Skip to content

fix: resolve container scan findings - #66

Merged
GethosTheWalrus merged 1 commit into
mainfrom
fix/code-scanning-results
Aug 20, 2026
Merged

fix: resolve container scan findings#66
GethosTheWalrus merged 1 commit into
mainfrom
fix/code-scanning-results

Conversation

@GethosTheWalrus

Copy link
Copy Markdown
Owner

Summary

  • remove build-only packaging tools from the application virtual environment
  • remove the base image's system pip installation from the runtime stage
  • update scheduled OSV scanning to v2.5.0

Verification

  • built the updated container image successfully
  • verified application runtime imports and CLI startup
  • scanned the final image with Docker Scout: 0 critical, high, medium, or low vulnerabilities
  • verified Dependabot alerts and security updates are enabled for the repository

@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown

Security Scan Results

Updated for commit a06a13d after a security scan completed.

Scanner Check Result
OSV dependency scan success (details) OSV PR check completed; open details for vulnerability status.
CodeQL success (details) No open CodeQL alerts reported for this PR ref.
Docker Scout success (details) No open critical/high fixable container CVEs reported for this PR ref.

This comment is updated automatically as OSV, CodeQL, and Docker Scout finish for the PR.

@GethosTheWalrus
GethosTheWalrus merged commit ca5c2f9 into main Aug 20, 2026
18 checks passed
@GethosTheWalrus
GethosTheWalrus deleted the fix/code-scanning-results branch August 20, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant