Saltar al contenido
QuenchWorks

Hoja de ruta

Qué está publicado, qué sigue

375 bases de datos y herramientas están endurecidas y publicadas hoy. Debajo está lo que viene, primero las opciones limpias OSI. Cada entrada se compila desde el código fuente sobre Wolfi, se escanea hasta cero CVE corregibles, se firma y se fija por digest antes de pasar a disponible.

375/471
80% publicado
37580%
Publicado
9420%
En la hoja de ruta
20%
Bloqueadas

Disponible ahora

375

Puerta de enlace de IA

2

Analítico

1

Aplicaciones y productividad

28

Imagen base

1

Herramienta de compilación

7

CI

2

CI/CD y registro

27

Caché

7

Coordinación

13

Coordinación y malla

18

Database

1

Bases de datos y motores

12

Developer tools / IDE

1

Documental

5

Puerta de enlace

26

Git

4

GitOps

3

Grafos

1

Identidad

12

Entorno de ejecución de lenguaje

13

Machine learning & AI

8

Medios y streaming

3

Mensajería

17

Métricas/Exportador

6

Almacenamiento de objetos

5

Observabilidad

32

PaaS

3

Registro

10

Relacional

10

Base de ejecución

4

Búsqueda

8

Búsqueda y vectores

1

Secretos

3

Secretos e identidad

2

Seguridad y cadena de suministro

41

Almacenamiento y plataforma

17

Series temporales

4

Vectorial

1

Columna ancha

2

Flujo de trabajo

14

Retenidas — compiladas, sin publicar

2

Se compilan y prueban limpias pero aún no alcanzan 0 CVE corregibles — la app o su base fija una dependencia por debajo de la versión que corrige un CVE conocido, así que la retenemos en lugar de publicar una imagen vulnerable. Cada una se vuelve a listar automáticamente en cuanto el upstream publica la corrección. Toca ¿por qué bloqueada? para ver la fijación exacta.

Aplicaciones y productividad

1
  • Apache Supersetbloqueada

    Plataforma de exploración de datos y paneles de inteligencia de negocio respaldada por una base de datos de metadatos y Redis.

    Aplicaciones y productividadApache-2.0

Observabilidad

1
  • OpenSearch Dashboardsbloqueada

    Interfaz de visualización y paneles para OpenSearch.

    ObservabilidadApache-2.0

En la hoja de ruta

94

Candidatos, no compromisos. próximo = las apuestas más sólidas a corto plazo; luego siguen planificado y explorando. Los elementos marcados como precaución son de código disponible (no OSI) y solo se publicarían con una nota de licencia visible y la alternativa limpia señalada. (Las apps que compilan pero aún no llegan a 0 CVE corregibles están en Retenidas, arriba.) Cada tarjeta también muestra cómo se publicará: imagen + chart para un servicio desplegable, osolo imagen para una utilidad base/CLI/sidecar (como busybox).

Búsqueda y vectores

1
  • Milvusplanificado

    Base de datos vectorial escalable para cargas de trabajo de IA.

    imagen + chartApache-2.0

Flujo de trabajo y datos

8
  • Apache Pinotplanificado

    Almacén de datos OLAP distribuido en tiempo real para analítica de baja latencia.

    imagen + chartApache-2.0
  • Apache Sparkplanificado

    Motor unificado de analítica por lotes y en streaming.

    imagen + chartApache-2.0
  • Camundaplanificado

    Automatización de procesos y orquestación BPMN, incluido el motor Zeebe.

    imagen + chartCamunda-License-1.0precaución
  • Apache Camel Kexplorando

    Kubernetes-native integration framework.

    imagen + chartApache-2.0
  • Apache Druidexplorando

    Base de datos de analítica en tiempo real para consultas OLAP de alta concurrencia.

    imagen + chartApache-2.0
  • Apache Polarisexplorando

    Open REST catalog for Apache Iceberg tables.

    imagen + chartApache-2.0
  • Cubeexplorando

    Semantic layer and analytics API over your data.

    imagen + chartApache-2.0
  • Hyperledger Fabricexplorando

    Permissioned enterprise blockchain platform.

    imagen + chartApache-2.0

Mensajería y streaming

4
  • Apicurio Registryplanificado

    API and schema registry for Kafka, Avro, and Protobuf. Measured 2026-09-25: the 3.3.3 app distribution carries 467 findings; 26 in-place jar swaps clear all but opentelemetry-api 1.57.0 (CVE-2026-45292, fixed only in 1.62.0), which adds packages the prebuilt Quarkus index cannot load. Needs a source build that regenerates the index.

    imagen + chartApache-2.0
  • Redpandaplanificado

    Streaming compatible con Kafka. De código disponible, no OSI.

    alt. limpia: Kafka or Pulsar (Apache-2.0), both already shipped.

    imagen + chartBSL-1.1precaución
  • Strimziplanificado

    Kubernetes operator for running and managing Kafka. Sized 2026-09-25: two from-source images, the operator (a Maven multi-module build; the release ships only install YAML) and Strimzi's own Kafka image, whose run scripts and agents the operator drives; the QuenchWorks kafka image does not have that layout. Measured 2026-09-29: Wolfi packages Strimzi too (strimzi-kafka-operator with kafka-strimzi-compat), but at 1.0.0-r4 against upstream 1.2.0, and that stack scans at 849 fixable findings (59 critical, 353 high), including jackson-databind 2.21.2 and the JMX exporter; so it still needs the from-source build.

    imagen + chartApache-2.0
  • Apache Stormexplorando

    Distributed real-time stream processing.

    imagen + chartApache-2.0

Coordinación y malla

11
  • Calicoplanificado

    eBPF/iptables CNI for networking and network policy.

    imagen + chartApache-2.0
  • Cilium Envoyplanificado

    Cilium's own patched Envoy; not reusable from our stock envoy image.

    imagen + chartApache-2.0
  • Consulplanificado

    Descubrimiento de servicios y malla. De código disponible, no OSI.

    alt. limpia: Kuma (Apache-2.0) -- already shipped; or Linkerd / Istio.

    imagen + chartBUSL-1.1precaución
  • Consul Dataplaneplanificado

    Envoy-based sidecar for Consul. MPL, so cleaner than the BUSL server.

    imagen + chartMPL-2.0
  • Consul K8s Control Planeplanificado

    The operator that makes Consul work on Kubernetes.

    imagen + chartMPL-2.0
  • Istioplanificado

    Malla de servicios construida sobre Envoy: gestión de tráfico, mTLS y observabilidad. A escala de plataforma, una oleada de varias imágenes (plano de control istiod más sidecars y pasarelas de Envoy) en lugar de una sola imagen.

    imagen + chartApache-2.0
  • Istio CNIplanificado

    Privileged node agent; hostPath + privileged. Needs the node-agent exception tier.

    imagen + chartApache-2.0
  • Istio ztunnelplanificado

    Rust node proxy for Istio ambient mode. Skip if we ship sidecar mode only.

    imagen + chartApache-2.0
  • Linkerd CNIplanificado

    Privileged node agent (alternative to proxy-init). Needs the node-agent exception tier.

    imagen + chartApache-2.0
  • Linkerd Vizplanificado

    Observability extension: metrics-api, tap, tap-injector, web. Ship only if dashboard parity is wanted.

    imagen + chartApache-2.0
  • Nomadplanificado

    Planificador de cargas de trabajo. De código disponible, no OSI.

    imagen + chartBUSL-1.1precaución

Bases de datos y motores

11
  • Percona XtraDB Cluster Operatorpróximo

    Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery. Image SHIPPED 2026-09-27 (1.18.0, 1.19.1, 1.20.0; it is also the pods' init image). Chart HELD: in the kind gate the operator creates the cluster and its init containers complete, but the Percona 8.4.8 database pod starts mysqld with wsrep provider none and never becomes ready, and it does the same with upstream's init image and with the 8.0 database image. Percona's forum reports the same failure in kind and minikube on Linux; the chart waits for a gate on a non-kind cluster.

    imagen + chartApache-2.0
  • ArangoDBplanificado

    Base de datos multimodelo para documentos, grafos y clave-valor (Community Edition).

    imagen + chartBSL-1.1precaución
  • Liquibaseplanificado

    Database schema change and migration management. Relicensed: 5.x is under the Functional Source License 1.1 (source-available, Apache-2.0 two years after each release, competing use restricted); the last Apache-2.0 release is 4.33.0 and its line is no longer patched. Flyway (Apache-2.0) covers the same job.

    imagen + chartFSL-1.1precaución
  • MongoDB Community Operatorplanificado

    MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI). Held 2026-10-07: the community operator repo is archived; its successor mongodb/mongodb-kubernetes (1.13.0, Apache-2.0 for Community clusters) runs every member beside mongodb-agent, a closed-source binary its Dockerfile downloads prebuilt (agent 109.0.1.9310-1), which cannot be built or scanned.

    imagen + chartApache-2.0
  • SurrealDBplanificado

    Base de datos multimodelo. De código disponible, no OSI.

    imagen + chartBUSL-1.1precaución
  • Aerospikeexplorando

    Real-time key-value database; community edition is AGPL.

    imagen + chartAGPL-3.0agpl
  • Couchbaseexplorando

    Distributed document database. Source-available, not OSI.

    alt. limpia: CouchDB (Apache-2.0), already shipped.

    imagen + chartBSL-1.1precaución
  • JanusGraphexplorando

    Base de datos de grafos distribuida sobre backends de almacenamiento intercambiables.

    imagen + chartApache-2.0
  • KeyDBexplorando

    Fork multihilo de Redis; con licencia BSD y compatible con el protocolo de Redis.

    imagen + chartBSD-3-Clause
  • OrientDBexplorando

    Multi-model graph and document database.

    imagen + chartApache-2.0
  • Tiny RDMexplorando

    Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.

    imagen + chartGPL-3.0agpl

Almacenamiento y plataforma

5
  • Apache Ozoneplanificado

    Almacén de objetos distribuido escalable (S3 + HDFS).

    imagen + chartApache-2.0
  • Dokployplanificado

    PaaS autoalojable sobre Docker Swarm. Open-core: la mayor parte es Apache-2.0, las partes /proprietary son de código disponible (DSAL-1.0). No encaja en el catálogo endurecido: requiere root, el socket de Docker y un Swarm inicializado, por lo que no puede ejecutarse como nonroot ni en modo de solo lectura.

    alt. limpia: Coolify (Apache-2.0), already shipped.

    imagen + chartApache-2.0 + DSAL-1.0precaución
  • MinIOplanificado

    S3-compatible object storage; relicensed to AGPL-3.0.

    alt. limpia: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.

    imagen + chartAGPL-3.0agpl
  • SonarQubeplanificado

    Inspección continua de calidad y seguridad del código.

    imagen + chartLGPL-3.0
  • Rookexplorando

    Ceph storage orchestrator for Kubernetes (block/object/file).

    imagen + chartApache-2.0

Aplicaciones y productividad

13
  • Appsmithplanificado

    Constructor low-code de herramientas internas y paneles de administración respaldado por PostgreSQL y Redis.

    imagen + chartApache-2.0
  • Discourseplanificado

    Plataforma de debate y foros en Ruby respaldada por PostgreSQL y Redis.

    imagen + chartGPL-2.0-or-lateragpl
  • Gotenbergplanificado

    API sin estado de conversión de HTML y Office a PDF.

    imagen + chartMIT
  • Gristplanificado

    Self-hosted spreadsheet-database hybrid, an Airtable alternative. Sized 2026-09-25: a Node build plus the Python 3.11 formula sandbox (gVisor or Pyodide); larger than the controller queue ahead of it.

    imagen + chartApache-2.0
  • Moodleplanificado

    Sistema de gestión del aprendizaje en PHP respaldado por MySQL, MariaDB o PostgreSQL.

    imagen + chartGPL-3.0-or-lateragpl
  • Rocket.Chatplanificado

    Self-hosted team chat platform backed by MongoDB.

    imagen + chartMIT
  • SuiteCRMplanificado

    Aplicación de gestión de relaciones con clientes en PHP respaldada por MySQL o MariaDB.

    imagen + chartAGPL-3.0-onlyagpl
  • Backdrop CMSexplorando

    Drupal fork focused on simplicity, backed by MySQL.

    imagen + chartGPL-2.0-or-later
  • Chromiumexplorando

    Headless browser for rendering, scraping, and PDF export.

    imagen + chartBSD-3-Clause
  • Friendicaexplorando

    Federated social network server.

    imagen + chartAGPL-3.0agpl
  • Ploneexplorando

    Python enterprise CMS on Zope.

    imagen + chartGPL-2.0-or-later
  • Selenium Gridexplorando

    Distributed browser automation and testing grid.

    imagen + chartApache-2.0
  • XWikiexplorando

    Enterprise wiki and structured collaboration platform.

    imagen + chartLGPL-2.1

Medios y streaming

1
  • Jellyfinplanificado

    Servidor multimedia autoalojado para películas, música y TV en directo.

    imagen + chartGPL-2.0-onlyagpl

CI/CD y registro

4
  • Concourseexplorando

    Sistema de integración continua basado en pipelines respaldado por PostgreSQL.

    imagen + chartApache-2.0
  • GitLab CEexplorando

    Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.

    alt. limpia: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.

    imagen + chartMITprecaución
  • KubeVirtexplorando

    Run virtual machines as Kubernetes workloads.

    imagen + chartApache-2.0
  • OneDevexplorando

    Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option. Measured 2026-10-07 at 16.8.5 (47 findings): jackson-databind/core 2.22.2 in lib/ swap cleanly, but Hazelcast 5.7.0 (its newest release) relocates jackson 2.21.2 and tools.jackson 3.1.2 under com/hazelcast/shaded/, which needs a bytecode relocation rewrite or a Hazelcast release; logback 1.4.14 needs the 1.5 line; boot/ ships prebuilt Tanuki wrapper binaries.

    imagen + chartMIT

Aprendizaje automático

7
  • Langflowplanificado

    Constructor visual de aplicaciones de LLM y flujos de trabajo de agentes.

    imagen + chartMIT
  • Langfuseplanificado

    Plataforma de observabilidad y trazabilidad de LLM respaldada por PostgreSQL.

    imagen + chartMIT
  • Open WebUIplanificado

    Interfaz web autoalojada para chatear con LLM locales y remotos.

    imagen + chartOpen WebUI Licenseprecaución
  • AnythingLLMexplorando

    Self-hosted chat-with-your-documents LLM application.

    imagen + chartMIT
  • DataHubexplorando

    Metadata platform and data catalog.

    imagen + chartApache-2.0
  • Kubeflow Pipelinesexplorando

    ML pipeline orchestration on Kubernetes.

    imagen + chartApache-2.0
  • TensorFlow Servingexplorando

    High-performance serving system for TensorFlow models.

    imagen + chartApache-2.0

Observabilidad

5
  • Kibanaplanificado

    Visualización y paneles para Elasticsearch. La distribución por defecto es Elastic-2.0, no OSI.

    alt. limpia: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.

    imagen + chartElastic-2.0precaución
  • Logstashplanificado

    Pipeline de procesamiento de logs y eventos del lado del servidor. La distribución por defecto es Elastic-2.0, no OSI.

    alt. limpia: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.

    imagen + chartElastic-2.0precaución
  • Netdataplanificado

    Real-time per-second infrastructure monitoring agent.

    imagen + chartGPL-3.0agpl
  • Percona PMMplanificado

    Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved.

    imagen + chartAGPL-3.0
  • Cortexexplorando

    Horizontally scalable, multi-tenant Prometheus storage. Held 2026-10-05: four prometheus/prometheus CVEs (two HIGH) are fixed only in 0.311.3 (Prometheus 3.11.3), but Cortex 1.21.1 is on 0.308.1 and imports tsdb/errors, removed in Prometheus 3.10; Cortex master is on 0.309.1 and still imports it. Unblocks when a Cortex release moves to Prometheus 3.11.

    imagen + chartApache-2.0

Secretos e identidad

4
  • EJBCAplanificado

    Autoridad certificadora de PKI empresarial (Community Edition) respaldada por una base de datos relacional.

    imagen + chartLGPL-2.1-or-later
  • Teleportplanificado

    Plano de acceso que proporciona acceso basado en identidad a SSH, Kubernetes y bases de datos. La edición community es AGPL-3.0.

    imagen + chartAGPL-3.0-onlyagpl
  • SATOSAexplorando

    Proxy that translates between SAML and OIDC.

    imagen + chartApache-2.0
  • Secrets Store CSI Driverexplorando

    CSI driver that mounts secrets from external stores (Vault, cloud KMS) as volumes. Held 2026-09-25: a CSI node plugin runs privileged with bidirectional mount propagation on hostPath, so it waits on the node-agent exception tier with Linkerd CNI and Istio CNI.

    imagen + chartApache-2.0

Seguridad y cadena de suministro

7
  • Daggerplanificado

    Programmable CI/CD engine that runs pipelines in containers. Sized 2026-09-27: the CLI is plain Go, but the engine image bundles runc, CNI plugins and the Go, Python and TypeScript SDK runtimes as builtin content that upstream builds with Dagger itself. A multi-day build; not started.

    imagen + chartApache-2.0
  • Falcoplanificado

    Seguridad en tiempo de ejecución y detección de amenazas usando eventos del kernel y eBPF.

    imagen + chartApache-2.0
  • Kubescapeplanificado

    Kubernetes security, posture, and compliance scanner. Blocked 2026-09-25: 4.0.14 links github.com/docker/docker v28.5.2 (CVE-2026-33997, fixed only in moby 29.3.1, unreachable from the +incompatible module) through armosec/armoapi-go, whose newest v0.0.763 still requires it.

    imagen + chartApache-2.0
  • Kubescape Operatorplanificado

    In-cluster Kubescape components (operator, scanner, kubevuln) for continuous posture and vulnerability scanning. Distinct from the Kubescape CLI.

    imagen + chartApache-2.0
  • Wazuhplanificado

    Plataforma SIEM y XDR con componentes de manager, indexador y panel.

    imagen + chartGPL-2.0-onlyagpl
  • Kanikoexplorando

    Build container images inside Kubernetes without a daemon. Held 2026-09-25: Google archived it in June 2025 (continued as osscontainertools/kaniko 1.28 and chainguard-dev/kaniko 1.25), and the executor unpacks image layers over its own root filesystem, so it must run as root, against the nonroot rule. BuildKit rootless is the likelier fit.

    imagen + chartApache-2.0
  • TruffleHogexplorando

    Deep secret scanner across repos and filesystems.

    imagen + chartAGPL-3.0agpl

Stacks

7
  • ai-stackexplorando

    Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.

    imagen + chartApache-2.0
  • analytics-stackexplorando

    Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.

    imagen + chartApache-2.0
  • cost-stackexplorando

    OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.

    imagen + chartApache-2.0
  • mongodb-ha-stackexplorando

    Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.

    alt. limpia: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.

    imagen + chartSSPL-1.0precaución
  • orchestration-stackexplorando

    Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.

    imagen + chartApache-2.0
  • runtime-security-stackexplorando

    Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.

    imagen + chartApache-2.0
  • search-stackexplorando

    Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Held 2026-10-07: chart built and gated (OpenSearch document found through Dashboards), but it bundles the opensearch-dashboards image, which is held (see that entry).

    imagen + chartApache-2.0

Puertas de enlace y proxies

6
  • Apache ShenYuplanificado

    Java API gateway. shenyu-bootstrap + shenyu-admin; admin needs a database.

    imagen + chartApache-2.0
  • APISIX Dashboardplanificado

    Web UI for APISIX (Go API + Vue frontend). Confirm upstream is still maintained before building; the gateway ships without it.

    imagen + chartApache-2.0
  • Gravitee APIMplanificado

    Java + Angular, 3 components (gateway, management-api, management-ui), needs MongoDB or JDBC plus Elasticsearch. Heaviest gateway in the wave.

    imagen + chartApache-2.0
  • Higressplanificado

    Alibaba's Istio+Envoy-based gateway. Two components (higress-core, higress-console) and it inherits Istio/Envoy build weight.

    imagen + chartApache-2.0
  • Skipperplanificado

    Zalando's HTTP router. BLOCKING: GitHub reports NOASSERTION and the LICENSE fetch came back empty -- resolve the license before writing a recipe.

    imagen + chartUNVERIFIEDprecaución
  • Apache TomEEexplorando

    Tomcat plus the Jakarta EE stack.

    imagen + chartApache-2.0
bloqueada

Por qué se retienen algunas apps

QuenchWorks no publica nada que tenga un CVE corregible. Algunas apps compilan limpias pero aún no llegan a ese nivel: la propia app fija una dependencia por debajo de la versión que corrige un CVE conocido, así que parchearla rompería sus propias restricciones declaradas. Se marcan como bloqueadas: compiladas y probadas, retenidas (sin publicar) hasta que el upstream relaje la fijación o retroporte la corrección. Se publican en cuanto eso ocurre. Nada que ya esté en el catálogo tiene un CVE corregible conocido.

¿Quieres priorizar algo? Solicita una app y la ubicaremos en la hoja de ruta.

bloqueada

Probada y retenida: no alcanza 0 CVE corregibles