Scheduled CVE vulnerability scan of 5.x published images. #42
vulnerability-scan-schedule-5x.yml
on: schedule
Scan for vulnerabilities on 5.x images
/
setup-matrix
24s
Scan for vulnerabilities on 5.x images
/
set-sha-ref
5s
Matrix: Scan for vulnerabilities on 5.x images / vulnerability-scan
Annotations
19 errors and 7 warnings
Scan for vulnerabilities on 5.x images / vulnerability-scan (ci-builder)
2024-12-04T22:02:10Z INFO [vulndb] Need to update DB
2024-12-04T22:02:10Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:10Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:13Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:13Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:13Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:13Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/ci-builder:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/ci-builder:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/ci-builder:): failed to find image ghcr.io/dpc-sdp/bay/ci-builder:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/ci-builder/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (mariadb)
2024-12-04T22:02:10Z INFO [vulndb] Need to update DB
2024-12-04T22:02:10Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:10Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:13Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:13Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:13Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:13Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/mariadb:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/mariadb:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/mariadb:): failed to find image ghcr.io/dpc-sdp/bay/mariadb:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/mariadb/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (awx-ee)
2024-12-04T22:02:10Z INFO [vulndb] Need to update DB
2024-12-04T22:02:10Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:10Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:13Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:13Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:13Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:13Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/awx-ee:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/awx-ee:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/awx-ee:): failed to find image ghcr.io/dpc-sdp/bay/awx-ee:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/awx-ee/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (nginx)
2024-12-04T22:02:10Z INFO [vulndb] Need to update DB
2024-12-04T22:02:10Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:10Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:13Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:13Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:13Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:13Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:14Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/nginx:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/nginx:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/nginx:): failed to find image ghcr.io/dpc-sdp/bay/nginx:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/nginx/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (php-cli)
2024-12-04T22:02:10Z INFO [vulndb] Need to update DB
2024-12-04T22:02:10Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:10Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:14Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:14Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:14Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:14Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:14Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:14Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/php-cli:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/php-cli:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/php-cli:): failed to find image ghcr.io/dpc-sdp/bay/php-cli:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/php-cli/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (node)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (node)
2024-12-04T22:02:11Z INFO [vulndb] Need to update DB
2024-12-04T22:02:11Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:11Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:14Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:14Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:14Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:14Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:14Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:14Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/node:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/node:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/node:): failed to find image ghcr.io/dpc-sdp/bay/node:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/node/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (elasticsearch)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (elasticsearch)
2024-12-04T22:02:11Z INFO [vulndb] Need to update DB
2024-12-04T22:02:11Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:11Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:15Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:15Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:15Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:15Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:15Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:15Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/elasticsearch:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/elasticsearch:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/elasticsearch:): failed to find image ghcr.io/dpc-sdp/bay/elasticsearch:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/elasticsearch/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (php-fpm)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (php-fpm)
2024-12-04T22:02:11Z INFO [vulndb] Need to update DB
2024-12-04T22:02:11Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:11Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:15Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:15Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:15Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:15Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:15Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:15Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/php-fpm:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/php-fpm:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/php-fpm:): failed to find image ghcr.io/dpc-sdp/bay/php-fpm:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/php-fpm/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (mailhog)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (mailhog)
2024-12-04T22:02:11Z INFO [vulndb] Need to update DB
2024-12-04T22:02:11Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:11Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:14Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:14Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:14Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:14Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:14Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:14Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/mailhog:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/mailhog:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/mailhog:): failed to find image ghcr.io/dpc-sdp/bay/mailhog:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/mailhog/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (php-fpm-exporter)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (php-fpm-exporter)
2024-12-04T22:02:12Z INFO [vulndb] Need to update DB
2024-12-04T22:02:12Z INFO [vulndb] Downloading vulnerability DB...
2024-12-04T22:02:12Z INFO [vulndb] Downloading artifact... repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:15Z INFO [vulndb] Artifact successfully downloaded repo="mirror.gcr.io/aquasec/trivy-db:2"
2024-12-04T22:02:15Z INFO [vuln] Vulnerability scanning is enabled
2024-12-04T22:02:15Z INFO [secret] Secret scanning is enabled
2024-12-04T22:02:15Z INFO [secret] If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-12-04T22:02:15Z INFO [secret] Please see also https://aquasecurity.github.io/trivy/v0.57/docs/scanner/secret#recommendation for faster secret detection
2024-12-04T22:02:15Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "ghcr.io/dpc-sdp/bay/php-fpm-exporter:" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (ghcr.io/dpc-sdp/bay/php-fpm-exporter:): Error response from daemon: invalid reference format
* containerd error: parse error: invalid reference format
* podman error: unable to inspect the image (ghcr.io/dpc-sdp/bay/php-fpm-exporter:): failed to find image ghcr.io/dpc-sdp/bay/php-fpm-exporter:: invalid reference format
* remote error: GET https://ghcr.io/v2/dpc-sdp/bay/php-fpm-exporter/manifests/latest: MANIFEST_UNKNOWN: manifest unknown
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (mailpit)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (mailpit)
The operation was canceled.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (ripple-static)
The job was canceled because "ci-builder" failed.
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (ripple-static)
The operation was canceled.
|
Scan for vulnerabilities on 5.x images / set-sha-ref
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Scan for vulnerabilities on 5.x images / setup-matrix
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (ci-builder)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (mariadb)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (awx-ee)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (nginx)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|
Scan for vulnerabilities on 5.x images / vulnerability-scan (php-cli)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
|