docker.io/alpine/helm:4.2.2
Base OS: alpine 3.24.150 vulnerabilities fixed
Patched Image
ghcr.io/verity-org/alpine/helm:4.2.2
Supply Chain
Full compliance detailsSignedSLSA L3SBOMRekor
Verify this artifact
Cosign signature
cosign verify \ --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \ --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \ ghcr.io/verity-org/alpine/helm:4.2.2
Build provenance
gh attestation verify \ oci://ghcr.io/verity-org/alpine/helm:4.2.2 \ --owner verity-org
Before patching
Found 54 vulnerabilities in the original image. 50 fixed by Copa. 4 remaining after patching.
28 HIGH19 MEDIUM2 LOW5 UNKNOWN
Awaiting upstream fix
No fix is available yet for these vulnerabilities. They can be suppressed in your compliance tooling until an upstream fix is released.
- CVE-2026-50163HIGH
- Package
- oras.land/oras-go/v2
- Installed
- v2.6.1
- Fixed
- CVE-2026-50163HIGH
- Package
- oras.land/oras-go/v2
- Installed
- v2.6.1
- Fixed
- GO-2026-5932UNKNOWN
- Package
- golang.org/x/crypto
- Installed
- v0.53.0
- Fixed
- GO-2026-5932UNKNOWN
- Package
- golang.org/x/crypto
- Installed
- v0.53.0
- Fixed
| ID | Package | Installed | Fixed | Severity |
|---|---|---|---|---|
| CVE-2026-50163 | oras.land/oras-go/v2 | v2.6.1 | HIGH | |
| CVE-2026-50163 | oras.land/oras-go/v2 | v2.6.1 | HIGH | |
| GO-2026-5932 | golang.org/x/crypto | v0.53.0 | UNKNOWN | |
| GO-2026-5932 | golang.org/x/crypto | v0.53.0 | UNKNOWN |
Original image reference
docker.io/alpine/helm:4.2.2