تخطَّ إلى المحتوى
QuenchWorks

argocd

مخطط · GitOps · standard · v0.0.1

مثبّتة بالبصمةموقّعة بـ cosignSPDX SBOMمنشأ SLSAamd64 · arm64أُعيد بناؤها 2026-08-02

Argo CD, the CNCF declarative GitOps continuous-delivery controller for Kubernetes. One multi-call binary serves every component (server, repo-server, application-controller, applicationset-controller, commit-server, notifications, cmp-server), selected by argv[0] exactly as upstream does, so the chart picks a role with a single command. Built from source with upstream's own asset pipeline, so the server really serves its React web console instead of 404ing every UI route. Ships git, git-lfs, openssh-client and gnupg for private and signature-verified repos, plus Helm 3 built from source and the Wolfi Kustomize, both of which the repo-server execs by bare name.

بصمة الصورة المنشورة

sha256:e9f3d4132747b3813115a18eb744c5466d06ebcc8c3b5cdbb8536edf3c6dcdc7

إصدار OCI للمخطط

oci://ghcr.io/quenchworks/charts/argocd:0.0.1

يثبّت المخطط صورته بهذه البصمة الموقّعة، فلا تتعقّبها بنفسك أبدًا. تُرفَق التواقيع وقائمة المكوّنات والمنشأ بالبصمة نفسها.

موقّعة
cosign بدون مفتاح
SBOM
SPDX، على الصورة
المنشأ
بناء SLSA
المعماريات
amd64، arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط
حجم الصورة
106.0 MB

تقرير الأمان (Trivy)

D· 0/10054 fixable · rebuild clears them

تفاصيل الثغرات

argocd 3.4.6 · 22 CVE
الثغرة (CVE)الخطورةالحزمةالإصدار المثبَّتمُصلَحة فيالوصف
CVE-2026-39821HIGHstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39821HIGHstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHstdlibv1.26.51.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-46600HIGHgolang.org/x/netv0.55.00.56.0golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-46600HIGHstdlib1.26.51.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-50163HIGHoras.land/oras-go/v2v2.6.12.6.2oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks
CVE-2026-71556HIGHgithub.com/go-git/go-git/v5v5.19.15.19.2go-git is an extensible git implementation library written in pure Go. ...
CVE-2026-71557MEDIUMgithub.com/go-git/go-git/v5v5.19.15.19.2go-git is an extensible git implementation library written in pure Go. ...
CVE-2026-33818UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...
CVE-2026-33818UNKNOWNstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...
CVE-2026-56853UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a ...
CVE-2026-56853UNKNOWNstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a ...
CVE-2026-56858UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, pathological inputs could close an unescaped '/' early, al ...
CVE-2026-56858UNKNOWNstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, pathological inputs could close an unescaped '/' early, al ...
CVE-2026-56859UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, DecodeElement would reset the depth counter causing it to ...
CVE-2026-56859UNKNOWNstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, DecodeElement would reset the depth counter causing it to ...
CVE-2026-56860UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..' ...
CVE-2026-56860UNKNOWNstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..' ...
CVE-2026-56862UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state- ...
CVE-2026-56862UNKNOWNstdlib1.26.51.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state- ...
GO-2026-5932UNKNOWNgolang.org/x/cryptov0.53.0غير قابلة للإصلاحThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
GO-2026-5932UNKNOWNgolang.org/x/cryptov0.52.0غير قابلة للإصلاحThe golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
0
حرجة
17
عالية
1
متوسطة
0
منخفضة
40
غير معروفة

تقرير الأمان (Trivy) · image argocd 3.4.6

ثبّت المخطط

انشر إلى Kubernetes بإعدادات افتراضية مُحصّنة. يثبّت المخطط صورته ببصمة موقّعة، فلا تتعقّبها بنفسك أبدًا.

تثبيت (الأحدث)

helm install my-argocd oci://ghcr.io/quenchworks/charts/argocd --version 0.0.1

يَنشُر الصورة (مثبّتة بالبصمة)

ghcr.io/quenchworks/images/argocd@sha256:e9f3d4132747b3813115a18eb744c5466d06ebcc8c3b5cdbb8536edf3c6dcdc7
إصدار المخطط
0.0.1
إصدار التطبيق
3.4.6
رخصة المخطط
Apache-2.0
رخصة التطبيق
Apache-2.0
موقّع
cosign (بدون مفتاح)
مخطط القيم
نعم
آخر نشر
2026-08-02

تحقّق من المخطط

cosign verify ghcr.io/quenchworks/charts/argocd:0.0.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

الشفافية

يَنشُر المخطط شهاداته على GitHub ، والصورة التي ينشرها تحمل شهاداتها على البصمة نفسها، قابلة للتحقق علنًا بالأوامر أعلاه. كلاهما يُسجَّل في سجلّ شفافية Sigstore (Rekor)، الذي يفحصه cosign verify نيابةً عنك.

المشروع المنبع: https://argo-cd.readthedocs.io