CVE Monitor Alert
The scheduled Trivy scan found fixable CRITICAL or HIGH vulnerabilities
in the published image ghcr.io/knight-owl-dev/ci-tools:latest.
Next Steps
- Review the workflow run that triggered this alert
- Build and scan the image locally to investigate findings
- Update the base image or affected packages in
images/ci-tools/Dockerfile
- Cut a new release — the publish workflow re-scans before publishing
See docs/supply-chain-security.md
for scanning policy details.
CVE Monitor Alert
The scheduled Trivy scan found fixable CRITICAL or HIGH vulnerabilities
in the published image
ghcr.io/knight-owl-dev/ci-tools:latest.Next Steps
images/ci-tools/DockerfileSee docs/supply-chain-security.md
for scanning policy details.