Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. It contains 72 vulnerabilities, primarily denial-of-service (DoS) risks via network (e.g., CVE-2026-40355, CVE-2026-39882). Many of these require specific non-default configurations, such as enabling the NegoEx mechanism for Kerberos or controlling the OpenTelemetry collector endpoint. An attacker exploiting these could cause service unavailability or resource exhaustion. Disabling the NegoEx mechanism and ensuring the OpenTelemetry endpoint is trusted would fully mitigate the respective DoS vulnerabilities. The image originates from a reputable community source, but the volume and nature of vulnerabilities make it unsuitable for production without strong network segmentation and configuration hardening.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-40355 | MEDIUM6.38 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39882 | MEDIUM6.38 | go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.20.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39830 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-39835 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46597 | MEDIUM6.38 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-33814 | MEDIUM6.38 | golang.org/x/net v0.48.0 fixed in 0.53.0 | 0.8% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-27145 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.11, 1.26.4 | 0.9% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32280 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-32283 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.9, 1.26.2 | 0.6% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-33814 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-39836 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42499 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42504 | MEDIUM6.38 | stdlib v1.25.8 fixed in 1.25.11, 1.26.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42508 | MEDIUM6.29 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-46595 | MEDIUM6.03 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41602 | MEDIUM6 | github.com/apache/thrift v0.20.0 fixed in 0.23.0 | 1.2% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-39883 | MEDIUM5.95 | go.opentelemetry.io/otel/sdk v1.40.0 fixed in 1.43.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.9.4-3ubuntu3.2 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-39821 | MEDIUM5.58 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.35-0ubuntu3.13 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39827 | MEDIUM5.52 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39834 | MEDIUM5.52 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-25680 | MEDIUM5.52 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39825 | MEDIUM5.52 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32282 | MEDIUM5.44 | stdlib v1.25.8 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.24.0-6build1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-42502 | MEDIUM5.18 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-32289 | MEDIUM5.18 | stdlib v1.25.8 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-29181 | MEDIUM5.1 | go.opentelemetry.io/otel v1.40.0 fixed in 1.41.0 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-32281 | MEDIUM5.1 | stdlib v1.25.8 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33811 | MEDIUM5.1 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.35-0ubuntu3.13 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgcc-s1 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgfortran5 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libgomp1 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libquadmath0 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2022-27943 | MEDIUM4.67 | libstdc++6 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-39833 | MEDIUM4.67 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-32288 | MEDIUM4.67 | stdlib v1.25.8 fixed in 1.25.9, 1.26.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-58055 | MEDIUM4.59 | libnghttp2-14 1.43.0-1ubuntu0.3 fixed in 1.43.0-1ubuntu0.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42506 | MEDIUM4.59 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-39823 | MEDIUM4.59 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-39826 | MEDIUM4.59 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.35-0ubuntu3.13 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-46598 | MEDIUM4.5 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42505 | MEDIUM4.5 | stdlib v1.25.8 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42507 | MEDIUM4.5 | stdlib v1.25.8 fixed in 1.25.11, 1.26.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libgssapi-krb5-2 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libk5crypto3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5-3 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5support0 1.19.2-2ubuntu0.7 fixed in 1.19.2-2ubuntu0.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-9547 | LOW3.77 | libcurl4 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | curl 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-6238 | LOW3.31 | libc-bin 2.35-0ubuntu3.13 No fix yet | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl4 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-5435 | LOW3.01 | libc-bin 2.35-0ubuntu3.13 No fix yet | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-base 5.34.0-3ubuntu1.5 fixed in 5.34.0-3ubuntu1.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | curl 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | libcurl4 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-45582 | LOW2.86 | tar 1.34+dfsg-1ubuntu0.1.22.04.2 fixed in 1.34+dfsg-1ubuntu0.1.22.04.4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.34+dfsg-1ubuntu0.1.22.04.2 fixed in 1.34+dfsg-1ubuntu0.1.22.04.6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 249.11-0ubuntu3.21 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 249.11-0ubuntu3.21 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42496 | LOW2.78 | perl-base 5.34.0-3ubuntu1.5 fixed in 5.34.0-3ubuntu1.7 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2022-4899 | LOW2.7 | libzstd1 1.4.8+dfsg-3build1 No fix yet | 1.6% Low-Moderate Risk | Post-Exploit |
| CVE-2026-4046 | LOW2.7 | libc-bin 2.35-0ubuntu3.13 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39828 | LOW2.69 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-39832 | LOW2.66 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | curl 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl4 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-39831 | LOW2.48 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-25681 | LOW2.48 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27136 | LOW2.48 | golang.org/x/net v0.48.0 fixed in 0.55.0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.10-4ubuntu4.1 fixed in 1.10-4ubuntu4.2 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.37.2-4ubuntu3.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-39822 | LOW2.39 | stdlib v1.25.8 fixed in 1.25.12, 1.26.5, 1.27.0-rc.2 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW2.29 | curl 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW2.29 | gzip 1.10-4ubuntu4.1 fixed in 1.10-4ubuntu4.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW2.29 | libcurl4 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2022-41409 | LOW2.29 | libpcre2-8-0 10.39-3ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-39829 | LOW2.29 | golang.org/x/crypto v0.46.0 fixed in 0.52.0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-39820 | LOW2.29 | stdlib v1.25.8 fixed in 1.25.10, 1.26.3 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW2.26 | curl 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | login 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2023-29383 | LOW1.68 | passwd 1:4.8.1-2ubuntu2.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | NONE0 | libncurses6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libncursesw6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | libtinfo6 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-base 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-69720 | NONE0 | ncurses-bin 6.3-2ubuntu0.1 fixed in 6.3-2ubuntu0.2 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncurses6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libncursesw6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | libtinfo6 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-base 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2023-50495 | NONE0 | ncurses-bin 6.3-2ubuntu0.1 No fix yet | 1.0% Theoretical Threat | Not Applicable |
| CVE-2022-27943 | NONE0 | gcc-12-base 12.3.0-1ubuntu1~22.04.3 No fix yet | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-modules-bin 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam-runtime 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-54411 | NONE0 | libpam0g 1.4.0-11ubuntu2.6 fixed in 1.4.0-11ubuntu2.7 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-8458 | NONE0 | curl 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-8458 | NONE0 | libcurl4 7.81.0-1ubuntu1.24 fixed in 7.81.0-1ubuntu1.25 | 0.5% Theoretical Threat | Not Applicable |
| GHSA-xmrv-pmrh-hhx2 | NONE0 | github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.6.7 fixed in 1.7.8 | — | Not Applicable |
| GHSA-xmrv-pmrh-hhx2 | NONE0 | github.com/aws/aws-sdk-go-v2/service/bedrockruntime v1.23.0 fixed in 1.50.4 | — | Not Applicable |
| CVE-2026-2303 | NONE0 | go.mongodb.org/mongo-driver v1.13.1 fixed in 1.17.7 | 0.2% Theoretical Threat | Not Applicable |
| GO-2026-5932 | NONE0 | golang.org/x/crypto v0.46.0 No fix yet | — | Not Applicable |
| CVE-2026-46600 | NONE0 | golang.org/x/net v0.48.0 fixed in 0.56.0 | — | Not Applicable |
| CVE-2026-39824 | NONE0 | golang.org/x/sys v0.40.0 fixed in 0.44.0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56852 | NONE0 | golang.org/x/text v0.32.0 fixed in 0.39.0 | — | Not Applicable |
| GHSA-hrxh-6v49-42gf | NONE0 | google.golang.org/grpc v1.79.3 fixed in 1.82.1 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.