Skip to content
Discussion options

You must be logged in to vote

Hi! We previously had Docker Scout disabled, since we didn't find it hugely reliable or helpful (results are too noisy).

We update our base-images every two weeks, and pull in all upstream Ubuntu LTS updates (and make a point of not patching the images/including custom things) - so in general if there are any CVEs then it's an Ubuntu issue, not something we have any control over.

The builder images are then built upon these base-images and also include the upstream CNB lifecycle / launcher components per the CNB spec:
https://github.com/buildpacks/lifecycle

Looking at the CVEs reported by Docker Scout now, I see the highest level one (CVE-2025-22874) is from the upstream CNB lifecycle. Sa…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@nickhammond
Comment options

Answer selected by nickhammond
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants