github.com/argoproj/argo-workflows

govv0.4.7

Workflow Engine for Kubernetes

License Apache-2.0permissive120 versions1017 maintainers0 deps16,642 weekly dl
argoproj/argo-workflows
46
/ 100
Health
update required

github.com/argoproj/[email protected] has vulnerabilities — update to latest

Update to >= 4.0.2 to fix known vulnerabilities

  • 3 high severity vulnerabilities
Health breakdown0 – 100
0/25
maintenance
10/20
popularity
8/25
security
15/15
maturity
13/15
community
Vulnerabilities
6
3 high1 medium2 low
Advisories (6)
SeverityIDSummaryFixed in
highBIT-argo-workflows-2026-31892Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode3.7.11
highBIT-argo-workflows-2026-23960Argo Workflows affected by stored XSS in the artifact directory listing3.7.8
mediumGHSA-rc7p-gmvh-xfx2Attack on Kubernetes via Misconfigured Argo Workflows
highBIT-argo-workflows-2025-66626 RCE via ZipSlip and symbolic links in argoproj/argo-workflows3.6.14
unknownBIT-argo-workflows-2026-28229Unauthorized access to Argo Workflows Template in github.com/argoproj/argo-workflows4.0.2
unknownBIT-argo-workflows-2026-31892Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode in github.com/argoproj/argo-workflows4.0.2

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/argoproj/argo-workflows

Last updated · 2018-06-07T18:09:38Z