Skip to content

Weekly audit refresh: 34089089538 - #63

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh
Open

Weekly audit refresh: 34089089538#63
github-actions[bot] wants to merge 1 commit into
mainfrom
chore/weekly-audit-refresh

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

CVE delta

Net change

Severity Added Removed Net
Critical 13 0 +13
High 257 5 +252
Medium 869 30 +839
Low 116 1 +115

Changed images: 38 of 44

Per-image detail

adguard-adguardhome-v0.107.76

  • Added: C:1 H:0 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto

baserow-baserow-2.2.2

  • Added: C:1 H:7 M:18 L:3
  • Removed: C:0 H:0 M:8 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-76642 (HIGH) — bsdutils
      • CVE-2026-78408 (HIGH) — bsdutils
      • CVE-2026-78409 (HIGH) — bsdutils
      • CVE-2026-78410 (HIGH) — bsdutils
      • CVE-2026-81934 (HIGH) — redis
      • CVE-2026-82397 (HIGH) — tornado
      • CVE-2026-84304 (HIGH) — google.golang.org/grpc
      • ...and 21 more
    • [FIXED]:
      • CVE-2026-69248 (MEDIUM) — cryptography
      • GHSA-42h9-826w-cgv3 (MEDIUM) — axios
      • GHSA-7q8q-rj6j-mhjq (MEDIUM) — axios
      • GHSA-f4gw-2p7v-4548 (MEDIUM) — axios
      • GHSA-jqh4-m9w3-8hp9 (MEDIUM) — axios
      • GHSA-mmx7-hfxf-jppx (MEDIUM) — axios
      • GHSA-mwf2-3pr3-8698 (MEDIUM) — axios
      • GHSA-pmv8-rq9r-6j72 (MEDIUM) — axios

deluan-navidrome-0.61.2

  • Added: C:1 H:1 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-46603 (HIGH) — golang.org/x/image

docker.io-caddy-2.11.3

  • Added: C:1 H:9 M:10 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-8286 (HIGH) — curl
      • CVE-2026-84304 (HIGH) — google.golang.org/grpc
      • CVE-2026-8458 (HIGH) — curl
      • CVE-2026-8925 (HIGH) — curl
      • ...and 12 more

docker.io-library-postgres-18.4-alpine3.23

  • Added: C:0 H:14 M:10 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — libcurl
      • CVE-2026-11586 (HIGH) — libcurl
      • CVE-2026-12064 (HIGH) — libcurl
      • CVE-2026-53612 (HIGH) — libuuid
      • CVE-2026-53613 (HIGH) — libuuid
      • CVE-2026-53614 (HIGH) — libuuid
      • CVE-2026-76642 (HIGH) — libuuid
      • CVE-2026-78408 (HIGH) — libuuid
      • ...and 16 more

docker.io-louislam-uptime-kuma-2.3.2

  • Added: C:1 H:20 M:32 L:7
  • Removed: C:0 H:2 M:6 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-19154 (HIGH) — chromium
      • CVE-2026-19161 (HIGH) — chromium
      • CVE-2026-19176 (HIGH) — chromium
      • CVE-2026-67320 (HIGH) — axios
      • CVE-2026-76018 (HIGH) — chromium
      • CVE-2026-76020 (HIGH) — chromium
      • CVE-2026-76021 (HIGH) — chromium
      • ...and 52 more
    • [FIXED]:
      • GHSA-gcfj-64vw-6mp9 (HIGH) — axios
      • GHSA-p6gq-j5cr-w38f (HIGH) — nodemailer
      • CVE-2026-76956 (MEDIUM) — libexpat1
      • GHSA-42h9-826w-cgv3 (MEDIUM) — axios
      • GHSA-7q8q-rj6j-mhjq (MEDIUM) — axios
      • GHSA-f4gw-2p7v-4548 (MEDIUM) — axios
      • GHSA-mmx7-hfxf-jppx (MEDIUM) — axios
      • GHSA-pmv8-rq9r-6j72 (MEDIUM) — axios

docker.io-mariadb-12.2.2

  • Added: C:0 H:0 M:7 L:4
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13595 (MEDIUM) — bsdutils
      • CVE-2026-18374 (MEDIUM) — libc-bin
      • CVE-2026-39113 (MEDIUM) — libsqlite3-0
      • CVE-2026-53612 (MEDIUM) — bsdutils
      • CVE-2026-53613 (MEDIUM) — bsdutils
      • CVE-2026-53614 (MEDIUM) — bsdutils
      • CVE-2026-53615 (MEDIUM) — bsdutils
      • CVE-2025-5278 (LOW) — coreutils
      • ...and 3 more

docker.io-mongo-8.3.2

  • Added: C:1 H:0 M:12 L:4
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-13595 (MEDIUM) — bsdutils
      • CVE-2026-18374 (MEDIUM) — libc-bin
      • CVE-2026-53612 (MEDIUM) — bsdutils
      • CVE-2026-53613 (MEDIUM) — bsdutils
      • CVE-2026-53614 (MEDIUM) — bsdutils
      • CVE-2026-53615 (MEDIUM) — bsdutils
      • CVE-2026-59843 (MEDIUM) — libssh-4
      • ...and 9 more

docker.io-redis-8.6.3-alpine

  • Added: C:0 H:6 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-53612 (HIGH) — setpriv
      • CVE-2026-53613 (HIGH) — setpriv
      • CVE-2026-53614 (HIGH) — setpriv
      • CVE-2026-76642 (HIGH) — setpriv
      • CVE-2026-78408 (HIGH) — setpriv
      • CVE-2026-78410 (HIGH) — setpriv

docuseal-docuseal-3.0.0

  • Added: C:0 H:16 M:16 L:0
  • Removed: C:0 H:0 M:1 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — libcurl
      • CVE-2026-11586 (HIGH) — libcurl
      • CVE-2026-12064 (HIGH) — libcurl
      • CVE-2026-53612 (HIGH) — libblkid
      • CVE-2026-53613 (HIGH) — libblkid
      • CVE-2026-53614 (HIGH) — libblkid
      • CVE-2026-76642 (HIGH) — libblkid
      • CVE-2026-78408 (HIGH) — libblkid
      • ...and 24 more
    • [FIXED]:
      • GHSA-mvxr-6m87-mv2q (MEDIUM) — mail

fnsys-dockhand-v1.0.29

  • Added: C:0 H:2 M:0 L:1
  • Removed: C:0 H:1 M:0 L:0
    • [NEW]:
      • CVE-2026-82659 (HIGH) — nodemailer
      • CVE-2026-84304 (HIGH) — docker-cli-buildx
      • CVE-2026-54876 (LOW) — libcrypto3
    • [FIXED]:
      • GHSA-p6gq-j5cr-w38f (HIGH) — nodemailer

freshrss-freshrss-1.29.1-alpine

  • Added: C:0 H:14 M:14 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — libcurl
      • CVE-2026-11586 (HIGH) — libcurl
      • CVE-2026-12064 (HIGH) — libcurl
      • CVE-2026-53612 (HIGH) — libuuid
      • CVE-2026-53613 (HIGH) — libuuid
      • CVE-2026-53614 (HIGH) — libuuid
      • CVE-2026-76642 (HIGH) — libuuid
      • CVE-2026-78408 (HIGH) — libuuid
      • ...and 20 more

ghcr.io-goauthentik-server-2026.2.3

  • Added: C:0 H:20 M:142 L:27
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-74743 (HIGH) — linux-libc-dev
      • CVE-2026-74744 (HIGH) — linux-libc-dev
      • CVE-2026-74746 (HIGH) — linux-libc-dev
      • CVE-2026-74752 (HIGH) — linux-libc-dev
      • CVE-2026-76642 (HIGH) — bsdutils
      • CVE-2026-78408 (HIGH) — bsdutils
      • CVE-2026-78409 (HIGH) — bsdutils
      • CVE-2026-78410 (HIGH) — bsdutils
      • ...and 181 more

ghcr.io-open-webui-open-webui-0.9.5

  • Added: C:2 H:24 M:140 L:18
  • Removed: C:0 H:0 M:2 L:1
    • [NEW]:
      • CVE-2026-71428 (CRITICAL) — unstructured
      • CVE-2026-79675 (CRITICAL) — nltk
      • CVE-2026-38349 (HIGH) — ffmpeg
      • CVE-2026-62388 (HIGH) — nltk
      • CVE-2026-72818 (HIGH) — nltk
      • CVE-2026-74743 (HIGH) — linux-libc-dev
      • CVE-2026-74744 (HIGH) — linux-libc-dev
      • CVE-2026-74746 (HIGH) — linux-libc-dev
      • ...and 176 more
    • [FIXED]:
      • CVE-2026-76956 (MEDIUM) — libexpat1
      • GHSA-rf74-v2fm-23pw (MEDIUM) — nltk
      • CVE-2026-19582 (LOW) — binutils

ghcr.io-stoatchat-api-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-crond-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-events-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-file-server-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-for-web-0b94704

  • Added: C:0 H:0 M:0 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-9358 (LOW) — postcss-selector-parser

ghcr.io-stoatchat-gifbox-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-livekit-server-v1.9.13

  • Added: C:1 H:1 M:0 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-84304 (HIGH) — google.golang.org/grpc

ghcr.io-stoatchat-proxy-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-pushd-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-stoatchat-voice-ingress-v0.13.6

  • Added: C:0 H:0 M:2 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-18374 (MEDIUM) — libc6
      • CVE-2026-80489 (MEDIUM) — libc6

ghcr.io-wg-easy-wg-easy-15.3.0

  • Added: C:1 H:0 M:0 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-9358 (LOW) — postcss-selector-parser

ghcr.io-ylianst-meshcentral-1.1.59-mongodb

  • Added: C:0 H:10 M:26 L:1
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-32316 (HIGH) — jq
      • CVE-2026-40164 (HIGH) — jq
      • CVE-2026-8286 (HIGH) — curl
      • CVE-2026-8458 (HIGH) — curl
      • CVE-2026-8925 (HIGH) — curl
      • ...and 29 more

ghcr.io-zulip-zulip-server-12.0-0

  • Added: C:1 H:20 M:272 L:36
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-80631 (HIGH) — linux-libc-dev
      • CVE-2026-80634 (HIGH) — linux-libc-dev
      • CVE-2026-80637 (HIGH) — linux-libc-dev
      • CVE-2026-80644 (HIGH) — linux-libc-dev
      • CVE-2026-80668 (HIGH) — linux-libc-dev
      • CVE-2026-80671 (HIGH) — linux-libc-dev
      • CVE-2026-80681 (HIGH) — linux-libc-dev
      • ...and 321 more

lscr.io-linuxserver-jellyfin-10.11.9

  • Added: C:0 H:0 M:36 L:4
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2025-59375 (MEDIUM) — libexpat1
      • CVE-2026-13595 (MEDIUM) — bsdutils
      • CVE-2026-18374 (MEDIUM) — libc-bin
      • CVE-2026-32776 (MEDIUM) — libexpat1
      • CVE-2026-32777 (MEDIUM) — libexpat1
      • CVE-2026-32778 (MEDIUM) — libexpat1
      • CVE-2026-39113 (MEDIUM) — libsqlite3-0
      • CVE-2026-41080 (MEDIUM) — libexpat1
      • ...and 32 more

mongo-8.3.2

  • Added: C:1 H:0 M:12 L:4
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-13595 (MEDIUM) — bsdutils
      • CVE-2026-18374 (MEDIUM) — libc-bin
      • CVE-2026-53612 (MEDIUM) — bsdutils
      • CVE-2026-53613 (MEDIUM) — bsdutils
      • CVE-2026-53614 (MEDIUM) — bsdutils
      • CVE-2026-53615 (MEDIUM) — bsdutils
      • CVE-2026-59843 (MEDIUM) — libssh-4
      • ...and 9 more

n8nio-runners-2.22.1

  • Added: C:0 H:8 M:11 L:0
  • Removed: C:0 H:1 M:7 L:0
    • [NEW]:
      • CVE-2026-53612 (HIGH) — libuuid
      • CVE-2026-53613 (HIGH) — libuuid
      • CVE-2026-53614 (HIGH) — libuuid
      • CVE-2026-67320 (HIGH) — axios
      • CVE-2026-73086 (HIGH) — nanoid
      • CVE-2026-76642 (HIGH) — libuuid
      • CVE-2026-78408 (HIGH) — libuuid
      • CVE-2026-78410 (HIGH) — libuuid
      • ...and 11 more
    • [FIXED]:
      • GHSA-gcfj-64vw-6mp9 (HIGH) — axios
      • GHSA-42h9-826w-cgv3 (MEDIUM) — axios
      • GHSA-7q8q-rj6j-mhjq (MEDIUM) — axios
      • GHSA-f4gw-2p7v-4548 (MEDIUM) — axios
      • GHSA-jqh4-m9w3-8hp9 (MEDIUM) — axios
      • GHSA-mmx7-hfxf-jppx (MEDIUM) — axios
      • GHSA-mwf2-3pr3-8698 (MEDIUM) — axios
      • GHSA-pmv8-rq9r-6j72 (MEDIUM) — axios

nextcloud-33.0.3-fpm-alpine

  • Added: C:0 H:33 M:28 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-53612 (HIGH) — libblkid
      • CVE-2026-53613 (HIGH) — libblkid
      • CVE-2026-53614 (HIGH) — libblkid
      • CVE-2026-53783 (HIGH) — rsync
      • CVE-2026-53784 (HIGH) — rsync
      • ...and 53 more

nginx-1.31.0-alpine3.23

  • Added: C:0 H:14 M:14 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-53612 (HIGH) — libuuid
      • CVE-2026-53613 (HIGH) — libuuid
      • CVE-2026-53614 (HIGH) — libuuid
      • CVE-2026-76642 (HIGH) — libuuid
      • CVE-2026-78408 (HIGH) — libuuid
      • ...and 20 more

postgres-18.4

  • Added: C:0 H:4 M:5 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-76642 (HIGH) — bsdutils
      • CVE-2026-78408 (HIGH) — bsdutils
      • CVE-2026-78409 (HIGH) — bsdutils
      • CVE-2026-78410 (HIGH) — bsdutils
      • CVE-2026-15534 (MEDIUM) — libperl5.40
      • CVE-2026-18374 (MEDIUM) — libc-bin
      • CVE-2026-39113 (MEDIUM) — libsqlite3-0
      • CVE-2026-80489 (MEDIUM) — libc-bin
      • ...and 1 more

qbittorrentofficial-qbittorrent-nox-5.2.0-1

  • Added: C:0 H:14 M:14 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-53612 (HIGH) — libblkid
      • CVE-2026-53613 (HIGH) — libblkid
      • CVE-2026-53614 (HIGH) — libblkid
      • CVE-2026-76642 (HIGH) — libblkid
      • CVE-2026-78408 (HIGH) — libblkid
      • ...and 20 more

rabbitmq-4.3.0

  • Added: C:0 H:0 M:6 L:4
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-13595 (MEDIUM) — bsdutils
      • CVE-2026-18374 (MEDIUM) — libc-bin
      • CVE-2026-53612 (MEDIUM) — bsdutils
      • CVE-2026-53613 (MEDIUM) — bsdutils
      • CVE-2026-53614 (MEDIUM) — bsdutils
      • CVE-2026-53615 (MEDIUM) — bsdutils
      • CVE-2025-5278 (LOW) — coreutils
      • CVE-2025-6141 (LOW) — libncursesw6
      • ...and 2 more

syncthing-syncthing-2.1.0

  • Added: C:1 H:8 M:10 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-56854 (CRITICAL) — golang.org/x/crypto
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-8286 (HIGH) — curl
      • CVE-2026-8458 (HIGH) — curl
      • CVE-2026-8925 (HIGH) — curl
      • CVE-2026-8927 (HIGH) — curl
      • ...and 11 more

towfiqi-serpbear-3.1.0

  • Added: C:0 H:4 M:8 L:1
  • Removed: C:0 H:1 M:6 L:0
    • [NEW]:
      • CVE-2026-73086 (HIGH) — nanoid
      • CVE-2026-75975 (HIGH) — fast-uri
      • CVE-2026-76172 (HIGH) — fast-uri
      • CVE-2026-82659 (HIGH) — nodemailer
      • CVE-2026-67312 (MEDIUM) — axios
      • CVE-2026-67313 (MEDIUM) — axios
      • CVE-2026-67316 (MEDIUM) — axios
      • CVE-2026-67317 (MEDIUM) — axios
      • ...and 5 more
    • [FIXED]:
      • GHSA-p6gq-j5cr-w38f (HIGH) — nodemailer
      • GHSA-42h9-826w-cgv3 (MEDIUM) — axios
      • GHSA-7q8q-rj6j-mhjq (MEDIUM) — axios
      • GHSA-jqh4-m9w3-8hp9 (MEDIUM) — axios
      • GHSA-mmx7-hfxf-jppx (MEDIUM) — axios
      • GHSA-mwf2-3pr3-8698 (MEDIUM) — axios
      • GHSA-pmv8-rq9r-6j72 (MEDIUM) — axios

vaultwarden-server-1.36.0-alpine

  • Added: C:0 H:8 M:10 L:0
  • Removed: C:0 H:0 M:0 L:0
    • [NEW]:
      • CVE-2026-11352 (HIGH) — curl
      • CVE-2026-11586 (HIGH) — curl
      • CVE-2026-12064 (HIGH) — curl
      • CVE-2026-8286 (HIGH) — curl
      • CVE-2026-8458 (HIGH) — curl
      • CVE-2026-8925 (HIGH) — curl
      • CVE-2026-8927 (HIGH) — curl
      • CVE-2026-9547 (HIGH) — curl
      • ...and 10 more

@github-actions
github-actions Bot enabled auto-merge (squash) June 15, 2026 07:46
@github-actions github-actions Bot changed the title Weekly audit refresh: 27531642510 Weekly audit refresh: 27937554468 Jun 22, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch 2 times, most recently from b731738 to ee0b4cb Compare June 29, 2026 07:31
@github-actions github-actions Bot changed the title Weekly audit refresh: 27937554468 Weekly audit refresh: 28355862242 Jun 29, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from ee0b4cb to f74a280 Compare July 6, 2026 07:24
@github-actions github-actions Bot changed the title Weekly audit refresh: 28355862242 Weekly audit refresh: 28774870590 Jul 6, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from f74a280 to dd640f5 Compare July 13, 2026 08:41
@github-actions github-actions Bot changed the title Weekly audit refresh: 28774870590 Weekly audit refresh: 29236242866 Jul 13, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from dd640f5 to bf5d844 Compare July 20, 2026 08:33
@github-actions github-actions Bot changed the title Weekly audit refresh: 29236242866 Weekly audit refresh: 29728216532 Jul 20, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from bf5d844 to 816e6d7 Compare July 27, 2026 09:22
@github-actions github-actions Bot changed the title Weekly audit refresh: 29728216532 Weekly audit refresh: 30253527123 Jul 27, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 816e6d7 to 9cf054d Compare August 3, 2026 08:56
@github-actions github-actions Bot changed the title Weekly audit refresh: 30253527123 Weekly audit refresh: 30799210887 Aug 3, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 9cf054d to ac8c576 Compare August 10, 2026 06:23
@github-actions github-actions Bot changed the title Weekly audit refresh: 30799210887 Weekly audit refresh: 31361726896 Aug 10, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from ac8c576 to 0cab591 Compare August 17, 2026 06:06
@github-actions github-actions Bot changed the title Weekly audit refresh: 31361726896 Weekly audit refresh: 32000254350 Aug 17, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 0cab591 to 2cc93c5 Compare August 24, 2026 06:08
@github-actions github-actions Bot changed the title Weekly audit refresh: 32000254350 Weekly audit refresh: 32696049090 Aug 24, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 2cc93c5 to 8ac450e Compare August 31, 2026 06:03
@github-actions github-actions Bot changed the title Weekly audit refresh: 32696049090 Weekly audit refresh: 33362608869 Aug 31, 2026
@github-actions
github-actions Bot force-pushed the chore/weekly-audit-refresh branch from 8ac450e to a8821af Compare September 7, 2026 06:03
@github-actions github-actions Bot changed the title Weekly audit refresh: 33362608869 Weekly audit refresh: 34089089538 Sep 7, 2026
@wn-mira-org

wn-mira-org Bot commented Sep 7, 2026

Copy link
Copy Markdown

Mira PR Walkthrough

This PR refreshes the weekly audit documentation in AUDIT.md. The accompanying CVE delta reports changes for 38 of 44 images, with net increases of 13 critical, 252 high, 839 medium, and 115 low findings. The supplied file metadata shows only documentation changes, not vulnerability fixes or image upgrades.

Confidence: 4/5   ◉◉◉◉○   Safe with minor verification
  • The two-line documentation refresh poses minimal runtime risk, but the exact replacement text is unavailable and should be checked against the audit results before merging.

Key files to review:

  • AUDIT.md:5 — The new scan metadata labels an unchanged report despite the vulnerability changes reported in the PR description.

1 file reviewed · 1 comment (⚠️ 1 warning)


Comment @wn-mira-org help to get the list of available commands and usage tips.

@wn-mira-org wn-mira-org Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mira Review Summary

The audit refresh updates timestamps without updating the report to include the vulnerability delta described in the PR.

Key Issues

Issue Location
🔴 The new scan metadata labels an unchanged report despite the vulnerability changes reported in the PR description. AUDIT.md:5

Comment thread AUDIT.md
| Field | Value |
|---|---|
| **Scan date** | 2026-06-01 |
| **Scan date** | 2026-09-07 |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug
⚠️ Warning

Refresh the findings along with the scan metadata

The PR description reports 38 changed images, including net increases of 13 critical and 252 high findings, but this patch changes only the scan date and vulnerability database timestamp. The rest of AUDIT.md remains unchanged, so the new metadata presents the previous report as the September 7 scan. Regenerate the report from the new scan output and commit the updated findings with these timestamps.


Prompt for AI Agents
Regenerate AUDIT.md from the September 7 scan output rather than updating only the metadata at lines 5 and 7. Include the changed vulnerability findings and reconcile the image count with the same scan output. If that output is unavailable, revert both metadata changes until the full report can be refreshed.

Not useful? Reply @wn-mira-org reject to dismiss this suggestion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant