Vulnerability Reportbuildkite/agent:3.128-sidecar

buildkite/agent:3.128-sidecar
digestsha256:1045457693ee8ff2435ae1565dfb005aba7e866c536ae3b9d41527666f0d1e3c

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The image contains a few low-severity vulnerabilities (exposed max 3.6, post-exploit max 2.7), but none pose a significant practical risk due to their low impact and the image's strong trust credentials. No mitigations or configuration changes are necessary.

Vulnerabilities

Vulnerability Log

6 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42505LOW3.6
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-50274LOW2.7
github.com/DataDog/dd-trace-go/v2
v2.7.1
fixed in 2.8.1
Post-Exploit
CVE-2026-39822LOW2.39
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-Exploit
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.38.0
fixed in 0.39.0
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.81.1
fixed in 1.82.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.