This base/runtime image is a clean foundation for building production images. It has zero known vulnerabilities inherited by downstream images, eliminating the need for immediate remediation. Combined with its official status, cryptographic pinning, and massive community adoption, it provides a highly reliable and secure starting point for containerized applications. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| No vulnerabilities found matching filters. | ||||