-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
cve-monitorAutomated CVE monitoring alertsAutomated CVE monitoring alertssecuritySecurity-related changeSecurity-related change
Description
CVE Monitor Alert
The scheduled Trivy scan found fixable CRITICAL or HIGH vulnerabilities
in the published image ghcr.io/knight-owl-dev/ci-tools:latest.
Next Steps
- Review the workflow run that triggered this alert
- Build and scan the image locally to investigate findings
- Update the base image or affected packages in
images/ci-tools/Dockerfile - Cut a new release — the publish workflow re-scans before publishing
See docs/supply-chain-security.md
for scanning policy details.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
cve-monitorAutomated CVE monitoring alertsAutomated CVE monitoring alertssecuritySecurity-related changeSecurity-related change