تخطَّ إلى المحتوى
QuenchWorks

argocd

مخطط · GitOps · standard · v0.0.1

مثبّتة بالبصمةموقّعة بـ cosignSPDX SBOMمنشأ SLSAamd64 · arm64أُعيد بناؤها 2026-08-02

Argo CD, the CNCF declarative GitOps continuous-delivery controller for Kubernetes. One multi-call binary serves every component (server, repo-server, application-controller, applicationset-controller, commit-server, notifications, cmp-server), selected by argv[0] exactly as upstream does, so the chart picks a role with a single command. Built from source with upstream's own asset pipeline, so the server really serves its React web console instead of 404ing every UI route. Ships git, git-lfs, openssh-client and gnupg for private and signature-verified repos, plus Helm 3 built from source and the Wolfi Kustomize, both of which the repo-server execs by bare name.

بصمة الصورة المنشورة

sha256:e9f3d4132747b3813115a18eb744c5466d06ebcc8c3b5cdbb8536edf3c6dcdc7

إصدار OCI للمخطط

oci://ghcr.io/quenchworks/charts/argocd:0.0.1

يثبّت المخطط صورته بهذه البصمة الموقّعة، فلا تتعقّبها بنفسك أبدًا. تُرفَق التواقيع وقائمة المكوّنات والمنشأ بالبصمة نفسها.

موقّعة
cosign بدون مفتاح
SBOM
SPDX، على الصورة
المنشأ
بناء SLSA
المعماريات
amd64، arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط
حجم الصورة
106.0 MB

تقرير الأمان (Trivy)

D· 24/1006 fixable · rebuild clears them

تفاصيل الثغرات

argocd 3.4.6 · 6 CVE
الثغرة (CVE)الخطورةالحزمةالإصدار المثبَّتمُصلَحة فيالوصف
CVE-2026-50163HIGHoras.land/oras-go/v2v2.6.12.6.2oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks
CVE-2026-71556HIGHgithub.com/go-git/go-git/v5v5.19.15.19.2go-git is an extensible git implementation library written in pure Go. ...
CVE-2026-71557MEDIUMgithub.com/go-git/go-git/v5v5.19.15.19.2go-git is an extensible git implementation library written in pure Go. ...
CVE-2026-46600UNKNOWNgolang.org/x/netv0.55.00.56.0Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...
GO-2026-5932UNKNOWNgolang.org/x/cryptov0.53.0غير قابلة للإصلاحThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GO-2026-5932UNKNOWNgolang.org/x/cryptov0.52.0غير قابلة للإصلاحThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
0
حرجة
3
عالية
1
متوسطة
0
منخفضة
6
غير معروفة

تقرير الأمان (Trivy) · image argocd 3.4.6

ثبّت المخطط

انشر إلى Kubernetes بإعدادات افتراضية مُحصّنة. يثبّت المخطط صورته ببصمة موقّعة، فلا تتعقّبها بنفسك أبدًا.

تثبيت (الأحدث)

helm install my-argocd oci://ghcr.io/quenchworks/charts/argocd --version 0.0.1

يَنشُر الصورة (مثبّتة بالبصمة)

ghcr.io/quenchworks/images/argocd@sha256:e9f3d4132747b3813115a18eb744c5466d06ebcc8c3b5cdbb8536edf3c6dcdc7
إصدار المخطط
0.0.1
إصدار التطبيق
3.4.6
رخصة المخطط
Apache-2.0
رخصة التطبيق
Apache-2.0
موقّع
cosign (بدون مفتاح)
مخطط القيم
نعم
آخر نشر
2026-08-02

تحقّق من المخطط

cosign verify ghcr.io/quenchworks/charts/argocd:0.0.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

الشفافية

يَنشُر المخطط شهاداته على GitHub ، والصورة التي ينشرها تحمل شهاداتها على البصمة نفسها، قابلة للتحقق علنًا بالأوامر أعلاه. كلاهما يُسجَّل في سجلّ شفافية Sigstore (Rekor)، الذي يفحصه cosign verify نيابةً عنك.

المشروع المنبع: https://argo-cd.readthedocs.io