ghcr.io/cyclonedx/cdxgen:master (alma 10.1)¶
Trivy Image Scan
- Image:
ghcr.io/cyclonedx/cdxgen:master (alma 10.1) - Scan date: 2026-04-24
ghcr.io/cyclonedx/cdxgen:master (alma 10.1) (alma)¶
Java (jar)¶
Node.js (node-pkg)¶
Python (python-pkg)¶
| Package | Vulnerability ID | Severity | Installed Version | Fixed Version | Links |
|---|---|---|---|---|---|
| poetry | CVE-2026-41140 | LOW | 2.3.3 | 2.3.4 | https://github.com/python-poetry/poetry https://github.com/python-poetry/poetry/releases/tag/2.3.4 https://github.com/python-poetry/poetry/security/advisories/GHSA-73h3-mf4w-8647 |
| uv | GHSA-pjjw-68hj-v9mw | LOW | 0.11.5 | 0.11.6 | https://github.com/astral-sh/uv https://github.com/astral-sh/uv/commit/7983c7a5bef236fd8a04580fcedae7bd5bde4cdb https://github.com/astral-sh/uv/commit/a0e461ac44851f9a0f6e8974733e77d46f7a9ea9 https://github.com/astral-sh/uv/pull/18942 https://github.com/astral-sh/uv/pull/18943 https://github.com/astral-sh/uv/releases/tag/0.11.6 https://github.com/astral-sh/uv/security/advisories/GHSA-pjjw-68hj-v9mw |
| No Misconfigurations found | |||||
Ruby (gemspec)¶
opt/cdxgen/node_modules/.pnpm/@appthreat+atom-parsetools@1.1.3/node_modules/@appthreat/atom-parsetools/plugins/composer/installed.json (composer-vendor)¶
| No Vulnerabilities found | |||||
|---|---|---|---|---|---|
| No Misconfigurations found |
opt/cdxgen/node_modules/.pnpm/@cdxgen+cdxgen-plugins-bin-linux-amd64@2.0.3/node_modules/@cdxgen/cdxgen-plugins-bin-linux-amd64/plugins/sourcekitten/sbom-trivy-postbuild.cdx.json (gobinary)¶
opt/pypi/bin/uv (rustbinary)¶
| Package | Vulnerability ID | Severity | Installed Version | Fixed Version | Links |
|---|---|---|---|---|---|
| rand | GHSA-cq8v-f236-94qc | LOW | 0.8.5 | 0.9.3, 0.10.1, 0.8.6 | https://github.com/rust-random/rand https://github.com/rust-random/rand/pull/1763 https://rustsec.org/advisories/RUSTSEC-2026-0097.html |
| rand | GHSA-cq8v-f236-94qc | LOW | 0.9.2 | 0.9.3, 0.10.1, 0.8.6 | https://github.com/rust-random/rand https://github.com/rust-random/rand/pull/1763 https://rustsec.org/advisories/RUSTSEC-2026-0097.html |
| rustls-webpki | GHSA-965h-392x-2mh5 | LOW | 0.103.10 | 0.103.12, 0.104.0-alpha.6 | https://github.com/rustls/webpki https://github.com/rustls/webpki/security/advisories/GHSA-965h-392x-2mh5 https://rustsec.org/advisories/RUSTSEC-2026-0098.html |
| rustls-webpki | GHSA-xgp8-3hg3-c2mh | LOW | 0.103.10 | 0.103.12, 0.104.0-alpha.6 | https://github.com/rustls/webpki https://github.com/rustls/webpki/security/advisories/GHSA-xgp8-3hg3-c2mh https://rustsec.org/advisories/RUSTSEC-2026-0099.html |
| No Misconfigurations found | |||||
opt/pypi/bin/uvx (rustbinary)¶
| Package | Vulnerability ID | Severity | Installed Version | Fixed Version | Links |
|---|---|---|---|---|---|
| rand | GHSA-cq8v-f236-94qc | LOW | 0.8.5 | 0.9.3, 0.10.1, 0.8.6 | https://github.com/rust-random/rand https://github.com/rust-random/rand/pull/1763 https://rustsec.org/advisories/RUSTSEC-2026-0097.html |
| rand | GHSA-cq8v-f236-94qc | LOW | 0.9.2 | 0.9.3, 0.10.1, 0.8.6 | https://github.com/rust-random/rand https://github.com/rust-random/rand/pull/1763 https://rustsec.org/advisories/RUSTSEC-2026-0097.html |
| rustls-webpki | GHSA-965h-392x-2mh5 | LOW | 0.103.10 | 0.103.12, 0.104.0-alpha.6 | https://github.com/rustls/webpki https://github.com/rustls/webpki/security/advisories/GHSA-965h-392x-2mh5 https://rustsec.org/advisories/RUSTSEC-2026-0098.html |
| rustls-webpki | GHSA-xgp8-3hg3-c2mh | LOW | 0.103.10 | 0.103.12, 0.104.0-alpha.6 | https://github.com/rustls/webpki https://github.com/rustls/webpki/security/advisories/GHSA-xgp8-3hg3-c2mh https://rustsec.org/advisories/RUSTSEC-2026-0099.html |
| No Misconfigurations found | |||||