[ { "filename": "/tekton/home/clair-result-amd64.json", "namespace": "required_checks", "successes": 6, "warnings": [ { "msg": "Found packages with medium vulnerabilities associated with RHSA fixes. Consider updating to a newer version of those packages, they may no longer be affected by the reported CVEs.", "metadata": { "details": { "description": "Vulnerabilities found: pip-22.3.1 (GHSA-wf93-45jw-7689)", "name": "clair_medium_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 1 } }, { "msg": "Found packages with unpatched medium vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: coreutils-8.32-4+b1 (CVE-2016-2781)", "name": "clair_unpatched_medium_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 1 } }, { "msg": "Found packages with unpatched low/negligible vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: coreutils-8.32-4+b1 (CVE-2017-18018, CVE-2025-5278, CVE-2026-56391, CVE-2026-56392), mount-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libssl1.1-1.1.1n-0+deb11u3 (CVE-2025-27587), libmount1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libgssapi-krb5-2-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), libsystemd0-247.3-7+deb11u1 (CVE-2013-4392, CVE-2020-13529, CVE-2023-31437, CVE-2023-31438, CVE-2023-31439), libuuid1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libc6-2.31-13+deb11u5 (CVE-2010-4756, CVE-2018-20796, CVE-2019-1010022, CVE-2019-1010023, CVE-2019-1010024, CVE-2019-1010025, CVE-2019-9192), libapt-pkg6.0-2.2.4 (CVE-2011-3374), libgcc-s1-10.2.1-6 (CVE-2023-4039), libudev1-247.3-7+deb11u1 (CVE-2013-4392, CVE-2020-13529, CVE-2023-31437, CVE-2023-31438, CVE-2023-31439), login-1:4.8.1-1 (CVE-2007-5686, CVE-2013-4235, TEMP-0628843-DBAD28), openssl-1.1.1n-0+deb11u3 (CVE-2025-27587), libsmartcols1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libkrb5support0-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), perl-base-5.32.1-4+deb11u2 (CVE-2011-4116, CVE-2023-31486), libexpat1-2.2.10-2+deb11u5 (CVE-2013-0340, CVE-2023-52426, CVE-2024-28757), libblkid1-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), gcc-9-base-9.3.0-22 (CVE-2023-4039), libstdc++6-10.2.1-6 (CVE-2023-4039), libpcre2-8-0-10.36-2+deb11u1 (CVE-2022-41409), util-linux-2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), libkrb5-3-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), libsqlite3-0-3.34.1-3 (CVE-2021-45346, CVE-2022-35737, CVE-2025-29088, CVE-2025-70873), libgnutls30-3.7.1-5+deb11u2 (CVE-2011-3389), gcc-10-base-10.2.1-6 (CVE-2023-4039), libgcrypt20-1.8.7-6 (CVE-2018-6829, CVE-2024-2236), diffutils-1:3.7-5 (CVE-2026-53910), apt-2.2.4 (CVE-2011-3374), passwd-1:4.8.1-1 (CVE-2007-5686, CVE-2013-4235, TEMP-0628843-DBAD28), gpgv-2.2.27-2+deb11u2 (CVE-2022-3219), libpcre3-2:8.39-13 (CVE-2017-11164, CVE-2017-16231, CVE-2017-7245, CVE-2017-7246, CVE-2019-20838), bash-5.1-2+deb11u1 (TEMP-0841856-B18BAF), tar-1.34+dfsg-1 (CVE-2005-2541, TEMP-0290435-0B57B5), libk5crypto3-1.18.3-6+deb11u3 (CVE-2018-5709, CVE-2024-26458, CVE-2024-26461, CVE-2026-11850), bsdutils-1:2.36.1-8+deb11u1 (CVE-2022-0563, CVE-2025-14104), sysvinit-utils-2.96-7+deb11u1 (TEMP-0517018-A83CE6), libc-bin-2.31-13+deb11u5 (CVE-2010-4756, CVE-2018-20796, CVE-2019-1010022, CVE-2019-1010023, CVE-2019-1010024, CVE-2019-1010025, CVE-2019-9192)", "name": "clair_unpatched_low_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 96 } }, { "msg": "Found packages with unpatched unknown vulnerabilities. These vulnerabilities don't have a known fix at this time.", "metadata": { "details": { "description": "Vulnerabilities found: mount-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libssl1.1-1.1.1n-0+deb11u3 (CVE-2026-14456), libmount1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libpam0g-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), libbz2-1.0-1.0.8-4 (CVE-2026-42250), libsystemd0-247.3-7+deb11u1 (CVE-2026-40228), libuuid1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libc6-2.31-13+deb11u5 (CVE-2023-4806, CVE-2023-4813, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238, CVE-2026-6368, CVE-2026-6791), libpam-modules-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), libacl1-2.2.53-10 (CVE-2026-54369, CVE-2026-54370), zlib1g-1:1.2.11.dfsg-2+deb11u2 (CVE-2023-45853, CVE-2026-27171), libudev1-247.3-7+deb11u1 (CVE-2026-40228), libpam-runtime-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), login-1:4.8.1-1 (CVE-2024-56433), openssl-1.1.1n-0+deb11u3 (CVE-2026-14456), libsmartcols1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), sed-4.7-1 (CVE-2026-5958), libpam-modules-bin-1.4.0-9+deb11u1 (CVE-2024-10041, CVE-2025-8941, CVE-2026-54411), perl-base-5.32.1-4+deb11u2 (CVE-2025-15649, CVE-2026-12087, CVE-2026-13221, CVE-2026-15534, CVE-2026-19487, CVE-2026-42496, CVE-2026-42497, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432, CVE-2026-57433, CVE-2026-7010, CVE-2026-7017, CVE-2026-8376, CVE-2026-9538), libexpat1-2.2.10-2+deb11u5 (CVE-2024-8176, CVE-2025-59375, CVE-2025-66382, CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778, CVE-2026-41080, CVE-2026-45186, CVE-2026-50219, CVE-2026-56131, CVE-2026-56132, CVE-2026-56403, CVE-2026-56404, CVE-2026-56405, CVE-2026-56406, CVE-2026-56407, CVE-2026-56408, CVE-2026-56409, CVE-2026-56410, CVE-2026-56411, CVE-2026-56412, CVE-2026-72522), libblkid1-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), util-linux-2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), ncurses-base-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), libsqlite3-0-3.34.1-3 (CVE-2025-6965, CVE-2026-11822, CVE-2026-11824, CVE-2026-50812, CVE-2026-50813), libgcrypt20-1.8.7-6 (CVE-2021-33560), libattr1-1:2.4.48-6 (CVE-2026-54371), ncurses-bin-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), libdb5.3-5.3.28+dfsg1-0.8 (CVE-2019-8457), libncursesw6-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), passwd-1:4.8.1-1 (CVE-2024-56433), gpgv-2.2.27-2+deb11u2 (CVE-2025-30258, CVE-2025-68972), bash-5.1-2+deb11u1 (CVE-2022-3715), libp11-kit0-0.23.22-1 (CVE-2026-13757, CVE-2026-18938), gzip-1.10-4+deb11u1 (CVE-2026-41991, CVE-2026-41992), libtasn1-6-4.16.0-2 (CVE-2025-13151), tar-1.34+dfsg-1 (CVE-2026-18477, CVE-2026-18508, CVE-2026-5704), libzstd1-1.4.8+dfsg-2.1 (CVE-2022-4899), bsdutils-1:2.36.1-8+deb11u1 (CVE-2026-13595, CVE-2026-27456, CVE-2026-3184, CVE-2026-53613, CVE-2026-53615), libtinfo6-6.2+20201114-2 (CVE-2023-50495, CVE-2025-6141, CVE-2025-69720), libc-bin-2.31-13+deb11u5 (CVE-2023-4806, CVE-2023-4813, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238, CVE-2026-6368, CVE-2026-6791)", "name": "clair_unpatched_unknown_vulnerabilities", "url": "https://access.redhat.com/articles/red_hat_vulnerability_tutorial" }, "vulnerabilities_number": 147 } } ] } ] {"vulnerabilities":{"critical":0,"high":0,"medium":1,"low":0,"unknown":0},"unpatched_vulnerabilities":{"critical":0,"high":0,"medium":1,"low":96,"unknown":147}} {"image": {"pullspec": "quay.io/redhat-appstudio-qe/build-e2e-sample-python-basic-oci-docker-build-oci-ta/component-sample-python-basic-oci-docker-build-oci-ta:on-pr-5d26d4e33cbde6eebe29a8a7325ba5c8c70f75a9", "digests": ["sha256:8b5734b2fa55602bcdd5600e4f6a2524e6631ac5f2423c695c4d4ab0ec82b9fd"]}} {"result":"SUCCESS","timestamp":"2026-08-17T06:58:53+00:00","note":"Task clair-scan completed: Refer to Tekton task result SCAN_OUTPUT for vulnerabilities scanned by Clair.","namespace":"default","successes":0,"failures":0,"warnings":0}