{
  "apiVersion": "v1",
  "resource": "images",
  "total": 195,
  "data": [
    {
      "slug": "adminer",
      "name": "adminer",
      "category": "Apps & productivity",
      "summary": "vrana's single-file PHP database manager, a web UI for MySQL/MariaDB, PostgreSQL, and SQLite, served by a hardened PHP runtime. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.5.1, 5.4.4, 5.3.0",
      "versions": [
        {
          "version": "5.5.1",
          "size": "15.6 MB",
          "published": "2026-07-22T11:26:16Z",
          "digest": "sha256:c04641391a4020a55e83bfd44ee32ef68463ffc8905c33c3200b4ce4d0d8fdd3"
        },
        {
          "version": "5.4.4",
          "size": "15.6 MB",
          "published": "2026-07-22T11:26:11Z",
          "digest": "sha256:7d1f03de987addb467acad816b420a4f37f5fda2c29d09bb92f47a2e53880f5c"
        },
        {
          "version": "5.3.0",
          "size": "15.6 MB",
          "published": "2026-07-22T11:26:10Z",
          "digest": "sha256:68c345372078a7325e75d60ca5364f9c202683fa49eef93aebec2baf70ac26f5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.adminer.org",
      "source": "https://github.com/vrana/adminer",
      "image": "ghcr.io/quenchworks/images/adminer",
      "security": {
        "image": "ghcr.io/quenchworks/images/adminer",
        "version": "5.5.1",
        "tag": "ghcr.io/quenchworks/images/adminer:5.5.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.5.1",
            "tag": "ghcr.io/quenchworks/images/adminer:5.5.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.4.4",
            "tag": "ghcr.io/quenchworks/images/adminer:5.4.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "5.3.0",
            "tag": "ghcr.io/quenchworks/images/adminer:5.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "airflow",
      "name": "airflow",
      "category": "Workflow",
      "summary": "Apache Airflow, the programmatic workflow orchestration platform for authoring, scheduling, and monitoring DAGs. Built clean-room from source as a Python venv on Wolfi (python-3.12, official constraints), nonroot on a hardened read-only-rootfs base. Ships the 3.2 line (older lines carry unfixed CVEs in Airflow itself). Runs api-server + scheduler + dag-processor + triggerer (and Celery workers) from one image; needs PostgreSQL (and Redis for CeleryExecutor), provided by the chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.3.0, 3.2.2",
      "versions": [
        {
          "version": "3.3.0",
          "size": "113.6 MB",
          "published": "2026-07-28T06:16:52Z",
          "digest": "sha256:8142a61a094858e3c063c6c0d8c64f8fb60c41603b0684d568fe5104dc071aad"
        },
        {
          "version": "3.2.2",
          "size": "111.8 MB",
          "published": "2026-07-28T06:16:14Z",
          "digest": "sha256:4e6e24c4d061ac3b50be6c673221156b60b26dad14f6e7df5045986c9da2971b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://airflow.apache.org",
      "source": "https://github.com/apache/airflow",
      "image": "ghcr.io/quenchworks/images/airflow",
      "security": {
        "image": "ghcr.io/quenchworks/images/airflow",
        "version": "3.3.0",
        "tag": "ghcr.io/quenchworks/images/airflow:3.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.3.0",
            "tag": "ghcr.io/quenchworks/images/airflow:3.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.2.2",
            "tag": "ghcr.io/quenchworks/images/airflow:3.2.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "alertmanager",
      "name": "Alertmanager",
      "category": "Observability",
      "summary": "Companion to Prometheus that routes, groups, deduplicates, and silences alerts and dispatches them to email, Slack, PagerDuty, and more.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.33.1",
      "versions": [
        {
          "version": "0.33.1",
          "size": "24.2 MB",
          "published": "2026-07-22T08:26:58Z",
          "digest": "sha256:f9f5f7260be1d324024cf782f1f5e5cb465a942a70896e5b142197e1988df651"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/alertmanager",
      "source": "https://github.com/prometheus/alertmanager",
      "image": "ghcr.io/quenchworks/images/alertmanager",
      "security": {
        "image": "ghcr.io/quenchworks/images/alertmanager",
        "version": "0.33.1",
        "tag": "ghcr.io/quenchworks/images/alertmanager:0.33.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/alertmanager",
              "usr/bin/amtool"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.33.1",
            "tag": "ghcr.io/quenchworks/images/alertmanager:0.33.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/alertmanager",
                  "usr/bin/amtool"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ansible",
      "name": "ansible",
      "category": "CI/CD & registry",
      "summary": "Ansible — agentless IT automation and configuration management (the community `ansible` package plus ansible-core and curated collections) with ssh/git/rsync/sshpass tooling, ready to run playbooks. Built from source into a venv on a hardened nonroot Wolfi base. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0+",
      "licenseClean": "agpl",
      "version": "14.1.0, 14.2.0",
      "versions": [
        {
          "version": "14.1.0",
          "size": "126.6 MB",
          "published": "2026-07-26T12:19:26Z",
          "digest": "sha256:1c27197ae13e6c9f7391a263ebba7846646c70c9591dd8a5ad8107aeb4f4402c"
        },
        {
          "version": "14.2.0",
          "size": "127.0 MB",
          "published": "2026-07-26T12:19:09Z",
          "digest": "sha256:0a24f0269b8691d6679b4f976bdc376babebc160e1da02b2301603e797fda911"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.ansible.com",
      "source": "https://github.com/ansible/ansible",
      "image": "ghcr.io/quenchworks/images/ansible",
      "security": {
        "image": "ghcr.io/quenchworks/images/ansible",
        "version": "14.2.0",
        "tag": "ghcr.io/quenchworks/images/ansible:14.2.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "14.2.0",
            "tag": "ghcr.io/quenchworks/images/ansible:14.2.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "14.1.0",
            "tag": "ghcr.io/quenchworks/images/ansible:14.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "argo-workflows",
      "name": "argo-workflows",
      "category": "Workflow",
      "summary": "Kubernetes-native workflow engine for orchestrating parallel jobs as DAGs. Ships the workflow-controller and the argo CLI/API server with an embedded React UI, built from source on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.7.15",
      "versions": [
        {
          "version": "3.7.15",
          "size": "64.4 MB",
          "published": "2026-07-22T06:42:59Z",
          "digest": "sha256:d4f98e5766509fe5701ae37adb58b29664ead214cac2d6bbcc2363f7a6d2ebb8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://argoproj.github.io/workflows",
      "source": "https://github.com/argoproj/argo-workflows",
      "image": "ghcr.io/quenchworks/images/argo-workflows",
      "security": {
        "image": "ghcr.io/quenchworks/images/argo-workflows",
        "version": "3.7.15",
        "tag": "ghcr.io/quenchworks/images/argo-workflows:3.7.15",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/argo",
              "usr/bin/workflow-controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.15",
            "tag": "ghcr.io/quenchworks/images/argo-workflows:3.7.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/argo",
                  "usr/bin/workflow-controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "aspnet",
      "name": "aspnet",
      "category": "Runtime base",
      "summary": "Hardened ASP.NET Core runtime for web apps and APIs, no SDK. Build on the dotnet image, then run here. Lines 8/9/10.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "9.0.119, 8.0.127, 10.0.110",
      "versions": [
        {
          "version": "9.0.119",
          "size": "71.0 MB",
          "published": "2026-07-21T08:29:59Z",
          "digest": "sha256:11c7c102a26ba0de5f8035dc713e4494a167548ab3c582d8c5da63b070ec6640"
        },
        {
          "version": "8.0.127",
          "size": "68.2 MB",
          "published": "2026-07-15T11:18:11Z",
          "digest": "sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061"
        },
        {
          "version": "10.0.110",
          "size": "72.2 MB",
          "published": "2026-07-15T11:15:56Z",
          "digest": "sha256:54c8dee542ec87520f63d9500ed5ce9332ace84d6b359e84c0d51a664c5047a3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dotnet/runtime",
      "source": "https://github.com/dotnet/runtime",
      "image": "ghcr.io/quenchworks/images/aspnet",
      "security": {
        "image": "ghcr.io/quenchworks/images/aspnet",
        "version": "10.0.110",
        "tag": "ghcr.io/quenchworks/images/aspnet:10.0.110",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "10.0.110",
            "tag": "ghcr.io/quenchworks/images/aspnet:10.0.110",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.0.119",
            "tag": "ghcr.io/quenchworks/images/aspnet:9.0.119",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.127",
            "tag": "ghcr.io/quenchworks/images/aspnet:8.0.127",
            "critical": 3,
            "high": 9,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 12,
            "fixable": 12,
            "grade": "F",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "aspnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/aspnet@sha256:dc69dea5dc1c4f708b59a24f064ed1895e82004857533416591eabe59f819061 (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "atlantis",
      "name": "Atlantis",
      "category": "GitOps",
      "summary": "Terraform pull-request automation that runs plan on PRs and apply from PR comments, enforcing reviewed, Git-driven infrastructure changes with state locking.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.46.0",
      "versions": [
        {
          "version": "0.46.0",
          "size": "74.5 MB",
          "published": "2026-07-22T06:42:12Z",
          "digest": "sha256:769481554211806644df3e931c7021faa9d226a45aff333dd857b5f464936e0e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/runatlantis/atlantis",
      "source": "https://github.com/runatlantis/atlantis",
      "image": "ghcr.io/quenchworks/images/atlantis",
      "security": {
        "image": "ghcr.io/quenchworks/images/atlantis",
        "version": "0.46.0",
        "tag": "ghcr.io/quenchworks/images/atlantis:0.46.0",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 3,
        "fixable": 0,
        "grade": "D",
        "score": 86,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/tofu"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/atlantis",
              "usr/bin/tofu"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.46.0",
            "tag": "ghcr.io/quenchworks/images/atlantis:0.46.0",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 3,
            "fixable": 0,
            "grade": "D",
            "score": 86,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/tofu"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/atlantis",
                  "usr/bin/tofu"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "authelia",
      "name": "authelia",
      "category": "Identity",
      "summary": "Open-source authentication and authorization server providing single sign-on and two-factor authentication via a web portal, designed as a companion for reverse proxies. Packaged from Authelia's official prebuilt binary; needs a config plus a SQLite or PostgreSQL storage backend.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.39.20",
      "versions": [
        {
          "version": "4.39.20",
          "size": "21.7 MB",
          "published": "2026-07-26T12:18:52Z",
          "digest": "sha256:e9e9a5b5edcd91838d31ddc85df9a27e5e44c6be7371d45930c04437028cda96"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.authelia.com",
      "source": "https://github.com/authelia/authelia",
      "image": "ghcr.io/quenchworks/images/authelia",
      "security": {
        "image": "ghcr.io/quenchworks/images/authelia",
        "version": "4.39.20",
        "tag": "ghcr.io/quenchworks/images/authelia:4.39.20",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/authelia"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.39.20",
            "tag": "ghcr.io/quenchworks/images/authelia:4.39.20",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/authelia"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "authentik",
      "name": "authentik",
      "category": "Secrets & identity",
      "summary": "Self-hosted identity provider (OIDC, SAML, LDAP, SCIM) with flows, policies, and application/provider management. Built clean-room from source on Wolfi as a four-language image (nodejs web UI, Go server/proxy, Rust worker, Python/Django core via uv) on a hardened nonroot base; FIPS mode is not forced and the license-gated MaxMind GeoIP download is omitted. Needs PostgreSQL and Redis at runtime, provided by the chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2026.5.6",
      "versions": [
        {
          "version": "2026.5.6",
          "size": "229.7 MB",
          "published": "2026-07-28T06:29:36Z",
          "digest": "sha256:ae674559d1ed7cc9820d5128c914d5647f36effe3f3fed632e886946fcf5f634"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://goauthentik.io",
      "source": "https://github.com/goauthentik/authentik",
      "image": "ghcr.io/quenchworks/images/authentik",
      "security": {
        "image": "ghcr.io/quenchworks/images/authentik",
        "version": "2026.5.6",
        "tag": "ghcr.io/quenchworks/images/authentik:2026.5.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 0,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 99,
        "cves": [
          {
            "id": "CVE-2026-44405",
            "severity": "LOW",
            "pkg": "paramiko",
            "installed": "4.0.0",
            "fixed": null,
            "title": "paramiko: Paramiko: Data integrity could be compromised due to SHA-1 algorithm use",
            "url": "https://avd.aquasec.com/nvd/cve-2026-44405",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "2026.5.6",
            "tag": "ghcr.io/quenchworks/images/authentik:2026.5.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 0,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 99,
            "cves": [
              {
                "id": "CVE-2026-44405",
                "severity": "LOW",
                "pkg": "paramiko",
                "installed": "4.0.0",
                "fixed": null,
                "title": "paramiko: Paramiko: Data integrity could be compromised due to SHA-1 algorithm use",
                "url": "https://avd.aquasec.com/nvd/cve-2026-44405",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "blackbox-exporter",
      "name": "blackbox-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter that probes endpoints externally over HTTP, HTTPS, TCP, DNS, and ICMP for black-box uptime and latency monitoring.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.28.0",
      "versions": [
        {
          "version": "0.28.0",
          "size": "8.9 MB",
          "published": "2026-07-26T12:17:48Z",
          "digest": "sha256:f10c7ea6a9e66d4657f4539f9d2f235c6b538cc20ad3f443a76903970c228cf3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/blackbox_exporter",
      "source": "https://github.com/prometheus/blackbox_exporter",
      "image": "ghcr.io/quenchworks/images/blackbox-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/blackbox-exporter",
        "version": "0.28.0",
        "tag": "ghcr.io/quenchworks/images/blackbox-exporter:0.28.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/blackbox_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.28.0",
            "tag": "ghcr.io/quenchworks/images/blackbox-exporter:0.28.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/blackbox_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "buildkite-agent",
      "name": "buildkite-agent",
      "category": "CI/CD & registry",
      "summary": "The Buildkite CI build-runner agent that executes pipeline jobs on your own infrastructure. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "3.133.1, 3.134.0, 3.135.0",
      "versions": [
        {
          "version": "3.133.1",
          "size": "16.4 MB",
          "published": "2026-07-30T08:06:48Z",
          "digest": "sha256:3e3213c7eccfd2d57ae83025aa0d0e437a437a4c7cfbfb092402298ff545fb48"
        },
        {
          "version": "3.134.0",
          "size": "16.5 MB",
          "published": "2026-07-30T08:05:15Z",
          "digest": "sha256:7d24f62285c4d53c997bae1a7bbabe34c4137ebcaafd44c622ae9925e152ecb0"
        },
        {
          "version": "3.135.0",
          "size": "16.6 MB",
          "published": "2026-07-30T08:02:44Z",
          "digest": "sha256:6b538fde72550f107287d0ad23887697904fea0eed1c6ce052bc38edb0af0cbf"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://buildkite.com/docs/agent",
      "source": "https://github.com/buildkite/agent",
      "image": "ghcr.io/quenchworks/images/buildkite-agent",
      "security": {
        "image": "ghcr.io/quenchworks/images/buildkite-agent",
        "version": "3.134.0",
        "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.134.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/buildkite-agent"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.134.0",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.134.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          },
          {
            "version": "3.133.1",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.133.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          },
          {
            "version": "3.133.0",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.133.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          },
          {
            "version": "3.132.0",
            "tag": "ghcr.io/quenchworks/images/buildkite-agent:3.132.0",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "D",
            "score": 83,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/buildkite-agent"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "bun",
      "name": "bun",
      "category": "Language runtime",
      "summary": "Hardened Bun runtime and toolkit (runtime, bundler, package manager) for JavaScript and TypeScript. Latest stable (1).",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.3.13, 1.3.14, 1.3.11",
      "versions": [
        {
          "version": "1.3.13",
          "size": "42.3 MB",
          "published": "2026-07-04T10:49:28Z",
          "digest": "sha256:7d1e4366c4d4fffb65e8dfeb56e9e66ad370bb3662832d3459b5e1f0c4cdb413"
        },
        {
          "version": "1.3.14",
          "size": "38.1 MB",
          "published": "2026-07-04T10:48:45Z",
          "digest": "sha256:d1d2adb44bd9b77afb822fc397dd961633ac93cfbd775eb6b350cfbe894dd8e9"
        },
        {
          "version": "1.3.11",
          "size": "41.4 MB",
          "published": "2026-07-04T10:42:12Z",
          "digest": "sha256:8acfa03af5cbc9e5f6c738b178473e2a7af8f446515a580aef9683d674a0e3e7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/oven-sh/bun",
      "source": "https://github.com/oven-sh/bun",
      "image": "ghcr.io/quenchworks/images/bun",
      "security": {
        "image": "ghcr.io/quenchworks/images/bun",
        "version": "1.3.14",
        "tag": "ghcr.io/quenchworks/images/bun:1.3.14",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.3.14",
            "tag": "ghcr.io/quenchworks/images/bun:1.3.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.3.13",
            "tag": "ghcr.io/quenchworks/images/bun:1.3.13",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.3.11",
            "tag": "ghcr.io/quenchworks/images/bun:1.3.11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "busybox",
      "name": "BusyBox",
      "category": "Base image",
      "summary": "Hardened minimal base/toolbox image bundling common Unix utilities in one binary. Image only, no chart.",
      "tier": "low",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "1.38.0, 1.36.1, 1.37.0",
      "versions": [
        {
          "version": "1.38.0",
          "size": "4.1 MB",
          "published": "2026-07-04T11:34:34Z",
          "digest": "sha256:379b162cd4794ee14c63fec0cc501b855b804f33f824c4e46ced6183f644adfe"
        },
        {
          "version": "1.36.1",
          "size": "4.1 MB",
          "published": "2026-07-04T11:34:25Z",
          "digest": "sha256:b5d7d24c25561436a9285cbd209ecd6f2a6ad6ad7392267fe001e48f2651f8ea"
        },
        {
          "version": "1.37.0",
          "size": "4.1 MB",
          "published": "2026-07-04T11:34:18Z",
          "digest": "sha256:a0d34d7f510c4122f7e8a237bf8e186538a4b6752296c2f7e519451987b541e4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://busybox.net",
      "source": "https://busybox.net",
      "image": "ghcr.io/quenchworks/images/busybox",
      "security": {
        "image": "ghcr.io/quenchworks/images/busybox",
        "version": "1.38.0",
        "tag": "ghcr.io/quenchworks/images/busybox:1.38.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.38.0",
            "tag": "ghcr.io/quenchworks/images/busybox:1.38.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.37.0",
            "tag": "ghcr.io/quenchworks/images/busybox:1.37.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.36.1",
            "tag": "ghcr.io/quenchworks/images/busybox:1.36.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "caddy",
      "name": "Caddy",
      "category": "Gateway",
      "summary": "Web server and reverse proxy with fully automatic HTTPS via Let's Encrypt and a simple Caddyfile config.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.11.4",
      "versions": [
        {
          "version": "2.11.4",
          "size": "22.8 MB",
          "published": "2026-07-26T12:19:01Z",
          "digest": "sha256:916aca2000f2bc50c2fa01c4e30f3f44906fb339e159cb30e2d2611cf60c0303"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/caddyserver/caddy",
      "source": "https://github.com/caddyserver/caddy",
      "image": "ghcr.io/quenchworks/images/caddy",
      "security": {
        "image": "ghcr.io/quenchworks/images/caddy",
        "version": "2.11.4",
        "tag": "ghcr.io/quenchworks/images/caddy:2.11.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/caddy"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.11.4",
            "tag": "ghcr.io/quenchworks/images/caddy:2.11.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/caddy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cadence",
      "name": "cadence",
      "category": "Workflow",
      "summary": "Fault-tolerant, stateful workflow orchestration engine by Uber. Ships the cadence server and CLI as static Go binaries on a hardened nonroot Wolfi base; Cassandra or a SQL store is the operator's concern.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.4.1",
      "versions": [
        {
          "version": "1.4.1",
          "size": "58.0 MB",
          "published": "2026-07-22T08:34:10Z",
          "digest": "sha256:d58de1ef90e3ae2f79977d1cf800c29a96de67f2340d17b438ecd7589ac7b21f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cadenceworkflow.io",
      "source": "https://github.com/uber/cadence",
      "image": "ghcr.io/quenchworks/images/cadence",
      "security": {
        "image": "ghcr.io/quenchworks/images/cadence",
        "version": "1.4.1",
        "tag": "ghcr.io/quenchworks/images/cadence:1.4.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cadence",
              "usr/bin/cadence-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.4.1",
            "tag": "ghcr.io/quenchworks/images/cadence:1.4.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cadence",
                  "usr/bin/cadence-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cadvisor",
      "name": "cadvisor",
      "category": "Observability",
      "summary": "Analyzes resource usage and performance characteristics of running containers. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.60.5",
      "versions": [
        {
          "version": "0.60.5",
          "size": "10.2 MB",
          "published": "2026-07-22T08:26:00Z",
          "digest": "sha256:b4cb28bd96e0215b5abfc9e5868de27f6449eacd830e179bdbe45f1453f11eb0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/google/cadvisor",
      "source": "https://github.com/google/cadvisor",
      "image": "ghcr.io/quenchworks/images/cadvisor",
      "security": {
        "image": "ghcr.io/quenchworks/images/cadvisor",
        "version": "0.60.5",
        "tag": "ghcr.io/quenchworks/images/cadvisor:0.60.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cadvisor"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.60.5",
            "tag": "ghcr.io/quenchworks/images/cadvisor:0.60.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cadvisor"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cassandra",
      "name": "Cassandra",
      "category": "Wide-column",
      "summary": "Distributed wide-column NoSQL store built for linear horizontal scale and high availability with no single point of failure, tuned for heavy writes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.0.8",
      "versions": [
        {
          "version": "5.0.8",
          "size": "140.2 MB",
          "published": "2026-07-28T06:16:43Z",
          "digest": "sha256:5cdec9fcc9ecab75add9790da63ee05463184d0f13416fea9e847ed95d4bbcb2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/cassandra",
      "source": "https://downloads.apache.org/cassandra/5.0.8/apache-cassandra-5.0.8-bin.tar.gz",
      "image": "ghcr.io/quenchworks/images/cassandra",
      "security": {
        "image": "ghcr.io/quenchworks/images/cassandra",
        "version": "5.0.8",
        "tag": "ghcr.io/quenchworks/images/cassandra:5.0.8",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.0.8",
            "tag": "ghcr.io/quenchworks/images/cassandra:5.0.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "centrifugo",
      "name": "centrifugo",
      "category": "Messaging",
      "summary": "Scalable real-time messaging server (WebSocket, SSE, GRPC) with channels, presence, and JWT auth. Built from source as a static Go binary on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "6.9.1",
      "versions": [
        {
          "version": "6.9.1",
          "size": "23.0 MB",
          "published": "2026-07-26T12:18:15Z",
          "digest": "sha256:0a21d8e336e37e093817a6691a477acabe784d325f65bc1444d4e65e0bdb5ddc"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://centrifugal.dev",
      "source": "https://github.com/centrifugal/centrifugo",
      "image": "ghcr.io/quenchworks/images/centrifugo",
      "security": {
        "image": "ghcr.io/quenchworks/images/centrifugo",
        "version": "6.9.1",
        "tag": "ghcr.io/quenchworks/images/centrifugo:6.9.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/centrifugo"
            ]
          }
        ],
        "versions": [
          {
            "version": "6.9.1",
            "tag": "ghcr.io/quenchworks/images/centrifugo:6.9.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/centrifugo"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-acmesolver",
      "name": "cert-manager-acmesolver",
      "category": "Security & supply chain",
      "summary": "acmesolver component of cert-manager. The minimal HTTP server cert-manager runs as ephemeral pods to answer ACME http-01 challenge requests during certificate issuance.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.21.1, 1.19.6, 1.20.3",
      "versions": [
        {
          "version": "1.21.1",
          "size": "5.8 MB",
          "published": "2026-07-30T08:03:31Z",
          "digest": "sha256:78b0df18952a2b92133dca93ea9dcb70c8b86002cda09df70ce8a98fe1b888b3"
        },
        {
          "version": "1.19.6",
          "size": "7.9 MB",
          "published": "2026-07-30T08:03:30Z",
          "digest": "sha256:ee4ed58185fb9d542b95c657905360f43a92939ed28a7f073690deb5aed0e0c6"
        },
        {
          "version": "1.20.3",
          "size": "7.5 MB",
          "published": "2026-07-30T08:02:06Z",
          "digest": "sha256:cde325ad93021f98e3f680480888e879e85aa70655bf34e88d1b48a5c9577d2b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-acmesolver",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-acmesolver",
        "version": "1.21.0",
        "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.21.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.21.0",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.21.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.18.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-acmesolver:1.18.6",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "D",
            "score": 85,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/acmesolver"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-cainjector",
      "name": "cert-manager-cainjector",
      "category": "Security & supply chain",
      "summary": "cainjector component of cert-manager. Injects CA bundles into ValidatingWebhookConfigurations, MutatingWebhookConfigurations, APIServices, and conversion CRDs so the rest of the stack trusts cert-manager-issued certificates.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.19.6, 1.21.1, 1.20.3",
      "versions": [
        {
          "version": "1.19.6",
          "size": "16.4 MB",
          "published": "2026-07-30T08:06:08Z",
          "digest": "sha256:fb6a6ab87fd21235cd5dc47419a1ffab8fa044d437df5751f92da7ebd09e2a14"
        },
        {
          "version": "1.21.1",
          "size": "11.6 MB",
          "published": "2026-07-30T08:04:12Z",
          "digest": "sha256:7d0e1404b0001d83ac16f12f9df23067929bbc92264e5c5fbdc1d0a554483062"
        },
        {
          "version": "1.20.3",
          "size": "15.8 MB",
          "published": "2026-07-30T08:02:11Z",
          "digest": "sha256:5b88467bd6d7922a959691ec988bc98b368fd9a740f866b24865c6d8558b3aa1"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-cainjector",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-cainjector",
        "version": "1.21.0",
        "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.21.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cainjector"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.21.0",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.21.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          },
          {
            "version": "1.18.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-cainjector:1.18.6",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 1,
            "grade": "D",
            "score": 83,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/cainjector"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cainjector"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-controller",
      "name": "cert-manager-controller",
      "category": "Security & supply chain",
      "summary": "Core controller of cert-manager, the CNCF standard for X.509 certificate management on Kubernetes. Reconciles Certificate, Issuer, ClusterIssuer, and ACME order resources, automating issuance and renewal from Let's Encrypt, Vault, Venafi, and self-signed/CA issuers.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.21.1, 1.19.6, 1.20.3",
      "versions": [
        {
          "version": "1.21.1",
          "size": "24.0 MB",
          "published": "2026-07-30T08:10:20Z",
          "digest": "sha256:652fe926a9adb199b0a1becd3bb44981a27b6169c698a333073e91eea00fa2f0"
        },
        {
          "version": "1.19.6",
          "size": "23.3 MB",
          "published": "2026-07-30T08:08:41Z",
          "digest": "sha256:6f3862cf74b39433c827821045980ab2f3ed423f4c2711afaa46a101c62ef05e"
        },
        {
          "version": "1.20.3",
          "size": "23.0 MB",
          "published": "2026-07-30T08:08:40Z",
          "digest": "sha256:8a3aa246b07f26aa83f9d95dc6fa868f035b30215462862a980e68bdc1cb619d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-controller",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-controller",
        "version": "1.21.0",
        "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.21.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.21.0",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.21.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "1.18.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-controller:1.18.6",
            "critical": 0,
            "high": 2,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 3,
            "fixable": 2,
            "grade": "D",
            "score": 68,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/controller"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.79.3",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/controller"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cert-manager-webhook",
      "name": "cert-manager-webhook",
      "category": "Security & supply chain",
      "summary": "Admission webhook component of cert-manager. Validates and mutates cert-manager API resources and serves the conversion webhook for its CRD versions.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.19.6, 1.21.1, 1.20.3",
      "versions": [
        {
          "version": "1.19.6",
          "size": "19.5 MB",
          "published": "2026-07-30T08:09:53Z",
          "digest": "sha256:bd70884a68e8dd23ff51aba0b57a6c62b18ed1d3def1f204a3c4db406da16183"
        },
        {
          "version": "1.21.1",
          "size": "19.0 MB",
          "published": "2026-07-30T08:09:43Z",
          "digest": "sha256:a14cd3675a8ff6205bc9807ff48ad4d28820dc838737499a99c5513bba1336de"
        },
        {
          "version": "1.20.3",
          "size": "18.9 MB",
          "published": "2026-07-30T08:05:50Z",
          "digest": "sha256:d0fbc971fc0c294f132a9a64ea30cfaa0b5ce80caded675c2de3a17b8a614931"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://cert-manager.io",
      "source": "https://github.com/cert-manager/cert-manager",
      "image": "ghcr.io/quenchworks/images/cert-manager-webhook",
      "security": {
        "image": "ghcr.io/quenchworks/images/cert-manager-webhook",
        "version": "1.21.0",
        "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.21.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/webhook"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.21.0",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.21.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          },
          {
            "version": "1.20.3",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.20.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          },
          {
            "version": "1.19.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.19.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          },
          {
            "version": "1.18.6",
            "tag": "ghcr.io/quenchworks/images/cert-manager-webhook:1.18.6",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 4,
            "fixable": 3,
            "grade": "D",
            "score": 59,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/webhook"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.79.3",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/webhook"
                ]
              },
              {
                "id": "GHSA-gcjh-h69q-9w9g",
                "severity": "MEDIUM",
                "pkg": "github.com/google/cel-go",
                "installed": "v0.22.1",
                "fixed": "0.29.0",
                "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
                "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
                "targets": [
                  "usr/bin/webhook"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/webhook"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "chartmuseum",
      "name": "chartmuseum",
      "category": "CI/CD & registry",
      "summary": "Helm chart repository server with support for cloud object storage backends (S3, GCS, Azure, and more). Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.16.5",
      "versions": [
        {
          "version": "0.16.5",
          "size": "20.3 MB",
          "published": "2026-07-22T08:27:19Z",
          "digest": "sha256:35e24b059f4602e17750f0ceed45ecd3356b2bd0ad7d318c47823533bd291cbd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://chartmuseum.com",
      "source": "https://github.com/helm/chartmuseum",
      "image": "ghcr.io/quenchworks/images/chartmuseum",
      "security": {
        "image": "ghcr.io/quenchworks/images/chartmuseum",
        "version": "0.16.5",
        "tag": "ghcr.io/quenchworks/images/chartmuseum:0.16.5",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/chartmuseum"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/chartmuseum"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.16.5",
            "tag": "ghcr.io/quenchworks/images/chartmuseum:0.16.5",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/chartmuseum"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/chartmuseum"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "clickhouse",
      "name": "ClickHouse",
      "category": "Analytical",
      "summary": "Column-oriented OLAP database for real-time analytical queries over very large datasets, with high ingest rates and fast aggregations.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "26.6.2.81, 26.7.1.1315, 26.5.3.52",
      "versions": [
        {
          "version": "26.6.2.81",
          "size": "240.8 MB",
          "published": "2026-07-23T08:58:30Z",
          "digest": "sha256:378c62d2f23261b9bef396bc6ea8f0b6f920be4d0cbecddbf2aea6d89d6ef8d0"
        },
        {
          "version": "26.7.1.1315",
          "size": "229.7 MB",
          "published": "2026-07-23T08:58:28Z",
          "digest": "sha256:0fe6b62479965049517e9f59800529422f36038932676b798fa56d3db83757b4"
        },
        {
          "version": "26.5.3.52",
          "size": "225.7 MB",
          "published": "2026-07-23T08:58:24Z",
          "digest": "sha256:fb69216283354f87c80a7cd251c626b1ca68f893f290e795c36375fd1bb45abd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/ClickHouse/ClickHouse",
      "source": "https://github.com/ClickHouse/ClickHouse",
      "image": "ghcr.io/quenchworks/images/clickhouse",
      "security": {
        "image": "ghcr.io/quenchworks/images/clickhouse",
        "version": "26.7.1.1315",
        "tag": "ghcr.io/quenchworks/images/clickhouse:26.7.1.1315",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "26.7.1.1315",
            "tag": "ghcr.io/quenchworks/images/clickhouse:26.7.1.1315",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "26.6.2.81",
            "tag": "ghcr.io/quenchworks/images/clickhouse:26.6.2.81",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "26.5.3.52",
            "tag": "ghcr.io/quenchworks/images/clickhouse:26.5.3.52",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "code-server",
      "name": "code-server",
      "category": "Developer tools / IDE",
      "summary": "VS Code in the browser (Coder's code-server), a full IDE served over HTTP. Ships Coder's official prebuilt release (bundled Node 24 + compiled VS Code) hardened on a minimal, nonroot Wolfi base; runs as a single-replica Deployment with a persistent workspace and PASSWORD login.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "4.130.0",
      "versions": [
        {
          "version": "4.130.0",
          "size": "207.9 MB",
          "published": "2026-07-26T12:20:41Z",
          "digest": "sha256:886ebb269dbbb27cd8393fdb16c86beeed326a3eee8cd8cbf79917e7b384e38f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://coder.com",
      "source": "https://github.com/coder/code-server",
      "image": "ghcr.io/quenchworks/images/code-server",
      "security": {
        "image": "ghcr.io/quenchworks/images/code-server",
        "version": "4.130.0",
        "tag": "ghcr.io/quenchworks/images/code-server:4.130.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 0,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 99,
        "cves": [
          {
            "id": "GHSA-wx77-rp39-c6vg",
            "severity": "LOW",
            "pkg": "markdown",
            "installed": "30.0.0",
            "fixed": null,
            "title": "Regular Expression Denial of Service in markdown",
            "url": "https://github.com/advisories/GHSA-wx77-rp39-c6vg",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.130.0",
            "tag": "ghcr.io/quenchworks/images/code-server:4.130.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 0,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 99,
            "cves": [
              {
                "id": "GHSA-wx77-rp39-c6vg",
                "severity": "LOW",
                "pkg": "markdown",
                "installed": "30.0.0",
                "fixed": null,
                "title": "Regular Expression Denial of Service in markdown",
                "url": "https://github.com/advisories/GHSA-wx77-rp39-c6vg",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "composer",
      "name": "composer",
      "category": "Build tool",
      "summary": "PHP base image with the Composer dependency manager, used as the build stage for PHP projects. Line 2.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.10.1, 2.10.0, 2.10.2",
      "versions": [
        {
          "version": "2.10.1",
          "size": "28.8 MB",
          "published": "2026-07-04T10:28:18Z",
          "digest": "sha256:de8f90cc23437a8f56c22ce0252247416d9c5d6af78587ceea3c9533ef852fe6"
        },
        {
          "version": "2.10.0",
          "size": "28.8 MB",
          "published": "2026-07-04T10:26:36Z",
          "digest": "sha256:69b1d142232cd87281ce9fe193ad3eb2199373650f4ca01ddaded18f0b93ada6"
        },
        {
          "version": "2.10.2",
          "size": "28.8 MB",
          "published": "2026-07-04T10:22:18Z",
          "digest": "sha256:15b91ef4fed75a9adff1b45c6e0283466477f1d8d9d034799ee066e8e62c7408"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://getcomposer.org",
      "source": "https://getcomposer.org",
      "image": "ghcr.io/quenchworks/images/composer",
      "security": {
        "image": "ghcr.io/quenchworks/images/composer",
        "version": "2.10.2",
        "tag": "ghcr.io/quenchworks/images/composer:2.10.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.10.2",
            "tag": "ghcr.io/quenchworks/images/composer:2.10.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.10.1",
            "tag": "ghcr.io/quenchworks/images/composer:2.10.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.10.0",
            "tag": "ghcr.io/quenchworks/images/composer:2.10.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "coolify-app",
      "name": "Coolify",
      "category": "PaaS",
      "summary": "Control-plane application for Coolify, an open-source self-hostable PaaS alternative to Heroku, Vercel, and Netlify for deploying apps, databases, and services on your own servers.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.2.0",
      "versions": [
        {
          "version": "4.2.0",
          "size": "119.0 MB",
          "published": "2026-07-28T06:20:09Z",
          "digest": "sha256:a170bf310e7f2335dffb936c5df58f4bff8ccf567d78d80131919527ce4878f6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/coollabsio/coolify",
      "source": "https://github.com/coollabsio/coolify",
      "image": "ghcr.io/quenchworks/images/coolify-app",
      "security": {
        "image": "ghcr.io/quenchworks/images/coolify-app",
        "version": "4.2.0",
        "tag": "ghcr.io/quenchworks/images/coolify-app:4.2.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 4,
        "total": 4,
        "fixable": 2,
        "grade": "B",
        "score": 82,
        "cves": [
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/git-lfs",
              "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.52.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/git-lfs",
              "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.2.0",
            "tag": "ghcr.io/quenchworks/images/coolify-app:4.2.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 4,
            "total": 4,
            "fixable": 2,
            "grade": "B",
            "score": 82,
            "cves": [
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/git-lfs",
                  "var/lib/db/sbom/git-lfs-3.7.1-r18.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coolify-realtime",
      "name": "Coolify Realtime",
      "category": "PaaS",
      "summary": "Realtime server component of Coolify, providing the websocket connections and terminal/log gateway for the dashboard. Licensed AGPL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0+",
      "licenseClean": "agpl",
      "version": "1.0.16",
      "versions": [
        {
          "version": "1.0.16",
          "size": "99.6 MB",
          "published": "2026-07-28T09:49:08Z",
          "digest": "sha256:1a9514a1e15cf9901cc2f93817a26bcc34a4838b2f033778fbae49207f1201fd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/coollabsio/coolify",
      "source": "https://github.com/coollabsio/coolify",
      "image": "ghcr.io/quenchworks/images/coolify-realtime",
      "knownIssue": "Holds 1 Medium CVE (cloudflared CVE-2026-41178). The fix is cloudflared 2026.6.1-r2, not yet in Wolfi (newest is the vulnerable 2026.5.2-r2), so a rebuild cannot clear it. A new release follows as soon as Wolfi ships the patched cloudflared.",
      "security": {
        "image": "ghcr.io/quenchworks/images/coolify-realtime",
        "version": "1.0.16",
        "tag": "ghcr.io/quenchworks/images/coolify-realtime:1.0.16",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 97,
        "cves": [
          {
            "id": "GHSA-j965-2qgj-vjmq",
            "severity": "LOW",
            "pkg": "aws-sdk",
            "installed": "2.1426.0",
            "fixed": null,
            "title": "JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3",
            "url": "https://github.com/advisories/GHSA-j965-2qgj-vjmq",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cloudflared"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.0.16",
            "tag": "ghcr.io/quenchworks/images/coolify-realtime:1.0.16",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 97,
            "cves": [
              {
                "id": "GHSA-j965-2qgj-vjmq",
                "severity": "LOW",
                "pkg": "aws-sdk",
                "installed": "2.1426.0",
                "fixed": null,
                "title": "JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3",
                "url": "https://github.com/advisories/GHSA-j965-2qgj-vjmq",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cloudflared"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coredns",
      "name": "coredns",
      "category": "Coordination",
      "summary": "Fast, flexible DNS server that chains plugins to serve DNS and service discovery, the default cluster DNS for Kubernetes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.14.6",
      "versions": [
        {
          "version": "1.14.6",
          "size": "23.1 MB",
          "published": "2026-07-22T06:57:32Z",
          "digest": "sha256:cc733bae7b57919437ee0c306ef066419d742ef5ffb71e81254cd760f813a477"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://coredns.io",
      "source": "https://github.com/coredns/coredns",
      "image": "ghcr.io/quenchworks/images/coredns",
      "security": {
        "image": "ghcr.io/quenchworks/images/coredns",
        "version": "1.14.6",
        "tag": "ghcr.io/quenchworks/images/coredns:1.14.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/coredns"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.14.6",
            "tag": "ghcr.io/quenchworks/images/coredns:1.14.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/coredns"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "coroot",
      "name": "coroot",
      "category": "Observability",
      "summary": "Coroot — open-source observability/APM (eBPF-based metrics, logs, traces, cost insights and service maps) with an embedded Vue UI. Built from source on Wolfi (go:embedded frontend, cgo lz4), prometheus/ch-go bumped to their fixed lines. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.23.3",
      "versions": [
        {
          "version": "1.23.3",
          "size": "26.0 MB",
          "published": "2026-07-22T08:29:02Z",
          "digest": "sha256:4ca63d624cc8462c9844fc92319fe53b746fe355403f3f2332354357fb93b0f8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://coroot.com",
      "source": "https://github.com/coroot/coroot",
      "image": "ghcr.io/quenchworks/images/coroot",
      "security": {
        "image": "ghcr.io/quenchworks/images/coroot",
        "version": "1.23.3",
        "tag": "ghcr.io/quenchworks/images/coroot:1.23.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/coroot"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.23.3",
            "tag": "ghcr.io/quenchworks/images/coroot:1.23.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/coroot"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "cosign",
      "name": "cosign",
      "category": "Security & supply chain",
      "summary": "Sigstore's container-signing CLI. Keyless sign and verify of images, SBOMs, and attestations against the Fulcio/Rekor transparency log. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.1.2",
      "versions": [
        {
          "version": "3.1.2",
          "size": "30.2 MB",
          "published": "2026-07-22T06:59:07Z",
          "digest": "sha256:5d9e41e1b8cdec4884cc3dfac5c969029ba85805c438fc42f9c0c17719e17157"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.sigstore.dev",
      "source": "https://github.com/sigstore/cosign",
      "image": "ghcr.io/quenchworks/images/cosign",
      "security": {
        "image": "ghcr.io/quenchworks/images/cosign",
        "version": "3.1.2",
        "tag": "ghcr.io/quenchworks/images/cosign:3.1.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/cosign"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.1.2",
            "tag": "ghcr.io/quenchworks/images/cosign:3.1.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/cosign"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "couchdb",
      "name": "CouchDB",
      "category": "Document",
      "summary": "Document database with an HTTP/JSON API and multi-master replication, designed for offline-first sync across nodes and devices.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.4.3, 3.5.1, 3.5.2",
      "versions": [
        {
          "version": "3.4.3",
          "size": "123.7 MB",
          "published": "2026-07-04T10:43:31Z",
          "digest": "sha256:3d86508017bae7570dd518994194228fa26fafec988c77b8484050933de3ae20"
        },
        {
          "version": "3.5.1",
          "size": "127.2 MB",
          "published": "2026-07-04T10:42:03Z",
          "digest": "sha256:7bee1b27171ca553ea16ecef7bf91b6303f9e17928f0b7cb2c9c6463e7399128"
        },
        {
          "version": "3.5.2",
          "size": "126.9 MB",
          "published": "2026-07-04T10:34:36Z",
          "digest": "sha256:e654f0c3753e9bbc2ed975b07f447a48d3fe963bcb6e4e2f1627f3efcf11a524"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/couchdb",
      "source": "https://github.com/apache/couchdb",
      "image": "ghcr.io/quenchworks/images/couchdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/couchdb",
        "version": "3.5.2",
        "tag": "ghcr.io/quenchworks/images/couchdb:3.5.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.5.2",
            "tag": "ghcr.io/quenchworks/images/couchdb:3.5.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.5.1",
            "tag": "ghcr.io/quenchworks/images/couchdb:3.5.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.4.3",
            "tag": "ghcr.io/quenchworks/images/couchdb:3.4.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "crossplane",
      "name": "crossplane",
      "category": "GitOps",
      "summary": "Crossplane, the CNCF control-plane framework that turns Kubernetes into a universal API for infrastructure. Installs Providers, Functions and Configurations as OCI packages, and lets platform teams publish their own composite APIs from CompositeResourceDefinitions and Compositions.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.3.4, 2.1.8, 2.2.4",
      "versions": [
        {
          "version": "2.3.4",
          "size": "21.7 MB",
          "published": "2026-07-28T06:21:00Z",
          "digest": "sha256:8d6341bf870f28c451523991b9ad8248a50deab2fdc6b5987762bfc59f22d5e7"
        },
        {
          "version": "2.1.8",
          "size": "22.1 MB",
          "published": "2026-07-28T06:20:40Z",
          "digest": "sha256:65b7d50d3d7fe86e8a9c28d44011658b2480f6a1aa374f43994dcecd79fb5b21"
        },
        {
          "version": "2.2.4",
          "size": "21.7 MB",
          "published": "2026-07-28T06:17:59Z",
          "digest": "sha256:c65a7d1c0723f62a56629831d4c770cd44ebd1e598c630a5d7cb1442f20c036b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://crossplane.io",
      "source": "https://github.com/crossplane/crossplane",
      "image": "ghcr.io/quenchworks/images/crossplane",
      "security": {
        "image": "ghcr.io/quenchworks/images/crossplane",
        "version": "2.3.4",
        "tag": "ghcr.io/quenchworks/images/crossplane:2.3.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/crossplane"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.3.4",
            "tag": "ghcr.io/quenchworks/images/crossplane:2.3.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/crossplane"
                ]
              }
            ]
          },
          {
            "version": "2.2.4",
            "tag": "ghcr.io/quenchworks/images/crossplane:2.2.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/crossplane"
                ]
              }
            ]
          },
          {
            "version": "2.1.8",
            "tag": "ghcr.io/quenchworks/images/crossplane:2.1.8",
            "critical": 1,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "F",
            "score": 73,
            "cves": [
              {
                "id": "GHSA-wfqx-gjrf-g28r",
                "severity": "CRITICAL",
                "pkg": "github.com/crossplane/crossplane/v2",
                "installed": "v2.1.8",
                "fixed": null,
                "title": "Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag",
                "url": "https://github.com/advisories/GHSA-wfqx-gjrf-g28r",
                "targets": [
                  "usr/bin/crossplane"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/crossplane"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "deno",
      "name": "deno",
      "category": "Language runtime",
      "summary": "Hardened Deno runtime for JavaScript and TypeScript, secure by default with explicit permissions and built-in tooling. Latest stable (2).",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.9.4",
      "versions": [
        {
          "version": "2.9.4",
          "size": "47.9 MB",
          "published": "2026-07-26T12:25:52Z",
          "digest": "sha256:2185617879a11ca56dab581e7ecf5527f6c0c83f9f0a719d9751abbafda4733a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/denoland/deno",
      "source": "https://github.com/denoland/deno",
      "image": "ghcr.io/quenchworks/images/deno",
      "security": {
        "image": "ghcr.io/quenchworks/images/deno",
        "version": "2.9.4",
        "tag": "ghcr.io/quenchworks/images/deno:2.9.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.9.4",
            "tag": "ghcr.io/quenchworks/images/deno:2.9.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "descheduler",
      "name": "descheduler",
      "category": "Coordination",
      "summary": "Kubernetes descheduler that evicts pods so the scheduler can re-place them for better cluster balance. Single static Go binary on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.36.0",
      "versions": [
        {
          "version": "0.36.0",
          "size": "21.8 MB",
          "published": "2026-07-26T12:24:50Z",
          "digest": "sha256:184afaae471b6635fb26741d2829914d7f49c1bf1955cab5af32d335ab4fe534"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/kubernetes-sigs/descheduler",
      "source": "https://github.com/kubernetes-sigs/descheduler",
      "image": "ghcr.io/quenchworks/images/descheduler",
      "security": {
        "image": "ghcr.io/quenchworks/images/descheduler",
        "version": "0.36.0",
        "tag": "ghcr.io/quenchworks/images/descheduler:0.36.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/descheduler"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.36.0",
            "tag": "ghcr.io/quenchworks/images/descheduler:0.36.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/descheduler"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "dex",
      "name": "dex",
      "category": "Identity",
      "summary": "Federated OpenID Connect (OIDC) identity provider. Acts as a portal to other identity providers (LDAP, SAML, GitHub, Google, OIDC) and issues OIDC tokens to apps and Kubernetes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.45.1",
      "versions": [
        {
          "version": "2.45.1",
          "size": "17.0 MB",
          "published": "2026-07-22T07:33:08Z",
          "digest": "sha256:d2e9efd7188d66b120d975effdbb3d950945a921b0c69642f4151b53c5febe1e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://dexidp.io",
      "source": "https://github.com/dexidp/dex",
      "image": "ghcr.io/quenchworks/images/dex",
      "security": {
        "image": "ghcr.io/quenchworks/images/dex",
        "version": "2.45.1",
        "tag": "ghcr.io/quenchworks/images/dex:2.45.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/dex"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.45.1",
            "tag": "ghcr.io/quenchworks/images/dex:2.45.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/dex"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "distribution",
      "name": "distribution",
      "category": "Registry",
      "summary": "The CNCF reference OCI and Docker registry server for storing and distributing container images and other OCI artifacts.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.1.1",
      "versions": [
        {
          "version": "3.1.1",
          "size": "16.2 MB",
          "published": "2026-07-22T08:27:05Z",
          "digest": "sha256:d36575774b4742443ac5c4296b443f4b394caaf4340070d8fae6ca1378321de3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://distribution.github.io/distribution",
      "source": "https://github.com/distribution/distribution",
      "image": "ghcr.io/quenchworks/images/distribution",
      "security": {
        "image": "ghcr.io/quenchworks/images/distribution",
        "version": "3.1.1",
        "tag": "ghcr.io/quenchworks/images/distribution:3.1.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/registry"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.1.1",
            "tag": "ghcr.io/quenchworks/images/distribution:3.1.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/registry"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "documentdb",
      "name": "DocumentDB",
      "category": "Document",
      "summary": "Self-contained MongoDB-compatible server bundling PostgreSQL, the DocumentDB extension, and a wire gateway. Linux Foundation project, truly open under MIT.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.112.0, 0.114.0, 0.113.0",
      "versions": [
        {
          "version": "0.112.0",
          "size": "141.6 MB",
          "published": "2026-07-21T08:44:20Z",
          "digest": "sha256:6e4cd0ed68c07b8a6d4cb12a9e45d3544c45bab20d2282c47c85be30afe18c48"
        },
        {
          "version": "0.114.0",
          "size": "141.7 MB",
          "published": "2026-07-21T08:43:47Z",
          "digest": "sha256:bff5b31492f4c5fff162eb053d1f97cd6ddabd17deba967f4294b5096cdf21ca"
        },
        {
          "version": "0.113.0",
          "size": "141.8 MB",
          "published": "2026-07-21T08:41:31Z",
          "digest": "sha256:f08e3a64e8c1367858e6b75c99888fca1d0a990b4a4e8607f134fb07f5f55ad8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/documentdb/documentdb",
      "source": "https://github.com/documentdb/documentdb",
      "image": "ghcr.io/quenchworks/images/documentdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/documentdb",
        "version": "0.114.0",
        "tag": "ghcr.io/quenchworks/images/documentdb:0.114.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.114.0",
            "tag": "ghcr.io/quenchworks/images/documentdb:0.114.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.113.0",
            "tag": "ghcr.io/quenchworks/images/documentdb:0.113.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.112.0",
            "tag": "ghcr.io/quenchworks/images/documentdb:0.112.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "dotnet",
      "name": "dotnet",
      "category": "Language runtime",
      "summary": "Hardened .NET SDK for building and running .NET apps. Use as a build base; ships the current LTS line (10). Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "10.0.110",
      "versions": [
        {
          "version": "10.0.110",
          "size": "271.1 MB",
          "published": "2026-07-21T06:45:16Z",
          "digest": "sha256:1344024b5aaec97b041139fae3a10243e50cc7fb3c2e2221734ae532f69ec555"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dotnet/runtime",
      "source": "https://github.com/dotnet/runtime",
      "image": "ghcr.io/quenchworks/images/dotnet",
      "security": {
        "image": "ghcr.io/quenchworks/images/dotnet",
        "version": "10.0.110",
        "tag": "ghcr.io/quenchworks/images/dotnet:10.0.110",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "10.0.110",
            "tag": "ghcr.io/quenchworks/images/dotnet:10.0.110",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "dotnet-runtime",
      "name": "dotnet-runtime",
      "category": "Runtime base",
      "summary": "Hardened .NET runtime for console and worker apps, no SDK. Build on the dotnet image, then run here. Lines 8/9/10.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "9.0.119, 10.0.110, 8.0.127",
      "versions": [
        {
          "version": "9.0.119",
          "size": "60.1 MB",
          "published": "2026-07-21T08:34:16Z",
          "digest": "sha256:dca9d090e85b0138a9c849f41d1a404aa37a311bd0267ceb2ba93569360599c9"
        },
        {
          "version": "10.0.110",
          "size": "61.1 MB",
          "published": "2026-07-15T11:18:10Z",
          "digest": "sha256:2b76fa8aa868f08d2b63b24032970b3a34e3ce6592b7a82258b231c74eb39b76"
        },
        {
          "version": "8.0.127",
          "size": "56.9 MB",
          "published": "2026-07-15T11:17:45Z",
          "digest": "sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dotnet/runtime",
      "source": "https://github.com/dotnet/runtime",
      "image": "ghcr.io/quenchworks/images/dotnet-runtime",
      "security": {
        "image": "ghcr.io/quenchworks/images/dotnet-runtime",
        "version": "10.0.110",
        "tag": "ghcr.io/quenchworks/images/dotnet-runtime:10.0.110",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "10.0.110",
            "tag": "ghcr.io/quenchworks/images/dotnet-runtime:10.0.110",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.0.119",
            "tag": "ghcr.io/quenchworks/images/dotnet-runtime:9.0.119",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.127",
            "tag": "ghcr.io/quenchworks/images/dotnet-runtime:8.0.127",
            "critical": 2,
            "high": 6,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 8,
            "fixable": 8,
            "grade": "F",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47304",
                "severity": "CRITICAL",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Security Feature Bypass Vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47304",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-47302",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-47302",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50525",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET: Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50525",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-50648",
                "severity": "HIGH",
                "pkg": "dotnet-8-runtime",
                "installed": "8.0.127-r0",
                "fixed": "8.0.129-r1",
                "title": "dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50648",
                "targets": [
                  "ghcr.io/quenchworks/images/dotnet-runtime@sha256:4037bc156569390107c8ffd916dad95cd8e12d080f89728d04d1d41e7aa9889d (wolfi 20230201)"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "dragonfly",
      "name": "Dragonfly",
      "category": "Cache",
      "summary": "Multi-threaded, Redis- and Memcached-compatible in-memory datastore built to scale vertically on one node. BUSL is source-available, not open source; prefer Valkey (BSD-3-Clause).",
      "tier": "low",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "1.39.0, 1.37.2, 1.38.1",
      "versions": [
        {
          "version": "1.39.0",
          "size": "25.1 MB",
          "published": "2026-07-04T11:23:08Z",
          "digest": "sha256:9950a9aae3bd7292ceac904508f7ce9002c0cd76e959711b8364ab23e9751c74"
        },
        {
          "version": "1.37.2",
          "size": "23.6 MB",
          "published": "2026-07-04T11:09:36Z",
          "digest": "sha256:41b890dea153917121fdf475e26858d60e4b5aa87231f3aa23d588006f93272e"
        },
        {
          "version": "1.38.1",
          "size": "24.5 MB",
          "published": "2026-07-04T11:02:36Z",
          "digest": "sha256:5fcf14a620578357d6329b76d61558c402f4f648814e37e5f767da161ba0b83e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/dragonflydb/dragonfly",
      "source": "https://github.com/dragonflydb/dragonfly",
      "image": "ghcr.io/quenchworks/images/dragonfly",
      "caution": true,
      "cleanAlternative": "Valkey (BSD-3-Clause) — the truly-open Redis-compatible cache.",
      "security": {
        "image": "ghcr.io/quenchworks/images/dragonfly",
        "version": "1.39.0",
        "tag": "ghcr.io/quenchworks/images/dragonfly:1.39.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.39.0",
            "tag": "ghcr.io/quenchworks/images/dragonfly:1.39.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.38.1",
            "tag": "ghcr.io/quenchworks/images/dragonfly:1.38.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.37.2",
            "tag": "ghcr.io/quenchworks/images/dragonfly:1.37.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "drupal",
      "name": "drupal",
      "category": "Apps & productivity",
      "summary": "Drupal core, the open-source CMS and content framework. Built from the official release tarball on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs, supervisord); the chart supplies settings.php via ConfigMap and a MySQL backend. Ships the 11.3/11.4 lines (11.2 is held because drupal/core-recommended pins guzzle below its CVE fix).",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0+",
      "licenseClean": "clean",
      "version": "11.4.4",
      "versions": [
        {
          "version": "11.4.4",
          "size": "68.5 MB",
          "published": "2026-07-26T12:21:01Z",
          "digest": "sha256:23aa2bdb493cedda7c0d64d0f3f423d463f65e55abbed1bbfd45066ec8976eb0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.drupal.org",
      "source": "https://ftp.drupal.org/files/projects/drupal-11.4.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/drupal",
      "security": {
        "image": "ghcr.io/quenchworks/images/drupal",
        "version": "11.4.4",
        "tag": "ghcr.io/quenchworks/images/drupal:11.4.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "11.4.4",
            "tag": "ghcr.io/quenchworks/images/drupal:11.4.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "duckdb",
      "name": "duckdb",
      "category": "Databases & engines",
      "summary": "In-process analytical SQL database CLI, shipped from upstream's official precompiled binary. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.4.5, 1.3.2, 1.5.5",
      "versions": [
        {
          "version": "1.4.5",
          "size": "24.0 MB",
          "published": "2026-07-22T11:26:53Z",
          "digest": "sha256:303854cd4dd30e096246acff369b3458f6164d2aa1a3e6f7f0d3b77aad48091f"
        },
        {
          "version": "1.3.2",
          "size": "22.6 MB",
          "published": "2026-07-22T11:26:49Z",
          "digest": "sha256:fdcdecf75bcdcadec3de817432cc40fbeb9ee636646f2a3764eb709dcb6e8e58"
        },
        {
          "version": "1.5.5",
          "size": "26.2 MB",
          "published": "2026-07-22T11:26:49Z",
          "digest": "sha256:694ada7b706ca5b8142885ecfac8cf47e72946fcedb759dcebdf21384aa42bda"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://duckdb.org",
      "source": "https://github.com/duckdb/duckdb",
      "image": "ghcr.io/quenchworks/images/duckdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/duckdb",
        "version": "1.5.5",
        "tag": "ghcr.io/quenchworks/images/duckdb:1.5.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.5.5",
            "tag": "ghcr.io/quenchworks/images/duckdb:1.5.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.4.5",
            "tag": "ghcr.io/quenchworks/images/duckdb:1.4.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.3.2",
            "tag": "ghcr.io/quenchworks/images/duckdb:1.3.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "elasticsearch",
      "name": "Elasticsearch",
      "category": "Search",
      "summary": "Distributed search and analytics engine. Shipped under SSPL/Elastic License, which are not OSI-approved; OpenSearch (Apache-2.0) is the open drop-in fork.",
      "tier": "low",
      "status": "available",
      "license": "SSPL-1.0",
      "licenseClean": "caution",
      "version": "9.4.4",
      "versions": [
        {
          "version": "9.4.4",
          "size": "639.6 MB",
          "published": "2026-07-26T12:24:29Z",
          "digest": "sha256:326b98563554f8fe8bf6aa74d4448184aff3876e70bed71362600ace7d1c3c03"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/elastic/elasticsearch",
      "source": "https://github.com/elastic/elasticsearch",
      "image": "ghcr.io/quenchworks/images/elasticsearch",
      "caution": true,
      "cleanAlternative": "OpenSearch (Apache-2.0) — the open drop-in fork of Elasticsearch.",
      "security": {
        "image": "ghcr.io/quenchworks/images/elasticsearch",
        "version": "9.4.4",
        "tag": "ghcr.io/quenchworks/images/elasticsearch:9.4.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.4.4",
            "tag": "ghcr.io/quenchworks/images/elasticsearch:9.4.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "elixir",
      "name": "elixir",
      "category": "Language runtime",
      "summary": "Hardened Elixir runtime on the BEAM VM, built on Erlang/OTP, for concurrent, fault-tolerant apps (e.g. Phoenix). Latest stable (1.18).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.4, 1.19.5, 1.17.3",
      "versions": [
        {
          "version": "1.18.4",
          "size": "60.6 MB",
          "published": "2026-07-04T10:16:31Z",
          "digest": "sha256:399f63fd8bdc481f72455245c4dfc33d2ef2230aa63302cf874004b295fe33d8"
        },
        {
          "version": "1.19.5",
          "size": "68.9 MB",
          "published": "2026-07-04T10:16:23Z",
          "digest": "sha256:7424aca74824c1a1aa836fa43380fccbf1f01dfa984fba6e7cbb1dfef544e071"
        },
        {
          "version": "1.17.3",
          "size": "61.0 MB",
          "published": "2026-07-04T10:11:58Z",
          "digest": "sha256:8654bfd5f0578aa3bb6fc87378c813027fa315a3cb71b131994d9ed5acc71e02"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://elixir-lang.org",
      "source": "https://elixir-lang.org",
      "image": "ghcr.io/quenchworks/images/elixir",
      "security": {
        "image": "ghcr.io/quenchworks/images/elixir",
        "version": "1.19.5",
        "tag": "ghcr.io/quenchworks/images/elixir:1.19.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.19.5",
            "tag": "ghcr.io/quenchworks/images/elixir:1.19.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.18.4",
            "tag": "ghcr.io/quenchworks/images/elixir:1.18.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.17.3",
            "tag": "ghcr.io/quenchworks/images/elixir:1.17.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "emqx",
      "name": "emqx",
      "category": "Messaging",
      "summary": "Massively scalable, distributed MQTT broker for IoT, IIoT, and connected vehicles. Speaks MQTT 5.0 over TCP/TLS/websockets with a clustering engine and a web dashboard. Packaged from EMQX's official Erlang/OTP release. Licensed BSL 1.1 (single node free; clustering requires a commercial license).",
      "tier": "standard",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "6.2.2",
      "versions": [
        {
          "version": "6.2.2",
          "size": "125.8 MB",
          "published": "2026-07-05T10:11:30Z",
          "digest": "sha256:618646bdf882cff28aee50ca1ecaf196f7c5ade15c52d9ead72fc0e8c3070819"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.emqx.io",
      "source": "https://github.com/emqx/emqx",
      "image": "ghcr.io/quenchworks/images/emqx",
      "caution": true,
      "security": {
        "image": "ghcr.io/quenchworks/images/emqx",
        "version": "6.2.2",
        "tag": "ghcr.io/quenchworks/images/emqx:6.2.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "6.2.2",
            "tag": "ghcr.io/quenchworks/images/emqx:6.2.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "envoy",
      "name": "envoy",
      "category": "Gateway",
      "summary": "Cloud-native L7 proxy and communication bus, the data plane behind API gateways and service meshes. HTTP/gRPC routing, load balancing, rich observability, and an admin/health endpoint. The chart supplies the bootstrap config.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.37.1, 1.36.4, 1.38.1",
      "versions": [
        {
          "version": "1.37.1",
          "size": "41.7 MB",
          "published": "2026-07-04T11:00:56Z",
          "digest": "sha256:44923be0d745883de4e65533e5b86b7d6e2961202752eafb3a4d5f9070c8956a"
        },
        {
          "version": "1.36.4",
          "size": "39.9 MB",
          "published": "2026-07-04T10:57:05Z",
          "digest": "sha256:a5ebe3c301a3f70656bf3112d1b81251c176fd1433f7e17dad5c702b83d02156"
        },
        {
          "version": "1.38.1",
          "size": "46.3 MB",
          "published": "2026-07-04T10:53:49Z",
          "digest": "sha256:99cf0132c2d9521d564329f78512f5ba521d8e147a824bf64f3c27352efbc0af"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.envoyproxy.io",
      "source": "https://github.com/envoyproxy/envoy",
      "image": "ghcr.io/quenchworks/images/envoy",
      "security": {
        "image": "ghcr.io/quenchworks/images/envoy",
        "version": "1.38.1",
        "tag": "ghcr.io/quenchworks/images/envoy:1.38.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.38.1",
            "tag": "ghcr.io/quenchworks/images/envoy:1.38.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.37.1",
            "tag": "ghcr.io/quenchworks/images/envoy:1.37.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.36.4",
            "tag": "ghcr.io/quenchworks/images/envoy:1.36.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "erlang",
      "name": "erlang",
      "category": "Language runtime",
      "summary": "Hardened Erlang/OTP runtime on the BEAM VM, built for highly concurrent, fault-tolerant systems. Latest stable lines (27/28/29).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "28.5.0.4, 29.0.4, 27.3.4.15",
      "versions": [
        {
          "version": "28.5.0.4",
          "size": "62.2 MB",
          "published": "2026-07-28T09:50:01Z",
          "digest": "sha256:cba731cb63b90509d4710ab0c511a7eb4cd43944297275d424cc80ebdfab64ae"
        },
        {
          "version": "29.0.4",
          "size": "63.1 MB",
          "published": "2026-07-28T09:49:58Z",
          "digest": "sha256:08f2067a6d8a00a61e4cfe889101fea175c671a2ae5dcf0d688a8ecc76bd55b3"
        },
        {
          "version": "27.3.4.15",
          "size": "61.0 MB",
          "published": "2026-07-28T09:49:54Z",
          "digest": "sha256:cb5e5479d0a7ddf3ca4ba9b89e5f29590c6a305272a1bc0f6a94e8d49a4ee43c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.erlang.org",
      "source": "https://www.erlang.org",
      "image": "ghcr.io/quenchworks/images/erlang",
      "security": {
        "image": "ghcr.io/quenchworks/images/erlang",
        "version": "29.0.4",
        "tag": "ghcr.io/quenchworks/images/erlang:29.0.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "29.0.4",
            "tag": "ghcr.io/quenchworks/images/erlang:29.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "28.5.0.4",
            "tag": "ghcr.io/quenchworks/images/erlang:28.5.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "27.3.4.15",
            "tag": "ghcr.io/quenchworks/images/erlang:27.3.4.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "etcd",
      "name": "etcd",
      "category": "Coordination",
      "summary": "Distributed, strongly consistent key-value store using Raft consensus. The backing store for Kubernetes and a building block for service coordination and config.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.7.1",
      "versions": [
        {
          "version": "3.7.1",
          "size": "21.5 MB",
          "published": "2026-07-26T12:23:04Z",
          "digest": "sha256:f3ddaeabc17db4deddc07aaf13a60351370a440934ecc929721a4a75e4f8282a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/etcd-io/etcd",
      "source": "https://github.com/etcd-io/etcd",
      "image": "ghcr.io/quenchworks/images/etcd",
      "security": {
        "image": "ghcr.io/quenchworks/images/etcd",
        "version": "3.7.1",
        "tag": "ghcr.io/quenchworks/images/etcd:3.7.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/etcd",
              "usr/bin/etcdutl"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.1",
            "tag": "ghcr.io/quenchworks/images/etcd:3.7.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/etcd",
                  "usr/bin/etcdutl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "excalidraw",
      "name": "excalidraw",
      "category": "Apps & productivity",
      "summary": "Open-source virtual whiteboard for sketching hand-drawn-style diagrams. Self-hostable as a static SPA served by hardened nginx, with no backend or account required.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.18.1",
      "versions": [
        {
          "version": "0.18.1",
          "size": "28.4 MB",
          "published": "2026-07-04T11:06:50Z",
          "digest": "sha256:85ccb1fd7b34146ffecc67c3ded9cf814200a01863bab9922213988e6bb2ff51"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://excalidraw.com",
      "source": "https://github.com/excalidraw/excalidraw",
      "image": "ghcr.io/quenchworks/images/excalidraw",
      "security": {
        "image": "ghcr.io/quenchworks/images/excalidraw",
        "version": "0.18.1",
        "tag": "ghcr.io/quenchworks/images/excalidraw:0.18.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.18.1",
            "tag": "ghcr.io/quenchworks/images/excalidraw:0.18.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "external-dns",
      "name": "external-dns",
      "category": "Coordination & mesh",
      "summary": "Synchronizes Kubernetes Services and Ingresses with DNS providers so records are managed automatically. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.21.0",
      "versions": [
        {
          "version": "0.21.0",
          "size": "33.6 MB",
          "published": "2026-07-22T08:31:03Z",
          "digest": "sha256:ab6c52b713655557868d2488025155c8d1c9c46bde51853725afabf2453b1ae4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kubernetes-sigs.github.io/external-dns/",
      "source": "https://github.com/kubernetes-sigs/external-dns",
      "image": "ghcr.io/quenchworks/images/external-dns",
      "security": {
        "image": "ghcr.io/quenchworks/images/external-dns",
        "version": "0.21.0",
        "tag": "ghcr.io/quenchworks/images/external-dns:0.21.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/external-dns"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.21.0",
            "tag": "ghcr.io/quenchworks/images/external-dns:0.21.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/external-dns"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "external-secrets",
      "name": "external-secrets",
      "category": "Security & supply chain",
      "summary": "External Secrets Operator, the CNCF operator that syncs secrets from external APIs (AWS/GCP/Azure Secrets Manager, Vault, and many more) into Kubernetes Secrets. The single controller binary also serves the webhook and cert-controller, with every provider compiled in.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.8.0",
      "versions": [
        {
          "version": "2.8.0",
          "size": "51.8 MB",
          "published": "2026-07-26T12:25:53Z",
          "digest": "sha256:103de9fbbcc8a4059bf216ad89562e358370605b46986ed21a48a79e5b7912e5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://external-secrets.io",
      "source": "https://github.com/external-secrets/external-secrets",
      "image": "ghcr.io/quenchworks/images/external-secrets",
      "security": {
        "image": "ghcr.io/quenchworks/images/external-secrets",
        "version": "2.8.0",
        "tag": "ghcr.io/quenchworks/images/external-secrets:2.8.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/external-secrets"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.8.0",
            "tag": "ghcr.io/quenchworks/images/external-secrets:2.8.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/external-secrets"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ferretdb",
      "name": "FerretDB",
      "category": "Document",
      "summary": "MongoDB-compatible document database that translates the MongoDB wire protocol onto PostgreSQL via the DocumentDB extension. The clean-license substitute for MongoDB.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.7.0",
      "versions": [
        {
          "version": "2.7.0",
          "size": "10.2 MB",
          "published": "2026-07-22T06:59:06Z",
          "digest": "sha256:f61e374207f05beb027f1d5360a7f9a9c504a80e08b0f0bf942a13de0f92c558"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/FerretDB/FerretDB",
      "source": "https://github.com/FerretDB/FerretDB",
      "image": "ghcr.io/quenchworks/images/ferretdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/ferretdb",
        "version": "2.7.0",
        "tag": "ghcr.io/quenchworks/images/ferretdb:2.7.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/ferretdb"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.7.0",
            "tag": "ghcr.io/quenchworks/images/ferretdb:2.7.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/ferretdb"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "filebrowser",
      "name": "filebrowser",
      "category": "Apps & productivity",
      "summary": "Web-based file manager with a built-in UI, users, and share links. From source (Vite UI embedded in a static Go binary) on a hardened nonroot Wolfi base; data and served roots are volumes.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.63.18, 2.63.17",
      "versions": [
        {
          "version": "2.63.18",
          "size": "15.6 MB",
          "published": "2026-07-22T09:47:38Z",
          "digest": "sha256:b3f04c1b55124c83370b07fff02037e029fb7bd8b58a13af8b20ac352c11ab34"
        },
        {
          "version": "2.63.17",
          "size": "15.5 MB",
          "published": "2026-07-22T09:47:38Z",
          "digest": "sha256:3670cc55cdf28cd9fcb541bff747efd0f66ede4c8e702263135f32ca7d8a5942"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://filebrowser.org",
      "source": "https://github.com/filebrowser/filebrowser",
      "image": "ghcr.io/quenchworks/images/filebrowser",
      "security": {
        "image": "ghcr.io/quenchworks/images/filebrowser",
        "version": "2.63.18",
        "tag": "ghcr.io/quenchworks/images/filebrowser:2.63.18",
        "critical": 1,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 3,
        "fixable": 0,
        "grade": "F",
        "score": 72,
        "cves": [
          {
            "id": "CVE-2026-54089",
            "severity": "CRITICAL",
            "pkg": "github.com/filebrowser/filebrowser/v2",
            "installed": "2.63.18",
            "fixed": null,
            "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
            "url": "https://avd.aquasec.com/nvd/cve-2026-54089",
            "targets": [
              "usr/bin/filebrowser"
            ]
          },
          {
            "id": "CVE-2023-36308",
            "severity": "LOW",
            "pkg": "github.com/disintegration/imaging",
            "installed": "v1.6.2",
            "fixed": null,
            "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
            "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
            "targets": [
              "usr/bin/filebrowser"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/filebrowser"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.63.18",
            "tag": "ghcr.io/quenchworks/images/filebrowser:2.63.18",
            "critical": 1,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 3,
            "fixable": 0,
            "grade": "F",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-54089",
                "severity": "CRITICAL",
                "pkg": "github.com/filebrowser/filebrowser/v2",
                "installed": "2.63.18",
                "fixed": null,
                "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54089",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              }
            ]
          },
          {
            "version": "2.63.17",
            "tag": "ghcr.io/quenchworks/images/filebrowser:2.63.17",
            "critical": 1,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 3,
            "fixable": 0,
            "grade": "F",
            "score": 72,
            "cves": [
              {
                "id": "CVE-2026-54089",
                "severity": "CRITICAL",
                "pkg": "github.com/filebrowser/filebrowser/v2",
                "installed": "2.63.17",
                "fixed": null,
                "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
                "url": "https://avd.aquasec.com/nvd/cve-2026-54089",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/filebrowser"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "floci",
      "name": "floci",
      "category": "Apps & productivity",
      "summary": "Local AWS cloud emulator and LocalStack Community successor, built from source into a Quarkus fast-jar on a hardened Wolfi JRE. The hardened image runs all 55 of Floci's in-process AWS services nonroot with no Docker socket, covering S3, DynamoDB, SQS, SNS, SES, IAM, STS, KMS, Secrets Manager, API Gateway, Cognito, Kinesis, CloudFormation, Step Functions, EventBridge, CloudWatch, Route53, and more. The 10 Docker-backed services (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune) need the host Docker socket plus root and are out of scope for this image.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.5.34",
      "versions": [
        {
          "version": "1.5.34",
          "size": "191.3 MB",
          "published": "2026-07-30T08:11:21Z",
          "digest": "sha256:176ab5fde8c4f515e7d1f6e1c88906d7bc0b37531e4c268ddca79c3819ad37e8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://floci.io",
      "source": "https://github.com/floci-io/floci",
      "image": "ghcr.io/quenchworks/images/floci",
      "security": {
        "image": "ghcr.io/quenchworks/images/floci",
        "version": "1.5.33",
        "tag": "ghcr.io/quenchworks/images/floci:1.5.33",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.5.33",
            "tag": "ghcr.io/quenchworks/images/floci:1.5.33",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "floci-full",
      "name": "floci-full",
      "category": "Apps & productivity",
      "summary": "Opt-in, NON-hardened companion to the floci image: it runs as root and expects the host Docker socket mounted, which lets it emulate all 65 of Floci's AWS services including the 10 Docker-backed ones (Lambda, RDS, ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune). Same from-source Quarkus build and 0-CVE Trivy gate as floci, but running root with a mounted /var/run/docker.sock is a node-root / container-escape surface, so use it only in trusted single-tenant dev or CI. The floci Helm chart selects this image via mode=full behind an explicit acknowledgeRisk gate. Image only, no separate chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.5.29",
      "versions": [
        {
          "version": "1.5.29",
          "size": "190.8 MB",
          "published": "2026-07-28T06:18:52Z",
          "digest": "sha256:de65e07d085d55a89b605c446f20de0076b187b712b644da5c69937f956f2ec4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://floci.io",
      "source": "https://github.com/floci-io/floci",
      "image": "ghcr.io/quenchworks/images/floci-full",
      "security": {
        "image": "ghcr.io/quenchworks/images/floci-full",
        "version": "1.5.29",
        "tag": "ghcr.io/quenchworks/images/floci-full:1.5.29",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 1,
        "grade": "D",
        "score": 85,
        "cves": [
          {
            "id": "CVE-2026-50559",
            "severity": "HIGH",
            "pkg": "io.quarkus:quarkus-vertx-http",
            "installed": "3.36.0",
            "fixed": "3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3, 3.37.0",
            "title": "io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50559",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.5.29",
            "tag": "ghcr.io/quenchworks/images/floci-full:1.5.29",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 1,
            "grade": "D",
            "score": 85,
            "cves": [
              {
                "id": "CVE-2026-50559",
                "severity": "HIGH",
                "pkg": "io.quarkus:quarkus-vertx-http",
                "installed": "3.36.0",
                "fixed": "3.20.6.2, 3.27.4.1, 3.33.2.1, 3.36.3, 3.37.0",
                "title": "io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50559",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "fluent-bit",
      "name": "Fluent Bit",
      "category": "Observability",
      "summary": "Lightweight, fast log and metrics processor and forwarder for collecting, filtering, and shipping telemetry to many backends.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.0.9",
      "versions": [
        {
          "version": "5.0.9",
          "size": "35.2 MB",
          "published": "2026-07-05T10:15:33Z",
          "digest": "sha256:29822acfe2feb6d14a36aab8bf43bea8b6cb7191645640dcc012d30f6561345d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/fluent/fluent-bit",
      "source": "https://github.com/fluent/fluent-bit",
      "image": "ghcr.io/quenchworks/images/fluent-bit",
      "security": {
        "image": "ghcr.io/quenchworks/images/fluent-bit",
        "version": "5.0.9",
        "tag": "ghcr.io/quenchworks/images/fluent-bit:5.0.9",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.0.9",
            "tag": "ghcr.io/quenchworks/images/fluent-bit:5.0.9",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "forgejo",
      "name": "forgejo",
      "category": "Git",
      "summary": "Self-hosted lightweight Git forge (a community Gitea fork) with issues, PRs, CI, and packages. From source with the web UI embedded (no Node at runtime), CGO+static-musl SQLite, on a hardened nonroot Wolfi base; data lives on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0+",
      "licenseClean": "agpl",
      "version": "15.0.3",
      "versions": [
        {
          "version": "15.0.3",
          "size": "68.6 MB",
          "published": "2026-07-22T07:00:53Z",
          "digest": "sha256:9a899439937c7c6827d2f9d98ddb8c11868a12aa23019fb7b526cc70ebeb37b8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://forgejo.org",
      "source": "https://codeberg.org/forgejo/forgejo",
      "image": "ghcr.io/quenchworks/images/forgejo",
      "security": {
        "image": "ghcr.io/quenchworks/images/forgejo",
        "version": "15.0.3",
        "tag": "ghcr.io/quenchworks/images/forgejo:15.0.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/forgejo"
            ]
          }
        ],
        "versions": [
          {
            "version": "15.0.3",
            "tag": "ghcr.io/quenchworks/images/forgejo:15.0.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/forgejo"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "garage",
      "name": "Garage",
      "category": "Object storage",
      "summary": "Lightweight, S3-compatible object store for small, self-hosted, geo-distributed deployments that stays available across node failures. Licensed AGPL; runs well on modest hardware.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2.2.0, 2.3.0, 2.1.0",
      "versions": [
        {
          "version": "2.2.0",
          "size": "23.3 MB",
          "published": "2026-07-04T11:06:18Z",
          "digest": "sha256:573110f6f81975d519f481b411ada4414ed5c0308ddaab8f3219e00e751f8b8d"
        },
        {
          "version": "2.3.0",
          "size": "29.7 MB",
          "published": "2026-07-04T10:56:19Z",
          "digest": "sha256:feb4e12d18725972ed9eb8a742367af18ecee8b2eaa6127f8294d9bf4a4ff55f"
        },
        {
          "version": "2.1.0",
          "size": "16.1 MB",
          "published": "2026-07-04T10:49:18Z",
          "digest": "sha256:bc32d4041a0939b0557e6ff77b8a9aa1263cb6741d3481e5b604973395f13732"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/deuxfleurs-org/garage",
      "source": "https://github.com/deuxfleurs-org/garage",
      "image": "ghcr.io/quenchworks/images/garage",
      "security": {
        "image": "ghcr.io/quenchworks/images/garage",
        "version": "2.3.0",
        "tag": "ghcr.io/quenchworks/images/garage:2.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.3.0",
            "tag": "ghcr.io/quenchworks/images/garage:2.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.2.0",
            "tag": "ghcr.io/quenchworks/images/garage:2.2.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/garage:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "ghost",
      "name": "ghost",
      "category": "Apps & productivity",
      "summary": "Open-source Node.js publishing platform for blogs, newsletters, and membership sites. Packaged from Ghost's official npm distribution on a hardened Wolfi Node 22; configured entirely via environment and backed by an external MySQL/MariaDB with a content PVC for themes, images, and data.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "6.54.1",
      "versions": [
        {
          "version": "6.54.1",
          "size": "182.8 MB",
          "published": "2026-07-28T09:47:51Z",
          "digest": "sha256:7f589269c38500a138264a5c0f73bc04588f186d9e461a022db6954fa84a78b3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ghost.org",
      "source": "https://github.com/TryGhost/Ghost",
      "image": "ghcr.io/quenchworks/images/ghost",
      "security": {
        "image": "ghcr.io/quenchworks/images/ghost",
        "version": "6.54.1",
        "tag": "ghcr.io/quenchworks/images/ghost:6.54.1",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 0,
        "grade": "D",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2020-8203",
            "severity": "HIGH",
            "pkg": "lodash.pick",
            "installed": "4.4.0",
            "fixed": null,
            "title": "nodejs-lodash: prototype pollution in zipObjectDeep function",
            "url": "https://avd.aquasec.com/nvd/cve-2020-8203",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "CVE-2022-37620",
            "severity": "HIGH",
            "pkg": "html-minifier",
            "installed": "4.0.0",
            "fixed": null,
            "title": "kangax html-minifier REDoS vulnerability",
            "url": "https://avd.aquasec.com/nvd/cve-2022-37620",
            "targets": [
              "Node.js"
            ]
          },
          {
            "id": "GHSA-984p-xq9m-4rjw",
            "severity": "MEDIUM",
            "pkg": "express-brute",
            "installed": "1.0.1",
            "fixed": null,
            "title": "Rate Limiting Bypass in express-brute",
            "url": "https://github.com/advisories/GHSA-984p-xq9m-4rjw",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "6.54.1",
            "tag": "ghcr.io/quenchworks/images/ghost:6.54.1",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 0,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2020-8203",
                "severity": "HIGH",
                "pkg": "lodash.pick",
                "installed": "4.4.0",
                "fixed": null,
                "title": "nodejs-lodash: prototype pollution in zipObjectDeep function",
                "url": "https://avd.aquasec.com/nvd/cve-2020-8203",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "CVE-2022-37620",
                "severity": "HIGH",
                "pkg": "html-minifier",
                "installed": "4.0.0",
                "fixed": null,
                "title": "kangax html-minifier REDoS vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2022-37620",
                "targets": [
                  "Node.js"
                ]
              },
              {
                "id": "GHSA-984p-xq9m-4rjw",
                "severity": "MEDIUM",
                "pkg": "express-brute",
                "installed": "1.0.1",
                "fixed": null,
                "title": "Rate Limiting Bypass in express-brute",
                "url": "https://github.com/advisories/GHSA-984p-xq9m-4rjw",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "gitea",
      "name": "Gitea",
      "category": "Git",
      "summary": "Lightweight self-hosted Git service with repositories, issues, pull requests, and built-in CI/CD (Actions). A low-footprint GitHub alternative.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.27.1",
      "versions": [
        {
          "version": "1.27.1",
          "size": "70.1 MB",
          "published": "2026-07-28T09:48:52Z",
          "digest": "sha256:affb9f2aabdce981a175f8b3f48bf1bc0ee71f3e94a7e808b33aca07c3e6dad0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/go-gitea/gitea",
      "source": "https://github.com/go-gitea/gitea",
      "image": "ghcr.io/quenchworks/images/gitea",
      "security": {
        "image": "ghcr.io/quenchworks/images/gitea",
        "version": "1.27.1",
        "tag": "ghcr.io/quenchworks/images/gitea:1.27.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/gitea"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.27.1",
            "tag": "ghcr.io/quenchworks/images/gitea:1.27.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/gitea"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "go",
      "name": "go",
      "category": "Language runtime",
      "summary": "Hardened Go toolchain for compiling binaries in a build stage; pair the output with the static base for the runtime. Latest 3 stable lines (1.24/1.25/1.26).",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.26.5",
      "versions": [
        {
          "version": "1.26.5",
          "size": "59.1 MB",
          "published": "2026-07-08T10:37:16Z",
          "digest": "sha256:d79e890ef340a0162a5ebb994e9b83e8adab3a73a21fa2bf3f574a9e5ea5e549"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/golang/go",
      "source": "https://github.com/golang/go",
      "image": "ghcr.io/quenchworks/images/go",
      "security": {
        "image": "ghcr.io/quenchworks/images/go",
        "version": "1.26.5",
        "tag": "ghcr.io/quenchworks/images/go:1.26.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.26.5",
            "tag": "ghcr.io/quenchworks/images/go:1.26.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "gotify",
      "name": "gotify",
      "category": "Messaging",
      "summary": "Self-hosted server for sending and receiving real-time push messages over WebSocket, with a web UI and app tokens. From source (UI embedded, CGO+static-musl SQLite) on a hardened nonroot Wolfi base; data on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.9.1",
      "versions": [
        {
          "version": "2.9.1",
          "size": "13.2 MB",
          "published": "2026-07-21T14:00:46Z",
          "digest": "sha256:af3f894c8baa2f15b95d7fafe687f55960e894cfb9bc7283c0676e5ada858eb5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://gotify.net",
      "source": "https://github.com/gotify/server",
      "image": "ghcr.io/quenchworks/images/gotify",
      "security": {
        "image": "ghcr.io/quenchworks/images/gotify",
        "version": "2.9.1",
        "tag": "ghcr.io/quenchworks/images/gotify:2.9.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/gotify"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.9.1",
            "tag": "ghcr.io/quenchworks/images/gotify:2.9.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/gotify"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "gradle",
      "name": "gradle",
      "category": "Build tool",
      "summary": "JDK base image with Gradle, used as the build stage for Gradle projects; run the resulting jar on jre. Line 9.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "9.6.1",
      "versions": [
        {
          "version": "9.6.1",
          "size": "239.1 MB",
          "published": "2026-07-09T21:39:48Z",
          "digest": "sha256:113a7ff470c6c098b6ee62bfed8f10580ee4e0cd29c42ac82e1d0e260329d433"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://gradle.org",
      "source": "https://gradle.org",
      "image": "ghcr.io/quenchworks/images/gradle",
      "security": {
        "image": "ghcr.io/quenchworks/images/gradle",
        "version": "9.6.1",
        "tag": "ghcr.io/quenchworks/images/gradle:9.6.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.6.1",
            "tag": "ghcr.io/quenchworks/images/gradle:9.6.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "graylog",
      "name": "graylog",
      "category": "Observability",
      "summary": "Graylog, the log-management and analysis server (search, dashboards, alerting, GELF/Beats inputs). Built clean-room on a hardened Wolfi JRE (nonroot, read-only rootfs); the chart provides MongoDB (metadata) and OpenSearch (log storage) backends. Graylog Server is SSPL-1.0 (source-available, not OSI-approved).",
      "tier": "standard",
      "status": "available",
      "license": "SSPL-1.0",
      "licenseClean": "caution",
      "version": "7.1.6",
      "versions": [
        {
          "version": "7.1.6",
          "size": "425.0 MB",
          "published": "2026-07-26T12:26:35Z",
          "digest": "sha256:c151b6b951b1b15a232ad74c839f4cb0603b0020c2721e25baefeffba6053904"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.graylog.org",
      "source": "https://packages.graylog2.org/releases/graylog/graylog",
      "image": "ghcr.io/quenchworks/images/graylog",
      "caution": true,
      "security": {
        "image": "ghcr.io/quenchworks/images/graylog",
        "version": "7.1.6",
        "tag": "ghcr.io/quenchworks/images/graylog:7.1.6",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 0,
        "grade": "C",
        "score": 96,
        "cves": [
          {
            "id": "CVE-2025-48924",
            "severity": "MEDIUM",
            "pkg": "commons-lang:commons-lang",
            "installed": "2.6",
            "fixed": null,
            "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
            "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "7.1.6",
            "tag": "ghcr.io/quenchworks/images/graylog:7.1.6",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 0,
            "grade": "C",
            "score": 96,
            "cves": [
              {
                "id": "CVE-2025-48924",
                "severity": "MEDIUM",
                "pkg": "commons-lang:commons-lang",
                "installed": "2.6",
                "fixed": null,
                "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
                "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "grype",
      "name": "grype",
      "category": "Security & supply chain",
      "summary": "Anchore's vulnerability scanner for container images and filesystems, driven by the same SBOM engine as Syft. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.116.1",
      "versions": [
        {
          "version": "0.116.1",
          "size": "29.8 MB",
          "published": "2026-07-30T08:04:59Z",
          "digest": "sha256:af32102849b3a198457c4dc8329f65b0c872a536e824e01b2f521ad193f57f07"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/anchore/grype",
      "source": "https://github.com/anchore/grype",
      "image": "ghcr.io/quenchworks/images/grype",
      "security": {
        "image": "ghcr.io/quenchworks/images/grype",
        "version": "0.116.0",
        "tag": "ghcr.io/quenchworks/images/grype:0.116.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/grype"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.116.0",
            "tag": "ghcr.io/quenchworks/images/grype:0.116.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/grype"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "haproxy",
      "name": "HAProxy",
      "category": "Gateway",
      "summary": "High-performance TCP and HTTP load balancer and reverse proxy known for reliability and fine-grained traffic control at scale.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0+",
      "licenseClean": "clean",
      "version": "3.3.10, 3.2.19, 3.4.0",
      "versions": [
        {
          "version": "3.3.10",
          "size": "22.1 MB",
          "published": "2026-07-04T11:27:12Z",
          "digest": "sha256:9acd387839807d5d301e913d8a7b26c5711b16a599138105bb89dd5e54086444"
        },
        {
          "version": "3.2.19",
          "size": "20.3 MB",
          "published": "2026-07-04T11:26:43Z",
          "digest": "sha256:897c5270db41b0a44e324f19a57f520515777e0db2f3d30fed5972afc281eff8"
        },
        {
          "version": "3.4.0",
          "size": "23.0 MB",
          "published": "2026-07-04T11:24:16Z",
          "digest": "sha256:e5778500d8bd53a08f37f5471b9672dc9f3c5252e08047a80626ac81669a9d65"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/haproxy/haproxy",
      "source": "https://github.com/haproxy/haproxy",
      "image": "ghcr.io/quenchworks/images/haproxy",
      "security": {
        "image": "ghcr.io/quenchworks/images/haproxy",
        "version": "3.4.0",
        "tag": "ghcr.io/quenchworks/images/haproxy:3.4.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.4.0",
            "tag": "ghcr.io/quenchworks/images/haproxy:3.4.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.3.10",
            "tag": "ghcr.io/quenchworks/images/haproxy:3.3.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.2.19",
            "tag": "ghcr.io/quenchworks/images/haproxy:3.2.19",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "harbor-core",
      "name": "Harbor core",
      "category": "Registry",
      "summary": "Core API server and control plane of the Harbor container registry, handling auth, projects, policies, and orchestration.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "27.8 MB",
          "published": "2026-07-22T06:32:43Z",
          "digest": "sha256:b88bbe17b95132446ff2e2f61e392533410e78f42c36b2bae9afd73a1dc535ab"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-core",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-core",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-core:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 2,
        "low": 0,
        "unknown": 1,
        "total": 5,
        "fixable": 0,
        "grade": "D",
        "score": 70,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "CVE-2025-47909",
            "severity": "MEDIUM",
            "pkg": "github.com/gorilla/csrf",
            "installed": "v1.7.3",
            "fixed": null,
            "title": "Hosts listed in TrustedOrigins implicitly allow requests from the corr ...",
            "url": "https://avd.aquasec.com/nvd/cve-2025-47909",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_core"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/harbor_core"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-core:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 2,
            "low": 0,
            "unknown": 1,
            "total": 5,
            "fixable": 0,
            "grade": "D",
            "score": 70,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "CVE-2025-47909",
                "severity": "MEDIUM",
                "pkg": "github.com/gorilla/csrf",
                "installed": "v1.7.3",
                "fixed": null,
                "title": "Hosts listed in TrustedOrigins implicitly allow requests from the corr ...",
                "url": "https://avd.aquasec.com/nvd/cve-2025-47909",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/harbor_core"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-exporter",
      "name": "Harbor exporter",
      "category": "Registry",
      "summary": "Prometheus exporter that exposes Harbor registry health and usage metrics for monitoring.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "14.7 MB",
          "published": "2026-07-22T06:59:40Z",
          "digest": "sha256:a86587c1947e98144a194d2c763a9b77bdcfbbbab8a581b5464906577b3a322f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-exporter",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-exporter:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 0,
        "grade": "D",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_exporter"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_exporter"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-exporter:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 0,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_exporter"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_exporter"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-jobservice",
      "name": "Harbor jobservice",
      "category": "Registry",
      "summary": "Harbor's asynchronous job runner that executes replication, garbage collection, and image-scan tasks in the background.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "19.0 MB",
          "published": "2026-07-22T06:59:32Z",
          "digest": "sha256:16fa1fee1647bf06b202fd0472619561bafb64245566ce7e41f316052e21f0db"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-jobservice",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-jobservice",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-jobservice:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 3,
        "fixable": 0,
        "grade": "D",
        "score": 76,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_jobservice"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_jobservice"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_jobservice"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-jobservice:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 3,
            "fixable": 0,
            "grade": "D",
            "score": 76,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_jobservice"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_jobservice"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_jobservice"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-portal",
      "name": "Harbor portal",
      "category": "Registry",
      "summary": "Web UI for the Harbor container registry, serving the management dashboard for projects, repositories, and scan results.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "13.7 MB",
          "published": "2026-07-05T10:10:48Z",
          "digest": "sha256:85809ac40b4f954149daa33a5abde6c62109e199dbe99afbf07a48d7e4bb41ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-portal",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-portal",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-portal:2.15.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-portal:2.15.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "harbor-registry",
      "name": "Harbor registry",
      "category": "Registry",
      "summary": "OCI registry storage backend (Docker distribution) that stores and serves image layers and manifests for Harbor.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "12.6 MB",
          "published": "2026-07-22T08:28:17Z",
          "digest": "sha256:12dfcdb69c837af571beb647aeebba4d1443d7445eec225dd58d77c85ad76f17"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/distribution",
      "source": "https://github.com/goharbor/distribution",
      "image": "ghcr.io/quenchworks/images/harbor-registry",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-registry",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-registry:2.15.2",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2020-26160",
            "severity": "HIGH",
            "pkg": "github.com/dgrijalva/jwt-go",
            "installed": "v3.2.0+incompatible",
            "fixed": null,
            "title": "jwt-go: access restriction bypass vulnerability",
            "url": "https://avd.aquasec.com/nvd/cve-2020-26160",
            "targets": [
              "usr/bin/registry"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/registry"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-registry:2.15.2",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2020-26160",
                "severity": "HIGH",
                "pkg": "github.com/dgrijalva/jwt-go",
                "installed": "v3.2.0+incompatible",
                "fixed": null,
                "title": "jwt-go: access restriction bypass vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2020-26160",
                "targets": [
                  "usr/bin/registry"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/registry"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-registryctl",
      "name": "Harbor registryctl",
      "category": "Registry",
      "summary": "Harbor registry controller that manages garbage collection and registry storage lifecycle operations alongside the registry backend.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "13.0 MB",
          "published": "2026-07-22T06:58:43Z",
          "digest": "sha256:66e216f38986539bfb88cc48f03fc8dbd9a0afc9665e84ced32714f6de00b0d9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor",
      "source": "https://github.com/goharbor/harbor",
      "image": "ghcr.io/quenchworks/images/harbor-registryctl",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-registryctl",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-registryctl:2.15.2",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 4,
        "fixable": 0,
        "grade": "D",
        "score": 74,
        "cves": [
          {
            "id": "CVE-2026-33540",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
            "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          },
          {
            "id": "CVE-2026-35172",
            "severity": "HIGH",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          },
          {
            "id": "CVE-2026-41888",
            "severity": "MEDIUM",
            "pkg": "github.com/distribution/distribution",
            "installed": "v2.8.2+incompatible",
            "fixed": null,
            "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
            "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/harbor_registryctl"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-registryctl:2.15.2",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 4,
            "fixable": 0,
            "grade": "D",
            "score": 74,
            "cves": [
              {
                "id": "CVE-2026-33540",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via improper validation of authentication realm URL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33540",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              },
              {
                "id": "CVE-2026-35172",
                "severity": "HIGH",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-35172",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              },
              {
                "id": "CVE-2026-41888",
                "severity": "MEDIUM",
                "pkg": "github.com/distribution/distribution",
                "installed": "v2.8.2+incompatible",
                "fixed": null,
                "title": "github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41888",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/harbor_registryctl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "harbor-trivy-adapter",
      "name": "Harbor trivy-adapter",
      "category": "Registry",
      "summary": "Harbor vulnerability-scan adapter backed by Trivy, scanning pushed images for CVEs and reporting results into Harbor.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.15.2",
      "versions": [
        {
          "version": "2.15.2",
          "size": "80.0 MB",
          "published": "2026-07-22T09:02:43Z",
          "digest": "sha256:7121073c40eed52c7a268f82fcb16893b8788a8f18b1643807677de606b6900c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/goharbor/harbor-scanner-trivy",
      "source": "https://github.com/goharbor/harbor-scanner-trivy",
      "image": "ghcr.io/quenchworks/images/harbor-trivy-adapter",
      "security": {
        "image": "ghcr.io/quenchworks/images/harbor-trivy-adapter",
        "version": "2.15.2",
        "tag": "ghcr.io/quenchworks/images/harbor-trivy-adapter:2.15.2",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/trivy"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.15.2",
            "tag": "ghcr.io/quenchworks/images/harbor-trivy-adapter:2.15.2",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/trivy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "headscale",
      "name": "headscale",
      "category": "Coordination & mesh",
      "summary": "Open-source, self-hosted implementation of the Tailscale control server for coordinating a WireGuard mesh. Single static Go binary on a hardened nonroot Wolfi base; config and state on writable volumes.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "0.29.2",
      "versions": [
        {
          "version": "0.29.2",
          "size": "19.9 MB",
          "published": "2026-07-22T07:02:13Z",
          "digest": "sha256:84fdca10e8e309e0ccae939a07a961fc9e18a63925d4cc8b6aeed9bbdb81afe0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/juanfont/headscale",
      "source": "https://github.com/juanfont/headscale",
      "image": "ghcr.io/quenchworks/images/headscale",
      "security": {
        "image": "ghcr.io/quenchworks/images/headscale",
        "version": "0.29.2",
        "tag": "ghcr.io/quenchworks/images/headscale:0.29.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/headscale"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.29.2",
            "tag": "ghcr.io/quenchworks/images/headscale:0.29.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/headscale"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "httpd",
      "name": "httpd",
      "category": "Gateway",
      "summary": "Apache HTTP Server, the long-standing open-source web server and reverse proxy for serving static content and fronting application backends (mod_proxy).",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.4.68",
      "versions": [
        {
          "version": "2.4.68",
          "size": "34.5 MB",
          "published": "2026-07-21T13:43:57Z",
          "digest": "sha256:9e886be8fb82062f440fbd46e92ade34b465a4c5103dbc91041efd7a43be1efc"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/httpd",
      "source": "https://downloads.apache.org/httpd/",
      "image": "ghcr.io/quenchworks/images/httpd",
      "security": {
        "image": "ghcr.io/quenchworks/images/httpd",
        "version": "2.4.68",
        "tag": "ghcr.io/quenchworks/images/httpd:2.4.68",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.4.68",
            "tag": "ghcr.io/quenchworks/images/httpd:2.4.68",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "influxdb",
      "name": "InfluxDB",
      "category": "Time series",
      "summary": "Time-series database purpose-built for ingesting and querying metrics, events, and IoT/sensor data at high write rates.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.9.1",
      "versions": [
        {
          "version": "2.9.1",
          "size": "55.2 MB",
          "published": "2026-07-22T07:36:38Z",
          "digest": "sha256:fc6dc0f07e9f900fb698b24a8a1cc751aa971fb4c473f41f0f2c7c8bfa25c2aa"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/influxdata/influxdb",
      "source": "https://github.com/influxdata/influxdb",
      "image": "ghcr.io/quenchworks/images/influxdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/influxdb",
        "version": "2.9.1",
        "tag": "ghcr.io/quenchworks/images/influxdb:2.9.1",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "C",
        "score": 94,
        "cves": [
          {
            "id": "CVE-2024-28180",
            "severity": "MEDIUM",
            "pkg": "gopkg.in/square/go-jose.v2",
            "installed": "v2.5.1",
            "fixed": null,
            "title": "jose-go: improper handling of highly compressed data",
            "url": "https://avd.aquasec.com/nvd/cve-2024-28180",
            "targets": [
              "usr/bin/influxd"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/influxd"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.9.1",
            "tag": "ghcr.io/quenchworks/images/influxdb:2.9.1",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "C",
            "score": 94,
            "cves": [
              {
                "id": "CVE-2024-28180",
                "severity": "MEDIUM",
                "pkg": "gopkg.in/square/go-jose.v2",
                "installed": "v2.5.1",
                "fixed": null,
                "title": "jose-go: improper handling of highly compressed data",
                "url": "https://avd.aquasec.com/nvd/cve-2024-28180",
                "targets": [
                  "usr/bin/influxd"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/influxd"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ingress-nginx",
      "name": "ingress-nginx",
      "category": "Gateway",
      "summary": "The Kubernetes NGINX Ingress Controller. Routes external HTTP/HTTPS traffic to in-cluster Services via Ingress resources, with TLS termination, path/host routing, and an admission webhook. The chart wires its RBAC, IngressClass, and webhook.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.15.8",
      "versions": [
        {
          "version": "1.15.8",
          "size": "79.8 MB",
          "published": "2026-07-28T06:16:54Z",
          "digest": "sha256:3f88b7c56cf30d630f367c0175477af5ac406a1145a7d3d0225a8c53f23e99b8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kubernetes.github.io/ingress-nginx",
      "source": "https://github.com/kubernetes/ingress-nginx",
      "image": "ghcr.io/quenchworks/images/ingress-nginx",
      "security": {
        "image": "ghcr.io/quenchworks/images/ingress-nginx",
        "version": "1.15.8",
        "tag": "ghcr.io/quenchworks/images/ingress-nginx:1.15.8",
        "critical": 0,
        "high": 2,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 4,
        "fixable": 4,
        "grade": "D",
        "score": 56,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.37.0",
            "fixed": "0.39.0",
            "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/nginx-ingress-controller",
              "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/nginx-ingress-controller",
              "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.15.8",
            "tag": "ghcr.io/quenchworks/images/ingress-nginx:1.15.8",
            "critical": 0,
            "high": 2,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 4,
            "fixable": 4,
            "grade": "D",
            "score": 56,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.37.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/nginx-ingress-controller",
                  "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/nginx-ingress-controller",
                  "var/lib/db/sbom/ingress-nginx-controller-1.15-1.15.8-r8.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jaeger",
      "name": "jaeger",
      "category": "Observability",
      "summary": "Distributed tracing platform (Jaeger v2, OpenTelemetry-collector based) with an embedded query UI. From source on a hardened nonroot Wolfi base; in-memory storage by default, badger under a volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.19.0",
      "versions": [
        {
          "version": "2.19.0",
          "size": "28.1 MB",
          "published": "2026-07-22T07:02:27Z",
          "digest": "sha256:c7584ec45b12de93b944adc4b5d436019751ff99bab346a36e3fac786fecd274"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.jaegertracing.io",
      "source": "https://github.com/jaegertracing/jaeger",
      "image": "ghcr.io/quenchworks/images/jaeger",
      "security": {
        "image": "ghcr.io/quenchworks/images/jaeger",
        "version": "2.19.0",
        "tag": "ghcr.io/quenchworks/images/jaeger:2.19.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/jaeger"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.19.0",
            "tag": "ghcr.io/quenchworks/images/jaeger:2.19.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/jaeger"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jdk",
      "name": "jdk",
      "category": "Language runtime",
      "summary": "Hardened OpenJDK with the javac compiler, a build-stage base image to FROM for Java apps. LTS lines 17/21/25.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0-with-classpath-exception",
      "licenseClean": "clean",
      "version": "17.0.19, 21.0.11, 25.0.4",
      "versions": [
        {
          "version": "17.0.19",
          "size": "93.8 MB",
          "published": "2026-07-26T12:35:31Z",
          "digest": "sha256:8adc5957d829af58f9c3dc24004cf037ea8ba0d18276e2c5910928ebf6061509"
        },
        {
          "version": "21.0.11",
          "size": "100.6 MB",
          "published": "2026-07-26T12:35:21Z",
          "digest": "sha256:63dc4ab9e7013a36142f89fcb3b2824007d0498a9bc3104c76802ea3f8a24530"
        },
        {
          "version": "25.0.4",
          "size": "112.1 MB",
          "published": "2026-07-26T12:30:10Z",
          "digest": "sha256:457e9b526d7806bed3054407008fc1c790c032e0d361888450fc92b77cced99b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://openjdk.org",
      "source": "https://openjdk.org",
      "image": "ghcr.io/quenchworks/images/jdk",
      "security": {
        "image": "ghcr.io/quenchworks/images/jdk",
        "version": "25.0.4",
        "tag": "ghcr.io/quenchworks/images/jdk:25.0.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "25.0.4",
            "tag": "ghcr.io/quenchworks/images/jdk:25.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "21.0.11",
            "tag": "ghcr.io/quenchworks/images/jdk:21.0.11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "17.0.19",
            "tag": "ghcr.io/quenchworks/images/jdk:17.0.19",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "jenkins",
      "name": "jenkins",
      "category": "CI/CD & registry",
      "summary": "The leading open-source automation server for building, testing, and deploying software, with thousands of plugins. Ships the architecture-independent jenkins.war LTS line on a hardened Wolfi JRE.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.572",
      "versions": [
        {
          "version": "2.572",
          "size": "171.4 MB",
          "published": "2026-07-09T23:43:11Z",
          "digest": "sha256:ba641c1981ee3c70c53ae0e1fd2dc84a8f0794a3a6da0f425b5605ac4708cd25"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.jenkins.io",
      "source": "https://github.com/jenkinsci/jenkins",
      "image": "ghcr.io/quenchworks/images/jenkins",
      "security": {
        "image": "ghcr.io/quenchworks/images/jenkins",
        "version": "2.572",
        "tag": "ghcr.io/quenchworks/images/jenkins:2.572",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 0,
        "grade": "C",
        "score": 96,
        "cves": [
          {
            "id": "CVE-2025-48924",
            "severity": "MEDIUM",
            "pkg": "commons-lang:commons-lang",
            "installed": "2.6",
            "fixed": null,
            "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
            "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.572",
            "tag": "ghcr.io/quenchworks/images/jenkins:2.572",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 0,
            "grade": "C",
            "score": 96,
            "cves": [
              {
                "id": "CVE-2025-48924",
                "severity": "MEDIUM",
                "pkg": "commons-lang:commons-lang",
                "installed": "2.6",
                "fixed": null,
                "title": "commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang",
                "url": "https://avd.aquasec.com/nvd/cve-2025-48924",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "jenkins-inbound-agent",
      "name": "jenkins-inbound-agent",
      "category": "CI/CD & registry",
      "summary": "Jenkins inbound (JNLP/websocket) build agent — the remoting agent.jar plus launch script on a hardened Wolfi JRE, connecting back to a Jenkins controller to run builds. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.jenkins.io",
      "source": "https://github.com/jenkinsci/remoting",
      "image": "ghcr.io/quenchworks/images/jenkins-inbound-agent",
      "security": null
    },
    {
      "slug": "jmeter",
      "name": "jmeter",
      "category": "Observability",
      "summary": "Apache JMeter load-testing and performance-measurement tool, the official binary distribution running on a hardened Wolfi JRE. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "5.6.3",
      "versions": [
        {
          "version": "5.6.3",
          "size": "140.2 MB",
          "published": "2026-07-09T16:34:34Z",
          "digest": "sha256:ea5b54a97c6f2cf119ff02b48c2e515afd4c33d0fba7a1bf31012c3024307b5f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://jmeter.apache.org",
      "source": "https://github.com/apache/jmeter",
      "image": "ghcr.io/quenchworks/images/jmeter",
      "security": {
        "image": "ghcr.io/quenchworks/images/jmeter",
        "version": "5.6.3",
        "tag": "ghcr.io/quenchworks/images/jmeter:5.6.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.6.3",
            "tag": "ghcr.io/quenchworks/images/jmeter:5.6.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "jre",
      "name": "jre",
      "category": "Runtime base",
      "summary": "Hardened Java runtime (JRE) for running a built jar, no compiler. Pair with the jdk, maven, or gradle build image. LTS lines 17/21/25.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0-with-classpath-exception",
      "licenseClean": "clean",
      "version": "21.0.11, 17.0.19, 25.0.4",
      "versions": [
        {
          "version": "21.0.11",
          "size": "74.6 MB",
          "published": "2026-07-26T12:27:43Z",
          "digest": "sha256:6e48c46a9d81903bdd5d8f0cd117fcc0a0e02e93f3b5aa055c14391e145f2597"
        },
        {
          "version": "17.0.19",
          "size": "68.5 MB",
          "published": "2026-07-26T12:27:06Z",
          "digest": "sha256:b95cc91f36cb8882f3a6e667ea1646d2bce622fd8696fb1501310d58ce7a84ea"
        },
        {
          "version": "25.0.4",
          "size": "83.2 MB",
          "published": "2026-07-26T12:23:43Z",
          "digest": "sha256:6eef69de22c7b3cca358a6984a50bd993bb17f948a47241ba3b5834c6153965d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://openjdk.org",
      "source": "https://openjdk.org",
      "image": "ghcr.io/quenchworks/images/jre",
      "security": {
        "image": "ghcr.io/quenchworks/images/jre",
        "version": "25.0.4",
        "tag": "ghcr.io/quenchworks/images/jre:25.0.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "25.0.4",
            "tag": "ghcr.io/quenchworks/images/jre:25.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "21.0.11",
            "tag": "ghcr.io/quenchworks/images/jre:21.0.11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "17.0.19",
            "tag": "ghcr.io/quenchworks/images/jre:17.0.19",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "k6",
      "name": "k6",
      "category": "Observability",
      "summary": "Developer-friendly load and performance testing tool scripted in JavaScript. Single static Go binary on a hardened nonroot Wolfi base; test scripts are mounted at runtime.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2.1.0",
      "versions": [
        {
          "version": "2.1.0",
          "size": "16.6 MB",
          "published": "2026-07-22T07:21:44Z",
          "digest": "sha256:e05cde371e5d8c0a4850455e10545fc2b38ff6daa0e0c7ddfa9a735ccc69b8aa"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://k6.io",
      "source": "https://github.com/grafana/k6",
      "image": "ghcr.io/quenchworks/images/k6",
      "security": {
        "image": "ghcr.io/quenchworks/images/k6",
        "version": "2.1.0",
        "tag": "ghcr.io/quenchworks/images/k6:2.1.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/k6"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/k6:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/k6"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kafka",
      "name": "Kafka",
      "category": "Messaging",
      "summary": "Distributed event-streaming platform for high-throughput, durable, replayable publish-subscribe pipelines and stream processing.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.3.1",
      "versions": [
        {
          "version": "4.3.1",
          "size": "204.3 MB",
          "published": "2026-07-28T06:52:03Z",
          "digest": "sha256:494e320e90e532f34b5ae0135c60d3567e55e031fb023a4f4085beb6b1772039"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/kafka",
      "source": "https://archive.apache.org/dist/kafka/4.3.0/kafka_2.13-4.3.0.tgz",
      "image": "ghcr.io/quenchworks/images/kafka",
      "security": {
        "image": "ghcr.io/quenchworks/images/kafka",
        "version": "4.3.1",
        "tag": "ghcr.io/quenchworks/images/kafka:4.3.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.3.1",
            "tag": "ghcr.io/quenchworks/images/kafka:4.3.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "keda",
      "name": "keda",
      "category": "Coordination",
      "summary": "Kubernetes event-driven autoscaler that scales workloads based on external event sources (queues, streams, metrics). Ships the operator and metrics adapter as static Go binaries on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.20.1",
      "versions": [
        {
          "version": "2.20.1",
          "size": "79.8 MB",
          "published": "2026-07-26T12:26:29Z",
          "digest": "sha256:c4e008de38998bb0e0590a247c326d7346d756b0fcb9ec71a698f8df637ffb1f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://keda.sh",
      "source": "https://github.com/kedacore/keda",
      "image": "ghcr.io/quenchworks/images/keda",
      "security": {
        "image": "ghcr.io/quenchworks/images/keda",
        "version": "2.20.1",
        "tag": "ghcr.io/quenchworks/images/keda:2.20.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/keda",
              "usr/bin/keda-adapter"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.20.1",
            "tag": "ghcr.io/quenchworks/images/keda:2.20.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/keda",
                  "usr/bin/keda-adapter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "keycloak",
      "name": "Keycloak",
      "category": "Identity",
      "summary": "Open-source identity and access management server providing SSO, user federation, and OAuth2/OIDC and SAML for apps and APIs.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "26.7.0",
      "versions": [
        {
          "version": "26.7.0",
          "size": "231.6 MB",
          "published": "2026-07-28T06:23:01Z",
          "digest": "sha256:fbb91104b4da73ca9f3117874fb1c343dd208e9ea5a25e118c0d10f5f28a8db2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/keycloak/keycloak",
      "source": "https://github.com/keycloak/keycloak",
      "image": "ghcr.io/quenchworks/images/keycloak",
      "security": {
        "image": "ghcr.io/quenchworks/images/keycloak",
        "version": "26.7.0",
        "tag": "ghcr.io/quenchworks/images/keycloak:26.7.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "26.7.0",
            "tag": "ghcr.io/quenchworks/images/keycloak:26.7.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "kube-state-metrics",
      "name": "kube-state-metrics",
      "category": "Observability",
      "summary": "Exposes the state of Kubernetes objects as Prometheus metrics for dashboards and alerts. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.18.0, 2.17.0, 2.19.1",
      "versions": [
        {
          "version": "2.18.0",
          "size": "18.8 MB",
          "published": "2026-07-26T12:29:07Z",
          "digest": "sha256:07a7ea22df6f6a39e75a92c58716d5b4e63bcd797bb896e8edb60037d05826f4"
        },
        {
          "version": "2.17.0",
          "size": "18.8 MB",
          "published": "2026-07-26T12:27:40Z",
          "digest": "sha256:7af4e77d5068075504d071323e297c5b9140ab3cebe03d93d9fe7d483d074fd5"
        },
        {
          "version": "2.19.1",
          "size": "18.2 MB",
          "published": "2026-07-26T12:27:25Z",
          "digest": "sha256:6785c8b5b673e5844c281afe37a86e4352b6c8663d24ef8e585649a3de50e471"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/kubernetes/kube-state-metrics",
      "source": "https://github.com/kubernetes/kube-state-metrics",
      "image": "ghcr.io/quenchworks/images/kube-state-metrics",
      "security": {
        "image": "ghcr.io/quenchworks/images/kube-state-metrics",
        "version": "2.19.1",
        "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.19.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/kube-state-metrics"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.19.1",
            "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.19.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kube-state-metrics"
                ]
              }
            ]
          },
          {
            "version": "2.18.0",
            "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.18.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kube-state-metrics"
                ]
              }
            ]
          },
          {
            "version": "2.17.0",
            "tag": "ghcr.io/quenchworks/images/kube-state-metrics:2.17.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kube-state-metrics"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kubectl",
      "name": "kubectl",
      "category": "CI/CD & registry",
      "summary": "Hardened kubectl image with the common cluster toolbelt (helm, kustomize, jq, a busybox shell) — the 0-CVE answer to alpine/k8s and bitnami/kubectl for CI jobs and in-cluster tooling. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.34.10, 1.36.3",
      "versions": [
        {
          "version": "1.34.10",
          "size": "61.7 MB",
          "published": "2026-07-28T06:48:13Z",
          "digest": "sha256:c7623897a0b29b82eb0d1a8e322caa3d84376c6cccbf6bf2dc8ca70045066ebd"
        },
        {
          "version": "1.36.3",
          "size": "61.3 MB",
          "published": "2026-07-26T12:33:36Z",
          "digest": "sha256:44a86469299c7f7e56e1fbe93c67106004fec0d7b2f764ccc9cc026b5e299705"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kubernetes.io",
      "source": "https://github.com/kubernetes/kubernetes",
      "image": "ghcr.io/quenchworks/images/kubectl",
      "security": {
        "image": "ghcr.io/quenchworks/images/kubectl",
        "version": "1.36.3",
        "tag": "ghcr.io/quenchworks/images/kubectl:1.36.3",
        "critical": 0,
        "high": 2,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 4,
        "fixable": 2,
        "grade": "D",
        "score": 66,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.38.0",
            "fixed": "0.39.0",
            "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/kubectl-1.36",
              "var/lib/db/sbom/kubectl-1.36-1.36.3-r1.spdx.json"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/helm",
              "var/lib/db/sbom/helm-4-4.2.3-r1.spdx.json"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.36.3",
            "tag": "ghcr.io/quenchworks/images/kubectl:1.36.3",
            "critical": 0,
            "high": 2,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 4,
            "fixable": 2,
            "grade": "D",
            "score": 66,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/kubectl-1.36",
                  "var/lib/db/sbom/kubectl-1.36-1.36.3-r1.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/helm",
                  "var/lib/db/sbom/helm-4-4.2.3-r1.spdx.json"
                ]
              }
            ]
          },
          {
            "version": "1.34.10",
            "tag": "ghcr.io/quenchworks/images/kubectl:1.34.10",
            "critical": 0,
            "high": 3,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 5,
            "fixable": 3,
            "grade": "D",
            "score": 51,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "kubectl-1.34",
                "installed": "1.34.10-r2",
                "fixed": "1.34.10-r3",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "ghcr.io/quenchworks/images/kubectl@sha256:c7623897a0b29b82eb0d1a8e322caa3d84376c6cccbf6bf2dc8ca70045066ebd (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/kubectl-1.34",
                  "var/lib/db/sbom/kubectl-1.34-1.34.10-r2.spdx.json"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/helm",
                  "var/lib/db/sbom/helm-4-4.2.3-r1.spdx.json"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kuma",
      "name": "kuma",
      "category": "Coordination & mesh",
      "summary": "CNCF service mesh control plane (Envoy-based) for multi-zone and multi-cluster meshes. Ships kuma-cp and kumactl with an embedded GUI, built from source on a hardened nonroot Wolfi base; default in-memory store runs standalone.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.14.0",
      "versions": [
        {
          "version": "2.14.0",
          "size": "62.5 MB",
          "published": "2026-07-26T12:26:51Z",
          "digest": "sha256:3ccbf3268792cd2500ff68851c008c995ba4e881679524bc63280130f0480cb4"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kuma.io",
      "source": "https://github.com/kumahq/kuma",
      "image": "ghcr.io/quenchworks/images/kuma",
      "security": {
        "image": "ghcr.io/quenchworks/images/kuma",
        "version": "2.14.0",
        "tag": "ghcr.io/quenchworks/images/kuma:2.14.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/kuma-cp",
              "usr/bin/kumactl"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.14.0",
            "tag": "ghcr.io/quenchworks/images/kuma:2.14.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/kuma-cp",
                  "usr/bin/kumactl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "kyverno",
      "name": "kyverno",
      "category": "Security & supply chain",
      "summary": "Kubernetes-native policy engine for validating, mutating, and generating resources with no new language. Ships the controllers and CLI as static Go binaries on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.1",
      "versions": [
        {
          "version": "1.18.1",
          "size": "253.3 MB",
          "published": "2026-07-26T12:32:48Z",
          "digest": "sha256:299a9ca690cdeb7ebe223172bed559e96280472948af0f64b0ac71e01abf0abd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://kyverno.io",
      "source": "https://github.com/kyverno/kyverno",
      "image": "ghcr.io/quenchworks/images/kyverno",
      "security": {
        "image": "ghcr.io/quenchworks/images/kyverno",
        "version": "1.18.1",
        "tag": "ghcr.io/quenchworks/images/kyverno:1.18.1",
        "critical": 0,
        "high": 6,
        "medium": 0,
        "low": 0,
        "unknown": 6,
        "total": 12,
        "fixable": 0,
        "grade": "D",
        "score": 28,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/background-controller",
              "usr/bin/cleanup-controller",
              "usr/bin/kubectl-kyverno",
              "usr/bin/kyverno",
              "usr/bin/kyvernopre",
              "usr/bin/reports-controller"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/background-controller",
              "usr/bin/cleanup-controller",
              "usr/bin/kubectl-kyverno",
              "usr/bin/kyverno",
              "usr/bin/kyvernopre",
              "usr/bin/reports-controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.18.1",
            "tag": "ghcr.io/quenchworks/images/kyverno:1.18.1",
            "critical": 0,
            "high": 6,
            "medium": 0,
            "low": 0,
            "unknown": 6,
            "total": 12,
            "fixable": 0,
            "grade": "D",
            "score": 28,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/background-controller",
                  "usr/bin/cleanup-controller",
                  "usr/bin/kubectl-kyverno",
                  "usr/bin/kyverno",
                  "usr/bin/kyvernopre",
                  "usr/bin/reports-controller"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/background-controller",
                  "usr/bin/cleanup-controller",
                  "usr/bin/kubectl-kyverno",
                  "usr/bin/kyverno",
                  "usr/bin/kyvernopre",
                  "usr/bin/reports-controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "litestream",
      "name": "litestream",
      "category": "Storage & platform",
      "summary": "Streaming replication for SQLite databases to object storage such as S3, GCS, and Azure. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.5.15",
      "versions": [
        {
          "version": "0.5.15",
          "size": "16.9 MB",
          "published": "2026-07-22T11:29:05Z",
          "digest": "sha256:d49434ed72a38e01b27780779a1a5ed11751295ca0472d62c5a5a2c61c0d8549"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://litestream.io",
      "source": "https://github.com/benbjohnson/litestream",
      "image": "ghcr.io/quenchworks/images/litestream",
      "security": {
        "image": "ghcr.io/quenchworks/images/litestream",
        "version": "0.5.15",
        "tag": "ghcr.io/quenchworks/images/litestream:0.5.15",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/litestream"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.5.15",
            "tag": "ghcr.io/quenchworks/images/litestream:0.5.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/litestream"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "livekit",
      "name": "livekit",
      "category": "Media & streaming",
      "summary": "WebRTC SFU server for scalable real-time audio, video, and data. Single static Go binary on a hardened nonroot Wolfi base; config via mounted YAML or LIVEKIT_ env.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.13.4",
      "versions": [
        {
          "version": "1.13.4",
          "size": "18.0 MB",
          "published": "2026-07-26T12:26:49Z",
          "digest": "sha256:6fd6e07ed2927bdae925ad694f5c557beebc28f27cd533c50ca14d164de2c316"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://livekit.io",
      "source": "https://github.com/livekit/livekit",
      "image": "ghcr.io/quenchworks/images/livekit",
      "security": {
        "image": "ghcr.io/quenchworks/images/livekit",
        "version": "1.13.4",
        "tag": "ghcr.io/quenchworks/images/livekit:1.13.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/livekit-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.13.4",
            "tag": "ghcr.io/quenchworks/images/livekit:1.13.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/livekit-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "loki",
      "name": "Loki",
      "category": "Observability",
      "summary": "Horizontally scalable log aggregation system from Grafana that indexes only labels, not full log text. Like Prometheus, but for logs. Licensed AGPL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "3.7.4",
      "versions": [
        {
          "version": "3.7.4",
          "size": "88.1 MB",
          "published": "2026-07-26T12:27:05Z",
          "digest": "sha256:8ad6b4a777ce3b35eec4b51cb61fe2e703a4404134391d723aee1a0c6a73431f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/grafana/loki",
      "source": "https://github.com/grafana/loki",
      "image": "ghcr.io/quenchworks/images/loki",
      "security": {
        "image": "ghcr.io/quenchworks/images/loki",
        "version": "3.7.4",
        "tag": "ghcr.io/quenchworks/images/loki:3.7.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/logcli",
              "usr/bin/loki"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.4",
            "tag": "ghcr.io/quenchworks/images/loki:3.7.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/logcli",
                  "usr/bin/loki"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mailpit",
      "name": "mailpit",
      "category": "Apps & productivity",
      "summary": "Email and SMTP testing tool with a web UI for capturing and inspecting messages during development. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.30.6",
      "versions": [
        {
          "version": "1.30.6",
          "size": "9.3 MB",
          "published": "2026-07-28T09:48:56Z",
          "digest": "sha256:36b2c7470826961182094048c009d112b4998f5d71559cab8243696d3c9e6416"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mailpit.axllent.org",
      "source": "https://github.com/axllent/mailpit",
      "image": "ghcr.io/quenchworks/images/mailpit",
      "security": {
        "image": "ghcr.io/quenchworks/images/mailpit",
        "version": "1.30.6",
        "tag": "ghcr.io/quenchworks/images/mailpit:1.30.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/mailpit"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.30.6",
            "tag": "ghcr.io/quenchworks/images/mailpit:1.30.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/mailpit"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mariadb",
      "name": "MariaDB",
      "category": "Relational",
      "summary": "Community-developed relational database and drop-in MySQL successor, GPL-licensed and fully open. Default MySQL-compatible engine for the catalog.",
      "tier": "critical",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "11.8.8, 12.3.2, 11.4.12",
      "versions": [
        {
          "version": "11.8.8",
          "size": "116.0 MB",
          "published": "2026-07-28T06:44:29Z",
          "digest": "sha256:fc26a36e421363f7426951407c93cf94d834786cd19356fdcd1b08e83717beab"
        },
        {
          "version": "12.3.2",
          "size": "117.9 MB",
          "published": "2026-07-28T06:44:29Z",
          "digest": "sha256:de7f6d2143a534b7882d292a494f359bf4c7003b8f12598a97a424a1d5da354d"
        },
        {
          "version": "11.4.12",
          "size": "114.7 MB",
          "published": "2026-07-28T06:44:25Z",
          "digest": "sha256:3f110a0686888b1fd21f49cf17bcab66562bf12a4033d0c09e1d6fe000dd4b44"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/MariaDB/server",
      "source": "https://archive.mariadb.org/mariadb-11.8.8/source/mariadb-11.8.8.tar.gz",
      "image": "ghcr.io/quenchworks/images/mariadb",
      "security": {
        "image": "ghcr.io/quenchworks/images/mariadb",
        "version": "12.3.2",
        "tag": "ghcr.io/quenchworks/images/mariadb:12.3.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "12.3.2",
            "tag": "ghcr.io/quenchworks/images/mariadb:12.3.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "11.8.8",
            "tag": "ghcr.io/quenchworks/images/mariadb:11.8.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "11.4.12",
            "tag": "ghcr.io/quenchworks/images/mariadb:11.4.12",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mattermost",
      "name": "mattermost",
      "category": "Messaging",
      "summary": "Open-source, self-hosted team messaging and collaboration platform (a Slack alternative) with channels, direct messages, file sharing, and integrations. Packaged from Mattermost's official Team Edition server release; requires an external PostgreSQL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "11.9.0",
      "versions": [
        {
          "version": "11.9.0",
          "size": "403.6 MB",
          "published": "2026-07-22T08:40:53Z",
          "digest": "sha256:fbd623821cab4daadfbedfdebad2235e20d6f646824c2c3bcafaf9a54aa2d3a6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mattermost.com",
      "source": "https://github.com/mattermost/mattermost",
      "image": "ghcr.io/quenchworks/images/mattermost",
      "security": {
        "image": "ghcr.io/quenchworks/images/mattermost",
        "version": "11.9.0",
        "tag": "ghcr.io/quenchworks/images/mattermost:11.9.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "opt/mattermost/bin/mattermost",
              "opt/mattermost/bin/mmctl"
            ]
          }
        ],
        "versions": [
          {
            "version": "11.9.0",
            "tag": "ghcr.io/quenchworks/images/mattermost:11.9.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "opt/mattermost/bin/mattermost",
                  "opt/mattermost/bin/mmctl"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "maven",
      "name": "maven",
      "category": "Build tool",
      "summary": "JDK base image with Apache Maven, used as the build stage for Maven projects; run the resulting jar on jre. Line 3.9.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.9.15, 3.9.14, 3.9.16",
      "versions": [
        {
          "version": "3.9.15",
          "size": "110.0 MB",
          "published": "2026-07-04T11:30:19Z",
          "digest": "sha256:c8dd0cff480ad43d8caefd24ae3e71dd7319db28b88347e42c3cfbba69ae1794"
        },
        {
          "version": "3.9.14",
          "size": "110.0 MB",
          "published": "2026-07-04T11:27:46Z",
          "digest": "sha256:6c7502b89bdbf51aea1cb5337ccbe1c3c10d31fcb06e63e43037b5dcc115409e"
        },
        {
          "version": "3.9.16",
          "size": "110.1 MB",
          "published": "2026-07-04T11:10:50Z",
          "digest": "sha256:cb1f3d902c0530209185075f1eaf60609d6a5e9c6a16c846b989e64953389c38"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://maven.apache.org",
      "source": "https://maven.apache.org",
      "image": "ghcr.io/quenchworks/images/maven",
      "security": {
        "image": "ghcr.io/quenchworks/images/maven",
        "version": "3.9.16",
        "tag": "ghcr.io/quenchworks/images/maven:3.9.16",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.9.16",
            "tag": "ghcr.io/quenchworks/images/maven:3.9.16",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.9.15",
            "tag": "ghcr.io/quenchworks/images/maven:3.9.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.9.14",
            "tag": "ghcr.io/quenchworks/images/maven:3.9.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mediamtx",
      "name": "mediamtx",
      "category": "Media & streaming",
      "summary": "Real-time media server and proxy for RTSP, RTMP, HLS, WebRTC, and SRT. Single static Go binary on a hardened nonroot Wolfi base; config via a mounted mediamtx.yml.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.19.3",
      "versions": [
        {
          "version": "1.19.3",
          "size": "17.7 MB",
          "published": "2026-07-26T12:32:18Z",
          "digest": "sha256:a35e28d544b8fe20c804b51645af9b0646c6d58d4bff399c28d5edac5476b56b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/bluenviron/mediamtx",
      "source": "https://github.com/bluenviron/mediamtx",
      "image": "ghcr.io/quenchworks/images/mediamtx",
      "security": {
        "image": "ghcr.io/quenchworks/images/mediamtx",
        "version": "1.19.3",
        "tag": "ghcr.io/quenchworks/images/mediamtx:1.19.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/mediamtx"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.19.3",
            "tag": "ghcr.io/quenchworks/images/mediamtx:1.19.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/mediamtx"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "meilisearch",
      "name": "Meilisearch",
      "category": "Search",
      "summary": "Fast, typo-tolerant full-text search engine with an instant-search API, easy to embed for site and in-app search with relevant results out of the box.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.50.0, 1.49.0, 1.51.0",
      "versions": [
        {
          "version": "1.50.0",
          "size": "94.5 MB",
          "published": "2026-07-28T10:23:22Z",
          "digest": "sha256:6f81bb675e9cf58244cfb9c8ad5ca7a00b1db1d428e31d67580158de7fefa8e3"
        },
        {
          "version": "1.49.0",
          "size": "94.4 MB",
          "published": "2026-07-28T10:23:17Z",
          "digest": "sha256:c3edc16b325020c6cb2047540811a18757c54830732128e69ebefde44a70abf1"
        },
        {
          "version": "1.51.0",
          "size": "94.1 MB",
          "published": "2026-07-28T10:23:17Z",
          "digest": "sha256:04bcb20754c136541f9eaab771b8eb9a07c9f5ac8c30a2f3910f60f6d69508ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/meilisearch/meilisearch",
      "source": "https://github.com/meilisearch/meilisearch",
      "image": "ghcr.io/quenchworks/images/meilisearch",
      "security": {
        "image": "ghcr.io/quenchworks/images/meilisearch",
        "version": "1.51.0",
        "tag": "ghcr.io/quenchworks/images/meilisearch:1.51.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.51.0",
            "tag": "ghcr.io/quenchworks/images/meilisearch:1.51.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.50.0",
            "tag": "ghcr.io/quenchworks/images/meilisearch:1.50.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.49.0",
            "tag": "ghcr.io/quenchworks/images/meilisearch:1.49.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "memcached",
      "name": "Memcached",
      "category": "Cache",
      "summary": "Simple, high-performance distributed in-memory cache for storing small objects and database query results to reduce backend load.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.6.45",
      "versions": [
        {
          "version": "1.6.45",
          "size": "7.2 MB",
          "published": "2026-07-12T12:17:26Z",
          "digest": "sha256:d078d5186da4a439b22a7ac65968d553ff8a57f6304817fb6f633855c6f34546"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/memcached/memcached",
      "source": "https://www.memcached.org/files/memcached-1.6.42.tar.gz",
      "image": "ghcr.io/quenchworks/images/memcached",
      "security": {
        "image": "ghcr.io/quenchworks/images/memcached",
        "version": "1.6.45",
        "tag": "ghcr.io/quenchworks/images/memcached:1.6.45",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.6.45",
            "tag": "ghcr.io/quenchworks/images/memcached:1.6.45",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mimir",
      "name": "mimir",
      "category": "Observability",
      "summary": "Horizontally scalable, highly available long-term storage for Prometheus metrics. Single static Go binary (all-in-one or microservices target) on a hardened nonroot Wolfi base; object storage is the operator's choice.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "3.1.2",
      "versions": [
        {
          "version": "3.1.2",
          "size": "39.5 MB",
          "published": "2026-07-21T11:31:43Z",
          "digest": "sha256:2ca8589ad58fca650b777a0807a3df829bab92b5a5f5c542b7f55b063f36828d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://grafana.com/oss/mimir",
      "source": "https://github.com/grafana/mimir",
      "image": "ghcr.io/quenchworks/images/mimir",
      "security": {
        "image": "ghcr.io/quenchworks/images/mimir",
        "version": "3.1.2",
        "tag": "ghcr.io/quenchworks/images/mimir:3.1.2",
        "critical": 0,
        "high": 2,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 4,
        "fixable": 3,
        "grade": "D",
        "score": 61,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.37.0",
            "fixed": "0.39.0",
            "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/mimir"
            ]
          },
          {
            "id": "GHSA-hrxh-6v49-42gf",
            "severity": "HIGH",
            "pkg": "google.golang.org/grpc",
            "installed": "v1.80.0",
            "fixed": "1.82.1",
            "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
            "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
            "targets": [
              "usr/bin/mimir"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/mimir"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.52.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/mimir"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.1.2",
            "tag": "ghcr.io/quenchworks/images/mimir:3.1.2",
            "critical": 0,
            "high": 2,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 4,
            "fixable": 3,
            "grade": "D",
            "score": 61,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.37.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/mimir"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.80.0",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/mimir"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/mimir"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/mimir"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "miniflux",
      "name": "miniflux",
      "category": "Apps & productivity",
      "summary": "Minimalist, opinionated RSS and Atom feed reader with a clean web UI and a REST API. Single pure-Go static binary on a hardened nonroot Wolfi base; needs PostgreSQL at runtime (operator-provided).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.3.2",
      "versions": [
        {
          "version": "2.3.2",
          "size": "8.9 MB",
          "published": "2026-07-22T08:30:10Z",
          "digest": "sha256:f4b847570d250f8e72f73acbe0d07d67feeeb0d624ef935305ab8950819e51da"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://miniflux.app",
      "source": "https://github.com/miniflux/v2",
      "image": "ghcr.io/quenchworks/images/miniflux",
      "security": {
        "image": "ghcr.io/quenchworks/images/miniflux",
        "version": "2.3.2",
        "tag": "ghcr.io/quenchworks/images/miniflux:2.3.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/miniflux"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.3.2",
            "tag": "ghcr.io/quenchworks/images/miniflux:2.3.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/miniflux"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "mlflow",
      "name": "mlflow",
      "category": "Machine learning & AI",
      "summary": "MLflow Tracking Server for the ML lifecycle — experiment tracking, model registry, and run metadata over a REST/UI on port 5000. Packaged as the lightweight mlflow-skinny stack (gunicorn + psycopg2 + boto3) on a hardened Wolfi python base; needs an external PostgreSQL backend store and an artifact store (S3 or PVC).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.13.0, 3.14.0",
      "versions": [
        {
          "version": "3.13.0",
          "size": "130.0 MB",
          "published": "2026-07-26T12:33:56Z",
          "digest": "sha256:c98c53565b2b1d131d97aebdedc2e4b3f62ace7cb35b077eb9579dfe89b2bef6"
        },
        {
          "version": "3.14.0",
          "size": "130.3 MB",
          "published": "2026-07-26T12:30:44Z",
          "digest": "sha256:e5a1e2d7d848f26e942648b50055f3f5de5a6aca091b6b6b2e663b6922ba8fb7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mlflow.org",
      "source": "https://github.com/mlflow/mlflow",
      "image": "ghcr.io/quenchworks/images/mlflow",
      "security": {
        "image": "ghcr.io/quenchworks/images/mlflow",
        "version": "3.14.0",
        "tag": "ghcr.io/quenchworks/images/mlflow:3.14.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.14.0",
            "tag": "ghcr.io/quenchworks/images/mlflow:3.14.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.13.0",
            "tag": "ghcr.io/quenchworks/images/mlflow:3.13.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mongodb",
      "name": "MongoDB",
      "category": "Document",
      "summary": "Document (NoSQL) database for JSON-like data. SSPL is not OSI-approved / source-available, not open source; prefer the clean alternative FerretDB or DocumentDB.",
      "tier": "standard",
      "status": "available",
      "license": "SSPL-1.0",
      "licenseClean": "caution",
      "version": "8.0.26, 6.0.29, 7.0.37",
      "versions": [
        {
          "version": "8.0.26",
          "size": "171.9 MB",
          "published": "2026-07-04T11:21:19Z",
          "digest": "sha256:86da138b90eb830a38b3110e00b9b19191bb71d413a2c898134c36631bfe4584"
        },
        {
          "version": "6.0.29",
          "size": "154.5 MB",
          "published": "2026-07-04T11:20:14Z",
          "digest": "sha256:5266cccb060d860226a009367b8a2e1a1653334443f10c1c4a83733abba7887d"
        },
        {
          "version": "7.0.37",
          "size": "163.1 MB",
          "published": "2026-07-04T11:17:14Z",
          "digest": "sha256:f5822cf3da3837f9b08f54ceedd04c31bae842f504d09dad45dd09217747068e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/mongodb/mongo",
      "source": "https://github.com/mongodb/mongo",
      "image": "ghcr.io/quenchworks/images/mongodb",
      "caution": true,
      "cleanAlternative": "FerretDB + DocumentDB — MongoDB-wire-compatible and truly open (Apache-2.0 / PostgreSQL).",
      "security": {
        "image": "ghcr.io/quenchworks/images/mongodb",
        "version": "8.0.26",
        "tag": "ghcr.io/quenchworks/images/mongodb:8.0.26",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "8.0.26",
            "tag": "ghcr.io/quenchworks/images/mongodb:8.0.26",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "7.0.37",
            "tag": "ghcr.io/quenchworks/images/mongodb:7.0.37",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "6.0.29",
            "tag": "ghcr.io/quenchworks/images/mongodb:6.0.29",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mosquitto",
      "name": "mosquitto",
      "category": "Messaging",
      "summary": "Lightweight Eclipse MQTT broker for IoT and pub/sub messaging. Speaks MQTT 3.1/3.1.1/5.0 over TCP, TLS, and websockets; built from source with OpenSSL and a hardened nonroot, read-only-rootfs runtime.",
      "tier": "standard",
      "status": "available",
      "license": "EPL-2.0 OR BSD-3-Clause",
      "licenseClean": "clean",
      "version": "2.1.0, 2.1.1, 2.1.2",
      "versions": [
        {
          "version": "2.1.0",
          "size": "10.1 MB",
          "published": "2026-07-04T11:18:52Z",
          "digest": "sha256:0ae9bdf6c85b614f031c00f080fe87c9728927a5a96bb068a49215cf699663a5"
        },
        {
          "version": "2.1.1",
          "size": "10.1 MB",
          "published": "2026-07-04T11:16:49Z",
          "digest": "sha256:9b657e1f05ac78e6f45a10e1cd9d2c7f8b416c541ce47365250a219097716578"
        },
        {
          "version": "2.1.2",
          "size": "10.1 MB",
          "published": "2026-07-04T11:11:16Z",
          "digest": "sha256:bd01aa290b0d387335e6faa2ba578bc81cf8c4178c694db257b0817d4a02cc5e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://mosquitto.org",
      "source": "https://github.com/eclipse-mosquitto/mosquitto",
      "image": "ghcr.io/quenchworks/images/mosquitto",
      "security": {
        "image": "ghcr.io/quenchworks/images/mosquitto",
        "version": "2.1.2",
        "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.1.2",
            "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.1.1",
            "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/mosquitto:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "mysql",
      "name": "MySQL",
      "category": "Relational",
      "summary": "Widely used open-source relational database for general-purpose OLTP workloads, with broad framework and tooling support.",
      "tier": "critical",
      "status": "available",
      "license": "GPL-2.0",
      "licenseClean": "clean",
      "version": "8.4.11, 9.7.2",
      "versions": [
        {
          "version": "8.4.11",
          "size": "149.9 MB",
          "published": "2026-07-30T09:07:32Z",
          "digest": "sha256:9707870ea4984e5ce8585f0836f30e3c457d361a0911e72a262b79e66fdec0d3"
        },
        {
          "version": "9.7.2",
          "size": "157.4 MB",
          "published": "2026-07-30T09:07:19Z",
          "digest": "sha256:01e08bae9a563f645e776a868274c3a9bf0a405891d3615cd59ef6aab0f2a9e7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/mysql/mysql-server",
      "source": "https://dev.mysql.com/get/Downloads/MySQL-9.7/mysql-9.7.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/mysql",
      "security": {
        "image": "ghcr.io/quenchworks/images/mysql",
        "version": "9.7.1",
        "tag": "ghcr.io/quenchworks/images/mysql:9.7.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.7.1",
            "tag": "ghcr.io/quenchworks/images/mysql:9.7.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.4.10",
            "tag": "ghcr.io/quenchworks/images/mysql:8.4.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.46",
            "tag": "ghcr.io/quenchworks/images/mysql:8.0.46",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "n8n",
      "name": "n8n",
      "category": "Workflow",
      "summary": "Fair-code workflow automation platform — build integrations and automations across 400+ apps via a visual node editor, with native AI/LLM agent nodes. Node build on a hardened nonroot Wolfi base; the flagged transitive npm CVE class is cleared image-side with pinned overrides.",
      "tier": "standard",
      "status": "available",
      "license": "LicenseRef-n8n-Sustainable-Use-License-1.0",
      "licenseClean": "clean",
      "version": "2.32.6",
      "versions": [
        {
          "version": "2.32.6",
          "size": "398.4 MB",
          "published": "2026-07-30T10:30:45Z",
          "digest": "sha256:942a5d312eb804a843e2fa1a06b03c6318a827124c5a20a9fb70bee55f07c39c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://n8n.io",
      "source": "https://github.com/n8n-io/n8n",
      "image": "ghcr.io/quenchworks/images/n8n",
      "security": {
        "image": "ghcr.io/quenchworks/images/n8n",
        "version": "2.32.1",
        "tag": "ghcr.io/quenchworks/images/n8n:2.32.1",
        "critical": 0,
        "high": 0,
        "medium": 1,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 0,
        "grade": "C",
        "score": 96,
        "cves": [
          {
            "id": "CVE-2024-1899",
            "severity": "MEDIUM",
            "pkg": "showdown",
            "installed": "2.1.0",
            "fixed": null,
            "title": "Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing",
            "url": "https://avd.aquasec.com/nvd/cve-2024-1899",
            "targets": [
              "Node.js"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.32.1",
            "tag": "ghcr.io/quenchworks/images/n8n:2.32.1",
            "critical": 0,
            "high": 0,
            "medium": 1,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 0,
            "grade": "C",
            "score": 96,
            "cves": [
              {
                "id": "CVE-2024-1899",
                "severity": "MEDIUM",
                "pkg": "showdown",
                "installed": "2.1.0",
                "fixed": null,
                "title": "Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2024-1899",
                "targets": [
                  "Node.js"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "n8n-runners",
      "name": "n8n-runners",
      "category": "Workflow",
      "summary": "n8n external task-runner sidecar — isolates and executes workflow code (JS/Python) out of the main n8n process for security and scale. Built from source on Wolfi. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "LicenseRef-n8n-Sustainable-Use-License-1.0",
      "licenseClean": "clean",
      "version": "2.32.6",
      "versions": [
        {
          "version": "2.32.6",
          "size": "181.6 MB",
          "published": "2026-07-30T08:09:47Z",
          "digest": "sha256:05d4416bfe8b4403ba1f7bd838fab9f2b176d1875a2dac1a9345deed0f178210"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://n8n.io",
      "source": "https://github.com/n8n-io/n8n",
      "image": "ghcr.io/quenchworks/images/n8n-runners",
      "security": {
        "image": "ghcr.io/quenchworks/images/n8n-runners",
        "version": "2.31.7",
        "tag": "ghcr.io/quenchworks/images/n8n-runners:2.31.7",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.31.7",
            "tag": "ghcr.io/quenchworks/images/n8n-runners:2.31.7",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "nats",
      "name": "NATS",
      "category": "Messaging",
      "summary": "Lightweight, high-performance messaging system for cloud-native pub/sub and request-reply, with optional JetStream persistence and streaming.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.14.1, 2.14.2, 2.14.3",
      "versions": [
        {
          "version": "2.14.1",
          "size": "6.6 MB",
          "published": "2026-07-22T07:07:48Z",
          "digest": "sha256:6450039d56e3e4990d84b8026e77a1e88136381c0dc6ef052f271a5b5c6744ac"
        },
        {
          "version": "2.14.2",
          "size": "6.6 MB",
          "published": "2026-07-22T07:07:46Z",
          "digest": "sha256:fadf748d682d6f188120f78a250cd0671415a9a990d508369f06c61ff96c67bb"
        },
        {
          "version": "2.14.3",
          "size": "6.6 MB",
          "published": "2026-07-22T07:06:25Z",
          "digest": "sha256:c06b8b41bed663fd6e59c05696d4b1fb1a568662b139b080bb91842e53e87ab5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/nats-io/nats-server",
      "source": "https://github.com/nats-io/nats-server",
      "image": "ghcr.io/quenchworks/images/nats",
      "security": {
        "image": "ghcr.io/quenchworks/images/nats",
        "version": "2.14.3",
        "tag": "ghcr.io/quenchworks/images/nats:2.14.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/nats-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.14.3",
            "tag": "ghcr.io/quenchworks/images/nats:2.14.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/nats-server"
                ]
              }
            ]
          },
          {
            "version": "2.14.2",
            "tag": "ghcr.io/quenchworks/images/nats:2.14.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/nats-server"
                ]
              }
            ]
          },
          {
            "version": "2.14.1",
            "tag": "ghcr.io/quenchworks/images/nats:2.14.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/nats-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "navidrome",
      "name": "navidrome",
      "category": "Media & streaming",
      "summary": "Self-hosted music server and streamer compatible with the Subsonic/OpenSubsonic API, with a modern web UI. From source (React UI embedded, CGO+static-musl SQLite) on a hardened nonroot Wolfi base; music and data on writable volumes.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0",
      "licenseClean": "agpl",
      "version": "0.62.0",
      "versions": [
        {
          "version": "0.62.0",
          "size": "22.2 MB",
          "published": "2026-07-23T12:02:55Z",
          "digest": "sha256:898cde2401631e113731e4232b5451643bdb3167f27b2b47b37df400ffa8bfe5"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.navidrome.org",
      "source": "https://github.com/navidrome/navidrome",
      "image": "ghcr.io/quenchworks/images/navidrome",
      "security": {
        "image": "ghcr.io/quenchworks/images/navidrome",
        "version": "0.62.0",
        "tag": "ghcr.io/quenchworks/images/navidrome:0.62.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/navidrome"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.62.0",
            "tag": "ghcr.io/quenchworks/images/navidrome:0.62.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/navidrome"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "neo4j",
      "name": "Neo4j",
      "category": "Graph",
      "summary": "Graph database for highly connected data, queried with Cypher for traversals and relationship-heavy workloads. Community edition is GPLv3.",
      "tier": "low",
      "status": "available",
      "license": "GPL-3.0",
      "licenseClean": "agpl",
      "version": "2026.05.0",
      "versions": [
        {
          "version": "2026.05.0",
          "size": "243.5 MB",
          "published": "2026-07-28T06:23:30Z",
          "digest": "sha256:4e1102d63efa02dd161f2405a669ea859753699c97a3fb4bb3cd622f8bd6e54a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/neo4j/neo4j",
      "source": "https://github.com/neo4j/neo4j",
      "image": "ghcr.io/quenchworks/images/neo4j",
      "security": {
        "image": "ghcr.io/quenchworks/images/neo4j",
        "version": "2026.05.0",
        "tag": "ghcr.io/quenchworks/images/neo4j:2026.05.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2026.05.0",
            "tag": "ghcr.io/quenchworks/images/neo4j:2026.05.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "nextcloud",
      "name": "nextcloud",
      "category": "Apps & productivity",
      "summary": "Nextcloud, the self-hosted file-sync and content-collaboration platform. Reconstructed clean-room on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs); the chart installs via occ and provides a MariaDB backend. Nextcloud is AGPL-3.0-only (strong copyleft).",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "34.0.2",
      "versions": [
        {
          "version": "34.0.2",
          "size": "436.7 MB",
          "published": "2026-07-26T12:30:15Z",
          "digest": "sha256:e20d5f20e45e5c9c5405629738defe66b5f6997da3a55e1c262123051a0c3a54"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://nextcloud.com",
      "source": "https://download.nextcloud.com/server/releases/nextcloud-34.0.1.tar.bz2",
      "image": "ghcr.io/quenchworks/images/nextcloud",
      "security": {
        "image": "ghcr.io/quenchworks/images/nextcloud",
        "version": "34.0.2",
        "tag": "ghcr.io/quenchworks/images/nextcloud:34.0.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "34.0.2",
            "tag": "ghcr.io/quenchworks/images/nextcloud:34.0.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "nginx",
      "name": "nginx",
      "category": "Gateway",
      "summary": "High-performance web server, reverse proxy, and load balancer for serving static content and fronting application backends.",
      "tier": "critical",
      "status": "available",
      "license": "BSD-2-Clause",
      "licenseClean": "clean",
      "version": "1.30.4, 1.26.3, 1.28.3",
      "versions": [
        {
          "version": "1.30.4",
          "size": "11.5 MB",
          "published": "2026-07-21T08:28:25Z",
          "digest": "sha256:ba15d418a862217869a6f90e2912b9acdfb54864d26395e8a8e753ea5823e30f"
        },
        {
          "version": "1.26.3",
          "size": "11.3 MB",
          "published": "2026-07-21T08:28:23Z",
          "digest": "sha256:c88b1d331faeabed253d858fe68391e60bc8ce566cffe41e2d88f5eca4b48745"
        },
        {
          "version": "1.28.3",
          "size": "11.4 MB",
          "published": "2026-07-21T08:28:13Z",
          "digest": "sha256:70def6a2dda1da1e9ac9665c22867b40411542301c62f904ec252b1b8708cca9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/nginx/nginx",
      "source": "https://github.com/nginx/nginx",
      "image": "ghcr.io/quenchworks/images/nginx",
      "security": {
        "image": "ghcr.io/quenchworks/images/nginx",
        "version": "1.30.4",
        "tag": "ghcr.io/quenchworks/images/nginx:1.30.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.30.4",
            "tag": "ghcr.io/quenchworks/images/nginx:1.30.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.28.3",
            "tag": "ghcr.io/quenchworks/images/nginx:1.28.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.26.3",
            "tag": "ghcr.io/quenchworks/images/nginx:1.26.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "node",
      "name": "node",
      "category": "Language runtime",
      "summary": "Hardened Node.js runtime with npm, a 0-CVE signed nonroot base image for JavaScript apps. Active LTS lines (20/22/24).",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "24.18.0, 26.5.0, 22.23.1",
      "versions": [
        {
          "version": "24.18.0",
          "size": "56.1 MB",
          "published": "2026-07-28T06:23:23Z",
          "digest": "sha256:eca7dbc8936cf48cedc125c1fe709ec4cd7e686d659b5e93b4d12770cf6a1a2b"
        },
        {
          "version": "26.5.0",
          "size": "60.3 MB",
          "published": "2026-07-28T06:23:11Z",
          "digest": "sha256:b54769c85510f0691c294af57652639b798f1916031bea59737dded4b6137435"
        },
        {
          "version": "22.23.1",
          "size": "55.7 MB",
          "published": "2026-07-28T06:23:02Z",
          "digest": "sha256:853d071634fad63ad69948c36e8bed645f232f5e66c1378a130edcb7f612b300"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/nodejs/node",
      "source": "https://github.com/nodejs/node",
      "image": "ghcr.io/quenchworks/images/node",
      "security": {
        "image": "ghcr.io/quenchworks/images/node",
        "version": "26.5.0",
        "tag": "ghcr.io/quenchworks/images/node:26.5.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "26.5.0",
            "tag": "ghcr.io/quenchworks/images/node:26.5.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "24.18.0",
            "tag": "ghcr.io/quenchworks/images/node:24.18.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "22.23.1",
            "tag": "ghcr.io/quenchworks/images/node:22.23.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "node-exporter",
      "name": "node-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter for host-level hardware and OS metrics (CPU, memory, disk, network) on Linux machines.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.12.1",
      "versions": [
        {
          "version": "1.12.1",
          "size": "6.5 MB",
          "published": "2026-07-15T12:44:28Z",
          "digest": "sha256:4426d70c51fc41c540da00ba3f3631c7a8e72165062fcb48e9dc9be3933977b7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/node_exporter",
      "source": "https://github.com/prometheus/node_exporter",
      "image": "ghcr.io/quenchworks/images/node-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/node-exporter",
        "version": "1.12.1",
        "tag": "ghcr.io/quenchworks/images/node-exporter:1.12.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/node_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.12.1",
            "tag": "ghcr.io/quenchworks/images/node-exporter:1.12.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/node_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "nsq",
      "name": "nsq",
      "category": "Messaging",
      "summary": "Realtime distributed messaging platform. Ships nsqd, nsqlookupd, and nsqadmin as static Go binaries on a hardened nonroot Wolfi base; nsqd data path is a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.2.1, 1.3.0, 1.2.0",
      "versions": [
        {
          "version": "1.2.1",
          "size": "11.3 MB",
          "published": "2026-07-08T10:55:09Z",
          "digest": "sha256:78d18e0395103feb3281328991624be00556278f85b92319e8eaf4a8c6e1c276"
        },
        {
          "version": "1.3.0",
          "size": "11.0 MB",
          "published": "2026-07-08T10:55:07Z",
          "digest": "sha256:6605a00792074485207398ebba6178ef11d4037aa1fbcc734b6dc0e1b4254cc5"
        },
        {
          "version": "1.2.0",
          "size": "10.9 MB",
          "published": "2026-07-08T10:51:28Z",
          "digest": "sha256:b32cfd806654bb5c9ea11f5a01212400917e3c45315fcbfdd64d35420325178f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://nsq.io",
      "source": "https://github.com/nsqio/nsq",
      "image": "ghcr.io/quenchworks/images/nsq",
      "security": {
        "image": "ghcr.io/quenchworks/images/nsq",
        "version": "1.3.0",
        "tag": "ghcr.io/quenchworks/images/nsq:1.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.3.0",
            "tag": "ghcr.io/quenchworks/images/nsq:1.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.2.1",
            "tag": "ghcr.io/quenchworks/images/nsq:1.2.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.2.0",
            "tag": "ghcr.io/quenchworks/images/nsq:1.2.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "ntfy",
      "name": "ntfy",
      "category": "Messaging",
      "summary": "Simple HTTP-based pub-sub notification service for sending push notifications to phones and desktops from any script. From source with the web UI embedded (no Node at runtime) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.25.0",
      "versions": [
        {
          "version": "2.25.0",
          "size": "20.4 MB",
          "published": "2026-07-22T08:59:26Z",
          "digest": "sha256:8e8b81c670e8b45851d76e84f64fb896440948dc755014b4462443037be18f85"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ntfy.sh",
      "source": "https://github.com/binwiederhier/ntfy",
      "image": "ghcr.io/quenchworks/images/ntfy",
      "security": {
        "image": "ghcr.io/quenchworks/images/ntfy",
        "version": "2.25.0",
        "tag": "ghcr.io/quenchworks/images/ntfy:2.25.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/ntfy"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.25.0",
            "tag": "ghcr.io/quenchworks/images/ntfy:2.25.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/ntfy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "oauth2-proxy",
      "name": "oauth2-proxy",
      "category": "Secrets & identity",
      "summary": "Reverse-proxy authentication layer that secures upstream apps by delegating sign-in to OIDC and OAuth2 providers.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "7.15.3",
      "versions": [
        {
          "version": "7.15.3",
          "size": "9.9 MB",
          "published": "2026-07-22T07:05:27Z",
          "digest": "sha256:3a469bcaacf5f3d63b941e8e14f5e6d9a596632e31d7f2782a84709b44acb980"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://oauth2-proxy.github.io/oauth2-proxy/",
      "source": "https://github.com/oauth2-proxy/oauth2-proxy",
      "image": "ghcr.io/quenchworks/images/oauth2-proxy",
      "security": {
        "image": "ghcr.io/quenchworks/images/oauth2-proxy",
        "version": "7.15.3",
        "tag": "ghcr.io/quenchworks/images/oauth2-proxy:7.15.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/oauth2-proxy"
            ]
          }
        ],
        "versions": [
          {
            "version": "7.15.3",
            "tag": "ghcr.io/quenchworks/images/oauth2-proxy:7.15.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/oauth2-proxy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ollama",
      "name": "ollama",
      "category": "Machine learning & AI",
      "summary": "Local LLM runtime that pulls, runs, and serves open models (Llama, Gemma, Qwen, DeepSeek, and more) behind a simple REST API. CPU-only image; the chart mounts a writable volume for the model store.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.32.5",
      "versions": [
        {
          "version": "0.32.5",
          "size": "1.6 GB",
          "published": "2026-07-28T09:49:28Z",
          "digest": "sha256:3b2f7a4980d2e1f292a756e66e28d603b829b9e3740c3997b0800bc5e47ab190"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ollama.com",
      "source": "https://github.com/ollama/ollama",
      "image": "ghcr.io/quenchworks/images/ollama",
      "security": {
        "image": "ghcr.io/quenchworks/images/ollama",
        "version": "0.32.5",
        "tag": "ghcr.io/quenchworks/images/ollama:0.32.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/ollama"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.32.5",
            "tag": "ghcr.io/quenchworks/images/ollama:0.32.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/ollama"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "opa",
      "name": "opa",
      "category": "Security & supply chain",
      "summary": "Open Policy Agent, the CNCF general-purpose policy engine. Evaluates Rego policies over JSON and YAML to enforce authorization, admission control, and configuration rules across the stack.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.2",
      "versions": [
        {
          "version": "1.18.2",
          "size": "13.2 MB",
          "published": "2026-07-23T12:00:30Z",
          "digest": "sha256:870921494dbe65c9efe9ec86d806f52708fe728437e1aa688446f491317a27db"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.openpolicyagent.org",
      "source": "https://github.com/open-policy-agent/opa",
      "image": "ghcr.io/quenchworks/images/opa",
      "security": {
        "image": "ghcr.io/quenchworks/images/opa",
        "version": "1.18.2",
        "tag": "ghcr.io/quenchworks/images/opa:1.18.2",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/opa"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/opa"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.18.2",
            "tag": "ghcr.io/quenchworks/images/opa:1.18.2",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/opa"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/opa"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "openbao",
      "name": "OpenBao",
      "category": "Secrets",
      "summary": "Open-source secrets and encryption management for tokens, keys, and certificates, with dynamic secrets and leasing. The Linux Foundation MPL-2.0 community fork of HashiCorp Vault.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "2.6.1",
      "versions": [
        {
          "version": "2.6.1",
          "size": "42.2 MB",
          "published": "2026-07-30T08:08:12Z",
          "digest": "sha256:a27e51c4ac384b57e5141aaf0435163c8c3d36cd185510a163eb5126e56d6394"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/openbao/openbao",
      "source": "https://github.com/openbao/openbao",
      "image": "ghcr.io/quenchworks/images/openbao",
      "security": {
        "image": "ghcr.io/quenchworks/images/openbao",
        "version": "2.6.0",
        "tag": "ghcr.io/quenchworks/images/openbao:2.6.0",
        "critical": 0,
        "high": 2,
        "medium": 1,
        "low": 0,
        "unknown": 2,
        "total": 5,
        "fixable": 4,
        "grade": "D",
        "score": 52,
        "cves": [
          {
            "id": "CVE-2026-56852",
            "severity": "HIGH",
            "pkg": "golang.org/x/text",
            "installed": "v0.38.0",
            "fixed": "0.39.0",
            "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
            "targets": [
              "usr/bin/bao"
            ]
          },
          {
            "id": "GHSA-hrxh-6v49-42gf",
            "severity": "HIGH",
            "pkg": "google.golang.org/grpc",
            "installed": "v1.81.1",
            "fixed": "1.82.1",
            "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
            "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
            "targets": [
              "usr/bin/bao"
            ]
          },
          {
            "id": "GHSA-gcjh-h69q-9w9g",
            "severity": "MEDIUM",
            "pkg": "github.com/google/cel-go",
            "installed": "v0.28.1",
            "fixed": "0.29.0",
            "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
            "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
            "targets": [
              "usr/bin/bao"
            ]
          },
          {
            "id": "CVE-2026-46600",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/net",
            "installed": "v0.55.0",
            "fixed": "0.56.0",
            "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
            "targets": [
              "usr/bin/bao"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/bao"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.6.0",
            "tag": "ghcr.io/quenchworks/images/openbao:2.6.0",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 2,
            "total": 5,
            "fixable": 4,
            "grade": "D",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.38.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.81.1",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-gcjh-h69q-9w9g",
                "severity": "MEDIUM",
                "pkg": "github.com/google/cel-go",
                "installed": "v0.28.1",
                "fixed": "0.29.0",
                "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
                "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/bao"
                ]
              }
            ]
          },
          {
            "version": "2.5.5",
            "tag": "ghcr.io/quenchworks/images/openbao:2.5.5",
            "critical": 0,
            "high": 2,
            "medium": 1,
            "low": 0,
            "unknown": 2,
            "total": 5,
            "fixable": 4,
            "grade": "D",
            "score": 52,
            "cves": [
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.37.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.80.0",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-gcjh-h69q-9w9g",
                "severity": "MEDIUM",
                "pkg": "github.com/google/cel-go",
                "installed": "v0.26.1",
                "fixed": "0.29.0",
                "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
                "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.55.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.52.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/bao"
                ]
              }
            ]
          },
          {
            "version": "2.5.4",
            "tag": "ghcr.io/quenchworks/images/openbao:2.5.4",
            "critical": 0,
            "high": 20,
            "medium": 14,
            "low": 3,
            "unknown": 7,
            "total": 44,
            "fixable": 43,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2024-8185",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.0.3",
                "title": "hashicorp/vault: Vault Vulnerable to Denial of Service When Processing Raft Join Requests",
                "url": "https://avd.aquasec.com/nvd/cve-2024-8185",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2024-9180",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.0.3",
                "title": "hashicorp/vault: Vault Operators in Root Namespace May Elevate Their Privileges",
                "url": "https://avd.aquasec.com/nvd/cve-2024-9180",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-59043",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.4.1",
                "title": "OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests",
                "url": "https://avd.aquasec.com/nvd/cve-2025-59043",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-64761",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.4.4",
                "title": "OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation",
                "url": "https://avd.aquasec.com/nvd/cve-2025-64761",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-25681",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting",
                "url": "https://avd.aquasec.com/nvd/cve-2026-25681",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-27136",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-27136",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39821",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39821",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39822",
                "severity": "HIGH",
                "pkg": "stdlib",
                "installed": "v1.26.4",
                "fixed": "1.25.12, 1.26.5, 1.27.0-rc.2",
                "title": "os: golang: Go os.Root: Symlink following vulnerability allows directory traversal",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39822",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39828",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39828",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39829",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39829",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39830",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39830",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39831",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39831",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39832",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39832",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39835",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39835",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42508",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42508",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-45808",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-45808",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46595",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46595",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46597",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46597",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.36.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.80.0",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-25680",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-25680",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-32952",
                "severity": "MEDIUM",
                "pkg": "github.com/Azure/go-ntlmssp",
                "installed": "v0.0.0-20221128193559-754e69321358",
                "fixed": "0.1.1",
                "title": "go-ntlmssp: go-ntlmssp: Denial of Service via malicious NTLM challenge",
                "url": "https://avd.aquasec.com/nvd/cve-2026-32952",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39827",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39827",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39833",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39833",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39834",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39834",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42502",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42502",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42505",
                "severity": "MEDIUM",
                "pkg": "stdlib",
                "installed": "v1.26.4",
                "fixed": "1.25.12, 1.26.5, 1.27.0-rc.2",
                "title": "crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42505",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42506",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42506",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46358",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's Inline Auth Incorrectly Redacted Headers",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46358",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46405",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46405",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46598",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46598",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55770",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "0.0.0-20260617104213-10b7825c714c",
                "title": "OpenBao: LDAPi ldaputil (wrong escape func)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55770",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55776",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "0.0.0-20260617104123-db57c62602b2",
                "title": "OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55776",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-gcjh-h69q-9w9g",
                "severity": "MEDIUM",
                "pkg": "github.com/google/cel-go",
                "installed": "v0.26.1",
                "fixed": "0.29.0",
                "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
                "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41889",
                "severity": "LOW",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.9.1",
                "fixed": "5.9.2",
                "title": "github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41889",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55774",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "0.0.0-20260617103932-b20b999dd404",
                "title": "OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55774",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55775",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20260520155348-4f6d47246a05+dirty",
                "fixed": "0.0.0-20260617103935-d3c1cc64b1ae",
                "title": "OpenBao's System Backend allows Unauthorized Management of the containing Namespace",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55775",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39824",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/sys",
                "installed": "v0.43.0",
                "fixed": "0.44.0",
                "title": "Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39824",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.53.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "glibc",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:891ead55e81de29fb5d38a718c59a87f4269e00a7d461b263e403e4c3b5f53e5 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "glibc-locale-posix",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:891ead55e81de29fb5d38a718c59a87f4269e00a7d461b263e403e4c3b5f53e5 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "ld-linux",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:891ead55e81de29fb5d38a718c59a87f4269e00a7d461b263e403e4c3b5f53e5 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "libcrypt1",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:891ead55e81de29fb5d38a718c59a87f4269e00a7d461b263e403e4c3b5f53e5 (wolfi 20230201)"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.50.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/bao"
                ]
              }
            ]
          },
          {
            "version": "2.4.4",
            "tag": "ghcr.io/quenchworks/images/openbao:2.4.4",
            "critical": 5,
            "high": 29,
            "medium": 17,
            "low": 9,
            "unknown": 7,
            "total": 67,
            "fixable": 63,
            "grade": "F",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-33186",
                "severity": "CRITICAL",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.77.0",
                "fixed": "1.79.3",
                "title": "google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33186",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33757",
                "severity": "CRITICAL",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260325142553-e32103951925",
                "title": "OpenBao: lack of user confirmation for OpenBao OIDC direct callback mode",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33757",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33758",
                "severity": "CRITICAL",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260325133417-6e2b2dd84f0e",
                "title": "OpenBao: reflected XSS in OpenBao OIDC authentication error message",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33758",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33815",
                "severity": "CRITICAL",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.7.6",
                "fixed": "5.9.0",
                "title": "github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33815",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33816",
                "severity": "CRITICAL",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.7.6",
                "fixed": "5.9.0",
                "title": "github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33816",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2024-8185",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.0.3",
                "title": "hashicorp/vault: Vault Vulnerable to Denial of Service When Processing Raft Join Requests",
                "url": "https://avd.aquasec.com/nvd/cve-2024-8185",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2024-9180",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.0.3",
                "title": "hashicorp/vault: Vault Operators in Root Namespace May Elevate Their Privileges",
                "url": "https://avd.aquasec.com/nvd/cve-2024-9180",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-59043",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.4.1",
                "title": "OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests",
                "url": "https://avd.aquasec.com/nvd/cve-2025-59043",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-64761",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.4.4",
                "title": "OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation",
                "url": "https://avd.aquasec.com/nvd/cve-2025-64761",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-24051",
                "severity": "HIGH",
                "pkg": "go.opentelemetry.io/otel/sdk",
                "installed": "v1.38.0",
                "fixed": "1.40.0",
                "title": "OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking",
                "url": "https://avd.aquasec.com/nvd/cve-2026-24051",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-25681",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting",
                "url": "https://avd.aquasec.com/nvd/cve-2026-25681",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-27136",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-27136",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-29181",
                "severity": "HIGH",
                "pkg": "go.opentelemetry.io/otel",
                "installed": "v1.38.0",
                "fixed": "1.41.0",
                "title": "github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers",
                "url": "https://avd.aquasec.com/nvd/cve-2026-29181",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33814",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.53.0",
                "title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33814",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-34040",
                "severity": "HIGH",
                "pkg": "github.com/docker/docker",
                "installed": "v28.3.3+incompatible",
                "fixed": "29.3.1",
                "title": "Moby: Moby: Authorization bypass vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-34040",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-34986",
                "severity": "HIGH",
                "pkg": "github.com/go-jose/go-jose/v3",
                "installed": "v3.0.4",
                "fixed": "3.0.5",
                "title": "github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object",
                "url": "https://avd.aquasec.com/nvd/cve-2026-34986",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-34986",
                "severity": "HIGH",
                "pkg": "github.com/go-jose/go-jose/v4",
                "installed": "v4.1.3",
                "fixed": "4.1.4",
                "title": "github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object",
                "url": "https://avd.aquasec.com/nvd/cve-2026-34986",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39821",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39821",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39822",
                "severity": "HIGH",
                "pkg": "stdlib",
                "installed": "v1.26.4",
                "fixed": "1.25.12, 1.26.5, 1.27.0-rc.2",
                "title": "os: golang: Go os.Root: Symlink following vulnerability allows directory traversal",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39822",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39828",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39828",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39829",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39829",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39830",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39830",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39831",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39831",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39832",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39832",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39835",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39835",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39883",
                "severity": "HIGH",
                "pkg": "go.opentelemetry.io/otel/sdk",
                "installed": "v1.38.0",
                "fixed": "1.43.0",
                "title": "github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39883",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42508",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42508",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-45808",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-45808",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46595",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46595",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46597",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46597",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.31.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.77.0",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41567",
                "severity": "HIGH",
                "pkg": "github.com/docker/docker",
                "installed": "v28.3.3+incompatible",
                "fixed": null,
                "title": "docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41567",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42306",
                "severity": "HIGH",
                "pkg": "github.com/docker/docker",
                "installed": "v28.3.3+incompatible",
                "fixed": null,
                "title": "Moby is an open source container framework. In Docker Engine prior to  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42306",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-25680",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-25680",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-32952",
                "severity": "MEDIUM",
                "pkg": "github.com/Azure/go-ntlmssp",
                "installed": "v0.0.0-20221128193559-754e69321358",
                "fixed": "0.1.1",
                "title": "go-ntlmssp: go-ntlmssp: Denial of Service via malicious NTLM challenge",
                "url": "https://avd.aquasec.com/nvd/cve-2026-32952",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33997",
                "severity": "MEDIUM",
                "pkg": "github.com/docker/docker",
                "installed": "v28.3.3+incompatible",
                "fixed": "29.3.1",
                "title": "moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33997",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39827",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39827",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39833",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39833",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39834",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39834",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39946",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260420155735-b596b0882620",
                "title": "OpenBao: OpenBao: SQL injection via improper database quoting during PostgreSQL role revocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39946",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42502",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42502",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42505",
                "severity": "MEDIUM",
                "pkg": "stdlib",
                "installed": "v1.26.4",
                "fixed": "1.25.12, 1.26.5, 1.27.0-rc.2",
                "title": "crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42505",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42506",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42506",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46358",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's Inline Auth Incorrectly Redacted Headers",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46358",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46405",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46405",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46598",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46598",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55770",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260617104213-10b7825c714c",
                "title": "OpenBao: LDAPi ldaputil (wrong escape func)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55770",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55776",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260617104123-db57c62602b2",
                "title": "OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55776",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-gcjh-h69q-9w9g",
                "severity": "MEDIUM",
                "pkg": "github.com/google/cel-go",
                "installed": "v0.26.1",
                "fixed": "0.29.0",
                "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
                "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41568",
                "severity": "MEDIUM",
                "pkg": "github.com/docker/docker",
                "installed": "v28.3.3+incompatible",
                "fixed": null,
                "title": "github.com/docker/docker: github.com/moby/moby: Moby: Denial of Service via race condition in docker cp mount setup",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41568",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-1229",
                "severity": "LOW",
                "pkg": "github.com/cloudflare/circl",
                "installed": "v1.6.1",
                "fixed": "1.6.3",
                "title": "CIRCL has an incorrect calculation in secp384r1 CombinedMult",
                "url": "https://avd.aquasec.com/nvd/cve-2026-1229",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-26958",
                "severity": "LOW",
                "pkg": "filippo.io/edwards25519",
                "installed": "v1.1.0",
                "fixed": "1.1.1",
                "title": "filippo.io/edwards25519: filippo.io/edwards25519: Cryptographic integrity bypass due to incorrect MultiScalarMult results",
                "url": "https://avd.aquasec.com/nvd/cve-2026-26958",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39388",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260420160924-abe84e1af4c3",
                "title": "OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39388",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39396",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260420180337-2b2a901aa9f7",
                "title": "OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39396",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-40264",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260420162526-f58111d2ca54",
                "title": "OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-40264",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41889",
                "severity": "LOW",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.7.6",
                "fixed": "5.9.2",
                "title": "github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41889",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42186",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260420173541-6d2e0506e2b4",
                "title": "OpenBao's Namespace Deletion May Not Delete Data Properly",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42186",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55774",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260617103932-b20b999dd404",
                "title": "OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55774",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55775",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20251124193704-4bfd70723d4f+dirty",
                "fixed": "0.0.0-20260617103935-d3c1cc64b1ae",
                "title": "OpenBao's System Backend allows Unauthorized Management of the containing Namespace",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55775",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39824",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/sys",
                "installed": "v0.38.0",
                "fixed": "0.44.0",
                "title": "Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39824",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.47.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "glibc",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:3b2209b28cdd78f7477826db3bda79a8cf5815b71507f639bd9abe0d8b1387ca (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "glibc-locale-posix",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:3b2209b28cdd78f7477826db3bda79a8cf5815b71507f639bd9abe0d8b1387ca (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "ld-linux",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:3b2209b28cdd78f7477826db3bda79a8cf5815b71507f639bd9abe0d8b1387ca (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "libcrypt1",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:3b2209b28cdd78f7477826db3bda79a8cf5815b71507f639bd9abe0d8b1387ca (wolfi 20230201)"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.45.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/bao"
                ]
              }
            ]
          },
          {
            "version": "2.3.2",
            "tag": "ghcr.io/quenchworks/images/openbao:2.3.2",
            "critical": 5,
            "high": 30,
            "medium": 24,
            "low": 10,
            "unknown": 7,
            "total": 76,
            "fixable": 72,
            "grade": "F",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-33186",
                "severity": "CRITICAL",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.74.2",
                "fixed": "1.79.3",
                "title": "google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33186",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33757",
                "severity": "CRITICAL",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260325142553-e32103951925",
                "title": "OpenBao: lack of user confirmation for OpenBao OIDC direct callback mode",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33757",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33758",
                "severity": "CRITICAL",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260325133417-6e2b2dd84f0e",
                "title": "OpenBao: reflected XSS in OpenBao OIDC authentication error message",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33758",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33815",
                "severity": "CRITICAL",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.7.5",
                "fixed": "5.9.0",
                "title": "github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33815",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33816",
                "severity": "CRITICAL",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.7.5",
                "fixed": "5.9.0",
                "title": "github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33816",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2024-8185",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.0.3",
                "title": "hashicorp/vault: Vault Vulnerable to Denial of Service When Processing Raft Join Requests",
                "url": "https://avd.aquasec.com/nvd/cve-2024-8185",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2024-9180",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.0.3",
                "title": "hashicorp/vault: Vault Operators in Root Namespace May Elevate Their Privileges",
                "url": "https://avd.aquasec.com/nvd/cve-2024-9180",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-47913",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.43.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS",
                "url": "https://avd.aquasec.com/nvd/cve-2025-47913",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-59043",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.4.1",
                "title": "OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests",
                "url": "https://avd.aquasec.com/nvd/cve-2025-59043",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-64761",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.4.4",
                "title": "OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation",
                "url": "https://avd.aquasec.com/nvd/cve-2025-64761",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-24051",
                "severity": "HIGH",
                "pkg": "go.opentelemetry.io/otel/sdk",
                "installed": "v1.36.0",
                "fixed": "1.40.0",
                "title": "OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking",
                "url": "https://avd.aquasec.com/nvd/cve-2026-24051",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-25681",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting",
                "url": "https://avd.aquasec.com/nvd/cve-2026-25681",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-27136",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass",
                "url": "https://avd.aquasec.com/nvd/cve-2026-27136",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-29181",
                "severity": "HIGH",
                "pkg": "go.opentelemetry.io/otel",
                "installed": "v1.36.0",
                "fixed": "1.41.0",
                "title": "github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers",
                "url": "https://avd.aquasec.com/nvd/cve-2026-29181",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33814",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.53.0",
                "title": "net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33814",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-34040",
                "severity": "HIGH",
                "pkg": "github.com/docker/docker",
                "installed": "v27.4.1+incompatible",
                "fixed": "29.3.1",
                "title": "Moby: Moby: Authorization bypass vulnerability",
                "url": "https://avd.aquasec.com/nvd/cve-2026-34040",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-34986",
                "severity": "HIGH",
                "pkg": "github.com/go-jose/go-jose/v3",
                "installed": "v3.0.4",
                "fixed": "3.0.5",
                "title": "github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object",
                "url": "https://avd.aquasec.com/nvd/cve-2026-34986",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-34986",
                "severity": "HIGH",
                "pkg": "github.com/go-jose/go-jose/v4",
                "installed": "v4.0.5",
                "fixed": "4.1.4",
                "title": "github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object",
                "url": "https://avd.aquasec.com/nvd/cve-2026-34986",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39821",
                "severity": "HIGH",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39821",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39822",
                "severity": "HIGH",
                "pkg": "stdlib",
                "installed": "v1.26.4",
                "fixed": "1.25.12, 1.26.5, 1.27.0-rc.2",
                "title": "os: golang: Go os.Root: Symlink following vulnerability allows directory traversal",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39822",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39828",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39828",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39829",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39829",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39830",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39830",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39831",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39831",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39832",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39832",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39835",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39835",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39883",
                "severity": "HIGH",
                "pkg": "go.opentelemetry.io/otel/sdk",
                "installed": "v1.36.0",
                "fixed": "1.43.0",
                "title": "github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39883",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42508",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42508",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-45808",
                "severity": "HIGH",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL",
                "url": "https://avd.aquasec.com/nvd/cve-2026-45808",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46595",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46595",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46597",
                "severity": "HIGH",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46597",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-56852",
                "severity": "HIGH",
                "pkg": "golang.org/x/text",
                "installed": "v0.27.0",
                "fixed": "0.39.0",
                "title": "A norm.Iter can enter an infinite loop when handling input containing  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56852",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-hrxh-6v49-42gf",
                "severity": "HIGH",
                "pkg": "google.golang.org/grpc",
                "installed": "v1.74.2",
                "fixed": "1.82.1",
                "title": "gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities",
                "url": "https://github.com/advisories/GHSA-hrxh-6v49-42gf",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41567",
                "severity": "HIGH",
                "pkg": "github.com/docker/docker",
                "installed": "v27.4.1+incompatible",
                "fixed": null,
                "title": "docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41567",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42306",
                "severity": "HIGH",
                "pkg": "github.com/docker/docker",
                "installed": "v27.4.1+incompatible",
                "fixed": null,
                "title": "Moby is an open source container framework. In Docker Engine prior to  ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42306",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-11065",
                "severity": "MEDIUM",
                "pkg": "github.com/go-viper/mapstructure/v2",
                "installed": "v2.3.0",
                "fixed": "2.4.0",
                "title": "github.com/go-viper/mapstructure/v2: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure",
                "url": "https://avd.aquasec.com/nvd/cve-2025-11065",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-47911",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.45.0",
                "title": "golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html",
                "url": "https://avd.aquasec.com/nvd/cve-2025-47911",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-47914",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.45.0",
                "title": "golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages",
                "url": "https://avd.aquasec.com/nvd/cve-2025-47914",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-58181",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.45.0",
                "title": "golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication",
                "url": "https://avd.aquasec.com/nvd/cve-2025-58181",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-58190",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.45.0",
                "title": "golang.org/x/net/html: Infinite parsing loop in golang.org/x/net",
                "url": "https://avd.aquasec.com/nvd/cve-2025-58190",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-62513",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20251022165510-cc2c476bac66",
                "title": "OpenBao leaks HTTPRawBody in Audit Logs",
                "url": "https://avd.aquasec.com/nvd/cve-2025-62513",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-62705",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20251022165510-cc2c476bac66",
                "title": "OpenBao and Vault Leak []byte Fields in Audit Logs ",
                "url": "https://avd.aquasec.com/nvd/cve-2025-62705",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-25680",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-25680",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-32952",
                "severity": "MEDIUM",
                "pkg": "github.com/Azure/go-ntlmssp",
                "installed": "v0.0.0-20221128193559-754e69321358",
                "fixed": "0.1.1",
                "title": "go-ntlmssp: go-ntlmssp: Denial of Service via malicious NTLM challenge",
                "url": "https://avd.aquasec.com/nvd/cve-2026-32952",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-33997",
                "severity": "MEDIUM",
                "pkg": "github.com/docker/docker",
                "installed": "v27.4.1+incompatible",
                "fixed": "29.3.1",
                "title": "moby: docker: github.com/moby/moby: Moby: Privilege validation bypass during plugin installation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-33997",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39827",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39827",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39833",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39833",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39834",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39834",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39946",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260420155735-b596b0882620",
                "title": "OpenBao: OpenBao: SQL injection via improper database quoting during PostgreSQL role revocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39946",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42502",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42502",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42505",
                "severity": "MEDIUM",
                "pkg": "stdlib",
                "installed": "v1.26.4",
                "fixed": "1.25.12, 1.26.5, 1.27.0-rc.2",
                "title": "crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42505",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42506",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.55.0",
                "title": "golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42506",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46358",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's Inline Auth Incorrectly Redacted Headers",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46358",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46405",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "2.5.4",
                "title": "OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46405",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46598",
                "severity": "MEDIUM",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": "0.52.0",
                "title": "golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46598",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55770",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260617104213-10b7825c714c",
                "title": "OpenBao: LDAPi ldaputil (wrong escape func)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55770",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55776",
                "severity": "MEDIUM",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260617104123-db57c62602b2",
                "title": "OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55776",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "GHSA-gcjh-h69q-9w9g",
                "severity": "MEDIUM",
                "pkg": "github.com/google/cel-go",
                "installed": "v0.26.0",
                "fixed": "0.29.0",
                "title": "cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag",
                "url": "https://github.com/advisories/GHSA-gcjh-h69q-9w9g",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41568",
                "severity": "MEDIUM",
                "pkg": "github.com/docker/docker",
                "installed": "v27.4.1+incompatible",
                "fixed": null,
                "title": "github.com/docker/docker: github.com/moby/moby: Moby: Denial of Service via race condition in docker cp mount setup",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41568",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2025-54410",
                "severity": "LOW",
                "pkg": "github.com/docker/docker",
                "installed": "v27.4.1+incompatible",
                "fixed": "25.0.13, 28.0.0",
                "title": "github.com/moby/moby: Moby's Firewalld reload removes bridge network isolation",
                "url": "https://avd.aquasec.com/nvd/cve-2025-54410",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-1229",
                "severity": "LOW",
                "pkg": "github.com/cloudflare/circl",
                "installed": "v1.6.1",
                "fixed": "1.6.3",
                "title": "CIRCL has an incorrect calculation in secp384r1 CombinedMult",
                "url": "https://avd.aquasec.com/nvd/cve-2026-1229",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-26958",
                "severity": "LOW",
                "pkg": "filippo.io/edwards25519",
                "installed": "v1.1.0",
                "fixed": "1.1.1",
                "title": "filippo.io/edwards25519: filippo.io/edwards25519: Cryptographic integrity bypass due to incorrect MultiScalarMult results",
                "url": "https://avd.aquasec.com/nvd/cve-2026-26958",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39388",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260420160924-abe84e1af4c3",
                "title": "OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39388",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39396",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260420180337-2b2a901aa9f7",
                "title": "OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39396",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-40264",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260420162526-f58111d2ca54",
                "title": "OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation",
                "url": "https://avd.aquasec.com/nvd/cve-2026-40264",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-41889",
                "severity": "LOW",
                "pkg": "github.com/jackc/pgx/v5",
                "installed": "v5.7.5",
                "fixed": "5.9.2",
                "title": "github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions",
                "url": "https://avd.aquasec.com/nvd/cve-2026-41889",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-42186",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260420173541-6d2e0506e2b4",
                "title": "OpenBao's Namespace Deletion May Not Delete Data Properly",
                "url": "https://avd.aquasec.com/nvd/cve-2026-42186",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55774",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260617103932-b20b999dd404",
                "title": "OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55774",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-55775",
                "severity": "LOW",
                "pkg": "github.com/openbao/openbao",
                "installed": "v0.0.0-20250808034624-b1a68f558c89+dirty",
                "fixed": "0.0.0-20260617103935-d3c1cc64b1ae",
                "title": "OpenBao's System Backend allows Unauthorized Management of the containing Namespace",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55775",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-39824",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/sys",
                "installed": "v0.34.0",
                "fixed": "0.44.0",
                "title": "Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows",
                "url": "https://avd.aquasec.com/nvd/cve-2026-39824",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-46600",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/net",
                "installed": "v0.42.0",
                "fixed": "0.56.0",
                "title": "Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-46600",
                "targets": [
                  "usr/bin/bao"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "glibc",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:65a1094c0ebd23cb2183cabac0ed47763bdc783c48268255843c8a51c812c8d7 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "glibc-locale-posix",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:65a1094c0ebd23cb2183cabac0ed47763bdc783c48268255843c8a51c812c8d7 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "ld-linux",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:65a1094c0ebd23cb2183cabac0ed47763bdc783c48268255843c8a51c812c8d7 (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-6791",
                "severity": "UNKNOWN",
                "pkg": "libcrypt1",
                "installed": "2.43-r8",
                "fixed": "2.43-r10",
                "title": null,
                "url": null,
                "targets": [
                  "ghcr.io/quenchworks/images/openbao@sha256:65a1094c0ebd23cb2183cabac0ed47763bdc783c48268255843c8a51c812c8d7 (wolfi 20230201)"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.40.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/bao"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "openfga",
      "name": "openfga",
      "category": "Identity",
      "summary": "Fine-grained authorization engine (Zanzibar-style relationship-based access control) over HTTP and gRPC. From source on a hardened nonroot Wolfi base; datastore is the operator's choice.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.1",
      "versions": [
        {
          "version": "1.18.1",
          "size": "20.6 MB",
          "published": "2026-07-26T12:32:15Z",
          "digest": "sha256:74d0198bcd52281d335e1e9c120a4d78154191204f90a8f75e6db38fde482977"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://openfga.dev",
      "source": "https://github.com/openfga/openfga",
      "image": "ghcr.io/quenchworks/images/openfga",
      "security": {
        "image": "ghcr.io/quenchworks/images/openfga",
        "version": "1.18.1",
        "tag": "ghcr.io/quenchworks/images/openfga:1.18.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.18.1",
            "tag": "ghcr.io/quenchworks/images/openfga:1.18.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "openldap",
      "name": "openldap",
      "category": "Identity",
      "summary": "OpenLDAP slapd, the reference open-source LDAP directory server, with the LMDB (back-mdb) backend and the client tools. Runs nonroot on unprivileged ports 1389/1636 and backs directory-driven auth for the identity stack.",
      "tier": "standard",
      "status": "available",
      "license": "OLDAP-2.8",
      "licenseClean": "clean",
      "version": "2.6.13",
      "versions": [
        {
          "version": "2.6.13",
          "size": "11.9 MB",
          "published": "2026-07-26T12:27:22Z",
          "digest": "sha256:b4c9a8113cf797fb24528d2557671edb9021ebe34540ca1d5e9e5cf899142d86"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.openldap.org",
      "source": "https://git.openldap.org/openldap/openldap",
      "image": "ghcr.io/quenchworks/images/openldap",
      "security": {
        "image": "ghcr.io/quenchworks/images/openldap",
        "version": "2.6.13",
        "tag": "ghcr.io/quenchworks/images/openldap:2.6.13",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.6.13",
            "tag": "ghcr.io/quenchworks/images/openldap:2.6.13",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "opensearch",
      "name": "OpenSearch",
      "category": "Search",
      "summary": "Search and analytics suite with a Kibana-style dashboards UI. The Apache-2.0 community fork of Elasticsearch and the recommended open alternative.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.7.0",
      "versions": [
        {
          "version": "3.7.0",
          "size": "965.3 MB",
          "published": "2026-07-15T11:22:08Z",
          "digest": "sha256:b14f3ca466499405a7f2d0b375d8976eb7e1eec7c9a40aae2e37c83eb9b32e6b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/opensearch-project/OpenSearch",
      "source": "https://github.com/opensearch-project/OpenSearch",
      "image": "ghcr.io/quenchworks/images/opensearch",
      "security": {
        "image": "ghcr.io/quenchworks/images/opensearch",
        "version": "3.7.0",
        "tag": "ghcr.io/quenchworks/images/opensearch:3.7.0",
        "critical": 0,
        "high": 19,
        "medium": 30,
        "low": 0,
        "unknown": 0,
        "total": 49,
        "fixable": 49,
        "grade": "D",
        "score": 0,
        "cves": [
          {
            "id": "CVE-2026-10050",
            "severity": "HIGH",
            "pkg": "org.eclipse.jetty:jetty-security",
            "installed": "9.4.58.v20250814",
            "fixed": "9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
            "title": "Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution",
            "url": "https://avd.aquasec.com/nvd/cve-2026-10050",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-55831",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing",
            "url": "https://avd.aquasec.com/nvd/cve-2026-55831",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-55833",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification",
            "url": "https://avd.aquasec.com/nvd/cve-2026-55833",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-56745",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56745",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-56816",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-http3",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final",
            "title": "Netty is a network application framework for development of protocol s ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56816",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59901",
            "severity": "HIGH",
            "pkg": "io.netty:netty-codec-compression",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final",
            "title": "io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59901",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "GHSA-r7wm-3cxj-wff9",
            "severity": "HIGH",
            "pkg": "com.fasterxml.jackson.core:jackson-core",
            "installed": "2.21.3",
            "fixed": "2.18.8, 2.21.4, 2.22.1",
            "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
            "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "GHSA-r7wm-3cxj-wff9",
            "severity": "HIGH",
            "pkg": "tools.jackson.core:jackson-core",
            "installed": "3.1.3",
            "fixed": "3.1.4, 3.2.1",
            "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
            "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-56746",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header",
            "url": "https://avd.aquasec.com/nvd/cve-2026-56746",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59889",
            "severity": "MEDIUM",
            "pkg": "tools.jackson.core:jackson-databind",
            "installed": "3.1.4",
            "fixed": "3.1.5, 3.2.1",
            "title": "jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59889",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59898",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59898",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59899",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59899",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59900",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http2",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59900",
            "targets": [
              "Java"
            ]
          },
          {
            "id": "CVE-2026-59921",
            "severity": "MEDIUM",
            "pkg": "io.netty:netty-codec-http",
            "installed": "4.2.15.Final",
            "fixed": "4.2.16.Final, 4.1.136.Final",
            "title": "io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59921",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.0",
            "tag": "ghcr.io/quenchworks/images/opensearch:3.7.0",
            "critical": 0,
            "high": 19,
            "medium": 30,
            "low": 0,
            "unknown": 0,
            "total": 49,
            "fixable": 49,
            "grade": "D",
            "score": 0,
            "cves": [
              {
                "id": "CVE-2026-10050",
                "severity": "HIGH",
                "pkg": "org.eclipse.jetty:jetty-security",
                "installed": "9.4.58.v20250814",
                "fixed": "9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10",
                "title": "Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution",
                "url": "https://avd.aquasec.com/nvd/cve-2026-10050",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-55831",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55831",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-55833",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification",
                "url": "https://avd.aquasec.com/nvd/cve-2026-55833",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-56745",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56745",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-56816",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-http3",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final",
                "title": "Netty is a network application framework for development of protocol s ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56816",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59901",
                "severity": "HIGH",
                "pkg": "io.netty:netty-codec-compression",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final",
                "title": "io.netty/netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59901",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "GHSA-r7wm-3cxj-wff9",
                "severity": "HIGH",
                "pkg": "com.fasterxml.jackson.core:jackson-core",
                "installed": "2.21.3",
                "fixed": "2.18.8, 2.21.4, 2.22.1",
                "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
                "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "GHSA-r7wm-3cxj-wff9",
                "severity": "HIGH",
                "pkg": "tools.jackson.core:jackson-core",
                "installed": "3.1.3",
                "fixed": "3.1.4, 3.2.1",
                "title": "jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)",
                "url": "https://github.com/advisories/GHSA-r7wm-3cxj-wff9",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-56746",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header",
                "url": "https://avd.aquasec.com/nvd/cve-2026-56746",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59889",
                "severity": "MEDIUM",
                "pkg": "tools.jackson.core:jackson-databind",
                "installed": "3.1.4",
                "fixed": "3.1.5, 3.2.1",
                "title": "jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59889",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59898",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Protocol version confusion in netty-codec-http (WebSocket)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59898",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59899",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59899",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59900",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http2",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http2: Netty: Improper header neutralization in netty-codec-http2",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59900",
                "targets": [
                  "Java"
                ]
              },
              {
                "id": "CVE-2026-59921",
                "severity": "MEDIUM",
                "pkg": "io.netty:netty-codec-http",
                "installed": "4.2.15.Final",
                "fixed": "4.2.16.Final, 4.1.136.Final",
                "title": "io.netty/netty-codec-http: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59921",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "otel-collector",
      "name": "OpenTelemetry Collector",
      "category": "Observability",
      "summary": "OpenTelemetry Collector that receives, processes, and exports traces, metrics, and logs, a vendor-neutral pipeline for telemetry routing.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.156.0",
      "versions": [
        {
          "version": "0.156.0",
          "size": "115.6 MB",
          "published": "2026-07-22T12:34:24Z",
          "digest": "sha256:4e544e87eb18026b7e717bcb1249d38ba3d63b0653d829f7c21f0f159048c752"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/open-telemetry/opentelemetry-collector",
      "source": "https://github.com/open-telemetry/opentelemetry-collector",
      "image": "ghcr.io/quenchworks/images/otel-collector",
      "security": {
        "image": "ghcr.io/quenchworks/images/otel-collector",
        "version": "0.156.0",
        "tag": "ghcr.io/quenchworks/images/otel-collector:0.156.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/otelcol-contrib"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.156.0",
            "tag": "ghcr.io/quenchworks/images/otel-collector:0.156.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/otelcol-contrib"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "opentofu",
      "name": "opentofu",
      "category": "CI/CD & registry",
      "summary": "Open-source, community-governed fork of Terraform, an infrastructure-as-code CLI. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "1.12.5",
      "versions": [
        {
          "version": "1.12.5",
          "size": "34.8 MB",
          "published": "2026-07-22T11:30:24Z",
          "digest": "sha256:9a2a0f9da641c4a42d6e37933c975f4defce1ef41fd8531745f53c41501775e9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://opentofu.org",
      "source": "https://github.com/opentofu/opentofu",
      "image": "ghcr.io/quenchworks/images/opentofu",
      "security": {
        "image": "ghcr.io/quenchworks/images/opentofu",
        "version": "1.12.5",
        "tag": "ghcr.io/quenchworks/images/opentofu:1.12.5",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/tofu"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/tofu"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.12.5",
            "tag": "ghcr.io/quenchworks/images/opentofu:1.12.5",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/tofu"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/tofu"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "perl",
      "name": "perl",
      "category": "Language runtime",
      "summary": "Hardened Perl interpreter for scripts, text processing, and tooling. A base image to FROM for Perl workloads. Latest stable (5).",
      "tier": "standard",
      "status": "available",
      "license": "Artistic-1.0-Perl OR GPL-1.0+",
      "licenseClean": "clean",
      "version": "5.44.0",
      "versions": [
        {
          "version": "5.44.0",
          "size": "14.2 MB",
          "published": "2026-07-21T08:40:43Z",
          "digest": "sha256:36a30810647ea6f05a969d7fec00a58a8b3c62a055e9363469e9a95e1f262182"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.perl.org",
      "source": "https://www.perl.org",
      "image": "ghcr.io/quenchworks/images/perl",
      "security": {
        "image": "ghcr.io/quenchworks/images/perl",
        "version": "5.44.0",
        "tag": "ghcr.io/quenchworks/images/perl:5.44.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "5.44.0",
            "tag": "ghcr.io/quenchworks/images/perl:5.44.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "perses",
      "name": "perses",
      "category": "Observability",
      "summary": "CNCF dashboards and observability visualization tool with an embedded React UI and 24 default panel/datasource plugins. From source (Node UI build embedded in a static Go binary) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.53.1",
      "versions": [
        {
          "version": "0.53.1",
          "size": "92.1 MB",
          "published": "2026-07-26T12:32:23Z",
          "digest": "sha256:10bad8982a39acfa681a6824fadb66d17bdc2d22c59406e69dbb6af11eea7147"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://perses.dev",
      "source": "https://github.com/perses/perses",
      "image": "ghcr.io/quenchworks/images/perses",
      "security": {
        "image": "ghcr.io/quenchworks/images/perses",
        "version": "0.53.1",
        "tag": "ghcr.io/quenchworks/images/perses:0.53.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/percli",
              "usr/bin/perses"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.53.1",
            "tag": "ghcr.io/quenchworks/images/perses:0.53.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/percli",
                  "usr/bin/perses"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pgbouncer",
      "name": "pgbouncer",
      "category": "Relational",
      "summary": "Lightweight connection pooler for PostgreSQL that fronts thousands of client connections with a small backend pool, cutting per-connection overhead.",
      "tier": "standard",
      "status": "available",
      "license": "ISC",
      "licenseClean": "clean",
      "version": "1.23.1, 1.25.2, 1.24.1",
      "versions": [
        {
          "version": "1.23.1",
          "size": "7.6 MB",
          "published": "2026-07-04T11:33:03Z",
          "digest": "sha256:6b5f4dfe415ec733457ef43a575750832ec531969e9dd36695a6cdd6d9173b4b"
        },
        {
          "version": "1.25.2",
          "size": "7.6 MB",
          "published": "2026-07-04T11:31:43Z",
          "digest": "sha256:e1c0e92e4abb1259def3adb3766fece53f2c90c10aad1cfc867ab8f102a6efe6"
        },
        {
          "version": "1.24.1",
          "size": "7.6 MB",
          "published": "2026-07-04T11:31:01Z",
          "digest": "sha256:4a27e34aa9b7f123dcd1d9c094f265a4f8dc70d1c35306c0dfdff1b20c08a0de"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/pgbouncer/pgbouncer",
      "source": "https://github.com/pgbouncer/pgbouncer",
      "image": "ghcr.io/quenchworks/images/pgbouncer",
      "security": {
        "image": "ghcr.io/quenchworks/images/pgbouncer",
        "version": "1.25.2",
        "tag": "ghcr.io/quenchworks/images/pgbouncer:1.25.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.25.2",
            "tag": "ghcr.io/quenchworks/images/pgbouncer:1.25.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.24.1",
            "tag": "ghcr.io/quenchworks/images/pgbouncer:1.24.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.23.1",
            "tag": "ghcr.io/quenchworks/images/pgbouncer:1.23.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "pgpool",
      "name": "pgpool",
      "category": "Relational",
      "summary": "PostgreSQL connection pooler, load balancer and query router. Pools client connections, spreads read-only queries across streaming-replication standbys, and detaches a backend that fails its health check.",
      "tier": "standard",
      "status": "available",
      "license": "HPND",
      "licenseClean": "clean",
      "version": "4.6.7, 4.5.12, 4.7.2",
      "versions": [
        {
          "version": "4.6.7",
          "size": "16.3 MB",
          "published": "2026-07-28T06:23:46Z",
          "digest": "sha256:0eb712cefc80ca75349da052b2bd2b3b568f71c99fde6517a4aba59275913944"
        },
        {
          "version": "4.5.12",
          "size": "16.1 MB",
          "published": "2026-07-28T06:23:45Z",
          "digest": "sha256:32f77780a23df79110cf72da280f00a9f61dd074aaff5ab60ccab5dc60aa8274"
        },
        {
          "version": "4.7.2",
          "size": "16.4 MB",
          "published": "2026-07-28T06:23:33Z",
          "digest": "sha256:4dea6db1cc99a9821959378a89fb70625382e8c745eca055a19db8d7ab9385e9"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://git.postgresql.org/gitweb/?p=pgpool2.git",
      "source": "https://www.pgpool.net/source/",
      "image": "ghcr.io/quenchworks/images/pgpool",
      "security": {
        "image": "ghcr.io/quenchworks/images/pgpool",
        "version": "4.7.2",
        "tag": "ghcr.io/quenchworks/images/pgpool:4.7.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.7.2",
            "tag": "ghcr.io/quenchworks/images/pgpool:4.7.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.6.7",
            "tag": "ghcr.io/quenchworks/images/pgpool:4.6.7",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.5.12",
            "tag": "ghcr.io/quenchworks/images/pgpool:4.5.12",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "php",
      "name": "php",
      "category": "Language runtime",
      "summary": "Hardened PHP CLI with common extensions, a base image to FROM for PHP apps. Latest 3 stable lines (8.3/8.4/8.5).",
      "tier": "standard",
      "status": "available",
      "license": "PHP-3.01",
      "licenseClean": "clean",
      "version": "8.5.9, 8.4.24, 8.3.33",
      "versions": [
        {
          "version": "8.5.9",
          "size": "48.2 MB",
          "published": "2026-07-30T08:12:46Z",
          "digest": "sha256:0a3ae5198ca12e4072a933237480b1a7a5488e6da3c341b15d80d2f6773261dc"
        },
        {
          "version": "8.4.24",
          "size": "47.3 MB",
          "published": "2026-07-30T08:12:46Z",
          "digest": "sha256:0bef71b1a74bae74b618cfc6d036b0ac4a8d71e1489060a4d7396bc5ce5ef1a1"
        },
        {
          "version": "8.3.33",
          "size": "46.3 MB",
          "published": "2026-07-30T08:12:40Z",
          "digest": "sha256:847c7480eebd3e8b0b8b214692156291aed2c3986a77816c50e0621c1a998e0c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/php/php-src",
      "source": "https://github.com/php/php-src",
      "image": "ghcr.io/quenchworks/images/php",
      "security": {
        "image": "ghcr.io/quenchworks/images/php",
        "version": "8.5.8",
        "tag": "ghcr.io/quenchworks/images/php:8.5.8",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "8.5.8",
            "tag": "ghcr.io/quenchworks/images/php:8.5.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.4.23",
            "tag": "ghcr.io/quenchworks/images/php:8.4.23",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.3.32",
            "tag": "ghcr.io/quenchworks/images/php:8.3.32",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "pnpm",
      "name": "pnpm",
      "category": "Build tool",
      "summary": "Node base image with pnpm preinstalled via corepack, used as the build stage for pnpm projects. Lines 10/11.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "11.18.0",
      "versions": [
        {
          "version": "11.18.0",
          "size": "60.8 MB",
          "published": "2026-07-30T08:08:01Z",
          "digest": "sha256:6651a33a5602886ea5c2bc046ecee4dc89fd2861185f4d23662cac67715722ea"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://pnpm.io",
      "source": "https://pnpm.io",
      "image": "ghcr.io/quenchworks/images/pnpm",
      "security": {
        "image": "ghcr.io/quenchworks/images/pnpm",
        "version": "11.17.0",
        "tag": "ghcr.io/quenchworks/images/pnpm:11.17.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "11.17.0",
            "tag": "ghcr.io/quenchworks/images/pnpm:11.17.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "pocketbase",
      "name": "pocketbase",
      "category": "Apps & productivity",
      "summary": "Open-source backend in a single file with an embedded SQLite database, auth, file storage, realtime subscriptions, and an admin dashboard over a REST API. Pure-Go static binary (UI embedded) on a hardened nonroot Wolfi base; state on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.39.5",
      "versions": [
        {
          "version": "0.39.5",
          "size": "12.2 MB",
          "published": "2026-07-22T07:05:12Z",
          "digest": "sha256:01c7db103bf8030aa55e3732a8c416bd9947d055b941546e860618cb4e8a9d32"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://pocketbase.io",
      "source": "https://github.com/pocketbase/pocketbase",
      "image": "ghcr.io/quenchworks/images/pocketbase",
      "security": {
        "image": "ghcr.io/quenchworks/images/pocketbase",
        "version": "0.39.5",
        "tag": "ghcr.io/quenchworks/images/pocketbase:0.39.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 97,
        "cves": [
          {
            "id": "CVE-2023-36308",
            "severity": "LOW",
            "pkg": "github.com/disintegration/imaging",
            "installed": "v1.6.2",
            "fixed": null,
            "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
            "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
            "targets": [
              "usr/bin/pocketbase"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/pocketbase"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.39.5",
            "tag": "ghcr.io/quenchworks/images/pocketbase:0.39.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 97,
            "cves": [
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/pocketbase"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pocketbase"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "poetry",
      "name": "poetry",
      "category": "Build tool",
      "summary": "Python base image with Poetry for dependency management and packaging, used as the build stage for Python projects. Line 2.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "2.4.1",
      "versions": [
        {
          "version": "2.4.1",
          "size": "47.2 MB",
          "published": "2026-07-26T12:32:01Z",
          "digest": "sha256:f438a25432152aeb6e46ab2ef819bf77cf72a79cc2192035fb90c65442d97653"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://python-poetry.org",
      "source": "https://python-poetry.org",
      "image": "ghcr.io/quenchworks/images/poetry",
      "security": {
        "image": "ghcr.io/quenchworks/images/poetry",
        "version": "2.4.1",
        "tag": "ghcr.io/quenchworks/images/poetry:2.4.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.4.1",
            "tag": "ghcr.io/quenchworks/images/poetry:2.4.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "postgres-exporter",
      "name": "postgres-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter that collects PostgreSQL activity, replication, and performance stats and exposes them as metrics for monitoring.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.20.1",
      "versions": [
        {
          "version": "0.20.1",
          "size": "5.6 MB",
          "published": "2026-07-15T12:44:12Z",
          "digest": "sha256:f92a94662c76f6d76d1befc1238214829453db48d22ff595123bde0338bd1417"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus-community/postgres_exporter",
      "source": "https://github.com/prometheus-community/postgres_exporter",
      "image": "ghcr.io/quenchworks/images/postgres-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgres-exporter",
        "version": "0.20.1",
        "tag": "ghcr.io/quenchworks/images/postgres-exporter:0.20.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/postgres_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.20.1",
            "tag": "ghcr.io/quenchworks/images/postgres-exporter:0.20.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/postgres_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "postgresql",
      "name": "PostgreSQL",
      "category": "Relational",
      "summary": "Advanced open-source relational database (v18.x) with strong SQL, ACID transactions, JSON, and a rich extension ecosystem. The catalog's default SQL engine.",
      "tier": "critical",
      "status": "available",
      "license": "PostgreSQL",
      "licenseClean": "clean",
      "version": "16.14, 17.10, 18.4",
      "versions": [
        {
          "version": "16.14",
          "size": "81.3 MB",
          "published": "2026-07-30T10:29:32Z",
          "digest": "sha256:cb695b1904e10ccc925d1d64fd543ab7ce9e088df25c9c7e25245a4f53e297af"
        },
        {
          "version": "17.10",
          "size": "82.0 MB",
          "published": "2026-07-30T10:29:32Z",
          "digest": "sha256:756816dfcc66557d1b1886c483d1d00f87be8515a5604306649a822549449856"
        },
        {
          "version": "18.4",
          "size": "82.4 MB",
          "published": "2026-07-30T10:29:22Z",
          "digest": "sha256:949125181299709eff3ede2d74a3d04dd982279a3510ffcc907eae51eb037fd3"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/postgres/postgres",
      "source": "https://ftp.postgresql.org/pub/source/v18.4/postgresql-18.4.tar.bz2",
      "image": "ghcr.io/quenchworks/images/postgresql",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgresql",
        "version": "18.4",
        "tag": "ghcr.io/quenchworks/images/postgresql:18.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "18.4",
            "tag": "ghcr.io/quenchworks/images/postgresql:18.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "17.10",
            "tag": "ghcr.io/quenchworks/images/postgresql:17.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "16.14",
            "tag": "ghcr.io/quenchworks/images/postgresql:16.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "postgres-documentdb",
      "name": "PostgreSQL + DocumentDB",
      "category": "Document",
      "summary": "PostgreSQL 17 plus the open DocumentDB extension, providing BSON document storage and queries. The storage backend that powers FerretDB v2.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "0.105.0, 0.106.0, 0.107.0",
      "versions": [
        {
          "version": "0.105.0",
          "size": "135.5 MB",
          "published": "2026-07-04T11:25:42Z",
          "digest": "sha256:4fc3a6f6f00cb67ee6ce401bda8a66f3e928c1f78333a040fe66cf6bd4df85b9"
        },
        {
          "version": "0.106.0",
          "size": "135.6 MB",
          "published": "2026-07-04T11:25:18Z",
          "digest": "sha256:f4968ed36f0e055d60b97a1f5229879253843106476175c30206705e9f45a88b"
        },
        {
          "version": "0.107.0",
          "size": "135.8 MB",
          "published": "2026-07-04T11:21:41Z",
          "digest": "sha256:39c2571a1ec2c21922b082462198a1afa34abfb32fc54b23463ed1663a2cf73c"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/FerretDB/documentdb",
      "source": "https://github.com/FerretDB/documentdb",
      "image": "ghcr.io/quenchworks/images/postgres-documentdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgres-documentdb",
        "version": "0.107.0",
        "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.107.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.107.0",
            "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.107.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.106.0",
            "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.106.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.105.0",
            "tag": "ghcr.io/quenchworks/images/postgres-documentdb:0.105.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "postgresql-15",
      "name": "PostgreSQL 15",
      "category": "Relational",
      "summary": "PostgreSQL 15.x build for the Coolify wave, which pins PG 15 (the default postgresql image tracks 18.x). Same hardened build with bundled contrib extensions.",
      "tier": "critical",
      "status": "available",
      "license": "PostgreSQL",
      "licenseClean": "clean",
      "version": "15.17, 15.18, 15.16",
      "versions": [
        {
          "version": "15.17",
          "size": "52.6 MB",
          "published": "2026-07-04T11:32:02Z",
          "digest": "sha256:e5a7b8ec08564aa5fa8120cbdd74dc3c8423bdb95a5262799a20b3da96e92590"
        },
        {
          "version": "15.18",
          "size": "52.7 MB",
          "published": "2026-07-04T11:29:02Z",
          "digest": "sha256:037f012988d7de9e7fad2d4407c3179c37dc8aeff0c616d010a77ea8b16615b6"
        },
        {
          "version": "15.16",
          "size": "52.7 MB",
          "published": "2026-07-04T11:23:43Z",
          "digest": "sha256:92ef9ebd49fe1709eca6c7899053453fb9d87898108c4c92d759227123e97263"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://ftp.postgresql.org/pub/source/v15.18/postgresql-15.18.tar.bz2",
      "source": "https://ftp.postgresql.org/pub/source/v15.18/postgresql-15.18.tar.bz2",
      "image": "ghcr.io/quenchworks/images/postgresql-15",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgresql-15",
        "version": "15.18",
        "tag": "ghcr.io/quenchworks/images/postgresql-15:15.18",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "15.18",
            "tag": "ghcr.io/quenchworks/images/postgresql-15:15.18",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "15.17",
            "tag": "ghcr.io/quenchworks/images/postgresql-15:15.17",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "15.16",
            "tag": "ghcr.io/quenchworks/images/postgresql-15:15.16",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "postgrest",
      "name": "postgrest",
      "category": "Databases & engines",
      "summary": "REST API server that serves a RESTful API directly from a PostgreSQL schema. Shipped as upstream's official prebuilt static binary. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "14.15, 14.14, 14.16",
      "versions": [
        {
          "version": "14.15",
          "size": "9.7 MB",
          "published": "2026-07-28T09:49:30Z",
          "digest": "sha256:2e238170b4b3a4fe93e25981968e936316ff670478e7b6886988079b1dcdc160"
        },
        {
          "version": "14.14",
          "size": "9.7 MB",
          "published": "2026-07-28T09:49:23Z",
          "digest": "sha256:d9c1d565dff3e7a1cd9a5dce41f2e0dafcde3e2831dbe2c595d0122a9e4081b6"
        },
        {
          "version": "14.16",
          "size": "9.7 MB",
          "published": "2026-07-28T09:49:08Z",
          "digest": "sha256:3d2ea136a7edf4644b8625ec664ca3fd21400446fccf3b778087f78f8817896f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://postgrest.org",
      "source": "https://github.com/PostgREST/postgrest",
      "image": "ghcr.io/quenchworks/images/postgrest",
      "security": {
        "image": "ghcr.io/quenchworks/images/postgrest",
        "version": "14.16",
        "tag": "ghcr.io/quenchworks/images/postgrest:14.16",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "14.16",
            "tag": "ghcr.io/quenchworks/images/postgrest:14.16",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "14.15",
            "tag": "ghcr.io/quenchworks/images/postgrest:14.15",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "14.14",
            "tag": "ghcr.io/quenchworks/images/postgrest:14.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "prometheus",
      "name": "Prometheus",
      "category": "Observability",
      "summary": "Metrics collection, storage, and alerting system that scrapes targets and runs PromQL queries. The de-facto cloud-native monitoring TSDB.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.13.1",
      "versions": [
        {
          "version": "3.13.1",
          "size": "57.3 MB",
          "published": "2026-07-22T07:09:45Z",
          "digest": "sha256:75da3329773a48704c8337b1dc10b1d651ed0011261087a4feb8ebe40262e2de"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/prometheus/prometheus",
      "source": "https://github.com/prometheus/prometheus",
      "image": "ghcr.io/quenchworks/images/prometheus",
      "security": {
        "image": "ghcr.io/quenchworks/images/prometheus",
        "version": "3.13.1",
        "tag": "ghcr.io/quenchworks/images/prometheus:3.13.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/prometheus",
              "usr/bin/promtool"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.13.1",
            "tag": "ghcr.io/quenchworks/images/prometheus:3.13.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/prometheus",
                  "usr/bin/promtool"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pulsar",
      "name": "Pulsar",
      "category": "Messaging",
      "summary": "Cloud-native distributed messaging and streaming platform with multi-tenancy, geo-replication, and tiered storage that separates compute from storage.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.2.3",
      "versions": [
        {
          "version": "4.2.3",
          "size": "311.4 MB",
          "published": "2026-07-28T06:56:07Z",
          "digest": "sha256:6a11b321dba3c75a7d88f4d2e9c7334a85b021e7184ca083a0d98331efa94f36"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/pulsar",
      "source": "https://github.com/apache/pulsar",
      "image": "ghcr.io/quenchworks/images/pulsar",
      "security": {
        "image": "ghcr.io/quenchworks/images/pulsar",
        "version": "4.2.3",
        "tag": "ghcr.io/quenchworks/images/pulsar:4.2.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.2.3",
            "tag": "ghcr.io/quenchworks/images/pulsar:4.2.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "pulumi",
      "name": "pulumi",
      "category": "CI/CD & registry",
      "summary": "Infrastructure-as-code CLI for managing cloud resources with general-purpose programming languages. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.253.0, 3.254.0, 3.255.0",
      "versions": [
        {
          "version": "3.253.0",
          "size": "34.3 MB",
          "published": "2026-07-30T08:12:23Z",
          "digest": "sha256:322a74d6fcc458f1b5f584a4eb1d074c264b1d9b2a3efb4f7691c8402faac78f"
        },
        {
          "version": "3.254.0",
          "size": "34.6 MB",
          "published": "2026-07-30T08:12:07Z",
          "digest": "sha256:24c099eb9ee79f9213dacf689d7a922259eb69229a8dc9bab4fcf049ddc331c0"
        },
        {
          "version": "3.255.0",
          "size": "34.6 MB",
          "published": "2026-07-30T08:11:04Z",
          "digest": "sha256:c3fb398da0e6c7c1c6e58d0b1800bae0a47a2972d78e1d70e7090c408e73c382"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.pulumi.com",
      "source": "https://github.com/pulumi/pulumi",
      "image": "ghcr.io/quenchworks/images/pulumi",
      "security": {
        "image": "ghcr.io/quenchworks/images/pulumi",
        "version": "3.254.0",
        "tag": "ghcr.io/quenchworks/images/pulumi:3.254.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/pulumi"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.254.0",
            "tag": "ghcr.io/quenchworks/images/pulumi:3.254.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pulumi"
                ]
              }
            ]
          },
          {
            "version": "3.253.0",
            "tag": "ghcr.io/quenchworks/images/pulumi:3.253.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pulumi"
                ]
              }
            ]
          },
          {
            "version": "3.252.0",
            "tag": "ghcr.io/quenchworks/images/pulumi:3.252.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pulumi"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "pyroscope",
      "name": "pyroscope",
      "category": "Observability",
      "summary": "Continuous profiling database for analyzing CPU, memory, and other resource usage over time. From source with the React UI embedded (no Node at runtime) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2.1.0",
      "versions": [
        {
          "version": "2.1.0",
          "size": "31.1 MB",
          "published": "2026-07-22T07:09:55Z",
          "digest": "sha256:d1c3716254a3d83ac12a78d08b03a7bad82b5330eb4b6fb82be26c888a3af552"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://grafana.com/oss/pyroscope",
      "source": "https://github.com/grafana/pyroscope",
      "image": "ghcr.io/quenchworks/images/pyroscope",
      "security": {
        "image": "ghcr.io/quenchworks/images/pyroscope",
        "version": "2.1.0",
        "tag": "ghcr.io/quenchworks/images/pyroscope:2.1.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/pyroscope"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.1.0",
            "tag": "ghcr.io/quenchworks/images/pyroscope:2.1.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/pyroscope"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "python",
      "name": "python",
      "category": "Language runtime",
      "summary": "Hardened CPython interpreter with pip, a 0-CVE signed nonroot base image to FROM for Python apps. Ships the latest 3 stable minors (no :latest).",
      "tier": "standard",
      "status": "available",
      "license": "PSF-2.0",
      "licenseClean": "clean",
      "version": "3.13.14, 3.12.13, 3.14.6",
      "versions": [
        {
          "version": "3.13.14",
          "size": "29.5 MB",
          "published": "2026-07-26T12:36:37Z",
          "digest": "sha256:fd6b1db256d3871e79b6c9c52a079abf34867195e185c86bc2085cd8d8cb5a67"
        },
        {
          "version": "3.12.13",
          "size": "29.8 MB",
          "published": "2026-07-26T12:36:33Z",
          "digest": "sha256:3415f111409eb9431c59054037c8166fdb1fb893518f9ca1686ae9cb1f5d8d8f"
        },
        {
          "version": "3.14.6",
          "size": "31.0 MB",
          "published": "2026-07-26T12:36:03Z",
          "digest": "sha256:e286f6249932951787969db8530aae31d486db6e1754c66b3789215f272adb3f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.python.org",
      "source": "https://www.python.org",
      "image": "ghcr.io/quenchworks/images/python",
      "security": {
        "image": "ghcr.io/quenchworks/images/python",
        "version": "3.14.6",
        "tag": "ghcr.io/quenchworks/images/python:3.14.6",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.14.6",
            "tag": "ghcr.io/quenchworks/images/python:3.14.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.13.14",
            "tag": "ghcr.io/quenchworks/images/python:3.13.14",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.12.13",
            "tag": "ghcr.io/quenchworks/images/python:3.12.13",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "qdrant",
      "name": "Qdrant",
      "category": "Vector",
      "summary": "Vector database and similarity-search engine for AI embeddings, powering semantic search, recommendations, and RAG with filtered nearest-neighbor queries.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.3",
      "versions": [
        {
          "version": "1.18.3",
          "size": "43.5 MB",
          "published": "2026-07-21T09:16:50Z",
          "digest": "sha256:981a6f4dd9924a6b6630ccb29419ecb5b4b1963db830b0b2d1793041281f4ff2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/qdrant/qdrant",
      "source": "https://github.com/qdrant/qdrant",
      "image": "ghcr.io/quenchworks/images/qdrant",
      "security": {
        "image": "ghcr.io/quenchworks/images/qdrant",
        "version": "1.18.3",
        "tag": "ghcr.io/quenchworks/images/qdrant:1.18.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.18.3",
            "tag": "ghcr.io/quenchworks/images/qdrant:1.18.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "questdb",
      "name": "questdb",
      "category": "Time series",
      "summary": "High-performance time-series SQL database for fast ingestion and queries over metrics, financial ticks, and IoT data, with PostgreSQL-wire and InfluxDB line-protocol ingestion.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "9.4.2, 9.4.3, 9.4.1",
      "versions": [
        {
          "version": "9.4.2",
          "size": "117.5 MB",
          "published": "2026-07-23T06:48:26Z",
          "digest": "sha256:0d56f8fc3555c66ab774ed18e718159e87e72b378a97faeeaa8c059feff4d9e8"
        },
        {
          "version": "9.4.3",
          "size": "117.7 MB",
          "published": "2026-07-23T06:48:26Z",
          "digest": "sha256:dcb5f489ccf8419df8baaf29f81d12d197a148edbfa89a96e37ac0b5cbf1b582"
        },
        {
          "version": "9.4.1",
          "size": "117.6 MB",
          "published": "2026-07-23T06:48:21Z",
          "digest": "sha256:fc86ab64a9a2cea47ff09672394a371af694ba3fc57951c490a8d86f97cc2686"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/questdb/questdb",
      "source": "https://github.com/questdb/questdb",
      "image": "ghcr.io/quenchworks/images/questdb",
      "security": {
        "image": "ghcr.io/quenchworks/images/questdb",
        "version": "9.4.3",
        "tag": "ghcr.io/quenchworks/images/questdb:9.4.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.4.3",
            "tag": "ghcr.io/quenchworks/images/questdb:9.4.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.4.2",
            "tag": "ghcr.io/quenchworks/images/questdb:9.4.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.4.1",
            "tag": "ghcr.io/quenchworks/images/questdb:9.4.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "quickwit",
      "name": "quickwit",
      "category": "Search",
      "summary": "Cloud-native search engine for logs, traces, and analytics with sub-second search over object storage. Built from Rust source (UI embedded, no Node at runtime) on a hardened nonroot Wolfi base; index data on object storage or a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "0.8.2",
      "versions": [
        {
          "version": "0.8.2",
          "size": "95.0 MB",
          "published": "2026-07-03T04:02:11Z",
          "digest": "sha256:c4ae313ed9dc0e7539bfc4315779a4cd1baef6878b10f87d0d9da8ecf2da81ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://quickwit.io",
      "source": "https://github.com/quickwit-oss/quickwit",
      "image": "ghcr.io/quenchworks/images/quickwit",
      "security": {
        "image": "ghcr.io/quenchworks/images/quickwit",
        "version": "0.8.2",
        "tag": "ghcr.io/quenchworks/images/quickwit:0.8.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.8.2",
            "tag": "ghcr.io/quenchworks/images/quickwit:0.8.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rabbitmq",
      "name": "RabbitMQ",
      "category": "Messaging",
      "summary": "Reliable message broker speaking AMQP plus MQTT and STOMP, with flexible routing, queues, and acknowledgements for decoupling services.",
      "tier": "critical",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "4.3.4, 4.1.8, 4.2.8",
      "versions": [
        {
          "version": "4.3.4",
          "size": "128.9 MB",
          "published": "2026-07-26T12:37:56Z",
          "digest": "sha256:9321555e564ac1c81379902143635a43e5cff262578d37c8707d868cbaf05851"
        },
        {
          "version": "4.1.8",
          "size": "128.5 MB",
          "published": "2026-07-26T12:37:55Z",
          "digest": "sha256:21f9ebcb9176abdd209711b99b6bd3b9bf27b7277236a03fc6228ce34a834d1f"
        },
        {
          "version": "4.2.8",
          "size": "128.7 MB",
          "published": "2026-07-26T12:37:51Z",
          "digest": "sha256:b5529bf9ebb20af69813b5e05892cbad8b51f13d36964900933b28507ced8623"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/rabbitmq/rabbitmq-server",
      "source": "https://github.com/rabbitmq/rabbitmq-server",
      "image": "ghcr.io/quenchworks/images/rabbitmq",
      "security": {
        "image": "ghcr.io/quenchworks/images/rabbitmq",
        "version": "4.3.4",
        "tag": "ghcr.io/quenchworks/images/rabbitmq:4.3.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.3.4",
            "tag": "ghcr.io/quenchworks/images/rabbitmq:4.3.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.2.8",
            "tag": "ghcr.io/quenchworks/images/rabbitmq:4.2.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "4.1.8",
            "tag": "ghcr.io/quenchworks/images/rabbitmq:4.1.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rclone",
      "name": "rclone",
      "category": "Storage & platform",
      "summary": "Command-line program to sync files and directories to and from dozens of cloud storage providers. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.74.4",
      "versions": [
        {
          "version": "1.74.4",
          "size": "27.7 MB",
          "published": "2026-07-22T07:07:36Z",
          "digest": "sha256:807979a2de55c6ee4b62756036aa9daeae6a5c97458e253d0c33c2aff1d763d2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://rclone.org",
      "source": "https://github.com/rclone/rclone",
      "image": "ghcr.io/quenchworks/images/rclone",
      "security": {
        "image": "ghcr.io/quenchworks/images/rclone",
        "version": "1.74.4",
        "tag": "ghcr.io/quenchworks/images/rclone:1.74.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/rclone"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.74.4",
            "tag": "ghcr.io/quenchworks/images/rclone:1.74.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/rclone"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "redis",
      "name": "Redis",
      "category": "Cache",
      "summary": "In-memory key-value store used as a cache, message broker, and ephemeral datastore. Shipped under AGPL (not permissive); Valkey is the BSD-licensed open alternative.",
      "tier": "critical",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "8.8.1, 8.10.0, 8.6.5",
      "versions": [
        {
          "version": "8.8.1",
          "size": "14.7 MB",
          "published": "2026-07-30T10:27:00Z",
          "digest": "sha256:e318315dd4c474df6823ecaeed8345aab845679c326d2589a453c7470f8c3d99"
        },
        {
          "version": "8.10.0",
          "size": "15.2 MB",
          "published": "2026-07-30T10:26:53Z",
          "digest": "sha256:95942647e5f2eeaefb01fd34d95d796b3fddfa5d38d67050710c8b99893d1c08"
        },
        {
          "version": "8.6.5",
          "size": "15.5 MB",
          "published": "2026-07-30T10:26:45Z",
          "digest": "sha256:9f94c4da0b3fef65f2879a16cbaa4d9511b073fda55704899ae1b72b0b3eb38b"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/redis/redis",
      "source": "https://download.redis.io/releases/redis-8.8.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/redis",
      "security": {
        "image": "ghcr.io/quenchworks/images/redis",
        "version": "8.8.1",
        "tag": "ghcr.io/quenchworks/images/redis:8.8.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "8.8.1",
            "tag": "ghcr.io/quenchworks/images/redis:8.8.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.6.4",
            "tag": "ghcr.io/quenchworks/images/redis:8.6.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.4.4",
            "tag": "ghcr.io/quenchworks/images/redis:8.4.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "redis-exporter",
      "name": "redis-exporter",
      "category": "Metrics/Exporter",
      "summary": "Prometheus exporter that scrapes Redis and Valkey runtime stats and exposes them as metrics for dashboards and alerts.",
      "tier": "critical",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.88.0, 1.86.0, 1.87.0",
      "versions": [
        {
          "version": "1.88.0",
          "size": "4.6 MB",
          "published": "2026-07-26T12:35:42Z",
          "digest": "sha256:aa1cbf997c0ca1770cb6e570b3702645294aadce9ade268015473d28c0f0e706"
        },
        {
          "version": "1.86.0",
          "size": "4.6 MB",
          "published": "2026-07-26T12:35:38Z",
          "digest": "sha256:2b06b1ddc455ef2a869ff526c1a1e8d2372c91b50dcf49d6749e730b06b2d41a"
        },
        {
          "version": "1.87.0",
          "size": "4.6 MB",
          "published": "2026-07-26T12:32:46Z",
          "digest": "sha256:ee25f477dee790cf59b0831c7dfaaa3517ac2f65d5ed8bed4710c09925536222"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/oliver006/redis_exporter",
      "source": "https://github.com/oliver006/redis_exporter",
      "image": "ghcr.io/quenchworks/images/redis-exporter",
      "security": {
        "image": "ghcr.io/quenchworks/images/redis-exporter",
        "version": "1.88.0",
        "tag": "ghcr.io/quenchworks/images/redis-exporter:1.88.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/redis_exporter"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.88.0",
            "tag": "ghcr.io/quenchworks/images/redis-exporter:1.88.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/redis_exporter"
                ]
              }
            ]
          },
          {
            "version": "1.87.0",
            "tag": "ghcr.io/quenchworks/images/redis-exporter:1.87.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/redis_exporter"
                ]
              }
            ]
          },
          {
            "version": "1.86.0",
            "tag": "ghcr.io/quenchworks/images/redis-exporter:1.86.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/redis_exporter"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "renovate",
      "name": "renovate",
      "category": "CI/CD & registry",
      "summary": "Automated dependency-update CLI that opens PRs to keep dependencies current, on a hardened Wolfi Node runtime. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "44.2.3",
      "versions": [
        {
          "version": "44.2.3",
          "size": "118.7 MB",
          "published": "2026-07-30T08:10:58Z",
          "digest": "sha256:dc333b313c76c2388e7e8aea64b2ca9d61577f2e3d66d9a86e83fb3f203b661e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.renovatebot.com",
      "source": "https://github.com/renovatebot/renovate",
      "image": "ghcr.io/quenchworks/images/renovate",
      "security": {
        "image": "ghcr.io/quenchworks/images/renovate",
        "version": "43.285.4",
        "tag": "ghcr.io/quenchworks/images/renovate:43.285.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "43.285.4",
            "tag": "ghcr.io/quenchworks/images/renovate:43.285.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rqlite",
      "name": "rqlite",
      "category": "Relational",
      "summary": "Lightweight, distributed relational database built on SQLite and Raft. Ships rqlited and the rqlite CLI as static (musl) Go binaries on a hardened nonroot Wolfi base; data dir is a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "10.2.5",
      "versions": [
        {
          "version": "10.2.5",
          "size": "18.9 MB",
          "published": "2026-07-22T07:06:53Z",
          "digest": "sha256:8322ad9a89976557cc70e94500ea1521a590a48cc0d8b41beffbff25c6a8a7e6"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://rqlite.io",
      "source": "https://github.com/rqlite/rqlite",
      "image": "ghcr.io/quenchworks/images/rqlite",
      "security": {
        "image": "ghcr.io/quenchworks/images/rqlite",
        "version": "10.2.5",
        "tag": "ghcr.io/quenchworks/images/rqlite:10.2.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/rqlite"
            ]
          }
        ],
        "versions": [
          {
            "version": "10.2.5",
            "tag": "ghcr.io/quenchworks/images/rqlite:10.2.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/rqlite"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "ruby",
      "name": "ruby",
      "category": "Language runtime",
      "summary": "Hardened Ruby interpreter with Bundler, a base image to FROM for Ruby apps. Latest 3 stable lines (3.2/3.3/3.4).",
      "tier": "standard",
      "status": "available",
      "license": "Ruby",
      "licenseClean": "clean",
      "version": "3.4.10",
      "versions": [
        {
          "version": "3.4.10",
          "size": "46.8 MB",
          "published": "2026-07-28T06:23:45Z",
          "digest": "sha256:c4b1d95136febeaf35b0c1ff78e46b2210f21509bff503d0a8cebe9a2a397d86"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/ruby/ruby",
      "source": "https://github.com/ruby/ruby",
      "image": "ghcr.io/quenchworks/images/ruby",
      "security": {
        "image": "ghcr.io/quenchworks/images/ruby",
        "version": "3.4.10",
        "tag": "ghcr.io/quenchworks/images/ruby:3.4.10",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.4.10",
            "tag": "ghcr.io/quenchworks/images/ruby:3.4.10",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rust",
      "name": "rust",
      "category": "Language runtime",
      "summary": "Hardened Rust toolchain (cargo plus rustc) for build stages; ship the compiled binary on the static base. Latest 3 stable lines (1.94/1.95/1.96).",
      "tier": "standard",
      "status": "available",
      "license": "MIT OR Apache-2.0",
      "licenseClean": "clean",
      "version": "1.97.1",
      "versions": [
        {
          "version": "1.97.1",
          "size": "363.4 MB",
          "published": "2026-07-28T06:23:59Z",
          "digest": "sha256:c5f367e37c0e1c43e802c15ba9d5d10cdfe334b4e28cbe595439f7ebd03cb043"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/rust-lang/rust",
      "source": "https://github.com/rust-lang/rust",
      "image": "ghcr.io/quenchworks/images/rust",
      "security": {
        "image": "ghcr.io/quenchworks/images/rust",
        "version": "1.97.1",
        "tag": "ghcr.io/quenchworks/images/rust:1.97.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.97.1",
            "tag": "ghcr.io/quenchworks/images/rust:1.97.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "rustfs",
      "name": "RustFS",
      "category": "Object storage",
      "summary": "S3-compatible, high-performance object store written in Rust with a zero-master architecture, positioned as an Apache-2.0 MinIO alternative. Beta/preview.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.0.0_beta10, 1.0.0_beta12, 1.0.0_beta11",
      "versions": [
        {
          "version": "1.0.0_beta10",
          "size": "77.3 MB",
          "published": "2026-07-30T10:25:56Z",
          "digest": "sha256:a641db726c9515ad2b63aca632a77847b552d8d9a14ab085e31864a6fbbcb68d"
        },
        {
          "version": "1.0.0_beta12",
          "size": "82.5 MB",
          "published": "2026-07-30T10:25:54Z",
          "digest": "sha256:db83dde295d0b8c980a16eb3bbb455116abdb56e1f9770389f85a063c759f18c"
        },
        {
          "version": "1.0.0_beta11",
          "size": "79.1 MB",
          "published": "2026-07-30T10:25:51Z",
          "digest": "sha256:04af0e91402e5e2a4edb329e6a51bd0e0bb3ce2d5748fa9193e8be5b1eced8ea"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/rustfs/rustfs",
      "source": "https://github.com/rustfs/rustfs",
      "image": "ghcr.io/quenchworks/images/rustfs",
      "security": {
        "image": "ghcr.io/quenchworks/images/rustfs",
        "version": "1.0.0_beta11_p1",
        "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta11_p1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.0.0_beta11_p1",
            "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta11_p1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.0.0_beta11",
            "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta11",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.0.0_beta10_p5",
            "tag": "ghcr.io/quenchworks/images/rustfs:1.0.0_beta10_p5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "scylladb",
      "name": "ScyllaDB",
      "category": "Wide-column",
      "summary": "High-throughput, low-latency wide-column store, API-compatible with Apache Cassandra and DynamoDB. This 6.x build is the final OSS line under AGPL.",
      "tier": "low",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "2026.2.2",
      "versions": [
        {
          "version": "2026.2.2",
          "size": "78.2 MB",
          "published": "2026-07-26T12:31:47Z",
          "digest": "sha256:e96ca9dd6b6c8c278639945a4a68dcb7c4f093255eced4c2124bb7923a59bfaa"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/scylladb/scylladb",
      "source": "https://github.com/scylladb/scylladb",
      "image": "ghcr.io/quenchworks/images/scylladb",
      "security": {
        "image": "ghcr.io/quenchworks/images/scylladb",
        "version": "2026.2.2",
        "tag": "ghcr.io/quenchworks/images/scylladb:2026.2.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2026.2.2",
            "tag": "ghcr.io/quenchworks/images/scylladb:2026.2.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "sealed-secrets",
      "name": "sealed-secrets",
      "category": "Security & supply chain",
      "summary": "Sealed Secrets, the controller that lets you commit encrypted secrets to Git safely. A cluster-side private key decrypts SealedSecret resources into ordinary Kubernetes Secrets, so the encrypted form is the only thing that ever leaves the cluster.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.36.6, 0.38.4, 0.37.0",
      "versions": [
        {
          "version": "0.36.6",
          "size": "14.3 MB",
          "published": "2026-07-26T12:36:49Z",
          "digest": "sha256:2bccd402d758a2aa72e9591a53d92ef11ed3a6b24fdd8174e293bc6b4504737b"
        },
        {
          "version": "0.38.4",
          "size": "14.5 MB",
          "published": "2026-07-26T12:36:42Z",
          "digest": "sha256:7e2522cfc9ed4f82ffd15037afe2055c029e4bbfc9eb2c54e09850e83e957d47"
        },
        {
          "version": "0.37.0",
          "size": "14.5 MB",
          "published": "2026-07-26T12:36:38Z",
          "digest": "sha256:cde1ac4ccb853721ce3dcac25fecbf6fe65dad134b7a8de06eec90b21dbc62e8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://sealed-secrets.netlify.app",
      "source": "https://github.com/bitnami-labs/sealed-secrets",
      "image": "ghcr.io/quenchworks/images/sealed-secrets",
      "security": {
        "image": "ghcr.io/quenchworks/images/sealed-secrets",
        "version": "0.38.4",
        "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.38.4",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/controller"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.38.4",
            "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.38.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "0.37.0",
            "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.37.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          },
          {
            "version": "0.36.6",
            "tag": "ghcr.io/quenchworks/images/sealed-secrets:0.36.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "seaweedfs",
      "name": "SeaweedFS",
      "category": "Object storage",
      "summary": "Fast distributed storage for blobs, objects, and files (S3 API) built on Facebook's Haystack design, with O(1) disk seeks for billions of small files. Default object store after MinIO restricted its community edition.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "4.40",
      "versions": [
        {
          "version": "4.40",
          "size": "48.8 MB",
          "published": "2026-07-22T08:36:07Z",
          "digest": "sha256:7bb0bbc92fe277023f63e0292ae272231d54161948225a982213578bc41e775e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/seaweedfs/seaweedfs",
      "source": "https://github.com/seaweedfs/seaweedfs",
      "image": "ghcr.io/quenchworks/images/seaweedfs",
      "security": {
        "image": "ghcr.io/quenchworks/images/seaweedfs",
        "version": "4.40",
        "tag": "ghcr.io/quenchworks/images/seaweedfs:4.40",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/weed"
            ]
          }
        ],
        "versions": [
          {
            "version": "4.40",
            "tag": "ghcr.io/quenchworks/images/seaweedfs:4.40",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/weed"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "solr",
      "name": "Solr",
      "category": "Search",
      "summary": "Enterprise search platform built on Apache Lucene, offering full-text search, faceting, and indexing over large document collections.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "10.0.0",
      "versions": [
        {
          "version": "10.0.0",
          "size": "333.1 MB",
          "published": "2026-07-23T12:25:11Z",
          "digest": "sha256:9fd776670393c21b8d6a16dc02a29c63fe36caa981e23cc648c9a4cf6a08291a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/solr",
      "source": "https://github.com/apache/solr",
      "image": "ghcr.io/quenchworks/images/solr",
      "security": {
        "image": "ghcr.io/quenchworks/images/solr",
        "version": "10.0.0",
        "tag": "ghcr.io/quenchworks/images/solr:10.0.0",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 1,
        "fixable": 0,
        "grade": "D",
        "score": 90,
        "cves": [
          {
            "id": "CVE-2026-44825",
            "severity": "HIGH",
            "pkg": "org.apache.solr:solr-core",
            "installed": "10.0.0",
            "fixed": null,
            "title": "solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.",
            "url": "https://avd.aquasec.com/nvd/cve-2026-44825",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "10.0.0",
            "tag": "ghcr.io/quenchworks/images/solr:10.0.0",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 1,
            "fixable": 0,
            "grade": "D",
            "score": 90,
            "cves": [
              {
                "id": "CVE-2026-44825",
                "severity": "HIGH",
                "pkg": "org.apache.solr:solr-core",
                "installed": "10.0.0",
                "fixed": null,
                "title": "solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.",
                "url": "https://avd.aquasec.com/nvd/cve-2026-44825",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "sonar-scanner-cli",
      "name": "sonar-scanner-cli",
      "category": "CI/CD & registry",
      "summary": "SonarScanner CLI, the standalone scanner that analyzes a project and pushes results to a SonarQube server. Bundles its own OpenJDK. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "LGPL-3.0",
      "licenseClean": "clean",
      "version": "8.1.0.6389",
      "versions": [
        {
          "version": "8.1.0.6389",
          "size": "85.2 MB",
          "published": "2026-07-04T15:04:38Z",
          "digest": "sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.sonarsource.com/sonarqube-server/latest/analyzing-source-code/scanners/sonarscanner/",
      "source": "https://github.com/SonarSource/sonar-scanner-cli",
      "image": "ghcr.io/quenchworks/images/sonar-scanner-cli",
      "security": {
        "image": "ghcr.io/quenchworks/images/sonar-scanner-cli",
        "version": "8.1.0.6389",
        "tag": "ghcr.io/quenchworks/images/sonar-scanner-cli:8.1.0.6389",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 3,
        "unknown": 0,
        "total": 3,
        "fixable": 3,
        "grade": "B",
        "score": 82,
        "cves": [
          {
            "id": "CVE-2026-10532",
            "severity": "LOW",
            "pkg": "sonar-scanner-cli",
            "installed": "8.1.0.6389-r1",
            "fixed": "8.1.0.6389-r3",
            "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
            "targets": [
              "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
            ]
          },
          {
            "id": "CVE-2026-10532",
            "severity": "LOW",
            "pkg": "ch.qos.logback:logback-core",
            "installed": "1.5.33",
            "fixed": "1.5.34",
            "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
            "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
            "targets": [
              "Java"
            ]
          }
        ],
        "versions": [
          {
            "version": "8.1.0.6389",
            "tag": "ghcr.io/quenchworks/images/sonar-scanner-cli:8.1.0.6389",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 3,
            "unknown": 0,
            "total": 3,
            "fixable": 3,
            "grade": "B",
            "score": 82,
            "cves": [
              {
                "id": "CVE-2026-10532",
                "severity": "LOW",
                "pkg": "sonar-scanner-cli",
                "installed": "8.1.0.6389-r1",
                "fixed": "8.1.0.6389-r3",
                "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
                "targets": [
                  "ghcr.io/quenchworks/images/sonar-scanner-cli@sha256:49125b47f9c81e4de5158bf67b01afc47b3322bf808be2ef1da2764e16fc832d (wolfi 20230201)"
                ]
              },
              {
                "id": "CVE-2026-10532",
                "severity": "LOW",
                "pkg": "ch.qos.logback:logback-core",
                "installed": "1.5.33",
                "fixed": "1.5.34",
                "title": "Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...",
                "url": "https://avd.aquasec.com/nvd/cve-2026-10532",
                "targets": [
                  "Java"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "spicedb",
      "name": "spicedb",
      "category": "Identity",
      "summary": "Zanzibar-style authorization database for fine-grained permissions over gRPC. From source on a hardened nonroot Wolfi base; the operator supplies the datastore (in-memory, postgres, or cockroach).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.56.0",
      "versions": [
        {
          "version": "1.56.0",
          "size": "24.3 MB",
          "published": "2026-07-26T12:29:23Z",
          "digest": "sha256:1f8dbdcc20597944240261b491221efd13c77f0c0fd832c28377a5ce9ed82a3d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://authzed.com",
      "source": "https://github.com/authzed/spicedb",
      "image": "ghcr.io/quenchworks/images/spicedb",
      "security": {
        "image": "ghcr.io/quenchworks/images/spicedb",
        "version": "1.56.0",
        "tag": "ghcr.io/quenchworks/images/spicedb:1.56.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/spicedb"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.56.0",
            "tag": "ghcr.io/quenchworks/images/spicedb:1.56.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/spicedb"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "static",
      "name": "static",
      "category": "Runtime base",
      "summary": "Tiny static base for self-contained binaries from Go or Rust. Nonroot, no shell, no package manager. The only image tagged :latest.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "20260621",
      "versions": [
        {
          "version": "20260621",
          "size": "617.2 KB",
          "published": "2026-06-21T09:27:02Z",
          "digest": "sha256:40f7b14a295980f410f31ace75078ffb1649dedee09e6c68d07ed5b3fd05eae2"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/wolfi-dev",
      "source": "https://github.com/wolfi-dev",
      "image": "ghcr.io/quenchworks/images/static",
      "security": {
        "image": "ghcr.io/quenchworks/images/static",
        "version": "20260621",
        "tag": "ghcr.io/quenchworks/images/static:20260621",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "20260621",
            "tag": "ghcr.io/quenchworks/images/static:20260621",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "step-ca",
      "name": "step-ca",
      "category": "Security & supply chain",
      "summary": "Online private certificate authority and ACME server for issuing X.509 and SSH certificates. Single static Go binary on a hardened nonroot Wolfi base; config and data live under a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.30.2",
      "versions": [
        {
          "version": "0.30.2",
          "size": "29.6 MB",
          "published": "2026-07-22T07:33:23Z",
          "digest": "sha256:09210b2c05d273ab2d72811c69d20e42081263f1cbc470de870b7a725c87cd65"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://smallstep.com",
      "source": "https://github.com/smallstep/certificates",
      "image": "ghcr.io/quenchworks/images/step-ca",
      "security": {
        "image": "ghcr.io/quenchworks/images/step-ca",
        "version": "0.30.2",
        "tag": "ghcr.io/quenchworks/images/step-ca:0.30.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/step",
              "usr/bin/step-ca"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.30.2",
            "tag": "ghcr.io/quenchworks/images/step-ca:0.30.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/step",
                  "usr/bin/step-ca"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "syft",
      "name": "syft",
      "category": "Security & supply chain",
      "summary": "Anchore's CLI for generating Software Bills of Materials (SBOMs) from container images and filesystems. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.50.0",
      "versions": [
        {
          "version": "1.50.0",
          "size": "28.6 MB",
          "published": "2026-07-30T08:11:58Z",
          "digest": "sha256:63dbb666329f1c34f88aa6715d88432267b9491bb5264b31aabf49d47e5826fe"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://anchore.com/opensource/",
      "source": "https://github.com/anchore/syft",
      "image": "ghcr.io/quenchworks/images/syft",
      "security": {
        "image": "ghcr.io/quenchworks/images/syft",
        "version": "1.49.0",
        "tag": "ghcr.io/quenchworks/images/syft:1.49.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/syft"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.49.0",
            "tag": "ghcr.io/quenchworks/images/syft:1.49.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/syft"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tekton",
      "name": "tekton",
      "category": "CI/CD & registry",
      "summary": "Kubernetes-native CI/CD pipelines. Ships the Tekton Pipelines controller, webhook, resolvers, and pod-injected helper binaries, built from source on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.14.0",
      "versions": [
        {
          "version": "1.14.0",
          "size": "117.0 MB",
          "published": "2026-07-26T12:35:20Z",
          "digest": "sha256:051d50601e10539071958afa9a6bc217e137c1b68f6d7c7894c70da07ff08d3a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://tekton.dev",
      "source": "https://github.com/tektoncd/pipeline",
      "image": "ghcr.io/quenchworks/images/tekton",
      "security": {
        "image": "ghcr.io/quenchworks/images/tekton",
        "version": "1.14.0",
        "tag": "ghcr.io/quenchworks/images/tekton:1.14.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 3,
        "total": 3,
        "fixable": 0,
        "grade": "B",
        "score": 94,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/controller",
              "usr/bin/resolvers",
              "usr/bin/sidecarlogresults"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.14.0",
            "tag": "ghcr.io/quenchworks/images/tekton:1.14.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 3,
            "total": 3,
            "fixable": 0,
            "grade": "B",
            "score": 94,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/controller",
                  "usr/bin/resolvers",
                  "usr/bin/sidecarlogresults"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tempo",
      "name": "Tempo",
      "category": "Observability",
      "summary": "Distributed tracing backend from Grafana that ingests OpenTelemetry, Jaeger, and Zipkin spans and stores them cheaply in object storage. Licensed AGPL.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0",
      "licenseClean": "agpl",
      "version": "3.0.2",
      "versions": [
        {
          "version": "3.0.2",
          "size": "39.5 MB",
          "published": "2026-07-22T07:11:05Z",
          "digest": "sha256:069eaae190bd2c5a36c247bd5e535b65d84798618d395ce6654ab24ad53dcb96"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/grafana/tempo",
      "source": "https://github.com/grafana/tempo",
      "image": "ghcr.io/quenchworks/images/tempo",
      "security": {
        "image": "ghcr.io/quenchworks/images/tempo",
        "version": "3.0.2",
        "tag": "ghcr.io/quenchworks/images/tempo:3.0.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/tempo"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.0.2",
            "tag": "ghcr.io/quenchworks/images/tempo:3.0.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/tempo"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "temporal",
      "name": "Temporal",
      "category": "Workflow",
      "summary": "Durable workflow orchestration engine that persists execution state so long-running, multi-step processes survive crashes and resume exactly where they left off.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.31.2",
      "versions": [
        {
          "version": "1.31.2",
          "size": "61.5 MB",
          "published": "2026-07-22T08:35:23Z",
          "digest": "sha256:e476bb1280ee530a0d963b1c94f2e50e6328d943e96e2fa4332aa12929b7f833"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/temporalio/temporal",
      "source": "https://github.com/temporalio/temporal",
      "image": "ghcr.io/quenchworks/images/temporal",
      "security": {
        "image": "ghcr.io/quenchworks/images/temporal",
        "version": "1.31.2",
        "tag": "ghcr.io/quenchworks/images/temporal:1.31.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 3,
        "total": 3,
        "fixable": 0,
        "grade": "B",
        "score": 94,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/temporal-cassandra-tool",
              "usr/bin/temporal-server",
              "usr/bin/temporal-sql-tool"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.31.2",
            "tag": "ghcr.io/quenchworks/images/temporal:1.31.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 3,
            "total": 3,
            "fixable": 0,
            "grade": "B",
            "score": 94,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal-cassandra-tool",
                  "usr/bin/temporal-server",
                  "usr/bin/temporal-sql-tool"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "temporal-cli",
      "name": "Temporal CLI",
      "category": "Workflow",
      "summary": "Command-line client and built-in dev server for Temporal, used to start workflows, inspect history, and run a local cluster.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "1.7.3, 1.8.1, 1.6.2",
      "versions": [
        {
          "version": "1.7.3",
          "size": "114.2 MB",
          "published": "2026-07-22T11:31:29Z",
          "digest": "sha256:ce339addb1a8f536fa11205b07cf87ae5565414fbe4abbb4810a2c74d75ff088"
        },
        {
          "version": "1.8.1",
          "size": "41.3 MB",
          "published": "2026-07-22T11:31:28Z",
          "digest": "sha256:5e4e57a3c999216d06165063fe17c15a5d4e46704b08e1f409183c8188043f5a"
        },
        {
          "version": "1.6.2",
          "size": "85.6 MB",
          "published": "2026-07-22T11:31:27Z",
          "digest": "sha256:3a5310dceb07d2221409ba0dd06b916e9546c5b55e86e1130509312ee664dadd"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/temporalio/cli",
      "source": "https://github.com/temporalio/cli",
      "image": "ghcr.io/quenchworks/images/temporal-cli",
      "security": {
        "image": "ghcr.io/quenchworks/images/temporal-cli",
        "version": "1.8.1",
        "tag": "ghcr.io/quenchworks/images/temporal-cli:1.8.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/temporal"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.8.1",
            "tag": "ghcr.io/quenchworks/images/temporal-cli:1.8.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal"
                ]
              }
            ]
          },
          {
            "version": "1.7.3",
            "tag": "ghcr.io/quenchworks/images/temporal-cli:1.7.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal"
                ]
              }
            ]
          },
          {
            "version": "1.6.2",
            "tag": "ghcr.io/quenchworks/images/temporal-cli:1.6.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/temporal"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tigerbeetle",
      "name": "tigerbeetle",
      "category": "Database",
      "summary": "Distributed financial-grade accounting database for high-throughput double-entry bookkeeping. Ships a single self-contained static Zig binary; speaks its own binary protocol (not HTTP) on port 3000.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.17.4, 0.17.8, 0.17.9",
      "versions": [
        {
          "version": "0.17.4",
          "size": "11.3 MB",
          "published": "2026-07-23T06:48:21Z",
          "digest": "sha256:07394bfe56198e2d3b95a0437608bfa83bf9dfe79602008323ecad5ab2d3295f"
        },
        {
          "version": "0.17.8",
          "size": "11.5 MB",
          "published": "2026-07-23T06:48:21Z",
          "digest": "sha256:d411e1c2ed6944c627c442ca41ce13f28988d88418920b7fc780733a107493f7"
        },
        {
          "version": "0.17.9",
          "size": "11.6 MB",
          "published": "2026-07-23T06:48:15Z",
          "digest": "sha256:81cd83b527c9e21db69417a33b02ef7800702d1e0f0c0754a52e5ed32316887d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/tigerbeetle/tigerbeetle",
      "source": "https://github.com/tigerbeetle/tigerbeetle",
      "image": "ghcr.io/quenchworks/images/tigerbeetle",
      "security": {
        "image": "ghcr.io/quenchworks/images/tigerbeetle",
        "version": "0.17.9",
        "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.9",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.17.9",
            "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.9",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.17.8",
            "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.17.4",
            "tag": "ghcr.io/quenchworks/images/tigerbeetle:0.17.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "timescaledb",
      "name": "timescaledb",
      "category": "Time series",
      "summary": "PostgreSQL 17 plus the open TimescaleDB extension (Apache-only edition), adding hypertables, continuous aggregates, and time-series functions for high-ingest metrics and event data. Built clean-licensed from source on Wolfi (no TSL community code).",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.28.2, 2.29.0, 2.28.3",
      "versions": [
        {
          "version": "2.28.2",
          "size": "147.9 MB",
          "published": "2026-07-30T10:25:44Z",
          "digest": "sha256:87fa1b06bfdf134c97d9edb163e13e62f294a03d5e1cc2fbc047b079ba16f7d3"
        },
        {
          "version": "2.29.0",
          "size": "148.1 MB",
          "published": "2026-07-30T10:25:39Z",
          "digest": "sha256:1a769b019525f5b8f5ae529dd9d8bf8d7c40d689eafd2c2280d9b12951742bdd"
        },
        {
          "version": "2.28.3",
          "size": "147.9 MB",
          "published": "2026-07-30T10:25:36Z",
          "digest": "sha256:6fd7baf730e2c462cebcd50da2266853400e63e85071122c5be4b3703f01f0c0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.timescale.com",
      "source": "https://github.com/timescale/timescaledb",
      "image": "ghcr.io/quenchworks/images/timescaledb",
      "security": {
        "image": "ghcr.io/quenchworks/images/timescaledb",
        "version": "2.28.3",
        "tag": "ghcr.io/quenchworks/images/timescaledb:2.28.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "2.28.3",
            "tag": "ghcr.io/quenchworks/images/timescaledb:2.28.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.28.2",
            "tag": "ghcr.io/quenchworks/images/timescaledb:2.28.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "2.28.1",
            "tag": "ghcr.io/quenchworks/images/timescaledb:2.28.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "tomcat",
      "name": "tomcat",
      "category": "Gateway",
      "summary": "Apache Tomcat, the widely used open-source Java servlet container and web/application server for running Jakarta Servlet, JSP, and WebSocket web applications.",
      "tier": "critical",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "11.0.24",
      "versions": [
        {
          "version": "11.0.24",
          "size": "86.9 MB",
          "published": "2026-07-09T07:40:43Z",
          "digest": "sha256:628940ef118c30a1fe99b5ae44ca590f9f40e22a31bbca58ff943377a8cc913d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/tomcat",
      "source": "https://downloads.apache.org/tomcat/tomcat-11/",
      "image": "ghcr.io/quenchworks/images/tomcat",
      "security": {
        "image": "ghcr.io/quenchworks/images/tomcat",
        "version": "11.0.24",
        "tag": "ghcr.io/quenchworks/images/tomcat:11.0.24",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "11.0.24",
            "tag": "ghcr.io/quenchworks/images/tomcat:11.0.24",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "traefik",
      "name": "Traefik",
      "category": "Gateway",
      "summary": "Cloud-native reverse proxy and load balancer with automatic service discovery, dynamic config, and built-in Let's Encrypt TLS.",
      "tier": "standard",
      "status": "available",
      "license": "MIT",
      "licenseClean": "clean",
      "version": "3.7.9",
      "versions": [
        {
          "version": "3.7.9",
          "size": "53.9 MB",
          "published": "2026-07-26T12:34:36Z",
          "digest": "sha256:8c2d7f3557eae0f28e7aaf9a76c2671d4593f0f494c5f0328f1931da513e829e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/traefik/traefik",
      "source": "https://github.com/traefik/traefik",
      "image": "ghcr.io/quenchworks/images/traefik",
      "security": {
        "image": "ghcr.io/quenchworks/images/traefik",
        "version": "3.7.9",
        "tag": "ghcr.io/quenchworks/images/traefik:3.7.9",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/traefik"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.7.9",
            "tag": "ghcr.io/quenchworks/images/traefik:3.7.9",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/traefik"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "trivy",
      "name": "trivy",
      "category": "Security & supply chain",
      "summary": "Aqua Security's all-in-one vulnerability, misconfiguration, secret, and SBOM scanner for images, filesystems, and repositories. Image only, no chart.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.72.0",
      "versions": [
        {
          "version": "0.72.0",
          "size": "50.5 MB",
          "published": "2026-07-22T07:11:33Z",
          "digest": "sha256:33cbc12ef9912b9bbba3e0ee4d1784b768396e01a332aebbc412850632bb981f"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://trivy.dev",
      "source": "https://github.com/aquasecurity/trivy",
      "image": "ghcr.io/quenchworks/images/trivy",
      "security": {
        "image": "ghcr.io/quenchworks/images/trivy",
        "version": "0.72.0",
        "tag": "ghcr.io/quenchworks/images/trivy:0.72.0",
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "D",
        "score": 88,
        "cves": [
          {
            "id": "CVE-2026-50163",
            "severity": "HIGH",
            "pkg": "oras.land/oras-go/v2",
            "installed": "v2.6.1",
            "fixed": null,
            "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
            "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
            "targets": [
              "usr/bin/trivy"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/trivy"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.72.0",
            "tag": "ghcr.io/quenchworks/images/trivy:0.72.0",
            "critical": 0,
            "high": 1,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "D",
            "score": 88,
            "cves": [
              {
                "id": "CVE-2026-50163",
                "severity": "HIGH",
                "pkg": "oras.land/oras-go/v2",
                "installed": "v2.6.1",
                "fixed": null,
                "title": "oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks",
                "url": "https://avd.aquasec.com/nvd/cve-2026-50163",
                "targets": [
                  "usr/bin/trivy"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/trivy"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "tyk",
      "name": "tyk",
      "category": "Gateway",
      "summary": "Full-featured API gateway with rate limiting, auth, and quotas. Single static Go binary on a hardened nonroot Wolfi base; Redis is a runtime dependency the operator provides.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "5.13.1",
      "versions": [
        {
          "version": "5.13.1",
          "size": "91.1 MB",
          "published": "2026-07-22T07:12:58Z",
          "digest": "sha256:9cfda1cf047ad83818dd92116b23777d4fbaf7c6974c395a504ca456bcd13c33"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://tyk.io",
      "source": "https://github.com/TykTechnologies/tyk",
      "image": "ghcr.io/quenchworks/images/tyk",
      "security": {
        "image": "ghcr.io/quenchworks/images/tyk",
        "version": "5.13.1",
        "tag": "ghcr.io/quenchworks/images/tyk:5.13.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/tyk"
            ]
          }
        ],
        "versions": [
          {
            "version": "5.13.1",
            "tag": "ghcr.io/quenchworks/images/tyk:5.13.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/tyk"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "typesense",
      "name": "typesense",
      "category": "Search",
      "summary": "Fast, typo-tolerant search engine with an instant-search REST API and a self-contained embedded store (no external database), tuned for low-latency site and in-app search.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-3.0",
      "licenseClean": "agpl",
      "version": "29.1, 28.0, 30.2",
      "versions": [
        {
          "version": "29.1",
          "size": "137.8 MB",
          "published": "2026-07-21T07:43:38Z",
          "digest": "sha256:72ccab4a6ea292551f8ce43a6c4cff9ed8bab689979e792e96fc5cc7855f39ae"
        },
        {
          "version": "28.0",
          "size": "122.7 MB",
          "published": "2026-07-21T07:43:31Z",
          "digest": "sha256:e189949ed7d958d94db1af35cfda889780840ebcdbc1ddaa116cff658146eccf"
        },
        {
          "version": "30.2",
          "size": "147.4 MB",
          "published": "2026-07-21T07:43:31Z",
          "digest": "sha256:cd0f547e0efe05502c9d2dcbef4a2e0071084d4bed694aac244b6c3a5f6e8337"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/typesense/typesense",
      "source": "https://github.com/typesense/typesense",
      "image": "ghcr.io/quenchworks/images/typesense",
      "security": {
        "image": "ghcr.io/quenchworks/images/typesense",
        "version": "30.2",
        "tag": "ghcr.io/quenchworks/images/typesense:30.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "30.2",
            "tag": "ghcr.io/quenchworks/images/typesense:30.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "29.1",
            "tag": "ghcr.io/quenchworks/images/typesense:29.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "28.0",
            "tag": "ghcr.io/quenchworks/images/typesense:28.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "uv",
      "name": "uv",
      "category": "Build tool",
      "summary": "Python base image with uv, a fast Rust-based installer and resolver, used as the build stage for Python projects. Line 0.11.",
      "tier": "standard",
      "status": "available",
      "license": "MIT OR Apache-2.0",
      "licenseClean": "clean",
      "version": "0.11.31, 0.11.33, 0.11.32",
      "versions": [
        {
          "version": "0.11.31",
          "size": "56.4 MB",
          "published": "2026-07-30T08:12:21Z",
          "digest": "sha256:d139e3412fa50bf2bed5921c58b5b49c26a88378532092dc48ed4de032c67b6d"
        },
        {
          "version": "0.11.33",
          "size": "51.6 MB",
          "published": "2026-07-30T08:12:17Z",
          "digest": "sha256:71a5b699b5fbe192b4a488254c560b2b2222aff4c8e147af489ab47d5c4e59f6"
        },
        {
          "version": "0.11.32",
          "size": "56.5 MB",
          "published": "2026-07-30T08:12:04Z",
          "digest": "sha256:99eff9b7441fc014af305be2873bc9b059d421a1d5ff8dd064db824d29e8c964"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/astral-sh/uv",
      "source": "https://github.com/astral-sh/uv",
      "image": "ghcr.io/quenchworks/images/uv",
      "security": {
        "image": "ghcr.io/quenchworks/images/uv",
        "version": "0.11.32",
        "tag": "ghcr.io/quenchworks/images/uv:0.11.32",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.11.32",
            "tag": "ghcr.io/quenchworks/images/uv:0.11.32",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.11.31",
            "tag": "ghcr.io/quenchworks/images/uv:0.11.31",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "0.11.30",
            "tag": "ghcr.io/quenchworks/images/uv:0.11.30",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "valkey",
      "name": "Valkey",
      "category": "Cache",
      "summary": "BSD-licensed in-memory key-value store, the truly-open community fork of Redis 7.2. QuenchWorks' default cache and the recommended Redis drop-in replacement.",
      "tier": "critical",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "9.0.4, 9.1.1, 8.1.8",
      "versions": [
        {
          "version": "9.0.4",
          "size": "14.1 MB",
          "published": "2026-07-22T11:31:18Z",
          "digest": "sha256:9821d46e38697f92405ef6c3997dc1f32a5d6219163e2b679f919d72239f4cf7"
        },
        {
          "version": "9.1.1",
          "size": "14.9 MB",
          "published": "2026-07-22T11:31:17Z",
          "digest": "sha256:8ee902be36ca7d49a25607ee77629433f225e89f905e15fdde67dd29a15686f2"
        },
        {
          "version": "8.1.8",
          "size": "13.4 MB",
          "published": "2026-07-22T11:31:14Z",
          "digest": "sha256:e5ad713627f5fbdabbd0270413e76d50ddfb690c2c2aaf457a0a2599367ffe8e"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/valkey-io/valkey",
      "source": "https://github.com/valkey-io/valkey",
      "image": "ghcr.io/quenchworks/images/valkey",
      "security": {
        "image": "ghcr.io/quenchworks/images/valkey",
        "version": "9.1.1",
        "tag": "ghcr.io/quenchworks/images/valkey:9.1.1",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.1.1",
            "tag": "ghcr.io/quenchworks/images/valkey:9.1.1",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "9.0.4",
            "tag": "ghcr.io/quenchworks/images/valkey:9.0.4",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.1.8",
            "tag": "ghcr.io/quenchworks/images/valkey:8.1.8",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "varnish",
      "name": "varnish",
      "category": "Cache",
      "summary": "HTTP reverse-proxy cache (web accelerator) that fronts an origin and serves its responses from memory, cutting backend load and tail latency. Caching policy is VCL, which varnishd compiles to native code at startup. The chart supplies the VCL and the backend.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-2-Clause",
      "licenseClean": "clean",
      "version": "7.7.3, 9.0.3, 8.0.0",
      "versions": [
        {
          "version": "7.7.3",
          "size": "192.8 MB",
          "published": "2026-07-28T09:49:03Z",
          "digest": "sha256:59e7a38ad2b437e539721b935b4f7932fbee6cb758a389f79a5611116fb58f30"
        },
        {
          "version": "9.0.3",
          "size": "196.0 MB",
          "published": "2026-07-28T09:48:39Z",
          "digest": "sha256:97d1607e3e49d53ec45173a82a8fb9636017b76b05f09ad7f99fe4bb540a7a77"
        },
        {
          "version": "8.0.0",
          "size": "192.9 MB",
          "published": "2026-07-28T09:48:26Z",
          "digest": "sha256:e131fa7719363e61c91513d20a39ef89280139a30d44e41c837d84f69acf705d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://www.varnish.org",
      "source": "https://github.com/varnish/varnish",
      "image": "ghcr.io/quenchworks/images/varnish",
      "security": {
        "image": "ghcr.io/quenchworks/images/varnish",
        "version": "9.0.3",
        "tag": "ghcr.io/quenchworks/images/varnish:9.0.3",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "9.0.3",
            "tag": "ghcr.io/quenchworks/images/varnish:9.0.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "8.0.0",
            "tag": "ghcr.io/quenchworks/images/varnish:8.0.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "7.7.3",
            "tag": "ghcr.io/quenchworks/images/varnish:7.7.3",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "vault",
      "name": "vault",
      "category": "Secrets",
      "summary": "Secrets and encryption management for tokens, keys, and certificates, with dynamic secrets, leasing, and PKI. Shipped under the Business Source License 1.1, which is not OSI-approved; OpenBao (MPL-2.0) is the open drop-in fork. Built from source without the web UI; the 1.20.x line is CVE-blocked upstream and not shipped.",
      "tier": "low",
      "status": "available",
      "license": "BUSL-1.1",
      "licenseClean": "caution",
      "version": "2.0.3",
      "versions": [
        {
          "version": "2.0.3",
          "size": "89.6 MB",
          "published": "2026-07-30T06:12:34Z",
          "digest": "sha256:3428da8e9cee6078dfb909784150e6ac487123ffa13c94091f18b82c8865d893"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/hashicorp/vault",
      "source": "https://github.com/hashicorp/vault",
      "image": "ghcr.io/quenchworks/images/vault",
      "caution": true,
      "security": null
    },
    {
      "slug": "vector",
      "name": "Vector",
      "category": "Observability",
      "summary": "High-performance observability pipeline that collects, transforms, and routes logs, metrics, and traces between sources and sinks.",
      "tier": "standard",
      "status": "available",
      "license": "MPL-2.0",
      "licenseClean": "clean",
      "version": "0.57.0",
      "versions": [
        {
          "version": "0.57.0",
          "size": "32.5 MB",
          "published": "2026-07-15T12:10:00Z",
          "digest": "sha256:e3aa5744d0138f42f68fc3afbb1bea1d62ce2c1edb7a885dfaacfb1a81b0f736"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/vectordotdev/vector",
      "source": "https://github.com/vectordotdev/vector",
      "image": "ghcr.io/quenchworks/images/vector",
      "security": {
        "image": "ghcr.io/quenchworks/images/vector",
        "version": "0.57.0",
        "tag": "ghcr.io/quenchworks/images/vector:0.57.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "0.57.0",
            "tag": "ghcr.io/quenchworks/images/vector:0.57.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "velero",
      "name": "velero",
      "category": "Storage & platform",
      "summary": "CNCF backup and disaster-recovery tool for Kubernetes cluster resources and persistent volumes. Single static Go binary on a hardened nonroot Wolfi base; object-store and snapshot backends are the operator's choice.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.18.2",
      "versions": [
        {
          "version": "1.18.2",
          "size": "30.3 MB",
          "published": "2026-07-22T07:11:43Z",
          "digest": "sha256:6d22413905ef1e3c2c04197fb2b6b446665ad9f2e72050dc75894b3029d196f8"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://velero.io",
      "source": "https://github.com/vmware-tanzu/velero",
      "image": "ghcr.io/quenchworks/images/velero",
      "security": {
        "image": "ghcr.io/quenchworks/images/velero",
        "version": "1.18.2",
        "tag": "ghcr.io/quenchworks/images/velero:1.18.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/velero"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.18.2",
            "tag": "ghcr.io/quenchworks/images/velero:1.18.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/velero"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "victorialogs",
      "name": "victorialogs",
      "category": "Observability",
      "summary": "Fast, cost-efficient logs database with the LogsQL query language. Single static Go binary on a hardened nonroot Wolfi base; log data lives on a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.51.0",
      "versions": [
        {
          "version": "1.51.0",
          "size": "9.8 MB",
          "published": "2026-07-08T10:53:06Z",
          "digest": "sha256:bd1f3a98a422a596d6f9c776dc08c5f36ddbc61c0584c8e38fc395eb406086ba"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.victoriametrics.com/victorialogs",
      "source": "https://github.com/VictoriaMetrics/VictoriaLogs",
      "image": "ghcr.io/quenchworks/images/victorialogs",
      "security": {
        "image": "ghcr.io/quenchworks/images/victorialogs",
        "version": "1.51.0",
        "tag": "ghcr.io/quenchworks/images/victorialogs:1.51.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.51.0",
            "tag": "ghcr.io/quenchworks/images/victorialogs:1.51.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "victoriametrics",
      "name": "VictoriaMetrics",
      "category": "Time series",
      "summary": "Fast, cost-efficient time-series database that speaks PromQL and Prometheus remote_write. Drop-in long-term storage or full replacement for Prometheus.",
      "tier": "low",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "1.148.0",
      "versions": [
        {
          "version": "1.148.0",
          "size": "10.9 MB",
          "published": "2026-07-21T08:47:57Z",
          "digest": "sha256:c6890da882b13ed5dbef8811b5974feffe5af5374ce963c50f2442dc59b1220d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/VictoriaMetrics/VictoriaMetrics",
      "source": "https://github.com/VictoriaMetrics/VictoriaMetrics",
      "image": "ghcr.io/quenchworks/images/victoriametrics",
      "security": {
        "image": "ghcr.io/quenchworks/images/victoriametrics",
        "version": "1.148.0",
        "tag": "ghcr.io/quenchworks/images/victoriametrics:1.148.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.148.0",
            "tag": "ghcr.io/quenchworks/images/victoriametrics:1.148.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "vikunja",
      "name": "vikunja",
      "category": "Apps & productivity",
      "summary": "Self-hosted to-do and project management app (lists, kanban, gantt, calendar) serving both the API and the Vue web UI. From source with the UI embedded on a hardened nonroot Wolfi base; SQLite or an external SQL database.",
      "tier": "standard",
      "status": "available",
      "license": "AGPL-3.0+",
      "licenseClean": "agpl",
      "version": "2.3.0",
      "versions": [
        {
          "version": "2.3.0",
          "size": "29.7 MB",
          "published": "2026-07-15T12:43:57Z",
          "digest": "sha256:4a45a0d821538a6af5d08fea9f9c88f55d1bae3ebeef0a8417ee7ec815c5c169"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://vikunja.io",
      "source": "https://github.com/go-vikunja/vikunja",
      "image": "ghcr.io/quenchworks/images/vikunja",
      "security": {
        "image": "ghcr.io/quenchworks/images/vikunja",
        "version": "2.3.0",
        "tag": "ghcr.io/quenchworks/images/vikunja:2.3.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 1,
        "unknown": 1,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 97,
        "cves": [
          {
            "id": "CVE-2023-36308",
            "severity": "LOW",
            "pkg": "github.com/disintegration/imaging",
            "installed": "v1.6.2",
            "fixed": null,
            "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
            "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
            "targets": [
              "usr/bin/vikunja"
            ]
          },
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/vikunja"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.3.0",
            "tag": "ghcr.io/quenchworks/images/vikunja:2.3.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 1,
            "unknown": 1,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 97,
            "cves": [
              {
                "id": "CVE-2023-36308",
                "severity": "LOW",
                "pkg": "github.com/disintegration/imaging",
                "installed": "v1.6.2",
                "fixed": null,
                "title": "disintegration Imaging 1.6.2 allows attackers to cause a panic (becaus ...",
                "url": "https://avd.aquasec.com/nvd/cve-2023-36308",
                "targets": [
                  "usr/bin/vikunja"
                ]
              },
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/vikunja"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "vllm",
      "name": "vllm",
      "category": "Machine learning & AI",
      "summary": "vLLM, the high-throughput LLM inference and serving engine with an OpenAI-compatible API. CPU build — installs vLLM's prebuilt CPU wheel (torch+cpu, no source compile, no CUDA) into a venv on a hardened Wolfi python-3.12 base, 0-CVE across ~140 Python packages. The user supplies the model; the chart runs it as a StatefulSet with a persistent model cache.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "0.25.1",
      "versions": [
        {
          "version": "0.25.1",
          "size": "946.4 MB",
          "published": "2026-07-15T10:42:20Z",
          "digest": "sha256:8ddd4b1173ed21f264bd1f910a4dddb6f2f659a33374124b3b443538c3c81b02"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://docs.vllm.ai",
      "source": "https://github.com/vllm-project/vllm",
      "image": "ghcr.io/quenchworks/images/vllm",
      "security": {
        "image": "ghcr.io/quenchworks/images/vllm",
        "version": "0.25.1",
        "tag": "ghcr.io/quenchworks/images/vllm:0.25.1",
        "critical": 0,
        "high": 0,
        "medium": 2,
        "low": 1,
        "unknown": 0,
        "total": 3,
        "fixable": 2,
        "grade": "C",
        "score": 81,
        "cves": [
          {
            "id": "CVE-2026-59890",
            "severity": "MEDIUM",
            "pkg": "setuptools",
            "installed": "80.9.0",
            "fixed": "83.0.0",
            "title": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)",
            "url": "https://avd.aquasec.com/nvd/cve-2026-59890",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2025-69872",
            "severity": "MEDIUM",
            "pkg": "diskcache",
            "installed": "5.6.3",
            "fixed": null,
            "title": "python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization",
            "url": "https://avd.aquasec.com/nvd/cve-2025-69872",
            "targets": [
              "Python"
            ]
          },
          {
            "id": "CVE-2025-3000",
            "severity": "LOW",
            "pkg": "torch",
            "installed": "2.11.0+cpu",
            "fixed": "2.13.0",
            "title": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...",
            "url": "https://avd.aquasec.com/nvd/cve-2025-3000",
            "targets": [
              "Python"
            ]
          }
        ],
        "versions": [
          {
            "version": "0.25.1",
            "tag": "ghcr.io/quenchworks/images/vllm:0.25.1",
            "critical": 0,
            "high": 0,
            "medium": 2,
            "low": 1,
            "unknown": 0,
            "total": 3,
            "fixable": 2,
            "grade": "C",
            "score": 81,
            "cves": [
              {
                "id": "CVE-2026-59890",
                "severity": "MEDIUM",
                "pkg": "setuptools",
                "installed": "80.9.0",
                "fixed": "83.0.0",
                "title": "setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)",
                "url": "https://avd.aquasec.com/nvd/cve-2026-59890",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2025-69872",
                "severity": "MEDIUM",
                "pkg": "diskcache",
                "installed": "5.6.3",
                "fixed": null,
                "title": "python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization",
                "url": "https://avd.aquasec.com/nvd/cve-2025-69872",
                "targets": [
                  "Python"
                ]
              },
              {
                "id": "CVE-2025-3000",
                "severity": "LOW",
                "pkg": "torch",
                "installed": "2.11.0+cpu",
                "fixed": "2.13.0",
                "title": "A vulnerability classified as critical has been found in PyTorch 2.6.0 ...",
                "url": "https://avd.aquasec.com/nvd/cve-2025-3000",
                "targets": [
                  "Python"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "weaviate",
      "name": "weaviate",
      "category": "Search & vector",
      "summary": "Open-source AI-native vector database for semantic search and retrieval-augmented generation, with hybrid keyword plus vector queries.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.38.8",
      "versions": [
        {
          "version": "1.38.8",
          "size": "69.0 MB",
          "published": "2026-07-30T08:13:54Z",
          "digest": "sha256:519ffc0a60bb2d763a9186f859c1e736947a1cbc519925ea205edff3aa5dcd2a"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://weaviate.io",
      "source": "https://github.com/weaviate/weaviate",
      "image": "ghcr.io/quenchworks/images/weaviate",
      "security": {
        "image": "ghcr.io/quenchworks/images/weaviate",
        "version": "1.38.7",
        "tag": "ghcr.io/quenchworks/images/weaviate:1.38.7",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.54.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/weaviate-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "1.38.7",
            "tag": "ghcr.io/quenchworks/images/weaviate:1.38.7",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.54.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/weaviate-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "woodpecker",
      "name": "woodpecker",
      "category": "CI/CD & registry",
      "summary": "Lightweight, container-native CI/CD engine (a Drone-compatible fork) with a server, agent, and CLI. From source (Vue UI embedded in the static Go server) on a hardened nonroot Wolfi base.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.16.0",
      "versions": [
        {
          "version": "3.16.0",
          "size": "59.2 MB",
          "published": "2026-07-22T06:34:04Z",
          "digest": "sha256:66a6768fbc6a8e6fc5d57e757dceaa2afbdaf8eddaf361bd489868b251b6d1e7"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://woodpecker-ci.org",
      "source": "https://github.com/woodpecker-ci/woodpecker",
      "image": "ghcr.io/quenchworks/images/woodpecker",
      "security": {
        "image": "ghcr.io/quenchworks/images/woodpecker",
        "version": "3.16.0",
        "tag": "ghcr.io/quenchworks/images/woodpecker:3.16.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 2,
        "total": 2,
        "fixable": 0,
        "grade": "B",
        "score": 96,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/woodpecker-cli",
              "usr/bin/woodpecker-server"
            ]
          }
        ],
        "versions": [
          {
            "version": "3.16.0",
            "tag": "ghcr.io/quenchworks/images/woodpecker:3.16.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 2,
            "total": 2,
            "fixable": 0,
            "grade": "B",
            "score": 96,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/woodpecker-cli",
                  "usr/bin/woodpecker-server"
                ]
              }
            ]
          }
        ]
      }
    },
    {
      "slug": "wordpress",
      "name": "wordpress",
      "category": "Apps & productivity",
      "summary": "WordPress, the PHP content-management system and blogging platform. Reconstructed clean-room from the official release on a hardened Wolfi php-8.4-fpm + nginx runtime (nonroot, read-only rootfs, supervisord), not the php:apache upstream image. The image ships no wp-config.php; the chart supplies one via ConfigMap and provides a MySQL backend.",
      "tier": "standard",
      "status": "available",
      "license": "GPL-2.0+",
      "licenseClean": "clean",
      "version": "6.8.6, 7.0.2, 6.9.5",
      "versions": [
        {
          "version": "6.8.6",
          "size": "91.1 MB",
          "published": "2026-07-26T12:37:55Z",
          "digest": "sha256:ed91a26d0d7641f3732296e070d064cec5cc596ef1c2d8644608a1662fa93a6a"
        },
        {
          "version": "7.0.2",
          "size": "93.7 MB",
          "published": "2026-07-26T12:37:54Z",
          "digest": "sha256:dbe5e89bf4b10d8950e7bed7aea88d134fdd5554629de29c3aa6427bab8804f6"
        },
        {
          "version": "6.9.5",
          "size": "91.1 MB",
          "published": "2026-07-26T12:37:49Z",
          "digest": "sha256:7ac3ed7ed68ee8683cf0d0b4772c51eb18970b25b4c8f6d7236cef5df20218e0"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://wordpress.org",
      "source": "https://wordpress.org/wordpress-7.0.tar.gz",
      "image": "ghcr.io/quenchworks/images/wordpress",
      "security": {
        "image": "ghcr.io/quenchworks/images/wordpress",
        "version": "7.0.2",
        "tag": "ghcr.io/quenchworks/images/wordpress:7.0.2",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "7.0.2",
            "tag": "ghcr.io/quenchworks/images/wordpress:7.0.2",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "6.9.5",
            "tag": "ghcr.io/quenchworks/images/wordpress:6.9.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "6.8.6",
            "tag": "ghcr.io/quenchworks/images/wordpress:6.8.6",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "xyops",
      "name": "xyops",
      "category": "Workflow",
      "summary": "xyops, a workflow-automation and server-monitoring system (job scheduler, monitors, alerting, ticketing) by the creator of Cronicle. Built from source on Wolfi nodejs-22 (native better-sqlite3), nonroot on a hardened read-only-rootfs base. Single-instance with an embedded SQLite store on a persistent volume; the chart runs it as a StatefulSet.",
      "tier": "standard",
      "status": "available",
      "license": "BSD-3-Clause",
      "licenseClean": "clean",
      "version": "1.0.86",
      "versions": [
        {
          "version": "1.0.86",
          "size": "85.0 MB",
          "published": "2026-07-30T08:10:02Z",
          "digest": "sha256:ee7074c8201e3b2a05c4145af92ca3beb2421687ee347f033c831926fc02ed06"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/pixlcore/xyops",
      "source": "https://github.com/pixlcore/xyops",
      "image": "ghcr.io/quenchworks/images/xyops",
      "security": {
        "image": "ghcr.io/quenchworks/images/xyops",
        "version": "1.0.85",
        "tag": "ghcr.io/quenchworks/images/xyops:1.0.85",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "1.0.85",
            "tag": "ghcr.io/quenchworks/images/xyops:1.0.85",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "yarn",
      "name": "yarn",
      "category": "Build tool",
      "summary": "Node base image with Yarn preinstalled, used as the build stage for Yarn projects. Lines 1 (classic) and 4 (berry).",
      "tier": "standard",
      "status": "available",
      "license": "BSD-2-Clause",
      "licenseClean": "clean",
      "version": "4.17.0, 3.8.7, 1.22.22",
      "versions": [
        {
          "version": "4.17.0",
          "size": "53.4 MB",
          "published": "2026-07-04T11:34:16Z",
          "digest": "sha256:6418767b94abe2419f88fd5c3cfbcb18781c2743e082fee35a8fdd396702af20"
        },
        {
          "version": "3.8.7",
          "size": "53.2 MB",
          "published": "2026-07-04T11:34:15Z",
          "digest": "sha256:8bc7879fce7e56c07776a42c6a3cc8b854ee275bb3d0eac8cab07db27fc0856c"
        },
        {
          "version": "1.22.22",
          "size": "53.5 MB",
          "published": "2026-07-04T11:34:00Z",
          "digest": "sha256:7df831896c444391b86e2f8f60f807c8139a2932bced734509c6c54552278ce1"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://yarnpkg.com",
      "source": "https://yarnpkg.com",
      "image": "ghcr.io/quenchworks/images/yarn",
      "security": {
        "image": "ghcr.io/quenchworks/images/yarn",
        "version": "4.17.0",
        "tag": "ghcr.io/quenchworks/images/yarn:4.17.0",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "4.17.0",
            "tag": "ghcr.io/quenchworks/images/yarn:4.17.0",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "3.8.7",
            "tag": "ghcr.io/quenchworks/images/yarn:3.8.7",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          },
          {
            "version": "1.22.22",
            "tag": "ghcr.io/quenchworks/images/yarn:1.22.22",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "zookeeper",
      "name": "ZooKeeper",
      "category": "Coordination",
      "summary": "Centralized coordination service for distributed systems, providing configuration, naming, leader election, and synchronization primitives.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "3.9.5",
      "versions": [
        {
          "version": "3.9.5",
          "size": "92.5 MB",
          "published": "2026-07-23T11:58:11Z",
          "digest": "sha256:a2faaae10d092e74078559ceeeffc0c3246f0421e6559701c04db6832c3c5329"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://github.com/apache/zookeeper",
      "source": "https://archive.apache.org/dist/zookeeper/zookeeper-3.9.5/apache-zookeeper-3.9.5-bin.tar.gz",
      "image": "ghcr.io/quenchworks/images/zookeeper",
      "security": {
        "image": "ghcr.io/quenchworks/images/zookeeper",
        "version": "3.9.5",
        "tag": "ghcr.io/quenchworks/images/zookeeper:3.9.5",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 0,
        "total": 0,
        "fixable": 0,
        "grade": "A+",
        "score": 100,
        "cves": [],
        "versions": [
          {
            "version": "3.9.5",
            "tag": "ghcr.io/quenchworks/images/zookeeper:3.9.5",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 0,
            "total": 0,
            "fixable": 0,
            "grade": "A+",
            "score": 100,
            "cves": []
          }
        ]
      }
    },
    {
      "slug": "zot",
      "name": "zot",
      "category": "Registry",
      "summary": "OCI-native container registry (registry, sync, and dist-spec surface). Built from source as a static Go binary on a hardened nonroot Wolfi base; filesystem storage under a writable volume.",
      "tier": "standard",
      "status": "available",
      "license": "Apache-2.0",
      "licenseClean": "clean",
      "version": "2.1.18",
      "versions": [
        {
          "version": "2.1.18",
          "size": "22.3 MB",
          "published": "2026-07-26T12:35:16Z",
          "digest": "sha256:90d5fae2927a377892e1579bc41ace4370963e7e60fd44e4e5f9de376bd83a3d"
        }
      ],
      "arches": [
        "amd64",
        "arm64"
      ],
      "upstream": "https://zotregistry.dev",
      "source": "https://github.com/project-zot/zot",
      "image": "ghcr.io/quenchworks/images/zot",
      "security": {
        "image": "ghcr.io/quenchworks/images/zot",
        "version": "2.1.18",
        "tag": "ghcr.io/quenchworks/images/zot:2.1.18",
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "unknown": 1,
        "total": 1,
        "fixable": 0,
        "grade": "B",
        "score": 98,
        "cves": [
          {
            "id": "GO-2026-5932",
            "severity": "UNKNOWN",
            "pkg": "golang.org/x/crypto",
            "installed": "v0.53.0",
            "fixed": null,
            "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
            "url": "https://go.dev/issue/44226",
            "targets": [
              "usr/bin/zot"
            ]
          }
        ],
        "versions": [
          {
            "version": "2.1.18",
            "tag": "ghcr.io/quenchworks/images/zot:2.1.18",
            "critical": 0,
            "high": 0,
            "medium": 0,
            "low": 0,
            "unknown": 1,
            "total": 1,
            "fixable": 0,
            "grade": "B",
            "score": 98,
            "cves": [
              {
                "id": "GO-2026-5932",
                "severity": "UNKNOWN",
                "pkg": "golang.org/x/crypto",
                "installed": "v0.53.0",
                "fixed": null,
                "title": "The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues",
                "url": "https://go.dev/issue/44226",
                "targets": [
                  "usr/bin/zot"
                ]
              }
            ]
          }
        ]
      }
    }
  ]
}