kube-state-metrics8.4.1
Helm chartInstall kube-state-metrics to generate and expose cluster-level metrics
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 0
- Low
- 8
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
8 findings over 1 of 1 images measured · scored 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of 8.4.1, one sample per day, last 90 days. Hover a point for its date and advisory data.
Score moves
A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves
Fewer than two samples so far.
Findings
8 distinct across the version’s images
| Advisory | Package | Fixed in | Contribution | EPSS | Since | Digests |
|---|---|---|---|---|---|---|
| GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | google.golang.org/grpc@v1.79.3golang | 1.82.1 | 9/100 | — | 2 Sept 2026 | 42cfe3723a5f |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.79.3golang | 1.83.1 | 9/100 | — | 2 Sept 2026 | 42cfe3723a5f |
| GHSA-gcjh-h69q-9w9g cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag | github.com/google/cel-go@v0.26.0golang | 0.29.0 | 6/100 | — | 2 Sept 2026 | 42cfe3723a5f |
| GO-2026-5158 Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel | go.opentelemetry.io/otel@v1.43.0golang | 1.42.0 | 6/100 | 0.003 (26th pct) | 2 Sept 2026 | 42cfe3723a5f |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.54.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 42cfe3723a5f |
| GO-2026-5932 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | golang.org/x/crypto@v0.54.0golang | no fix listed | 4/100 | — | 2 Sept 2026 | 42cfe3723a5f |
| GO-2026-6061 Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc | google.golang.org/grpc@v1.79.3golang | 1.82.1 | 4/100 | — | 2 Sept 2026 | 42cfe3723a5f |
| GO-2026-6094 JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go | github.com/google/cel-go@v0.26.0golang | 0.30.0 | 4/100 | — | 2 Sept 2026 | 42cfe3723a5f |
Workloads and images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
| Container | Image | Tag | Digest | Radar Score |
|---|---|---|---|---|
| Deployment candidate-kube-state-metrics | ||||
| kube-state-metrics | registry.k8s.io/kube-state-metrics/kube-state-metrics | v2.20.0 | 42cfe3723a5f | 48 |
Unmeasured images (0)
Every image the render resolved has a scan.