docs: how to check a Renovate candidate against an image-scan finding #389
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!389
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/image-scan-candidate-check"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
The image-scan paragraph says a finding is closed by a newer digest and to check Renovate, but an open PR can still carry the finding (Lidarr #357 does: same ASP.NET runtime), and there was no written way to get the CVE list behind a count.
Fix
One sentence: scan the candidate with trivy in dagu-scanner before merging, and scan a running image by id for the CVE list.
Verification
Docs only; both commands are what produced the 2026-10-07 triage (three candidates clean, Lidarr not).
🤖 Generated with Claude Code