnet",
      "category": "Runtime base",
      "summary": "Hardened ASP.NET Core runtime for web apps and APIs, no SDK. Build on the dotnet image, then run here. Lines 8/9/10.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "9.0.119, 8.0.127, 10.0.110",
      "versions": [
        {
          "version": "9.0.119",
          "size": "71.0 MB",
          "published": "2026-07-21T08:29:59Z",
          "digest": "sha256:11c7c102a26ba0de5f8035dc713e4494a167548ab3c582d8c5da63b070ec6640"
        },
        {
          "version": "8.0.127",
          "size": "68.2 MB",
          "published": "2026-07-15T11:18:11Z",
          "digest": "sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061"
        },
        {
          "version": "10.0.110",
          "size": "72.2 MB",
          "published": "2026-07-15T11:15:56Z",
          "digest": "sha256:54c8dee542ec87520f63d9500ed5ce9332ace84d6b359e84c0d51a664c5047a3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dotnet/runtime",
      "source": "https://github.com/dotnet/runtime",
      "image": "ghcr.io/quenchworks/images/aspnet",
      "security": {
        "image": "ghcr.io/quenchworks/images/aspnet",
        "version": "10.0.110",
        "tag": "ghcr.io/quenchworks/images/aspnet:10.0.110",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "10.0.110",
            "tag": "ghcr.io/quenchworks/images/aspnet:10.0.110",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.0.119",
            "tag": "ghcr.io/quenchworks/images/aspnet:9.0.119",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.127",
            "tag": "ghcr.io/quenchworks/images/aspnet:8.0.127",
            "critical": 3,
            "high": 9,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 12,
            "fixable": 12,
            "grade": "F",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "atlantis",
      "name": "Atlantis",
      "category": "GitOps",
      "summary": "Terraform pull-request automation that runs plan on PRs and apply from PR comments, enforcing reviewed, Git-driven infrastructure changes with state locking.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.46.0",
      "versions": [
        {
          "version": "0.46.0",
          "size": "74.5 MB",
          "published": "2026-07-22T06:42:12Z",
          "digest": "sha256:769481554211806644df3e931c7021faa9d226a45aff333dd857b5f464936e0e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/runatlantis/atlantis",
      "source": "https://github.com/runatlantis/atlantis",
      "image": "ghcr.io/quenchworks/images/atlantis",
      "security": {
        "image": "ghcr.io/quenchworks/images/atlantis",
        "version": "0.46.0",
        "tag": "ghcr.io/quenchworks/images/atlantis:0.46.0",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 2,
        "total": 4,
        "fixable": 2,
        "grade": "D",
        "score": 72,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/tofu"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/atlantis@sha256:769481554211806644df3e931c7021faa9d226a45aff333dd857b5f464936e0e (wolfi 20230201)"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/atlantis",
              "usr/bin/tofu"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.46.0",
            "tag": "ghcr.io/quenchworks/images/atlantis:0.46.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 2,
            "total": 4,
            "fixable": 2,
            "grade": "D",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/tofu"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/atlantis@sha256:769481554211806644df3e931c7021faa9d226a45aff333dd857b5f464936e0e (wolfi 20230201)"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/atlantis",
                  "usr/bin/tofu"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "authelia",
      "name": "authelia",
      "category": "Identity",
      "summary": "Open-source authentication and authorization server providing single sign-on and two-factor authentication via a web portal, designed as a companion for reverse proxies. Packaged from Authelia's official prebuilt binary; needs a config plus a SQLite or PostgreSQL storage backend.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.39.20",
      "versions": [
        {
          "version": "4.39.20",
          "size": "21.7 MB",
          "published": "2026-07-26T12:18:52Z",
          "digest": "sha256:e9e9a5b5edcd91838d31ddc85df9a27e5e44c6be7371d45930c04437028cda96"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.authelia.com",
      "source": "https://github.com/authelia/authelia",
      "image": "ghcr.io/quenchworks/images/authelia",
      "security": {
        "image": "ghcr.io/quenchworks/images/authelia",
        "version": "4.39.20",
        "tag": "ghcr.io/quenchworks/images/authelia:4.39.20",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/authelia"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.39.20",
            "tag": "ghcr.io/quenchworks/images/authelia:4.39.20",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/authelia"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "authentik",
      "name": "authentik",
      "category": "Secrets & identity",
      "summary": "Self-hosted identity provider (OIDC, SAML, LDAP, SCIM) with flows, policies, and application/provider management. Built clean-room from source on Wolfi as a four-language image (nodejs web UI, Go server/proxy, Rust worker, Python/Django core via uv) on a hardened nonroot base; FIPS mode is not forced and the license-gated MaxMind GeoIP download is omitted. Needs PostgreSQL and Redis at runtime, provided by the chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2026.5.6",
      "versions": [
        {
          "version": "2026.5.6",
          "size": "229.7 MB",
          "published": "2026-07-28T06:29:36Z",
          "digest": "sha256:ae674559d1ed7cc9820d5128c914d5647f36effe3f3fed632e886946fcf5f634"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://goauthentik.io",
      "source": "https://github.com/goauthentik/authentik",
      "image": "ghcr.io/quenchworks/images/authentik",
      "security": {
        "image": "ghcr.io/quenchworks/images/authentik",
        "version": "2026.5.6",
        "tag": "ghcr.io/quenchworks/images/authentik:2026.5.6",
        "critical": 0,
        "high": 3,
        "medium": 6,
        "low": 2,
        "unknown": 0,
        "total": 11,
        "fixable": 10,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-69244",
            "severity": "HIGH",
            "pkg": "aiohttp",
            "installed": "3.14.1",
            "fixed": "3.14.3",
            "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69244",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-69247",
            "severity": "HIGH",
            "pkg": "cryptography",
            "installed": "48.0.1",
            "fixed": "50.0.0",
            "title": "cryptography is a package designed to expose cryptographic primitives  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-69249",
            "severity": "HIGH",
            "pkg": "cryptography",
            "installed": "48.0.1",
            "fixed": "49.0.0",
            "title": "python-cryptography is a package designed to expose cryptographic prim ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69249",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-53877",
            "severity": "MEDIUM",
            "pkg": "Django",
            "installed": "5.2.15",
            "fixed": "5.2.16, 6.0.7",
            "title": "django: Django: Information disclosure via heap buffer over-read in GDALRaster",
            "url": "https://avd.aquasec.com/nvd/cve-2026-53877",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-53878",
            "severity": "MEDIUM",
            "pkg": "Django",
            "installed": "5.2.15",
            "fixed": "5.2.16, 6.0.7",
            "title": "django: Django: HTTP header injection via DomainNameValidator accepting newlines",
            "url": "https://avd.aquasec.com/nvd/cve-2026-53878",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-59881",
            "severity": "MEDIUM",
            "pkg": "aiohttp",
            "installed": "3.14.1",
            "fixed": "3.14.2",
            "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59881",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-69243",
            "severity": "MEDIUM",
            "pkg": "aiohttp",
            "installed": "3.14.1",
            "fixed": "3.14.2",
            "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69243",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-69248",
            "severity": "MEDIUM",
            "pkg": "cryptography",
            "installed": "48.0.1",
            "fixed": "49.0.0",
            "title": "cryptography is a package designed to expose cryptographic primitives  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69248",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-71554",
            "severity": "MEDIUM",
            "pkg": "h2",
            "installed": "4.3.0",
            "fixed": "4.4.1",
            "title": "h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71554",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-48588",
            "severity": "LOW",
            "pkg": "Django",
            "installed": "5.2.15",
            "fixed": "5.2.16, 6.0.7",
            "title": "django: Django: Information disclosure due to improper caching of Set-Cookie responses",
            "url": "https://avd.aquasec.com/nvd/cve-2026-48588",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-44405",
            "severity": "LOW",
            "pkg": "paramiko",
            "installed": "4.0.0",
            "fixed": null,
            "title": "paramiko: Paramiko: Data integrity could be compromised due to SHA-1 algorithm use",
            "url": "https://avd.aquasec.com/nvd/cve-2026-44405",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "2026.5.6",
            "tag": "ghcr.io/quenchworks/images/authentik:2026.5.6",
            "critical": 0,
            "high": 3,
            "medium": 6,
            "low": 2,
            "unknown": 0,
            "total": 11,
            "fixable": 10,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-69244",
                "severity": "HIGH",
                "pkg": "aiohttp",
                "installed": "3.14.1",
                "fixed": "3.14.3",
                "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69244",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "48.0.1",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-69249",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "48.0.1",
                "fixed": "49.0.0",
                "title": "python-cryptography is a package designed to expose cryptographic prim ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69249",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-53877",
                "severity": "MEDIUM",
                "pkg": "Django",
                "installed": "5.2.15",
                "fixed": "5.2.16, 6.0.7",
                "title": "django: Django: Information disclosure via heap buffer over-read in GDALRaster",
                "url": "https://avd.aquasec.com/nvd/cve-2026-53877",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-53878",
                "severity": "MEDIUM",
                "pkg": "Django",
                "installed": "5.2.15",
                "fixed": "5.2.16, 6.0.7",
                "title": "django: Django: HTTP header injection via DomainNameValidator accepting newlines",
                "url": "https://avd.aquasec.com/nvd/cve-2026-53878",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-59881",
                "severity": "MEDIUM",
                "pkg": "aiohttp",
                "installed": "3.14.1",
                "fixed": "3.14.2",
                "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59881",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-69243",
                "severity": "MEDIUM",
                "pkg": "aiohttp",
                "installed": "3.14.1",
                "fixed": "3.14.2",
                "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69243",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-69248",
                "severity": "MEDIUM",
                "pkg": "cryptography",
                "installed": "48.0.1",
                "fixed": "49.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69248",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-71554",
                "severity": "MEDIUM",
                "pkg": "h2",
                "installed": "4.3.0",
                "fixed": "4.4.1",
                "title": "h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71554",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-48588",
                "severity": "LOW",
                "pkg": "Django",
                "installed": "5.2.15",
                "fixed": "5.2.16, 6.0.7",
                "title": "django: Django: Information disclosure due to improper caching of Set-Cookie responses",
                "url": "https://avd.aquasec.com/nvd/cve-2026-48588",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-44405",
                "severity": "LOW",
                "pkg": "paramiko",
                "installed": "4.0.0",
                "fixed": null,
                "title": "paramiko: Paramiko: Data integrity could be compromised due to SHA-1 algorithm use",
                "url": "https://avd.aquasec.com/nvd/cve-2026-44405",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "blackbox-exporter",
      "name": "blackbox-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter that probes endpoints externally over HTTP, HTTPS, TCP, DNS, and ICMP for black-box uptime and latency monitoring.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.28.0",
      "versions": [
        {
          "version": "0.28.0",
          "size": "8.9 MB",
          "published": "2026-07-26T12:17:48Z",
          "digest": "sha256:f10c7ea6a9e66d4657f4539f9d2f235c6b538cc20ad3f443a76903970c228cf3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/blackbox_exporter",
      "source": "https://github.com/prometheus/blackbox_exporter",
      "image": "ghcr.io/quenchworks/images/blackbox-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/blackbox-exporter",
        "version": "0.28.0",
        "tag": "ghcr.io/quenchworks/images/blackbox-exporter:0.28.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/blackbox_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.28.0",
            "tag": "ghcr.io/quenchworks/images/blackbox-exporter:0.28.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/blackbox_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "buildkite-agent",
      "name": "buildkite-agent",
      "category": "CI/CD & registry",
      "summary": "The Buildkite CI build-runner agent that executes pipeline jobs on your own infrastructure. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "3.133.1, 3.134.0, 3.135.0",
      "versions": [
        {
          "version": "3.133.1",
          "size": "16.4 MB",
          "published": "2026-07-30T08:06:48Z",
          "digest": "sha256:3e3213c7eccfd2d57ae83025aa0d0e437a437a4c7cfbfb092402298ff545fb48"
        },
        {
          "version": "3.134.0",
          "size": "16.5 MB",
          "published": "2026-07-30T08:05:15Z",
          "digest": "sha256:7d24f62285c4d53c997bae1a7bbabe34c4137ebcaafd44c622ae9925e152ecb0"
        },
        {
          "version": "3.135.0",
          "size": "16.6 MB",
          "published": "2026-07-30T08:02:44Z",
          "digest": "sha256:6b538fde72550f107287d0ad23887697904fea0eed1c6ce052bc38edb0af0cbf"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://buildkite.com/docs/agent",
      "source": "https://github.com/buildkite/agent",
      "image": "ghcr.io/quenchworks/images/buildkite-agent",
      "security": {
        "image": "ghcr.io/quenchworks/images/buildkite-agent",
        "version": "3.135.0",
        "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.135.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/buildkite-agent"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.135.0",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.135.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          },
          {
            "version": "3.134.0",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.134.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          },
          {
            "version": "3.133.1",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.133.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "bun",
      "name": "bun",
      "category": "Language runtime",
      "summary": "Hardened Bun runtime and toolkit (runtime, bundler, package manager) for JavaScript and TypeScript. Latest stable (1).",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.3.13, 1.3.14, 1.3.11",
      "versions": [
        {
          "version": "1.3.13",
          "size": "42.3 MB",
          "published": "2026-07-04T10:49:28Z",
          "digest": "sha256:7d1e4366c4d4fffb65e8dfeb56e9e66ad370bb3662832d3459b5e1f0c4cdb413"
        },
        {
          "version": "1.3.14",
          "size": "38.1 MB",
          "published": "2026-07-04T10:48:45Z",
          "digest": "sha256:d1d2adb44bd9b77afb822fc397dd961633ac93cfbd775eb6b350cfbe894dd8e9"
        },
        {
          "version": "1.3.11",
          "size": "41.4 MB",
          "published": "2026-07-04T10:42:12Z",
          "digest": "sha256:8acfa03af5cbc9e5f6c738b178473e2a7af8f446515a580aef9683d674a0e3e7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/oven-sh/bun",
      "source": "https://github.com/oven-sh/bun",
      "image": "ghcr.io/quenchworks/images/bun",
      "security": {
        "image": "ghcr.io/quenchworks/images/bun",
        "version": "1.3.14",
        "tag": "ghcr.io/quenchworks/images/bun:1.3.14",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.3.14",
            "tag": "ghcr.io/quenchworks/images/bun:1.3.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.3.13",
            "tag": "ghcr.io/quenchworks/images/bun:1.3.13",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.3.11",
            "tag": "ghcr.io/quenchworks/images/bun:1.3.11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "busybox",
      "name": "BusyBox",
      "category": "Base image",
      "summary": "Hardened minimal base/toolbox image bundling common Unix utilities in one binary. Image only, no chart.",
      "tier": "low",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "1.38.0, 1.36.1, 1.37.0",
      "versions": [
        {
          "version": "1.38.0",
          "size": "4.1 MB",
          "published": "2026-07-04T11:34:34Z",
          "digest": "sha256:379b162cd4794ee14c63fec0cc501b855b804f33f824c4e46ced6183f644adfe"
        },
        {
          "version": "1.36.1",
          "size": "4.1 MB",
          "published": "2026-07-04T11:34:25Z",
          "digest": "sha256:b5d7d24c25561436a9285cbd209ecd6f2a6ad6ad7392267fe001e48f2651f8ea"
        },
        {
          "version": "1.37.0",
          "size": "4.1 MB",
          "published": "2026-07-04T11:34:18Z",
          "digest": "sha256:a0d34d7f510c4122f7e8a237bf8e186538a4b6752296c2f7e519451987b541e4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://busybox.net",
      "source": "https://busybox.net",
      "image": "ghcr.io/quenchworks/images/busybox",
      "security": {
        "image": "ghcr.io/quenchworks/images/busybox",
        "version": "1.38.0",
        "tag": "ghcr.io/quenchworks/images/busybox:1.38.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.38.0",
            "tag": "ghcr.io/quenchworks/images/busybox:1.38.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.37.0",
            "tag": "ghcr.io/quenchworks/images/busybox:1.37.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.36.1",
            "tag": "ghcr.io/quenchworks/images/busybox:1.36.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "caddy",
      "name": "Caddy",
      "category": "Gateway",
      "summary": "Web server and reverse proxy with fully automatic HTTPS via Let's Encrypt and a simple Caddyfile config.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.11.4",
      "versions": [
        {
          "version": "2.11.4",
          "size": "22.8 MB",
          "published": "2026-07-26T12:19:01Z",
          "digest": "sha256:916aca2000f2bc50c2fa01c4e30f3f44906fb339e159cb30e2d2611cf60c0303"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/caddyserver/caddy",
      "source": "https://github.com/caddyserver/caddy",
      "image": "ghcr.io/quenchworks/images/caddy",
      "security": {
        "image": "ghcr.io/quenchworks/images/caddy",
        "version": "2.11.4",
        "tag": "ghcr.io/quenchworks/images/caddy:2.11.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/caddy"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.11.4",
            "tag": "ghcr.io/quenchworks/images/caddy:2.11.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/caddy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cadence",
      "name": "cadence",
      "category": "Workflow",
      "summary": "Fault-tolerant, stateful workflow orchestration engine by Uber. Ships the cadence server and CLI as static Go binaries on a hardened nonroot Wolfi base; Cassandra or a SQL store is the operator's concern.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.4.1",
      "versions": [
        {
          "version": "1.4.1",
          "size": "58.0 MB",
          "published": "2026-07-22T08:34:10Z",
          "digest": "sha256:d58de1ef90e3ae2f79977d1cf800c29a96de67f2340d17b438ecd7589ac7b21f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cadenceworkflow.io",
      "source": "https://github.com/uber/cadence",
      "image": "ghcr.io/quenchworks/images/cadence",
      "security": {
        "image": "ghcr.io/quenchworks/images/cadence",
        "version": "1.4.1",
        "tag": "ghcr.io/quenchworks/images/cadence:1.4.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cadence",
              "usr/bin/cadence-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.4.1",
            "tag": "ghcr.io/quenchworks/images/cadence:1.4.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cadence",
                  "usr/bin/cadence-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cadvisor",
      "name": "cadvisor",
      "category": "Observability",
      "summary": "Analyzes resource usage and performance characteristics of running containers. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.60.5",
      "versions": [
        {
          "version": "0.60.5",
          "size": "10.2 MB",
          "published": "2026-07-22T08:26:00Z",
          "digest": "sha256:b4cb28bd96e0215b5abfc9e5868de27f6449eacd830e179bdbe45f1453f11eb0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/google/cadvisor",
      "source": "https://github.com/google/cadvisor",
      "image": "ghcr.io/quenchworks/images/cadvisor",
      "security": {
        "image": "ghcr.io/quenchworks/images/cadvisor",
        "version": "0.60.5",
        "tag": "ghcr.io/quenchworks/images/cadvisor:0.60.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cadvisor"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.60.5",
            "tag": "ghcr.io/quenchworks/images/cadvisor:0.60.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cadvisor"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cassandra",
      "name": "Cassandra",
      "category": "Wide-column",
      "summary": "Distributed wide-column NoSQL store built for linear horizontal scale and high availability with no single point of failure, tuned for heavy writes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.0.8",
      "versions": [
        {
          "version": "5.0.8",
          "size": "140.2 MB",
          "published": "2026-07-28T06:16:43Z",
          "digest": "sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/cassandra",
      "source": "https://downloads.apache.org/cassandra/5.0.8/apache-cassandra-5.0.8-bin.tar.gz",
      "image": "ghcr.io/quenchworks/images/cassandra",
      "security": {
        "image": "ghcr.io/quenchworks/images/cassandra",
        "version": "5.0.8",
        "tag": "ghcr.io/quenchworks/images/cassandra:5.0.8",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "C",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-17-jre",
            "installed": "17.0.19-r4",
            "fixed": "17.0.20-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/cassandra@sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-17-jre",
            "installed": "17.0.19-r4",
            "fixed": "17.0.20-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/cassandra@sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-17-jre",
            "installed": "17.0.19-r4",
            "fixed": "17.0.20-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/cassandra@sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "5.0.8",
            "tag": "ghcr.io/quenchworks/images/cassandra:5.0.8",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "C",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-jre",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/cassandra@sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-jre",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/cassandra@sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-17-jre",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/cassandra@sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "centrifugo",
      "name": "centrifugo",
      "category": "Messaging",
      "summary": "Scalable real-time messaging server (WebSocket, SSE, GRPC) with channels, presence, and JWT auth. Built from source as a static Go binary on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "6.9.1",
      "versions": [
        {
          "version": "6.9.1",
          "size": "23.0 MB",
          "published": "2026-07-26T12:18:15Z",
          "digest": "sha256:0a21d8e336e37e093817a6691a477acabe784d325f65bc1444d4e65e0bdb5ddc"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://centrifugal.dev",
      "source": "https://github.com/centrifugal/centrifugo",
      "image": "ghcr.io/quenchworks/images/centrifugo",
      "security": {
        "image": "ghcr.io/quenchworks/images/centrifugo",
        "version": "6.9.1",
        "tag": "ghcr.io/quenchworks/images/centrifugo:6.9.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/centrifugo"
            ]
          }
        ],
        "versions": [
          {
            "version": "6.9.1",
            "tag": "ghcr.io/quenchworks/images/centrifugo:6.9.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/centrifugo"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-acmesolver",
      "name": "cert-manager-acmesolver",
      "category": "Security & supply chain",
      "summary": "acmesolver component of cert-manager. The minimal HTTP server cert-manager runs as ephemeral pods to answer ACME http-01 challenge requests during certificate issuance.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.21.1, 1.19.6, 1.20.3",
      "versions": [
        {
          "version": "1.21.1",
          "size": "5.8 MB",
          "published": "2026-07-30T08:03:31Z",
          "digest": "sha256:78b0df18952a2b92133dca93ea9dcb70c8b86002cda09df70ce8a98fe1b888b3"
        },
        {
          "version": "1.19.6",
          "size": "7.9 MB",
          "published": "2026-07-30T08:03:30Z",
          "digest": "sha256:ee4ed58185fb9d542b95c657905360f43a92939ed28a7f073690deb5aed0e0c6"
        },
        {
          "version": "1.20.3",
          "size": "7.5 MB",
          "published": "2026-07-30T08:02:06Z",
          "digest": "sha256:cde325ad93021f98e3f680480888e879e85aa70655bf34e88d1b48a5c9577d2b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-acmesolver",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-acmesolver",
        "version": "1.21.1",
        "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.21.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.21.1",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.21.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "cert-manager-cainjector",
      "name": "cert-manager-cainjector",
      "category": "Security & supply chain",
      "summary": "cainjector component of cert-manager. Injects CA bundles into ValidatingWebhookConfigurations, MutatingWebhookConfigurations, APIServices, and conversion CRDs so the rest of the stack trusts cert-manager-issued certificates.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.19.6, 1.21.1, 1.20.3",
      "versions": [
        {
          "version": "1.19.6",
          "size": "16.4 MB",
          "published": "2026-07-30T08:06:08Z",
          "digest": "sha256:fb6a6ab87fd21235cd5dc47419a1ffab8fa044d437df5751f92da7ebd09e2a14"
        },
        {
          "version": "1.21.1",
          "size": "11.6 MB",
          "published": "2026-07-30T08:04:12Z",
          "digest": "sha256:7d0e1404b0001d83ac16f12f9df23067929bbc92264e5c5fbdc1d0a554483062"
        },
        {
          "version": "1.20.3",
          "size": "15.8 MB",
          "published": "2026-07-30T08:02:11Z",
          "digest": "sha256:5b88467bd6d7922a959691ec988bc98b368fd9a740f866b24865c6d8558b3aa1"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-cainjector",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-cainjector",
        "version": "1.21.1",
        "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.21.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cainjector"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.21.1",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.21.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-controller",
      "name": "cert-manager-controller",
      "category": "Security & supply chain",
      "summary": "Core controller of cert-manager, the CNCF standard for X.509 certificate management on Kubernetes. Reconciles Certificate, Issuer, ClusterIssuer, and ACME order resources, automating issuance and renewal from Let's Encrypt, Vault, Venafi, and self-signed/CA issuers.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.21.1, 1.19.6, 1.20.3",
      "versions": [
        {
          "version": "1.21.1",
          "size": "24.0 MB",
          "published": "2026-07-30T08:10:20Z",
          "digest": "sha256:652fe926a9adb199b0a1becd3bb44981a27b6169c698a333073e91eea00fa2f0"
        },
        {
          "version": "1.19.6",
          "size": "23.3 MB",
          "published": "2026-07-30T08:08:41Z",
          "digest": "sha256:6f3862cf74b39433c827821045980ab2f3ed423f4c2711afaa46a101c62ef05e"
        },
        {
          "version": "1.20.3",
          "size": "23.0 MB",
          "published": "2026-07-30T08:08:40Z",
          "digest": "sha256:8a3aa246b07f26aa83f9d95dc6fa868f035b30215462862a980e68bdc1cb619d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-controller",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-controller",
        "version": "1.21.1",
        "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.21.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.21.1",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.21.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-webhook",
      "name": "cert-manager-webhook",
      "category": "Security & supply chain",
      "summary": "Admission webhook component of cert-manager. Validates and mutates cert-manager API resources and serves the conversion webhook for its CRD versions.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.19.6, 1.21.1, 1.20.3",
      "versions": [
        {
          "version": "1.19.6",
          "size": "19.5 MB",
          "published": "2026-07-30T08:09:53Z",
          "digest": "sha256:bd70884a68e8dd23ff51aba0b57a6c62b18ed1d3def1f204a3c4db406da16183"
        },
        {
          "version": "1.21.1",
          "size": "19.0 MB",
          "published": "2026-07-30T08:09:43Z",
          "digest": "sha256:a14cd3675a8ff6205bc9807ff48ad4d28820dc838737499a99c5513bba1336de"
        },
        {
          "version": "1.20.3",
          "size": "18.9 MB",
          "published": "2026-07-30T08:05:50Z",
          "digest": "sha256:d0fbc971fc0c294f132a9a64ea30cfaa0b5ce80caded675c2de3a17b8a614931"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-webhook",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-webhook",
        "version": "1.21.1",
        "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.21.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/webhook"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.21.1",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.21.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "chartmuseum",
      "name": "chartmuseum",
      "category": "CI/CD & registry",
      "summary": "Helm chart repository server with support for cloud object storage backends (S3, GCS, Azure, and more). Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.16.5",
      "versions": [
        {
          "version": "0.16.5",
          "size": "20.3 MB",
          "published": "2026-07-22T08:27:19Z",
          "digest": "sha256:35e24b059f4602e17750f0ceed45ecd3356b2bd0ad7d318c47823533bd291cbd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://chartmuseum.com",
      "source": "https://github.com/helm/chartmuseum",
      "image": "ghcr.io/quenchworks/images/chartmuseum",
      "security": {
        "image": "ghcr.io/quenchworks/images/chartmuseum",
        "version": "0.16.5",
        "tag": "ghcr.io/quenchworks/images/chartmuseum:0.16.5",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 1,
        "grade": "D",
        "score": 83,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/chartmuseum"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/chartmuseum"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.16.5",
            "tag": "ghcr.io/quenchworks/images/chartmuseum:0.16.5",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "D",
            "score": 83,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/chartmuseum"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/chartmuseum"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "clickhouse",
      "name": "ClickHouse",
      "category": "Analytical",
      "summary": "Column-oriented OLAP database for real-time analytical queries over very large datasets, with high ingest rates and fast aggregations.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "26.6.2.81, 26.7.1.1315, 26.5.3.52",
      "versions": [
        {
          "version": "26.6.2.81",
          "size": "240.8 MB",
          "published": "2026-07-23T08:58:30Z",
          "digest": "sha256:378c62d2f23261b9bef396bc6ea8f0b6f920be4d0cbecddbf2aea6d89d6ef8d0"
        },
        {
          "version": "26.7.1.1315",
          "size": "229.7 MB",
          "published": "2026-07-23T08:58:28Z",
          "digest": "sha256:0fe6b62479965049517e9f59800529422f36038932676b798fa56d3db83757b4"
        },
        {
          "version": "26.5.3.52",
          "size": "225.7 MB",
          "published": "2026-07-23T08:58:24Z",
          "digest": "sha256:fb69216283354f87c80a7cd251c626b1ca68f893f290e795c36375fd1bb45abd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/ClickHouse/ClickHouse",
      "source": "https://github.com/ClickHouse/ClickHouse",
      "image": "ghcr.io/quenchworks/images/clickhouse",
      "security": {
        "image": "ghcr.io/quenchworks/images/clickhouse",
        "version": "26.7.1.1315",
        "tag": "ghcr.io/quenchworks/images/clickhouse:26.7.1.1315",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "26.7.1.1315",
            "tag": "ghcr.io/quenchworks/images/clickhouse:26.7.1.1315",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "26.6.2.81",
            "tag": "ghcr.io/quenchworks/images/clickhouse:26.6.2.81",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "26.5.3.52",
            "tag": "ghcr.io/quenchworks/images/clickhouse:26.5.3.52",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "code-server",
      "name": "code-server",
      "category": "Developer tools / IDE",
      "summary": "VS Code in the browser (Coder's code-server), a full IDE served over HTTP. Ships Coder's official prebuilt release (bundled Node 24 + compiled VS Code) hardened on a minimal, nonroot Wolfi base; runs as a single-replica Deployment with a persistent workspace and PASSWORD login.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "4.131.0",
      "versions": [
        {
          "version": "4.131.0",
          "size": "234.8 MB",
          "published": "2026-08-02T08:38:12Z",
          "digest": "sha256:fec2882c38457130c9a46f0ec8c6eead7314bbf2b1e0c86f7e670f712844d2b6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://coder.com",
      "source": "https://github.com/coder/code-server",
      "image": "ghcr.io/quenchworks/images/code-server",
      "security": {
        "image": "ghcr.io/quenchworks/images/code-server",
        "version": "4.131.0",
        "tag": "ghcr.io/quenchworks/images/code-server:4.131.0",
        "critical": 0,
        "high": 4,
        "medium": 8,
        "low": 1,
        "unknown": 0,
        "total": 13,
        "fixable": 12,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-13697",
            "severity": "HIGH",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "7.29.0, 8.9.0",
            "title": "undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives",
            "url": "https://avd.aquasec.com/nvd/cve-2026-13697",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69192",
            "severity": "HIGH",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.3.1",
            "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-5p4m-2wfm-xmqj",
            "severity": "HIGH",
            "pkg": "js-yaml",
            "installed": "4.3.0",
            "fixed": "4.3.1, 3.15.1",
            "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
            "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-14643",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "7.29.0, 8.9.0",
            "title": "undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing",
            "url": "https://avd.aquasec.com/nvd/cve-2026-14643",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-15157",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
            "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16728",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16729",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-54272",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.1",
            "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69198",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.2",
            "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-wx77-rp39-c6vg",
            "severity": "LOW",
            "pkg": "markdown",
            "installed": "30.0.0",
            "fixed": null,
            "title": "Regular Expression Denial of Service in markdown",
            "url": "https://github.com/advisories/GHSA-wx77-rp39-c6vg",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.131.0",
            "tag": "ghcr.io/quenchworks/images/code-server:4.131.0",
            "critical": 0,
            "high": 4,
            "medium": 8,
            "low": 1,
            "unknown": 0,
            "total": 13,
            "fixable": 12,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-13697",
                "severity": "HIGH",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "7.29.0, 8.9.0",
                "title": "undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives",
                "url": "https://avd.aquasec.com/nvd/cve-2026-13697",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69192",
                "severity": "HIGH",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.3.1",
                "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-5p4m-2wfm-xmqj",
                "severity": "HIGH",
                "pkg": "js-yaml",
                "installed": "4.3.0",
                "fixed": "4.3.1, 3.15.1",
                "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
                "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-14643",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "7.29.0, 8.9.0",
                "title": "undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-14643",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-54272",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.1",
                "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69198",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.2",
                "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-wx77-rp39-c6vg",
                "severity": "LOW",
                "pkg": "markdown",
                "installed": "30.0.0",
                "fixed": null,
                "title": "Regular Expression Denial of Service in markdown",
                "url": "https://github.com/advisories/GHSA-wx77-rp39-c6vg",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "composer",
      "name": "composer",
      "category": "Build tool",
      "summary": "PHP base image with the Composer dependency manager, used as the build stage for PHP projects. Line 2.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.10.1, 2.10.0, 2.10.2",
      "versions": [
        {
          "version": "2.10.1",
          "size": "28.8 MB",
          "published": "2026-07-04T10:28:18Z",
          "digest": "sha256:de8f90cc23437a8f56c22ce0252247416d9c5d6af78587ceea3c9533ef852fe6"
        },
        {
          "version": "2.10.0",
          "size": "28.8 MB",
          "published": "2026-07-04T10:26:36Z",
          "digest": "sha256:69b1d142232cd87281ce9fe193ad3eb2199373650f4ca01ddaded18f0b93ada6"
        },
        {
          "version": "2.10.2",
          "size": "28.8 MB",
          "published": "2026-07-04T10:22:18Z",
          "digest": "sha256:15b91ef4fed75a9adff1b45c6e0283466477f1d8d9d034799ee066e8e62c7408"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://getcomposer.org",
      "source": "https://getcomposer.org",
      "image": "ghcr.io/quenchworks/images/composer",
      "security": {
        "image": "ghcr.io/quenchworks/images/composer",
        "version": "2.10.2",
        "tag": "ghcr.io/quenchworks/images/composer:2.10.2",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "C",
        "score": 91,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/composer@sha256:15b91ef4fed75a9adff1b45c6e0283466477f1d8d9d034799ee066e8e62c7408 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.10.2",
            "tag": "ghcr.io/quenchworks/images/composer:2.10.2",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/composer@sha256:15b91ef4fed75a9adff1b45c6e0283466477f1d8d9d034799ee066e8e62c7408 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "2.10.1",
            "tag": "ghcr.io/quenchworks/images/composer:2.10.1",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/composer@sha256:de8f90cc23437a8f56c22ce0252247416d9c5d6af78587ceea3c9533ef852fe6 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "2.10.0",
            "tag": "ghcr.io/quenchworks/images/composer:2.10.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/composer@sha256:69b1d142232cd87281ce9fe193ad3eb2199373650f4ca01ddaded18f0b93ada6 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coolify-app",
      "name": "Coolify",
      "category": "PaaS",
      "summary": "Control-plane application for Coolify, an open-source self-hostable PaaS alternative to Heroku, Vercel, and Netlify for deploying apps, databases, and services on your own servers.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.2.0",
      "versions": [
        {
          "version": "4.2.0",
          "size": "119.0 MB",
          "published": "2026-07-28T06:20:09Z",
          "digest": "sha256:a170bf310e7f2335dffb936c5df58f4bff8ccf567d78d80131919527ce4878f6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/coollabsio/coolify",
      "source": "https://github.com/coollabsio/coolify",
      "image": "ghcr.io/quenchworks/images/coolify-app",
      "security": {
        "image": "ghcr.io/quenchworks/images/coolify-app",
        "version": "4.2.0",
        "tag": "ghcr.io/quenchworks/images/coolify-app:4.2.0",
        "critical": 0,
        "high": 4,
        "medium": 3,
        "low": 0,
        "unknown": 4,
        "total": 11,
        "fixable": 9,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-71488",
            "severity": "HIGH",
            "pkg": "league/commonmark",
            "installed": "2.8.3",
            "fixed": "2.9.0",
            "title": "league/commonmark: Quadratic-time denial of service when parsing crafted Markdown",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71488",
            "targets": [
              "var/www/html/vendor/composer/installed.json"
            ]
          },
          {
            "id": "GHSA-g2gp-3wwq-f4ph",
            "severity": "HIGH",
            "pkg": "league/commonmark",
            "installed": "2.8.3",
            "fixed": "2.9.0",
            "title": "league/commonmark: Denial of service via adjacent inline attribute blocks",
            "url": "https://github.com/advisories/GHSA-g2gp-3wwq-f4ph",
            "targets": [
              "var/www/html/vendor/composer/installed.json"
            ]
          },
          {
            "id": "GHSA-jfm3-95jq-q3rf",
            "severity": "HIGH",
            "pkg": "league/commonmark",
            "installed": "2.8.3",
            "fixed": "2.9.0",
            "title": "league/commonmark:  Denial of service via duplicate footnote definitions",
            "url": "https://github.com/advisories/GHSA-jfm3-95jq-q3rf",
            "targets": [
              "var/www/html/vendor/composer/installed.json"
            ]
          },
          {
            "id": "GHSA-mh25-x5hq-wrqp",
            "severity": "HIGH",
            "pkg": "league/commonmark",
            "installed": "2.8.3",
            "fixed": "2.9.0",
            "title": "league/commonmark: Denial of service via colliding heading slugs",
            "url": "https://github.com/advisories/GHSA-mh25-x5hq-wrqp",
            "targets": [
              "var/www/html/vendor/composer/installed.json"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/coolify-app@sha256:a170bf310e7f2335dffb936c5df58f4bff8ccf567d78d80131919527ce4878f6 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71478",
            "severity": "MEDIUM",
            "pkg": "league/commonmark",
            "installed": "2.8.3",
            "fixed": "2.9.0",
            "title": "league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71478",
            "targets": [
              "var/www/html/vendor/composer/installed.json"
            ]
          },
          {
            "id": "GHSA-mj63-m3rc-8ppr",
            "severity": "MEDIUM",
            "pkg": "league/commonmark",
            "installed": "2.8.3",
            "fixed": "2.9.0",
            "title": "league/commonmark: Denial of service via deeply nested XML output",
            "url": "https://github.com/advisories/GHSA-mj63-m3rc-8ppr",
            "targets": [
              "var/www/html/vendor/composer/installed.json"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/git-lfs",
              "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.52.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/git-lfs",
              "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.2.0",
            "tag": "ghcr.io/quenchworks/images/coolify-app:4.2.0",
            "critical": 0,
            "high": 4,
            "medium": 3,
            "low": 0,
            "unknown": 4,
            "total": 11,
            "fixable": 9,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-71488",
                "severity": "HIGH",
                "pkg": "league/commonmark",
                "installed": "2.8.3",
                "fixed": "2.9.0",
                "title": "league/commonmark: Quadratic-time denial of service when parsing crafted Markdown",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71488",
                "targets": [
                  "var/www/html/vendor/composer/installed.json"
                ]
              },
              {
                "id": "GHSA-g2gp-3wwq-f4ph",
                "severity": "HIGH",
                "pkg": "league/commonmark",
                "installed": "2.8.3",
                "fixed": "2.9.0",
                "title": "league/commonmark: Denial of service via adjacent inline attribute blocks",
                "url": "https://github.com/advisories/GHSA-g2gp-3wwq-f4ph",
                "targets": [
                  "var/www/html/vendor/composer/installed.json"
                ]
              },
              {
                "id": "GHSA-jfm3-95jq-q3rf",
                "severity": "HIGH",
                "pkg": "league/commonmark",
                "installed": "2.8.3",
                "fixed": "2.9.0",
                "title": "league/commonmark:  Denial of service via duplicate footnote definitions",
                "url": "https://github.com/advisories/GHSA-jfm3-95jq-q3rf",
                "targets": [
                  "var/www/html/vendor/composer/installed.json"
                ]
              },
              {
                "id": "GHSA-mh25-x5hq-wrqp",
                "severity": "HIGH",
                "pkg": "league/commonmark",
                "installed": "2.8.3",
                "fixed": "2.9.0",
                "title": "league/commonmark: Denial of service via colliding heading slugs",
                "url": "https://github.com/advisories/GHSA-mh25-x5hq-wrqp",
                "targets": [
                  "var/www/html/vendor/composer/installed.json"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/coolify-app@sha256:a170bf310e7f2335dffb936c5df58f4bff8ccf567d78d80131919527ce4878f6 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71478",
                "severity": "MEDIUM",
                "pkg": "league/commonmark",
                "installed": "2.8.3",
                "fixed": "2.9.0",
                "title": "league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71478",
                "targets": [
                  "var/www/html/vendor/composer/installed.json"
                ]
              },
              {
                "id": "GHSA-mj63-m3rc-8ppr",
                "severity": "MEDIUM",
                "pkg": "league/commonmark",
                "installed": "2.8.3",
                "fixed": "2.9.0",
                "title": "league/commonmark: Denial of service via deeply nested XML output",
                "url": "https://github.com/advisories/GHSA-mj63-m3rc-8ppr",
                "targets": [
                  "var/www/html/vendor/composer/installed.json"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coolify-realtime",
      "name": "Coolify Realtime",
      "category": "PaaS",
      "summary": "Realtime server component of Coolify, providing the websocket connections and terminal/log gateway for the dashboard. Licensed AGPL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0+",
      "licenseClean": "agpl",
      "version": "1.0.16",
      "versions": [
        {
          "version": "1.0.16",
          "size": "99.6 MB",
          "published": "2026-07-28T09:49:08Z",
          "digest": "sha256:1a9514a1e15cf9901cc2f93817a26bcc34a4838b2f033778fbae49207f1201fd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/coollabsio/coolify",
      "source": "https://github.com/coollabsio/coolify",
      "image": "ghcr.io/quenchworks/images/coolify-realtime",
      "knownIssue": "Holds 1 Medium CVE (cloudflared CVE-2026-41178). The fix is cloudflared 2026.6.1-r2, not yet in Wolfi (newest is the vulnerable 2026.5.2-r2), so a rebuild cannot clear it. A new release follows as soon as Wolfi ships the patched cloudflared.",
      "security": {
        "image": "ghcr.io/quenchworks/images/coolify-realtime",
        "version": "1.0.16",
        "tag": "ghcr.io/quenchworks/images/coolify-realtime:1.0.16",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 1,
        "unknown": 1,
        "total": 5,
        "fixable": 3,
        "grade": "D",
        "score": 58,
        "cves": [
          {
            "id": "CVE-2026-69152",
            "severity": "HIGH",
            "pkg": "brace-expansion",
            "installed": "5.0.8",
            "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
            "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-5p4m-2wfm-xmqj",
            "severity": "HIGH",
            "pkg": "js-yaml",
            "installed": "4.3.0",
            "fixed": "4.3.1, 3.15.1",
            "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
            "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/coolify-realtime@sha256:1a9514a1e15cf9901cc2f93817a26bcc34a4838b2f033778fbae49207f1201fd (wolfi 20230201)"
            ]
          },
          {
            "id": "GHSA-j965-2qgj-vjmq",
            "severity": "LOW",
            "pkg": "aws-sdk",
            "installed": "2.1426.0",
            "fixed": null,
            "title": "JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3",
            "url": "https://github.com/advisories/GHSA-j965-2qgj-vjmq",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cloudflared"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.0.16",
            "tag": "ghcr.io/quenchworks/images/coolify-realtime:1.0.16",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 1,
            "unknown": 1,
            "total": 5,
            "fixable": 3,
            "grade": "D",
            "score": 58,
            "cves": [
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-5p4m-2wfm-xmqj",
                "severity": "HIGH",
                "pkg": "js-yaml",
                "installed": "4.3.0",
                "fixed": "4.3.1, 3.15.1",
                "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
                "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/coolify-realtime@sha256:1a9514a1e15cf9901cc2f93817a26bcc34a4838b2f033778fbae49207f1201fd (wolfi 20230201)"
                ]
              },
              {
                "id": "GHSA-j965-2qgj-vjmq",
                "severity": "LOW",
                "pkg": "aws-sdk",
                "installed": "2.1426.0",
                "fixed": null,
                "title": "JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3",
                "url": "https://github.com/advisories/GHSA-j965-2qgj-vjmq",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cloudflared"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coredns",
      "name": "coredns",
      "category": "Coordination",
      "summary": "Fast, flexible DNS server that chains plugins to serve DNS and service discovery, the default cluster DNS for Kubernetes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.14.6",
      "versions": [
        {
          "version": "1.14.6",
          "size": "23.1 MB",
          "published": "2026-07-22T06:57:32Z",
          "digest": "sha256:cc733bae7b57919437ee0c306ef066419d742ef5ffb71e81254cd760f813a477"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://coredns.io",
      "source": "https://github.com/coredns/coredns",
      "image": "ghcr.io/quenchworks/images/coredns",
      "security": {
        "image": "ghcr.io/quenchworks/images/coredns",
        "version": "1.14.6",
        "tag": "ghcr.io/quenchworks/images/coredns:1.14.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/coredns"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.14.6",
            "tag": "ghcr.io/quenchworks/images/coredns:1.14.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/coredns"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coroot",
      "name": "coroot",
      "category": "Observability",
      "summary": "Coroot — open-source observability/APM (eBPF-based metrics, logs, traces, cost insights and service maps) with an embedded Vue UI. Built from source on Wolfi (go:embedded frontend, cgo lz4), prometheus/ch-go bumped to their fixed lines. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.23.3",
      "versions": [
        {
          "version": "1.23.3",
          "size": "26.0 MB",
          "published": "2026-07-22T08:29:02Z",
          "digest": "sha256:4ca63d624cc8462c9844fc92319fe53b746fe355403f3f2332354357fb93b0f8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://coroot.com",
      "source": "https://github.com/coroot/coroot",
      "image": "ghcr.io/quenchworks/images/coroot",
      "security": {
        "image": "ghcr.io/quenchworks/images/coroot",
        "version": "1.23.3",
        "tag": "ghcr.io/quenchworks/images/coroot:1.23.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/coroot"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.23.3",
            "tag": "ghcr.io/quenchworks/images/coroot:1.23.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/coroot"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cosign",
      "name": "cosign",
      "category": "Security & supply chain",
      "summary": "Sigstore's container-signing CLI. Keyless sign and verify of images, SBOMs, and attestations against the Fulcio/Rekor transparency log. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.1.2",
      "versions": [
        {
          "version": "3.1.2",
          "size": "30.2 MB",
          "published": "2026-07-22T06:59:07Z",
          "digest": "sha256:5d9e41e1b8cdec4884cc3dfac5c969029ba85805c438fc42f9c0c17719e17157"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.sigstore.dev",
      "source": "https://github.com/sigstore/cosign",
      "image": "ghcr.io/quenchworks/images/cosign",
      "security": {
        "image": "ghcr.io/quenchworks/images/cosign",
        "version": "3.1.2",
        "tag": "ghcr.io/quenchworks/images/cosign:3.1.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cosign"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.1.2",
            "tag": "ghcr.io/quenchworks/images/cosign:3.1.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cosign"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cosmian-kms",
      "name": "cosmian-kms",
      "category": "Secrets",
      "summary": "KMIP 2.1 key management server with PKCS#11 and Google/Microsoft CSE support -- the only KMIP speaker in this catalog. Shipped under BUSL-1.1, which is NOT OSI-approved AND caps production use at 2 vCPUs (1 physical core) while barring third-party offering; read the licence before deploying. Built non-FIPS against Wolfi's OpenSSL, so it is NOT FIPS 140-3 validated despite upstream's description.",
      "tier": "low",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "5.24.0, 5.25.0, 5.23.0",
      "versions": [
        {
          "version": "5.24.0",
          "size": "15.1 MB",
          "published": "2026-08-04T10:43:44Z",
          "digest": "sha256:aa9464a418f5c53e4951a0ac76072089c7278c122e25f4bd48deb930d293c03f"
        },
        {
          "version": "5.25.0",
          "size": "15.4 MB",
          "published": "2026-08-04T10:43:39Z",
          "digest": "sha256:ed05b34f42b3b6ec9642a4a15a79bae35848c533d85f993dd02f9685d0bcabf0"
        },
        {
          "version": "5.23.0",
          "size": "15.0 MB",
          "published": "2026-08-04T10:43:35Z",
          "digest": "sha256:dfa02fb06c836ee2be5ec6187ea61d823e0e1e6e54b84fc88cbb2a1d572793fc"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/Cosmian/kms",
      "source": "https://github.com/Cosmian/kms",
      "image": "ghcr.io/quenchworks/images/cosmian-kms",
      "caution": true,
      "security": {
        "image": "ghcr.io/quenchworks/images/cosmian-kms",
        "version": "5.25.0",
        "tag": "ghcr.io/quenchworks/images/cosmian-kms:5.25.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.25.0",
            "tag": "ghcr.io/quenchworks/images/cosmian-kms:5.25.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.24.0",
            "tag": "ghcr.io/quenchworks/images/cosmian-kms:5.24.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.23.0",
            "tag": "ghcr.io/quenchworks/images/cosmian-kms:5.23.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "couchdb",
      "name": "CouchDB",
      "category": "Document",
      "summary": "Document database with an HTTP/JSON API and multi-master replication, designed for offline-first sync across nodes and devices.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.4.3, 3.5.1, 3.5.2",
      "versions": [
        {
          "version": "3.4.3",
          "size": "123.7 MB",
          "published": "2026-07-04T10:43:31Z",
          "digest": "sha256:3d86508017bae7570dd518994194228fa26fafec988c77b8484050933de3ae20"
        },
        {
          "version": "3.5.1",
          "size": "127.2 MB",
          "published": "2026-07-04T10:42:03Z",
          "digest": "sha256:7bee1b27171ca553ea16ecef7bf91b6303f9e17928f0b7cb2c9c6463e7399128"
        },
        {
          "version": "3.5.2",
          "size": "126.9 MB",
          "published": "2026-07-04T10:34:36Z",
          "digest": "sha256:e654f0c3753e9bbc2ed975b07f447a48d3fe963bcb6e4e2f1627f3efcf11a524"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/couchdb",
      "source": "https://github.com/apache/couchdb",
      "image": "ghcr.io/quenchworks/images/couchdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/couchdb",
        "version": "3.5.2",
        "tag": "ghcr.io/quenchworks/images/couchdb:3.5.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.5.2",
            "tag": "ghcr.io/quenchworks/images/couchdb:3.5.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.5.1",
            "tag": "ghcr.io/quenchworks/images/couchdb:3.5.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.4.3",
            "tag": "ghcr.io/quenchworks/images/couchdb:3.4.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "crossplane",
      "name": "crossplane",
      "category": "GitOps",
      "summary": "Crossplane, the CNCF control-plane framework that turns Kubernetes into a universal API for infrastructure. Installs Providers, Functions and Configurations as OCI packages, and lets platform teams publish their own composite APIs from CompositeResourceDefinitions and Compositions.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.3.4, 2.1.8, 2.2.4",
      "versions": [
        {
          "version": "2.3.4",
          "size": "21.7 MB",
          "published": "2026-07-28T06:21:00Z",
          "digest": "sha256:8d6341bf870f28c451523991b9ad8248a50deab2fdc6b5987762bfc59f22d5e7"
        },
        {
          "version": "2.1.8",
          "size": "22.1 MB",
          "published": "2026-07-28T06:20:40Z",
          "digest": "sha256:65b7d50d3d7fe86e8a9c28d44011658b2480f6a1aa374f43994dcecd79fb5b21"
        },
        {
          "version": "2.2.4",
          "size": "21.7 MB",
          "published": "2026-07-28T06:17:59Z",
          "digest": "sha256:c65a7d1c0723f62a56629831d4c770cd44ebd1e598c630a5d7cb1442f20c036b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://crossplane.io",
      "source": "https://github.com/crossplane/crossplane",
      "image": "ghcr.io/quenchworks/images/crossplane",
      "security": {
        "image": "ghcr.io/quenchworks/images/crossplane",
        "version": "2.3.4",
        "tag": "ghcr.io/quenchworks/images/crossplane:2.3.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 2,
        "fixable": 1,
        "grade": "B",
        "score": 92,
        "cves": [
          {
            "id": "CVE-2026-54787",
            "severity": "LOW",
            "pkg": "github.com/sigstore/sigstore-go",
            "installed": "v1.2.0",
            "fixed": "1.2.1",
            "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
            "targets": [
              "usr/bin/crossplane"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/crossplane"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.3.4",
            "tag": "ghcr.io/quenchworks/images/crossplane:2.3.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "B",
            "score": 92,
            "cves": [
              {
                "id": "CVE-2026-54787",
                "severity": "LOW",
                "pkg": "github.com/sigstore/sigstore-go",
                "installed": "v1.2.0",
                "fixed": "1.2.1",
                "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
                "targets": [
                  "usr/bin/crossplane"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/crossplane"
                ]
              }
            ]
          },
          {
            "version": "2.2.4",
            "tag": "ghcr.io/quenchworks/images/crossplane:2.2.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "B",
            "score": 92,
            "cves": [
              {
                "id": "CVE-2026-54787",
                "severity": "LOW",
                "pkg": "github.com/sigstore/sigstore-go",
                "installed": "v1.2.0",
                "fixed": "1.2.1",
                "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
                "targets": [
                  "usr/bin/crossplane"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/crossplane"
                ]
              }
            ]
          },
          {
            "version": "2.1.8",
            "tag": "ghcr.io/quenchworks/images/crossplane:2.1.8",
            "critical": 1,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 3,
            "fixable": 1,
            "grade": "F",
            "score": 67,
            "cves": [
              {
                "id": "GHSA-wfqx-gjrf-g28r",
                "severity": "CRITICAL",
                "pkg": "github.com/crossplane/crossplane/v2",
                "installed": "v2.1.8",
                "fixed": null,
                "title": "Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag",
                "url": "https://github.com/advisories/GHSA-wfqx-gjrf-g28r",
                "targets": [
                  "usr/bin/crossplane"
                ]
              },
              {
                "id": "CVE-2026-54787",
                "severity": "LOW",
                "pkg": "github.com/sigstore/sigstore-go",
                "installed": "v1.2.0",
                "fixed": "1.2.1",
                "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
                "targets": [
                  "usr/bin/crossplane"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/crossplane"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "deno",
      "name": "deno",
      "category": "Language runtime",
      "summary": "Hardened Deno runtime for JavaScript and TypeScript, secure by default with explicit permissions and built-in tooling. Latest stable (2).",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.9.4",
      "versions": [
        {
          "version": "2.9.4",
          "size": "47.9 MB",
          "published": "2026-07-26T12:25:52Z",
          "digest": "sha256:2185617879a11ca56dab581e7ecf5527f6c0c83f9f0a719d9751abbafda4733a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/denoland/deno",
      "source": "https://github.com/denoland/deno",
      "image": "ghcr.io/quenchworks/images/deno",
      "security": {
        "image": "ghcr.io/quenchworks/images/deno",
        "version": "2.9.4",
        "tag": "ghcr.io/quenchworks/images/deno:2.9.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.9.4",
            "tag": "ghcr.io/quenchworks/images/deno:2.9.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "descheduler",
      "name": "descheduler",
      "category": "Coordination",
      "summary": "Kubernetes descheduler that evicts pods so the scheduler can re-place them for better cluster balance. Single static Go binary on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.36.0",
      "versions": [
        {
          "version": "0.36.0",
          "size": "21.8 MB",
          "published": "2026-07-26T12:24:50Z",
          "digest": "sha256:184afaae471b6635fb26741d2829914d7f49c1bf1955cab5af32d335ab4fe534"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/kubernetes-sigs/descheduler",
      "source": "https://github.com/kubernetes-sigs/descheduler",
      "image": "ghcr.io/quenchworks/images/descheduler",
      "security": {
        "image": "ghcr.io/quenchworks/images/descheduler",
        "version": "0.36.0",
        "tag": "ghcr.io/quenchworks/images/descheduler:0.36.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/descheduler"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.36.0",
            "tag": "ghcr.io/quenchworks/images/descheduler:0.36.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/descheduler"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "dex",
      "name": "dex",
      "category": "Identity",
      "summary": "Federated OpenID Connect (OIDC) identity provider. Acts as a portal to other identity providers (LDAP, SAML, GitHub, Google, OIDC) and issues OIDC tokens to apps and Kubernetes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.45.1",
      "versions": [
        {
          "version": "2.45.1",
          "size": "17.0 MB",
          "published": "2026-07-22T07:33:08Z",
          "digest": "sha256:d2e9efd7188d66b120d975effdbb3d950945a921b0c69642f4151b53c5febe1e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://dexidp.io",
      "source": "https://github.com/dexidp/dex",
      "image": "ghcr.io/quenchworks/images/dex",
      "security": {
        "image": "ghcr.io/quenchworks/images/dex",
        "version": "2.45.1",
        "tag": "ghcr.io/quenchworks/images/dex:2.45.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/dex"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.45.1",
            "tag": "ghcr.io/quenchworks/images/dex:2.45.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/dex"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "distribution",
      "name": "distribution",
      "category": "Registry",
      "summary": "The CNCF reference OCI and Docker registry server for storing and distributing container images and other OCI artifacts.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.1.1",
      "versions": [
        {
          "version": "3.1.1",
          "size": "16.2 MB",
          "published": "2026-07-22T08:27:05Z",
          "digest": "sha256:d36575774b4742443ac5c4296b443f4b394caaf4340070d8fae6ca1378321de3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://distribution.github.io/distribution",
      "source": "https://github.com/distribution/distribution",
      "image": "ghcr.io/quenchworks/images/distribution",
      "security": {
        "image": "ghcr.io/quenchworks/images/distribution",
        "version": "3.1.1",
        "tag": "ghcr.io/quenchworks/images/distribution:3.1.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/registry"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.1.1",
            "tag": "ghcr.io/quenchworks/images/distribution:3.1.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/registry"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "documentdb",
      "name": "DocumentDB",
      "category": "Document",
      "summary": "Self-contained MongoDB-compatible server bundling PostgreSQL, the DocumentDB extension, and a wire gateway. Linux Foundation project, truly open under MIT.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.112.0, 0.114.0, 0.113.0",
      "versions": [
        {
          "version": "0.112.0",
          "size": "141.6 MB",
          "published": "2026-07-21T08:44:20Z",
          "digest": "sha256:6e4cd0ed68c07b8a6d4cb12a9e45d3544c45bab20d2282c47c85be30afe18c48"
        },
        {
          "version": "0.114.0",
          "size": "141.7 MB",
          "published": "2026-07-21T08:43:47Z",
          "digest": "sha256:bff5b31492f4c5fff162eb053d1f97cd6ddabd17deba967f4294b5096cdf21ca"
        },
        {
          "version": "0.113.0",
          "size": "141.8 MB",
          "published": "2026-07-21T08:41:31Z",
          "digest": "sha256:f08e3a64e8c1367858e6b75c99888fca1d0a990b4a4e8607f134fb07f5f55ad8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/documentdb/documentdb",
      "source": "https://github.com/documentdb/documentdb",
      "image": "ghcr.io/quenchworks/images/documentdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/documentdb",
        "version": "0.114.0",
        "tag": "ghcr.io/quenchworks/images/documentdb:0.114.0",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "C",
        "score": 91,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/documentdb@sha256:bff5b31492f4c5fff162eb053d1f97cd6ddabd17deba967f4294b5096cdf21ca (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.114.0",
            "tag": "ghcr.io/quenchworks/images/documentdb:0.114.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/documentdb@sha256:bff5b31492f4c5fff162eb053d1f97cd6ddabd17deba967f4294b5096cdf21ca (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "0.113.0",
            "tag": "ghcr.io/quenchworks/images/documentdb:0.113.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/documentdb@sha256:f08e3a64e8c1367858e6b75c99888fca1d0a990b4a4e8607f134fb07f5f55ad8 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "0.112.0",
            "tag": "ghcr.io/quenchworks/images/documentdb:0.112.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/documentdb@sha256:6e4cd0ed68c07b8a6d4cb12a9e45d3544c45bab20d2282c47c85be30afe18c48 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "dotnet",
      "name": "dotnet",
      "category": "Language runtime",
      "summary": "Hardened .NET SDK for building and running .NET apps. Use as a build base; ships the current LTS line (10). Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "10.0.110",
      "versions": [
        {
          "version": "10.0.110",
          "size": "271.1 MB",
          "published": "2026-07-21T06:45:16Z",
          "digest": "sha256:1344024b5aaec97b041139fae3a10243e50cc7fb3c2e2221734ae532f69ec555"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dotnet/runtime",
      "source": "https://github.com/dotnet/runtime",
      "image": "ghcr.io/quenchworks/images/dotnet",
      "security": {
        "image": "ghcr.io/quenchworks/images/dotnet",
        "version": "10.0.110",
        "tag": "ghcr.io/quenchworks/images/dotnet:10.0.110",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "10.0.110",
            "tag": "ghcr.io/quenchworks/images/dotnet:10.0.110",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "dotnet-runtime",
      "name": "dotnet-runtime",
      "category": "Runtime base",
      "summary": "Hardened .NET runtime for console and worker apps, no SDK. Build on the dotnet image, then run here. Lines 8/9/10.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "9.0.119, 10.0.110, 8.0.127",
      "versions": [
        {
          "version": "9.0.119",
          "size": "60.1 MB",
          "published": "2026-07-21T08:34:16Z",
          "digest": "sha256:dca9d090e85b0138a9c849f41d1a404aa37a311bd0267ceb2ba93569360599c9"
        },
        {
          "version": "10.0.110",
          "size": "61.1 MB",
          "published": "2026-07-15T11:18:10Z",
          "digest": "sha256:2b76fa8aa868f08d2b63b24032970b3a34e3ce6592b7a82258b231c74eb39b76"
        },
        {
          "version": "8.0.127",
          "size": "56.9 MB",
          "published": "2026-07-15T11:17:45Z",
          "digest": "sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dotnet/runtime",
      "source": "https://github.com/dotnet/runtime",
      "image": "ghcr.io/quenchworks/images/dotnet-runtime",
      "security": {
        "image": "ghcr.io/quenchworks/images/dotnet-runtime",
        "version": "10.0.110",
        "tag": "ghcr.io/quenchworks/images/dotnet-runtime:10.0.110",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "10.0.110",
            "tag": "ghcr.io/quenchworks/images/dotnet-runtime:10.0.110",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.0.119",
            "tag": "ghcr.io/quenchworks/images/dotnet-runtime:9.0.119",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.127",
            "tag": "ghcr.io/quenchworks/images/dotnet-runtime:8.0.127",
            "critical": 2,
            "high": 6,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 8,
            "fixable": 8,
            "grade": "F",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "dragonfly",
      "name": "Dragonfly",
      "category": "Cache",
      "summary": "Multi-threaded, Redis- and Memcached-compatible in-memory datastore built to scale vertically on one node. BUSL is source-available, not open source; prefer Valkey (BSD-3-Clause).",
      "tier": "low",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "1.39.0, 1.37.2, 1.38.1",
      "versions": [
        {
          "version": "1.39.0",
          "size": "25.1 MB",
          "published": "2026-07-04T11:23:08Z",
          "digest": "sha256:9950a9aae3bd7292ceac904508f7ce9002c0cd76e959711b8364ab23e9751c74"
        },
        {
          "version": "1.37.2",
          "size": "23.6 MB",
          "published": "2026-07-04T11:09:36Z",
          "digest": "sha256:41b890dea153917121fdf475e26858d60e4b5aa87231f3aa23d588006f93272e"
        },
        {
          "version": "1.38.1",
          "size": "24.5 MB",
          "published": "2026-07-04T11:02:36Z",
          "digest": "sha256:5fcf14a620578357d6329b76d61558c402f4f648814e37e5f767da161ba0b83e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dragonflydb/dragonfly",
      "source": "https://github.com/dragonflydb/dragonfly",
      "image": "ghcr.io/quenchworks/images/dragonfly",
      "caution": true,
      "cleanAlternative": "Valkey (BSD-3-Clause) — the truly-open Redis-compatible cache.",
      "security": {
        "image": "ghcr.io/quenchworks/images/dragonfly",
        "version": "1.39.0",
        "tag": "ghcr.io/quenchworks/images/dragonfly:1.39.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.39.0",
            "tag": "ghcr.io/quenchworks/images/dragonfly:1.39.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.38.1",
            "tag": "ghcr.io/quenchworks/images/dragonfly:1.38.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.37.2",
            "tag": "ghcr.io/quenchworks/images/dragonfly:1.37.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "drupal",
      "name": "drupal",
      "category": "Apps & productivity",
      "summary": "Drupal core, the open-source CMS and content framework. Built from the official release tarball on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs, supervisord); the chart supplies settings.php via ConfigMap and a MySQL backend. Ships the 11.3/11.4 lines (11.2 is held because drupal/core-recommended pins guzzle below its CVE fix).",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0+",
      "licenseClean": "clean",
      "version": "11.4.4",
      "versions": [
        {
          "version": "11.4.4",
          "size": "68.5 MB",
          "published": "2026-07-26T12:21:01Z",
          "digest": "sha256:23aa2bdb493cedda7c0d64d0f3f423d463f65e55abbed1bbfd45066ec8976eb0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.drupal.org",
      "source": "https://ftp.drupal.org/files/projects/drupal-11.4.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/drupal",
      "security": {
        "image": "ghcr.io/quenchworks/images/drupal",
        "version": "11.4.4",
        "tag": "ghcr.io/quenchworks/images/drupal:11.4.4",
        "critical": 0,
        "high": 1,
        "medium": 2,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "D",
        "score": 67,
        "cves": [
          {
            "id": "CVE-2026-69246",
            "severity": "HIGH",
            "pkg": "guzzlehttp/guzzle",
            "installed": "7.15.1",
            "fixed": "7.15.2, 8.0.1",
            "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69246",
            "targets": [
              "opt/drupal/vendor/composer/installed.json"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/drupal@sha256:23aa2bdb493cedda7c0d64d0f3f423d463f65e55abbed1bbfd45066ec8976eb0 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-69245",
            "severity": "MEDIUM",
            "pkg": "guzzlehttp/guzzle",
            "installed": "7.15.1",
            "fixed": "7.15.2, 8.0.1",
            "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69245",
            "targets": [
              "opt/drupal/vendor/composer/installed.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "11.4.4",
            "tag": "ghcr.io/quenchworks/images/drupal:11.4.4",
            "critical": 0,
            "high": 1,
            "medium": 2,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "D",
            "score": 67,
            "cves": [
              {
                "id": "CVE-2026-69246",
                "severity": "HIGH",
                "pkg": "guzzlehttp/guzzle",
                "installed": "7.15.1",
                "fixed": "7.15.2, 8.0.1",
                "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69246",
                "targets": [
                  "opt/drupal/vendor/composer/installed.json"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/drupal@sha256:23aa2bdb493cedda7c0d64d0f3f423d463f65e55abbed1bbfd45066ec8976eb0 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69245",
                "severity": "MEDIUM",
                "pkg": "guzzlehttp/guzzle",
                "installed": "7.15.1",
                "fixed": "7.15.2, 8.0.1",
                "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69245",
                "targets": [
                  "opt/drupal/vendor/composer/installed.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "duckdb",
      "name": "duckdb",
      "category": "Databases & engines",
      "summary": "In-process analytical SQL database CLI, shipped from upstream's official precompiled binary. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.4.5, 1.3.2, 1.5.5",
      "versions": [
        {
          "version": "1.4.5",
          "size": "24.0 MB",
          "published": "2026-07-22T11:26:53Z",
          "digest": "sha256:303854cd4dd30e096246acff369b3458f6164d2aa1a3e6f7f0d3b77aad48091f"
        },
        {
          "version": "1.3.2",
          "size": "22.6 MB",
          "published": "2026-07-22T11:26:49Z",
          "digest": "sha256:fdcdecf75bcdcadec3de817432cc40fbeb9ee636646f2a3764eb709dcb6e8e58"
        },
        {
          "version": "1.5.5",
          "size": "26.2 MB",
          "published": "2026-07-22T11:26:49Z",
          "digest": "sha256:694ada7b706ca5b8142885ecfac8cf47e72946fcedb759dcebdf21384aa42bda"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://duckdb.org",
      "source": "https://github.com/duckdb/duckdb",
      "image": "ghcr.io/quenchworks/images/duckdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/duckdb",
        "version": "1.5.5",
        "tag": "ghcr.io/quenchworks/images/duckdb:1.5.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.5.5",
            "tag": "ghcr.io/quenchworks/images/duckdb:1.5.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.4.5",
            "tag": "ghcr.io/quenchworks/images/duckdb:1.4.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.3.2",
            "tag": "ghcr.io/quenchworks/images/duckdb:1.3.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "elasticsearch",
      "name": "Elasticsearch",
      "category": "Search",
      "summary": "Distributed search and analytics engine. Shipped under SSPL/Elastic License, which are not OSI-approved; OpenSearch (Apache-2.0) is the open drop-in fork.",
      "tier": "low",
      "status": "available",
      "license": "SSPL-1.0",
      "licenseClean": "caution",
      "version": "9.4.4",
      "versions": [
        {
          "version": "9.4.4",
          "size": "639.6 MB",
          "published": "2026-07-26T12:24:29Z",
          "digest": "sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/elastic/elasticsearch",
      "source": "https://github.com/elastic/elasticsearch",
      "image": "ghcr.io/quenchworks/images/elasticsearch",
      "caution": true,
      "cleanAlternative": "OpenSearch (Apache-2.0) — the open drop-in fork of Elasticsearch.",
      "security": {
        "image": "ghcr.io/quenchworks/images/elasticsearch",
        "version": "9.4.4",
        "tag": "ghcr.io/quenchworks/images/elasticsearch:9.4.4",
        "critical": 0,
        "high": 0,
        "medium": 3,
        "low": 1,
        "unknown": 0,
        "total": 4,
        "fixable": 4,
        "grade": "C",
        "score": 67,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/elasticsearch@sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/elasticsearch@sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71497",
            "severity": "MEDIUM",
            "pkg": "org.jsoup:jsoup",
            "installed": "1.21.2",
            "fixed": "1.23.1",
            "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/elasticsearch@sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "9.4.4",
            "tag": "ghcr.io/quenchworks/images/elasticsearch:9.4.4",
            "critical": 0,
            "high": 0,
            "medium": 3,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 4,
            "grade": "C",
            "score": 67,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/elasticsearch@sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/elasticsearch@sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71497",
                "severity": "MEDIUM",
                "pkg": "org.jsoup:jsoup",
                "installed": "1.21.2",
                "fixed": "1.23.1",
                "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/elasticsearch@sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "elixir",
      "name": "elixir",
      "category": "Language runtime",
      "summary": "Hardened Elixir runtime on the BEAM VM, built on Erlang/OTP, for concurrent, fault-tolerant apps (e.g. Phoenix). Latest stable (1.18).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.4, 1.19.5, 1.17.3",
      "versions": [
        {
          "version": "1.18.4",
          "size": "60.6 MB",
          "published": "2026-07-04T10:16:31Z",
          "digest": "sha256:399f63fd8bdc481f72455245c4dfc33d2ef2230aa63302cf874004b295fe33d8"
        },
        {
          "version": "1.19.5",
          "size": "68.9 MB",
          "published": "2026-07-04T10:16:23Z",
          "digest": "sha256:7424aca74824c1a1aa836fa43380fccbf1f01dfa984fba6e7cbb1dfef544e071"
        },
        {
          "version": "1.17.3",
          "size": "61.0 MB",
          "published": "2026-07-04T10:11:58Z",
          "digest": "sha256:8654bfd5f0578aa3bb6fc87378c813027fa315a3cb71b131994d9ed5acc71e02"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://elixir-lang.org",
      "source": "https://elixir-lang.org",
      "image": "ghcr.io/quenchworks/images/elixir",
      "security": {
        "image": "ghcr.io/quenchworks/images/elixir",
        "version": "1.19.5",
        "tag": "ghcr.io/quenchworks/images/elixir:1.19.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.19.5",
            "tag": "ghcr.io/quenchworks/images/elixir:1.19.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.18.4",
            "tag": "ghcr.io/quenchworks/images/elixir:1.18.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.17.3",
            "tag": "ghcr.io/quenchworks/images/elixir:1.17.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "emqx",
      "name": "emqx",
      "category": "Messaging",
      "summary": "Massively scalable, distributed MQTT broker for IoT, IIoT, and connected vehicles. Speaks MQTT 5.0 over TCP/TLS/websockets with a clustering engine and a web dashboard. Packaged from EMQX's official Erlang/OTP release. Licensed BSL 1.1 (single node free; clustering requires a commercial license).",
      "tier": "standard",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "6.2.2",
      "versions": [
        {
          "version": "6.2.2",
          "size": "125.8 MB",
          "published": "2026-07-05T10:11:30Z",
          "digest": "sha256:618646bdf882cff28aee50ca1ecaf196f7c5ade15c52d9ead72fc0e8c3070819"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.emqx.io",
      "source": "https://github.com/emqx/emqx",
      "image": "ghcr.io/quenchworks/images/emqx",
      "caution": true,
      "security": {
        "image": "ghcr.io/quenchworks/images/emqx",
        "version": "6.2.2",
        "tag": "ghcr.io/quenchworks/images/emqx:6.2.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "6.2.2",
            "tag": "ghcr.io/quenchworks/images/emqx:6.2.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "envoy",
      "name": "envoy",
      "category": "Gateway",
      "summary": "Cloud-native L7 proxy and communication bus, the data plane behind API gateways and service meshes. HTTP/gRPC routing, load balancing, rich observability, and an admin/health endpoint. The chart supplies the bootstrap config.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.37.1, 1.36.4, 1.38.1",
      "versions": [
        {
          "version": "1.37.1",
          "size": "41.7 MB",
          "published": "2026-07-04T11:00:56Z",
          "digest": "sha256:44923be0d745883de4e65533e5b86b7d6e2961202752eafb3a4d5f9070c8956a"
        },
        {
          "version": "1.36.4",
          "size": "39.9 MB",
          "published": "2026-07-04T10:57:05Z",
          "digest": "sha256:a5ebe3c301a3f70656bf3112d1b81251c176fd1433f7e17dad5c702b83d02156"
        },
        {
          "version": "1.38.1",
          "size": "46.3 MB",
          "published": "2026-07-04T10:53:49Z",
          "digest": "sha256:99cf0132c2d9521d564329f78512f5ba521d8e147a824bf64f3c27352efbc0af"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.envoyproxy.io",
      "source": "https://github.com/envoyproxy/envoy",
      "image": "ghcr.io/quenchworks/images/envoy",
      "security": {
        "image": "ghcr.io/quenchworks/images/envoy",
        "version": "1.38.1",
        "tag": "ghcr.io/quenchworks/images/envoy:1.38.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.38.1",
            "tag": "ghcr.io/quenchworks/images/envoy:1.38.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.37.1",
            "tag": "ghcr.io/quenchworks/images/envoy:1.37.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.36.4",
            "tag": "ghcr.io/quenchworks/images/envoy:1.36.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "erlang",
      "name": "erlang",
      "category": "Language runtime",
      "summary": "Hardened Erlang/OTP runtime on the BEAM VM, built for highly concurrent, fault-tolerant systems. Latest stable lines (27/28/29).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "28.5.0.4, 29.0.4, 27.3.4.15",
      "versions": [
        {
          "version": "28.5.0.4",
          "size": "62.2 MB",
          "published": "2026-07-28T09:50:01Z",
          "digest": "sha256:cba731cb63b90509d4710ab0c511a7eb4cd43944297275d424cc80ebdfab64ae"
        },
        {
          "version": "29.0.4",
          "size": "63.1 MB",
          "published": "2026-07-28T09:49:58Z",
          "digest": "sha256:08f2067a6d8a00a61e4cfe889101fea175c671a2ae5dcf0d688a8ecc76bd55b3"
        },
        {
          "version": "27.3.4.15",
          "size": "61.0 MB",
          "published": "2026-07-28T09:49:54Z",
          "digest": "sha256:cb5e5479d0a7ddf3ca4ba9b89e5f29590c6a305272a1bc0f6a94e8d49a4ee43c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.erlang.org",
      "source": "https://www.erlang.org",
      "image": "ghcr.io/quenchworks/images/erlang",
      "security": {
        "image": "ghcr.io/quenchworks/images/erlang",
        "version": "29.0.4",
        "tag": "ghcr.io/quenchworks/images/erlang:29.0.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "29.0.4",
            "tag": "ghcr.io/quenchworks/images/erlang:29.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "28.5.0.4",
            "tag": "ghcr.io/quenchworks/images/erlang:28.5.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "27.3.4.15",
            "tag": "ghcr.io/quenchworks/images/erlang:27.3.4.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "etcd",
      "name": "etcd",
      "category": "Coordination",
      "summary": "Distributed, strongly consistent key-value store using Raft consensus. The backing store for Kubernetes and a building block for service coordination and config.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.7.1",
      "versions": [
        {
          "version": "3.7.1",
          "size": "21.5 MB",
          "published": "2026-07-26T12:23:04Z",
          "digest": "sha256:f3ddaeabc17db4deddc07aaf13a60351370a440934ecc929721a4a75e4f8282a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/etcd-io/etcd",
      "source": "https://github.com/etcd-io/etcd",
      "image": "ghcr.io/quenchworks/images/etcd",
      "security": {
        "image": "ghcr.io/quenchworks/images/etcd",
        "version": "3.7.1",
        "tag": "ghcr.io/quenchworks/images/etcd:3.7.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/etcd",
              "usr/bin/etcdutl"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.1",
            "tag": "ghcr.io/quenchworks/images/etcd:3.7.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/etcd",
                  "usr/bin/etcdutl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "excalidraw",
      "name": "excalidraw",
      "category": "Apps & productivity",
      "summary": "Open-source virtual whiteboard for sketching hand-drawn-style diagrams. Self-hostable as a static SPA served by hardened nginx, with no backend or account required.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.18.1",
      "versions": [
        {
          "version": "0.18.1",
          "size": "28.4 MB",
          "published": "2026-07-04T11:06:50Z",
          "digest": "sha256:85ccb1fd7b34146ffecc67c3ded9cf814200a01863bab9922213988e6bb2ff51"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://excalidraw.com",
      "source": "https://github.com/excalidraw/excalidraw",
      "image": "ghcr.io/quenchworks/images/excalidraw",
      "security": {
        "image": "ghcr.io/quenchworks/images/excalidraw",
        "version": "0.18.1",
        "tag": "ghcr.io/quenchworks/images/excalidraw:0.18.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.18.1",
            "tag": "ghcr.io/quenchworks/images/excalidraw:0.18.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "external-dns",
      "name": "external-dns",
      "category": "Coordination & mesh",
      "summary": "Synchronizes Kubernetes Services and Ingresses with DNS providers so records are managed automatically. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.21.0",
      "versions": [
        {
          "version": "0.21.0",
          "size": "33.6 MB",
          "published": "2026-07-22T08:31:03Z",
          "digest": "sha256:ab6c52b713655557868d2488025155c8d1c9c46bde51853725afabf2453b1ae4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kubernetes-sigs.github.io/external-dns/",
      "source": "https://github.com/kubernetes-sigs/external-dns",
      "image": "ghcr.io/quenchworks/images/external-dns",
      "security": {
        "image": "ghcr.io/quenchworks/images/external-dns",
        "version": "0.21.0",
        "tag": "ghcr.io/quenchworks/images/external-dns:0.21.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/external-dns"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.21.0",
            "tag": "ghcr.io/quenchworks/images/external-dns:0.21.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/external-dns"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "external-secrets",
      "name": "external-secrets",
      "category": "Security & supply chain",
      "summary": "External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into Kubernetes Secrets. The single controller binary also serves the webhook and cert-controller, with every provider compiled in.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.8.0",
      "versions": [
        {
          "version": "2.8.0",
          "size": "51.8 MB",
          "published": "2026-07-26T12:25:53Z",
          "digest": "sha256:103de9fbbcc8a4059bf216ad89562e358370605b46986ed21a48a79e5b7912e5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://external-secrets.io",
      "source": "https://github.com/external-secrets/external-secrets",
      "image": "ghcr.io/quenchworks/images/external-secrets",
      "security": {
        "image": "ghcr.io/quenchworks/images/external-secrets",
        "version": "2.8.0",
        "tag": "ghcr.io/quenchworks/images/external-secrets:2.8.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/external-secrets"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.8.0",
            "tag": "ghcr.io/quenchworks/images/external-secrets:2.8.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/external-secrets"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ferretdb",
      "name": "FerretDB",
      "category": "Document",
      "summary": "MongoDB-compatible document database that translates the MongoDB wire protocol onto PostgreSQL via the DocumentDB extension. The clean-license substitute for MongoDB.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.7.0",
      "versions": [
        {
          "version": "2.7.0",
          "size": "10.2 MB",
          "published": "2026-07-22T06:59:06Z",
          "digest": "sha256:f61e374207f05beb027f1d5360a7f9a9c504a80e08b0f0bf942a13de0f92c558"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/FerretDB/FerretDB",
      "source": "https://github.com/FerretDB/FerretDB",
      "image": "ghcr.io/quenchworks/images/ferretdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/ferretdb",
        "version": "2.7.0",
        "tag": "ghcr.io/quenchworks/images/ferretdb:2.7.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/ferretdb"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.7.0",
            "tag": "ghcr.io/quenchworks/images/ferretdb:2.7.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/ferretdb"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "filebrowser",
      "name": "filebrowser",
      "category": "Apps & productivity",
      "summary": "Web-based file manager with a built-in UI, users, and share links. From source (Vite UI embedded in a static Go binary) on a hardened nonroot Wolfi base; data and served roots are volumes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.63.18, 2.63.17",
      "versions": [
        {
          "version": "2.63.18",
          "size": "15.6 MB",
          "published": "2026-07-22T09:47:38Z",
          "digest": "sha256:b3f04c1b55124c83370b07fff02037e029fb7bd8b58a13af8b20ac352c11ab34"
        },
        {
          "version": "2.63.17",
          "size": "15.5 MB",
          "published": "2026-07-22T09:47:38Z",
          "digest": "sha256:3670cc55cdf28cd9fcb541bff747efd0f66ede4c8e702263135f32ca7d8a5942"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://filebrowser.org",
      "source": "https://github.com/filebrowser/filebrowser",
      "image": "ghcr.io/quenchworks/images/filebrowser",
      "security": {
        "image": "ghcr.io/quenchworks/images/filebrowser",
        "version": "2.63.18",
        "tag": "ghcr.io/quenchworks/images/filebrowser:2.63.18",
        "critical": 1,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 3,
        "fixable": 0,
        "grade": "F",
        "score": 72,
        "cves": [
          {
            "id": "CVE-2026-54089",
            "severity": "CRITICAL",
            "pkg": "github.com/filebrowser/filebrowser/v2",
            "installed": "2.63.18",
            "fixed": null,
            "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54089",
            "targets": [
              "usr/bin/filebrowser"
            ]
          },
          {
            "id": "CVE-2023-36308",
            "severity": "LOW",
            "pkg": "github.com/disintegration/imaging",
            "installed": "v1.6.2",
            "fixed": null,
            "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
            "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
            "targets": [
              "usr/bin/filebrowser"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/filebrowser"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.63.18",
            "tag": "ghcr.io/quenchworks/images/filebrowser:2.63.18",
            "critical": 1,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 3,
            "fixable": 0,
            "grade": "F",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-54089",
                "severity": "CRITICAL",
                "pkg": "github.com/filebrowser/filebrowser/v2",
                "installed": "2.63.18",
                "fixed": null,
                "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54089",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              }
            ]
          },
          {
            "version": "2.63.17",
            "tag": "ghcr.io/quenchworks/images/filebrowser:2.63.17",
            "critical": 1,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 3,
            "fixable": 0,
            "grade": "F",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-54089",
                "severity": "CRITICAL",
                "pkg": "github.com/filebrowser/filebrowser/v2",
                "installed": "2.63.17",
                "fixed": null,
                "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54089",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "floci",
      "name": "floci",
      "category": "Apps & productivity",
      "summary": "Local AWS cloud emulator and LocalStack Community successor, built from source into a Quarkus fast-jar on a hardened Wolfi JRE. The hardened image runs all 55 of Floci's in-process AWS services nonroot with no Docker socket, covering S3, DynamoDB, SQS, SNS, SES, IAM, STS, KMS, Secrets Manager, API Gateway, Cognito, Kinesis, CloudFormation, Step Functions, EventBridge, CloudWatch, Route53, and more. The 10 Docker-backed services (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune) need the host Docker socket plus root and are out of scope for this image.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.5.34",
      "versions": [
        {
          "version": "1.5.34",
          "size": "191.3 MB",
          "published": "2026-07-30T08:11:21Z",
          "digest": "sha256:176ab5fde8c4f515e7d1f6e1c88906d7bc0b37531e4c268ddca79c3819ad37e8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://floci.io",
      "source": "https://github.com/floci-io/floci",
      "image": "ghcr.io/quenchworks/images/floci",
      "security": {
        "image": "ghcr.io/quenchworks/images/floci",
        "version": "1.5.34",
        "tag": "ghcr.io/quenchworks/images/floci:1.5.34",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.5.34",
            "tag": "ghcr.io/quenchworks/images/floci:1.5.34",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "floci-full",
      "name": "floci-full",
      "category": "Apps & productivity",
      "summary": "Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune). Same from-source Quarkus build and 0-CVE Trivy gate as floci, but running root with a mounted /var/run/docker.sock is a node-root / container-escape surface, so use it only in trusted single-tenant dev or CI. The floci Helm chart selects this image via mode=full behind an explicit acknowledgeRisk gate. Image only, no separate chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.5.29",
      "versions": [
        {
          "version": "1.5.29",
          "size": "190.8 MB",
          "published": "2026-07-28T06:18:52Z",
          "digest": "sha256:de65e07d085d55a89b605c446f20de0076b187b712b644da5c69937f956f2ec4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://floci.io",
      "source": "https://github.com/floci-io/floci",
      "image": "ghcr.io/quenchworks/images/floci-full",
      "security": {
        "image": "ghcr.io/quenchworks/images/floci-full",
        "version": "1.5.29",
        "tag": "ghcr.io/quenchworks/images/floci-full:1.5.29",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "D",
        "score": 85,
        "cves": [
          {
            "id": "CVE-2026-50559",
            "severity": "HIGH",
            "pkg": "io.quarkus:quarkus-vertx-http",
            "installed": "3.36.0",
            "fixed": "3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3, 3.37.0",
            "title": "io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50559",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.5.29",
            "tag": "ghcr.io/quenchworks/images/floci-full:1.5.29",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "D",
            "score": 85,
            "cves": [
              {
                "id": "CVE-2026-50559",
                "severity": "HIGH",
                "pkg": "io.quarkus:quarkus-vertx-http",
                "installed": "3.36.0",
                "fixed": "3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3, 3.37.0",
                "title": "io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50559",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "fluent-bit",
      "name": "Fluent Bit",
      "category": "Observability",
      "summary": "Lightweight, fast log and metrics processor and forwarder for collecting, filtering, and shipping telemetry to many backends.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.0.9",
      "versions": [
        {
          "version": "5.0.9",
          "size": "35.2 MB",
          "published": "2026-07-05T10:15:33Z",
          "digest": "sha256:29822acfe2feb6d14a36aab8bf43bea8b6cb7191645640dcc012d30f6561345d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/fluent/fluent-bit",
      "source": "https://github.com/fluent/fluent-bit",
      "image": "ghcr.io/quenchworks/images/fluent-bit",
      "security": {
        "image": "ghcr.io/quenchworks/images/fluent-bit",
        "version": "5.0.9",
        "tag": "ghcr.io/quenchworks/images/fluent-bit:5.0.9",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.0.9",
            "tag": "ghcr.io/quenchworks/images/fluent-bit:5.0.9",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "forgejo",
      "name": "forgejo",
      "category": "Git",
      "summary": "Self-hosted lightweight Git forge (a community Gitea fork) with issues, PRs, CI, and packages. From source with the web UI embedded (no Node at runtime), CGO+static-musl SQLite, on a hardened nonroot Wolfi base; data lives on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0+",
      "licenseClean": "agpl",
      "version": "15.0.3",
      "versions": [
        {
          "version": "15.0.3",
          "size": "68.6 MB",
          "published": "2026-07-22T07:00:53Z",
          "digest": "sha256:9a899439937c7c6827d2f9d98ddb8c11868a12aa23019fb7b526cc70ebeb37b8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://forgejo.org",
      "source": "https://codeberg.org/forgejo/forgejo",
      "image": "ghcr.io/quenchworks/images/forgejo",
      "security": {
        "image": "ghcr.io/quenchworks/images/forgejo",
        "version": "15.0.3",
        "tag": "ghcr.io/quenchworks/images/forgejo:15.0.3",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 1,
        "grade": "C",
        "score": 89,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/forgejo@sha256:9a899439937c7c6827d2f9d98ddb8c11868a12aa23019fb7b526cc70ebeb37b8 (wolfi 20230201)"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/forgejo"
            ]
          }
        ],
        "versions": [
          {
            "version": "15.0.3",
            "tag": "ghcr.io/quenchworks/images/forgejo:15.0.3",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "C",
            "score": 89,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/forgejo@sha256:9a899439937c7c6827d2f9d98ddb8c11868a12aa23019fb7b526cc70ebeb37b8 (wolfi 20230201)"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/forgejo"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "garage",
      "name": "Garage",
      "category": "Object storage",
      "summary": "Lightweight, S3-compatible object store for small, self-hosted, geo-distributed deployments that stays available across node failures. Licensed AGPL; runs well on modest hardware.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2.2.0, 2.3.0, 2.1.0",
      "versions": [
        {
          "version": "2.2.0",
          "size": "23.3 MB",
          "published": "2026-07-04T11:06:18Z",
          "digest": "sha256:573110f6f81975d519f481b411ada4414ed5c0308ddaab8f3219e00e751f8b8d"
        },
        {
          "version": "2.3.0",
          "size": "29.7 MB",
          "published": "2026-07-04T10:56:19Z",
          "digest": "sha256:feb4e12d18725972ed9eb8a742367af18ecee8b2eaa6127f8294d9bf4a4ff55f"
        },
        {
          "version": "2.1.0",
          "size": "16.1 MB",
          "published": "2026-07-04T10:49:18Z",
          "digest": "sha256:bc32d4041a0939b0557e6ff77b8a9aa1263cb6741d3481e5b604973395f13732"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/deuxfleurs-org/garage",
      "source": "https://github.com/deuxfleurs-org/garage",
      "image": "ghcr.io/quenchworks/images/garage",
      "security": {
        "image": "ghcr.io/quenchworks/images/garage",
        "version": "2.3.0",
        "tag": "ghcr.io/quenchworks/images/garage:2.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.3.0",
            "tag": "ghcr.io/quenchworks/images/garage:2.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.2.0",
            "tag": "ghcr.io/quenchworks/images/garage:2.2.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/garage:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "ghost",
      "name": "ghost",
      "category": "Apps & productivity",
      "summary": "Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "6.55.0",
      "versions": [
        {
          "version": "6.55.0",
          "size": "182.8 MB",
          "published": "2026-08-02T08:53:50Z",
          "digest": "sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ghost.org",
      "source": "https://github.com/TryGhost/Ghost",
      "image": "ghcr.io/quenchworks/images/ghost",
      "security": {
        "image": "ghcr.io/quenchworks/images/ghost",
        "version": "6.55.0",
        "tag": "ghcr.io/quenchworks/images/ghost:6.55.0",
        "critical": 0,
        "high": 11,
        "medium": 13,
        "low": 1,
        "unknown": 0,
        "total": 25,
        "fixable": 20,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-13697",
            "severity": "HIGH",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "7.29.0, 8.9.0",
            "title": "undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives",
            "url": "https://avd.aquasec.com/nvd/cve-2026-13697",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-18446",
            "severity": "HIGH",
            "pkg": "fast-uri",
            "installed": "3.1.4",
            "fixed": "2.4.4, 3.1.5, 4.1.2",
            "title": "fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority",
            "url": "https://avd.aquasec.com/nvd/cve-2026-18446",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-58043",
            "severity": "HIGH",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
            "targets": [
              "ghcr.io/quenchworks/images/ghost@sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-67213",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.16",
            "fixed": "3.3.17, 5.1.6",
            "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69152",
            "severity": "HIGH",
            "pkg": "brace-expansion",
            "installed": "5.0.8",
            "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
            "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69192",
            "severity": "HIGH",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.3.1",
            "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-5p4m-2wfm-xmqj",
            "severity": "HIGH",
            "pkg": "js-yaml",
            "installed": "4.3.0",
            "fixed": "4.3.1, 3.15.1",
            "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
            "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2020-8203",
            "severity": "HIGH",
            "pkg": "lodash.pick",
            "installed": "4.4.0",
            "fixed": null,
            "title": "nodejs-lodash: prototype pollution in zipObjectDeep function",
            "url": "https://avd.aquasec.com/nvd/cve-2020-8203",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2022-37620",
            "severity": "HIGH",
            "pkg": "html-minifier",
            "installed": "4.0.0",
            "fixed": null,
            "title": "kangax html-minifier REDoS vulnerability",
            "url": "https://avd.aquasec.com/nvd/cve-2022-37620",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2025-71329",
            "severity": "HIGH",
            "pkg": "image-size",
            "installed": "1.2.1",
            "fixed": null,
            "title": "image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field",
            "url": "https://avd.aquasec.com/nvd/cve-2025-71329",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2025-71330",
            "severity": "HIGH",
            "pkg": "image-size",
            "installed": "1.2.1",
            "fixed": null,
            "title": "image-size: image-size: Denial of Service via crafted ICNS image buffer",
            "url": "https://avd.aquasec.com/nvd/cve-2025-71330",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-14643",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "7.29.0, 8.9.0",
            "title": "undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing",
            "url": "https://avd.aquasec.com/nvd/cve-2026-14643",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-15157",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
            "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-15157",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
            "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16728",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16728",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16729",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16729",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "7.28.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-54272",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.1",
            "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/ghost@sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-69198",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.2",
            "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-71498",
            "severity": "MEDIUM",
            "pkg": "re2",
            "installed": "1.25.2",
            "fixed": "1.26.1",
            "title": "node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71498",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-55q2-fjhq-7xh7",
            "severity": "MEDIUM",
            "pkg": "dompurify",
            "installed": "3.4.12",
            "fixed": "3.4.13",
            "title": "DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS",
            "url": "https://github.com/advisories/GHSA-55q2-fjhq-7xh7",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-984p-xq9m-4rjw",
            "severity": "MEDIUM",
            "pkg": "express-brute",
            "installed": "1.0.1",
            "fixed": null,
            "title": "Rate Limiting Bypass in express-brute",
            "url": "https://github.com/advisories/GHSA-984p-xq9m-4rjw",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56847",
            "severity": "LOW",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
            "targets": [
              "ghcr.io/quenchworks/images/ghost@sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "6.55.0",
            "tag": "ghcr.io/quenchworks/images/ghost:6.55.0",
            "critical": 0,
            "high": 11,
            "medium": 13,
            "low": 1,
            "unknown": 0,
            "total": 25,
            "fixable": 20,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-13697",
                "severity": "HIGH",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "7.29.0, 8.9.0",
                "title": "undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives",
                "url": "https://avd.aquasec.com/nvd/cve-2026-13697",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-18446",
                "severity": "HIGH",
                "pkg": "fast-uri",
                "installed": "3.1.4",
                "fixed": "2.4.4, 3.1.5, 4.1.2",
                "title": "fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority",
                "url": "https://avd.aquasec.com/nvd/cve-2026-18446",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/ghost@sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-67213",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.16",
                "fixed": "3.3.17, 5.1.6",
                "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69192",
                "severity": "HIGH",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.3.1",
                "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-5p4m-2wfm-xmqj",
                "severity": "HIGH",
                "pkg": "js-yaml",
                "installed": "4.3.0",
                "fixed": "4.3.1, 3.15.1",
                "title": "JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
                "url": "https://github.com/advisories/GHSA-5p4m-2wfm-xmqj",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2020-8203",
                "severity": "HIGH",
                "pkg": "lodash.pick",
                "installed": "4.4.0",
                "fixed": null,
                "title": "nodejs-lodash: prototype pollution in zipObjectDeep function",
                "url": "https://avd.aquasec.com/nvd/cve-2020-8203",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2022-37620",
                "severity": "HIGH",
                "pkg": "html-minifier",
                "installed": "4.0.0",
                "fixed": null,
                "title": "kangax html-minifier REDoS vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2022-37620",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2025-71329",
                "severity": "HIGH",
                "pkg": "image-size",
                "installed": "1.2.1",
                "fixed": null,
                "title": "image-size: image-size: Denial of Service via crafted image buffer with zero-valued size field",
                "url": "https://avd.aquasec.com/nvd/cve-2025-71329",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2025-71330",
                "severity": "HIGH",
                "pkg": "image-size",
                "installed": "1.2.1",
                "fixed": null,
                "title": "image-size: image-size: Denial of Service via crafted ICNS image buffer",
                "url": "https://avd.aquasec.com/nvd/cve-2025-71330",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-14643",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "7.29.0, 8.9.0",
                "title": "undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-14643",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "7.28.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-54272",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.1",
                "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/ghost@sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69198",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.2",
                "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-71498",
                "severity": "MEDIUM",
                "pkg": "re2",
                "installed": "1.25.2",
                "fixed": "1.26.1",
                "title": "node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71498",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-55q2-fjhq-7xh7",
                "severity": "MEDIUM",
                "pkg": "dompurify",
                "installed": "3.4.12",
                "fixed": "3.4.13",
                "title": "DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS",
                "url": "https://github.com/advisories/GHSA-55q2-fjhq-7xh7",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-984p-xq9m-4rjw",
                "severity": "MEDIUM",
                "pkg": "express-brute",
                "installed": "1.0.1",
                "fixed": null,
                "title": "Rate Limiting Bypass in express-brute",
                "url": "https://github.com/advisories/GHSA-984p-xq9m-4rjw",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/ghost@sha256:39498f8e00d8dd97671aeff171c202767270757e46a529ba890e5d831f7f85fe (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "gitea",
      "name": "Gitea",
      "category": "Git",
      "summary": "Lightweight self-hosted Git service with repositories, issues, pull requests, and built-in CI/CD (Actions). A low-footprint GitHub alternative.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.27.1",
      "versions": [
        {
          "version": "1.27.1",
          "size": "70.1 MB",
          "published": "2026-07-28T09:48:52Z",
          "digest": "sha256:affb9f2aabdce981a175f8b3f48bf1bc0ee71f3e94a7e808b33aca07c3e6dad0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/go-gitea/gitea",
      "source": "https://github.com/go-gitea/gitea",
      "image": "ghcr.io/quenchworks/images/gitea",
      "security": {
        "image": "ghcr.io/quenchworks/images/gitea",
        "version": "1.27.1",
        "tag": "ghcr.io/quenchworks/images/gitea:1.27.1",
        "critical": 0,
        "high": 1,
        "medium": 2,
        "low": 0,
        "unknown": 1,
        "total": 4,
        "fixable": 3,
        "grade": "D",
        "score": 65,
        "cves": [
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/gitea"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/gitea@sha256:affb9f2aabdce981a175f8b3f48bf1bc0ee71f3e94a7e808b33aca07c3e6dad0 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/gitea"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/gitea"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.27.1",
            "tag": "ghcr.io/quenchworks/images/gitea:1.27.1",
            "critical": 0,
            "high": 1,
            "medium": 2,
            "low": 0,
            "unknown": 1,
            "total": 4,
            "fixable": 3,
            "grade": "D",
            "score": 65,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/gitea"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/gitea@sha256:affb9f2aabdce981a175f8b3f48bf1bc0ee71f3e94a7e808b33aca07c3e6dad0 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/gitea"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/gitea"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "go",
      "name": "go",
      "category": "Language runtime",
      "summary": "Hardened Go toolchain for compiling binaries in a build stage; pair the output with the static base for the runtime. Latest 3 stable lines (1.24/1.25/1.26).",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.26.5",
      "versions": [
        {
          "version": "1.26.5",
          "size": "59.1 MB",
          "published": "2026-07-08T10:37:16Z",
          "digest": "sha256:d79e890ef340a0162a5ebb994e9b83e8adab3a73a21fa2bf3f574a9e5ea5e549"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/golang/go",
      "source": "https://github.com/golang/go",
      "image": "ghcr.io/quenchworks/images/go",
      "security": {
        "image": "ghcr.io/quenchworks/images/go",
        "version": "1.26.5",
        "tag": "ghcr.io/quenchworks/images/go:1.26.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.26.5",
            "tag": "ghcr.io/quenchworks/images/go:1.26.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "gotify",
      "name": "gotify",
      "category": "Messaging",
      "summary": "Self-hosted server for sending and receiving real-time push messages over WebSocket, with a web UI and app tokens. From source (UI embedded, CGO+static-musl SQLite) on a hardened nonroot Wolfi base; data on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.9.1",
      "versions": [
        {
          "version": "2.9.1",
          "size": "13.2 MB",
          "published": "2026-07-21T14:00:46Z",
          "digest": "sha256:af3f894c8baa2f15b95d7fafe687f55960e894cfb9bc7283c0676e5ada858eb5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://gotify.net",
      "source": "https://github.com/gotify/server",
      "image": "ghcr.io/quenchworks/images/gotify",
      "security": {
        "image": "ghcr.io/quenchworks/images/gotify",
        "version": "2.9.1",
        "tag": "ghcr.io/quenchworks/images/gotify:2.9.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/gotify"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.9.1",
            "tag": "ghcr.io/quenchworks/images/gotify:2.9.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/gotify"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "gradle",
      "name": "gradle",
      "category": "Build tool",
      "summary": "JDK base image with Gradle, used as the build stage for Gradle projects; run the resulting jar on jre. Line 9.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "9.6.1",
      "versions": [
        {
          "version": "9.6.1",
          "size": "239.1 MB",
          "published": "2026-07-09T21:39:48Z",
          "digest": "sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://gradle.org",
      "source": "https://gradle.org",
      "image": "ghcr.io/quenchworks/images/gradle",
      "security": {
        "image": "ghcr.io/quenchworks/images/gradle",
        "version": "9.6.1",
        "tag": "ghcr.io/quenchworks/images/gradle:9.6.1",
        "critical": 0,
        "high": 0,
        "medium": 5,
        "low": 2,
        "unknown": 0,
        "total": 7,
        "fixable": 7,
        "grade": "C",
        "score": 43,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-default-jdk",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-default-jdk",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71497",
            "severity": "MEDIUM",
            "pkg": "org.jsoup:jsoup",
            "installed": "1.15.3",
            "fixed": "1.23.1",
            "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-default-jdk",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "9.6.1",
            "tag": "ghcr.io/quenchworks/images/gradle:9.6.1",
            "critical": 0,
            "high": 0,
            "medium": 5,
            "low": 2,
            "unknown": 0,
            "total": 7,
            "fixable": 7,
            "grade": "C",
            "score": 43,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71497",
                "severity": "MEDIUM",
                "pkg": "org.jsoup:jsoup",
                "installed": "1.15.3",
                "fixed": "1.23.1",
                "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/gradle@sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "graylog",
      "name": "graylog",
      "category": "Observability",
      "summary": "Graylog, the log-management and analysis server (search, dashboards, alerting, GELF/Beats inputs). Built clean-room on a hardened Wolfi JRE (nonroot, read-only rootfs); the chart provides MongoDB (metadata) and OpenSearch (log storage) backends. Graylog Server is SSPL-1.0 (source-available, not OSI-approved).",
      "tier": "standard",
      "status": "available",
      "license": "SSPL-1.0",
      "licenseClean": "caution",
      "version": "7.1.6",
      "versions": [
        {
          "version": "7.1.6",
          "size": "425.0 MB",
          "published": "2026-07-26T12:26:35Z",
          "digest": "sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.graylog.org",
      "source": "https://packages.graylog2.org/releases/graylog/graylog",
      "image": "ghcr.io/quenchworks/images/graylog",
      "caution": true,
      "security": {
        "image": "ghcr.io/quenchworks/images/graylog",
        "version": "7.1.6",
        "tag": "ghcr.io/quenchworks/images/graylog:7.1.6",
        "critical": 0,
        "high": 0,
        "medium": 4,
        "low": 1,
        "unknown": 0,
        "total": 5,
        "fixable": 4,
        "grade": "C",
        "score": 63,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/graylog@sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/graylog@sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71497",
            "severity": "MEDIUM",
            "pkg": "org.jsoup:jsoup",
            "installed": "1.22.1",
            "fixed": "1.23.1",
            "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2025-48924",
            "severity": "MEDIUM",
            "pkg": "commons-lang:commons-lang",
            "installed": "2.6",
            "fixed": null,
            "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
            "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/graylog@sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "7.1.6",
            "tag": "ghcr.io/quenchworks/images/graylog:7.1.6",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 1,
            "unknown": 0,
            "total": 5,
            "fixable": 4,
            "grade": "C",
            "score": 63,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/graylog@sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/graylog@sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71497",
                "severity": "MEDIUM",
                "pkg": "org.jsoup:jsoup",
                "installed": "1.22.1",
                "fixed": "1.23.1",
                "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2025-48924",
                "severity": "MEDIUM",
                "pkg": "commons-lang:commons-lang",
                "installed": "2.6",
                "fixed": null,
                "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
                "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/graylog@sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "grype",
      "name": "grype",
      "category": "Security & supply chain",
      "summary": "Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.116.1",
      "versions": [
        {
          "version": "0.116.1",
          "size": "29.8 MB",
          "published": "2026-07-30T08:04:59Z",
          "digest": "sha256:af32102849b3a198457c4dc8329f65b0c872a536e824e01b2f521ad193f57f07"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/anchore/grype",
      "source": "https://github.com/anchore/grype",
      "image": "ghcr.io/quenchworks/images/grype",
      "security": {
        "image": "ghcr.io/quenchworks/images/grype",
        "version": "0.116.1",
        "tag": "ghcr.io/quenchworks/images/grype:0.116.1",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 3,
        "fixable": 2,
        "grade": "D",
        "score": 74,
        "cves": [
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/grype"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/grype"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/grype"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.116.1",
            "tag": "ghcr.io/quenchworks/images/grype:0.116.1",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/grype"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/grype"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/grype"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "haproxy",
      "name": "HAProxy",
      "category": "Gateway",
      "summary": "High-performance TCP and HTTP load balancer and reverse proxy known for reliability and fine-grained traffic control at scale.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0+",
      "licenseClean": "clean",
      "version": "3.3.10, 3.2.19, 3.4.0",
      "versions": [
        {
          "version": "3.3.10",
          "size": "22.1 MB",
          "published": "2026-07-04T11:27:12Z",
          "digest": "sha256:9acd387839807d5d301e913d8a7b26c5711b16a599138105bb89dd5e54086444"
        },
        {
          "version": "3.2.19",
          "size": "20.3 MB",
          "published": "2026-07-04T11:26:43Z",
          "digest": "sha256:897c5270db41b0a44e324f19a57f520515777e0db2f3d30fed5972afc281eff8"
        },
        {
          "version": "3.4.0",
          "size": "23.0 MB",
          "published": "2026-07-04T11:24:16Z",
          "digest": "sha256:e5778500d8bd53a08f37f5471b9672dc9f3c5252e08047a80626ac81669a9d65"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/haproxy/haproxy",
      "source": "https://github.com/haproxy/haproxy",
      "image": "ghcr.io/quenchworks/images/haproxy",
      "security": {
        "image": "ghcr.io/quenchworks/images/haproxy",
        "version": "3.4.0",
        "tag": "ghcr.io/quenchworks/images/haproxy:3.4.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.4.0",
            "tag": "ghcr.io/quenchworks/images/haproxy:3.4.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.3.10",
            "tag": "ghcr.io/quenchworks/images/haproxy:3.3.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.2.19",
            "tag": "ghcr.io/quenchworks/images/haproxy:3.2.19",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "harbor-core",
      "name": "Harbor core",
      "category": "Registry",
      "summary": "Core API server and control plane of the Harbor container registry, handling auth, projects, policies, and orchestration.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "27.8 MB",
          "published": "2026-07-22T06:32:43Z",
          "digest": "sha256:b88bbe17b95132446ff2e2f61e392533410e78f42c36b2bae9afd73a1dc535ab"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-core",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-core",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-core:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 2,
        "low": 0,
        "unknown": 1,
        "total": 5,
        "fixable": 0,
        "grade": "D",
        "score": 70,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "CVE-2025-47909",
            "severity": "MEDIUM",
            "pkg": "github.com/gorilla/csrf",
            "installed": "v1.7.3",
            "fixed": null,
            "title": "Hosts listed in TrustedOrigins implicitly allow requests from the corr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2025-47909",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/harbor_core"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-core:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 2,
            "low": 0,
            "unknown": 1,
            "total": 5,
            "fixable": 0,
            "grade": "D",
            "score": 70,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "CVE-2025-47909",
                "severity": "MEDIUM",
                "pkg": "github.com/gorilla/csrf",
                "installed": "v1.7.3",
                "fixed": null,
                "title": "Hosts listed in TrustedOrigins implicitly allow requests from the corr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2025-47909",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-exporter",
      "name": "Harbor exporter",
      "category": "Registry",
      "summary": "Prometheus exporter that exposes Harbor registry health and usage metrics for monitoring.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "14.7 MB",
          "published": "2026-07-22T06:59:40Z",
          "digest": "sha256:a86587c1947e98144a194d2c763a9b77bdcfbbbab8a581b5464906577b3a322f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-exporter",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-exporter:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 0,
        "grade": "D",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_exporter"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_exporter"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-exporter:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 0,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_exporter"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_exporter"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-jobservice",
      "name": "Harbor jobservice",
      "category": "Registry",
      "summary": "Harbor's asynchronous job runner that executes replication, garbage collection, and image-scan tasks in the background.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "19.0 MB",
          "published": "2026-07-22T06:59:32Z",
          "digest": "sha256:16fa1fee1647bf06b202fd0472619561bafb64245566ce7e41f316052e21f0db"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-jobservice",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-jobservice",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-jobservice:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 0,
        "grade": "D",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_jobservice"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_jobservice"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_jobservice"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-jobservice:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 0,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_jobservice"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_jobservice"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_jobservice"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-portal",
      "name": "Harbor portal",
      "category": "Registry",
      "summary": "Web UI for the Harbor container registry, serving the management dashboard for projects, repositories, and scan results.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "13.7 MB",
          "published": "2026-07-05T10:10:48Z",
          "digest": "sha256:85809ac40b4f954149daa33a5abde6c62109e199dbe99afbf07a48d7e4bb41ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-portal",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-portal",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-portal:2.15.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-portal:2.15.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "harbor-registry",
      "name": "Harbor registry",
      "category": "Registry",
      "summary": "OCI registry storage backend (Docker distribution) that stores and serves image layers and manifests for Harbor.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "12.6 MB",
          "published": "2026-07-22T08:28:17Z",
          "digest": "sha256:12dfcdb69c837af571beb647aeebba4d1443d7445eec225dd58d77c85ad76f17"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/distribution",
      "source": "https://github.com/goharbor/distribution",
      "image": "ghcr.io/quenchworks/images/harbor-registry",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-registry",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-registry:2.15.2",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2020-26160",
            "severity": "HIGH",
            "pkg": "github.com/dgrijalva/jwt-go",
            "installed": "v3.2.0+incompatible",
            "fixed": null,
            "title": "jwt-go: access restriction bypass vulnerability",
            "url": "https://avd.aquasec.com/nvd/cve-2020-26160",
            "targets": [
              "usr/bin/registry"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/registry"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-registry:2.15.2",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2020-26160",
                "severity": "HIGH",
                "pkg": "github.com/dgrijalva/jwt-go",
                "installed": "v3.2.0+incompatible",
                "fixed": null,
                "title": "jwt-go: access restriction bypass vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2020-26160",
                "targets": [
                  "usr/bin/registry"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/registry"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-registryctl",
      "name": "Harbor registryctl",
      "category": "Registry",
      "summary": "Harbor registry controller that manages garbage collection and registry storage lifecycle operations alongside the registry backend.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "13.0 MB",
          "published": "2026-07-22T06:58:43Z",
          "digest": "sha256:66e216f38986539bfb88cc48f03fc8dbd9a0afc9665e84ced32714f6de00b0d9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-registryctl",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-registryctl",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-registryctl:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 4,
        "fixable": 0,
        "grade": "D",
        "score": 74,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-registryctl:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 4,
            "fixable": 0,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-trivy-adapter",
      "name": "Harbor trivy-adapter",
      "category": "Registry",
      "summary": "Harbor vulnerability-scan adapter backed by Trivy, scanning pushed images for CVEs and reporting results into Harbor.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "80.0 MB",
          "published": "2026-07-22T09:02:43Z",
          "digest": "sha256:7121073c40eed52c7a268f82fcb16893b8788a8f18b1643807677de606b6900c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor-scanner-trivy",
      "source": "https://github.com/goharbor/harbor-scanner-trivy",
      "image": "ghcr.io/quenchworks/images/harbor-trivy-adapter",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-trivy-adapter",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-trivy-adapter:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 2,
        "low": 1,
        "unknown": 1,
        "total": 6,
        "fixable": 5,
        "grade": "D",
        "score": 44,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/harbor-trivy-adapter@sha256:7121073c40eed52c7a268f82fcb16893b8788a8f18b1643807677de606b6900c (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "CVE-2026-54787",
            "severity": "LOW",
            "pkg": "github.com/sigstore/sigstore-go",
            "installed": "v1.2.0",
            "fixed": "1.2.1",
            "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/trivy"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-trivy-adapter:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 2,
            "low": 1,
            "unknown": 1,
            "total": 6,
            "fixable": 5,
            "grade": "D",
            "score": 44,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/harbor-trivy-adapter@sha256:7121073c40eed52c7a268f82fcb16893b8788a8f18b1643807677de606b6900c (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "CVE-2026-54787",
                "severity": "LOW",
                "pkg": "github.com/sigstore/sigstore-go",
                "installed": "v1.2.0",
                "fixed": "1.2.1",
                "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/trivy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "headscale",
      "name": "headscale",
      "category": "Coordination & mesh",
      "summary": "Open-source, self-hosted implementation of the Tailscale control server for coordinating a WireGuard mesh. Single static Go binary on a hardened nonroot Wolfi base; config and state on writable volumes.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "0.29.2",
      "versions": [
        {
          "version": "0.29.2",
          "size": "19.9 MB",
          "published": "2026-07-22T07:02:13Z",
          "digest": "sha256:84fdca10e8e309e0ccae939a07a961fc9e18a63925d4cc8b6aeed9bbdb81afe0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/juanfont/headscale",
      "source": "https://github.com/juanfont/headscale",
      "image": "ghcr.io/quenchworks/images/headscale",
      "security": {
        "image": "ghcr.io/quenchworks/images/headscale",
        "version": "0.29.2",
        "tag": "ghcr.io/quenchworks/images/headscale:0.29.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/headscale"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.29.2",
            "tag": "ghcr.io/quenchworks/images/headscale:0.29.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/headscale"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "httpd",
      "name": "httpd",
      "category": "Gateway",
      "summary": "Apache HTTP Server, the long-standing open-source web server and reverse proxy for serving static content and fronting application backends (mod_proxy).",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.4.68",
      "versions": [
        {
          "version": "2.4.68",
          "size": "34.5 MB",
          "published": "2026-07-21T13:43:57Z",
          "digest": "sha256:9e886be8fb82062f440fbd46e92ade34b465a4c5103dbc91041efd7a43be1efc"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/httpd",
      "source": "https://downloads.apache.org/httpd/",
      "image": "ghcr.io/quenchworks/images/httpd",
      "security": {
        "image": "ghcr.io/quenchworks/images/httpd",
        "version": "2.4.68",
        "tag": "ghcr.io/quenchworks/images/httpd:2.4.68",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.4.68",
            "tag": "ghcr.io/quenchworks/images/httpd:2.4.68",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "influxdb",
      "name": "InfluxDB",
      "category": "Time series",
      "summary": "Time-series database purpose-built for ingesting and querying metrics, events, and IoT/sensor data at high write rates.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.9.1",
      "versions": [
        {
          "version": "2.9.1",
          "size": "55.2 MB",
          "published": "2026-07-22T07:36:38Z",
          "digest": "sha256:fc6dc0f07e9f900fb698b24a8a1cc751aa971fb4c473f41f0f2c7c8bfa25c2aa"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/influxdata/influxdb",
      "source": "https://github.com/influxdata/influxdb",
      "image": "ghcr.io/quenchworks/images/influxdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/influxdb",
        "version": "2.9.1",
        "tag": "ghcr.io/quenchworks/images/influxdb:2.9.1",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "C",
        "score": 94,
        "cves": [
          {
            "id": "CVE-2024-28180",
            "severity": "MEDIUM",
            "pkg": "gopkg.in/square/go-jose.v2",
            "installed": "v2.5.1",
            "fixed": null,
            "title": "jose-go: improper handling of highly compressed data",
            "url": "https://avd.aquasec.com/nvd/cve-2024-28180",
            "targets": [
              "usr/bin/influxd"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/influxd"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.9.1",
            "tag": "ghcr.io/quenchworks/images/influxdb:2.9.1",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "C",
            "score": 94,
            "cves": [
              {
                "id": "CVE-2024-28180",
                "severity": "MEDIUM",
                "pkg": "gopkg.in/square/go-jose.v2",
                "installed": "v2.5.1",
                "fixed": null,
                "title": "jose-go: improper handling of highly compressed data",
                "url": "https://avd.aquasec.com/nvd/cve-2024-28180",
                "targets": [
                  "usr/bin/influxd"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/influxd"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ingress-nginx",
      "name": "ingress-nginx",
      "category": "Gateway",
      "summary": "The Kubernetes NGINX Ingress Controller. Routes external HTTP/HTTPS traffic to in-cluster Services via Ingress resources, with TLS termination, path/host routing, and an admission webhook. The chart wires its RBAC, IngressClass, and webhook.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.15.8",
      "versions": [
        {
          "version": "1.15.8",
          "size": "79.8 MB",
          "published": "2026-07-28T06:16:54Z",
          "digest": "sha256:3f88b7c56cf30d630f367c0175477af5ac406a1145a7d3d0225a8c53f23e99b8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kubernetes.github.io/ingress-nginx",
      "source": "https://github.com/kubernetes/ingress-nginx",
      "image": "ghcr.io/quenchworks/images/ingress-nginx",
      "security": {
        "image": "ghcr.io/quenchworks/images/ingress-nginx",
        "version": "1.15.8",
        "tag": "ghcr.io/quenchworks/images/ingress-nginx:1.15.8",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 2,
        "total": 5,
        "fixable": 5,
        "grade": "D",
        "score": 47,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.37.0",
            "fixed": "0.39.0",
            "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/nginx-ingress-controller",
              "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/ingress-nginx@sha256:3f88b7c56cf30d630f367c0175477af5ac406a1145a7d3d0225a8c53f23e99b8 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/nginx-ingress-controller",
              "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.15.8",
            "tag": "ghcr.io/quenchworks/images/ingress-nginx:1.15.8",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 2,
            "total": 5,
            "fixable": 5,
            "grade": "D",
            "score": 47,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.37.0",
                "fixed": "0.39.0",
                "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/nginx-ingress-controller",
                  "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/ingress-nginx@sha256:3f88b7c56cf30d630f367c0175477af5ac406a1145a7d3d0225a8c53f23e99b8 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/nginx-ingress-controller",
                  "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jaeger",
      "name": "jaeger",
      "category": "Observability",
      "summary": "Distributed tracing platform (Jaeger v2, OpenTelemetry-collector based) with an embedded query UI. From source on a hardened nonroot Wolfi base; in-memory storage by default, badger under a volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.19.0",
      "versions": [
        {
          "version": "2.19.0",
          "size": "28.1 MB",
          "published": "2026-07-22T07:02:27Z",
          "digest": "sha256:c7584ec45b12de93b944adc4b5d436019751ff99bab346a36e3fac786fecd274"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.jaegertracing.io",
      "source": "https://github.com/jaegertracing/jaeger",
      "image": "ghcr.io/quenchworks/images/jaeger",
      "security": {
        "image": "ghcr.io/quenchworks/images/jaeger",
        "version": "2.19.0",
        "tag": "ghcr.io/quenchworks/images/jaeger:2.19.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/jaeger"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.19.0",
            "tag": "ghcr.io/quenchworks/images/jaeger:2.19.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/jaeger"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jdk",
      "name": "jdk",
      "category": "Language runtime",
      "summary": "Hardened OpenJDK with the javac compiler, a build-stage base image to FROM for Java apps. LTS lines 17/21/25.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0-with-classpath-exception",
      "licenseClean": "clean",
      "version": "17.0.19, 21.0.11, 25.0.4",
      "versions": [
        {
          "version": "17.0.19",
          "size": "93.8 MB",
          "published": "2026-07-26T12:35:31Z",
          "digest": "sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509"
        },
        {
          "version": "21.0.11",
          "size": "100.6 MB",
          "published": "2026-07-26T12:35:21Z",
          "digest": "sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530"
        },
        {
          "version": "25.0.4",
          "size": "112.1 MB",
          "published": "2026-07-26T12:30:10Z",
          "digest": "sha256:457e9b526d7806bed3054407008fc1c790c032e0d361888450fc92b77cced99b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://openjdk.org",
      "source": "https://openjdk.org",
      "image": "ghcr.io/quenchworks/images/jdk",
      "security": {
        "image": "ghcr.io/quenchworks/images/jdk",
        "version": "25.0.4",
        "tag": "ghcr.io/quenchworks/images/jdk:25.0.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "25.0.4",
            "tag": "ghcr.io/quenchworks/images/jdk:25.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "21.0.11",
            "tag": "ghcr.io/quenchworks/images/jdk:21.0.11",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "17.0.19",
            "tag": "ghcr.io/quenchworks/images/jdk:17.0.19",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-17",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-default-jdk",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-17",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-default-jdk",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-17",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-17-default-jdk",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jdk@sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jenkins",
      "name": "jenkins",
      "category": "CI/CD & registry",
      "summary": "The leading open-source automation server for building, testing, and deploying software, with thousands of plugins. Ships the architecture-independent jenkins.war LTS line on a hardened Wolfi JRE.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.572",
      "versions": [
        {
          "version": "2.572",
          "size": "171.4 MB",
          "published": "2026-07-09T23:43:11Z",
          "digest": "sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.jenkins.io",
      "source": "https://github.com/jenkinsci/jenkins",
      "image": "ghcr.io/quenchworks/images/jenkins",
      "security": {
        "image": "ghcr.io/quenchworks/images/jenkins",
        "version": "2.572",
        "tag": "ghcr.io/quenchworks/images/jenkins:2.572",
        "critical": 0,
        "high": 0,
        "medium": 3,
        "low": 1,
        "unknown": 0,
        "total": 4,
        "fixable": 3,
        "grade": "C",
        "score": 72,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/jenkins@sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/jenkins@sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2025-48924",
            "severity": "MEDIUM",
            "pkg": "commons-lang:commons-lang",
            "installed": "2.6",
            "fixed": null,
            "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
            "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/jenkins@sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.572",
            "tag": "ghcr.io/quenchworks/images/jenkins:2.572",
            "critical": 0,
            "high": 0,
            "medium": 3,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 3,
            "grade": "C",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jenkins@sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jenkins@sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2025-48924",
                "severity": "MEDIUM",
                "pkg": "commons-lang:commons-lang",
                "installed": "2.6",
                "fixed": null,
                "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
                "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jenkins@sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jenkins-inbound-agent",
      "name": "jenkins-inbound-agent",
      "category": "CI/CD & registry",
      "summary": "Jenkins inbound (JNLP/websocket) build agent — the remoting agent.jar plus launch script on a hardened Wolfi JRE, connecting back to a Jenkins controller to run builds. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.jenkins.io",
      "source": "https://github.com/jenkinsci/remoting",
      "image": "ghcr.io/quenchworks/images/jenkins-inbound-agent",
      "security": null
    },
    {
      "slug": "jmeter",
      "name": "jmeter",
      "category": "Observability",
      "summary": "Apache JMeter load-testing and performance-measurement tool, the official binary distribution running on a hardened Wolfi JRE. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.6.3",
      "versions": [
        {
          "version": "5.6.3",
          "size": "140.2 MB",
          "published": "2026-07-09T16:34:34Z",
          "digest": "sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://jmeter.apache.org",
      "source": "https://github.com/apache/jmeter",
      "image": "ghcr.io/quenchworks/images/jmeter",
      "security": {
        "image": "ghcr.io/quenchworks/images/jmeter",
        "version": "5.6.3",
        "tag": "ghcr.io/quenchworks/images/jmeter:5.6.3",
        "critical": 0,
        "high": 0,
        "medium": 3,
        "low": 1,
        "unknown": 0,
        "total": 4,
        "fixable": 4,
        "grade": "C",
        "score": 67,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/jmeter@sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/jmeter@sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71497",
            "severity": "MEDIUM",
            "pkg": "org.jsoup:jsoup",
            "installed": "1.17.1",
            "fixed": "1.23.1",
            "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/jmeter@sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "5.6.3",
            "tag": "ghcr.io/quenchworks/images/jmeter:5.6.3",
            "critical": 0,
            "high": 0,
            "medium": 3,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 4,
            "grade": "C",
            "score": 67,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jmeter@sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jmeter@sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71497",
                "severity": "MEDIUM",
                "pkg": "org.jsoup:jsoup",
                "installed": "1.17.1",
                "fixed": "1.23.1",
                "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jmeter@sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jre",
      "name": "jre",
      "category": "Runtime base",
      "summary": "Hardened Java runtime (JRE) for running a built jar, no compiler. Pair with the jdk, maven, or gradle build image. LTS lines 17/21/25.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0-with-classpath-exception",
      "licenseClean": "clean",
      "version": "21.0.11, 17.0.19, 25.0.4",
      "versions": [
        {
          "version": "21.0.11",
          "size": "74.6 MB",
          "published": "2026-07-26T12:27:43Z",
          "digest": "sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597"
        },
        {
          "version": "17.0.19",
          "size": "68.5 MB",
          "published": "2026-07-26T12:27:06Z",
          "digest": "sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea"
        },
        {
          "version": "25.0.4",
          "size": "83.2 MB",
          "published": "2026-07-26T12:23:43Z",
          "digest": "sha256:6eef69de22c7b3cca358a6984a50bd993bb17f948a47241ba3b5834c6153965d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://openjdk.org",
      "source": "https://openjdk.org",
      "image": "ghcr.io/quenchworks/images/jre",
      "security": {
        "image": "ghcr.io/quenchworks/images/jre",
        "version": "25.0.4",
        "tag": "ghcr.io/quenchworks/images/jre:25.0.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "25.0.4",
            "tag": "ghcr.io/quenchworks/images/jre:25.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "21.0.11",
            "tag": "ghcr.io/quenchworks/images/jre:21.0.11",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jvm",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jvm",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-default-jvm",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "17.0.19",
            "tag": "ghcr.io/quenchworks/images/jre:17.0.19",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-default-jvm",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-jre",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-default-jvm",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-17-jre",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-17-default-jvm",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-17-jre",
                "installed": "17.0.19-r4",
                "fixed": "17.0.20-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/jre@sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "k6",
      "name": "k6",
      "category": "Observability",
      "summary": "Developer-friendly load and performance testing tool scripted in JavaScript. Single static Go binary on a hardened nonroot Wolfi base; test scripts are mounted at runtime.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2.1.0",
      "versions": [
        {
          "version": "2.1.0",
          "size": "16.6 MB",
          "published": "2026-07-22T07:21:44Z",
          "digest": "sha256:e05cde371e5d8c0a4850455e10545fc2b38ff6daa0e0c7ddfa9a735ccc69b8aa"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://k6.io",
      "source": "https://github.com/grafana/k6",
      "image": "ghcr.io/quenchworks/images/k6",
      "security": {
        "image": "ghcr.io/quenchworks/images/k6",
        "version": "2.1.0",
        "tag": "ghcr.io/quenchworks/images/k6:2.1.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/k6"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/k6:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/k6"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kafka",
      "name": "Kafka",
      "category": "Messaging",
      "summary": "Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.3.1",
      "versions": [
        {
          "version": "4.3.1",
          "size": "204.3 MB",
          "published": "2026-07-28T06:52:03Z",
          "digest": "sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/kafka",
      "source": "https://archive.apache.org/dist/kafka/4.3.0/kafka_2.13-4.3.0.tgz",
      "image": "ghcr.io/quenchworks/images/kafka",
      "security": {
        "image": "ghcr.io/quenchworks/images/kafka",
        "version": "4.3.1",
        "tag": "ghcr.io/quenchworks/images/kafka:4.3.1",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "C",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/kafka@sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/kafka@sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/kafka@sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.3.1",
            "tag": "ghcr.io/quenchworks/images/kafka:4.3.1",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "C",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/kafka@sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/kafka@sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/kafka@sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "keda",
      "name": "keda",
      "category": "Coordination",
      "summary": "Kubernetes event-driven autoscaler that scales workloads based on external event sources (queues, streams, metrics). Ships the operator and metrics adapter as static Go binaries on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.20.1",
      "versions": [
        {
          "version": "2.20.1",
          "size": "79.8 MB",
          "published": "2026-07-26T12:26:29Z",
          "digest": "sha256:c4e008de38998bb0e0590a247c326d7346d756b0fcb9ec71a698f8df637ffb1f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://keda.sh",
      "source": "https://github.com/kedacore/keda",
      "image": "ghcr.io/quenchworks/images/keda",
      "security": {
        "image": "ghcr.io/quenchworks/images/keda",
        "version": "2.20.1",
        "tag": "ghcr.io/quenchworks/images/keda:2.20.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/keda",
              "usr/bin/keda-adapter"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.20.1",
            "tag": "ghcr.io/quenchworks/images/keda:2.20.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/keda",
                  "usr/bin/keda-adapter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "keycloak",
      "name": "Keycloak",
      "category": "Identity",
      "summary": "Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "26.7.0",
      "versions": [
        {
          "version": "26.7.0",
          "size": "231.6 MB",
          "published": "2026-07-28T06:23:01Z",
          "digest": "sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/keycloak/keycloak",
      "source": "https://github.com/keycloak/keycloak",
      "image": "ghcr.io/quenchworks/images/keycloak",
      "security": {
        "image": "ghcr.io/quenchworks/images/keycloak",
        "version": "26.7.0",
        "tag": "ghcr.io/quenchworks/images/keycloak:26.7.0",
        "critical": 0,
        "high": 2,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 5,
        "fixable": 5,
        "grade": "D",
        "score": 46,
        "cves": [
          {
            "id": "CVE-2026-40983",
            "severity": "HIGH",
            "pkg": "io.micrometer:micrometer-core",
            "installed": "1.16.3",
            "fixed": "1.16.6, 1.15.12",
            "title": "micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-40983",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-40984",
            "severity": "HIGH",
            "pkg": "io.micrometer:micrometer-core",
            "installed": "1.16.3",
            "fixed": "1.16.6, 1.15.12",
            "title": "micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-40984",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/keycloak@sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/keycloak@sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/keycloak@sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "26.7.0",
            "tag": "ghcr.io/quenchworks/images/keycloak:26.7.0",
            "critical": 0,
            "high": 2,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 5,
            "fixable": 5,
            "grade": "D",
            "score": 46,
            "cves": [
              {
                "id": "CVE-2026-40983",
                "severity": "HIGH",
                "pkg": "io.micrometer:micrometer-core",
                "installed": "1.16.3",
                "fixed": "1.16.6, 1.15.12",
                "title": "micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-40983",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-40984",
                "severity": "HIGH",
                "pkg": "io.micrometer:micrometer-core",
                "installed": "1.16.3",
                "fixed": "1.16.6, 1.15.12",
                "title": "micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-40984",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/keycloak@sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/keycloak@sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/keycloak@sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kong",
      "name": "kong",
      "category": "Gateway",
      "summary": "API gateway and ingress controller on a patched OpenResty, with routing, auth, rate limiting, and a plugin ecosystem. Built from source against current OpenSSL rather than Kong's pinned older crypto; ships the Admin API without the Kong Manager GUI, whose assets are not built from source upstream.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.9.3",
      "versions": [
        {
          "version": "3.9.3",
          "size": "42.3 MB",
          "published": "2026-08-04T10:06:16Z",
          "digest": "sha256:dcf9af271e724e8063894813a65bdae23559f04528f839a8b8b2affebf92fa6e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/Kong/kong",
      "source": "https://github.com/Kong/kong",
      "image": "ghcr.io/quenchworks/images/kong",
      "security": {
        "image": "ghcr.io/quenchworks/images/kong",
        "version": "3.9.3",
        "tag": "ghcr.io/quenchworks/images/kong:3.9.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.9.3",
            "tag": "ghcr.io/quenchworks/images/kong:3.9.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "kube-state-metrics",
      "name": "kube-state-metrics",
      "category": "Observability",
      "summary": "Exposes the state of Kubernetes objects as Prometheus metrics for dashboards and alerts. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.18.0, 2.17.0, 2.19.1",
      "versions": [
        {
          "version": "2.18.0",
          "size": "18.8 MB",
          "published": "2026-07-26T12:29:07Z",
          "digest": "sha256:07a7ea22df6f6a39e75a92c58716d5b4e63bcd797bb896e8edb60037d05826f4"
        },
        {
          "version": "2.17.0",
          "size": "18.8 MB",
          "published": "2026-07-26T12:27:40Z",
          "digest": "sha256:7af4e77d5068075504d071323e297c5b9140ab3cebe03d93d9fe7d483d074fd5"
        },
        {
          "version": "2.19.1",
          "size": "18.2 MB",
          "published": "2026-07-26T12:27:25Z",
          "digest": "sha256:6785c8b5b673e5844c281afe37a86e4352b6c8663d24ef8e585649a3de50e471"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/kubernetes/kube-state-metrics",
      "source": "https://github.com/kubernetes/kube-state-metrics",
      "image": "ghcr.io/quenchworks/images/kube-state-metrics",
      "security": {
        "image": "ghcr.io/quenchworks/images/kube-state-metrics",
        "version": "2.19.1",
        "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.19.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/kube-state-metrics"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.19.1",
            "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.19.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kube-state-metrics"
                ]
              }
            ]
          },
          {
            "version": "2.18.0",
            "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.18.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kube-state-metrics"
                ]
              }
            ]
          },
          {
            "version": "2.17.0",
            "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.17.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kube-state-metrics"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kubectl",
      "name": "kubectl",
      "category": "CI/CD & registry",
      "summary": "Hardened kubectl image with the common cluster toolbelt (helm, kustomize, jq, a busybox shell) — the 0-CVE answer to alpine/k8s and bitnami/kubectl for CI jobs and in-cluster tooling. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.34.10, 1.36.3",
      "versions": [
        {
          "version": "1.34.10",
          "size": "61.7 MB",
          "published": "2026-07-28T06:48:13Z",
          "digest": "sha256:c7623897a0b29b82eb0d1a8e322caa3d84376c6cccbf6bf2dc8ca70045066ebd"
        },
        {
          "version": "1.36.3",
          "size": "61.3 MB",
          "published": "2026-07-26T12:33:36Z",
          "digest": "sha256:44a86469299c7f7e56e1fbe93c67106004fec0d7b2f764ccc9cc026b5e299705"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kubernetes.io",
      "source": "https://github.com/kubernetes/kubernetes",
      "image": "ghcr.io/quenchworks/images/kubectl",
      "security": {
        "image": "ghcr.io/quenchworks/images/kubectl",
        "version": "1.36.3",
        "tag": "ghcr.io/quenchworks/images/kubectl:1.36.3",
        "critical": 0,
        "high": 3,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 5,
        "fixable": 3,
        "grade": "D",
        "score": 51,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "kubectl-1.36",
            "installed": "1.36.3-r1",
            "fixed": "1.36.3-r2",
            "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "ghcr.io/quenchworks/images/kubectl@sha256:44a86469299c7f7e56e1fbe93c67106004fec0d7b2f764ccc9cc026b5e299705 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.38.0",
            "fixed": "0.39.0",
            "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/kubectl-1.36",
              "var/lib/db/sbom/kubectl-1.36-1.36.3-r1.spdx.json"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/helm",
              "var/lib/db/sbom/helm-4-4.2.3-r1.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.36.3",
            "tag": "ghcr.io/quenchworks/images/kubectl:1.36.3",
            "critical": 0,
            "high": 3,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 5,
            "fixable": 3,
            "grade": "D",
            "score": 51,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "kubectl-1.36",
                "installed": "1.36.3-r1",
                "fixed": "1.36.3-r2",
                "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "ghcr.io/quenchworks/images/kubectl@sha256:44a86469299c7f7e56e1fbe93c67106004fec0d7b2f764ccc9cc026b5e299705 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/kubectl-1.36",
                  "var/lib/db/sbom/kubectl-1.36-1.36.3-r1.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/helm",
                  "var/lib/db/sbom/helm-4-4.2.3-r1.spdx.json"
                ]
              }
            ]
          },
          {
            "version": "1.34.10",
            "tag": "ghcr.io/quenchworks/images/kubectl:1.34.10",
            "critical": 0,
            "high": 3,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 5,
            "fixable": 3,
            "grade": "D",
            "score": 51,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "kubectl-1.34",
                "installed": "1.34.10-r2",
                "fixed": "1.34.10-r3",
                "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "ghcr.io/quenchworks/images/kubectl@sha256:c7623897a0b29b82eb0d1a8e322caa3d84376c6cccbf6bf2dc8ca70045066ebd (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/kubectl-1.34",
                  "var/lib/db/sbom/kubectl-1.34-1.34.10-r2.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/helm",
                  "var/lib/db/sbom/helm-4-4.2.3-r1.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kuma",
      "name": "kuma",
      "category": "Coordination & mesh",
      "summary": "CNCF service mesh control plane (Envoy-based) for multi-zone and multi-cluster meshes. Ships kuma-cp and kumactl with an embedded GUI, built from source on a hardened nonroot Wolfi base; default in-memory store runs standalone.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.14.0",
      "versions": [
        {
          "version": "2.14.0",
          "size": "62.5 MB",
          "published": "2026-07-26T12:26:51Z",
          "digest": "sha256:3ccbf3268792cd2500ff68851c008c995ba4e881679524bc63280130f0480cb4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kuma.io",
      "source": "https://github.com/kumahq/kuma",
      "image": "ghcr.io/quenchworks/images/kuma",
      "security": {
        "image": "ghcr.io/quenchworks/images/kuma",
        "version": "2.14.0",
        "tag": "ghcr.io/quenchworks/images/kuma:2.14.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/kuma-cp",
              "usr/bin/kumactl"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.14.0",
            "tag": "ghcr.io/quenchworks/images/kuma:2.14.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kuma-cp",
                  "usr/bin/kumactl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kyverno",
      "name": "kyverno",
      "category": "Security & supply chain",
      "summary": "Kubernetes-native policy engine for validating, mutating, and generating resources with no new language. Ships the controllers and CLI as static Go binaries on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.1",
      "versions": [
        {
          "version": "1.18.1",
          "size": "253.3 MB",
          "published": "2026-07-26T12:32:48Z",
          "digest": "sha256:299a9ca690cdeb7ebe223172bed559e96280472948af0f64b0ac71e01abf0abd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kyverno.io",
      "source": "https://github.com/kyverno/kyverno",
      "image": "ghcr.io/quenchworks/images/kyverno",
      "security": {
        "image": "ghcr.io/quenchworks/images/kyverno",
        "version": "1.18.1",
        "tag": "ghcr.io/quenchworks/images/kyverno:1.18.1",
        "critical": 0,
        "high": 7,
        "medium": 1,
        "low": 6,
        "unknown": 6,
        "total": 20,
        "fixable": 14,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/background-controller",
              "usr/bin/cleanup-controller",
              "usr/bin/kubectl-kyverno",
              "usr/bin/kyverno",
              "usr/bin/kyvernopre",
              "usr/bin/reports-controller"
            ]
          },
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/kubectl-kyverno"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/kubectl-kyverno"
            ]
          },
          {
            "id": "CVE-2026-54787",
            "severity": "LOW",
            "pkg": "github.com/sigstore/sigstore-go",
            "installed": "v1.2.0",
            "fixed": "1.2.1",
            "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
            "targets": [
              "usr/bin/background-controller",
              "usr/bin/cleanup-controller",
              "usr/bin/kubectl-kyverno",
              "usr/bin/kyverno",
              "usr/bin/kyvernopre",
              "usr/bin/reports-controller"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/background-controller",
              "usr/bin/cleanup-controller",
              "usr/bin/kubectl-kyverno",
              "usr/bin/kyverno",
              "usr/bin/kyvernopre",
              "usr/bin/reports-controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.18.1",
            "tag": "ghcr.io/quenchworks/images/kyverno:1.18.1",
            "critical": 0,
            "high": 7,
            "medium": 1,
            "low": 6,
            "unknown": 6,
            "total": 20,
            "fixable": 14,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/background-controller",
                  "usr/bin/cleanup-controller",
                  "usr/bin/kubectl-kyverno",
                  "usr/bin/kyverno",
                  "usr/bin/kyvernopre",
                  "usr/bin/reports-controller"
                ]
              },
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/kubectl-kyverno"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/kubectl-kyverno"
                ]
              },
              {
                "id": "CVE-2026-54787",
                "severity": "LOW",
                "pkg": "github.com/sigstore/sigstore-go",
                "installed": "v1.2.0",
                "fixed": "1.2.1",
                "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
                "targets": [
                  "usr/bin/background-controller",
                  "usr/bin/cleanup-controller",
                  "usr/bin/kubectl-kyverno",
                  "usr/bin/kyverno",
                  "usr/bin/kyvernopre",
                  "usr/bin/reports-controller"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/background-controller",
                  "usr/bin/cleanup-controller",
                  "usr/bin/kubectl-kyverno",
                  "usr/bin/kyverno",
                  "usr/bin/kyvernopre",
                  "usr/bin/reports-controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "litestream",
      "name": "litestream",
      "category": "Storage & platform",
      "summary": "Streaming replication for SQLite databases to object storage such as S3, GCS, and Azure. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.5.15",
      "versions": [
        {
          "version": "0.5.15",
          "size": "16.9 MB",
          "published": "2026-07-22T11:29:05Z",
          "digest": "sha256:d49434ed72a38e01b27780779a1a5ed11751295ca0472d62c5a5a2c61c0d8549"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://litestream.io",
      "source": "https://github.com/benbjohnson/litestream",
      "image": "ghcr.io/quenchworks/images/litestream",
      "security": {
        "image": "ghcr.io/quenchworks/images/litestream",
        "version": "0.5.15",
        "tag": "ghcr.io/quenchworks/images/litestream:0.5.15",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/litestream"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.5.15",
            "tag": "ghcr.io/quenchworks/images/litestream:0.5.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/litestream"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "livekit",
      "name": "livekit",
      "category": "Media & streaming",
      "summary": "WebRTC SFU server for scalable real-time audio, video, and data. Single static Go binary on a hardened nonroot Wolfi base; config via mounted YAML or LIVEKIT_ env.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.13.4",
      "versions": [
        {
          "version": "1.13.4",
          "size": "18.0 MB",
          "published": "2026-07-26T12:26:49Z",
          "digest": "sha256:6fd6e07ed2927bdae925ad694f5c557beebc28f27cd533c50ca14d164de2c316"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://livekit.io",
      "source": "https://github.com/livekit/livekit",
      "image": "ghcr.io/quenchworks/images/livekit",
      "security": {
        "image": "ghcr.io/quenchworks/images/livekit",
        "version": "1.13.4",
        "tag": "ghcr.io/quenchworks/images/livekit:1.13.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/livekit-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.13.4",
            "tag": "ghcr.io/quenchworks/images/livekit:1.13.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/livekit-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "loki",
      "name": "Loki",
      "category": "Observability",
      "summary": "Horizontally scalable log aggregation system from Grafana that indexes only labels, not full log text. Like Prometheus, but for logs. Licensed AGPL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "3.7.4",
      "versions": [
        {
          "version": "3.7.4",
          "size": "88.1 MB",
          "published": "2026-07-26T12:27:05Z",
          "digest": "sha256:8ad6b4a777ce3b35eec4b51cb61fe2e703a4404134391d723aee1a0c6a73431f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/grafana/loki",
      "source": "https://github.com/grafana/loki",
      "image": "ghcr.io/quenchworks/images/loki",
      "security": {
        "image": "ghcr.io/quenchworks/images/loki",
        "version": "3.7.4",
        "tag": "ghcr.io/quenchworks/images/loki:3.7.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/logcli",
              "usr/bin/loki"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.4",
            "tag": "ghcr.io/quenchworks/images/loki:3.7.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/logcli",
                  "usr/bin/loki"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mailpit",
      "name": "mailpit",
      "category": "Apps & productivity",
      "summary": "Email and SMTP testing tool with a web UI for capturing and inspecting messages during development. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.30.6",
      "versions": [
        {
          "version": "1.30.6",
          "size": "9.3 MB",
          "published": "2026-07-28T09:48:56Z",
          "digest": "sha256:36b2c7470826961182094048c009d112b4998f5d71559cab8243696d3c9e6416"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mailpit.axllent.org",
      "source": "https://github.com/axllent/mailpit",
      "image": "ghcr.io/quenchworks/images/mailpit",
      "security": {
        "image": "ghcr.io/quenchworks/images/mailpit",
        "version": "1.30.6",
        "tag": "ghcr.io/quenchworks/images/mailpit:1.30.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/mailpit"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.30.6",
            "tag": "ghcr.io/quenchworks/images/mailpit:1.30.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/mailpit"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mariadb",
      "name": "MariaDB",
      "category": "Relational",
      "summary": "Community-developed relational database and drop-in MySQL successor, GPL-licensed and fully open. Default MySQL-compatible engine for the catalog.",
      "tier": "critical",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "11.8.8, 12.3.2, 11.4.12",
      "versions": [
        {
          "version": "11.8.8",
          "size": "116.0 MB",
          "published": "2026-07-28T06:44:29Z",
          "digest": "sha256:fc26a36e421363f7426951407c93cf94d834786cd19356fdcd1b08e83717beab"
        },
        {
          "version": "12.3.2",
          "size": "117.9 MB",
          "published": "2026-07-28T06:44:29Z",
          "digest": "sha256:de7f6d2143a534b7882d292a494f359bf4c7003b8f12598a97a424a1d5da354d"
        },
        {
          "version": "11.4.12",
          "size": "114.7 MB",
          "published": "2026-07-28T06:44:25Z",
          "digest": "sha256:3f110a0686888b1fd21f49cf17bcab66562bf12a4033d0c09e1d6fe000dd4b44"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/MariaDB/server",
      "source": "https://archive.mariadb.org/mariadb-11.8.8/source/mariadb-11.8.8.tar.gz",
      "image": "ghcr.io/quenchworks/images/mariadb",
      "security": {
        "image": "ghcr.io/quenchworks/images/mariadb",
        "version": "12.3.2",
        "tag": "ghcr.io/quenchworks/images/mariadb:12.3.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "12.3.2",
            "tag": "ghcr.io/quenchworks/images/mariadb:12.3.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "11.8.8",
            "tag": "ghcr.io/quenchworks/images/mariadb:11.8.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "11.4.12",
            "tag": "ghcr.io/quenchworks/images/mariadb:11.4.12",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "matomo",
      "name": "matomo",
      "category": "Apps & productivity",
      "summary": "Matomo, the self-hosted web analytics platform and a privacy-respecting alternative to Google Analytics: you keep the raw data. Built from the official release tarball on a hardened Wolfi php-8.3-fpm runtime fronted by nginx built from source (nonroot, read-only rootfs, supervisord), with the vendored twig/twig replaced by 3.28.0 to clear 14 advisories the shipped 3.11.3 carries. The tarball ships no composer.lock, so the recipe re-materialises the dependency inventory from vendor/composer/installed.php purely so scanners can enumerate what is vendored. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0+",
      "licenseClean": "agpl",
      "version": "5.12.0, 5.11.2",
      "versions": [
        {
          "version": "5.12.0",
          "size": "90.2 MB",
          "published": "2026-08-02T12:55:33Z",
          "digest": "sha256:8d771a71ca6ee35a1595cda0a87d07d15adbc76d51be874ab251d243a90688b0"
        },
        {
          "version": "5.11.2",
          "size": "90.2 MB",
          "published": "2026-08-02T12:55:31Z",
          "digest": "sha256:c98c52d90e749fb75ae2da390d74f3f5a7847988125e21d6dd2e8b783605f60b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://matomo.org",
      "source": "https://builds.matomo.org/matomo-5.12.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/matomo",
      "security": {
        "image": "ghcr.io/quenchworks/images/matomo",
        "version": "5.12.0",
        "tag": "ghcr.io/quenchworks/images/matomo:5.12.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.12.0",
            "tag": "ghcr.io/quenchworks/images/matomo:5.12.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.11.2",
            "tag": "ghcr.io/quenchworks/images/matomo:5.11.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mattermost",
      "name": "mattermost",
      "category": "Messaging",
      "summary": "Open-source, self-hosted team messaging and collaboration platform (a Slack alternative) with channels, direct messages, file sharing, and integrations. Packaged from Mattermost's official Team Edition server release; requires an external PostgreSQL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "11.9.0",
      "versions": [
        {
          "version": "11.9.0",
          "size": "403.6 MB",
          "published": "2026-07-22T08:40:53Z",
          "digest": "sha256:fbd623821cab4daadfbedfdebad2235e20d6f646824c2c3bcafaf9a54aa2d3a6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mattermost.com",
      "source": "https://github.com/mattermost/mattermost",
      "image": "ghcr.io/quenchworks/images/mattermost",
      "security": {
        "image": "ghcr.io/quenchworks/images/mattermost",
        "version": "11.9.0",
        "tag": "ghcr.io/quenchworks/images/mattermost:11.9.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "opt/mattermost/bin/mattermost",
              "opt/mattermost/bin/mmctl"
            ]
          }
        ],
        "versions": [
          {
            "version": "11.9.0",
            "tag": "ghcr.io/quenchworks/images/mattermost:11.9.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "opt/mattermost/bin/mattermost",
                  "opt/mattermost/bin/mmctl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "maven",
      "name": "maven",
      "category": "Build tool",
      "summary": "JDK base image with Apache Maven, used as the build stage for Maven projects; run the resulting jar on jre. Line 3.9.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.9.15, 3.9.14, 3.9.16",
      "versions": [
        {
          "version": "3.9.15",
          "size": "110.0 MB",
          "published": "2026-07-04T11:30:19Z",
          "digest": "sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794"
        },
        {
          "version": "3.9.14",
          "size": "110.0 MB",
          "published": "2026-07-04T11:27:46Z",
          "digest": "sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e"
        },
        {
          "version": "3.9.16",
          "size": "110.1 MB",
          "published": "2026-07-04T11:10:50Z",
          "digest": "sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://maven.apache.org",
      "source": "https://maven.apache.org",
      "image": "ghcr.io/quenchworks/images/maven",
      "security": {
        "image": "ghcr.io/quenchworks/images/maven",
        "version": "3.9.16",
        "tag": "ghcr.io/quenchworks/images/maven:3.9.16",
        "critical": 0,
        "high": 0,
        "medium": 4,
        "low": 2,
        "unknown": 0,
        "total": 6,
        "fixable": 6,
        "grade": "C",
        "score": 52,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-default-jdk",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-default-jdk",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-default-jdk",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.9.16",
            "tag": "ghcr.io/quenchworks/images/maven:3.9.16",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "3.9.15",
            "tag": "ghcr.io/quenchworks/images/maven:3.9.15",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "3.9.14",
            "tag": "ghcr.io/quenchworks/images/maven:3.9.14",
            "critical": 0,
            "high": 0,
            "medium": 4,
            "low": 2,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-default-jdk",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/maven@sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mediamtx",
      "name": "mediamtx",
      "category": "Media & streaming",
      "summary": "Real-time media server and proxy for RTSP, RTMP, HLS, WebRTC, and SRT. Single static Go binary on a hardened nonroot Wolfi base; config via a mounted mediamtx.yml.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.19.3",
      "versions": [
        {
          "version": "1.19.3",
          "size": "17.7 MB",
          "published": "2026-07-26T12:32:18Z",
          "digest": "sha256:a35e28d544b8fe20c804b51645af9b0646c6d58d4bff399c28d5edac5476b56b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/bluenviron/mediamtx",
      "source": "https://github.com/bluenviron/mediamtx",
      "image": "ghcr.io/quenchworks/images/mediamtx",
      "security": {
        "image": "ghcr.io/quenchworks/images/mediamtx",
        "version": "1.19.3",
        "tag": "ghcr.io/quenchworks/images/mediamtx:1.19.3",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 3,
        "fixable": 2,
        "grade": "D",
        "score": 74,
        "cves": [
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/mediamtx"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/mediamtx"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/mediamtx"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.19.3",
            "tag": "ghcr.io/quenchworks/images/mediamtx:1.19.3",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/mediamtx"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/mediamtx"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/mediamtx"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "meilisearch",
      "name": "Meilisearch",
      "category": "Search",
      "summary": "Fast, typo-tolerant full-text search engine with an instant-search API, easy to embed for site and in-app search with relevant results out of the box.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.50.0, 1.49.0, 1.51.0",
      "versions": [
        {
          "version": "1.50.0",
          "size": "94.5 MB",
          "published": "2026-07-28T10:23:22Z",
          "digest": "sha256:6f81bb675e9cf58244cfb9c8ad5ca7a00b1db1d428e31d67580158de7fefa8e3"
        },
        {
          "version": "1.49.0",
          "size": "94.4 MB",
          "published": "2026-07-28T10:23:17Z",
          "digest": "sha256:c3edc16b325020c6cb2047540811a18757c54830732128e69ebefde44a70abf1"
        },
        {
          "version": "1.51.0",
          "size": "94.1 MB",
          "published": "2026-07-28T10:23:17Z",
          "digest": "sha256:04bcb20754c136541f9eaab771b8eb9a07c9f5ac8c30a2f3910f60f6d69508ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/meilisearch/meilisearch",
      "source": "https://github.com/meilisearch/meilisearch",
      "image": "ghcr.io/quenchworks/images/meilisearch",
      "security": {
        "image": "ghcr.io/quenchworks/images/meilisearch",
        "version": "1.51.0",
        "tag": "ghcr.io/quenchworks/images/meilisearch:1.51.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.51.0",
            "tag": "ghcr.io/quenchworks/images/meilisearch:1.51.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.50.0",
            "tag": "ghcr.io/quenchworks/images/meilisearch:1.50.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.49.0",
            "tag": "ghcr.io/quenchworks/images/meilisearch:1.49.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "memcached",
      "name": "Memcached",
      "category": "Cache",
      "summary": "Simple, high-performance distributed in-memory cache for storing small objects and database query results to reduce backend load.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.6.45",
      "versions": [
        {
          "version": "1.6.45",
          "size": "7.2 MB",
          "published": "2026-07-12T12:17:26Z",
          "digest": "sha256:d078d5186da4a439b22a7ac65968d553ff8a57f6304817fb6f633855c6f34546"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/memcached/memcached",
      "source": "https://www.memcached.org/files/memcached-1.6.42.tar.gz",
      "image": "ghcr.io/quenchworks/images/memcached",
      "security": {
        "image": "ghcr.io/quenchworks/images/memcached",
        "version": "1.6.45",
        "tag": "ghcr.io/quenchworks/images/memcached:1.6.45",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.6.45",
            "tag": "ghcr.io/quenchworks/images/memcached:1.6.45",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mimir",
      "name": "mimir",
      "category": "Observability",
      "summary": "Horizontally scalable, highly available long-term storage for Prometheus metrics. Single static Go binary (all-in-one or microservices target) on a hardened nonroot Wolfi base; object storage is the operator's choice.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "3.1.2",
      "versions": [
        {
          "version": "3.1.2",
          "size": "39.5 MB",
          "published": "2026-07-21T11:31:43Z",
          "digest": "sha256:2ca8589ad58fca650b777a0807a3df829bab92b5a5f5c542b7f55b063f36828d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://grafana.com/oss/mimir",
      "source": "https://github.com/grafana/mimir",
      "image": "ghcr.io/quenchworks/images/mimir",
      "security": {
        "image": "ghcr.io/quenchworks/images/mimir",
        "version": "3.1.2",
        "tag": "ghcr.io/quenchworks/images/mimir:3.1.2",
        "critical": 0,
        "high": 2,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 4,
        "fixable": 3,
        "grade": "D",
        "score": 61,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.37.0",
            "fixed": "0.39.0",
            "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/mimir"
            ]
          },
          {
            "id": "GHSA-hrxh-6v49-42gf",
            "severity": "HIGH",
            "pkg": "google.golang.org/grpc",
            "installed": "v1.80.0",
            "fixed": "1.82.1",
            "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
            "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
            "targets": [
              "usr/bin/mimir"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/mimir"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.52.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/mimir"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.1.2",
            "tag": "ghcr.io/quenchworks/images/mimir:3.1.2",
            "critical": 0,
            "high": 2,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 4,
            "fixable": 3,
            "grade": "D",
            "score": 61,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.37.0",
                "fixed": "0.39.0",
                "title": "golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/mimir"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.80.0",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/mimir"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/mimir"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/mimir"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "miniflux",
      "name": "miniflux",
      "category": "Apps & productivity",
      "summary": "Minimalist, opinionated RSS and Atom feed reader with a clean web UI and a REST API. Single pure-Go static binary on a hardened nonroot Wolfi base; needs PostgreSQL at runtime (operator-provided).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.3.2",
      "versions": [
        {
          "version": "2.3.2",
          "size": "8.9 MB",
          "published": "2026-07-22T08:30:10Z",
          "digest": "sha256:f4b847570d250f8e72f73acbe0d07d67feeeb0d624ef935305ab8950819e51da"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://miniflux.app",
      "source": "https://github.com/miniflux/v2",
      "image": "ghcr.io/quenchworks/images/miniflux",
      "security": {
        "image": "ghcr.io/quenchworks/images/miniflux",
        "version": "2.3.2",
        "tag": "ghcr.io/quenchworks/images/miniflux:2.3.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/miniflux"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.3.2",
            "tag": "ghcr.io/quenchworks/images/miniflux:2.3.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/miniflux"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mlflow",
      "name": "mlflow",
      "category": "Machine learning & AI",
      "summary": "MLflow Tracking Server for the ML lifecycle — experiment tracking, model registry, and run metadata over a REST/UI on port 5000. Packaged as the lightweight mlflow-skinny stack (gunicorn + psycopg2 + boto3) on a hardened Wolfi python base; needs an external PostgreSQL backend store and an artifact store (S3 or PVC).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.14.0, 3.15.0",
      "versions": [
        {
          "version": "3.14.0",
          "size": "127.0 MB",
          "published": "2026-08-02T08:53:06Z",
          "digest": "sha256:11ec7fa49d9f768d244d3bc0b1a0642d4601358e788dda87072f58c696d7f8ce"
        },
        {
          "version": "3.15.0",
          "size": "127.5 MB",
          "published": "2026-08-02T08:53:04Z",
          "digest": "sha256:cbbf30d07031de8545950d0aae2c5b4b0264a067b2151f0714462660ee796319"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mlflow.org",
      "source": "https://github.com/mlflow/mlflow",
      "image": "ghcr.io/quenchworks/images/mlflow",
      "security": {
        "image": "ghcr.io/quenchworks/images/mlflow",
        "version": "3.15.0",
        "tag": "ghcr.io/quenchworks/images/mlflow:3.15.0",
        "critical": 0,
        "high": 6,
        "medium": 3,
        "low": 0,
        "unknown": 0,
        "total": 9,
        "fixable": 9,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "GHSA-3f7w-8rr8-f37f",
            "severity": "HIGH",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.57",
            "title": "GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read",
            "url": "https://github.com/advisories/GHSA-3f7w-8rr8-f37f",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-4gmw-gg2m-w46p",
            "severity": "HIGH",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.58",
            "title": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite",
            "url": "https://github.com/advisories/GHSA-4gmw-gg2m-w46p",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-9rj7-rf2p-w77r",
            "severity": "HIGH",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.58",
            "title": "GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks",
            "url": "https://github.com/advisories/GHSA-9rj7-rf2p-w77r",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-hmq2-w58f-27jc",
            "severity": "HIGH",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.58",
            "title": "GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython",
            "url": "https://github.com/advisories/GHSA-hmq2-w58f-27jc",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-jm78-9fvv-mhgr",
            "severity": "HIGH",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.58",
            "title": "GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)",
            "url": "https://github.com/advisories/GHSA-jm78-9fvv-mhgr",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-wvpp-8hx9-p66j",
            "severity": "HIGH",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.58",
            "title": "GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution",
            "url": "https://github.com/advisories/GHSA-wvpp-8hx9-p66j",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-539m-9xh6-q6rr",
            "severity": "MEDIUM",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.57",
            "title": "GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()",
            "url": "https://github.com/advisories/GHSA-539m-9xh6-q6rr",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-hh9p-6wh2-4mfc",
            "severity": "MEDIUM",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.58",
            "title": "GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()",
            "url": "https://github.com/advisories/GHSA-hh9p-6wh2-4mfc",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "GHSA-p538-c434-8v24",
            "severity": "MEDIUM",
            "pkg": "GitPython",
            "installed": "3.1.55",
            "fixed": "3.1.56",
            "title": "GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count",
            "url": "https://github.com/advisories/GHSA-p538-c434-8v24",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.15.0",
            "tag": "ghcr.io/quenchworks/images/mlflow:3.15.0",
            "critical": 0,
            "high": 6,
            "medium": 3,
            "low": 0,
            "unknown": 0,
            "total": 9,
            "fixable": 9,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "GHSA-3f7w-8rr8-f37f",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.57",
                "title": "GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read",
                "url": "https://github.com/advisories/GHSA-3f7w-8rr8-f37f",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-4gmw-gg2m-w46p",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite",
                "url": "https://github.com/advisories/GHSA-4gmw-gg2m-w46p",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-9rj7-rf2p-w77r",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks",
                "url": "https://github.com/advisories/GHSA-9rj7-rf2p-w77r",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-hmq2-w58f-27jc",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython",
                "url": "https://github.com/advisories/GHSA-hmq2-w58f-27jc",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-jm78-9fvv-mhgr",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)",
                "url": "https://github.com/advisories/GHSA-jm78-9fvv-mhgr",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-wvpp-8hx9-p66j",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution",
                "url": "https://github.com/advisories/GHSA-wvpp-8hx9-p66j",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-539m-9xh6-q6rr",
                "severity": "MEDIUM",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.57",
                "title": "GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()",
                "url": "https://github.com/advisories/GHSA-539m-9xh6-q6rr",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-hh9p-6wh2-4mfc",
                "severity": "MEDIUM",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()",
                "url": "https://github.com/advisories/GHSA-hh9p-6wh2-4mfc",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-p538-c434-8v24",
                "severity": "MEDIUM",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.56",
                "title": "GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count",
                "url": "https://github.com/advisories/GHSA-p538-c434-8v24",
                "targets": [
                  "Python"
                ]
              }
            ]
          },
          {
            "version": "3.14.0",
            "tag": "ghcr.io/quenchworks/images/mlflow:3.14.0",
            "critical": 0,
            "high": 6,
            "medium": 3,
            "low": 0,
            "unknown": 0,
            "total": 9,
            "fixable": 9,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "GHSA-3f7w-8rr8-f37f",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.57",
                "title": "GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read",
                "url": "https://github.com/advisories/GHSA-3f7w-8rr8-f37f",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-4gmw-gg2m-w46p",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite",
                "url": "https://github.com/advisories/GHSA-4gmw-gg2m-w46p",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-9rj7-rf2p-w77r",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks",
                "url": "https://github.com/advisories/GHSA-9rj7-rf2p-w77r",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-hmq2-w58f-27jc",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython",
                "url": "https://github.com/advisories/GHSA-hmq2-w58f-27jc",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-jm78-9fvv-mhgr",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)",
                "url": "https://github.com/advisories/GHSA-jm78-9fvv-mhgr",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-wvpp-8hx9-p66j",
                "severity": "HIGH",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution",
                "url": "https://github.com/advisories/GHSA-wvpp-8hx9-p66j",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-539m-9xh6-q6rr",
                "severity": "MEDIUM",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.57",
                "title": "GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()",
                "url": "https://github.com/advisories/GHSA-539m-9xh6-q6rr",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-hh9p-6wh2-4mfc",
                "severity": "MEDIUM",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.58",
                "title": "GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()",
                "url": "https://github.com/advisories/GHSA-hh9p-6wh2-4mfc",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "GHSA-p538-c434-8v24",
                "severity": "MEDIUM",
                "pkg": "GitPython",
                "installed": "3.1.55",
                "fixed": "3.1.56",
                "title": "GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count",
                "url": "https://github.com/advisories/GHSA-p538-c434-8v24",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mongodb",
      "name": "MongoDB",
      "category": "Document",
      "summary": "Document (NoSQL) database for JSON-like data. SSPL is not OSI-approved / source-available, not open source; prefer the clean alternative FerretDB or DocumentDB.",
      "tier": "standard",
      "status": "available",
      "license": "SSPL-1.0",
      "licenseClean": "caution",
      "version": "8.0.26, 6.0.29, 7.0.37",
      "versions": [
        {
          "version": "8.0.26",
          "size": "171.9 MB",
          "published": "2026-07-04T11:21:19Z",
          "digest": "sha256:86da138b90eb830a38b3110e00b9b19191bb71d413a2c898134c36631bfe4584"
        },
        {
          "version": "6.0.29",
          "size": "154.5 MB",
          "published": "2026-07-04T11:20:14Z",
          "digest": "sha256:5266cccb060d860226a009367b8a2e1a1653334443f10c1c4a83733abba7887d"
        },
        {
          "version": "7.0.37",
          "size": "163.1 MB",
          "published": "2026-07-04T11:17:14Z",
          "digest": "sha256:f5822cf3da3837f9b08f54ceedd04c31bae842f504d09dad45dd09217747068e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/mongodb/mongo",
      "source": "https://github.com/mongodb/mongo",
      "image": "ghcr.io/quenchworks/images/mongodb",
      "caution": true,
      "cleanAlternative": "FerretDB + DocumentDB — MongoDB-wire-compatible and truly open (Apache-2.0 / PostgreSQL).",
      "security": {
        "image": "ghcr.io/quenchworks/images/mongodb",
        "version": "8.0.26",
        "tag": "ghcr.io/quenchworks/images/mongodb:8.0.26",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "C",
        "score": 91,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/mongodb@sha256:86da138b90eb830a38b3110e00b9b19191bb71d413a2c898134c36631bfe4584 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "8.0.26",
            "tag": "ghcr.io/quenchworks/images/mongodb:8.0.26",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/mongodb@sha256:86da138b90eb830a38b3110e00b9b19191bb71d413a2c898134c36631bfe4584 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "7.0.37",
            "tag": "ghcr.io/quenchworks/images/mongodb:7.0.37",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/mongodb@sha256:f5822cf3da3837f9b08f54ceedd04c31bae842f504d09dad45dd09217747068e (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "6.0.29",
            "tag": "ghcr.io/quenchworks/images/mongodb:6.0.29",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/mongodb@sha256:5266cccb060d860226a009367b8a2e1a1653334443f10c1c4a83733abba7887d (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mosquitto",
      "name": "mosquitto",
      "category": "Messaging",
      "summary": "Lightweight Eclipse MQTT broker for IoT and pub/sub messaging. Speaks MQTT 3.1/3.1.1/5.0 over TCP, TLS, and websockets; built from source with OpenSSL and a hardened nonroot, read-only-rootfs runtime.",
      "tier": "standard",
      "status": "available",
      "license": "EPL-2.0 OR BSD-3-Clause",
      "licenseClean": "clean",
      "version": "2.1.0, 2.1.1, 2.1.2",
      "versions": [
        {
          "version": "2.1.0",
          "size": "10.1 MB",
          "published": "2026-07-04T11:18:52Z",
          "digest": "sha256:0ae9bdf6c85b614f031c00f080fe87c9728927a5a96bb068a49215cf699663a5"
        },
        {
          "version": "2.1.1",
          "size": "10.1 MB",
          "published": "2026-07-04T11:16:49Z",
          "digest": "sha256:9b657e1f05ac78e6f45a10e1cd9d2c7f8b416c541ce47365250a219097716578"
        },
        {
          "version": "2.1.2",
          "size": "10.1 MB",
          "published": "2026-07-04T11:11:16Z",
          "digest": "sha256:bd01aa290b0d387335e6faa2ba578bc81cf8c4178c694db257b0817d4a02cc5e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mosquitto.org",
      "source": "https://github.com/eclipse-mosquitto/mosquitto",
      "image": "ghcr.io/quenchworks/images/mosquitto",
      "security": {
        "image": "ghcr.io/quenchworks/images/mosquitto",
        "version": "2.1.2",
        "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.1.2",
            "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.1.1",
            "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mysql",
      "name": "MySQL",
      "category": "Relational",
      "summary": "Widely used open-source relational database for general-purpose OLTP workloads, with broad framework and tooling support.",
      "tier": "critical",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "8.4.11, 9.7.2",
      "versions": [
        {
          "version": "8.4.11",
          "size": "149.9 MB",
          "published": "2026-07-30T09:07:32Z",
          "digest": "sha256:9707870ea4984e5ce8585f0836f30e3c457d361a0911e72a262b79e66fdec0d3"
        },
        {
          "version": "9.7.2",
          "size": "157.4 MB",
          "published": "2026-07-30T09:07:19Z",
          "digest": "sha256:01e08bae9a563f645e776a868274c3a9bf0a405891d3615cd59ef6aab0f2a9e7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/mysql/mysql-server",
      "source": "https://dev.mysql.com/get/Downloads/MySQL-9.7/mysql-9.7.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/mysql",
      "security": {
        "image": "ghcr.io/quenchworks/images/mysql",
        "version": "9.7.2",
        "tag": "ghcr.io/quenchworks/images/mysql:9.7.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.7.2",
            "tag": "ghcr.io/quenchworks/images/mysql:9.7.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.4.11",
            "tag": "ghcr.io/quenchworks/images/mysql:8.4.11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "n8n",
      "name": "n8n",
      "category": "Workflow",
      "summary": "Fair-code workflow automation platform — build integrations and automations across 400+ apps via a visual node editor, with native AI/LLM agent nodes. Node build on a hardened nonroot Wolfi base; the flagged transitive npm CVE class is cleared image-side with pinned overrides.",
      "tier": "standard",
      "status": "available",
      "license": "LicenseRef-n8n-Sustainable-Use-License-1.0",
      "licenseClean": "clean",
      "version": "2.32.7",
      "versions": [
        {
          "version": "2.32.7",
          "size": "398.7 MB",
          "published": "2026-08-02T09:03:05Z",
          "digest": "sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://n8n.io",
      "source": "https://github.com/n8n-io/n8n",
      "image": "ghcr.io/quenchworks/images/n8n",
      "security": {
        "image": "ghcr.io/quenchworks/images/n8n",
        "version": "2.32.7",
        "tag": "ghcr.io/quenchworks/images/n8n:2.32.7",
        "critical": 0,
        "high": 5,
        "medium": 7,
        "low": 2,
        "unknown": 0,
        "total": 14,
        "fixable": 11,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-58043",
            "severity": "HIGH",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
            "targets": [
              "ghcr.io/quenchworks/images/n8n@sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-67213",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.16",
            "fixed": "3.3.17, 5.1.6",
            "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-67213",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.8",
            "fixed": "3.3.17, 5.1.6",
            "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-67214",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.8",
            "fixed": "3.3.16, 5.1.16",
            "title": "nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67214",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69152",
            "severity": "HIGH",
            "pkg": "brace-expansion",
            "installed": "5.0.8",
            "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
            "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/n8n@sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-69207",
            "severity": "MEDIUM",
            "pkg": "hono",
            "installed": "4.12.33",
            "fixed": "4.12.34",
            "title": "Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69207",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-71848",
            "severity": "MEDIUM",
            "pkg": "hono",
            "installed": "4.12.33",
            "fixed": "4.12.34",
            "title": "Hono: Algorithmic Complexity DoS in Language Middleware",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71848",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-71850",
            "severity": "MEDIUM",
            "pkg": "hono",
            "installed": "4.12.33",
            "fixed": "4.12.34",
            "title": "Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71850",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2024-1899",
            "severity": "MEDIUM",
            "pkg": "showdown",
            "installed": "2.1.0",
            "fixed": null,
            "title": "Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing",
            "url": "https://avd.aquasec.com/nvd/cve-2024-1899",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-59710",
            "severity": "MEDIUM",
            "pkg": "showdown",
            "installed": "2.1.0",
            "fixed": null,
            "title": "showdown: Showdown: Stored Cross-Site Scripting via unescaped table header ID attributes in markdown",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59710",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-59711",
            "severity": "MEDIUM",
            "pkg": "showdown",
            "installed": "2.1.0",
            "fixed": null,
            "title": "showdown: Showdown: Cross-site scripting via unescaped metadata title allows arbitrary code execution",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59711",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56847",
            "severity": "LOW",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
            "targets": [
              "ghcr.io/quenchworks/images/n8n@sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-71849",
            "severity": "LOW",
            "pkg": "hono",
            "installed": "4.12.33",
            "fixed": "4.12.34",
            "title": "Hono: Proxy Helper does not remove response headers listed in the `Connection` header",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71849",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.32.7",
            "tag": "ghcr.io/quenchworks/images/n8n:2.32.7",
            "critical": 0,
            "high": 5,
            "medium": 7,
            "low": 2,
            "unknown": 0,
            "total": 14,
            "fixable": 11,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/n8n@sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-67213",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.16",
                "fixed": "3.3.17, 5.1.6",
                "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-67213",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.8",
                "fixed": "3.3.17, 5.1.6",
                "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-67214",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.8",
                "fixed": "3.3.16, 5.1.16",
                "title": "nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67214",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/n8n@sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69207",
                "severity": "MEDIUM",
                "pkg": "hono",
                "installed": "4.12.33",
                "fixed": "4.12.34",
                "title": "Hono: ReDoS in CORS middleware via Access-Control-Request-Headers",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69207",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-71848",
                "severity": "MEDIUM",
                "pkg": "hono",
                "installed": "4.12.33",
                "fixed": "4.12.34",
                "title": "Hono: Algorithmic Complexity DoS in Language Middleware",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71848",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-71850",
                "severity": "MEDIUM",
                "pkg": "hono",
                "installed": "4.12.33",
                "fixed": "4.12.34",
                "title": "Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71850",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2024-1899",
                "severity": "MEDIUM",
                "pkg": "showdown",
                "installed": "2.1.0",
                "fixed": null,
                "title": "Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2024-1899",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-59710",
                "severity": "MEDIUM",
                "pkg": "showdown",
                "installed": "2.1.0",
                "fixed": null,
                "title": "showdown: Showdown: Stored Cross-Site Scripting via unescaped table header ID attributes in markdown",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59710",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-59711",
                "severity": "MEDIUM",
                "pkg": "showdown",
                "installed": "2.1.0",
                "fixed": null,
                "title": "showdown: Showdown: Cross-site scripting via unescaped metadata title allows arbitrary code execution",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59711",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/n8n@sha256:5c8e6d281041e0d9b2063c24911f5129d683f714a1cc967fdde9cd7eedb5daec (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-71849",
                "severity": "LOW",
                "pkg": "hono",
                "installed": "4.12.33",
                "fixed": "4.12.34",
                "title": "Hono: Proxy Helper does not remove response headers listed in the `Connection` header",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71849",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "n8n-runners",
      "name": "n8n-runners",
      "category": "Workflow",
      "summary": "n8n external task-runner sidecar — isolates and executes workflow code (JS/Python) out of the main n8n process for security and scale. Built from source on Wolfi. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "LicenseRef-n8n-Sustainable-Use-License-1.0",
      "licenseClean": "clean",
      "version": "2.32.7",
      "versions": [
        {
          "version": "2.32.7",
          "size": "181.8 MB",
          "published": "2026-08-02T08:41:43Z",
          "digest": "sha256:45ae091187d4893ecf2eeb92750b057c87fa7e17b7049055c10ec6fb1fdc1f01"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://n8n.io",
      "source": "https://github.com/n8n-io/n8n",
      "image": "ghcr.io/quenchworks/images/n8n-runners",
      "security": {
        "image": "ghcr.io/quenchworks/images/n8n-runners",
        "version": "2.32.7",
        "tag": "ghcr.io/quenchworks/images/n8n-runners:2.32.7",
        "critical": 0,
        "high": 6,
        "medium": 11,
        "low": 0,
        "unknown": 0,
        "total": 17,
        "fixable": 17,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-67213",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.8",
            "fixed": "3.3.17, 5.1.6",
            "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-67214",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.8",
            "fixed": "3.3.16, 5.1.16",
            "title": "nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67214",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69152",
            "severity": "HIGH",
            "pkg": "brace-expansion",
            "installed": "5.0.8",
            "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
            "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69192",
            "severity": "HIGH",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.3.1",
            "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-15157",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
            "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16728",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16729",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-54272",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.1",
            "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-24",
            "installed": "24.18.1-r1",
            "fixed": "24.19.0-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/n8n-runners@sha256:45ae091187d4893ecf2eeb92750b057c87fa7e17b7049055c10ec6fb1fdc1f01 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-69198",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.2",
            "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.32.7",
            "tag": "ghcr.io/quenchworks/images/n8n-runners:2.32.7",
            "critical": 0,
            "high": 6,
            "medium": 11,
            "low": 0,
            "unknown": 0,
            "total": 17,
            "fixable": 17,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-67213",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.8",
                "fixed": "3.3.17, 5.1.6",
                "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-67214",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.8",
                "fixed": "3.3.16, 5.1.16",
                "title": "nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67214",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69192",
                "severity": "HIGH",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.3.1",
                "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-54272",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.1",
                "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-24",
                "installed": "24.18.1-r1",
                "fixed": "24.19.0-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/n8n-runners@sha256:45ae091187d4893ecf2eeb92750b057c87fa7e17b7049055c10ec6fb1fdc1f01 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69198",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.2",
                "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "nats",
      "name": "NATS",
      "category": "Messaging",
      "summary": "Lightweight, high-performance messaging system for cloud-native pub/sub and request-reply, with optional JetStream persistence and streaming.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.14.3, 2.14.2, 2.14.4",
      "versions": [
        {
          "version": "2.14.3",
          "size": "6.6 MB",
          "published": "2026-08-02T08:43:18Z",
          "digest": "sha256:a0e792a6833fd94135700898ae3f9b55d9e661e6d3a1ec431e26bdf7b19ce190"
        },
        {
          "version": "2.14.2",
          "size": "6.6 MB",
          "published": "2026-08-02T08:43:00Z",
          "digest": "sha256:b0f8ce231b6d45fe4038be56e950c9d81751390d40a67ee305b4835153dc0a4b"
        },
        {
          "version": "2.14.4",
          "size": "6.6 MB",
          "published": "2026-08-02T08:42:58Z",
          "digest": "sha256:03927b898680b302ad2ab29c7d07afbf807ff1a00fbe4bad0b1e660fb53db0ea"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/nats-io/nats-server",
      "source": "https://github.com/nats-io/nats-server",
      "image": "ghcr.io/quenchworks/images/nats",
      "security": {
        "image": "ghcr.io/quenchworks/images/nats",
        "version": "2.14.4",
        "tag": "ghcr.io/quenchworks/images/nats:2.14.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/nats-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.14.4",
            "tag": "ghcr.io/quenchworks/images/nats:2.14.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/nats-server"
                ]
              }
            ]
          },
          {
            "version": "2.14.3",
            "tag": "ghcr.io/quenchworks/images/nats:2.14.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/nats-server"
                ]
              }
            ]
          },
          {
            "version": "2.14.2",
            "tag": "ghcr.io/quenchworks/images/nats:2.14.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/nats-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "navidrome",
      "name": "navidrome",
      "category": "Media & streaming",
      "summary": "Self-hosted music server and streamer compatible with the Subsonic/OpenSubsonic API, with a modern web UI. From source (React UI embedded, CGO+static-musl SQLite) on a hardened nonroot Wolfi base; music and data on writable volumes.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0",
      "licenseClean": "agpl",
      "version": "0.62.0",
      "versions": [
        {
          "version": "0.62.0",
          "size": "22.2 MB",
          "published": "2026-07-23T12:02:55Z",
          "digest": "sha256:898cde2401631e113731e4232b5451643bdb3167f27b2b47b37df400ffa8bfe5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.navidrome.org",
      "source": "https://github.com/navidrome/navidrome",
      "image": "ghcr.io/quenchworks/images/navidrome",
      "security": {
        "image": "ghcr.io/quenchworks/images/navidrome",
        "version": "0.62.0",
        "tag": "ghcr.io/quenchworks/images/navidrome:0.62.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/navidrome"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.62.0",
            "tag": "ghcr.io/quenchworks/images/navidrome:0.62.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/navidrome"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "neo4j",
      "name": "Neo4j",
      "category": "Graph",
      "summary": "Graph database for highly connected data, queried with Cypher for traversals and relationship-heavy workloads. Community edition is GPLv3.",
      "tier": "low",
      "status": "available",
      "license": "GPL-3.0",
      "licenseClean": "agpl",
      "version": "2026.05.0",
      "versions": [
        {
          "version": "2026.05.0",
          "size": "243.5 MB",
          "published": "2026-07-28T06:23:30Z",
          "digest": "sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/neo4j/neo4j",
      "source": "https://github.com/neo4j/neo4j",
      "image": "ghcr.io/quenchworks/images/neo4j",
      "security": {
        "image": "ghcr.io/quenchworks/images/neo4j",
        "version": "2026.05.0",
        "tag": "ghcr.io/quenchworks/images/neo4j:2026.05.0",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "C",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/neo4j@sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/neo4j@sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/neo4j@sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "2026.05.0",
            "tag": "ghcr.io/quenchworks/images/neo4j:2026.05.0",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "C",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/neo4j@sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/neo4j@sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/neo4j@sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "nextcloud",
      "name": "nextcloud",
      "category": "Apps & productivity",
      "summary": "Nextcloud, the self-hosted file-sync and content-collaboration platform. Reconstructed clean-room on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs); the chart installs via occ and provides a MariaDB backend. Nextcloud is AGPL-3.0-only (strong copyleft).",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "34.0.2",
      "versions": [
        {
          "version": "34.0.2",
          "size": "436.7 MB",
          "published": "2026-07-26T12:30:15Z",
          "digest": "sha256:e20d5f20e45e5c9c5405629738defe66b5f6997da3a55e1c262123051a0c3a54"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://nextcloud.com",
      "source": "https://download.nextcloud.com/server/releases/nextcloud-34.0.1.tar.bz2",
      "image": "ghcr.io/quenchworks/images/nextcloud",
      "security": {
        "image": "ghcr.io/quenchworks/images/nextcloud",
        "version": "34.0.2",
        "tag": "ghcr.io/quenchworks/images/nextcloud:34.0.2",
        "critical": 0,
        "high": 2,
        "medium": 3,
        "low": 0,
        "unknown": 0,
        "total": 5,
        "fixable": 5,
        "grade": "D",
        "score": 43,
        "cves": [
          {
            "id": "CVE-2026-69246",
            "severity": "HIGH",
            "pkg": "guzzlehttp/guzzle",
            "installed": "7.15.1",
            "fixed": "7.15.2, 8.0.1",
            "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69246",
            "targets": [
              "var/www/html/3rdparty/composer/installed.json",
              "var/www/html/apps/notifications/vendor/composer/installed.json"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/nextcloud@sha256:e20d5f20e45e5c9c5405629738defe66b5f6997da3a55e1c262123051a0c3a54 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-69245",
            "severity": "MEDIUM",
            "pkg": "guzzlehttp/guzzle",
            "installed": "7.15.1",
            "fixed": "7.15.2, 8.0.1",
            "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69245",
            "targets": [
              "var/www/html/3rdparty/composer/installed.json",
              "var/www/html/apps/notifications/vendor/composer/installed.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "34.0.2",
            "tag": "ghcr.io/quenchworks/images/nextcloud:34.0.2",
            "critical": 0,
            "high": 2,
            "medium": 3,
            "low": 0,
            "unknown": 0,
            "total": 5,
            "fixable": 5,
            "grade": "D",
            "score": 43,
            "cves": [
              {
                "id": "CVE-2026-69246",
                "severity": "HIGH",
                "pkg": "guzzlehttp/guzzle",
                "installed": "7.15.1",
                "fixed": "7.15.2, 8.0.1",
                "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69246",
                "targets": [
                  "var/www/html/3rdparty/composer/installed.json",
                  "var/www/html/apps/notifications/vendor/composer/installed.json"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/nextcloud@sha256:e20d5f20e45e5c9c5405629738defe66b5f6997da3a55e1c262123051a0c3a54 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69245",
                "severity": "MEDIUM",
                "pkg": "guzzlehttp/guzzle",
                "installed": "7.15.1",
                "fixed": "7.15.2, 8.0.1",
                "title": "Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69245",
                "targets": [
                  "var/www/html/3rdparty/composer/installed.json",
                  "var/www/html/apps/notifications/vendor/composer/installed.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "nginx",
      "name": "nginx",
      "category": "Gateway",
      "summary": "High-performance web server, reverse proxy, and load balancer for serving static content and fronting application backends.",
      "tier": "critical",
      "status": "available",
      "license": "BSD-2-Clause",
      "licenseClean": "clean",
      "version": "1.30.4, 1.26.3, 1.28.3",
      "versions": [
        {
          "version": "1.30.4",
          "size": "11.5 MB",
          "published": "2026-07-21T08:28:25Z",
          "digest": "sha256:ba15d418a862217869a6f90e2912b9acdfb54864d26395e8a8e753ea5823e30f"
        },
        {
          "version": "1.26.3",
          "size": "11.3 MB",
          "published": "2026-07-21T08:28:23Z",
          "digest": "sha256:c88b1d331faeabed253d858fe68391e60bc8ce566cffe41e2d88f5eca4b48745"
        },
        {
          "version": "1.28.3",
          "size": "11.4 MB",
          "published": "2026-07-21T08:28:13Z",
          "digest": "sha256:70def6a2dda1da1e9ac9665c22867b40411542301c62f904ec252b1b8708cca9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/nginx/nginx",
      "source": "https://github.com/nginx/nginx",
      "image": "ghcr.io/quenchworks/images/nginx",
      "security": {
        "image": "ghcr.io/quenchworks/images/nginx",
        "version": "1.30.4",
        "tag": "ghcr.io/quenchworks/images/nginx:1.30.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.30.4",
            "tag": "ghcr.io/quenchworks/images/nginx:1.30.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.28.3",
            "tag": "ghcr.io/quenchworks/images/nginx:1.28.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.26.3",
            "tag": "ghcr.io/quenchworks/images/nginx:1.26.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "node",
      "name": "node",
      "category": "Language runtime",
      "summary": "Hardened Node.js runtime with npm, a 0-CVE signed nonroot base image for JavaScript apps. Active LTS lines (20/22/24).",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "22.23.1, 24.18.1, 26.5.1",
      "versions": [
        {
          "version": "22.23.1",
          "size": "55.7 MB",
          "published": "2026-08-02T08:43:39Z",
          "digest": "sha256:2c698892bc203461cdf64dd2de58ce7b93e9e7ea0661d322f20603c95f80f114"
        },
        {
          "version": "24.18.1",
          "size": "56.1 MB",
          "published": "2026-08-02T08:43:37Z",
          "digest": "sha256:0b15aeefc7cd9c3e21521d9621f49f13a013d8b734092abc569dd0c136b913f4"
        },
        {
          "version": "26.5.1",
          "size": "60.4 MB",
          "published": "2026-08-02T08:43:37Z",
          "digest": "sha256:f4dae35c320c565e03e6b3c3506564b287726c8c9750e0d0c1a3e1b7fb2b956c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/nodejs/node",
      "source": "https://github.com/nodejs/node",
      "image": "ghcr.io/quenchworks/images/node",
      "security": {
        "image": "ghcr.io/quenchworks/images/node",
        "version": "26.5.1",
        "tag": "ghcr.io/quenchworks/images/node:26.5.1",
        "critical": 0,
        "high": 4,
        "medium": 10,
        "low": 0,
        "unknown": 0,
        "total": 14,
        "fixable": 14,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-69152",
            "severity": "HIGH",
            "pkg": "brace-expansion",
            "installed": "5.0.8",
            "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
            "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69192",
            "severity": "HIGH",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.3.1",
            "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-15157",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
            "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16728",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-16729",
            "severity": "MEDIUM",
            "pkg": "undici",
            "installed": "6.27.0",
            "fixed": "6.28.0, 7.29.0, 8.9.0",
            "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
            "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-54272",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.1",
            "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-69198",
            "severity": "MEDIUM",
            "pkg": "ip-address",
            "installed": "10.2.0",
            "fixed": "10.2.2",
            "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "26.5.1",
            "tag": "ghcr.io/quenchworks/images/node:26.5.1",
            "critical": 0,
            "high": 4,
            "medium": 10,
            "low": 0,
            "unknown": 0,
            "total": 14,
            "fixable": 14,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69192",
                "severity": "HIGH",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.3.1",
                "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-54272",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.1",
                "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69198",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.2",
                "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          },
          {
            "version": "24.18.1",
            "tag": "ghcr.io/quenchworks/images/node:24.18.1",
            "critical": 0,
            "high": 4,
            "medium": 11,
            "low": 0,
            "unknown": 0,
            "total": 15,
            "fixable": 15,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69192",
                "severity": "HIGH",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.3.1",
                "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-54272",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.1",
                "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-24",
                "installed": "24.18.1-r1",
                "fixed": "24.19.0-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/node@sha256:0b15aeefc7cd9c3e21521d9621f49f13a013d8b734092abc569dd0c136b913f4 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69198",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.2",
                "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          },
          {
            "version": "22.23.1",
            "tag": "ghcr.io/quenchworks/images/node:22.23.1",
            "critical": 0,
            "high": 5,
            "medium": 11,
            "low": 1,
            "unknown": 0,
            "total": 17,
            "fixable": 17,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/node@sha256:2c698892bc203461cdf64dd2de58ce7b93e9e7ea0661d322f20603c95f80f114 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-69192",
                "severity": "HIGH",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.3.1",
                "title": "ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69192",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-15157",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: HTTP header injection via unvalidated blob-like body type property",
                "url": "https://avd.aquasec.com/nvd/cve-2026-15157",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16728",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16728",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-16729",
                "severity": "MEDIUM",
                "pkg": "undici",
                "installed": "6.27.0",
                "fixed": "6.28.0, 7.29.0, 8.9.0",
                "title": "undici: Undici: Cookie attribute injection allows bypassing security protections",
                "url": "https://avd.aquasec.com/nvd/cve-2026-16729",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-54272",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.1",
                "title": "ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54272",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/node@sha256:2c698892bc203461cdf64dd2de58ce7b93e9e7ea0661d322f20603c95f80f114 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-69198",
                "severity": "MEDIUM",
                "pkg": "ip-address",
                "installed": "10.2.0",
                "fixed": "10.2.2",
                "title": "ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69198",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/node@sha256:2c698892bc203461cdf64dd2de58ce7b93e9e7ea0661d322f20603c95f80f114 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "node-exporter",
      "name": "node-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter for host-level hardware and OS metrics (CPU, memory, disk, network) on Linux machines.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.12.1",
      "versions": [
        {
          "version": "1.12.1",
          "size": "6.5 MB",
          "published": "2026-07-15T12:44:28Z",
          "digest": "sha256:4426d70c51fc41c540da00ba3f3631c7a8e72165062fcb48e9dc9be3933977b7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/node_exporter",
      "source": "https://github.com/prometheus/node_exporter",
      "image": "ghcr.io/quenchworks/images/node-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/node-exporter",
        "version": "1.12.1",
        "tag": "ghcr.io/quenchworks/images/node-exporter:1.12.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/node_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.12.1",
            "tag": "ghcr.io/quenchworks/images/node-exporter:1.12.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/node_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "nsq",
      "name": "nsq",
      "category": "Messaging",
      "summary": "Realtime distributed messaging platform. Ships nsqd, nsqlookupd, and nsqadmin as static Go binaries on a hardened nonroot Wolfi base; nsqd data path is a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.2.1, 1.3.0, 1.2.0",
      "versions": [
        {
          "version": "1.2.1",
          "size": "11.3 MB",
          "published": "2026-07-08T10:55:09Z",
          "digest": "sha256:78d18e0395103feb3281328991624be00556278f85b92319e8eaf4a8c6e1c276"
        },
        {
          "version": "1.3.0",
          "size": "11.0 MB",
          "published": "2026-07-08T10:55:07Z",
          "digest": "sha256:6605a00792074485207398ebba6178ef11d4037aa1fbcc734b6dc0e1b4254cc5"
        },
        {
          "version": "1.2.0",
          "size": "10.9 MB",
          "published": "2026-07-08T10:51:28Z",
          "digest": "sha256:b32cfd806654bb5c9ea11f5a01212400917e3c45315fcbfdd64d35420325178f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://nsq.io",
      "source": "https://github.com/nsqio/nsq",
      "image": "ghcr.io/quenchworks/images/nsq",
      "security": {
        "image": "ghcr.io/quenchworks/images/nsq",
        "version": "1.3.0",
        "tag": "ghcr.io/quenchworks/images/nsq:1.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.3.0",
            "tag": "ghcr.io/quenchworks/images/nsq:1.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.2.1",
            "tag": "ghcr.io/quenchworks/images/nsq:1.2.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.2.0",
            "tag": "ghcr.io/quenchworks/images/nsq:1.2.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "ntfy",
      "name": "ntfy",
      "category": "Messaging",
      "summary": "Simple HTTP-based pub-sub notification service for sending push notifications to phones and desktops from any script. From source with the web UI embedded (no Node at runtime) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.25.0",
      "versions": [
        {
          "version": "2.25.0",
          "size": "20.4 MB",
          "published": "2026-07-22T08:59:26Z",
          "digest": "sha256:8e8b81c670e8b45851d76e84f64fb896440948dc755014b4462443037be18f85"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ntfy.sh",
      "source": "https://github.com/binwiederhier/ntfy",
      "image": "ghcr.io/quenchworks/images/ntfy",
      "security": {
        "image": "ghcr.io/quenchworks/images/ntfy",
        "version": "2.25.0",
        "tag": "ghcr.io/quenchworks/images/ntfy:2.25.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/ntfy"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.25.0",
            "tag": "ghcr.io/quenchworks/images/ntfy:2.25.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/ntfy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "oauth2-proxy",
      "name": "oauth2-proxy",
      "category": "Secrets & identity",
      "summary": "Reverse-proxy authentication layer that secures upstream apps by delegating sign-in to OIDC and OAuth2 providers.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "7.15.3",
      "versions": [
        {
          "version": "7.15.3",
          "size": "9.9 MB",
          "published": "2026-07-22T07:05:27Z",
          "digest": "sha256:3a469bcaacf5f3d63b941e8e14f5e6d9a596632e31d7f2782a84709b44acb980"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://oauth2-proxy.github.io/oauth2-proxy/",
      "source": "https://github.com/oauth2-proxy/oauth2-proxy",
      "image": "ghcr.io/quenchworks/images/oauth2-proxy",
      "security": {
        "image": "ghcr.io/quenchworks/images/oauth2-proxy",
        "version": "7.15.3",
        "tag": "ghcr.io/quenchworks/images/oauth2-proxy:7.15.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/oauth2-proxy"
            ]
          }
        ],
        "versions": [
          {
            "version": "7.15.3",
            "tag": "ghcr.io/quenchworks/images/oauth2-proxy:7.15.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/oauth2-proxy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ollama",
      "name": "ollama",
      "category": "Machine learning & AI",
      "summary": "Local LLM runtime that pulls, runs, and serves open models (Llama, Gemma, Qwen, DeepSeek, and more) behind a simple REST API. CPU-only image; the chart mounts a writable volume for the model store.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.32.5",
      "versions": [
        {
          "version": "0.32.5",
          "size": "1.6 GB",
          "published": "2026-07-28T09:49:28Z",
          "digest": "sha256:3b2f7a4980d2e1f292a756e66e28d603b829b9e3740c3997b0800bc5e47ab190"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ollama.com",
      "source": "https://github.com/ollama/ollama",
      "image": "ghcr.io/quenchworks/images/ollama",
      "security": {
        "image": "ghcr.io/quenchworks/images/ollama",
        "version": "0.32.5",
        "tag": "ghcr.io/quenchworks/images/ollama:0.32.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/ollama"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.32.5",
            "tag": "ghcr.io/quenchworks/images/ollama:0.32.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/ollama"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "opa",
      "name": "opa",
      "category": "Security & supply chain",
      "summary": "Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control, and configuration rules across the stack.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.19.0",
      "versions": [
        {
          "version": "1.19.0",
          "size": "13.7 MB",
          "published": "2026-08-02T08:42:11Z",
          "digest": "sha256:bedf2af19a72b70baebce6c86d7ce470eadcfcd1e12881344df760c5775ae617"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.openpolicyagent.org",
      "source": "https://github.com/open-policy-agent/opa",
      "image": "ghcr.io/quenchworks/images/opa",
      "security": {
        "image": "ghcr.io/quenchworks/images/opa",
        "version": "1.19.0",
        "tag": "ghcr.io/quenchworks/images/opa:1.19.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/opa"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.19.0",
            "tag": "ghcr.io/quenchworks/images/opa:1.19.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/opa"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "openbao",
      "name": "OpenBao",
      "category": "Secrets",
      "summary": "Open-source secrets and encryption management for tokens, keys, and certificates, with dynamic secrets and leasing. The Linux Foundation MPL-2.0 community fork of HashiCorp Vault.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "2.6.1",
      "versions": [
        {
          "version": "2.6.1",
          "size": "42.2 MB",
          "published": "2026-07-30T08:08:12Z",
          "digest": "sha256:a27e51c4ac384b57e5141aaf0435163c8c3d36cd185510a163eb5126e56d6394"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/openbao/openbao",
      "source": "https://github.com/openbao/openbao",
      "image": "ghcr.io/quenchworks/images/openbao",
      "security": {
        "image": "ghcr.io/quenchworks/images/openbao",
        "version": "2.6.1",
        "tag": "ghcr.io/quenchworks/images/openbao:2.6.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/bao"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.6.1",
            "tag": "ghcr.io/quenchworks/images/openbao:2.6.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/bao"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "openfga",
      "name": "openfga",
      "category": "Identity",
      "summary": "Fine-grained authorization engine (Zanzibar-style relationship-based access control) over HTTP and gRPC. From source on a hardened nonroot Wolfi base; datastore is the operator's choice.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.1",
      "versions": [
        {
          "version": "1.18.1",
          "size": "20.6 MB",
          "published": "2026-07-26T12:32:15Z",
          "digest": "sha256:74d0198bcd52281d335e1e9c120a4d78154191204f90a8f75e6db38fde482977"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://openfga.dev",
      "source": "https://github.com/openfga/openfga",
      "image": "ghcr.io/quenchworks/images/openfga",
      "security": {
        "image": "ghcr.io/quenchworks/images/openfga",
        "version": "1.18.1",
        "tag": "ghcr.io/quenchworks/images/openfga:1.18.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.18.1",
            "tag": "ghcr.io/quenchworks/images/openfga:1.18.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "openldap",
      "name": "openldap",
      "category": "Identity",
      "summary": "OpenLDAP slapd, the reference open-source LDAP directory server, with the LMDB (back-mdb) backend and the client tools. Runs nonroot on unprivileged ports 1389/1636 and backs directory-driven auth for the identity stack.",
      "tier": "standard",
      "status": "available",
      "license": "OLDAP-2.8",
      "licenseClean": "clean",
      "version": "2.6.13",
      "versions": [
        {
          "version": "2.6.13",
          "size": "11.9 MB",
          "published": "2026-07-26T12:27:22Z",
          "digest": "sha256:b4c9a8113cf797fb24528d2557671edb9021ebe34540ca1d5e9e5cf899142d86"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.openldap.org",
      "source": "https://git.openldap.org/openldap/openldap",
      "image": "ghcr.io/quenchworks/images/openldap",
      "security": {
        "image": "ghcr.io/quenchworks/images/openldap",
        "version": "2.6.13",
        "tag": "ghcr.io/quenchworks/images/openldap:2.6.13",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.6.13",
            "tag": "ghcr.io/quenchworks/images/openldap:2.6.13",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "opensearch",
      "name": "OpenSearch",
      "category": "Search",
      "summary": "Search and analytics suite with a Kibana-style dashboards UI. The Apache-2.0 community fork of Elasticsearch and the recommended open alternative.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.7.0",
      "versions": [
        {
          "version": "3.7.0",
          "size": "965.3 MB",
          "published": "2026-07-15T11:22:08Z",
          "digest": "sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/opensearch-project/OpenSearch",
      "source": "https://github.com/opensearch-project/OpenSearch",
      "image": "ghcr.io/quenchworks/images/opensearch",
      "security": {
        "image": "ghcr.io/quenchworks/images/opensearch",
        "version": "3.7.0",
        "tag": "ghcr.io/quenchworks/images/opensearch:3.7.0",
        "critical": 0,
        "high": 23,
        "medium": 34,
        "low": 1,
        "unknown": 0,
        "total": 58,
        "fixable": 58,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-10050",
            "severity": "HIGH",
            "pkg": "org.eclipse.jetty:jetty-security",
            "installed": "9.4.58.v20250814",
            "fixed": "9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
            "title": "In Eclipse Jetty, the Digest authentication server-side component uses ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-10050",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-55831",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing",
            "url": "https://avd.aquasec.com/nvd/cve-2026-55831",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-55833",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification",
            "url": "https://avd.aquasec.com/nvd/cve-2026-55833",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-56745",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56745",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-56816",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http3",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final",
            "title": "Netty is a network application framework for development of protocol s ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56816",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-56819",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http2",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56819",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59901",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-compression",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final",
            "title": "io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59901",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "GHSA-r7wm-3cxj-wff9",
            "severity": "HIGH",
            "pkg": "com.fasterxml.jackson.core:jackson-core",
            "installed": "2.21.3",
            "fixed": "2.18.8, 2.21.4",
            "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
            "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "GHSA-r7wm-3cxj-wff9",
            "severity": "HIGH",
            "pkg": "tools.jackson.core:jackson-core",
            "installed": "3.1.3",
            "fixed": "3.1.4",
            "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
            "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/opensearch@sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/opensearch@sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56746",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56746",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59889",
            "severity": "MEDIUM",
            "pkg": "tools.jackson.core:jackson-databind",
            "installed": "3.1.4",
            "fixed": "3.1.5, 3.2.1",
            "title": "jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59889",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59898",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59898",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59899",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59899",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59900",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http2",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59900",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59921",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59921",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-71497",
            "severity": "MEDIUM",
            "pkg": "org.jsoup:jsoup",
            "installed": "1.15.3",
            "fixed": "1.23.1",
            "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-71497",
            "severity": "MEDIUM",
            "pkg": "org.jsoup:jsoup",
            "installed": "1.19.1",
            "fixed": "1.23.1",
            "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/opensearch@sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.0",
            "tag": "ghcr.io/quenchworks/images/opensearch:3.7.0",
            "critical": 0,
            "high": 23,
            "medium": 34,
            "low": 1,
            "unknown": 0,
            "total": 58,
            "fixable": 58,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-10050",
                "severity": "HIGH",
                "pkg": "org.eclipse.jetty:jetty-security",
                "installed": "9.4.58.v20250814",
                "fixed": "9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
                "title": "In Eclipse Jetty, the Digest authentication server-side component uses ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-10050",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-55831",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55831",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-55833",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55833",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-56745",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56745",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-56816",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http3",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final",
                "title": "Netty is a network application framework for development of protocol s ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56816",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-56819",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http2",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56819",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59901",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-compression",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final",
                "title": "io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59901",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "GHSA-r7wm-3cxj-wff9",
                "severity": "HIGH",
                "pkg": "com.fasterxml.jackson.core:jackson-core",
                "installed": "2.21.3",
                "fixed": "2.18.8, 2.21.4",
                "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
                "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "GHSA-r7wm-3cxj-wff9",
                "severity": "HIGH",
                "pkg": "tools.jackson.core:jackson-core",
                "installed": "3.1.3",
                "fixed": "3.1.4",
                "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
                "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/opensearch@sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/opensearch@sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56746",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56746",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59889",
                "severity": "MEDIUM",
                "pkg": "tools.jackson.core:jackson-databind",
                "installed": "3.1.4",
                "fixed": "3.1.5, 3.2.1",
                "title": "jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59889",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59898",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59898",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59899",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59899",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59900",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http2",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59900",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59921",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59921",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-71497",
                "severity": "MEDIUM",
                "pkg": "org.jsoup:jsoup",
                "installed": "1.15.3",
                "fixed": "1.23.1",
                "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-71497",
                "severity": "MEDIUM",
                "pkg": "org.jsoup:jsoup",
                "installed": "1.19.1",
                "fixed": "1.23.1",
                "title": "org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71497",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/opensearch@sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "otel-collector",
      "name": "OpenTelemetry Collector",
      "category": "Observability",
      "summary": "OpenTelemetry Collector that receives, processes, and exports traces, metrics, and logs, a vendor-neutral pipeline for telemetry routing.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.157.0",
      "versions": [
        {
          "version": "0.157.0",
          "size": "116.1 MB",
          "published": "2026-08-02T09:02:34Z",
          "digest": "sha256:f439e895c93c303cfc181e09892bd9f0fe08fc1622b18bf1847d95d6a1ded6ea"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/open-telemetry/opentelemetry-collector",
      "source": "https://github.com/open-telemetry/opentelemetry-collector",
      "image": "ghcr.io/quenchworks/images/otel-collector",
      "security": {
        "image": "ghcr.io/quenchworks/images/otel-collector",
        "version": "0.157.0",
        "tag": "ghcr.io/quenchworks/images/otel-collector:0.157.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/otelcol-contrib"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.157.0",
            "tag": "ghcr.io/quenchworks/images/otel-collector:0.157.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/otelcol-contrib"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "opentofu",
      "name": "opentofu",
      "category": "CI/CD & registry",
      "summary": "Open-source, community-governed fork of Terraform, an infrastructure-as-code CLI. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "1.12.5",
      "versions": [
        {
          "version": "1.12.5",
          "size": "34.8 MB",
          "published": "2026-07-22T11:30:24Z",
          "digest": "sha256:9a2a0f9da641c4a42d6e37933c975f4defce1ef41fd8531745f53c41501775e9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://opentofu.org",
      "source": "https://github.com/opentofu/opentofu",
      "image": "ghcr.io/quenchworks/images/opentofu",
      "security": {
        "image": "ghcr.io/quenchworks/images/opentofu",
        "version": "1.12.5",
        "tag": "ghcr.io/quenchworks/images/opentofu:1.12.5",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 1,
        "grade": "D",
        "score": 83,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/tofu"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/tofu"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.12.5",
            "tag": "ghcr.io/quenchworks/images/opentofu:1.12.5",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "D",
            "score": 83,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/tofu"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/tofu"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "perl",
      "name": "perl",
      "category": "Language runtime",
      "summary": "Hardened Perl interpreter for scripts, text processing, and tooling. A base image to FROM for Perl workloads. Latest stable (5).",
      "tier": "standard",
      "status": "available",
      "license": "Artistic-1.0-Perl OR GPL-1.0+",
      "licenseClean": "clean",
      "version": "5.44.0",
      "versions": [
        {
          "version": "5.44.0",
          "size": "14.2 MB",
          "published": "2026-07-21T08:40:43Z",
          "digest": "sha256:36a30810647ea6f05a969d7fec00a58a8b3c62a055e9363469e9a95e1f262182"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.perl.org",
      "source": "https://www.perl.org",
      "image": "ghcr.io/quenchworks/images/perl",
      "security": {
        "image": "ghcr.io/quenchworks/images/perl",
        "version": "5.44.0",
        "tag": "ghcr.io/quenchworks/images/perl:5.44.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.44.0",
            "tag": "ghcr.io/quenchworks/images/perl:5.44.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "perses",
      "name": "perses",
      "category": "Observability",
      "summary": "CNCF dashboards and observability visualization tool with an embedded React UI and 24 default panel/datasource plugins. From source (Node UI build embedded in a static Go binary) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.53.1",
      "versions": [
        {
          "version": "0.53.1",
          "size": "92.1 MB",
          "published": "2026-07-26T12:32:23Z",
          "digest": "sha256:10bad8982a39acfa681a6824fadb66d17bdc2d22c59406e69dbb6af11eea7147"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://perses.dev",
      "source": "https://github.com/perses/perses",
      "image": "ghcr.io/quenchworks/images/perses",
      "security": {
        "image": "ghcr.io/quenchworks/images/perses",
        "version": "0.53.1",
        "tag": "ghcr.io/quenchworks/images/perses:0.53.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/percli",
              "usr/bin/perses"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.53.1",
            "tag": "ghcr.io/quenchworks/images/perses:0.53.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/percli",
                  "usr/bin/perses"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pgbouncer",
      "name": "pgbouncer",
      "category": "Relational",
      "summary": "Lightweight connection pooler for PostgreSQL that fronts thousands of client connections with a small backend pool, cutting per-connection overhead.",
      "tier": "standard",
      "status": "available",
      "license": "ISC",
      "licenseClean": "clean",
      "version": "1.23.1, 1.25.2, 1.24.1",
      "versions": [
        {
          "version": "1.23.1",
          "size": "7.6 MB",
          "published": "2026-07-04T11:33:03Z",
          "digest": "sha256:6b5f4dfe415ec733457ef43a575750832ec531969e9dd36695a6cdd6d9173b4b"
        },
        {
          "version": "1.25.2",
          "size": "7.6 MB",
          "published": "2026-07-04T11:31:43Z",
          "digest": "sha256:e1c0e92e4abb1259def3adb3766fece53f2c90c10aad1cfc867ab8f102a6efe6"
        },
        {
          "version": "1.24.1",
          "size": "7.6 MB",
          "published": "2026-07-04T11:31:01Z",
          "digest": "sha256:4a27e34aa9b7f123dcd1d9c094f265a4f8dc70d1c35306c0dfdff1b20c08a0de"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/pgbouncer/pgbouncer",
      "source": "https://github.com/pgbouncer/pgbouncer",
      "image": "ghcr.io/quenchworks/images/pgbouncer",
      "security": {
        "image": "ghcr.io/quenchworks/images/pgbouncer",
        "version": "1.25.2",
        "tag": "ghcr.io/quenchworks/images/pgbouncer:1.25.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.25.2",
            "tag": "ghcr.io/quenchworks/images/pgbouncer:1.25.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.24.1",
            "tag": "ghcr.io/quenchworks/images/pgbouncer:1.24.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.23.1",
            "tag": "ghcr.io/quenchworks/images/pgbouncer:1.23.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "pgpool",
      "name": "pgpool",
      "category": "Relational",
      "summary": "PostgreSQL connection pooler, load balancer and query router. Pools client connections, spreads read-only queries across streaming-replication standbys, and detaches a backend that fails its health check.",
      "tier": "standard",
      "status": "available",
      "license": "HPND",
      "licenseClean": "clean",
      "version": "4.6.7, 4.5.12, 4.7.2",
      "versions": [
        {
          "version": "4.6.7",
          "size": "16.3 MB",
          "published": "2026-07-28T06:23:46Z",
          "digest": "sha256:0eb712cefc80ca75349da052b2bd2b3b568f71c99fde6517a4aba59275913944"
        },
        {
          "version": "4.5.12",
          "size": "16.1 MB",
          "published": "2026-07-28T06:23:45Z",
          "digest": "sha256:32f77780a23df79110cf72da280f00a9f61dd074aaff5ab60ccab5dc60aa8274"
        },
        {
          "version": "4.7.2",
          "size": "16.4 MB",
          "published": "2026-07-28T06:23:33Z",
          "digest": "sha256:4dea6db1cc99a9821959378a89fb70625382e8c745eca055a19db8d7ab9385e9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://git.postgresql.org/gitweb/?p=pgpool2.git",
      "source": "https://www.pgpool.net/source/",
      "image": "ghcr.io/quenchworks/images/pgpool",
      "security": {
        "image": "ghcr.io/quenchworks/images/pgpool",
        "version": "4.7.2",
        "tag": "ghcr.io/quenchworks/images/pgpool:4.7.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.7.2",
            "tag": "ghcr.io/quenchworks/images/pgpool:4.7.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.6.7",
            "tag": "ghcr.io/quenchworks/images/pgpool:4.6.7",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.5.12",
            "tag": "ghcr.io/quenchworks/images/pgpool:4.5.12",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "php",
      "name": "php",
      "category": "Language runtime",
      "summary": "Hardened PHP CLI with common extensions, a base image to FROM for PHP apps. Latest 3 stable lines (8.3/8.4/8.5).",
      "tier": "standard",
      "status": "available",
      "license": "PHP-3.01",
      "licenseClean": "clean",
      "version": "8.5.9, 8.4.24, 8.3.33",
      "versions": [
        {
          "version": "8.5.9",
          "size": "48.2 MB",
          "published": "2026-07-30T08:12:46Z",
          "digest": "sha256:0a3ae5198ca12e4072a933237480b1a7a5488e6da3c341b15d80d2f6773261dc"
        },
        {
          "version": "8.4.24",
          "size": "47.3 MB",
          "published": "2026-07-30T08:12:46Z",
          "digest": "sha256:0bef71b1a74bae74b618cfc6d036b0ac4a8d71e1489060a4d7396bc5ce5ef1a1"
        },
        {
          "version": "8.3.33",
          "size": "46.3 MB",
          "published": "2026-07-30T08:12:40Z",
          "digest": "sha256:847c7480eebd3e8b0b8b214692156291aed2c3986a77816c50e0621c1a998e0c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/php/php-src",
      "source": "https://github.com/php/php-src",
      "image": "ghcr.io/quenchworks/images/php",
      "security": {
        "image": "ghcr.io/quenchworks/images/php",
        "version": "8.5.9",
        "tag": "ghcr.io/quenchworks/images/php:8.5.9",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "8.5.9",
            "tag": "ghcr.io/quenchworks/images/php:8.5.9",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.4.24",
            "tag": "ghcr.io/quenchworks/images/php:8.4.24",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.3.33",
            "tag": "ghcr.io/quenchworks/images/php:8.3.33",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "phpmyadmin",
      "name": "phpmyadmin",
      "category": "Apps & productivity",
      "summary": "phpMyAdmin, the web console for MySQL and MariaDB. Built from the official release tarball on a hardened Wolfi php-8.3-fpm + nginx runtime (nonroot, read-only rootfs, supervisord), with the stale vendored composer deps (twig, symfony/cache, symfony/process, sodium_compat) re-resolved to their fixed releases and the bundled js-cookie prototype-pollution hole patched. Stateless — the chart is a Deployment that supplies config.inc.php via a ConfigMap, keeps the blowfish_secret across upgrades, and can bundle MariaDB.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "5.2.3",
      "versions": [
        {
          "version": "5.2.3",
          "size": "65.2 MB",
          "published": "2026-08-02T08:39:56Z",
          "digest": "sha256:f25754b97737e0030e8f8c2e1e26ec95d1fc687a78f0d2f215ab81095010ed41"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.phpmyadmin.net",
      "source": "https://files.phpmyadmin.net/phpMyAdmin/5.2.3/phpMyAdmin-5.2.3-all-languages.tar.xz",
      "image": "ghcr.io/quenchworks/images/phpmyadmin",
      "security": {
        "image": "ghcr.io/quenchworks/images/phpmyadmin",
        "version": "5.2.3",
        "tag": "ghcr.io/quenchworks/images/phpmyadmin:5.2.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.2.3",
            "tag": "ghcr.io/quenchworks/images/phpmyadmin:5.2.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "pnpm",
      "name": "pnpm",
      "category": "Build tool",
      "summary": "Node base image with pnpm preinstalled via corepack, used as the build stage for pnpm projects. Lines 10/11.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "11.19.0",
      "versions": [
        {
          "version": "11.19.0",
          "size": "60.6 MB",
          "published": "2026-08-02T08:42:55Z",
          "digest": "sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://pnpm.io",
      "source": "https://pnpm.io",
      "image": "ghcr.io/quenchworks/images/pnpm",
      "security": {
        "image": "ghcr.io/quenchworks/images/pnpm",
        "version": "11.19.0",
        "tag": "ghcr.io/quenchworks/images/pnpm:11.19.0",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "D",
        "score": 70,
        "cves": [
          {
            "id": "CVE-2026-58043",
            "severity": "HIGH",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
            "targets": [
              "ghcr.io/quenchworks/images/pnpm@sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/pnpm@sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56847",
            "severity": "LOW",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
            "targets": [
              "ghcr.io/quenchworks/images/pnpm@sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "11.19.0",
            "tag": "ghcr.io/quenchworks/images/pnpm:11.19.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "D",
            "score": 70,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/pnpm@sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/pnpm@sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/pnpm@sha256:5e71ddcd82f2c1985ba7434aa037f021a9846c97ea8dbfe0f40c16e04b2e3b5f (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pocketbase",
      "name": "pocketbase",
      "category": "Apps & productivity",
      "summary": "Open-source backend in a single file with an embedded SQLite database, auth, file storage, realtime subscriptions, and an admin dashboard over a REST API. Pure-Go static binary (UI embedded) on a hardened nonroot Wolfi base; state on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.39.5",
      "versions": [
        {
          "version": "0.39.5",
          "size": "12.2 MB",
          "published": "2026-07-22T07:05:12Z",
          "digest": "sha256:01c7db103bf8030aa55e3732a8c416bd9947d055b941546e860618cb4e8a9d32"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://pocketbase.io",
      "source": "https://github.com/pocketbase/pocketbase",
      "image": "ghcr.io/quenchworks/images/pocketbase",
      "security": {
        "image": "ghcr.io/quenchworks/images/pocketbase",
        "version": "0.39.5",
        "tag": "ghcr.io/quenchworks/images/pocketbase:0.39.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 97,
        "cves": [
          {
            "id": "CVE-2023-36308",
            "severity": "LOW",
            "pkg": "github.com/disintegration/imaging",
            "installed": "v1.6.2",
            "fixed": null,
            "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
            "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
            "targets": [
              "usr/bin/pocketbase"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/pocketbase"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.39.5",
            "tag": "ghcr.io/quenchworks/images/pocketbase:0.39.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 97,
            "cves": [
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/pocketbase"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pocketbase"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "poetry",
      "name": "poetry",
      "category": "Build tool",
      "summary": "Python base image with Poetry for dependency management and packaging, used as the build stage for Python projects. Line 2.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.4.1",
      "versions": [
        {
          "version": "2.4.1",
          "size": "47.2 MB",
          "published": "2026-07-26T12:32:01Z",
          "digest": "sha256:f438a25432152aeb6e46ab2ef819bf77cf72a79cc2192035fb90c65442d97653"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://python-poetry.org",
      "source": "https://python-poetry.org",
      "image": "ghcr.io/quenchworks/images/poetry",
      "security": {
        "image": "ghcr.io/quenchworks/images/poetry",
        "version": "2.4.1",
        "tag": "ghcr.io/quenchworks/images/poetry:2.4.1",
        "critical": 0,
        "high": 2,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 2,
        "fixable": 2,
        "grade": "D",
        "score": 70,
        "cves": [
          {
            "id": "CVE-2026-69247",
            "severity": "HIGH",
            "pkg": "cryptography",
            "installed": "49.0.0",
            "fixed": "50.0.0",
            "title": "cryptography is a package designed to expose cryptographic primitives  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.4.1",
            "tag": "ghcr.io/quenchworks/images/poetry:2.4.1",
            "critical": 0,
            "high": 2,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 2,
            "fixable": 2,
            "grade": "D",
            "score": 70,
            "cves": [
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "49.0.0",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "postgres-exporter",
      "name": "postgres-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter that collects PostgreSQL activity, replication, and performance stats and exposes them as metrics for monitoring.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.20.1",
      "versions": [
        {
          "version": "0.20.1",
          "size": "5.6 MB",
          "published": "2026-07-15T12:44:12Z",
          "digest": "sha256:f92a94662c76f6d76d1befc1238214829453db48d22ff595123bde0338bd1417"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus-community/postgres_exporter",
      "source": "https://github.com/prometheus-community/postgres_exporter",
      "image": "ghcr.io/quenchworks/images/postgres-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgres-exporter",
        "version": "0.20.1",
        "tag": "ghcr.io/quenchworks/images/postgres-exporter:0.20.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/postgres_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.20.1",
            "tag": "ghcr.io/quenchworks/images/postgres-exporter:0.20.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/postgres_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "postgresql",
      "name": "PostgreSQL",
      "category": "Relational",
      "summary": "Advanced open-source relational database (v18.x) with strong SQL, ACID transactions, JSON, and a rich extension ecosystem. The catalog's default SQL engine.",
      "tier": "critical",
      "status": "available",
      "license": "PostgreSQL",
      "licenseClean": "clean",
      "version": "16.14, 17.10, 18.4",
      "versions": [
        {
          "version": "16.14",
          "size": "81.3 MB",
          "published": "2026-07-30T10:29:32Z",
          "digest": "sha256:cb695b1904e10ccc925d1d64fd543ab7ce9e088df25c9c7e25245a4f53e297af"
        },
        {
          "version": "17.10",
          "size": "82.0 MB",
          "published": "2026-07-30T10:29:32Z",
          "digest": "sha256:756816dfcc66557d1b1886c483d1d00f87be8515a5604306649a822549449856"
        },
        {
          "version": "18.4",
          "size": "82.4 MB",
          "published": "2026-07-30T10:29:22Z",
          "digest": "sha256:949125181299709eff3ede2d74a3d04dd982279a3510ffcc907eae51eb037fd3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/postgres/postgres",
      "source": "https://ftp.postgresql.org/pub/source/v18.4/postgresql-18.4.tar.bz2",
      "image": "ghcr.io/quenchworks/images/postgresql",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgresql",
        "version": "18.4",
        "tag": "ghcr.io/quenchworks/images/postgresql:18.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "18.4",
            "tag": "ghcr.io/quenchworks/images/postgresql:18.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "17.10",
            "tag": "ghcr.io/quenchworks/images/postgresql:17.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "16.14",
            "tag": "ghcr.io/quenchworks/images/postgresql:16.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "postgres-documentdb",
      "name": "PostgreSQL + DocumentDB",
      "category": "Document",
      "summary": "PostgreSQL 17 plus the open DocumentDB extension, providing BSON document storage and queries. The storage backend that powers FerretDB v2.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.105.0, 0.106.0, 0.107.0",
      "versions": [
        {
          "version": "0.105.0",
          "size": "135.5 MB",
          "published": "2026-07-04T11:25:42Z",
          "digest": "sha256:4fc3a6f6f00cb67ee6ce401bda8a66f3e928c1f78333a040fe66cf6bd4df85b9"
        },
        {
          "version": "0.106.0",
          "size": "135.6 MB",
          "published": "2026-07-04T11:25:18Z",
          "digest": "sha256:f4968ed36f0e055d60b97a1f5229879253843106476175c30206705e9f45a88b"
        },
        {
          "version": "0.107.0",
          "size": "135.8 MB",
          "published": "2026-07-04T11:21:41Z",
          "digest": "sha256:39c2571a1ec2c21922b082462198a1afa34abfb32fc54b23463ed1663a2cf73c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/FerretDB/documentdb",
      "source": "https://github.com/FerretDB/documentdb",
      "image": "ghcr.io/quenchworks/images/postgres-documentdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgres-documentdb",
        "version": "0.107.0",
        "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.107.0",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "C",
        "score": 91,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/postgres-documentdb@sha256:39c2571a1ec2c21922b082462198a1afa34abfb32fc54b23463ed1663a2cf73c (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.107.0",
            "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.107.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/postgres-documentdb@sha256:39c2571a1ec2c21922b082462198a1afa34abfb32fc54b23463ed1663a2cf73c (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "0.106.0",
            "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.106.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/postgres-documentdb@sha256:f4968ed36f0e055d60b97a1f5229879253843106476175c30206705e9f45a88b (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "0.105.0",
            "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.105.0",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/postgres-documentdb@sha256:4fc3a6f6f00cb67ee6ce401bda8a66f3e928c1f78333a040fe66cf6bd4df85b9 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "postgresql-15",
      "name": "PostgreSQL 15",
      "category": "Relational",
      "summary": "PostgreSQL 15.x build for the Coolify wave, which pins PG 15 (the default postgresql image tracks 18.x). Same hardened build with bundled contrib extensions.",
      "tier": "critical",
      "status": "available",
      "license": "PostgreSQL",
      "licenseClean": "clean",
      "version": "15.17, 15.18, 15.16",
      "versions": [
        {
          "version": "15.17",
          "size": "52.6 MB",
          "published": "2026-07-04T11:32:02Z",
          "digest": "sha256:e5a7b8ec08564aa5fa8120cbdd74dc3c8423bdb95a5262799a20b3da96e92590"
        },
        {
          "version": "15.18",
          "size": "52.7 MB",
          "published": "2026-07-04T11:29:02Z",
          "digest": "sha256:037f012988d7de9e7fad2d4407c3179c37dc8aeff0c616d010a77ea8b16615b6"
        },
        {
          "version": "15.16",
          "size": "52.7 MB",
          "published": "2026-07-04T11:23:43Z",
          "digest": "sha256:92ef9ebd49fe1709eca6c7899053453fb9d87898108c4c92d759227123e97263"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ftp.postgresql.org/pub/source/v15.18/postgresql-15.18.tar.bz2",
      "source": "https://ftp.postgresql.org/pub/source/v15.18/postgresql-15.18.tar.bz2",
      "image": "ghcr.io/quenchworks/images/postgresql-15",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgresql-15",
        "version": "15.18",
        "tag": "ghcr.io/quenchworks/images/postgresql-15:15.18",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "15.18",
            "tag": "ghcr.io/quenchworks/images/postgresql-15:15.18",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "15.17",
            "tag": "ghcr.io/quenchworks/images/postgresql-15:15.17",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "15.16",
            "tag": "ghcr.io/quenchworks/images/postgresql-15:15.16",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "postgrest",
      "name": "postgrest",
      "category": "Databases & engines",
      "summary": "REST API server that serves a RESTful API directly from a PostgreSQL schema. Shipped as upstream's official prebuilt static binary. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "14.15, 14.14, 14.16",
      "versions": [
        {
          "version": "14.15",
          "size": "9.7 MB",
          "published": "2026-07-28T09:49:30Z",
          "digest": "sha256:2e238170b4b3a4fe93e25981968e936316ff670478e7b6886988079b1dcdc160"
        },
        {
          "version": "14.14",
          "size": "9.7 MB",
          "published": "2026-07-28T09:49:23Z",
          "digest": "sha256:d9c1d565dff3e7a1cd9a5dce41f2e0dafcde3e2831dbe2c595d0122a9e4081b6"
        },
        {
          "version": "14.16",
          "size": "9.7 MB",
          "published": "2026-07-28T09:49:08Z",
          "digest": "sha256:3d2ea136a7edf4644b8625ec664ca3fd21400446fccf3b778087f78f8817896f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://postgrest.org",
      "source": "https://github.com/PostgREST/postgrest",
      "image": "ghcr.io/quenchworks/images/postgrest",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgrest",
        "version": "14.16",
        "tag": "ghcr.io/quenchworks/images/postgrest:14.16",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "14.16",
            "tag": "ghcr.io/quenchworks/images/postgrest:14.16",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "14.15",
            "tag": "ghcr.io/quenchworks/images/postgrest:14.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "14.14",
            "tag": "ghcr.io/quenchworks/images/postgrest:14.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "prometheus",
      "name": "Prometheus",
      "category": "Observability",
      "summary": "Metrics collection, storage, and alerting system that scrapes targets and runs PromQL queries. The de-facto cloud-native monitoring TSDB.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.13.2",
      "versions": [
        {
          "version": "3.13.2",
          "size": "57.3 MB",
          "published": "2026-08-02T08:43:37Z",
          "digest": "sha256:c1be5464affbf11c929b6cfa7538c78bb021bf82f711f1831281113e0da0a852"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/prometheus",
      "source": "https://github.com/prometheus/prometheus",
      "image": "ghcr.io/quenchworks/images/prometheus",
      "security": {
        "image": "ghcr.io/quenchworks/images/prometheus",
        "version": "3.13.2",
        "tag": "ghcr.io/quenchworks/images/prometheus:3.13.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/prometheus",
              "usr/bin/promtool"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.13.2",
            "tag": "ghcr.io/quenchworks/images/prometheus:3.13.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/prometheus",
                  "usr/bin/promtool"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pulsar",
      "name": "Pulsar",
      "category": "Messaging",
      "summary": "Cloud-native distributed messaging and streaming platform with multi-tenancy, geo-replication, and tiered storage that separates compute from storage.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.2.3",
      "versions": [
        {
          "version": "4.2.3",
          "size": "311.4 MB",
          "published": "2026-07-28T06:56:07Z",
          "digest": "sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/pulsar",
      "source": "https://github.com/apache/pulsar",
      "image": "ghcr.io/quenchworks/images/pulsar",
      "security": {
        "image": "ghcr.io/quenchworks/images/pulsar",
        "version": "4.2.3",
        "tag": "ghcr.io/quenchworks/images/pulsar:4.2.3",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "C",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/pulsar@sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/pulsar@sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/pulsar@sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.2.3",
            "tag": "ghcr.io/quenchworks/images/pulsar:4.2.3",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "C",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/pulsar@sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/pulsar@sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/pulsar@sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pulumi",
      "name": "pulumi",
      "category": "CI/CD & registry",
      "summary": "Infrastructure-as-code CLI for managing cloud resources with general-purpose programming languages. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.253.0, 3.254.0, 3.255.0",
      "versions": [
        {
          "version": "3.253.0",
          "size": "34.3 MB",
          "published": "2026-07-30T08:12:23Z",
          "digest": "sha256:322a74d6fcc458f1b5f584a4eb1d074c264b1d9b2a3efb4f7691c8402faac78f"
        },
        {
          "version": "3.254.0",
          "size": "34.6 MB",
          "published": "2026-07-30T08:12:07Z",
          "digest": "sha256:24c099eb9ee79f9213dacf689d7a922259eb69229a8dc9bab4fcf049ddc331c0"
        },
        {
          "version": "3.255.0",
          "size": "34.6 MB",
          "published": "2026-07-30T08:11:04Z",
          "digest": "sha256:c3fb398da0e6c7c1c6e58d0b1800bae0a47a2972d78e1d70e7090c408e73c382"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.pulumi.com",
      "source": "https://github.com/pulumi/pulumi",
      "image": "ghcr.io/quenchworks/images/pulumi",
      "security": {
        "image": "ghcr.io/quenchworks/images/pulumi",
        "version": "3.255.0",
        "tag": "ghcr.io/quenchworks/images/pulumi:3.255.0",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 3,
        "fixable": 2,
        "grade": "D",
        "score": 74,
        "cves": [
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v6",
            "installed": "v6.0.0-alpha.4",
            "fixed": "6.0.0-alpha.5",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/pulumi"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v6",
            "installed": "v6.0.0-alpha.4",
            "fixed": "6.0.0-alpha.5",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/pulumi"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/pulumi"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.255.0",
            "tag": "ghcr.io/quenchworks/images/pulumi:3.255.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v6",
                "installed": "v6.0.0-alpha.4",
                "fixed": "6.0.0-alpha.5",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/pulumi"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v6",
                "installed": "v6.0.0-alpha.4",
                "fixed": "6.0.0-alpha.5",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/pulumi"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pulumi"
                ]
              }
            ]
          },
          {
            "version": "3.254.0",
            "tag": "ghcr.io/quenchworks/images/pulumi:3.254.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v6",
                "installed": "v6.0.0-alpha.4",
                "fixed": "6.0.0-alpha.5",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/pulumi"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v6",
                "installed": "v6.0.0-alpha.4",
                "fixed": "6.0.0-alpha.5",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/pulumi"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pulumi"
                ]
              }
            ]
          },
          {
            "version": "3.253.0",
            "tag": "ghcr.io/quenchworks/images/pulumi:3.253.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v6",
                "installed": "v6.0.0-alpha.4",
                "fixed": "6.0.0-alpha.5",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/pulumi"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v6",
                "installed": "v6.0.0-alpha.4",
                "fixed": "6.0.0-alpha.5",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/pulumi"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pulumi"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pyroscope",
      "name": "pyroscope",
      "category": "Observability",
      "summary": "Continuous profiling database for analyzing CPU, memory, and other resource usage over time. From source with the React UI embedded (no Node at runtime) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2.1.0",
      "versions": [
        {
          "version": "2.1.0",
          "size": "31.1 MB",
          "published": "2026-07-22T07:09:55Z",
          "digest": "sha256:d1c3716254a3d83ac12a78d08b03a7bad82b5330eb4b6fb82be26c888a3af552"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://grafana.com/oss/pyroscope",
      "source": "https://github.com/grafana/pyroscope",
      "image": "ghcr.io/quenchworks/images/pyroscope",
      "security": {
        "image": "ghcr.io/quenchworks/images/pyroscope",
        "version": "2.1.0",
        "tag": "ghcr.io/quenchworks/images/pyroscope:2.1.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/pyroscope"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/pyroscope:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pyroscope"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "python",
      "name": "python",
      "category": "Language runtime",
      "summary": "Hardened CPython interpreter with pip, a 0-CVE signed nonroot base image to FROM for Python apps. Ships the latest 3 stable minors (no :latest).",
      "tier": "standard",
      "status": "available",
      "license": "PSF-2.0",
      "licenseClean": "clean",
      "version": "3.13.14, 3.12.13, 3.14.6",
      "versions": [
        {
          "version": "3.13.14",
          "size": "29.5 MB",
          "published": "2026-07-26T12:36:37Z",
          "digest": "sha256:fd6b1db256d3871e79b6c9c52a079abf34867195e185c86bc2085cd8d8cb5a67"
        },
        {
          "version": "3.12.13",
          "size": "29.8 MB",
          "published": "2026-07-26T12:36:33Z",
          "digest": "sha256:3415f111409eb9431c59054037c8166fdb1fb893518f9ca1686ae9cb1f5d8d8f"
        },
        {
          "version": "3.14.6",
          "size": "31.0 MB",
          "published": "2026-07-26T12:36:03Z",
          "digest": "sha256:e286f6249932951787969db8530aae31d486db6e1754c66b3789215f272adb3f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.python.org",
      "source": "https://www.python.org",
      "image": "ghcr.io/quenchworks/images/python",
      "security": {
        "image": "ghcr.io/quenchworks/images/python",
        "version": "3.14.6",
        "tag": "ghcr.io/quenchworks/images/python:3.14.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.14.6",
            "tag": "ghcr.io/quenchworks/images/python:3.14.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.13.14",
            "tag": "ghcr.io/quenchworks/images/python:3.13.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.12.13",
            "tag": "ghcr.io/quenchworks/images/python:3.12.13",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "qdrant",
      "name": "Qdrant",
      "category": "Vector",
      "summary": "Vector database and similarity-search engine for AI embeddings, powering semantic search, recommendations, and RAG with filtered nearest-neighbor queries.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.3",
      "versions": [
        {
          "version": "1.18.3",
          "size": "43.5 MB",
          "published": "2026-07-21T09:16:50Z",
          "digest": "sha256:981a6f4dd9924a6b6630ccb29419ecb5b4b1963db830b0b2d1793041281f4ff2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/qdrant/qdrant",
      "source": "https://github.com/qdrant/qdrant",
      "image": "ghcr.io/quenchworks/images/qdrant",
      "security": {
        "image": "ghcr.io/quenchworks/images/qdrant",
        "version": "1.18.3",
        "tag": "ghcr.io/quenchworks/images/qdrant:1.18.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.18.3",
            "tag": "ghcr.io/quenchworks/images/qdrant:1.18.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "questdb",
      "name": "questdb",
      "category": "Time series",
      "summary": "High-performance time-series SQL database for fast ingestion and queries over metrics, financial ticks, and IoT data, with PostgreSQL-wire and InfluxDB line-protocol ingestion.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "9.4.2, 9.4.3, 9.4.1",
      "versions": [
        {
          "version": "9.4.2",
          "size": "117.5 MB",
          "published": "2026-07-23T06:48:26Z",
          "digest": "sha256:0d56f8fc3555c66ab774ed18e718159e87e72b378a97faeeaa8c059feff4d9e8"
        },
        {
          "version": "9.4.3",
          "size": "117.7 MB",
          "published": "2026-07-23T06:48:26Z",
          "digest": "sha256:dcb5f489ccf8419df8baaf29f81d12d197a148edbfa89a96e37ac0b5cbf1b582"
        },
        {
          "version": "9.4.1",
          "size": "117.6 MB",
          "published": "2026-07-23T06:48:21Z",
          "digest": "sha256:fc86ab64a9a2cea47ff09672394a371af694ba3fc57951c490a8d86f97cc2686"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/questdb/questdb",
      "source": "https://github.com/questdb/questdb",
      "image": "ghcr.io/quenchworks/images/questdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/questdb",
        "version": "9.4.3",
        "tag": "ghcr.io/quenchworks/images/questdb:9.4.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.4.3",
            "tag": "ghcr.io/quenchworks/images/questdb:9.4.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.4.2",
            "tag": "ghcr.io/quenchworks/images/questdb:9.4.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.4.1",
            "tag": "ghcr.io/quenchworks/images/questdb:9.4.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "quickwit",
      "name": "quickwit",
      "category": "Search",
      "summary": "Cloud-native search engine for logs, traces, and analytics with sub-second search over object storage. Built from Rust source (UI embedded, no Node at runtime) on a hardened nonroot Wolfi base; index data on object storage or a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "0.8.2",
      "versions": [
        {
          "version": "0.8.2",
          "size": "95.0 MB",
          "published": "2026-07-03T04:02:11Z",
          "digest": "sha256:c4ae313ed9dc0e7539bfc4315779a4cd1baef6878b10f87d0d9da8ecf2da81ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://quickwit.io",
      "source": "https://github.com/quickwit-oss/quickwit",
      "image": "ghcr.io/quenchworks/images/quickwit",
      "security": {
        "image": "ghcr.io/quenchworks/images/quickwit",
        "version": "0.8.2",
        "tag": "ghcr.io/quenchworks/images/quickwit:0.8.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.8.2",
            "tag": "ghcr.io/quenchworks/images/quickwit:0.8.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rabbitmq",
      "name": "RabbitMQ",
      "category": "Messaging",
      "summary": "Reliable message broker speaking AMQP plus MQTT and STOMP, with flexible routing, queues, and acknowledgements for decoupling services.",
      "tier": "critical",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "4.3.4, 4.1.8, 4.2.8",
      "versions": [
        {
          "version": "4.3.4",
          "size": "128.9 MB",
          "published": "2026-07-26T12:37:56Z",
          "digest": "sha256:9321555e564ac1c81379902143635a43e5cff262578d37c8707d868cbaf05851"
        },
        {
          "version": "4.1.8",
          "size": "128.5 MB",
          "published": "2026-07-26T12:37:55Z",
          "digest": "sha256:21f9ebcb9176abdd209711b99b6bd3b9bf27b7277236a03fc6228ce34a834d1f"
        },
        {
          "version": "4.2.8",
          "size": "128.7 MB",
          "published": "2026-07-26T12:37:51Z",
          "digest": "sha256:b5529bf9ebb20af69813b5e05892cbad8b51f13d36964900933b28507ced8623"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/rabbitmq/rabbitmq-server",
      "source": "https://github.com/rabbitmq/rabbitmq-server",
      "image": "ghcr.io/quenchworks/images/rabbitmq",
      "security": {
        "image": "ghcr.io/quenchworks/images/rabbitmq",
        "version": "4.3.4",
        "tag": "ghcr.io/quenchworks/images/rabbitmq:4.3.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.3.4",
            "tag": "ghcr.io/quenchworks/images/rabbitmq:4.3.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.2.8",
            "tag": "ghcr.io/quenchworks/images/rabbitmq:4.2.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.1.8",
            "tag": "ghcr.io/quenchworks/images/rabbitmq:4.1.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rclone",
      "name": "rclone",
      "category": "Storage & platform",
      "summary": "Command-line program to sync files and directories to and from dozens of cloud storage providers. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.75.0",
      "versions": [
        {
          "version": "1.75.0",
          "size": "29.6 MB",
          "published": "2026-08-02T08:42:52Z",
          "digest": "sha256:92c8629aa90200840533723e608af8c87f0070f4fb6c785840be63ffe6771c04"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://rclone.org",
      "source": "https://github.com/rclone/rclone",
      "image": "ghcr.io/quenchworks/images/rclone",
      "security": {
        "image": "ghcr.io/quenchworks/images/rclone",
        "version": "1.75.0",
        "tag": "ghcr.io/quenchworks/images/rclone:1.75.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/rclone"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.75.0",
            "tag": "ghcr.io/quenchworks/images/rclone:1.75.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/rclone"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "redis",
      "name": "Redis",
      "category": "Cache",
      "summary": "In-memory key-value store used as a cache, message broker, and ephemeral datastore. Shipped under AGPL (not permissive); Valkey is the BSD-licensed open alternative.",
      "tier": "critical",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "8.8.1, 8.10.0, 8.6.5",
      "versions": [
        {
          "version": "8.8.1",
          "size": "14.7 MB",
          "published": "2026-07-30T10:27:00Z",
          "digest": "sha256:e318315dd4c474df6823ecaeed8345aab845679c326d2589a453c7470f8c3d99"
        },
        {
          "version": "8.10.0",
          "size": "15.2 MB",
          "published": "2026-07-30T10:26:53Z",
          "digest": "sha256:95942647e5f2eeaefb01fd34d95d796b3fddfa5d38d67050710c8b99893d1c08"
        },
        {
          "version": "8.6.5",
          "size": "15.5 MB",
          "published": "2026-07-30T10:26:45Z",
          "digest": "sha256:9f94c4da0b3fef65f2879a16cbaa4d9511b073fda55704899ae1b72b0b3eb38b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/redis/redis",
      "source": "https://download.redis.io/releases/redis-8.8.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/redis",
      "security": {
        "image": "ghcr.io/quenchworks/images/redis",
        "version": "8.10.0",
        "tag": "ghcr.io/quenchworks/images/redis:8.10.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "8.10.0",
            "tag": "ghcr.io/quenchworks/images/redis:8.10.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.8.1",
            "tag": "ghcr.io/quenchworks/images/redis:8.8.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.6.5",
            "tag": "ghcr.io/quenchworks/images/redis:8.6.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "redis-exporter",
      "name": "redis-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter that scrapes Redis and Valkey runtime stats and exposes them as metrics for dashboards and alerts.",
      "tier": "critical",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.88.0, 1.86.0, 1.87.0",
      "versions": [
        {
          "version": "1.88.0",
          "size": "4.6 MB",
          "published": "2026-07-26T12:35:42Z",
          "digest": "sha256:aa1cbf997c0ca1770cb6e570b3702645294aadce9ade268015473d28c0f0e706"
        },
        {
          "version": "1.86.0",
          "size": "4.6 MB",
          "published": "2026-07-26T12:35:38Z",
          "digest": "sha256:2b06b1ddc455ef2a869ff526c1a1e8d2372c91b50dcf49d6749e730b06b2d41a"
        },
        {
          "version": "1.87.0",
          "size": "4.6 MB",
          "published": "2026-07-26T12:32:46Z",
          "digest": "sha256:ee25f477dee790cf59b0831c7dfaaa3517ac2f65d5ed8bed4710c09925536222"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/oliver006/redis_exporter",
      "source": "https://github.com/oliver006/redis_exporter",
      "image": "ghcr.io/quenchworks/images/redis-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/redis-exporter",
        "version": "1.88.0",
        "tag": "ghcr.io/quenchworks/images/redis-exporter:1.88.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/redis_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.88.0",
            "tag": "ghcr.io/quenchworks/images/redis-exporter:1.88.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/redis_exporter"
                ]
              }
            ]
          },
          {
            "version": "1.87.0",
            "tag": "ghcr.io/quenchworks/images/redis-exporter:1.87.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/redis_exporter"
                ]
              }
            ]
          },
          {
            "version": "1.86.0",
            "tag": "ghcr.io/quenchworks/images/redis-exporter:1.86.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/redis_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "renovate",
      "name": "renovate",
      "category": "CI/CD & registry",
      "summary": "Automated dependency-update CLI that opens PRs to keep dependencies current, on a hardened Wolfi Node runtime. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "44.6.0",
      "versions": [
        {
          "version": "44.6.0",
          "size": "118.3 MB",
          "published": "2026-08-02T08:42:44Z",
          "digest": "sha256:84db890bb58829700acbdf29b52994885e27c698110625f23ecac061accffe03"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.renovatebot.com",
      "source": "https://github.com/renovatebot/renovate",
      "image": "ghcr.io/quenchworks/images/renovate",
      "security": {
        "image": "ghcr.io/quenchworks/images/renovate",
        "version": "44.6.0",
        "tag": "ghcr.io/quenchworks/images/renovate:44.6.0",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "D",
        "score": 61,
        "cves": [
          {
            "id": "CVE-2026-69152",
            "severity": "HIGH",
            "pkg": "brace-expansion",
            "installed": "5.0.8",
            "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
            "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-24",
            "installed": "24.18.1-r1",
            "fixed": "24.19.0-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/renovate@sha256:84db890bb58829700acbdf29b52994885e27c698110625f23ecac061accffe03 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "44.6.0",
            "tag": "ghcr.io/quenchworks/images/renovate:44.6.0",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "D",
            "score": 61,
            "cves": [
              {
                "id": "CVE-2026-69152",
                "severity": "HIGH",
                "pkg": "brace-expansion",
                "installed": "5.0.8",
                "fixed": "1.1.18, 2.1.4, 3.0.6, 5.0.9",
                "title": "brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69152",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-24",
                "installed": "24.18.1-r1",
                "fixed": "24.19.0-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/renovate@sha256:84db890bb58829700acbdf29b52994885e27c698110625f23ecac061accffe03 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "rqlite",
      "name": "rqlite",
      "category": "Relational",
      "summary": "Lightweight, distributed relational database built on SQLite and Raft. Ships rqlited and the rqlite CLI as static (musl) Go binaries on a hardened nonroot Wolfi base; data dir is a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "10.2.5",
      "versions": [
        {
          "version": "10.2.5",
          "size": "18.9 MB",
          "published": "2026-07-22T07:06:53Z",
          "digest": "sha256:8322ad9a89976557cc70e94500ea1521a590a48cc0d8b41beffbff25c6a8a7e6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://rqlite.io",
      "source": "https://github.com/rqlite/rqlite",
      "image": "ghcr.io/quenchworks/images/rqlite",
      "security": {
        "image": "ghcr.io/quenchworks/images/rqlite",
        "version": "10.2.5",
        "tag": "ghcr.io/quenchworks/images/rqlite:10.2.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/rqlite"
            ]
          }
        ],
        "versions": [
          {
            "version": "10.2.5",
            "tag": "ghcr.io/quenchworks/images/rqlite:10.2.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/rqlite"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ruby",
      "name": "ruby",
      "category": "Language runtime",
      "summary": "Hardened Ruby interpreter with Bundler, a base image to FROM for Ruby apps. Latest 3 stable lines (3.2/3.3/3.4).",
      "tier": "standard",
      "status": "available",
      "license": "Ruby",
      "licenseClean": "clean",
      "version": "3.4.10",
      "versions": [
        {
          "version": "3.4.10",
          "size": "46.8 MB",
          "published": "2026-07-28T06:23:45Z",
          "digest": "sha256:c4b1d95136febeaf35b0c1ff78e46b2210f21509bff503d0a8cebe9a2a397d86"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/ruby/ruby",
      "source": "https://github.com/ruby/ruby",
      "image": "ghcr.io/quenchworks/images/ruby",
      "security": {
        "image": "ghcr.io/quenchworks/images/ruby",
        "version": "3.4.10",
        "tag": "ghcr.io/quenchworks/images/ruby:3.4.10",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "B",
        "score": 94,
        "cves": [
          {
            "id": "CVE-2026-71847",
            "severity": "LOW",
            "pkg": "json",
            "installed": "2.21.1",
            "fixed": "2.21.2",
            "title": "Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71847",
            "targets": [
              "Ruby"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.4.10",
            "tag": "ghcr.io/quenchworks/images/ruby:3.4.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "B",
            "score": 94,
            "cves": [
              {
                "id": "CVE-2026-71847",
                "severity": "LOW",
                "pkg": "json",
                "installed": "2.21.1",
                "fixed": "2.21.2",
                "title": "Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71847",
                "targets": [
                  "Ruby"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "rust",
      "name": "rust",
      "category": "Language runtime",
      "summary": "Hardened Rust toolchain (cargo plus rustc) for build stages; ship the compiled binary on the static base. Latest 3 stable lines (1.94/1.95/1.96).",
      "tier": "standard",
      "status": "available",
      "license": "MIT OR Apache-2.0",
      "licenseClean": "clean",
      "version": "1.97.1",
      "versions": [
        {
          "version": "1.97.1",
          "size": "363.4 MB",
          "published": "2026-07-28T06:23:59Z",
          "digest": "sha256:c5f367e37c0e1c43e802c15ba9d5d10cdfe334b4e28cbe595439f7ebd03cb043"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/rust-lang/rust",
      "source": "https://github.com/rust-lang/rust",
      "image": "ghcr.io/quenchworks/images/rust",
      "security": {
        "image": "ghcr.io/quenchworks/images/rust",
        "version": "1.97.1",
        "tag": "ghcr.io/quenchworks/images/rust:1.97.1",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "C",
        "score": 91,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/rust@sha256:c5f367e37c0e1c43e802c15ba9d5d10cdfe334b4e28cbe595439f7ebd03cb043 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.97.1",
            "tag": "ghcr.io/quenchworks/images/rust:1.97.1",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/rust@sha256:c5f367e37c0e1c43e802c15ba9d5d10cdfe334b4e28cbe595439f7ebd03cb043 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "rustfs",
      "name": "RustFS",
      "category": "Object storage",
      "summary": "S3-compatible, high-performance object store written in Rust with a zero-master architecture, positioned as an Apache-2.0 MinIO alternative. Beta/preview.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.0.0_beta10, 1.0.0_beta12, 1.0.0_beta11",
      "versions": [
        {
          "version": "1.0.0_beta10",
          "size": "77.3 MB",
          "published": "2026-07-30T10:25:56Z",
          "digest": "sha256:a641db726c9515ad2b63aca632a77847b552d8d9a14ab085e31864a6fbbcb68d"
        },
        {
          "version": "1.0.0_beta12",
          "size": "82.5 MB",
          "published": "2026-07-30T10:25:54Z",
          "digest": "sha256:db83dde295d0b8c980a16eb3bbb455116abdb56e1f9770389f85a063c759f18c"
        },
        {
          "version": "1.0.0_beta11",
          "size": "79.1 MB",
          "published": "2026-07-30T10:25:51Z",
          "digest": "sha256:04af0e91402e5e2a4edb329e6a51bd0e0bb3ce2d5748fa9193e8be5b1eced8ea"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/rustfs/rustfs",
      "source": "https://github.com/rustfs/rustfs",
      "image": "ghcr.io/quenchworks/images/rustfs",
      "security": {
        "image": "ghcr.io/quenchworks/images/rustfs",
        "version": "1.0.0_beta12",
        "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta12",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.0.0_beta12",
            "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta12",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.0.0_beta11",
            "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.0.0_beta10",
            "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "scylladb",
      "name": "ScyllaDB",
      "category": "Wide-column",
      "summary": "High-throughput, low-latency wide-column store, API-compatible with Apache Cassandra and DynamoDB. This 6.x build is the final OSS line under AGPL.",
      "tier": "low",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2026.2.2",
      "versions": [
        {
          "version": "2026.2.2",
          "size": "78.2 MB",
          "published": "2026-07-26T12:31:47Z",
          "digest": "sha256:e96ca9dd6b6c8c278639945a4a68dcb7c4f093255eced4c2124bb7923a59bfaa"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/scylladb/scylladb",
      "source": "https://github.com/scylladb/scylladb",
      "image": "ghcr.io/quenchworks/images/scylladb",
      "security": {
        "image": "ghcr.io/quenchworks/images/scylladb",
        "version": "2026.2.2",
        "tag": "ghcr.io/quenchworks/images/scylladb:2026.2.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2026.2.2",
            "tag": "ghcr.io/quenchworks/images/scylladb:2026.2.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "sealed-secrets",
      "name": "sealed-secrets",
      "category": "Security & supply chain",
      "summary": "Sealed Secrets, the controller that lets you commit encrypted secrets to Git safely. A cluster-side private key decrypts SealedSecret resources into ordinary Kubernetes Secrets, so the encrypted form is the only thing that ever leaves the cluster.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.36.6, 0.38.4, 0.37.0",
      "versions": [
        {
          "version": "0.36.6",
          "size": "14.3 MB",
          "published": "2026-07-26T12:36:49Z",
          "digest": "sha256:2bccd402d758a2aa72e9591a53d92ef11ed3a6b24fdd8174e293bc6b4504737b"
        },
        {
          "version": "0.38.4",
          "size": "14.5 MB",
          "published": "2026-07-26T12:36:42Z",
          "digest": "sha256:7e2522cfc9ed4f82ffd15037afe2055c029e4bbfc9eb2c54e09850e83e957d47"
        },
        {
          "version": "0.37.0",
          "size": "14.5 MB",
          "published": "2026-07-26T12:36:38Z",
          "digest": "sha256:cde1ac4ccb853721ce3dcac25fecbf6fe65dad134b7a8de06eec90b21dbc62e8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://sealed-secrets.netlify.app",
      "source": "https://github.com/bitnami-labs/sealed-secrets",
      "image": "ghcr.io/quenchworks/images/sealed-secrets",
      "security": {
        "image": "ghcr.io/quenchworks/images/sealed-secrets",
        "version": "0.38.4",
        "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.38.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.38.4",
            "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.38.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "0.37.0",
            "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.37.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "0.36.6",
            "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.36.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "seaweedfs",
      "name": "SeaweedFS",
      "category": "Object storage",
      "summary": "Fast distributed storage for blobs, objects, and files (S3 API) built on Facebook's Haystack design, with O(1) disk seeks for billions of small files. Default object store after MinIO restricted its community edition.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.40",
      "versions": [
        {
          "version": "4.40",
          "size": "48.8 MB",
          "published": "2026-07-22T08:36:07Z",
          "digest": "sha256:7bb0bbc92fe277023f63e0292ae272231d54161948225a982213578bc41e775e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/seaweedfs/seaweedfs",
      "source": "https://github.com/seaweedfs/seaweedfs",
      "image": "ghcr.io/quenchworks/images/seaweedfs",
      "security": {
        "image": "ghcr.io/quenchworks/images/seaweedfs",
        "version": "4.40",
        "tag": "ghcr.io/quenchworks/images/seaweedfs:4.40",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/weed"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.40",
            "tag": "ghcr.io/quenchworks/images/seaweedfs:4.40",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/weed"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "solr",
      "name": "Solr",
      "category": "Search",
      "summary": "Enterprise search platform built on Apache Lucene, offering full-text search, faceting, and indexing over large document collections.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "10.0.0",
      "versions": [
        {
          "version": "10.0.0",
          "size": "333.1 MB",
          "published": "2026-07-23T12:25:11Z",
          "digest": "sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/solr",
      "source": "https://github.com/apache/solr",
      "image": "ghcr.io/quenchworks/images/solr",
      "security": {
        "image": "ghcr.io/quenchworks/images/solr",
        "version": "10.0.0",
        "tag": "ghcr.io/quenchworks/images/solr:10.0.0",
        "critical": 0,
        "high": 1,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 4,
        "fixable": 3,
        "grade": "D",
        "score": 66,
        "cves": [
          {
            "id": "CVE-2026-44825",
            "severity": "HIGH",
            "pkg": "org.apache.solr:solr-core",
            "installed": "10.0.0",
            "fixed": null,
            "title": "solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.",
            "url": "https://avd.aquasec.com/nvd/cve-2026-44825",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/solr@sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/solr@sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/solr@sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "10.0.0",
            "tag": "ghcr.io/quenchworks/images/solr:10.0.0",
            "critical": 0,
            "high": 1,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 3,
            "grade": "D",
            "score": 66,
            "cves": [
              {
                "id": "CVE-2026-44825",
                "severity": "HIGH",
                "pkg": "org.apache.solr:solr-core",
                "installed": "10.0.0",
                "fixed": null,
                "title": "solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.",
                "url": "https://avd.aquasec.com/nvd/cve-2026-44825",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/solr@sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/solr@sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/solr@sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "sonar-scanner-cli",
      "name": "sonar-scanner-cli",
      "category": "CI/CD & registry",
      "summary": "SonarScanner CLI, the standalone scanner that analyzes a project and pushes results to a SonarQube server. Bundles its own OpenJDK. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "LGPL-3.0",
      "licenseClean": "clean",
      "version": "8.1.0.6389",
      "versions": [
        {
          "version": "8.1.0.6389",
          "size": "85.2 MB",
          "published": "2026-07-04T15:04:38Z",
          "digest": "sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.sonarsource.com/sonarqube-server/latest/analyzing-source-code/scanners/sonarscanner/",
      "source": "https://github.com/SonarSource/sonar-scanner-cli",
      "image": "ghcr.io/quenchworks/images/sonar-scanner-cli",
      "security": {
        "image": "ghcr.io/quenchworks/images/sonar-scanner-cli",
        "version": "8.1.0.6389",
        "tag": "ghcr.io/quenchworks/images/sonar-scanner-cli:8.1.0.6389",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 4,
        "unknown": 0,
        "total": 6,
        "fixable": 6,
        "grade": "C",
        "score": 58,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-10532",
            "severity": "LOW",
            "pkg": "sonar-scanner-cli",
            "installed": "8.1.0.6389-r1",
            "fixed": "8.1.0.6389-r3",
            "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
            "targets": [
              "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-10532",
            "severity": "LOW",
            "pkg": "ch.qos.logback:logback-core",
            "installed": "1.5.33",
            "fixed": "1.5.34",
            "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "8.1.0.6389",
            "tag": "ghcr.io/quenchworks/images/sonar-scanner-cli:8.1.0.6389",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 4,
            "unknown": 0,
            "total": 6,
            "fixable": 6,
            "grade": "C",
            "score": 58,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-10532",
                "severity": "LOW",
                "pkg": "sonar-scanner-cli",
                "installed": "8.1.0.6389-r1",
                "fixed": "8.1.0.6389-r3",
                "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
                "targets": [
                  "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-10532",
                "severity": "LOW",
                "pkg": "ch.qos.logback:logback-core",
                "installed": "1.5.33",
                "fixed": "1.5.34",
                "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "spicedb",
      "name": "spicedb",
      "category": "Identity",
      "summary": "Zanzibar-style authorization database for fine-grained permissions over gRPC. From source on a hardened nonroot Wolfi base; the operator supplies the datastore (in-memory, postgres, or cockroach).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.56.0",
      "versions": [
        {
          "version": "1.56.0",
          "size": "24.3 MB",
          "published": "2026-07-26T12:29:23Z",
          "digest": "sha256:1f8dbdcc20597944240261b491221efd13c77f0c0fd832c28377a5ce9ed82a3d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://authzed.com",
      "source": "https://github.com/authzed/spicedb",
      "image": "ghcr.io/quenchworks/images/spicedb",
      "security": {
        "image": "ghcr.io/quenchworks/images/spicedb",
        "version": "1.56.0",
        "tag": "ghcr.io/quenchworks/images/spicedb:1.56.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/spicedb"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.56.0",
            "tag": "ghcr.io/quenchworks/images/spicedb:1.56.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/spicedb"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "static",
      "name": "static",
      "category": "Runtime base",
      "summary": "Tiny static base for self-contained binaries from Go or Rust. Nonroot, no shell, no package manager. The only image tagged :latest.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "20260621",
      "versions": [
        {
          "version": "20260621",
          "size": "617.2 KB",
          "published": "2026-06-21T09:27:02Z",
          "digest": "sha256:40f7b14a295980f410f31ace75078ffb1649dedee09e6c68d07ed5b3fd05eae2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/wolfi-dev",
      "source": "https://github.com/wolfi-dev",
      "image": "ghcr.io/quenchworks/images/static",
      "security": {
        "image": "ghcr.io/quenchworks/images/static",
        "version": "20260621",
        "tag": "ghcr.io/quenchworks/images/static:20260621",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "20260621",
            "tag": "ghcr.io/quenchworks/images/static:20260621",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "step-ca",
      "name": "step-ca",
      "category": "Security & supply chain",
      "summary": "Online private certificate authority and ACME server for issuing X.509 and SSH certificates. Single static Go binary on a hardened nonroot Wolfi base; config and data live under a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.30.2",
      "versions": [
        {
          "version": "0.30.2",
          "size": "29.6 MB",
          "published": "2026-07-22T07:33:23Z",
          "digest": "sha256:09210b2c05d273ab2d72811c69d20e42081263f1cbc470de870b7a725c87cd65"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://smallstep.com",
      "source": "https://github.com/smallstep/certificates",
      "image": "ghcr.io/quenchworks/images/step-ca",
      "security": {
        "image": "ghcr.io/quenchworks/images/step-ca",
        "version": "0.30.2",
        "tag": "ghcr.io/quenchworks/images/step-ca:0.30.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/step",
              "usr/bin/step-ca"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.30.2",
            "tag": "ghcr.io/quenchworks/images/step-ca:0.30.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/step",
                  "usr/bin/step-ca"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "syft",
      "name": "syft",
      "category": "Security & supply chain",
      "summary": "Anchore's CLI for generating Software Bills of Materials (SBOMs) from container images and filesystems. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.50.0",
      "versions": [
        {
          "version": "1.50.0",
          "size": "28.6 MB",
          "published": "2026-07-30T08:11:58Z",
          "digest": "sha256:63dbb666329f1c34f88aa6715d88432267b9491bb5264b31aabf49d47e5826fe"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://anchore.com/opensource/",
      "source": "https://github.com/anchore/syft",
      "image": "ghcr.io/quenchworks/images/syft",
      "security": {
        "image": "ghcr.io/quenchworks/images/syft",
        "version": "1.50.0",
        "tag": "ghcr.io/quenchworks/images/syft:1.50.0",
        "critical": 0,
        "high": 1,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 3,
        "fixable": 2,
        "grade": "D",
        "score": 74,
        "cves": [
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/syft"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/syft"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/syft"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.50.0",
            "tag": "ghcr.io/quenchworks/images/syft:1.50.0",
            "critical": 0,
            "high": 1,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/syft"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/syft"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/syft"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tekton",
      "name": "tekton",
      "category": "CI/CD & registry",
      "summary": "Kubernetes-native CI/CD pipelines. Ships the Tekton Pipelines controller, webhook, resolvers, and pod-injected helper binaries, built from source on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.14.0",
      "versions": [
        {
          "version": "1.14.0",
          "size": "117.0 MB",
          "published": "2026-07-26T12:35:20Z",
          "digest": "sha256:051d50601e10539071958afa9a6bc217e137c1b68f6d7c7894c70da07ff08d3a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://tekton.dev",
      "source": "https://github.com/tektoncd/pipeline",
      "image": "ghcr.io/quenchworks/images/tekton",
      "security": {
        "image": "ghcr.io/quenchworks/images/tekton",
        "version": "1.14.0",
        "tag": "ghcr.io/quenchworks/images/tekton:1.14.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 3,
        "total": 3,
        "fixable": 0,
        "grade": "B",
        "score": 94,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/controller",
              "usr/bin/resolvers",
              "usr/bin/sidecarlogresults"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.14.0",
            "tag": "ghcr.io/quenchworks/images/tekton:1.14.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 3,
            "total": 3,
            "fixable": 0,
            "grade": "B",
            "score": 94,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller",
                  "usr/bin/resolvers",
                  "usr/bin/sidecarlogresults"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tempo",
      "name": "Tempo",
      "category": "Observability",
      "summary": "Distributed tracing backend from Grafana that ingests OpenTelemetry, Jaeger, and Zipkin spans and stores them cheaply in object storage. Licensed AGPL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "3.0.2",
      "versions": [
        {
          "version": "3.0.2",
          "size": "39.5 MB",
          "published": "2026-07-22T07:11:05Z",
          "digest": "sha256:069eaae190bd2c5a36c247bd5e535b65d84798618d395ce6654ab24ad53dcb96"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/grafana/tempo",
      "source": "https://github.com/grafana/tempo",
      "image": "ghcr.io/quenchworks/images/tempo",
      "security": {
        "image": "ghcr.io/quenchworks/images/tempo",
        "version": "3.0.2",
        "tag": "ghcr.io/quenchworks/images/tempo:3.0.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/tempo"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.0.2",
            "tag": "ghcr.io/quenchworks/images/tempo:3.0.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/tempo"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "temporal",
      "name": "Temporal",
      "category": "Workflow",
      "summary": "Durable workflow orchestration engine that persists execution state so long-running, multi-step processes survive crashes and resume exactly where they left off.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.31.2",
      "versions": [
        {
          "version": "1.31.2",
          "size": "61.5 MB",
          "published": "2026-07-22T08:35:23Z",
          "digest": "sha256:e476bb1280ee530a0d963b1c94f2e50e6328d943e96e2fa4332aa12929b7f833"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/temporalio/temporal",
      "source": "https://github.com/temporalio/temporal",
      "image": "ghcr.io/quenchworks/images/temporal",
      "security": {
        "image": "ghcr.io/quenchworks/images/temporal",
        "version": "1.31.2",
        "tag": "ghcr.io/quenchworks/images/temporal:1.31.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 3,
        "total": 3,
        "fixable": 0,
        "grade": "B",
        "score": 94,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/temporal-cassandra-tool",
              "usr/bin/temporal-server",
              "usr/bin/temporal-sql-tool"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.31.2",
            "tag": "ghcr.io/quenchworks/images/temporal:1.31.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 3,
            "total": 3,
            "fixable": 0,
            "grade": "B",
            "score": 94,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal-cassandra-tool",
                  "usr/bin/temporal-server",
                  "usr/bin/temporal-sql-tool"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "temporal-cli",
      "name": "Temporal CLI",
      "category": "Workflow",
      "summary": "Command-line client and built-in dev server for Temporal, used to start workflows, inspect history, and run a local cluster.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.8.2, 1.7.3, 1.6.2",
      "versions": [
        {
          "version": "1.8.2",
          "size": "41.4 MB",
          "published": "2026-08-02T08:47:09Z",
          "digest": "sha256:b9680ee15742706cb2a7ad570b8617ed51ecf35dec7f006eac9eaea03483c388"
        },
        {
          "version": "1.7.3",
          "size": "114.2 MB",
          "published": "2026-08-02T08:47:02Z",
          "digest": "sha256:195cc68232af9961abceac241b6309bd276ef1d16a0442e520d07bffe0239ce1"
        },
        {
          "version": "1.6.2",
          "size": "85.5 MB",
          "published": "2026-08-02T08:47:00Z",
          "digest": "sha256:9d0b0ee6b6dff814066f32e6a95b5a66fb0af08931d8984977f62d213799cb97"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/temporalio/cli",
      "source": "https://github.com/temporalio/cli",
      "image": "ghcr.io/quenchworks/images/temporal-cli",
      "security": {
        "image": "ghcr.io/quenchworks/images/temporal-cli",
        "version": "1.8.2",
        "tag": "ghcr.io/quenchworks/images/temporal-cli:1.8.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/temporal"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.8.2",
            "tag": "ghcr.io/quenchworks/images/temporal-cli:1.8.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal"
                ]
              }
            ]
          },
          {
            "version": "1.7.3",
            "tag": "ghcr.io/quenchworks/images/temporal-cli:1.7.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal"
                ]
              }
            ]
          },
          {
            "version": "1.6.2",
            "tag": "ghcr.io/quenchworks/images/temporal-cli:1.6.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tigerbeetle",
      "name": "tigerbeetle",
      "category": "Database",
      "summary": "Distributed financial-grade accounting database for high-throughput double-entry bookkeeping. Ships a single self-contained static Zig binary; speaks its own binary protocol (not HTTP) on port 3000.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.17.4, 0.17.8, 0.17.9",
      "versions": [
        {
          "version": "0.17.4",
          "size": "11.3 MB",
          "published": "2026-07-23T06:48:21Z",
          "digest": "sha256:07394bfe56198e2d3b95a0437608bfa83bf9dfe79602008323ecad5ab2d3295f"
        },
        {
          "version": "0.17.8",
          "size": "11.5 MB",
          "published": "2026-07-23T06:48:21Z",
          "digest": "sha256:d411e1c2ed6944c627c442ca41ce13f28988d88418920b7fc780733a107493f7"
        },
        {
          "version": "0.17.9",
          "size": "11.6 MB",
          "published": "2026-07-23T06:48:15Z",
          "digest": "sha256:81cd83b527c9e21db69417a33b02ef7800702d1e0f0c0754a52e5ed32316887d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/tigerbeetle/tigerbeetle",
      "source": "https://github.com/tigerbeetle/tigerbeetle",
      "image": "ghcr.io/quenchworks/images/tigerbeetle",
      "security": {
        "image": "ghcr.io/quenchworks/images/tigerbeetle",
        "version": "0.17.9",
        "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.9",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.17.9",
            "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.9",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.17.8",
            "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.17.4",
            "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "timescaledb",
      "name": "timescaledb",
      "category": "Time series",
      "summary": "PostgreSQL 17 plus the open TimescaleDB extension (Apache-only edition), adding hypertables, continuous aggregates, and time-series functions for high-ingest metrics and event data. Built clean-licensed from source on Wolfi (no TSL community code).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.28.2, 2.29.0, 2.28.3",
      "versions": [
        {
          "version": "2.28.2",
          "size": "147.9 MB",
          "published": "2026-07-30T10:25:44Z",
          "digest": "sha256:87fa1b06bfdf134c97d9edb163e13e62f294a03d5e1cc2fbc047b079ba16f7d3"
        },
        {
          "version": "2.29.0",
          "size": "148.1 MB",
          "published": "2026-07-30T10:25:39Z",
          "digest": "sha256:1a769b019525f5b8f5ae529dd9d8bf8d7c40d689eafd2c2280d9b12951742bdd"
        },
        {
          "version": "2.28.3",
          "size": "147.9 MB",
          "published": "2026-07-30T10:25:36Z",
          "digest": "sha256:6fd7baf730e2c462cebcd50da2266853400e63e85071122c5be4b3703f01f0c0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.timescale.com",
      "source": "https://github.com/timescale/timescaledb",
      "image": "ghcr.io/quenchworks/images/timescaledb",
      "security": {
        "image": "ghcr.io/quenchworks/images/timescaledb",
        "version": "2.29.0",
        "tag": "ghcr.io/quenchworks/images/timescaledb:2.29.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.29.0",
            "tag": "ghcr.io/quenchworks/images/timescaledb:2.29.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.28.3",
            "tag": "ghcr.io/quenchworks/images/timescaledb:2.28.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.28.2",
            "tag": "ghcr.io/quenchworks/images/timescaledb:2.28.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "tomcat",
      "name": "tomcat",
      "category": "Gateway",
      "summary": "Apache Tomcat, the widely used open-source Java servlet container and web/application server for running Jakarta Servlet, JSP, and WebSocket web applications.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "11.0.24",
      "versions": [
        {
          "version": "11.0.24",
          "size": "86.9 MB",
          "published": "2026-07-09T07:40:43Z",
          "digest": "sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/tomcat",
      "source": "https://downloads.apache.org/tomcat/tomcat-11/",
      "image": "ghcr.io/quenchworks/images/tomcat",
      "security": {
        "image": "ghcr.io/quenchworks/images/tomcat",
        "version": "11.0.24",
        "tag": "ghcr.io/quenchworks/images/tomcat:11.0.24",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "C",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/tomcat@sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/tomcat@sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/tomcat@sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "11.0.24",
            "tag": "ghcr.io/quenchworks/images/tomcat:11.0.24",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "C",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/tomcat@sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/tomcat@sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/tomcat@sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "traefik",
      "name": "Traefik",
      "category": "Gateway",
      "summary": "Cloud-native reverse proxy and load balancer with automatic service discovery, dynamic config, and built-in Let's Encrypt TLS.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "3.7.10",
      "versions": [
        {
          "version": "3.7.10",
          "size": "54.3 MB",
          "published": "2026-08-02T08:48:09Z",
          "digest": "sha256:a1c7ec59912393e09eb5859b76f112f6cd8ee1e81d60888dac3a76c1a8fc11bd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/traefik/traefik",
      "source": "https://github.com/traefik/traefik",
      "image": "ghcr.io/quenchworks/images/traefik",
      "security": {
        "image": "ghcr.io/quenchworks/images/traefik",
        "version": "3.7.10",
        "tag": "ghcr.io/quenchworks/images/traefik:3.7.10",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/traefik"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.10",
            "tag": "ghcr.io/quenchworks/images/traefik:3.7.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/traefik"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "trivy",
      "name": "trivy",
      "category": "Security & supply chain",
      "summary": "Aqua Security's all-in-one vulnerability, misconfiguration, secret, and SBOM scanner for images, filesystems, and repositories. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.72.0",
      "versions": [
        {
          "version": "0.72.0",
          "size": "50.5 MB",
          "published": "2026-07-22T07:11:33Z",
          "digest": "sha256:33cbc12ef9912b9bbba3e0ee4d1784b768396e01a332aebbc412850632bb981f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://trivy.dev",
      "source": "https://github.com/aquasecurity/trivy",
      "image": "ghcr.io/quenchworks/images/trivy",
      "security": {
        "image": "ghcr.io/quenchworks/images/trivy",
        "version": "0.72.0",
        "tag": "ghcr.io/quenchworks/images/trivy:0.72.0",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 1,
        "unknown": 1,
        "total": 5,
        "fixable": 4,
        "grade": "D",
        "score": 53,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": "2.6.2",
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "CVE-2026-71556",
            "severity": "HIGH",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "CVE-2026-71557",
            "severity": "MEDIUM",
            "pkg": "github.com/go-git/go-git/v5",
            "installed": "v5.19.1",
            "fixed": "5.19.2",
            "title": "go-git is an extensible git implementation library written in pure Go. ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "CVE-2026-54787",
            "severity": "LOW",
            "pkg": "github.com/sigstore/sigstore-go",
            "installed": "v1.2.0",
            "fixed": "1.2.1",
            "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/trivy"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.72.0",
            "tag": "ghcr.io/quenchworks/images/trivy:0.72.0",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 1,
            "unknown": 1,
            "total": 5,
            "fixable": 4,
            "grade": "D",
            "score": 53,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": "2.6.2",
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "CVE-2026-71556",
                "severity": "HIGH",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71556",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "CVE-2026-71557",
                "severity": "MEDIUM",
                "pkg": "github.com/go-git/go-git/v5",
                "installed": "v5.19.1",
                "fixed": "5.19.2",
                "title": "go-git is an extensible git implementation library written in pure Go. ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-71557",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "CVE-2026-54787",
                "severity": "LOW",
                "pkg": "github.com/sigstore/sigstore-go",
                "installed": "v1.2.0",
                "fixed": "1.2.1",
                "title": "github.com/sigstore/sigstore-go: sigstore-go: Signature bypass allows acceptance of bundles signed with expired keys",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54787",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/trivy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tyk",
      "name": "tyk",
      "category": "Gateway",
      "summary": "Full-featured API gateway with rate limiting, auth, and quotas. Single static Go binary on a hardened nonroot Wolfi base; Redis is a runtime dependency the operator provides.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "5.13.1",
      "versions": [
        {
          "version": "5.13.1",
          "size": "91.1 MB",
          "published": "2026-07-22T07:12:58Z",
          "digest": "sha256:9cfda1cf047ad83818dd92116b23777d4fbaf7c6974c395a504ca456bcd13c33"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://tyk.io",
      "source": "https://github.com/TykTechnologies/tyk",
      "image": "ghcr.io/quenchworks/images/tyk",
      "security": {
        "image": "ghcr.io/quenchworks/images/tyk",
        "version": "5.13.1",
        "tag": "ghcr.io/quenchworks/images/tyk:5.13.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/tyk"
            ]
          }
        ],
        "versions": [
          {
            "version": "5.13.1",
            "tag": "ghcr.io/quenchworks/images/tyk:5.13.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/tyk"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "typesense",
      "name": "typesense",
      "category": "Search",
      "summary": "Fast, typo-tolerant search engine with an instant-search REST API and a self-contained embedded store (no external database), tuned for low-latency site and in-app search.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0",
      "licenseClean": "agpl",
      "version": "29.1, 28.0, 30.2",
      "versions": [
        {
          "version": "29.1",
          "size": "137.8 MB",
          "published": "2026-07-21T07:43:38Z",
          "digest": "sha256:72ccab4a6ea292551f8ce43a6c4cff9ed8bab689979e792e96fc5cc7855f39ae"
        },
        {
          "version": "28.0",
          "size": "122.7 MB",
          "published": "2026-07-21T07:43:31Z",
          "digest": "sha256:e189949ed7d958d94db1af35cfda889780840ebcdbc1ddaa116cff658146eccf"
        },
        {
          "version": "30.2",
          "size": "147.4 MB",
          "published": "2026-07-21T07:43:31Z",
          "digest": "sha256:cd0f547e0efe05502c9d2dcbef4a2e0071084d4bed694aac244b6c3a5f6e8337"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/typesense/typesense",
      "source": "https://github.com/typesense/typesense",
      "image": "ghcr.io/quenchworks/images/typesense",
      "security": {
        "image": "ghcr.io/quenchworks/images/typesense",
        "version": "30.2",
        "tag": "ghcr.io/quenchworks/images/typesense:30.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "30.2",
            "tag": "ghcr.io/quenchworks/images/typesense:30.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "29.1",
            "tag": "ghcr.io/quenchworks/images/typesense:29.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "28.0",
            "tag": "ghcr.io/quenchworks/images/typesense:28.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "uv",
      "name": "uv",
      "category": "Build tool",
      "summary": "Python base image with uv, a fast Rust-based installer and resolver, used as the build stage for Python projects. Line 0.11.",
      "tier": "standard",
      "status": "available",
      "license": "MIT OR Apache-2.0",
      "licenseClean": "clean",
      "version": "0.12.1, 0.12.0, 0.11.33",
      "versions": [
        {
          "version": "0.12.1",
          "size": "45.8 MB",
          "published": "2026-08-02T08:57:34Z",
          "digest": "sha256:336a88e7c476ac78c127a10160ca117c910fbf6061267d22d8a917e6b3b57e38"
        },
        {
          "version": "0.12.0",
          "size": "45.5 MB",
          "published": "2026-08-02T08:57:31Z",
          "digest": "sha256:df2dd583bcff2e1f8375878e5f8db499c6ece329cefc76d4895733acbcec352c"
        },
        {
          "version": "0.11.33",
          "size": "45.6 MB",
          "published": "2026-08-02T08:57:31Z",
          "digest": "sha256:424b41b632cb28f7f0e01f9b2a57653e562b961f4a421e7d66639bdf6f2685de"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/astral-sh/uv",
      "source": "https://github.com/astral-sh/uv",
      "image": "ghcr.io/quenchworks/images/uv",
      "security": {
        "image": "ghcr.io/quenchworks/images/uv",
        "version": "0.12.1",
        "tag": "ghcr.io/quenchworks/images/uv:0.12.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.12.1",
            "tag": "ghcr.io/quenchworks/images/uv:0.12.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.12.0",
            "tag": "ghcr.io/quenchworks/images/uv:0.12.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.11.33",
            "tag": "ghcr.io/quenchworks/images/uv:0.11.33",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "valkey",
      "name": "Valkey",
      "category": "Cache",
      "summary": "BSD-licensed in-memory key-value store, the truly-open community fork of Redis 7.2. QuenchWorks' default cache and the recommended Redis drop-in replacement.",
      "tier": "critical",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "9.0.4, 9.1.1, 8.1.8",
      "versions": [
        {
          "version": "9.0.4",
          "size": "14.1 MB",
          "published": "2026-07-22T11:31:18Z",
          "digest": "sha256:9821d46e38697f92405ef6c3997dc1f32a5d6219163e2b679f919d72239f4cf7"
        },
        {
          "version": "9.1.1",
          "size": "14.9 MB",
          "published": "2026-07-22T11:31:17Z",
          "digest": "sha256:8ee902be36ca7d49a25607ee77629433f225e89f905e15fdde67dd29a15686f2"
        },
        {
          "version": "8.1.8",
          "size": "13.4 MB",
          "published": "2026-07-22T11:31:14Z",
          "digest": "sha256:e5ad713627f5fbdabbd0270413e76d50ddfb690c2c2aaf457a0a2599367ffe8e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/valkey-io/valkey",
      "source": "https://github.com/valkey-io/valkey",
      "image": "ghcr.io/quenchworks/images/valkey",
      "security": {
        "image": "ghcr.io/quenchworks/images/valkey",
        "version": "9.1.1",
        "tag": "ghcr.io/quenchworks/images/valkey:9.1.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.1.1",
            "tag": "ghcr.io/quenchworks/images/valkey:9.1.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.0.4",
            "tag": "ghcr.io/quenchworks/images/valkey:9.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.1.8",
            "tag": "ghcr.io/quenchworks/images/valkey:8.1.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "varnish",
      "name": "varnish",
      "category": "Cache",
      "summary": "HTTP reverse-proxy cache (web accelerator) that fronts an origin and serves its responses from memory, cutting backend load and tail latency. Caching policy is VCL, which varnishd compiles to native code at startup. The chart supplies the VCL and the backend.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-2-Clause",
      "licenseClean": "clean",
      "version": "7.7.3, 9.0.3, 8.0.0",
      "versions": [
        {
          "version": "7.7.3",
          "size": "192.8 MB",
          "published": "2026-07-28T09:49:03Z",
          "digest": "sha256:59e7a38ad2b437e539721b935b4f7932fbee6cb758a389f79a5611116fb58f30"
        },
        {
          "version": "9.0.3",
          "size": "196.0 MB",
          "published": "2026-07-28T09:48:39Z",
          "digest": "sha256:97d1607e3e49d53ec45173a82a8fb9636017b76b05f09ad7f99fe4bb540a7a77"
        },
        {
          "version": "8.0.0",
          "size": "192.9 MB",
          "published": "2026-07-28T09:48:26Z",
          "digest": "sha256:e131fa7719363e61c91513d20a39ef89280139a30d44e41c837d84f69acf705d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.varnish.org",
      "source": "https://github.com/varnish/varnish",
      "image": "ghcr.io/quenchworks/images/varnish",
      "security": {
        "image": "ghcr.io/quenchworks/images/varnish",
        "version": "9.0.3",
        "tag": "ghcr.io/quenchworks/images/varnish:9.0.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.0.3",
            "tag": "ghcr.io/quenchworks/images/varnish:9.0.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.0",
            "tag": "ghcr.io/quenchworks/images/varnish:8.0.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "7.7.3",
            "tag": "ghcr.io/quenchworks/images/varnish:7.7.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "vault",
      "name": "vault",
      "category": "Secrets",
      "summary": "Secrets and encryption management for tokens, keys, and certificates, with dynamic secrets, leasing, and PKI. Shipped under the Business Source License 1.1, which is not OSI-approved; OpenBao (MPL-2.0) is the open drop-in fork. Built from source with the web UI included; the chart supports multi-node raft HA. The 1.20.x line is CVE-blocked upstream and not shipped.",
      "tier": "low",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "2.0.3",
      "versions": [
        {
          "version": "2.0.3",
          "size": "95.5 MB",
          "published": "2026-08-03T08:35:41Z",
          "digest": "sha256:9379b7e3219452a823449ae7a45ae8eac26ad26126cdff57d8746d796c4bdebf"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/hashicorp/vault",
      "source": "https://github.com/hashicorp/vault",
      "image": "ghcr.io/quenchworks/images/vault",
      "caution": true,
      "security": {
        "image": "ghcr.io/quenchworks/images/vault",
        "version": "2.0.3",
        "tag": "ghcr.io/quenchworks/images/vault:2.0.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/vault"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.0.3",
            "tag": "ghcr.io/quenchworks/images/vault:2.0.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/vault"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "vector",
      "name": "Vector",
      "category": "Observability",
      "summary": "High-performance observability pipeline that collects, transforms, and routes logs, metrics, and traces between sources and sinks.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "0.57.0",
      "versions": [
        {
          "version": "0.57.0",
          "size": "32.5 MB",
          "published": "2026-07-15T12:10:00Z",
          "digest": "sha256:e3aa5744d0138f42f68fc3afbb1bea1d62ce2c1edb7a885dfaacfb1a81b0f736"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/vectordotdev/vector",
      "source": "https://github.com/vectordotdev/vector",
      "image": "ghcr.io/quenchworks/images/vector",
      "security": {
        "image": "ghcr.io/quenchworks/images/vector",
        "version": "0.57.0",
        "tag": "ghcr.io/quenchworks/images/vector:0.57.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.57.0",
            "tag": "ghcr.io/quenchworks/images/vector:0.57.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "velero",
      "name": "velero",
      "category": "Storage & platform",
      "summary": "CNCF backup and disaster-recovery tool for Kubernetes cluster resources and persistent volumes. Single static Go binary on a hardened nonroot Wolfi base; object-store and snapshot backends are the operator's choice.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.2",
      "versions": [
        {
          "version": "1.18.2",
          "size": "30.3 MB",
          "published": "2026-07-22T07:11:43Z",
          "digest": "sha256:6d22413905ef1e3c2c04197fb2b6b446665ad9f2e72050dc75894b3029d196f8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://velero.io",
      "source": "https://github.com/vmware-tanzu/velero",
      "image": "ghcr.io/quenchworks/images/velero",
      "security": {
        "image": "ghcr.io/quenchworks/images/velero",
        "version": "1.18.2",
        "tag": "ghcr.io/quenchworks/images/velero:1.18.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/velero"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.18.2",
            "tag": "ghcr.io/quenchworks/images/velero:1.18.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/velero"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "victorialogs",
      "name": "victorialogs",
      "category": "Observability",
      "summary": "Fast, cost-efficient logs database with the LogsQL query language. Single static Go binary on a hardened nonroot Wolfi base; log data lives on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.51.0",
      "versions": [
        {
          "version": "1.51.0",
          "size": "9.8 MB",
          "published": "2026-07-08T10:53:06Z",
          "digest": "sha256:bd1f3a98a422a596d6f9c776dc08c5f36ddbc61c0584c8e38fc395eb406086ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.victoriametrics.com/victorialogs",
      "source": "https://github.com/VictoriaMetrics/VictoriaLogs",
      "image": "ghcr.io/quenchworks/images/victorialogs",
      "security": {
        "image": "ghcr.io/quenchworks/images/victorialogs",
        "version": "1.51.0",
        "tag": "ghcr.io/quenchworks/images/victorialogs:1.51.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.51.0",
            "tag": "ghcr.io/quenchworks/images/victorialogs:1.51.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "victoriametrics",
      "name": "VictoriaMetrics",
      "category": "Time series",
      "summary": "Fast, cost-efficient time-series database that speaks PromQL and Prometheus remote_write. Drop-in long-term storage or full replacement for Prometheus.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.148.0",
      "versions": [
        {
          "version": "1.148.0",
          "size": "10.9 MB",
          "published": "2026-07-21T08:47:57Z",
          "digest": "sha256:c6890da882b13ed5dbef8811b5974feffe5af5374ce963c50f2442dc59b1220d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/VictoriaMetrics/VictoriaMetrics",
      "source": "https://github.com/VictoriaMetrics/VictoriaMetrics",
      "image": "ghcr.io/quenchworks/images/victoriametrics",
      "security": {
        "image": "ghcr.io/quenchworks/images/victoriametrics",
        "version": "1.148.0",
        "tag": "ghcr.io/quenchworks/images/victoriametrics:1.148.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.148.0",
            "tag": "ghcr.io/quenchworks/images/victoriametrics:1.148.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "vikunja",
      "name": "vikunja",
      "category": "Apps & productivity",
      "summary": "Self-hosted to-do and project management app (lists, kanban, gantt, calendar) serving both the API and the Vue web UI. From source with the UI embedded on a hardened nonroot Wolfi base; SQLite or an external SQL database.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0+",
      "licenseClean": "agpl",
      "version": "2.3.0",
      "versions": [
        {
          "version": "2.3.0",
          "size": "29.7 MB",
          "published": "2026-07-15T12:43:57Z",
          "digest": "sha256:4a45a0d821538a6af5d08fea9f9c88f55d1bae3ebeef0a8417ee7ec815c5c169"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://vikunja.io",
      "source": "https://github.com/go-vikunja/vikunja",
      "image": "ghcr.io/quenchworks/images/vikunja",
      "security": {
        "image": "ghcr.io/quenchworks/images/vikunja",
        "version": "2.3.0",
        "tag": "ghcr.io/quenchworks/images/vikunja:2.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 97,
        "cves": [
          {
            "id": "CVE-2023-36308",
            "severity": "LOW",
            "pkg": "github.com/disintegration/imaging",
            "installed": "v1.6.2",
            "fixed": null,
            "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
            "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
            "targets": [
              "usr/bin/vikunja"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/vikunja"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.3.0",
            "tag": "ghcr.io/quenchworks/images/vikunja:2.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 97,
            "cves": [
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/vikunja"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/vikunja"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "vllm",
      "name": "vllm",
      "category": "Machine learning & AI",
      "summary": "vLLM, the high-throughput LLM inference and serving engine with an OpenAI-compatible API. CPU build — installs vLLM's prebuilt CPU wheel (torch+cpu, no source compile, no CUDA) into a venv on a hardened Wolfi python-3.12 base, 0-CVE across ~140 Python packages. The user supplies the model; the chart runs it as a StatefulSet with a persistent model cache.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.25.1",
      "versions": [
        {
          "version": "0.25.1",
          "size": "946.4 MB",
          "published": "2026-07-15T10:42:20Z",
          "digest": "sha256:8ddd4b1173ed21f264bd1f910a4dddb6f2f659a33374124b3b443538c3c81b02"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.vllm.ai",
      "source": "https://github.com/vllm-project/vllm",
      "image": "ghcr.io/quenchworks/images/vllm",
      "security": {
        "image": "ghcr.io/quenchworks/images/vllm",
        "version": "0.25.1",
        "tag": "ghcr.io/quenchworks/images/vllm:0.25.1",
        "critical": 0,
        "high": 2,
        "medium": 4,
        "low": 1,
        "unknown": 0,
        "total": 7,
        "fixable": 6,
        "grade": "D",
        "score": 33,
        "cves": [
          {
            "id": "CVE-2026-69244",
            "severity": "HIGH",
            "pkg": "aiohttp",
            "installed": "3.14.1",
            "fixed": "3.14.3",
            "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69244",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-69247",
            "severity": "HIGH",
            "pkg": "cryptography",
            "installed": "49.0.0",
            "fixed": "50.0.0",
            "title": "cryptography is a package designed to expose cryptographic primitives  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-59881",
            "severity": "MEDIUM",
            "pkg": "aiohttp",
            "installed": "3.14.1",
            "fixed": "3.14.2",
            "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59881",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-59890",
            "severity": "MEDIUM",
            "pkg": "setuptools",
            "installed": "80.9.0",
            "fixed": "83.0.0",
            "title": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59890",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2026-69243",
            "severity": "MEDIUM",
            "pkg": "aiohttp",
            "installed": "3.14.1",
            "fixed": "3.14.2",
            "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-69243",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2025-69872",
            "severity": "MEDIUM",
            "pkg": "diskcache",
            "installed": "5.6.3",
            "fixed": null,
            "title": "python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization",
            "url": "https://avd.aquasec.com/nvd/cve-2025-69872",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2025-3000",
            "severity": "LOW",
            "pkg": "torch",
            "installed": "2.11.0+cpu",
            "fixed": "2.13.0",
            "title": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...",
            "url": "https://avd.aquasec.com/nvd/cve-2025-3000",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.25.1",
            "tag": "ghcr.io/quenchworks/images/vllm:0.25.1",
            "critical": 0,
            "high": 2,
            "medium": 4,
            "low": 1,
            "unknown": 0,
            "total": 7,
            "fixable": 6,
            "grade": "D",
            "score": 33,
            "cves": [
              {
                "id": "CVE-2026-69244",
                "severity": "HIGH",
                "pkg": "aiohttp",
                "installed": "3.14.1",
                "fixed": "3.14.3",
                "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69244",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-69247",
                "severity": "HIGH",
                "pkg": "cryptography",
                "installed": "49.0.0",
                "fixed": "50.0.0",
                "title": "cryptography is a package designed to expose cryptographic primitives  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69247",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-59881",
                "severity": "MEDIUM",
                "pkg": "aiohttp",
                "installed": "3.14.1",
                "fixed": "3.14.2",
                "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59881",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-59890",
                "severity": "MEDIUM",
                "pkg": "setuptools",
                "installed": "80.9.0",
                "fixed": "83.0.0",
                "title": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59890",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2026-69243",
                "severity": "MEDIUM",
                "pkg": "aiohttp",
                "installed": "3.14.1",
                "fixed": "3.14.2",
                "title": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-69243",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2025-69872",
                "severity": "MEDIUM",
                "pkg": "diskcache",
                "installed": "5.6.3",
                "fixed": null,
                "title": "python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization",
                "url": "https://avd.aquasec.com/nvd/cve-2025-69872",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2025-3000",
                "severity": "LOW",
                "pkg": "torch",
                "installed": "2.11.0+cpu",
                "fixed": "2.13.0",
                "title": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...",
                "url": "https://avd.aquasec.com/nvd/cve-2025-3000",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "weaviate",
      "name": "weaviate",
      "category": "Search & vector",
      "summary": "Open-source AI-native vector database for semantic search and retrieval-augmented generation, with hybrid keyword plus vector queries.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.38.8",
      "versions": [
        {
          "version": "1.38.8",
          "size": "69.0 MB",
          "published": "2026-07-30T08:13:54Z",
          "digest": "sha256:519ffc0a60bb2d763a9186f859c1e736947a1cbc519925ea205edff3aa5dcd2a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://weaviate.io",
      "source": "https://github.com/weaviate/weaviate",
      "image": "ghcr.io/quenchworks/images/weaviate",
      "security": {
        "image": "ghcr.io/quenchworks/images/weaviate",
        "version": "1.38.8",
        "tag": "ghcr.io/quenchworks/images/weaviate:1.38.8",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/weaviate-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.38.8",
            "tag": "ghcr.io/quenchworks/images/weaviate:1.38.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/weaviate-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "woodpecker",
      "name": "woodpecker",
      "category": "CI/CD & registry",
      "summary": "Lightweight, container-native CI/CD engine (a Drone-compatible fork) with a server, agent, and CLI. From source (Vue UI embedded in the static Go server) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.16.0",
      "versions": [
        {
          "version": "3.16.0",
          "size": "59.2 MB",
          "published": "2026-07-22T06:34:04Z",
          "digest": "sha256:66a6768fbc6a8e6fc5d57e757dceaa2afbdaf8eddaf361bd489868b251b6d1e7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://woodpecker-ci.org",
      "source": "https://github.com/woodpecker-ci/woodpecker",
      "image": "ghcr.io/quenchworks/images/woodpecker",
      "security": {
        "image": "ghcr.io/quenchworks/images/woodpecker",
        "version": "3.16.0",
        "tag": "ghcr.io/quenchworks/images/woodpecker:3.16.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/woodpecker-cli",
              "usr/bin/woodpecker-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.16.0",
            "tag": "ghcr.io/quenchworks/images/woodpecker:3.16.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/woodpecker-cli",
                  "usr/bin/woodpecker-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "wordpress",
      "name": "wordpress",
      "category": "Apps & productivity",
      "summary": "WordPress, the PHP content-management system and blogging platform. Reconstructed clean-room from the official release on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs, supervisord), not the php:apache upstream image. The image ships no wp-config.php; the chart supplies one via ConfigMap and provides a MySQL backend.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0+",
      "licenseClean": "clean",
      "version": "6.8.6, 7.0.2, 6.9.5",
      "versions": [
        {
          "version": "6.8.6",
          "size": "91.1 MB",
          "published": "2026-07-26T12:37:55Z",
          "digest": "sha256:ed91a26d0d7641f3732296e070d064cec5cc596ef1c2d8644608a1662fa93a6a"
        },
        {
          "version": "7.0.2",
          "size": "93.7 MB",
          "published": "2026-07-26T12:37:54Z",
          "digest": "sha256:dbe5e89bf4b10d8950e7bed7aea88d134fdd5554629de29c3aa6427bab8804f6"
        },
        {
          "version": "6.9.5",
          "size": "91.1 MB",
          "published": "2026-07-26T12:37:49Z",
          "digest": "sha256:7ac3ed7ed68ee8683cf0d0b4772c51eb18970b25b4c8f6d7236cef5df20218e0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://wordpress.org",
      "source": "https://wordpress.org/wordpress-7.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/wordpress",
      "security": {
        "image": "ghcr.io/quenchworks/images/wordpress",
        "version": "7.0.2",
        "tag": "ghcr.io/quenchworks/images/wordpress:7.0.2",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "C",
        "score": 91,
        "cves": [
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/wordpress@sha256:dbe5e89bf4b10d8950e7bed7aea88d134fdd5554629de29c3aa6427bab8804f6 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "7.0.2",
            "tag": "ghcr.io/quenchworks/images/wordpress:7.0.2",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/wordpress@sha256:dbe5e89bf4b10d8950e7bed7aea88d134fdd5554629de29c3aa6427bab8804f6 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "6.9.5",
            "tag": "ghcr.io/quenchworks/images/wordpress:6.9.5",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/wordpress@sha256:7ac3ed7ed68ee8683cf0d0b4772c51eb18970b25b4c8f6d7236cef5df20218e0 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "6.8.6",
            "tag": "ghcr.io/quenchworks/images/wordpress:6.8.6",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "C",
            "score": 91,
            "cves": [
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/wordpress@sha256:ed91a26d0d7641f3732296e070d064cec5cc596ef1c2d8644608a1662fa93a6a (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "xyops",
      "name": "xyops",
      "category": "Workflow",
      "summary": "xyops, a workflow-automation and server-monitoring system (job scheduler, monitors, alerting, ticketing) by the creator of Cronicle. Built from source on Wolfi nodejs-22 (native better-sqlite3), nonroot on a hardened read-only-rootfs base. Single-instance with an embedded SQLite store on a persistent volume; the chart runs it as a StatefulSet.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.0.86",
      "versions": [
        {
          "version": "1.0.86",
          "size": "85.0 MB",
          "published": "2026-07-30T08:10:02Z",
          "digest": "sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/pixlcore/xyops",
      "source": "https://github.com/pixlcore/xyops",
      "image": "ghcr.io/quenchworks/images/xyops",
      "security": {
        "image": "ghcr.io/quenchworks/images/xyops",
        "version": "1.0.86",
        "tag": "ghcr.io/quenchworks/images/xyops:1.0.86",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 1,
        "unknown": 0,
        "total": 4,
        "fixable": 4,
        "grade": "D",
        "score": 55,
        "cves": [
          {
            "id": "CVE-2026-58043",
            "severity": "HIGH",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
            "targets": [
              "ghcr.io/quenchworks/images/xyops@sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-67213",
            "severity": "HIGH",
            "pkg": "nanoid",
            "installed": "3.3.16",
            "fixed": "3.3.17, 5.1.6",
            "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/xyops@sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56847",
            "severity": "LOW",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
            "targets": [
              "ghcr.io/quenchworks/images/xyops@sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.0.86",
            "tag": "ghcr.io/quenchworks/images/xyops:1.0.86",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 4,
            "grade": "D",
            "score": 55,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/xyops@sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-67213",
                "severity": "HIGH",
                "pkg": "nanoid",
                "installed": "3.3.16",
                "fixed": "3.3.17, 5.1.6",
                "title": "nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-67213",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/xyops@sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/xyops@sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "yarn",
      "name": "yarn",
      "category": "Build tool",
      "summary": "Node base image with Yarn preinstalled, used as the build stage for Yarn projects. Lines 1 (classic) and 4 (berry).",
      "tier": "standard",
      "status": "available",
      "license": "BSD-2-Clause",
      "licenseClean": "clean",
      "version": "4.17.0, 3.8.7, 1.22.22",
      "versions": [
        {
          "version": "4.17.0",
          "size": "53.4 MB",
          "published": "2026-07-04T11:34:16Z",
          "digest": "sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20"
        },
        {
          "version": "3.8.7",
          "size": "53.2 MB",
          "published": "2026-07-04T11:34:15Z",
          "digest": "sha256:8bc7879fce7e56c07776a42c6a3cc8b854ee275bb3d0eac8cab07db27fc0856c"
        },
        {
          "version": "1.22.22",
          "size": "53.5 MB",
          "published": "2026-07-04T11:34:00Z",
          "digest": "sha256:7df831896c444391b86e2f8f60f807c8139a2932bced734509c6c54552278ce1"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://yarnpkg.com",
      "source": "https://yarnpkg.com",
      "image": "ghcr.io/quenchworks/images/yarn",
      "security": {
        "image": "ghcr.io/quenchworks/images/yarn",
        "version": "4.17.0",
        "tag": "ghcr.io/quenchworks/images/yarn:4.17.0",
        "critical": 0,
        "high": 1,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 4,
        "fixable": 4,
        "grade": "D",
        "score": 61,
        "cves": [
          {
            "id": "CVE-2026-58043",
            "severity": "HIGH",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
            "targets": [
              "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56850",
            "severity": "MEDIUM",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
            "targets": [
              "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-58055",
            "severity": "MEDIUM",
            "pkg": "libnghttp2-14",
            "installed": "1.69.0-r0",
            "fixed": "1.70.0-r0",
            "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
            "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
            "targets": [
              "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-56847",
            "severity": "LOW",
            "pkg": "nodejs-22",
            "installed": "22.23.1-r1",
            "fixed": "22.23.2-r0",
            "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
            "targets": [
              "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.17.0",
            "tag": "ghcr.io/quenchworks/images/yarn:4.17.0",
            "critical": 0,
            "high": 1,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 4,
            "grade": "D",
            "score": 61,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20 (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "3.8.7",
            "tag": "ghcr.io/quenchworks/images/yarn:3.8.7",
            "critical": 0,
            "high": 1,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 4,
            "grade": "D",
            "score": 61,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:8bc7879fce7e56c07776a42c6a3cc8b854ee275bb3d0eac8cab07db27fc0856c (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:8bc7879fce7e56c07776a42c6a3cc8b854ee275bb3d0eac8cab07db27fc0856c (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:8bc7879fce7e56c07776a42c6a3cc8b854ee275bb3d0eac8cab07db27fc0856c (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:8bc7879fce7e56c07776a42c6a3cc8b854ee275bb3d0eac8cab07db27fc0856c (wolfi 20230201)"
                ]
              }
            ]
          },
          {
            "version": "1.22.22",
            "tag": "ghcr.io/quenchworks/images/yarn:1.22.22",
            "critical": 0,
            "high": 1,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 4,
            "fixable": 4,
            "grade": "D",
            "score": 61,
            "cves": [
              {
                "id": "CVE-2026-58043",
                "severity": "HIGH",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58043",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:7df831896c444391b86e2f8f60f807c8139a2932bced734509c6c54552278ce1 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56850",
                "severity": "MEDIUM",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56850",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:7df831896c444391b86e2f8f60f807c8139a2932bced734509c6c54552278ce1 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-58055",
                "severity": "MEDIUM",
                "pkg": "libnghttp2-14",
                "installed": "1.69.0-r0",
                "fixed": "1.70.0-r0",
                "title": "nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests",
                "url": "https://avd.aquasec.com/nvd/cve-2026-58055",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:7df831896c444391b86e2f8f60f807c8139a2932bced734509c6c54552278ce1 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56847",
                "severity": "LOW",
                "pkg": "nodejs-22",
                "installed": "22.23.1-r1",
                "fixed": "22.23.2-r0",
                "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56847",
                "targets": [
                  "ghcr.io/quenchworks/images/yarn@sha256:7df831896c444391b86e2f8f60f807c8139a2932bced734509c6c54552278ce1 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "zookeeper",
      "name": "ZooKeeper",
      "category": "Coordination",
      "summary": "Centralized coordination service for distributed systems, providing configuration, naming, leader election, and synchronization primitives.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.9.5",
      "versions": [
        {
          "version": "3.9.5",
          "size": "92.5 MB",
          "published": "2026-07-23T11:58:11Z",
          "digest": "sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/zookeeper",
      "source": "https://archive.apache.org/dist/zookeeper/zookeeper-3.9.5/apache-zookeeper-3.9.5-bin.tar.gz",
      "image": "ghcr.io/quenchworks/images/zookeeper",
      "security": {
        "image": "ghcr.io/quenchworks/images/zookeeper",
        "version": "3.9.5",
        "tag": "ghcr.io/quenchworks/images/zookeeper:3.9.5",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "C",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-46968",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
            "targets": [
              "ghcr.io/quenchworks/images/zookeeper@sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47021",
            "severity": "MEDIUM",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
            "targets": [
              "ghcr.io/quenchworks/images/zookeeper@sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329 (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-47010",
            "severity": "LOW",
            "pkg": "openjdk-21-jre",
            "installed": "21.0.11-r3",
            "fixed": "21.0.12-r0",
            "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
            "targets": [
              "ghcr.io/quenchworks/images/zookeeper@sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329 (wolfi 20230201)"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.9.5",
            "tag": "ghcr.io/quenchworks/images/zookeeper:3.9.5",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "C",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-46968",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46968",
                "targets": [
                  "ghcr.io/quenchworks/images/zookeeper@sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47021",
                "severity": "MEDIUM",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance XBM image support (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47021",
                "targets": [
                  "ghcr.io/quenchworks/images/zookeeper@sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47010",
                "severity": "LOW",
                "pkg": "openjdk-21-jre",
                "installed": "21.0.11-r3",
                "fixed": "21.0.12-r0",
                "title": "openjdk: Enhance JPEG handling (Oracle CPU 2026-07)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47010",
                "targets": [
                  "ghcr.io/quenchworks/images/zookeeper@sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "zot",
      "name": "zot",
      "category": "Registry",
      "summary": "OCI-native container registry (registry, sync, and dist-spec surface). Built from source as a static Go binary on a hardened nonroot Wolfi base; filesystem storage under a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.1.18",
      "versions": [
        {
          "version": "2.1.18",
          "size": "22.3 MB",
          "published": "2026-07-26T12:35:16Z",
          "digest": "sha256:90d5fae2927a377892e1579bc41ace4370963e7e60fd44e4e5f9de376bd83a3d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://zotregistry.dev",
      "source": "https://github.com/project-zot/zot",
      "image": "ghcr.io/quenchworks/images/zot",
      "security": {
        "image": "ghcr.io/quenchworks/images/zot",
        "version": "2.1.18",
        "tag": "ghcr.io/quenchworks/images/zot:2.1.18",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/zot"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.1.18",
            "tag": "ghcr.io/quenchworks/images/zot:2.1.18",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/zot"
                ]
              }
            ]
          }
        ]
      }
    }
  ]
}