You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Part of:#1730 — Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier)
Scope
Deployment: Hub
Severity: MEDIUM
Findings: 858 (across 20 images)
Current progress: 0% (test-based)
Basis:pnpm security:progress — all 5 targets (perl, glibc, xz-utils, node, pnpm) are container-level; not verifiable in this repo. Requires image re-scan.
Regression: no regressions (CI green).
Affected Hub images
Image
Platform
Findings (medium subset)
NestJS services v2.2.0 (x16, identical profile)
Alpine 3.23
43 packages (subset)
seed-v2.1.4-alpha.11
Alpine 3.21
69 packages (subset)
nats-2.12.4-alpine / 2.12.3 / 2.12.4
Alpine 3.22 / Scratch
subset
Total
858
Attribution (Upstream vs CREDEBL-owned)
Source
Findings (approx)
How fixed
Upstream (OS packages, transitive Node/Go deps)
~70%
P0 rebuilds + P1/P2 bumps — largely resolved as a side-effect of the CRITICAL/HIGH work.
Part of: #1730 — Security: Remediate 3,147 vulnerabilities across 26 container images (Hub + Verifier)
Scope
Current progress: 0% (test-based)
pnpm security:progress— all 5 targets (perl, glibc, xz-utils, node, pnpm) are container-level; not verifiable in this repo. Requires image re-scan.Affected Hub images
Attribution (Upstream vs CREDEBL-owned)
NOTE: exact per-finding upstream/owned counts to be finalised on the next container re-scan; package-level attribution is from #1730's P0–P4 tables.
Package checklist (from #1730 plan)
Acceptance criteria
Execution order reference
Follow #1730's execution order: P0 → P1 → P2 → P3 → re-scan. This issue is mostly "mop-up" after CRITICAL/HIGH are closed.