Skip to content
QuenchWorks

Roadmap

What is shipped, what is next

375 datastores and tools are hardened and shipping today. Below is what is on deck, OSI-clean options first. Every entry is built from source on Wolfi, scanned to zero fixable CVEs, signed, and pinned by digest before it moves to available.

375/471
80% shipped
37580%
Shipped
9420%
On the roadmap
20%
Blocked

Update queue

0 open

Newer upstream releases of apps already in the catalog, from the version check on. Each one ships only after its image passes the 0-CVE gate and its boot test, and its chart is re-pinned to the new digest.

AppFromToStatus
actions-runner2.337.02.338.0shipped
ansible14.4.014.5.0shipped
argocd3.3.14, 3.4.9, 3.5.33.3.15, 3.4.10, 3.5.4shipped
buildkite-agent4.2.04.2.1shipped
checkov3.3.233.3.25shipped
coroot1.27.01.27.1shipped
elasticsearch9.5.49.5.5shipped
ghost6.67.06.68.0shipped
gitea28.0.028.1.0shipped
grype0.120.00.120.1shipped
harbor2.15.22.15.3shipped

All seven images.

jaeger2.21.02.22.0shipped
kgateway2.3.9, 2.4.52.3.10, 2.4.6shipped

With kgateway-envoy.

livekit1.13.71.13.8shipped
mlflow3.16.13.17.0shipped
ollama0.35.10.40.0shipped
openfga1.21.01.22.0shipped
policy-reporter3.10.03.11.0shipped
prefect3.8.73.8.8shipped
scylladb2026.3.22026.3.3shipped
syft1.54.01.54.1shipped
vector0.58.00.59.0shipped
weaviate1.39.91.40.0shipped
wordpress6.9.9, 7.0.6, 7.1.26.9.10, 7.0.7, 7.1.3shipped
zot2.1.212.1.22shipped
clickhouse26.7.16.2, 26.9.5.226.7.23.7, 26.9.12.8held

Bespoke per-version maps; needs its own session.

coolify-app4.3.234.4.0held

4.4.0 replaces the realtime image with Reverb and coolify-terminal: a stack redesign.

grafana13.1.613.2.3held

The 13.1 recipe carries per-version source-build work; 13.2 needs its own session.

jellyfin12.112.2held

Blocked app.

metabase0.63.180.63.19held

New findings in 0.63.19.

odoo19.0.2026092919.0.20261007held

Nightly tarballs.

pnpm11.28.4, 12.9.111.28.5, 12.10.1held

Waits out the release cooldown (2026-10-20).

pulsar4.2.45.0.0held

New major: image first, chart after its migration notes.

renovate44.133.044.142.0held

Installed with npm 12: waits out the release cooldown.

documentdb0.117.01.0.RC1skipped

Release candidate.

meilisearch1.54.31.53.3skipped

Outside the build window.

Available now

375

AI gateway

2

Analytical

1

Apps & productivity

28

Base image

1

Build tool

7

CI

2

CI/CD & registry

27

Cache

7

Coordination

13

Coordination & mesh

18

Database

1

Databases & engines

12

Developer tools / IDE

1

Document

5

Gateway

26

Git

4

GitOps

3

Graph

1

Identity

12

Language runtime

13

Machine learning & AI

8

Media & streaming

3

Messaging

17

Metrics/Exporter

6

Object storage

5

Observability

32

PaaS

3

Registry

10

Relational

10

Runtime base

4

Search

8

Search & vector

1

Secrets

3

Secrets & identity

2

Security & supply chain

41

Storage & platform

17

Time series

4

Vector

1

Wide-column

2

Workflow

14

Held — built, not shipped

2

These build and test clean but can't reach 0 fixable CVEs yet — the app or its base pins a dependency below the version that fixes a known CVE, so we hold it rather than ship a vulnerable image. Each re-lists automatically the moment upstream ships the fix. Tapwhy blocked? for the exact pin.

Apps & productivity

1
  • Apache Supersetblocked

    Data exploration and business-intelligence dashboard platform backed by a metadata database and Redis. Measured 2026-09-26: 6.1.0 (and 6.0.0) have no advisories, 5.0 does. It pins pyarrow<19, whose wheel statically embeds OpenSSL 3.3.0 and libcurl 8.7.0 (Wolfi packages pyarrow 23 and newer only), and a loose PyPI resolve pulls a flask-caching that breaks its metastore cache. Needs a build from the tag's pinned requirements, a module float, and a pyarrow swap tested against result_set.py.

    Apps & productivityApache-2.0

Observability

1
  • OpenSearch Dashboardsblocked

    Visualization UI for OpenSearch. Measured 2026-09-26 at 3.8.0: the full bundle has 12 vulnerable npm packages, among them maplibre-gl 5.2.0 (CRITICAL, fixed only in 6.x) compiled into the maps, observability and anomaly-detection plugin bundles. The min distribution drops those plugins, leaving 7 patch-level fixes, but dompurify 3.4.11 is compiled into the Discover and chat UI bundles, so swapping node_modules would clear the scan and still ship the vulnerable code. Needs a from-source UI build (yarn build of OSD) to ship honestly. Re-measured 2026-10-07: an image that swaps node_modules scans 0 but still carries dompurify 3.4.11/3.4.12 in 8 browser bundles and maplibre-gl 5.2.0 in 3, so it is held. Upstream main has dompurify ^3.4.13 and maplibre-gl 6.4.1; Dashboards 3.9.0 (unreleased) is the next build to measure.

    ObservabilityApache-2.0

On the roadmap

94

Candidates, not commitments. next = strongest near-term picks;planned and exploring follow. Items marked caution are source-available (not OSI) and would ship only with a loud license note and the clean alternative called out. (Apps that build but can't hit 0 fixable CVEs yet are in Held, above.) Each card also shows how it will ship: image + chart for a deployable service, orimage only for a base/CLI/sidecar utility (like busybox).

Search & vector

1
  • Milvusplanned

    Scalable vector database for AI workloads. Measured 2026-09-30: releases ship only compose files and Wolfi has no package, so it is a from-source build: the C++ core through conan (about a hundred packages, often fetched as prebuilt binaries the scanner cannot see) plus a Rust component, a multi-hour build. Held until Wolfi packages it or a scanned from-source conan build is scoped.

    image + chartApache-2.0

Workflow & data

8
  • Apache Pinotplanned

    Real-time distributed OLAP datastore for low-latency analytics. Measured 2026-09-28: the 1.5.1 distribution carries 444 fixable findings (11 critical) in 31 packages, much of it netty 4.1.134 and jackson-databind 2.21.1 repeated across plugin jars. Measure again after the next release.

    image + chartApache-2.0
  • Apache Sparkplanned

    Unified batch and stream analytics engine. Measured 2026-09-24: the 4.2.0 distribution carries 99 findings, including Jetty 12.1.8 shaded into spark-core (fixed in 12.1.10), so it needs a from-source build. The Wolfi spark-4.0/4.1 packages were measured too (78 and 92 findings): Hive 2.3 jars, the YARN shuffle jar and shaded Jetty 11.0.26 remain, so the build must drop the hive and yarn profiles.

    image + chartApache-2.0
  • Camundaplanned

    Process automation and BPMN orchestration including the Zeebe engine. Checked 2026-09-27: the repository is under the Camunda License 1.0, not Apache-2.0.

    image + chartCamunda-License-1.0caution
  • Apache Camel Kexploring

    Kubernetes-native integration framework.

    image + chartApache-2.0
  • Apache Druidexploring

    Real-time analytics database for high-concurrency OLAP queries. Held 2026-09-26: the 37.0.0 distribution carries 137 findings. Two sit in the core lib/ and cannot be swapped: netty 3.10.6 (8 findings, end of life, fixes only exist in netty 4; Druid's HTTP client is built on it) and calcite-core 1.37.0 (the SQL planner, fixed in 1.42). Shipping needs Druid itself to move off both.

    image + chartApache-2.0
  • Apache Polarisexploring

    Open REST catalog for Apache Iceberg tables.

    image + chartApache-2.0
  • Cubeexploring

    Semantic layer and analytics API over your data.

    image + chartApache-2.0
  • Hyperledger Fabricexploring

    Permissioned enterprise blockchain platform.

    image + chartApache-2.0

Messaging & streaming

4
  • Apicurio Registryplanned

    API and schema registry for Kafka, Avro, and Protobuf. Measured 2026-09-25: the 3.3.3 app distribution carries 467 findings; 26 in-place jar swaps clear all but opentelemetry-api 1.57.0 (CVE-2026-45292, fixed only in 1.62.0), which adds packages the prebuilt Quarkus index cannot load. Needs a source build that regenerates the index.

    image + chartApache-2.0
  • Redpandaplanned

    Kafka-compatible streaming. Source-available, not OSI.

    clean alt: Kafka or Pulsar (Apache-2.0), both already shipped.

    image + chartBSL-1.1caution
  • Strimziplanned

    Kubernetes operator for running and managing Kafka. Sized 2026-09-25: two from-source images, the operator (a Maven multi-module build; the release ships only install YAML) and Strimzi's own Kafka image, whose run scripts and agents the operator drives; the QuenchWorks kafka image does not have that layout. Measured 2026-09-29: Wolfi packages Strimzi too (strimzi-kafka-operator with kafka-strimzi-compat), but at 1.0.0-r4 against upstream 1.2.0, and that stack scans at 849 fixable findings (59 critical, 353 high), including jackson-databind 2.21.2 and the JMX exporter; so it still needs the from-source build.

    image + chartApache-2.0
  • Apache Stormexploring

    Distributed real-time stream processing.

    image + chartApache-2.0

Coordination & mesh

11
  • Calicoplanned

    eBPF/iptables CNI for networking and network policy.

    image + chartApache-2.0
  • Cilium Envoyplanned

    Cilium's own patched Envoy; not reusable from our stock envoy image.

    image + chartApache-2.0
  • Consulplanned

    HashiCorp Consul. BUSL-1.1: source-available, NOT OSI. Recommendation is to skip -- the mesh slot is already covered by Kuma (shipped) plus Linkerd and Istio in this wave, all OSI-licensed. Revisit on explicit demand.

    clean alt: Kuma (Apache-2.0) -- already shipped; or Linkerd / Istio.

    image + chartBUSL-1.1caution
  • Consul Dataplaneplanned

    Envoy-based sidecar for Consul. MPL, so cleaner than the BUSL server.

    image + chartMPL-2.0
  • Consul K8s Control Planeplanned

    The operator that makes Consul work on Kubernetes.

    image + chartMPL-2.0
  • Istioplanned

    Service mesh built on Envoy. The control plane SHIPPED as istiod (1.29.7, 1.30.4, 1.31.0, with a chart); the wave is held on the data plane, Istio proxyv2, which has no melange-buildable path. Measured 2026-09-20.

    image + chartApache-2.0
  • Istio CNIplanned

    Privileged node agent; hostPath + privileged. Needs the node-agent exception tier.

    image + chartApache-2.0
  • Istio ztunnelplanned

    Rust node proxy for Istio ambient mode. Skip if we ship sidecar mode only.

    image + chartApache-2.0
  • Linkerd CNIplanned

    Privileged node agent (alternative to proxy-init). Needs the node-agent exception tier.

    image + chartApache-2.0
  • Linkerd Vizplanned

    Observability extension: metrics-api, tap, tap-injector, web. Ship only if dashboard parity is wanted.

    image + chartApache-2.0
  • Nomadplanned

    Workload scheduler. Source-available, not OSI.

    image + chartBUSL-1.1caution

Databases & engines

11
  • Percona XtraDB Cluster Operatornext

    Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery. Image SHIPPED 2026-09-27 (1.18.0, 1.19.1, 1.20.0; it is also the pods' init image). Chart HELD: in the kind gate the operator creates the cluster and its init containers complete, but the Percona 8.4.8 database pod starts mysqld with wsrep provider none and never becomes ready, and it does the same with upstream's init image and with the 8.0 database image. Percona's forum reports the same failure in kind and minikube on Linux; the chart waits for a gate on a non-kind cluster.

    image + chartApache-2.0
  • ArangoDBplanned

    Multi-model database for documents, graphs, and key-value. Checked 2026-09-27: the repository LICENSE is the Business Source License 1.1, not Apache-2.0.

    image + chartBSL-1.1caution
  • Liquibaseplanned

    Database schema change and migration management. Relicensed: 5.x is under the Functional Source License 1.1 (source-available, Apache-2.0 two years after each release, competing use restricted); the last Apache-2.0 release is 4.33.0 and its line is no longer patched. Flyway (Apache-2.0) covers the same job.

    image + chartFSL-1.1caution
  • MongoDB Community Operatorplanned

    MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI). Held 2026-10-07: the community operator repo is archived; its successor mongodb/mongodb-kubernetes (1.13.0, Apache-2.0 for Community clusters) runs every member beside mongodb-agent, a closed-source binary its Dockerfile downloads prebuilt (agent 109.0.1.9310-1), which cannot be built or scanned.

    image + chartApache-2.0
  • SurrealDBplanned

    Multi-model database. Source-available, not OSI.

    image + chartBUSL-1.1caution
  • Aerospikeexploring

    Real-time key-value database; community edition is AGPL.

    image + chartAGPL-3.0agpl
  • Couchbaseexploring

    Distributed document database. Source-available, not OSI.

    clean alt: CouchDB (Apache-2.0), already shipped.

    image + chartBSL-1.1caution
  • JanusGraphexploring

    Distributed graph database over pluggable storage backends. Measured 2026-09-26: the newest release (1.1.0, 2024-11) carries 57 vulnerable packages (4 CRITICAL, 35 HIGH) in its dist. The project is active but has not released since; shipping at 0 CVEs needs a from-source Maven build with dependency management across the tree.

    image + chartApache-2.0
  • KeyDBexploring

    Multi-threaded Redis fork; BSD-licensed and Redis-protocol compatible. Held 2026-09-25: upstream is dormant (last release 6.3.4 in October 2023, last push May 2024) on a Redis 6.2 base, so it misses the Lua and protocol fixes Redis and Valkey shipped since. Valkey covers the slot.

    image + chartBSD-3-Clause
  • OrientDBexploring

    Multi-model graph and document database.

    image + chartApache-2.0
  • Tiny RDMexploring

    Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.

    image + chartGPL-3.0agpl

Storage & platform

5
  • Apache Ozoneplanned

    Scalable distributed object store (S3 + HDFS). Measured 2026-09-28: the 2.2.1 distribution carries 143 fixable findings in 22 jars. Most swap on their own line (netty 4.1.137, jackson 2.21.5, log4j 2.26.1), but jetty-server 9.4 is fixed only in 12.1, spring-core 5.3.39 only in 7.0 and aircompressor 0.27 only in 2.x. Needs an upstream move off those lines.

    image + chartApache-2.0
  • Dokployplanned

    Self-hostable PaaS on Docker Swarm. Open-core: most is Apache-2.0, the /proprietary parts are source-available (DSAL-1.0). Not a fit for the hardened catalog: it requires root, the Docker socket, and an initialized Swarm, so it cannot run nonroot or read-only.

    clean alt: Coolify (Apache-2.0), already shipped.

    image + chartApache-2.0 + DSAL-1.0caution
  • MinIOplanned

    S3-compatible object storage; relicensed to AGPL-3.0.

    clean alt: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.

    image + chartAGPL-3.0agpl
  • SonarQubeplanned

    Continuous code-quality and security inspection. Measured 2026-09-28: the 26.9 Community distribution carries 72 findings (4 critical), most inside its bundled Elasticsearch 9.4.3 (x-pack modules, transport-netty4) and in fat jars (sonar-application, the scanner engine). Needs the embedded Elasticsearch rebuilt or swapped before it can gate clean.

    image + chartLGPL-3.0
  • Rookexploring

    Ceph storage orchestrator for Kubernetes (block/object/file).

    image + chartApache-2.0

Apps & productivity

13
  • Appsmithplanned

    Low-code internal-tools and admin-panel builder backed by PostgreSQL and Redis. Measured 2026-09-30 (v2.4.2, no release binaries, no Wolfi package): the upstream image is all-in-one under supervisor (Java server, React editor, Node RTS and MCP, Caddy, Redis, PostgreSQL and MongoDB). Appsmith has since removed PostgreSQL support (scripts/prepare_server_artifacts.sh builds only the MongoDB server), so the server needs MongoDB, which is SSPL. A clean image would run against an external MongoDB, or FerretDB/DocumentDB if Appsmith's use of transactions works there, which is unverified. Maven and yarn builds exceed the local gate, so it is gated in CI.

    image + chartApache-2.0
  • Discourseplanned

    Ruby discussion and forum platform backed by PostgreSQL and Redis. Measured 2026-09-29 at 2026.9.0: the Gemfile.lock and pnpm-lock.yaml scan clean and Wolfi has ruby-3.4, ImageMagick 7, pngquant and oxipng, but two native gems ship only prebuilt binaries the scanner cannot see into: libv8-node (V8 for mini_racer, which PrettyText needs; a source build is a multi-hour Node V8 compile per arch) and sass-embedded (a bundled dart-sass, needed at runtime for theme CSS; Wolfi has the Dart SDK, so that half is buildable). Held on the V8 build.

    image + chartGPL-2.0-or-lateragpl
  • Gotenbergplanned

    Stateless HTML and URL to PDF conversion API. Recipe committed 2026-09-26 (Chromium variant; Wolfi has no LibreOffice): everything gates clean except chromium CVE-2026-13032, fixed in 149.0.7827.200, which Wolfi has not published yet. Ships when it does.

    image + chartMIT
  • Gristplanned

    Self-hosted spreadsheet-database hybrid, an Airtable alternative. Sized 2026-09-25: a Node build plus the Python 3.11 formula sandbox (gVisor or Pyodide); larger than the controller queue ahead of it.

    image + chartApache-2.0
  • Moodleplanned

    PHP learning management system backed by MySQL, MariaDB, or PostgreSQL. Measured 2026-09-29 at 5.2.3: the PHP side is fixable (5.2 runs composer install at build, so guzzle, psr7, aws-sdk-php, php-jwt, slim and jmespath float like mediawiki), but the H5P editor ships a prebuilt CKEditor 5 43.0.0 bundle (CVE-2024-45613, CVE-2026-28343 fixed only in 47.6.0; lodash-es CVE-2026-4800 HIGH). The fix is a four-major rebuild of a custom H5P build nothing would test, so the image is held until Moodle updates that bundle.

    image + chartGPL-3.0-or-lateragpl
  • Rocket.Chatplanned

    Self-hosted team chat platform backed by MongoDB.

    image + chartMIT
  • SuiteCRMplanned

    PHP customer relationship management application backed by MySQL or MariaDB. Measured 2026-10-04 on 8.10.2: the shipped frontend is Angular 18 (203 yarn.lock findings, fixed only in Angular 19 and later) and api-platform/core v3.4.17 is fixed only in v4, so both need major ports upstream; guzzle and flysystem would float. Held until SuiteCRM moves to Angular 19+ and api-platform 4.

    image + chartAGPL-3.0-onlyagpl
  • Backdrop CMSexploring

    Drupal fork focused on simplicity, backed by MySQL.

    image + chartGPL-2.0-or-later
  • Chromiumexploring

    Headless browser for rendering, scraping, and PDF export.

    image + chartBSD-3-Clause
  • Friendicaexploring

    Federated social network server.

    image + chartAGPL-3.0agpl
  • Ploneexploring

    Python enterprise CMS on Zope.

    image + chartGPL-2.0-or-later
  • Selenium Gridexploring

    Distributed browser automation and testing grid.

    image + chartApache-2.0
  • XWikiexploring

    Enterprise wiki and structured collaboration platform.

    image + chartLGPL-2.1

Media & streaming

1
  • Jellyfinplanned

    Self-hosted media server for movies, music, and live TV. Built 2026-09-29 from Wolfi's jellyfin 12.1 apks and it gates clean (0 fixable CVEs, boot test passes), but it is held: libSkiaSharp.so, a prebuilt NuGet binary from a Debian 10 clang 13 build, statically links libjpeg-turbo 2.1.5.1 (behind several upstream security fixes), libpng and other image libraries the scanner cannot see. Needs Skia built against the system libraries. The recipe is committed as blocked.

    image + chartGPL-2.0-onlyagpl

CI/CD & registry

4
  • Concourseexploring

    Pipeline-based continuous integration system backed by PostgreSQL. Images shipped 2026-09-30 (web and worker, with the registry-image and time resource types bundled, plus concourse-git-resource). The worker runs root and privileged, which containerd needs. Chart held 2026-09-30: under kind on GitHub's Ubuntu 24.04 runners, task containers fail to mount /sys in their user namespace, while the same install runs tasks elsewhere; the release waits for that cause.

    image + chartApache-2.0
  • GitLab CEexploring

    Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.

    clean alt: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.

    image + chartMITcaution
  • KubeVirtexploring

    Run virtual machines as Kubernetes workloads.

    image + chartApache-2.0
  • OneDevexploring

    Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option. Measured 2026-10-07 at 16.8.5 (47 findings): jackson-databind/core 2.22.2 in lib/ swap cleanly, but Hazelcast 5.7.0 (its newest release) relocates jackson 2.21.2 and tools.jackson 3.1.2 under com/hazelcast/shaded/, which needs a bytecode relocation rewrite or a Hazelcast release; logback 1.4.14 needs the 1.5 line; boot/ ships prebuilt Tanuki wrapper binaries.

    image + chartMIT

Machine learning

7
  • Langflowplanned

    Visual builder for LLM applications and agent workflows. Measured 2026-09-28: 1.12.3 resolves to 457 packages (2.3 GB). The scanner reports only chromadb 1.5.9 (no fix), but the wheels carry what it cannot see: OpenSSL 3.5.1 (ibm_db.libs), OpenSSL 3.6.2 and libcurl 8.20.0 inside pyarrow, BoringSSL in grpcio and hf_xet, and 7 bundled .libs directories (numpy, scipy, pillow, cassandra-driver). Wolfi has py3.13 pyarrow, grpcio, numpy, tokenizers and orjson, but no onnxruntime, chromadb or ibm_db, so an honest 0-CVE build needs those built from source or dropped.

    image + chartMIT
  • Langfuseplanned

    LLM observability and tracing platform backed by PostgreSQL, ClickHouse, Redis and S3. Held 2026-09-27: the core is MIT, but ee/, web/src/ee and worker/src/ee are under the Langfuse Enterprise License, which forbids distributing them, and 80 core files import from those 120 files. An image needs a build with the ee paths removed and stubbed.

    image + chartMIT
  • Open WebUIplanned

    Self-hosted web UI for chatting with local and remote LLMs. Checked 2026-09-27: the license is BSD-3-Clause plus a branding clause (the Open WebUI branding may not be altered for deployments above 50 users without permission), so it is not OSI. 0.11.4 also pins sentence-transformers, transformers, onnxruntime and opencv.

    image + chartOpen WebUI Licensecaution
  • AnythingLLMexploring

    Self-hosted chat-with-your-documents LLM application.

    image + chartMIT
  • DataHubexploring

    Metadata platform and data catalog.

    image + chartApache-2.0
  • Kubeflow Pipelinesexploring

    ML pipeline orchestration on Kubernetes.

    image + chartApache-2.0
  • TensorFlow Servingexploring

    High-performance serving system for TensorFlow models.

    image + chartApache-2.0

Observability

5
  • Kibanaplanned

    Visualization and dashboards for Elasticsearch. Default distribution is Elastic-2.0, not OSI.

    clean alt: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.

    image + chartElastic-2.0caution
  • Logstashplanned

    Server-side log and event processing pipeline. Default distribution is Elastic-2.0, not OSI.

    clean alt: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.

    image + chartElastic-2.0caution
  • Netdataplanned

    Real-time per-second infrastructure monitoring agent.

    image + chartGPL-3.0agpl
  • Percona PMMplanned

    Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved.

    image + chartAGPL-3.0
  • Cortexexploring

    Horizontally scalable, multi-tenant Prometheus storage. Held 2026-10-05: four prometheus/prometheus CVEs (two HIGH) are fixed only in 0.311.3 (Prometheus 3.11.3), but Cortex 1.21.1 is on 0.308.1 and imports tsdb/errors, removed in Prometheus 3.10; Cortex master is on 0.309.1 and still imports it. Unblocks when a Cortex release moves to Prometheus 3.11.

    image + chartApache-2.0

Secrets & identity

4
  • EJBCAplanned

    Enterprise PKI certificate authority (Community Edition) backed by a relational database. Measured 2026-10-04 on r9.6.3 (source only, no release assets): 167 vendored jars in lib/ that Trivy identifies none of, so its scan is blind there; by filename bcprov 1.84 (CVE-2026-8763, fixed 1.85) and freemarker 2.3.34 (CVE-2026-84939, fixed 2.3.35) need swaps. Buildable with Gradle on our WildFly image; a multi-session job, not a hold.

    image + chartLGPL-2.1-or-later
  • Teleportplanned

    Access plane providing identity-based SSH, Kubernetes, and database access. Community edition is AGPL-3.0.

    image + chartAGPL-3.0-onlyagpl
  • SATOSAexploring

    Proxy that translates between SAML and OIDC.

    image + chartApache-2.0
  • Secrets Store CSI Driverexploring

    CSI driver that mounts secrets from external stores (Vault, cloud KMS) as volumes. Held 2026-09-25: a CSI node plugin runs privileged with bidirectional mount propagation on hostPath, so it waits on the node-agent exception tier with Linkerd CNI and Istio CNI.

    image + chartApache-2.0

Security & supply chain

7
  • Daggerplanned

    Programmable CI/CD engine that runs pipelines in containers. Sized 2026-09-27: the CLI is plain Go, but the engine image bundles runc, CNI plugins and the Go, Python and TypeScript SDK runtimes as builtin content that upstream builds with Dagger itself. A multi-day build; not started.

    image + chartApache-2.0
  • Falcoplanned

    Runtime security and threat detection using kernel and eBPF events. Measured 2026-09-28: the official 0.45.0 tarball bundles OpenSSL 3.1.4 (end of life) and zlib 1.3.1 statically; the public Wolfi falco-no-driver apk stops at 0.44.0-r0, whose container plugin (libcontainer.so, Go) scans at 57 findings. Needs a source build of Falco, falcosecurity/libs and the container plugin against system libraries.

    image + chartApache-2.0
  • Kubescapeplanned

    Kubernetes security, posture, and compliance scanner. Blocked 2026-09-25: 4.0.14 links github.com/docker/docker v28.5.2 (CVE-2026-33997, fixed only in moby 29.3.1, unreachable from the +incompatible module) through armosec/armoapi-go, whose newest v0.0.763 still requires it.

    image + chartApache-2.0
  • Kubescape Operatorplanned

    In-cluster Kubescape components (operator, scanner, kubevuln) for continuous posture and vulnerability scanning. Distinct from the Kubescape CLI.

    image + chartApache-2.0
  • Wazuhplanned

    SIEM and XDR platform with manager, indexer, and dashboard components.

    image + chartGPL-2.0-onlyagpl
  • Kanikoexploring

    Build container images inside Kubernetes without a daemon. Held 2026-09-25: Google archived it in June 2025 (continued as osscontainertools/kaniko 1.28 and chainguard-dev/kaniko 1.25), and the executor unpacks image layers over its own root filesystem, so it must run as root, against the nonroot rule. BuildKit rootless is the likelier fit.

    image + chartApache-2.0
  • TruffleHogexploring

    Deep secret scanner across repos and filesystems.

    image + chartAGPL-3.0agpl

Stacks

7
  • ai-stackexploring

    Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.

    image + chartApache-2.0
  • analytics-stackexploring

    Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.

    image + chartApache-2.0
  • cost-stackexploring

    OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.

    image + chartApache-2.0
  • mongodb-ha-stackexploring

    Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.

    clean alt: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.

    image + chartSSPL-1.0caution
  • orchestration-stackexploring

    Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.

    image + chartApache-2.0
  • runtime-security-stackexploring

    Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.

    image + chartApache-2.0
  • search-stackexploring

    Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Held 2026-10-07: chart built and gated (OpenSearch document found through Dashboards), but it bundles the opensearch-dashboards image, which is held (see that entry).

    image + chartApache-2.0

Gateways & proxies

6
  • Apache ShenYuplanned

    Java API gateway. shenyu-bootstrap + shenyu-admin; admin needs a database.

    image + chartApache-2.0
  • APISIX Dashboardplanned

    Web UI for APISIX (Go API + Vue frontend). Confirm upstream is still maintained before building; the gateway ships without it.

    image + chartApache-2.0
  • Gravitee APIMplanned

    Java + Angular, 3 components (gateway, management-api, management-ui), needs MongoDB or JDBC plus Elasticsearch. Heaviest gateway in the wave.

    image + chartApache-2.0
  • Higressplanned

    Alibaba's Istio+Envoy-based gateway. Two components (higress-core, higress-console) and it inherits Istio/Envoy build weight.

    image + chartApache-2.0
  • Skipperplanned

    Zalando's HTTP router. BLOCKING: GitHub reports NOASSERTION and the LICENSE fetch came back empty -- resolve the license before writing a recipe.

    image + chartUNVERIFIEDcaution
  • Apache TomEEexploring

    Tomcat plus the Jakarta EE stack.

    image + chartApache-2.0
blocked

Why some apps are held

QuenchWorks ships nothing that carries a fixable CVE. A few apps build cleanly but can't reach that bar yet: the app itself pins a dependency below the version that fixes a known CVE, so patching it would break the app's own declared constraints. Those are marked blocked: built and tested, held (not shipped) until upstream relaxes the pin or backports the fix. They go live the moment that lands. Nothing already in the catalog carries a known fixable CVE to get there faster.

Held in the image factory (4)

Each hold, as written in its recipe, with the date it was last re-measured.

  • gotenbergmeasured
    STATUS: BLOCKED 2026-09-26 on Wolfi's chromium. The only gate finding is
      chromium CVE-2026-13032 (CRITICAL, use after free in WebGL)
      installed 149.0.7827.53-r0, fixed in 149.0.7827.200-r0
    and Wolfi's live APKINDEX tops out at 149.0.7827.53-r0: the fix is not published.
    Everything else gates clean (gotenberg and pdfcpu from source, floated). Unblock
    when `chromium` >= 149.0.7827.200 is in the index: set BLOCKED=0, run the local
    gate, dispatch. Chromium ships CVE fixes often, so expect this app to wait on Wolfi
    again between releases.
    Re-measured 2026-09-30: Wolfi still tops out at chromium 149.0.7827.53-r0 on x86_64 and
    aarch64, so the fix is still unpublished.
    Re-measured 2026-10-01: unchanged, chromium 149.0.7827.53-r0 on both arches.
    Re-measured 2026-10-04: unchanged, chromium 149.0.7827.53-r0 on both arches, no other
    chromium package; gotenberg is still 8.37.0.
    Re-measured 2026-10-05: unchanged, chromium 149.0.7827.53-r0 on both arches.
    Re-measured 2026-10-07: unchanged, chromium 149.0.7827.53-r0 on both arches; gotenberg 8.37.0.
  • jellyfinmeasured
    STATUS: BLOCKED 2026-09-29 on SkiaSharp's prebuilt native library. Everything gates
    clean (0 fixable CVEs, and the boot test passes: health, version 12.1.0, first-run
    wizard, login, ffmpeg), but /usr/lib/jellyfin/libSkiaSharp.so is a 10 MB binary from
    the SkiaSharp NuGet package, built on Debian 10 with clang 13, that statically links
    its own image libraries. It embeds libjpeg-turbo 2.1.5.1 (libjpeg-turbo has shipped
    security fixes since, among them CVE-2026-75466 in 3.2.1) and libpng 1.6.58, plus
    freetype, harfbuzz, webp and zlib at versions it does not print. The scanner cannot
    see any of it, and this catalog does not ship code that hides from its own gate
    (the same class as the wheel-bundled OpenSSL found on 2026-09-28). Unblock by
    building Skia against the system libraries, or by an upstream Jellyfin that does.
    Wolfi's jellyfin apk carries the same NuGet blob.
    RE-MEASURED 2026-09-30: unchanged. Wolfi has no Skia package and jellyfin is still
    12.1-r0; upstream's latest is v12.1.
    RE-MEASURED 2026-10-01: unchanged (no Skia apk, jellyfin 12.1-r0, upstream v12.1).
    RE-MEASURED 2026-10-04: unchanged (no Skia apk, jellyfin 12.1-r0, upstream v12.1).
    RE-MEASURED 2026-10-05: unchanged (no Skia apk, jellyfin 12.1-r0 on both arches).
    RE-MEASURED 2026-10-07: jellyfin 12.2 is out (Wolfi 12.2-r0, upstream v12.2) and its apk
    still ships the same libSkiaSharp.so (libjpeg-turbo 2.1.5.1, libpng 1.6.58); no Skia apk.
    jellyfin: Jellyfin (GPL-2.0), the self-hosted media server, from Wolfi's pinned jellyfin
    and jellyfin-web apks (FROM_SOURCE=0), which build it from source on Wolfi's .NET runtime
    and system ffmpeg. Upstream ships the same version (12.1, 2026-09-15); the checker
    tracks Wolfi. NEWEST LINE ONLY: Wolfi's index still lists 10.11.x revisions, and 12.x
    is the line upstream maintains.
  • opensearch-dashboardsmeasured
    STATUS 2026-10-07: BLOCKED. The node_modules swaps below clear the scanner but not the
    code that runs: the browser bundles under */target/public are compiled at upstream's
    build and still carry dompurify 3.4.11/3.4.12 (8 bundles: data, discover, explore, chat,
    vis_type_table, agent_traces, reportsDashboards, investigationDashboards) and maplibre-gl
    5.2.0 (CVE-2026-85061, CRITICAL; customImportMapDashboards, observabilityDashboards,
    anomalyDetectionDashboards). Trivy reads package.json only, so the image scanned 0 while
    shipping that code. The 2026-09-26 roadmap measurement had already said so. Unblock: a
    from-source build of OSD 3.8.0 and its plugins (yarn build with the fixed versions
    resolved, bundles rebuilt), or an upstream release whose bundles carry the fixes. Check:
    grep the built image's target/public bundles for each library's version string.
    Upstream main (2026-10-07): core dompurify ^3.4.13 (yarn.lock 3.4.13, still below the 3.4.16
    LOW fix), dashboards-maps maplibre-gl 6.4.1. Dashboards 3.9.0 is unreleased (OpenSearch 3.9.0
    shipped 2026-09-29), so its release is the first upstream build to re-measure.
  • sparkmeasured
    STATUS: BLOCKED 2026-09-24. Measured locally (PUSH=0, x86_64, comprehensive Trivy):
      4.1.2-r3: 92 OS-section + 233 jar findings; 4.0.2-r13: 78 + 221.
    The Wolfi apks are built from source but still ship, per 4.1.2:
      * Hive 2.3.10 jars: hive-exec (fixed only in 4.0.1), derby 10.16.1.1 (CRITICAL,
        CVE-2022-46337), libthrift 0.16.0. Spark's built-in Hive has no fixed 2.3 line;
        the fix is building WITHOUT -Phive -Phive-thriftserver.
      * spark-4.1.2-yarn-shuffle.jar (43 findings, shaded): YARN NodeManager only; build
        WITHOUT -Pyarn.
      * Jetty 11.0.26 shaded into spark-core (CVE-2026-2332, fixed 11.0.29) and
        hadoop-client-runtime 3.4.2 (shaded): need -Djetty.version / a Hadoop bump at
        build time.
      * spark-connect-client-jvm (20, shaded), netty 4.2.13 (fix 4.2.16), jackson 2.21.1
        (fix 2.21.5), log4j-api 2.25.4, lz4-java 1.10.1, jline 3.29.0, nimbus-jose-jwt.
    RE-MEASURED 2026-09-30: unchanged. Wolfi still ships only 4.0.2-r13 and 4.1.2-r3; upstream
    now has 4.1.3 and 4.2.0. The Maven build runs far past the 600 s local gate, so the
    from-source recipe is gated in CI, not locally.
    RE-MEASURED 2026-10-01: unchanged (Wolfi spark-4.1 tops at 4.1.2-r3, no spark-4.2).
    RE-MEASURED 2026-10-04: unchanged (Wolfi spark-4.0 4.0.2-r13, spark-4.1 4.1.2-r3, no spark-4.2;
    upstream 4.1.3 and 4.2.0). The from-source Maven build below is still the way out.
    RE-MEASURED 2026-10-05: unchanged (4.0.2-r13, 4.1.2-r3, no spark-4.2, both arches).
    RE-MEASURED 2026-10-07: unchanged (4.0.2-r13, 4.1.2-r3, no spark-4.2, both arches); upstream
    has 4.2.1-rc1 and 4.3.0-rc1 tagged.
    Next step: a melange from-source Maven build (make-distribution.sh) with those
    profiles dropped and the versions floated, gated per line. This apko recipe stays
    as the image contract (entrypoint, SPARK_HOME, work-dir) the source build reuses.

Want something prioritized? Request an app and we will slot it into the roadmap.

blocked

Tested and held: cannot reach 0 fixable CVEs