Weekly scan found 1 HIGH/CRITICAL CVE across 1 package(s) in the published image.
refresh.yml rebuilds :latest against a fresh base two hours before this scan, so these survived a rebuild: either that run failed, or they need a real dependency change rather than fresher OS packages.
- CRITICAL CVE-2026-63374 in anyio@4.13.0: AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
Weekly scan found 1 HIGH/CRITICAL CVE across 1 package(s) in the published image.
refresh.yml rebuilds
:latestagainst a fresh base two hours before this scan, so these survived a rebuild: either that run failed, or they need a real dependency change rather than fresher OS packages.