[ { "filename": "/tekton/home/clair-result-amd64.json", "namespace": "required_checks", "successes": 4, "warnings": [ { "msg": "Found packages with high vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.", "metadata": { "details": { "description": "Vulnerabilities found: nodejs-nodemon-3.0.1-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-12151, CVE-2026-13149, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), libacl-2.3.1-4.el9 (CVE-2026-54369), openssl-libs-1:3.5.5-2.el9_8 (CVE-2026-45447), npm-1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461 (CVE-2026-12151, CVE-2026-13149, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), nodejs-libs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-12151, CVE-2026-13149, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), openssl-1:3.5.5-2.el9_8 (CVE-2026-45447), glib2-2.68.4-19.el9_8.1 (CVE-2026-58016), nodejs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-12151, CVE-2026-13149, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874), nodejs-full-i18n-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-12151, CVE-2026-13149, CVE-2026-42338, CVE-2026-48618, CVE-2026-48933, CVE-2026-59873, CVE-2026-59874)", "name": "clair_high_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 39 } }, { "msg": "Found packages with unpatched high vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: sqlite-libs-3.34.1-10.el9_8 (CVE-2026-51298), libcurl-minimal-7.76.1-40.el9 (CVE-2026-8286, CVE-2026-8458, CVE-2026-8927, CVE-2026-9547), tar-2:1.34-11.el9 (CVE-2026-73566), curl-minimal-7.76.1-40.el9 (CVE-2026-8286, CVE-2026-8458, CVE-2026-8927, CVE-2026-9547)", "name": "clair_unpatched_high_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 10 } }, { "msg": "Found packages with medium vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.", "metadata": { "details": { "description": "Vulnerabilities found: coreutils-single-8.32-40.el9 (CVE-2025-5278), nodejs-nodemon-3.0.1-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), p11-kit-0.26.2-1.el9 (CVE-2026-13757), openssl-fips-provider-so-3.0.7-8.el9 (CVE-2026-31790), glibc-2.34-270.el9_8 (CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), openssl-libs-1:3.5.5-2.el9_8 (CVE-2026-28390, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445), libgcrypt-1.10.0-11.el9 (CVE-2026-41989), npm-1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461 (CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), openssl-fips-provider-3.0.7-8.el9 (CVE-2026-31790), nodejs-libs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), glibc-common-2.34-270.el9_8 (CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), p11-kit-trust-0.26.2-1.el9 (CVE-2026-13757), openssl-1:3.5.5-2.el9_8 (CVE-2026-28390, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445), glibc-minimal-langpack-2.34-270.el9_8 (CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238), libnghttp2-1.43.0-6.el9_8.1 (CVE-2026-58055), libarchive-3.5.3-9.el9_7 (CVE-2026-14164), libsolv-0.7.24-4.el9 (CVE-2026-48864), nodejs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678), nodejs-full-i18n-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934, CVE-2026-9678)", "name": "clair_medium_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 61 } }, { "msg": "Found packages with unpatched medium vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: libxml2-2.9.13-14.el9_7 (CVE-2026-0990, CVE-2026-11979, CVE-2026-1757, CVE-2026-6653, CVE-2026-6732), coreutils-single-8.32-40.el9 (CVE-2026-56391, CVE-2026-56392), libattr-2.5.1-3.el9 (CVE-2026-54371), openssl-fips-provider-so-3.0.7-8.el9 (CVE-2026-2673), glibc-2.34-270.el9_8 (CVE-2026-6368, CVE-2026-6791), bzip2-libs-1.0.8-11.el9 (CVE-2026-42250), sed-4.8-10.el9 (CVE-2026-5958), openssl-libs-1:3.5.5-2.el9_8 (CVE-2026-2673), libsmartcols-2.37.4-25.el9 (CVE-2026-13595, CVE-2026-27456), libblkid-2.37.4-25.el9 (CVE-2026-13595, CVE-2026-27456), openssl-fips-provider-3.0.7-8.el9 (CVE-2026-2673), krb5-libs-1.21.1-10.el9_8 (CVE-2026-11850), gnupg2-2.3.3-5.el9_7 (CVE-2025-68972), openldap-2.6.8-4.el9 (CVE-2026-22185), glibc-common-2.34-270.el9_8 (CVE-2026-6368, CVE-2026-6791), openssl-1:3.5.5-2.el9_8 (CVE-2026-2673), libcurl-minimal-7.76.1-40.el9 (CVE-2025-13034, CVE-2025-14017, CVE-2026-11856, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6429, CVE-2026-7168, CVE-2026-8924, CVE-2026-8932), glibc-minimal-langpack-2.34-270.el9_8 (CVE-2026-6368, CVE-2026-6791), libuuid-2.37.4-25.el9 (CVE-2026-13595, CVE-2026-27456), libmount-2.37.4-25.el9 (CVE-2026-13595, CVE-2026-27456), libarchive-3.5.3-9.el9_7 (CVE-2023-30571, CVE-2025-60753, CVE-2026-4426, CVE-2026-5745), glib2-2.68.4-19.el9_8.1 (CVE-2026-1484, CVE-2026-1489, CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015), libsolv-0.7.24-4.el9 (CVE-2026-9149, CVE-2026-9150), gawk-5.1.0-6.el9 (CVE-2026-40467, CVE-2026-40468, CVE-2026-40553), tar-2:1.34-11.el9 (CVE-2025-64118, CVE-2026-18477, CVE-2026-18508, CVE-2026-33056, CVE-2026-53655, CVE-2026-5704, CVE-2026-59871, CVE-2026-59875), xz-libs-5.2.5-8.el9_0 (CVE-2026-34743), curl-minimal-7.76.1-40.el9 (CVE-2025-13034, CVE-2025-14017, CVE-2026-11856, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6429, CVE-2026-7168, CVE-2026-8924, CVE-2026-8932), systemd-libs-252-67.el9_8.2 (CVE-2026-4105)", "name": "clair_unpatched_medium_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 88 } }, { "msg": "Found packages with low/negligible vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.", "metadata": { "details": { "description": "Vulnerabilities found: libxml2-2.9.13-14.el9_7 (CVE-2024-34459, CVE-2025-6170), nodejs-nodemon-3.0.1-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), openssl-libs-1:3.5.5-2.el9_8 (CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45446, CVE-2026-7383, CVE-2026-9076), npm-1:10.9.7-1.22.22.2.1.module+el9.7.0+24157+8ddb2461 (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), nodejs-libs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), openssl-1:3.5.5-2.el9_8 (CVE-2026-34180, CVE-2026-34181, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770, CVE-2026-45446, CVE-2026-7383, CVE-2026-9076), nodejs-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), nodejs-full-i18n-1:22.22.2-1.module+el9.7.0+24157+8ddb2461 (CVE-2026-11525, CVE-2026-48935, CVE-2026-6733), libtasn1-4.16.0-9.el9 (CVE-2025-13151)", "name": "clair_low_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 38 } }, { "msg": "Found packages with unpatched low/negligible vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: libxml2-2.9.13-14.el9_7 (CVE-2023-45322, CVE-2025-27113, CVE-2026-0989, CVE-2026-0992), pcre2-syntax-10.40-6.el9 (CVE-2022-41409), ncurses-base-6.2-12.20210508.el9 (CVE-2023-50495), zlib-1.2.11-40.el9 (CVE-2026-27171), pcre2-10.40-6.el9 (CVE-2022-41409), openssl-libs-1:3.5.5-2.el9_8 (CVE-2024-13176, CVE-2024-41996, CVE-2025-9232, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789), libgcrypt-1.10.0-11.el9 (CVE-2026-41990), ncurses-libs-6.2-12.20210508.el9 (CVE-2023-50495), sqlite-libs-3.34.1-10.el9_8 (CVE-2024-0232, CVE-2025-70873), gnupg2-2.3.3-5.el9_7 (CVE-2022-3219, CVE-2025-30258, CVE-2026-24883, CVE-2026-57062), libgcc-11.5.0-14.el9 (CVE-2021-46195, CVE-2022-27943), libstdc++-11.5.0-14.el9 (CVE-2021-46195, CVE-2022-27943), openssl-1:3.5.5-2.el9_8 (CVE-2024-13176, CVE-2024-41996, CVE-2025-9232, CVE-2026-28388, CVE-2026-28389, CVE-2026-31789), popt-1.18-8.el9 (CVE-2026-18739, CVE-2026-18839), libcurl-minimal-7.76.1-40.el9 (CVE-2024-11053, CVE-2024-7264, CVE-2024-9681, CVE-2025-14524, CVE-2025-15079, CVE-2025-15224, CVE-2026-6276), libarchive-3.5.3-9.el9_7 (CVE-2025-1632, CVE-2025-5915, CVE-2025-5916, CVE-2025-5917, CVE-2025-5918, CVE-2026-15028, CVE-2026-16517), glib2-2.68.4-19.el9_8.1 (CVE-2023-32636, CVE-2025-3360, CVE-2025-7039, CVE-2026-0988, CVE-2026-1485), gawk-5.1.0-6.el9 (CVE-2023-4156), tar-2:1.34-11.el9 (CVE-2023-39804), curl-minimal-7.76.1-40.el9 (CVE-2024-11053, CVE-2024-7264, CVE-2024-9681, CVE-2025-14524, CVE-2025-15079, CVE-2025-15224, CVE-2026-6276)", "name": "clair_unpatched_low_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 62 } } ] } ] {"vulnerabilities":{"critical":0,"high":39,"medium":61,"low":38,"unknown":0},"unpatched_vulnerabilities":{"critical":0,"high":10,"medium":88,"low":62,"unknown":0}} {"image": {"pullspec": "quay.io/redhat-appstudio-qe/build-e2e-prefetch-yarn-modern/component-prefetch-yarn-modern:on-pr-42c05540c3504cfdecccc9b10cf84bf8e6d3240f", "digests": ["sha256:87ef4058a49968d2e264d556a486188d64334b5d4cdbc960b3db75ee9c8421c6"]}} {"result":"SUCCESS","timestamp":"2026-08-18T05:02:41+00:00","note":"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.","namespace":"default","successes":0,"failures":0,"warnings":0}