Goliash
Default
Live demo with three weeks of example data: read-only, and the data starts over regularly. Run your own: docker run --rm -p 8080:8080 ghcr.io/pipozzz/goliash try · Get started · Star on GitHub

Security posture

How long prod runs behind available releases, what is past its end of life, and where Goliash cannot see. Counted from when the first newer release came out; for risk registers and audits.

Export CSV
175 days Median exposure 90th percentile 841 days, in prod
14 Behind for 30+ days 12 of them 90+ days
7 Past end of life 0 more within 60 days
0 Accepted risk acknowledged in Goliash, with who and until when
1 Blind spots stale targets, targets without digests, services without a known upstream

Exposure in every environment

Only prod
ServiceRunningFixExposedWhy
redis
prod
7.2.4 8.10.2873 days
since 2024-05-19
major
keycloak
prod
24.0.5 26.8.0841 days
since 2024-06-20
end of life 2024-06-10 major
rabbitmq
prod
3.12.14 4.3.6807 days
since 2024-07-23
end of life 2024-02-21 major
fluent-bit
prod
3.0.7 5.1.3806 days
since 2024-07-25
end of life 2024-10-08 major
vault
prod
1.17.2 2.1.2730 days
since 2024-10-09
end of life 2024-10-09 major
nginx
prod
1.26.1 1.31.6710 days
since 2024-10-29
end of life 2025-04-23 minor
gitea
prod
1.22.1 28.1.0597 days
since 2025-02-19
major
traefik
prod
v3.1.2 3.7.14211 days
since 2026-03-12
end of life 2024-10-28 minor
grafana
prod
11.2.0 13.2.3175 days
since 2026-04-17
end of life 2025-05-27 major
postgres
webshop
prod
15.5 15.8138 days
since 2026-05-24
minor
postgres
identity
prod
15.6 15.8113 days
since 2026-06-18
minor
image-resizer
prod
3.9 3.1494 days
since 2026-07-07
minor
payments-api
prod
1.4.2
on demo-prod-us
1.7.082 days
since 2026-07-19
minor
orders-api
prod
3.9.0 3.11.031 days
since 2026-09-08
minor
invoice-pdf
prod
20 246 days
since 2026-10-03
major
checkout
prod
2.3.1 2.4.04 days
since 2026-10-05
minor
redis
staging
7.2.5 8.10.2802 days
since 2024-07-29
major
redis
dev
7.2.5 8.10.2802 days
since 2024-07-29
major
keycloak
staging
25.0.1 26.8.0749 days
since 2024-09-19
end of life 2024-10-04 major
rabbitmq
staging
3.13.6 4.3.6748 days
since 2024-09-21
end of life 2024-09-17 major
keycloak
dev
25.0.6 26.8.0735 days
since 2024-10-04
end of life 2024-10-04 major
rabbitmq
dev
4.0.2 4.3.6710 days
since 2024-10-28
end of life 2025-04-15 minor
search
staging
8.15.0 9.5.5294 days
since 2025-12-19
major
search
dev
8.15.0 9.5.5294 days
since 2025-12-19
major
traefik
staging
v3.1.2 3.7.14211 days
since 2026-03-12
end of life 2024-10-28 minor
grafana
staging
11.2.0 13.2.3175 days
since 2026-04-17
end of life 2025-05-27 major
postgres
identity
staging
15.7 15.888 days
since 2026-07-13
minor
postgres
webshop
staging
15.7 15.888 days
since 2026-07-13
minor
postgres
identity
dev
15.7 15.888 days
since 2026-07-13
minor
postgres
webshop
dev
15.7 15.888 days
since 2026-07-13
minor
payments-api
staging
1.6.0 1.7.010 days
since 2026-09-29
minor
payments-api
dev
1.6.0 1.7.010 days
since 2026-09-29
minor
orders-api
staging
3.10.0 3.11.08 days
since 2026-10-01
minor
orders-api
dev
3.10.0 3.11.08 days
since 2026-10-01
minor

Built on an unsupported base

rebuild on a newer base image
ServiceBase imageEnd of life
checkoutnode:18-alpineended 2025-04-30
invoice-pdfpython:3.9-slimended 2025-10-31
orders-apigolang:1.22-alpineended 2025-02-11

Supply-chain evidence

images running in prod: what their registry holds beside them
33% Signed 6 of 18 checked: cosign, Sigstore or Notation
67% With an SBOM 12 of 18: SPDX or CycloneDX attestation
67% With provenance 12 of 18: SLSA, from the build
3 Not checked private registries or no digest known

Goliash records that signatures and attestations exist; it does not verify who signed them.

12 unsigned images
ImageFound
gitea/gitea:1.22.1nothing
grafana/grafana:11.2.0nothing
istio/proxyv2:1.23.2nothing
nginx:1.26.1buildkit sbom, buildkit provenance
postgres:15.5buildkit sbom, buildkit provenance
postgres:15.6buildkit sbom, buildkit provenance
public.ecr.aws/lambda/nodejs:20nothing
public.ecr.aws/lambda/python:3.9nothing
quay.io/keycloak/keycloak:24.0.5nothing
rabbitmq:3.12.14buildkit sbom, buildkit provenance
redis:7.2.4buildkit sbom, buildkit provenance
traefik:v3.1.2buildkit sbom, buildkit provenance

Supply chain

what runs, as images
Moving tags
latest, stable: the version cannot be known
0
Tags pushed again
one tag running as different images
0
Untrusted registries
outside GOLIASH_ALLOWED_REGISTRIES
0
Digest unknown
a tag pushed again would go unnoticed
3

Blind spots

where the numbers above may be incomplete

Every target reported recently.

The newest release is known for every service in prod.

1 target report no image digests, so a tag pushed again would go unnoticed there; see why.