Tools 0.2.2 (amd64)
Contents
Reports
Information
Artifact Name | ghcr.io/mecha-hq/checkmake:0.2.2-amd64 |
Artifact Type | container image |
Details
Code | Title | Level | Alerts |
---|---|---|---|
DKL-LI-0001 | Avoid empty password | Skip | failed to detect etc/shadow,etc/master.passwd |
CIS-DI-0005 | Enable Content trust for Docker | Info | export DOCKER_CONTENT_TRUST=1 before docker pull/build |
CIS-DI-0006 | Add HEALTHCHECK instruction to the container image | Info | not found HEALTHCHECK statement |
Information
Artifact Name | ghcr.io/mecha-hq/checkmake:0.2.2-amd64 |
Artifact Type | image |
OS Kind | linux |
OS Name | N/A |
Architecture | amd64 |
Vulnerabilities
Id | Severity | State | Description |
---|---|---|---|
CVE-2025-4673 | Medium | Fixed | Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information. |
CVE-2025-0913 | Medium | Fixed | os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink. |
Information
Spdx Version | SPDX-2.3 |
Data License | CC0-1.0 |
Document Namespace | https://spdx.org/spdxdocs/apko/ |
Document Describes | [SPDXRef-Package-sha256-70a93d4c84786a197e402978a179bd252c5ca2c7dc82b3d48e465d67bbc3d871] |
Packages
Name | Description | Supplier | Purpose |
---|---|---|---|
sha256:70a93d4c84786a197e402978a179bd252c5ca2c7dc82b3d48e465d67bbc3d871 | apko container image | Organization: apko-generated image | CONTAINER |
sha256:b23e19178a724f70c15c764493a374b6762a4efaba69e04490b3a26f0342e2cf | apko operating system layer | Organization: apko-generated image | |
checkmake | Organization: Unknown |
Relationships
Element ID | Type | Related Element |
---|---|---|
SPDXRef-Package-sha256-70a93d4c84786a197e402978a179bd252c5ca2c7dc82b3d48e465d67bbc3d871 | CONTAINS | SPDXRef-Package-sha256-b23e19178a724f70c15c764493a374b6762a4efaba69e04490b3a26f0342e2cf |
Files
sbom.spdx.json
dockle.json
grype.json