Skip to content

Trivy: unresolved container vulnerabilities after rebuild #1356

@github-actions

Description

@github-actions

Summary

The daily Trivy periodic scan found Critical/High vulnerabilities in the latest published Docker image.
An automated rebuild was attempted but the rebuilt image still has vulnerabilities,
indicating the fix requires a manual dependency update rather than a base image refresh.

Next steps

  • Review findings in the Security tab
  • Update the affected dependencies to a version that includes the fix
  • Or add the CVE ID(s) to a .trivyignore file if the risk is accepted

Details

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions