Skip to content
QuenchWorks

Roadmap

What is shipped, what is next

405 datastores and tools are hardened and shipping today. Below is what is on deck, OSI-clean options first. Every entry is built from source on Wolfi, scanned to zero fixable CVEs, signed, and pinned by digest before it moves to available.

405/490
83% shipped
40583%
Shipped
8317%
On the roadmap
20%
Blocked

Update queue

0 open

Newer upstream releases of apps already in the catalog, from the version check on. Each one ships only after its image passes the 0-CVE gate and its boot test, and its chart is re-pinned to the new digest.

AppFromToStatus
atlantis0.48.00.48.1shipped
blackbox-exporter0.28.00.29.0shipped
checkov3.3.253.3.26shipped
dragonfly2.0.02.0.2shipped
ghost6.68.06.69.0shipped
gradle9.8.09.8.1shipped
graylog7.1.97.1.10shipped
litellm1.104.01.104.1, 1.103.4shipped
livekit1.13.81.13.9shipped
mimir3.2.13.2.2shipped
ntfy2.28.02.29.0shipped
pulumi3.267.03.268.0shipped
pyroscope2.3.12.3.2shipped
rqlite10.5.210.5.3shipped
timestamp-authority2.1.32.1.4shipped
vault2.1.12.1.2shipped
weaviate1.40.01.39.10shipped
woodpecker3.18.13.19.0shipped
clickhouse26.7.16.2, 26.9.5.226.7.24.8, 26.9.12.8held

Bespoke per-version maps; needs its own session.

coolify-app4.3.234.4.2held

4.4 replaces the realtime image with Reverb and coolify-terminal: a stack redesign.

documentdb0.117.01.0.RC1held

1.0.RC1 is a prerelease.

grafana13.1.613.2.3held

13.2 needs its own session (per-version thrift and datasource work).

jellyfin12.112.2held

Blocked: 12.2 still ships the prebuilt SkiaSharp library.

meilisearch1.54.31.53.3held

Outside the build window of the newest lines.

metabase0.63.180.64.1held

0.64 is a new minor with new findings; evaluated separately.

odoo19.0.2026092919.0.20261007held

Nightly tarballs rotate out within days.

pnpm11.28.4, 12.9.111.28.5, 12.10.1held

Held to 2026-10-20: same-day package-manager releases (npm cooldown).

pulsar4.2.45.0.0held

5.0.0 is a new major: image first, chart after its migration notes.

renovate44.133.044.145.1held

Held to 2026-10-20: installs with npm 12, inside its cooldown.

Available now

405

AI gateway

2

Analytical

1

Apps & productivity

28

Base image

1

Build tool

7

CI

2

CI/CD & registry

27

Cache

7

Coordination

13

Coordination & mesh

24

Database

1

Databases & engines

12

Developer tools / IDE

1

Document

5

Gateway

27

Git

4

GitOps

3

Graph

1

Identity

12

Language runtime

13

Machine learning & AI

8

Media & streaming

3

Messaging

20

Metrics/Exporter

6

Networking

9

Object storage

5

Observability

32

PaaS

3

Registry

10

Relational

10

Runtime base

4

Search

8

Search & vector

1

Secrets

3

Secrets & identity

2

Security & supply chain

48

Storage & platform

21

Time series

4

Vector

1

Wide-column

2

Workflow

14

Held — built, not shipped

2

These build and test clean but can't reach 0 fixable CVEs yet — the app or its base pins a dependency below the version that fixes a known CVE, so we hold it rather than ship a vulnerable image. Each re-lists automatically the moment upstream ships the fix. Tapwhy blocked? for the exact pin.

Apps & productivity

1
  • Apache Supersetblocked

    Data exploration and business-intelligence dashboard platform backed by a metadata database and Redis. Measured 2026-09-26: 6.1.0 (and 6.0.0) have no advisories, 5.0 does. It pins pyarrow<19, whose wheel statically embeds OpenSSL 3.3.0 and libcurl 8.7.0 (Wolfi packages pyarrow 23 and newer only), and a loose PyPI resolve pulls a flask-caching that breaks its metastore cache. Needs a build from the tag's pinned requirements, a module float, and a pyarrow swap tested against result_set.py.

    Apps & productivityApache-2.0

Observability

1
  • OpenSearch Dashboardsblocked

    Visualization UI for OpenSearch. Measured 2026-09-26 at 3.8.0: the full bundle has 12 vulnerable npm packages, among them maplibre-gl 5.2.0 (CRITICAL, fixed only in 6.x) compiled into the maps, observability and anomaly-detection plugin bundles. The min distribution drops those plugins, leaving 7 patch-level fixes, but dompurify 3.4.11 is compiled into the Discover and chat UI bundles, so swapping node_modules would clear the scan and still ship the vulnerable code. Needs a from-source UI build (yarn build of OSD) to ship honestly. Re-measured 2026-10-07: an image that swaps node_modules scans 0 but still carries dompurify 3.4.11/3.4.12 in 8 browser bundles and maplibre-gl 5.2.0 in 3, so it is held. Upstream main has dompurify ^3.4.13 and maplibre-gl 6.4.1; Dashboards 3.9.0 (unreleased) is the next build to measure.

    ObservabilityApache-2.0

On the roadmap

83

Candidates, not commitments. next = strongest near-term picks;planned and exploring follow. Items marked caution are source-available (not OSI) and would ship only with a loud license note and the clean alternative called out. (Apps that build but can't hit 0 fixable CVEs yet are in Held, above.) Each card also shows how it will ship: image + chart for a deployable service, orimage only for a base/CLI/sidecar utility (like busybox).

Search & vector

1
  • Milvusplanned

    Scalable vector database for AI workloads. Measured 2026-09-30: releases ship only compose files and Wolfi has no package, so it is a from-source build: the C++ core through conan (about a hundred packages, often fetched as prebuilt binaries the scanner cannot see) plus a Rust component, a multi-hour build. Held until Wolfi packages it or a scanned from-source conan build is scoped.

    image + chartApache-2.0

Workflow & data

8
  • Apache Pinotplanned

    Real-time distributed OLAP datastore for low-latency analytics. Measured 2026-09-28: the 1.5.1 distribution carries 444 fixable findings (11 critical) in 31 packages, much of it netty 4.1.134 and jackson-databind 2.21.1 repeated across plugin jars. Measure again after the next release.

    image + chartApache-2.0
  • Apache Sparkplanned

    Unified batch and stream analytics engine. Measured 2026-09-24: the 4.2.0 distribution carries 99 findings, including Jetty 12.1.8 shaded into spark-core (fixed in 12.1.10), so it needs a from-source build. The Wolfi spark-4.0/4.1 packages were measured too (78 and 92 findings): Hive 2.3 jars, the YARN shuffle jar and shaded Jetty 11.0.26 remain, so the build must drop the hive and yarn profiles.

    image + chartApache-2.0
  • Camundaplanned

    Process automation and BPMN orchestration including the Zeebe engine. Checked 2026-09-27: the repository is under the Camunda License 1.0, not Apache-2.0.

    image + chartCamunda-License-1.0caution
  • Apache Camel Kexploring

    Kubernetes-native integration framework.

    image + chartApache-2.0
  • Apache Druidexploring

    Real-time analytics database for high-concurrency OLAP queries. Held 2026-09-26: the 37.0.0 distribution carries 137 findings. Two sit in the core lib/ and cannot be swapped: netty 3.10.6 (8 findings, end of life, fixes only exist in netty 4; Druid's HTTP client is built on it) and calcite-core 1.37.0 (the SQL planner, fixed in 1.42). Shipping needs Druid itself to move off both.

    image + chartApache-2.0
  • Apache Polarisexploring

    Open REST catalog for Apache Iceberg tables.

    image + chartApache-2.0
  • Cubeexploring

    Semantic layer and analytics API over your data.

    image + chartApache-2.0
  • Hyperledger Fabricexploring

    Permissioned enterprise blockchain platform.

    image + chartApache-2.0

Messaging & streaming

3
  • Apicurio Registryplanned

    API and schema registry for Kafka, Avro, and Protobuf. Measured 2026-09-25: the 3.3.3 app distribution carries 467 findings; 26 in-place jar swaps clear all but opentelemetry-api 1.57.0 (CVE-2026-45292, fixed only in 1.62.0), which adds packages the prebuilt Quarkus index cannot load. Needs a source build that regenerates the index.

    image + chartApache-2.0
  • Redpandaplanned

    Kafka-compatible streaming. Source-available, not OSI.

    clean alt: Kafka or Pulsar (Apache-2.0), both already shipped.

    image + chartBSL-1.1caution
  • Strimziplanned

    Kubernetes operator for running and managing Kafka. Sized 2026-09-25: two from-source images, the operator (a Maven multi-module build; the release ships only install YAML) and Strimzi's own Kafka image, whose run scripts and agents the operator drives; the QuenchWorks kafka image does not have that layout. Measured 2026-09-29: Wolfi packages Strimzi too (strimzi-kafka-operator with kafka-strimzi-compat), but at 1.0.0-r4 against upstream 1.2.0, and that stack scans at 849 fixable findings (59 critical, 353 high), including jackson-databind 2.21.2 and the JMX exporter; so it still needs the from-source build.

    image + chartApache-2.0

Coordination & mesh

7
  • Cilium Envoyplanned

    Cilium's own patched Envoy; not reusable from our stock envoy image.

    image + chartApache-2.0
  • Consulplanned

    HashiCorp Consul. BUSL-1.1: source-available, NOT OSI. Recommendation is to skip -- the mesh slot is already covered by Kuma (shipped) plus Linkerd and Istio in this wave, all OSI-licensed. Revisit on explicit demand.

    clean alt: Kuma (Apache-2.0) -- already shipped; or Linkerd / Istio.

    image + chartBUSL-1.1caution
  • Consul Dataplaneplanned

    Envoy-based sidecar for Consul. MPL, so cleaner than the BUSL server.

    image + chartMPL-2.0
  • Consul K8s Control Planeplanned

    The operator that makes Consul work on Kubernetes.

    image + chartMPL-2.0
  • Istioplanned

    Service mesh built on Envoy. Ambient mode SHIPPED 2026-10-08: istiod, istio-cni and ztunnel charts on 1.30.5, gated on mTLS (HBONE) traffic between two pods. Still held: L7 waypoints and sidecar mode, which need the Istio proxyv2 image, which has no melange-buildable path.

    image + chartApache-2.0
  • Linkerd Vizplanned

    The Viz chart SHIPPED 2026-10-08 (metrics-api, tap, tap-injector; gated on linkerd viz stat and tap over mTLS). Still held: the web dashboard image, whose bundled JavaScript carries decode-uri-component 0.2.2, linkify-it 2.2.0, path-to-regexp 1.8.0 and moment 2.29.4, which the image scan cannot see.

    image + chartApache-2.0
  • Nomadplanned

    Workload scheduler. Source-available, not OSI.

    image + chartBUSL-1.1caution

Databases & engines

11
  • Percona XtraDB Cluster Operatornext

    Operator for Percona XtraDB Cluster (MySQL): synchronous multi-primary HA via Galera, with automated backups and point-in-time recovery. Image SHIPPED 2026-09-27 (1.18.0, 1.19.1, 1.20.0; it is also the pods' init image). Chart HELD: in the kind gate the operator creates the cluster and its init containers complete, but the Percona 8.4.8 database pod starts mysqld with wsrep provider none and never becomes ready, and it does the same with upstream's init image and with the 8.0 database image. Percona's forum reports the same failure in kind and minikube on Linux; the chart waits for a gate on a non-kind cluster.

    image + chartApache-2.0
  • ArangoDBplanned

    Multi-model database for documents, graphs, and key-value. Checked 2026-09-27: the repository LICENSE is the Business Source License 1.1, not Apache-2.0.

    image + chartBSL-1.1caution
  • Liquibaseplanned

    Database schema change and migration management. Relicensed: 5.x is under the Functional Source License 1.1 (source-available, Apache-2.0 two years after each release, competing use restricted); the last Apache-2.0 release is 4.33.0 and its line is no longer patched. Flyway (Apache-2.0) covers the same job.

    image + chartFSL-1.1caution
  • MongoDB Community Operatorplanned

    MongoDB Community Kubernetes Operator: replica-set HA, automated failover, and TLS via CRDs. The operator is Apache-2.0; note the MongoDB server it deploys is SSPL (not OSI). Held 2026-10-07: the community operator repo is archived; its successor mongodb/mongodb-kubernetes (1.13.0, Apache-2.0 for Community clusters) runs every member beside mongodb-agent, a closed-source binary its Dockerfile downloads prebuilt (agent 109.0.1.9310-1), which cannot be built or scanned.

    image + chartApache-2.0
  • SurrealDBplanned

    Multi-model database. Source-available, not OSI.

    image + chartBUSL-1.1caution
  • Aerospikeexploring

    Real-time key-value database; community edition is AGPL.

    image + chartAGPL-3.0agpl
  • Couchbaseexploring

    Distributed document database. Source-available, not OSI.

    clean alt: CouchDB (Apache-2.0), already shipped.

    image + chartBSL-1.1caution
  • JanusGraphexploring

    Distributed graph database over pluggable storage backends. Measured 2026-09-26: the newest release (1.1.0, 2024-11) carries 57 vulnerable packages (4 CRITICAL, 35 HIGH) in its dist. The project is active but has not released since; shipping at 0 CVEs needs a from-source Maven build with dependency management across the tree.

    image + chartApache-2.0
  • KeyDBexploring

    Multi-threaded Redis fork; BSD-licensed and Redis-protocol compatible. Held 2026-09-25: upstream is dormant (last release 6.3.4 in October 2023, last push May 2024) on a Redis 6.2 base, so it misses the Lua and protocol fixes Redis and Valkey shipped since. Valkey covers the slot.

    image + chartBSD-3-Clause
  • OrientDBexploring

    Multi-model graph and document database.

    image + chartApache-2.0
  • Tiny RDMexploring

    Modern Redis/Valkey desktop GUI (Wails/Go+Vue). A desktop client, not a deployable server, so it falls outside the hardened in-cluster image model — a web Redis UI (e.g. redis-commander) would be the cache-stack UI instead.

    image + chartGPL-3.0agpl

Storage & platform

4
  • Apache Ozoneplanned

    Scalable distributed object store (S3 + HDFS). Measured 2026-09-28: the 2.2.1 distribution carries 143 fixable findings in 22 jars. Most swap on their own line (netty 4.1.137, jackson 2.21.5, log4j 2.26.1), but jetty-server 9.4 is fixed only in 12.1, spring-core 5.3.39 only in 7.0 and aircompressor 0.27 only in 2.x. Needs an upstream move off those lines.

    image + chartApache-2.0
  • Dokployplanned

    Self-hostable PaaS on Docker Swarm. Open-core: most is Apache-2.0, the /proprietary parts are source-available (DSAL-1.0). Not a fit for the hardened catalog: it requires root, the Docker socket, and an initialized Swarm, so it cannot run nonroot or read-only.

    clean alt: Coolify (Apache-2.0), already shipped.

    image + chartApache-2.0 + DSAL-1.0caution
  • MinIOplanned

    S3-compatible object storage; relicensed to AGPL-3.0. Held 2026-10-08: minio/minio is archived (README: no longer maintained; the alternatives are the proprietary AIStor editions), last release RELEASE.2025-10-15T17-29-55Z. An archived server gets no CVE fixes. SeaweedFS, Garage, RustFS and Ceph (RGW) are the S3 options in the catalog.

    clean alt: SeaweedFS / Garage / RustFS (Apache-2.0), all already shipped.

    image + chartAGPL-3.0agpl
  • SonarQubeplanned

    Continuous code-quality and security inspection. Measured 2026-09-28: the 26.9 Community distribution carries 72 findings (4 critical), most inside its bundled Elasticsearch 9.4.3 (x-pack modules, transport-netty4) and in fat jars (sonar-application, the scanner engine). Needs the embedded Elasticsearch rebuilt or swapped before it can gate clean.

    image + chartLGPL-3.0

Apps & productivity

13
  • Appsmithplanned

    Low-code internal-tools and admin-panel builder backed by PostgreSQL and Redis. Measured 2026-09-30 (v2.4.2, no release binaries, no Wolfi package): the upstream image is all-in-one under supervisor (Java server, React editor, Node RTS and MCP, Caddy, Redis, PostgreSQL and MongoDB). Appsmith has since removed PostgreSQL support (scripts/prepare_server_artifacts.sh builds only the MongoDB server), so the server needs MongoDB, which is SSPL. A clean image would run against an external MongoDB, or FerretDB/DocumentDB if Appsmith's use of transactions works there, which is unverified. Maven and yarn builds exceed the local gate, so it is gated in CI.

    image + chartApache-2.0
  • Discourseplanned

    Ruby discussion and forum platform backed by PostgreSQL and Redis. Measured 2026-09-29 at 2026.9.0: the Gemfile.lock and pnpm-lock.yaml scan clean and Wolfi has ruby-3.4, ImageMagick 7, pngquant and oxipng, but two native gems ship only prebuilt binaries the scanner cannot see into: libv8-node (V8 for mini_racer, which PrettyText needs; a source build is a multi-hour Node V8 compile per arch) and sass-embedded (a bundled dart-sass, needed at runtime for theme CSS; Wolfi has the Dart SDK, so that half is buildable). Held on the V8 build.

    image + chartGPL-2.0-or-lateragpl
  • Gotenbergplanned

    Stateless HTML and URL to PDF conversion API. Recipe committed 2026-09-26 (Chromium variant; Wolfi has no LibreOffice): everything gates clean except chromium CVE-2026-13032, fixed in 149.0.7827.200, which Wolfi has not published yet. Ships when it does.

    image + chartMIT
  • Gristplanned

    Self-hosted spreadsheet-database hybrid, an Airtable alternative. Sized 2026-09-25: a Node build plus the Python 3.11 formula sandbox (gVisor or Pyodide); larger than the controller queue ahead of it.

    image + chartApache-2.0
  • Moodleplanned

    PHP learning management system backed by MySQL, MariaDB, or PostgreSQL. Measured 2026-09-29 at 5.2.3: the PHP side is fixable (5.2 runs composer install at build, so guzzle, psr7, aws-sdk-php, php-jwt, slim and jmespath float like mediawiki), but the H5P editor ships a prebuilt CKEditor 5 43.0.0 bundle (CVE-2024-45613, CVE-2026-28343 fixed only in 47.6.0; lodash-es CVE-2026-4800 HIGH). The fix is a four-major rebuild of a custom H5P build nothing would test, so the image is held until Moodle updates that bundle.

    image + chartGPL-3.0-or-lateragpl
  • Rocket.Chatplanned

    Self-hosted team chat platform backed by MongoDB.

    image + chartMIT
  • SuiteCRMplanned

    PHP customer relationship management application backed by MySQL or MariaDB. Measured 2026-10-04 on 8.10.2: the shipped frontend is Angular 18 (203 yarn.lock findings, fixed only in Angular 19 and later) and api-platform/core v3.4.17 is fixed only in v4, so both need major ports upstream; guzzle and flysystem would float. Held until SuiteCRM moves to Angular 19+ and api-platform 4.

    image + chartAGPL-3.0-onlyagpl
  • Backdrop CMSexploring

    Drupal fork focused on simplicity, backed by MySQL.

    image + chartGPL-2.0-or-later
  • Chromiumexploring

    Headless browser for rendering, scraping, and PDF export.

    image + chartBSD-3-Clause
  • Friendicaexploring

    Federated social network server.

    image + chartAGPL-3.0agpl
  • Ploneexploring

    Python enterprise CMS on Zope.

    image + chartGPL-2.0-or-later
  • Selenium Gridexploring

    Distributed browser automation and testing grid.

    image + chartApache-2.0
  • XWikiexploring

    Enterprise wiki and structured collaboration platform.

    image + chartLGPL-2.1

Media & streaming

1
  • Jellyfinplanned

    Self-hosted media server for movies, music, and live TV. Built 2026-09-29 from Wolfi's jellyfin 12.1 apks and it gates clean (0 fixable CVEs, boot test passes), but it is held: libSkiaSharp.so, a prebuilt NuGet binary from a Debian 10 clang 13 build, statically links libjpeg-turbo 2.1.5.1 (behind several upstream security fixes), libpng and other image libraries the scanner cannot see. Needs Skia built against the system libraries. The recipe is committed as blocked.

    image + chartGPL-2.0-onlyagpl

CI/CD & registry

4
  • Concourseexploring

    Pipeline-based continuous integration system backed by PostgreSQL. Images shipped 2026-09-30 (web and worker, with the registry-image and time resource types bundled, plus concourse-git-resource). The worker runs root and privileged, which containerd needs. Chart held 2026-09-30: under kind on GitHub's Ubuntu 24.04 runners, task containers fail to mount /sys in their user namespace, while the same install runs tasks elsewhere; the release waits for that cause.

    image + chartApache-2.0
  • GitLab CEexploring

    Full DevOps platform (Git forge + CI/CD + registry). Heavy fit: a large Ruby monolith that bundles PostgreSQL, Redis, Gitaly, Sidekiq and Workhorse, and the gitlab-org/gitlab repo is mostly EE-proprietary — only the CE-flagged code is MIT. Far from the minimal one-purpose hardened model.

    clean alt: Gitea or Forgejo — lightweight, fully-open Git forges that drop straight into the gitops-stack.

    image + chartMITcaution
  • KubeVirtexploring

    Run virtual machines as Kubernetes workloads. Sized 2026-10-08 at v1.9.0: upstream assembles its images with Bazel from CentOS Stream 9 RPMs (libvirt, qemu-kvm, passt). Wolfi has qemu 11.1.2 but no libvirt or passt package, so virt-launcher needs both built from source alongside the Go components (virt-operator, virt-api, virt-controller, virt-handler); it waits for local gates.

    image + chartApache-2.0
  • OneDevexploring

    Self-hosted Git server with built-in CI/CD, issues and kanban (Java). Heavier than Gitea/Gogs but far lighter than GitLab; an all-in-one gitops-stack backend option. Measured 2026-10-07 at 16.8.5 (47 findings): jackson-databind/core 2.22.2 in lib/ swap cleanly, but Hazelcast 5.7.0 (its newest release) relocates jackson 2.21.2 and tools.jackson 3.1.2 under com/hazelcast/shaded/, which needs a bytecode relocation rewrite or a Hazelcast release; logback 1.4.14 needs the 1.5 line; boot/ ships prebuilt Tanuki wrapper binaries.

    image + chartMIT

Machine learning

7
  • Langflowplanned

    Visual builder for LLM applications and agent workflows. Measured 2026-09-28: 1.12.3 resolves to 457 packages (2.3 GB). The scanner reports only chromadb 1.5.9 (no fix), but the wheels carry what it cannot see: OpenSSL 3.5.1 (ibm_db.libs), OpenSSL 3.6.2 and libcurl 8.20.0 inside pyarrow, BoringSSL in grpcio and hf_xet, and 7 bundled .libs directories (numpy, scipy, pillow, cassandra-driver). Wolfi has py3.13 pyarrow, grpcio, numpy, tokenizers and orjson, but no onnxruntime, chromadb or ibm_db, so an honest 0-CVE build needs those built from source or dropped.

    image + chartMIT
  • Langfuseplanned

    LLM observability and tracing platform backed by PostgreSQL, ClickHouse, Redis and S3. Held 2026-09-27: the core is MIT, but ee/, web/src/ee and worker/src/ee are under the Langfuse Enterprise License, which forbids distributing them, and 80 core files import from those 120 files. An image needs a build with the ee paths removed and stubbed.

    image + chartMIT
  • Open WebUIplanned

    Self-hosted web UI for chatting with local and remote LLMs. Checked 2026-09-27: the license is BSD-3-Clause plus a branding clause (the Open WebUI branding may not be altered for deployments above 50 users without permission), so it is not OSI. 0.11.4 also pins sentence-transformers, transformers, onnxruntime and opencv.

    image + chartOpen WebUI Licensecaution
  • AnythingLLMexploring

    Self-hosted chat-with-your-documents LLM application.

    image + chartMIT
  • DataHubexploring

    Metadata platform and data catalog.

    image + chartApache-2.0
  • Kubeflow Pipelinesexploring

    ML pipeline orchestration on Kubernetes.

    image + chartApache-2.0
  • TensorFlow Servingexploring

    High-performance serving system for TensorFlow models.

    image + chartApache-2.0

Observability

5
  • Kibanaplanned

    Visualization and dashboards for Elasticsearch. Default distribution is Elastic-2.0, not OSI.

    clean alt: OpenSearch Dashboards (Apache-2.0) over OpenSearch, both open.

    image + chartElastic-2.0caution
  • Logstashplanned

    Server-side log and event processing pipeline. Default distribution is Elastic-2.0, not OSI.

    clean alt: Vector (MPL-2.0) or Fluentd (Apache-2.0), both open pipelines.

    image + chartElastic-2.0caution
  • Netdataplanned

    Real-time per-second infrastructure monitoring agent.

    image + chartGPL-3.0agpl
  • Percona PMMplanned

    Percona Monitoring and Management — deep MySQL/PostgreSQL/MongoDB observability (query analytics) built on Prometheus, Grafana and VictoriaMetrics. AGPL, OSI-approved. Sized 2026-10-08 at v3.9.1 (no release binaries): pmm-server is one container that an Ansible playbook assembles on Oracle Linux 9 from eight RPMs built in the repo (pmm-managed, qan-api2, vmproxy, pmm-dump, pmm-ui, percona-dashboards) plus Percona forks of Grafana (12.4.5, frontend changes, so a full Node build unlike our grafana image) and VictoriaMetrics (pmm-6401-v1.149.0), with ClickHouse, PostgreSQL 14, nginx and supervisord in the same image. Several images of work plus a multi-process supervisor design; it waits for local gates (the btrfs metadata hold).

    image + chartAGPL-3.0
  • Cortexexploring

    Horizontally scalable, multi-tenant Prometheus storage. Held 2026-10-05: four prometheus/prometheus CVEs (two HIGH) are fixed only in 0.311.3 (Prometheus 3.11.3), but Cortex 1.21.1 is on 0.308.1 and imports tsdb/errors, removed in Prometheus 3.10; Cortex master is on 0.309.1 and still imports it. Unblocks when a Cortex release moves to Prometheus 3.11.

    image + chartApache-2.0

Secrets & identity

3
  • EJBCAplanned

    Enterprise PKI certificate authority (Community Edition) backed by a relational database. Measured 2026-10-04 on r9.6.3 (source only, no release assets): 167 vendored jars in lib/ that Trivy identifies none of, so its scan is blind there; by filename bcprov 1.84 (CVE-2026-8763, fixed 1.85) and freemarker 2.3.34 (CVE-2026-84939, fixed 2.3.35) need swaps. Buildable with Gradle on our WildFly image; a multi-session job, not a hold.

    image + chartLGPL-2.1-or-later
  • Teleportplanned

    Access plane providing identity-based SSH, Kubernetes, and database access. Community edition is AGPL-3.0.

    image + chartAGPL-3.0-onlyagpl
  • SATOSAexploring

    Proxy that translates between SAML and OIDC.

    image + chartApache-2.0

Security & supply chain

5
  • Daggerplanned

    Programmable CI/CD engine that runs pipelines in containers. Sized 2026-09-27: the CLI is plain Go, but the engine image bundles runc, CNI plugins and the Go, Python and TypeScript SDK runtimes as builtin content that upstream builds with Dagger itself. A multi-day build; not started.

    image + chartApache-2.0
  • Falcoplanned

    Runtime security and threat detection using kernel and eBPF events. Measured 2026-09-28: the official 0.45.0 tarball bundles OpenSSL 3.1.4 (end of life) and zlib 1.3.1 statically; the public Wolfi falco-no-driver apk stops at 0.44.0-r0, whose container plugin (libcontainer.so, Go) scans at 57 findings. Needs a source build of Falco, falcosecurity/libs and the container plugin against system libraries.

    image + chartApache-2.0
  • Wazuhplanned

    SIEM and XDR platform with manager, indexer, and dashboard components.

    image + chartGPL-2.0-onlyagpl
  • Kanikoexploring

    Build container images inside Kubernetes without a daemon. Held 2026-09-25: Google archived it in June 2025 (continued as osscontainertools/kaniko 1.28 and chainguard-dev/kaniko 1.25), and the executor unpacks image layers over its own root filesystem, so it must run as root, against the nonroot rule. BuildKit rootless is the likelier fit.

    image + chartApache-2.0
  • TruffleHogexploring

    Deep secret scanner across repos and filesystems.

    image + chartAGPL-3.0agpl

Stacks

7
  • ai-stackexploring

    Ollama (or vLLM) + Open WebUI + Qdrant — self-hosted LLM serving, a chat UI, and a vector DB for retrieval-augmented generation. Qdrant is built; needs Ollama/vLLM + Open WebUI images.

    image + chartApache-2.0
  • analytics-stackexploring

    Apache Superset + Trino + PostgreSQL — federated SQL analytics with self-service BI dashboards. PostgreSQL is built; needs Superset + Trino.

    image + chartApache-2.0
  • cost-stackexploring

    OpenCost + Prometheus + Grafana — Kubernetes cost monitoring and allocation dashboards; an add-on to the observability stack. Prometheus + Grafana are built; needs OpenCost.

    image + chartApache-2.0
  • mongodb-ha-stackexploring

    Operator-based HA MongoDB: MongoDB Community Operator + a metrics exporter — replica-set failover. CRD-driven. The operator is Apache-2.0, but MongoDB itself is SSPL (not OSI), so the stack inherits that caution.

    clean alt: FerretDB (Apache-2.0) on the pg-ha-stack — a MongoDB-compatible, fully-open document database over PostgreSQL.

    image + chartSSPL-1.0caution
  • orchestration-stackexploring

    Apache Airflow + PostgreSQL + Valkey — data-pipeline scheduling (Airflow needs a metadata DB and a broker). PostgreSQL + Valkey are built; needs Airflow.

    image + chartApache-2.0
  • runtime-security-stackexploring

    Falco + Tetragon — eBPF-based runtime threat detection and enforcement. Privileged host/kernel access by design (like node-exporter). Needs those images.

    image + chartApache-2.0
  • search-stackexploring

    Umbrella: OpenSearch + OpenSearch Dashboards — search with a UI. Held 2026-10-07: chart built and gated (OpenSearch document found through Dashboards), but it bundles the opensearch-dashboards image, which is held (see that entry).

    image + chartApache-2.0

Gateways & proxies

4
  • Apache ShenYuplanned

    Java API gateway. shenyu-bootstrap + shenyu-admin; admin needs a database.

    image + chartApache-2.0
  • Gravitee APIMplanned

    Java + Angular, 3 components (gateway, management-api, management-ui), needs MongoDB or JDBC plus Elasticsearch. Heaviest gateway in the wave.

    image + chartApache-2.0
  • Higressplanned

    Alibaba's Istio+Envoy-based gateway. Two components (higress-core, higress-console) and it inherits Istio/Envoy build weight.

    image + chartApache-2.0
  • Skipperplanned

    Zalando's HTTP router. BLOCKING: GitHub reports NOASSERTION and the LICENSE fetch came back empty -- resolve the license before writing a recipe.

    image + chartUNVERIFIEDcaution
blocked

Why some apps are held

QuenchWorks ships nothing that carries a fixable CVE. A few apps build cleanly but can't reach that bar yet: the app itself pins a dependency below the version that fixes a known CVE, so patching it would break the app's own declared constraints. Those are marked blocked: built and tested, held (not shipped) until upstream relaxes the pin or backports the fix. They go live the moment that lands. Nothing already in the catalog carries a known fixable CVE to get there faster.

Held in the image factory (7)

Each hold, as written in its recipe, with the date it was last re-measured.

  • cockroachdbmeasured
    STATUS 2026-10-11 (later): FROM-SOURCE BUILD MEASURED, NOT FEASIBLE; stays BLOCKED.
      User approved a source build on Go >= 1.26.9. Measured via the GitHub API, no clone:
      1) No plain `go build`: generated code is not committed (v26.2.7 pkg/roachpb has 0
         *.pb.go, pkg/sql/opt/memo no *.og.go); only `./dev generate` (Bazel 7.6.0 fork) makes it.
      2) Bazel builds with `--define gotags=bazel,gss`, and the bazel tag needs the
         cockroachdb/go runtime fork (pkg/util/grunning/enabled.go calls
         runtime.Grunningnanos; the fork carries 20 runtime patches: grunningnanos,
         PropagateCancel, CurrentP, Yield, SetGCAssistEnabled, NumRunnableGoroutines, ...).
         Wolfi go-1.26 lacks them. The fork's newest branch is cockroach-go1.26.6; there is
         no 1.26.9 fork, so we would have to rebase and maintain 20 runtime patches ourselves.
      3) Only 26.2.x source is public: no v26.3.x tag and no release-26.3 branch on GitHub
         (master pins go 1.26.2). v26.2.7 targets the go1.25.13 fork API.
      4) Upstream builds on self-hosted big/huge runners with prebuilt cross toolchains
         that run on x86_64 hosts only; not a 4 vCPU / 14 GB-disk native arm64 runner.
      Also checked: 26.3.2 (published, sha256 amd64 1b618025..., arm64 0d529bc2...) is still
      built with go1.26.6 on both arches. No CI round was spent.
      Unblock: a release whose `go version` reports >= go1.26.9 (or 1.27.2), or a
      cockroachdb/go fork branch on >= 1.26.9 plus public source for that line.
    STATUS 2026-10-11: BLOCKED (BLOCKED=0 -> 1), upstream-gated on the Go toolchain.
      The 26.2.7 gate fails on stdlib in usr/bin/cockroach: upstream built it with go1.25.13,
      and CVE-2026-78667 (HIGH) and its siblings are fixed only in Go 1.26.9 / 1.27.2; the
      go1.25 line gets no fix. The newest release, 26.3.1, was checked the same day
      (`go version` on the binary from binaries.cockroachdb.com, tarball sha256
      92b4ca97...): go1.26.6, still below 1.26.9. No published CockroachDB binary clears
      the gate, and this recipe ships upstream's binary rather than a Bazel source build.
      Unblock when a release is built with Go >= 1.26.9 (check `go version` on its binary),
      then add it to VERSIONS with both arch sha256s.
    cockroachdb: ships upstream's OWN official per-arch self-contained binary tarball
    (sha256-verified against binaries.cockroachdb.com's published .sha256sum), hardened
    on a minimal apko base. Single version: the newest stable patch, full X.Y.Z, used
    as-is.
      __VER__     = version (rendered quoted into melange version:)
      __SHA_AMD__ = linux-amd64 tarball sha256   __SHA_ARM__ = linux-arm64 tarball sha256
  • gotenbergmeasured
    STATUS: BLOCKED 2026-09-26 on Wolfi's chromium. The only gate finding is
      chromium CVE-2026-13032 (CRITICAL, use after free in WebGL)
      installed 149.0.7827.53-r0, fixed in 149.0.7827.200-r0
    and Wolfi's live APKINDEX tops out at 149.0.7827.53-r0: the fix is not published.
    Everything else gates clean (gotenberg and pdfcpu from source, floated). Unblock
    when `chromium` >= 149.0.7827.200 is in the index: set BLOCKED=0, run the local
    gate, dispatch. Chromium ships CVE fixes often, so expect this app to wait on Wolfi
    again between releases.
    Re-measured 2026-09-30: Wolfi still tops out at chromium 149.0.7827.53-r0 on x86_64 and
    aarch64, so the fix is still unpublished.
    Re-measured 2026-10-01: unchanged, chromium 149.0.7827.53-r0 on both arches.
    Re-measured 2026-10-04: unchanged, chromium 149.0.7827.53-r0 on both arches, no other
    chromium package; gotenberg is still 8.37.0.
    Re-measured 2026-10-05: unchanged, chromium 149.0.7827.53-r0 on both arches.
    Re-measured 2026-10-07: unchanged, chromium 149.0.7827.53-r0 on both arches; gotenberg 8.37.0.
  • jellyfinmeasured
    STATUS: BLOCKED 2026-09-29 on SkiaSharp's prebuilt native library. Everything gates
    clean (0 fixable CVEs, and the boot test passes: health, version 12.1.0, first-run
    wizard, login, ffmpeg), but /usr/lib/jellyfin/libSkiaSharp.so is a 10 MB binary from
    the SkiaSharp NuGet package, built on Debian 10 with clang 13, that statically links
    its own image libraries. It embeds libjpeg-turbo 2.1.5.1 (libjpeg-turbo has shipped
    security fixes since, among them CVE-2026-75466 in 3.2.1) and libpng 1.6.58, plus
    freetype, harfbuzz, webp and zlib at versions it does not print. The scanner cannot
    see any of it, and this catalog does not ship code that hides from its own gate
    (the same class as the wheel-bundled OpenSSL found on 2026-09-28). Unblock by
    building Skia against the system libraries, or by an upstream Jellyfin that does.
    Wolfi's jellyfin apk carries the same NuGet blob.
    RE-MEASURED 2026-09-30: unchanged. Wolfi has no Skia package and jellyfin is still
    12.1-r0; upstream's latest is v12.1.
    RE-MEASURED 2026-10-01: unchanged (no Skia apk, jellyfin 12.1-r0, upstream v12.1).
    RE-MEASURED 2026-10-04: unchanged (no Skia apk, jellyfin 12.1-r0, upstream v12.1).
    RE-MEASURED 2026-10-05: unchanged (no Skia apk, jellyfin 12.1-r0 on both arches).
    RE-MEASURED 2026-10-07: jellyfin 12.2 is out (Wolfi 12.2-r0, upstream v12.2) and its apk
    still ships the same libSkiaSharp.so (libjpeg-turbo 2.1.5.1, libpng 1.6.58); no Skia apk.
    jellyfin: Jellyfin (GPL-2.0), the self-hosted media server, from Wolfi's pinned jellyfin
    and jellyfin-web apks (FROM_SOURCE=0), which build it from source on Wolfi's .NET runtime
    and system ffmpeg. Upstream ships the same version (12.1, 2026-09-15); the checker
    tracks Wolfi. NEWEST LINE ONLY: Wolfi's index still lists 10.11.x revisions, and 12.x
    is the line upstream maintains.
  • n8nmeasured
    STATUS 2026-10-11: cooldown part RESOLVED. By user decision the npm install exempts
      @modelcontextprotocol/sdk (1.31.0) and handlebars (4.7.10) from npm 12's 14-day release-age
      cooldown (per-package --min-release-age-exclude on that one command; see melange.yaml).
      @langchain/mongodb 1.3.1 and @langchain/redis 1.1.3 are past the cooldown on their own.
    What still holds n8n is simple-git, below. MEASURED run 38148220690 (2026-10-11, both arches):
      the install and the build passed; the gate found exactly 4 and nothing else:
      simple-git 3.36.0 CVE-2026-102826 HIGH (fix 4.0.0), CVE-2026-102827 HIGH, CVE-2026-102828
      CRITICAL (fix 4.0.1); @simple-git/argv-parser 1.1.1 CVE-2026-102829 CRITICAL (fix 2.0.1).
    simple-git 3.36.0 + @simple-git/argv-parser 1.1.1 (CVE-2026-102826..102829, 2 CRITICAL) are
    fixed only in simple-git 4, and n8n 2.40.7 through 2.43.3 all still ship 3.36.0. v4 is not a
    drop-in for n8n's compiled code: (1) the default export is gone, and Git.node.js calls
    `(0, simple_git_1.default)(...)` through __importDefault; (2) v4's environment guard throws
    on GIT_* variables passed via .env() unless listed in allowEnvironment, and both the Git node
    (GIT_TERMINAL_PROMPT, GIT_ALLOW_PROTOCOL) and source control (GIT_TERMINAL_PROMPT,
    GIT_SSH_COMMAND) pass them. The boot test exercises neither path. Unblock: n8n upstream on
    simple-git 4, or patch both files (named simpleGit + allowEnvironment) AND add a test that
    runs a Git node clone; then set BLOCKED=0 and dispatch.
  • opensearch-dashboardsmeasured
    STATUS 2026-10-07: BLOCKED. The node_modules swaps below clear the scanner but not the
    code that runs: the browser bundles under */target/public are compiled at upstream's
    build and still carry dompurify 3.4.11/3.4.12 (8 bundles: data, discover, explore, chat,
    vis_type_table, agent_traces, reportsDashboards, investigationDashboards) and maplibre-gl
    5.2.0 (CVE-2026-85061, CRITICAL; customImportMapDashboards, observabilityDashboards,
    anomalyDetectionDashboards). Trivy reads package.json only, so the image scanned 0 while
    shipping that code. The 2026-09-26 roadmap measurement had already said so. Unblock: a
    from-source build of OSD 3.8.0 and its plugins (yarn build with the fixed versions
    resolved, bundles rebuilt), or an upstream release whose bundles carry the fixes. Check:
    grep the built image's target/public bundles for each library's version string.
    Upstream main (2026-10-07): core dompurify ^3.4.13 (yarn.lock 3.4.13, still below the 3.4.16
    LOW fix), dashboards-maps maplibre-gl 6.4.1. Dashboards 3.9.0 is unreleased (OpenSearch 3.9.0
    shipped 2026-09-29), so its release is the first upstream build to re-measure.
    Re-measured 2026-10-11 on the 3.9.0 dist (artifacts.opensearch.org, linux-x64, streamed
    and grepped in memory): dompurify 3.4.13 in the same 8 bundles (below the 3.4.16 fix) and
    maplibre-gl 4.5.2 in anomalyDetectionDashboards + observabilityDashboards (fix only in 6.x).
    3.9.0 does not unblock. Also open since 2026-10-05: core node_modules/handlebars 4.7.9
    (CVE-2026-106444/106445/106446, fixed 4.7.10), a plain swap once the bundles are fixed.
  • pulsarmeasured
    STATUS: BLOCKED 2026-10-11 on async-http-client. The gate finds
      org.asynchttpclient:async-http-client 2.16.1, CVE-2026-107226/-107227/-107228/-107230
      (two HIGH), fixed only in 3.0.14; the 2.x line has no fix (2.16.1 is its newest).
    Pulsar 4.2.4 and 4.2.5 both ship AHC 2.16.1. A jar swap cannot work: Pulsar moved to
    AHC 3 in apache/pulsar 140e1398ad with source changes in 6 classes (AsyncHttpConnector,
    HttpClient, FlowBase, the OIDC provider, ...), and AHC 3.0.14 builds on netty 4.2 while
    4.2.x ships netty 4.1. The lz4-java 1.11.4 swap is already in melange.yaml but cannot
    publish while the gate fails. Unblock: add the Pulsar 5.0.0 line (AHC 3.0.14, netty
    4.2.18; gradle build), or a 4.2.x release on AHC 3. Then set BLOCKED=0 and dispatch.
  • sparkmeasured
    STATUS: BLOCKED 2026-09-24. Measured locally (PUSH=0, x86_64, comprehensive Trivy):
      4.1.2-r3: 92 OS-section + 233 jar findings; 4.0.2-r13: 78 + 221.
    The Wolfi apks are built from source but still ship, per 4.1.2:
      * Hive 2.3.10 jars: hive-exec (fixed only in 4.0.1), derby 10.16.1.1 (CRITICAL,
        CVE-2022-46337), libthrift 0.16.0. Spark's built-in Hive has no fixed 2.3 line;
        the fix is building WITHOUT -Phive -Phive-thriftserver.
      * spark-4.1.2-yarn-shuffle.jar (43 findings, shaded): YARN NodeManager only; build
        WITHOUT -Pyarn.
      * Jetty 11.0.26 shaded into spark-core (CVE-2026-2332, fixed 11.0.29) and
        hadoop-client-runtime 3.4.2 (shaded): need -Djetty.version / a Hadoop bump at
        build time.
      * spark-connect-client-jvm (20, shaded), netty 4.2.13 (fix 4.2.16), jackson 2.21.1
        (fix 2.21.5), log4j-api 2.25.4, lz4-java 1.10.1, jline 3.29.0, nimbus-jose-jwt.
    RE-MEASURED 2026-09-30: unchanged. Wolfi still ships only 4.0.2-r13 and 4.1.2-r3; upstream
    now has 4.1.3 and 4.2.0. The Maven build runs far past the 600 s local gate, so the
    from-source recipe is gated in CI, not locally.
    RE-MEASURED 2026-10-01: unchanged (Wolfi spark-4.1 tops at 4.1.2-r3, no spark-4.2).
    RE-MEASURED 2026-10-04: unchanged (Wolfi spark-4.0 4.0.2-r13, spark-4.1 4.1.2-r3, no spark-4.2;
    upstream 4.1.3 and 4.2.0). The from-source Maven build below is still the way out.
    RE-MEASURED 2026-10-05: unchanged (4.0.2-r13, 4.1.2-r3, no spark-4.2, both arches).
    RE-MEASURED 2026-10-07: unchanged (4.0.2-r13, 4.1.2-r3, no spark-4.2, both arches); upstream
    has 4.2.1-rc1 and 4.3.0-rc1 tagged.
    Next step: a melange from-source Maven build (make-distribution.sh) with those
    profiles dropped and the versions floated, gated per line. This apko recipe stays
    as the image contract (entrypoint, SPARK_HOME, work-dir) the source build reuses.

Want something prioritized? Request an app and we will slot it into the roadmap.

blocked

Tested and held: cannot reach 0 fixable CVEs