Weekly audit refresh: 34089089538 - #63
Conversation
b731738 to
ee0b4cb
Compare
ee0b4cb to
f74a280
Compare
f74a280 to
dd640f5
Compare
dd640f5 to
bf5d844
Compare
bf5d844 to
816e6d7
Compare
816e6d7 to
9cf054d
Compare
9cf054d to
ac8c576
Compare
ac8c576 to
0cab591
Compare
0cab591 to
2cc93c5
Compare
2cc93c5 to
8ac450e
Compare
8ac450e to
a8821af
Compare
Mira PR WalkthroughThis PR refreshes the weekly audit documentation in AUDIT.md. The accompanying CVE delta reports changes for 38 of 44 images, with net increases of 13 critical, 252 high, 839 medium, and 115 low findings. The supplied file metadata shows only documentation changes, not vulnerability fixes or image upgrades. Confidence: 4/5 ◉◉◉◉○ Safe with minor verification
Key files to review:
1 file reviewed · 1 comment (
|
There was a problem hiding this comment.
Mira Review Summary
The audit refresh updates timestamps without updating the report to include the vulnerability delta described in the PR.
Key Issues
| Issue | Location | |
|---|---|---|
| 🔴 | The new scan metadata labels an unchanged report despite the vulnerability changes reported in the PR description. | AUDIT.md:5 |
| | Field | Value | | ||
| |---|---| | ||
| | **Scan date** | 2026-06-01 | | ||
| | **Scan date** | 2026-09-07 | |
There was a problem hiding this comment.
Bug
Refresh the findings along with the scan metadata
The PR description reports 38 changed images, including net increases of 13 critical and 252 high findings, but this patch changes only the scan date and vulnerability database timestamp. The rest of AUDIT.md remains unchanged, so the new metadata presents the previous report as the September 7 scan. Regenerate the report from the new scan output and commit the updated findings with these timestamps.
Prompt for AI Agents
Regenerate AUDIT.md from the September 7 scan output rather than updating only the metadata at lines 5 and 7. Include the changed vulnerability findings and reconcile the image count with the same scan output. If that output is unavailable, revert both metadata changes until the full report can be refreshed.
Not useful? Reply
@wn-mira-org rejectto dismiss this suggestion.
CVE delta
Net change
Changed images: 38 of 44
Per-image detail
adguard-adguardhome-v0.107.76CVE-2026-56854(CRITICAL) —golang.org/x/cryptobaserow-baserow-2.2.2CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-76642(HIGH) —bsdutilsCVE-2026-78408(HIGH) —bsdutilsCVE-2026-78409(HIGH) —bsdutilsCVE-2026-78410(HIGH) —bsdutilsCVE-2026-81934(HIGH) —redisCVE-2026-82397(HIGH) —tornadoCVE-2026-84304(HIGH) —google.golang.org/grpcCVE-2026-69248(MEDIUM) —cryptographyGHSA-42h9-826w-cgv3(MEDIUM) —axiosGHSA-7q8q-rj6j-mhjq(MEDIUM) —axiosGHSA-f4gw-2p7v-4548(MEDIUM) —axiosGHSA-jqh4-m9w3-8hp9(MEDIUM) —axiosGHSA-mmx7-hfxf-jppx(MEDIUM) —axiosGHSA-mwf2-3pr3-8698(MEDIUM) —axiosGHSA-pmv8-rq9r-6j72(MEDIUM) —axiosdeluan-navidrome-0.61.2CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-46603(HIGH) —golang.org/x/imagedocker.io-caddy-2.11.3CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-8286(HIGH) —curlCVE-2026-84304(HIGH) —google.golang.org/grpcCVE-2026-8458(HIGH) —curlCVE-2026-8925(HIGH) —curldocker.io-library-postgres-18.4-alpine3.23CVE-2026-11352(HIGH) —libcurlCVE-2026-11586(HIGH) —libcurlCVE-2026-12064(HIGH) —libcurlCVE-2026-53612(HIGH) —libuuidCVE-2026-53613(HIGH) —libuuidCVE-2026-53614(HIGH) —libuuidCVE-2026-76642(HIGH) —libuuidCVE-2026-78408(HIGH) —libuuiddocker.io-louislam-uptime-kuma-2.3.2CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-19154(HIGH) —chromiumCVE-2026-19161(HIGH) —chromiumCVE-2026-19176(HIGH) —chromiumCVE-2026-67320(HIGH) —axiosCVE-2026-76018(HIGH) —chromiumCVE-2026-76020(HIGH) —chromiumCVE-2026-76021(HIGH) —chromiumGHSA-gcfj-64vw-6mp9(HIGH) —axiosGHSA-p6gq-j5cr-w38f(HIGH) —nodemailerCVE-2026-76956(MEDIUM) —libexpat1GHSA-42h9-826w-cgv3(MEDIUM) —axiosGHSA-7q8q-rj6j-mhjq(MEDIUM) —axiosGHSA-f4gw-2p7v-4548(MEDIUM) —axiosGHSA-mmx7-hfxf-jppx(MEDIUM) —axiosGHSA-pmv8-rq9r-6j72(MEDIUM) —axiosdocker.io-mariadb-12.2.2CVE-2026-13595(MEDIUM) —bsdutilsCVE-2026-18374(MEDIUM) —libc-binCVE-2026-39113(MEDIUM) —libsqlite3-0CVE-2026-53612(MEDIUM) —bsdutilsCVE-2026-53613(MEDIUM) —bsdutilsCVE-2026-53614(MEDIUM) —bsdutilsCVE-2026-53615(MEDIUM) —bsdutilsCVE-2025-5278(LOW) —coreutilsdocker.io-mongo-8.3.2CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-13595(MEDIUM) —bsdutilsCVE-2026-18374(MEDIUM) —libc-binCVE-2026-53612(MEDIUM) —bsdutilsCVE-2026-53613(MEDIUM) —bsdutilsCVE-2026-53614(MEDIUM) —bsdutilsCVE-2026-53615(MEDIUM) —bsdutilsCVE-2026-59843(MEDIUM) —libssh-4docker.io-redis-8.6.3-alpineCVE-2026-53612(HIGH) —setprivCVE-2026-53613(HIGH) —setprivCVE-2026-53614(HIGH) —setprivCVE-2026-76642(HIGH) —setprivCVE-2026-78408(HIGH) —setprivCVE-2026-78410(HIGH) —setprivdocuseal-docuseal-3.0.0CVE-2026-11352(HIGH) —libcurlCVE-2026-11586(HIGH) —libcurlCVE-2026-12064(HIGH) —libcurlCVE-2026-53612(HIGH) —libblkidCVE-2026-53613(HIGH) —libblkidCVE-2026-53614(HIGH) —libblkidCVE-2026-76642(HIGH) —libblkidCVE-2026-78408(HIGH) —libblkidGHSA-mvxr-6m87-mv2q(MEDIUM) —mailfnsys-dockhand-v1.0.29CVE-2026-82659(HIGH) —nodemailerCVE-2026-84304(HIGH) —docker-cli-buildxCVE-2026-54876(LOW) —libcrypto3GHSA-p6gq-j5cr-w38f(HIGH) —nodemailerfreshrss-freshrss-1.29.1-alpineCVE-2026-11352(HIGH) —libcurlCVE-2026-11586(HIGH) —libcurlCVE-2026-12064(HIGH) —libcurlCVE-2026-53612(HIGH) —libuuidCVE-2026-53613(HIGH) —libuuidCVE-2026-53614(HIGH) —libuuidCVE-2026-76642(HIGH) —libuuidCVE-2026-78408(HIGH) —libuuidghcr.io-goauthentik-server-2026.2.3CVE-2026-74743(HIGH) —linux-libc-devCVE-2026-74744(HIGH) —linux-libc-devCVE-2026-74746(HIGH) —linux-libc-devCVE-2026-74752(HIGH) —linux-libc-devCVE-2026-76642(HIGH) —bsdutilsCVE-2026-78408(HIGH) —bsdutilsCVE-2026-78409(HIGH) —bsdutilsCVE-2026-78410(HIGH) —bsdutilsghcr.io-open-webui-open-webui-0.9.5CVE-2026-71428(CRITICAL) —unstructuredCVE-2026-79675(CRITICAL) —nltkCVE-2026-38349(HIGH) —ffmpegCVE-2026-62388(HIGH) —nltkCVE-2026-72818(HIGH) —nltkCVE-2026-74743(HIGH) —linux-libc-devCVE-2026-74744(HIGH) —linux-libc-devCVE-2026-74746(HIGH) —linux-libc-devCVE-2026-76956(MEDIUM) —libexpat1GHSA-rf74-v2fm-23pw(MEDIUM) —nltkCVE-2026-19582(LOW) —binutilsghcr.io-stoatchat-api-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-crond-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-events-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-file-server-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-for-web-0b94704CVE-2026-9358(LOW) —postcss-selector-parserghcr.io-stoatchat-gifbox-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-livekit-server-v1.9.13CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-84304(HIGH) —google.golang.org/grpcghcr.io-stoatchat-proxy-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-pushd-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-stoatchat-voice-ingress-v0.13.6CVE-2026-18374(MEDIUM) —libc6CVE-2026-80489(MEDIUM) —libc6ghcr.io-wg-easy-wg-easy-15.3.0CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-9358(LOW) —postcss-selector-parserghcr.io-ylianst-meshcentral-1.1.59-mongodbCVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-32316(HIGH) —jqCVE-2026-40164(HIGH) —jqCVE-2026-8286(HIGH) —curlCVE-2026-8458(HIGH) —curlCVE-2026-8925(HIGH) —curlghcr.io-zulip-zulip-server-12.0-0CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-80631(HIGH) —linux-libc-devCVE-2026-80634(HIGH) —linux-libc-devCVE-2026-80637(HIGH) —linux-libc-devCVE-2026-80644(HIGH) —linux-libc-devCVE-2026-80668(HIGH) —linux-libc-devCVE-2026-80671(HIGH) —linux-libc-devCVE-2026-80681(HIGH) —linux-libc-devlscr.io-linuxserver-jellyfin-10.11.9CVE-2025-59375(MEDIUM) —libexpat1CVE-2026-13595(MEDIUM) —bsdutilsCVE-2026-18374(MEDIUM) —libc-binCVE-2026-32776(MEDIUM) —libexpat1CVE-2026-32777(MEDIUM) —libexpat1CVE-2026-32778(MEDIUM) —libexpat1CVE-2026-39113(MEDIUM) —libsqlite3-0CVE-2026-41080(MEDIUM) —libexpat1mongo-8.3.2CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-13595(MEDIUM) —bsdutilsCVE-2026-18374(MEDIUM) —libc-binCVE-2026-53612(MEDIUM) —bsdutilsCVE-2026-53613(MEDIUM) —bsdutilsCVE-2026-53614(MEDIUM) —bsdutilsCVE-2026-53615(MEDIUM) —bsdutilsCVE-2026-59843(MEDIUM) —libssh-4n8nio-runners-2.22.1CVE-2026-53612(HIGH) —libuuidCVE-2026-53613(HIGH) —libuuidCVE-2026-53614(HIGH) —libuuidCVE-2026-67320(HIGH) —axiosCVE-2026-73086(HIGH) —nanoidCVE-2026-76642(HIGH) —libuuidCVE-2026-78408(HIGH) —libuuidCVE-2026-78410(HIGH) —libuuidGHSA-gcfj-64vw-6mp9(HIGH) —axiosGHSA-42h9-826w-cgv3(MEDIUM) —axiosGHSA-7q8q-rj6j-mhjq(MEDIUM) —axiosGHSA-f4gw-2p7v-4548(MEDIUM) —axiosGHSA-jqh4-m9w3-8hp9(MEDIUM) —axiosGHSA-mmx7-hfxf-jppx(MEDIUM) —axiosGHSA-mwf2-3pr3-8698(MEDIUM) —axiosGHSA-pmv8-rq9r-6j72(MEDIUM) —axiosnextcloud-33.0.3-fpm-alpineCVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-53612(HIGH) —libblkidCVE-2026-53613(HIGH) —libblkidCVE-2026-53614(HIGH) —libblkidCVE-2026-53783(HIGH) —rsyncCVE-2026-53784(HIGH) —rsyncnginx-1.31.0-alpine3.23CVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-53612(HIGH) —libuuidCVE-2026-53613(HIGH) —libuuidCVE-2026-53614(HIGH) —libuuidCVE-2026-76642(HIGH) —libuuidCVE-2026-78408(HIGH) —libuuidpostgres-18.4CVE-2026-76642(HIGH) —bsdutilsCVE-2026-78408(HIGH) —bsdutilsCVE-2026-78409(HIGH) —bsdutilsCVE-2026-78410(HIGH) —bsdutilsCVE-2026-15534(MEDIUM) —libperl5.40CVE-2026-18374(MEDIUM) —libc-binCVE-2026-39113(MEDIUM) —libsqlite3-0CVE-2026-80489(MEDIUM) —libc-binqbittorrentofficial-qbittorrent-nox-5.2.0-1CVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-53612(HIGH) —libblkidCVE-2026-53613(HIGH) —libblkidCVE-2026-53614(HIGH) —libblkidCVE-2026-76642(HIGH) —libblkidCVE-2026-78408(HIGH) —libblkidrabbitmq-4.3.0CVE-2026-13595(MEDIUM) —bsdutilsCVE-2026-18374(MEDIUM) —libc-binCVE-2026-53612(MEDIUM) —bsdutilsCVE-2026-53613(MEDIUM) —bsdutilsCVE-2026-53614(MEDIUM) —bsdutilsCVE-2026-53615(MEDIUM) —bsdutilsCVE-2025-5278(LOW) —coreutilsCVE-2025-6141(LOW) —libncursesw6syncthing-syncthing-2.1.0CVE-2026-56854(CRITICAL) —golang.org/x/cryptoCVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-8286(HIGH) —curlCVE-2026-8458(HIGH) —curlCVE-2026-8925(HIGH) —curlCVE-2026-8927(HIGH) —curltowfiqi-serpbear-3.1.0CVE-2026-73086(HIGH) —nanoidCVE-2026-75975(HIGH) —fast-uriCVE-2026-76172(HIGH) —fast-uriCVE-2026-82659(HIGH) —nodemailerCVE-2026-67312(MEDIUM) —axiosCVE-2026-67313(MEDIUM) —axiosCVE-2026-67316(MEDIUM) —axiosCVE-2026-67317(MEDIUM) —axiosGHSA-p6gq-j5cr-w38f(HIGH) —nodemailerGHSA-42h9-826w-cgv3(MEDIUM) —axiosGHSA-7q8q-rj6j-mhjq(MEDIUM) —axiosGHSA-jqh4-m9w3-8hp9(MEDIUM) —axiosGHSA-mmx7-hfxf-jppx(MEDIUM) —axiosGHSA-mwf2-3pr3-8698(MEDIUM) —axiosGHSA-pmv8-rq9r-6j72(MEDIUM) —axiosvaultwarden-server-1.36.0-alpineCVE-2026-11352(HIGH) —curlCVE-2026-11586(HIGH) —curlCVE-2026-12064(HIGH) —curlCVE-2026-8286(HIGH) —curlCVE-2026-8458(HIGH) —curlCVE-2026-8925(HIGH) —curlCVE-2026-8927(HIGH) —curlCVE-2026-9547(HIGH) —curl