Tools 0.2.2 (arm64)
Contents
Reports
Information
Artifact Name | ghcr.io/mecha-hq/checkmake:0.2.2-arm64 |
Artifact Type | container image |
Details
Code | Title | Level | Alerts |
---|---|---|---|
DKL-LI-0001 | Avoid empty password | Skip | failed to detect etc/shadow,etc/master.passwd |
CIS-DI-0005 | Enable Content trust for Docker | Info | export DOCKER_CONTENT_TRUST=1 before docker pull/build |
CIS-DI-0006 | Add HEALTHCHECK instruction to the container image | Info | not found HEALTHCHECK statement |
Information
Artifact Name | ghcr.io/mecha-hq/checkmake:0.2.2-arm64 |
Artifact Type | image |
OS Kind | linux |
OS Name | N/A |
Architecture | arm64 |
Vulnerabilities
Id | Severity | State | Description |
---|---|---|---|
CVE-2025-4673 | Medium | Fixed | Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information. |
CVE-2025-0913 | Medium | Fixed | os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink. |
Information
Spdx Version | SPDX-2.3 |
Data License | CC0-1.0 |
Document Namespace | https://spdx.org/spdxdocs/apko/ |
Document Describes | [SPDXRef-Package-sha256-8dcf7d490a234f4c2cda0afae1d5d919e3f694690a61a7b5dae3bcd5ca0da83f] |
Packages
Name | Description | Supplier | Purpose |
---|---|---|---|
sha256:8dcf7d490a234f4c2cda0afae1d5d919e3f694690a61a7b5dae3bcd5ca0da83f | apko container image | Organization: apko-generated image | CONTAINER |
sha256:9eebd3b8e6b6937136b34e7569d2a90ab09efee2d10dd26330e333a15f38c12f | apko operating system layer | Organization: apko-generated image | |
checkmake | Organization: Unknown |
Relationships
Element ID | Type | Related Element |
---|---|---|
SPDXRef-Package-sha256-8dcf7d490a234f4c2cda0afae1d5d919e3f694690a61a7b5dae3bcd5ca0da83f | CONTAINS | SPDXRef-Package-sha256-9eebd3b8e6b6937136b34e7569d2a90ab09efee2d10dd26330e333a15f38c12f |
Files
sbom.spdx.json
dockle.json
grype.json