Charts / PaaS / Coolify Realtime digest pinned cosign signed SPDX SBOM SLSA provenance amd64 · arm64 Rebuilt 2026-08-26
Realtime server component of Coolify, providing the websocket connections and terminal/log gateway for the dashboard. Licensed AGPL.
Version
The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version. Only the most recent releases are listed — an older chart pins an older image digest.
Deployed image digest
sha256:f128e512c9c07a7906222663085ccc5a61090a77a97a2fee4cb1a78d1819ed2bChart OCI version
oci://ghcr.io/quenchworks/charts/coolify-realtime:0.0.7The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Security report (Trivy) D· 0/100 14 fixable · rebuild clears them Full report
Vulnerability detail coolify-realtime 1.0.17 · 16 CVE CVE Severity Package Installed Fixed in Title CVE-2026-84304 HIGH google.golang.org/grpc v1.82.1 1.83.1 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ... CVE-2026-84375 HIGH js-yaml 4.3.1 4.3.2, 3.15.2 js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84445 HIGH google.golang.org/grpc v1.82.1 1.82.2, 1.83.2, 1.85.0-dev.0.20260825072537-93e31b48545e gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers GHSA-3f6p-5ww8-9rcr HIGH mysql2 3.9.8 3.22.0 MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials CVE-2026-18374 MEDIUM glibc-2.44 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-18374 MEDIUM glibc-2.44-locale-posix 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-18374 MEDIUM ld-linux-2.44 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-18374 MEDIUM libcrypt1-2.44 2.44-r1 2.44-r6 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string CVE-2026-45822 MEDIUM decode-uri-component 0.2.2 0.5.0 decode-uri-component: decode-uri-component: Denial of Service via crafted input CVE-2026-56855 MEDIUM golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages CVE-2026-78662 MEDIUM golang.org/x/crypto v0.55.0 0.56.0 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding CVE-2026-84303 MEDIUM google.golang.org/grpc v1.82.1 1.83.1 gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ... CVE-2026-85091 MEDIUM zlib 1.3.2-r4 1.3.3-r0 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... GHSA-rgwj-5xj2-c3m3 MEDIUM mysql2 3.9.8 3.23.1 MySQL2: Unbounded zlib inflate in compressed MySQL protocol handler allows decompression-bomb DoS GHSA-j965-2qgj-vjmq LOW aws-sdk 2.1426.0 — not fixable JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3 GO-2026-5932 UNKNOWN golang.org/x/crypto v0.55.0 — not fixable The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
Close
Security report (Trivy) · image coolify-realtime 1.0.17
Install the chart Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (latest)
helm install my-coolify-realtime oci://ghcr.io/quenchworks/charts/coolify-realtime --version 0.0.7Deploys image (digest-pinned)
ghcr.io/quenchworks/images/coolify-realtime@sha256:f128e512c9c07a7906222663085ccc5a61090a77a97a2fee4cb1a78d1819ed2b
Chart version 0.0.7
App version 1.0.17
Chart license AGPL-3.0-or-later
App license AGPL-3.0+
Signed cosign (keyless)
Values schema yes
Last published 2026-08-26 Verify the chart
cosign verify ghcr.io/quenchworks/charts/coolify-realtime:0.0.7 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.
Upstream project: https://github.com/coollabsio/coolify