No image vulnerability scanning #108

Open
opened 2026-08-17 15:07:09 -04:00 by mysticalsoap · 0 comments
Owner

Digest pinning is a deliberate opt-out of silent security patches. That's the right call only if something tells you a pinned digest has since gone vulnerable, and Renovate reports "a newer version exists," not "yours is CVE'd."

Trivy or Grype on a weekly timer against the running set closes the loop this design opens.

Digest pinning is a deliberate opt-out of silent security patches. That's the right call only if something tells you a pinned digest has since gone vulnerable, and Renovate reports "a newer version exists," not "yours is CVE'd." Trivy or Grype on a weekly timer against the running set closes the loop this design opens.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/docker#108
No description provided.