Through an update of the go main stdlib and crypto dependency many of the known CVEs can be addressed.
Here a list of the detected findings reported by trivy on a scan of ghcr.io/willnorris/imageproxy@sha256:ccfa95e7413a97a3bc6af17edacae7006ad542bbc46e99b9e77050c17f99ca84 as of today:
I'm not telling these are critical or so but it looks like a low hanging fruit to take the findings count back to a low number
Through an update of the go main stdlib and crypto dependency many of the known CVEs can be addressed.
Here a list of the detected findings reported by trivy on a scan of ghcr.io/willnorris/imageproxy@sha256:ccfa95e7413a97a3bc6af17edacae7006ad542bbc46e99b9e77050c17f99ca84 as of today:
I'm not telling these are critical or so but it looks like a low hanging fruit to take the findings count back to a low number