Vulnerability Reportprom/prometheus:v3.13.2

prom/prometheus:v3.13.2prom/prometheus:v3.13.2-busybox
digestsha256:508729e0e2d18e11fd742a5a5ca70e557b940a93948c3c95fd0123a6fd538b69

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. The sole exposed finding has a severity score of 0.0, presenting no practical risk to the Prometheus service. No post-exploit vulnerabilities are reported. The image's high community trust and immutable digest further support its safe deployment.

Vulnerabilities

Vulnerability Log

1 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
GO-2026-5932NONE0
golang.org/x/crypto
v0.53.0
No fix yet
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.