Vulnerability Reportnode:26-alpine3.23

node:current-alpine3.23
digestsha256:c3c6e314fd42e41962360b2482fc18d150beb47976c3aa7b8b9689d7ef42a5c2

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This base/runtime image is a clean foundation for building production images. Vulnerability scanning reports no exposed or post-exploit findings in this image, so downstream images inherit no known vulnerable packages from it. It is the Docker Official Node.js image, pinned by immutable digest, which gives predictable and reproducible builds. Continue your normal practice of scanning the final image after adding your own dependencies, since anything you layer on top is outside this base image's clean status. Note: this is a general-purpose base/runtime image — many findings live in components that an application built on top may never load, so actual exploitability depends on the final image. For an accurate risk picture, re-scan the final application image with context.

Vulnerabilities

Vulnerability Log

0 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
No vulnerabilities found matching filters.

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.