Last scanned:
This image is safe for production use. The provided vulnerability data lists zero exposed and zero post-exploit findings, so there are no CVE IDs to reference and no attacker consequences to describe for this build. Trust signals are favorable: the publisher dxflrs is a popular community image with about 6.9M pulls and the container is pinned by digest, so the exact artifact cannot be silently swapped. The main caveats are operational rather than exploitable — the image is neither official nor verified, and Garage is an S3-compatible storage service, so you should still restrict network exposure and protect credentials and data volumes at the deployment layer.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| No vulnerabilities found matching filters. | ||||
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.