Skip to content

Vulnerability Status

Latest Scan Results

Vulnerability scan results are uploaded to GitHub Security (SARIF) after each weekly rescan and pre-release build.

View the latest results in the GitHub Security tab.

Per-Image Status

ImageSARIF CategoryStatus
postgresvulnerability-scan/sbomify/postgresScanned weekly
redisvulnerability-scan/sbomify/redisScanned weekly
miniovulnerability-scan/sbomify/minioScanned weekly
sbomify-appvulnerability-scan/sbomify/sbomify-appScanned weekly
sbomify-keycloakvulnerability-scan/sbomify/sbomify-keycloakScanned weekly
sbomify-caddy-devvulnerability-scan/sbomify/sbomify-caddy-devScanned weekly
sbomify-minio-initvulnerability-scan/sbomify/sbomify-minio-initScanned weekly

How It Works

  1. The rescan-vulnerabilities workflow runs every Monday at 06:00 UTC
  2. It resolves the latest sbomify-v* release tag
  3. For each image, it extracts the SBOM from OCI attestations and scans with Grype
  4. Results are uploaded as SARIF to GitHub Code Scanning
  5. New findings are triaged per the remediation SLA