Vulnerability Reportnode:24.18.0-alpine

node:24.18.0-alpine
digestsha256:a0b9bf06e4e6193cf7a0f58816cc935ff8c2a908f81e6f1a95432d679c54fbfd

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. It has zero known vulnerabilities inherited by downstream images, eliminating the need for immediate remediation. Combined with its official status, cryptographic pinning, and massive community adoption, it provides a highly reliable and secure starting point for containerized applications. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

0 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
No vulnerabilities found matching filters.

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.