[ { "filename": "/tekton/home/clair-result-amd64.json", "namespace": "required_checks", "successes": 6, "warnings": [ { "msg": "Found packages with medium vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.", "metadata": { "details": { "description": "Vulnerabilities found: pip-22.3.1 (GHSA-wf93-45jw-7689)", "name": "clair_medium_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 1 } }, { "msg": "Found packages with unpatched medium vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: coreutils-8.32-4+b1 (CVE-2016-2781)", "name": "clair_unpatched_medium_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 1 } }, { "msg": "Found packages with unpatched low/negligible vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: gcc-10-base-10.2.1-6 (CVE-2023-4039), libapt-pkg6.0-2.2.4 (CVE-2011-3374), libblkid1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libc6-2.31-13+deb11u5 (CVE-2010-4756, CVE-2018-20796, CVE-2019-1010022, CVE-2019-1010023, CVE-2019-1010024, CVE-2019-1010025, CVE-2019-9192), libc-bin-2.31-13+deb11u5 (CVE-2010-4756, CVE-2018-20796, CVE-2019-1010022, CVE-2019-1010023, CVE-2019-1010024, CVE-2019-1010025, CVE-2019-9192), libpcre3-2:8.39-13 (CVE-2017-11164, CVE-2017-16231, CVE-2017-7245, CVE-2017-7246, CVE-2019-20838), libexpat1-2.2.10-2+deb11u5 (CVE-2013-0340, CVE-2023-52426, CVE-2024-28757), perl-base-5.32.1-4+deb11u2 (CVE-2011-4116, CVE-2023-31486), util-linux-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), passwd-1:4.8.1-1 (CVE-2007-5686, CVE-2013-4235, TEMP-0628843-DBAD28), tar-1.34+dfsg-1 (CVE-2005-2541, TEMP-0290435-0B57B5), bash-5.1-2+deb11u1 (TEMP-0841856-B18BAF), libuuid1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libgcrypt20-1.8.7-6 (CVE-2018-6829, CVE-2024-2236), libpcre2-8-0-10.36-2+deb11u1 (CVE-2022-41409), libgnutls30-3.7.1-5+deb11u2 (CVE-2011-3389), libgssapi-krb5-2-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), libssl1.1-1.1.1n-0+deb11u3 (CVE-2025-27587), libkrb5support0-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), gpgv-2.2.27-2+deb11u2 (CVE-2022-3219), libsqlite3-0-3.34.1-3 (CVE-2021-45346, CVE-2022-35737, CVE-2025-29088, CVE-2025-70873), bsdutils-1:2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), coreutils-8.32-4+b1 (CVE-2017-18018, CVE-2025-5278, CVE-2026-56391, CVE-2026-56392), libgcc-s1-10.2.1-6 (CVE-2023-4039), sysvinit-utils-2.96-7+deb11u1 (TEMP-0517018-A83CE6), libsmartcols1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libk5crypto3-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), libkrb5-3-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), gcc-9-base-9.3.0-22 (CVE-2023-4039), openssl-1.1.1n-0+deb11u3 (CVE-2025-27587), libmount1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libudev1-247.3-7+deb11u1 (CVE-2013-4392, CVE-2020-13529, CVE-2023-31437, CVE-2023-31438, CVE-2023-31439), libstdc++6-10.2.1-6 (CVE-2023-4039), libsystemd0-247.3-7+deb11u1 (CVE-2013-4392, CVE-2020-13529, CVE-2023-31437, CVE-2023-31438, CVE-2023-31439), mount-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), diffutils-1:3.7-5 (CVE-2026-53910), apt-2.2.4 (CVE-2011-3374), login-1:4.8.1-1 (CVE-2007-5686, CVE-2013-4235, TEMP-0628843-DBAD28)", "name": "clair_unpatched_low_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 96 } }, { "msg": "Found packages with unpatched unknown vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: ncurses-bin-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), libblkid1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libc6-2.31-13+deb11u5 (CVE-2023-4806, CVE-2023-4813, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238, CVE-2026-6368, CVE-2026-6791), libc-bin-2.31-13+deb11u5 (CVE-2023-4806, CVE-2023-4813, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238, CVE-2026-6368, CVE-2026-6791), libpam-modules-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), libpam0g-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), libexpat1-2.2.10-2+deb11u5 (CVE-2024-8176, CVE-2025-59375, CVE-2025-66382, CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-41080, CVE-2026-45186, CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412, CVE-2026-72522), libpam-runtime-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), perl-base-5.32.1-4+deb11u2 (CVE-2025-15649, CVE-2026-12087, CVE-2026-13221, CVE-2026-15534, CVE-2026-19487, CVE-2026-42496, CVE-2026-42497, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432, CVE-2026-57433, CVE-2026-7010, CVE-2026-7017, CVE-2026-8376, CVE-2026-9538), util-linux-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libncursesw6-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), passwd-1:4.8.1-1 (CVE-2024-56433), libattr1-1:2.4.48-6 (CVE-2026-54371), tar-1.34+dfsg-1 (CVE-2026-18477, CVE-2026-18508, CVE-2026-5704), bash-5.1-2+deb11u1 (CVE-2022-3715), libuuid1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libacl1-2.2.53-10 (CVE-2026-54369, CVE-2026-54370), libgcrypt20-1.8.7-6 (CVE-2021-33560), libp11-kit0-0.23.22-1 (CVE-2026-13757, CVE-2026-18938), libbz2-1.0-1.0.8-4 (CVE-2026-42250), libssl1.1-1.1.1n-0+deb11u3 (CVE-2026-14456), gpgv-2.2.27-2+deb11u2 (CVE-2025-30258, CVE-2025-68972), sed-4.7-1 (CVE-2026-5958), gzip-1.10-4+deb11u1 (CVE-2026-41991, CVE-2026-41992), zlib1g-1:1.2.11.dfsg-2+deb11u2 (CVE-2023-45853, CVE-2026-27171), libtinfo6-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), libsqlite3-0-3.34.1-3 (CVE-2025-6965, CVE-2026-11822, CVE-2026-11824, CVE-2026-50812, CVE-2026-50813), bsdutils-1:2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libzstd1-1.4.8+dfsg-2.1 (CVE-2022-4899), ncurses-base-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), libpam-modules-bin-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), libsmartcols1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libtasn1-6-4.16.0-2 (CVE-2025-13151), openssl-1.1.1n-0+deb11u3 (CVE-2026-14456), libmount1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libudev1-247.3-7+deb11u1 (CVE-2026-16742, CVE-2026-40228), libsystemd0-247.3-7+deb11u1 (CVE-2026-16742, CVE-2026-40228), mount-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), login-1:4.8.1-1 (CVE-2024-56433), libdb5.3-5.3.28+dfsg1-0.8 (CVE-2019-8457)", "name": "clair_unpatched_unknown_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 149 } } ] } ] {"vulnerabilities":{"critical":0,"high":0,"medium":1,"low":0,"unknown":0},"unpatched_vulnerabilities":{"critical":0,"high":0,"medium":1,"low":96,"unknown":149}} {"image": {"pullspec": "quay.io/redhat-appstudio-qe/build-e2e-sample-python-basic-oci-docker-build-oci-ta/component-sample-python-basic-oci-docker-build-oci-ta:on-pr-2cdd280aa3d81cedf77cdc231df2786d9db120d6", "digests": ["sha256:bf82bd63ce8e9ed740ec230ee92ea74f62db9ab9f69cd64e64063309fc2a15a0"]}} {"result":"SUCCESS","timestamp":"2026-08-18T08:08:42+00:00","note":"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.","namespace":"default","successes":0,"failures":0,"warnings":0}