Skip to content

Add apko lock file as nightly images attestation signed with cosign - #21

Merged
qboileau merged 1 commit into
mainfrom
lock-in-manifest
Aug 19, 2026
Merged

Add apko lock file as nightly images attestation signed with cosign#21
qboileau merged 1 commit into
mainfrom
lock-in-manifest

Conversation

@qboileau

Copy link
Copy Markdown
Member

No description provided.

@github-actions

Copy link
Copy Markdown

Container image CVE report

base-jre-25

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 9 9
Grype critical+high by component
Component Findings
busybox 1.38.0-r1 3
libcrypto3 3.6.3-r4 2
libssl3 3.6.3-r4 2
openssl 3.6.3-r4 2

base-monitoring

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 10 14
Grype critical+high by component
Component Findings
busybox 1.38.0-r1 3
libcrypto3 3.6.3-r4 2
libssl3 3.6.3-r4 2
openssl 3.6.3-r4 2
go.etcd.io/etcd/client/pkg/v3 v3.5.17 1

base-os

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 3 3
Grype critical+high by component
Component Findings
busybox 1.38.0-r1 3

debug

Scanner Critical Critical+High Total
Trivy ✅ 0 ✅ 0 0
Grype ✅ 0 ⚠️ 26 37
Grype critical+high by component
Component Findings
stdlib go1.25.12 12
busybox 1.38.0-r1 3
jline-remote-telnet 3.30.4 2
libcrypto3 3.6.3-r4 2
libssl3 3.6.3-r4 2
openssl 3.6.3-r4 2
golang.org/x/net v0.55.0 1
golang.org/x/text v0.37.0 1

Trivy counts fixed vulnerabilities only; Grype includes unfixed, so its totals run higher. Full reports are in the workflow artifacts.

@qboileau
qboileau merged commit 6c2b2f7 into main Aug 19, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants