Package
cloudbeat-fips-8.17
Component
github.com/aquasecurity/trivy
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
cloudbeat 8.17.10 pins trivy's pre-0.71 two-argument artifact.NewRunner API. The fix for this vulnerability is trivy >= 0.71.0, which changed that signature to require a TargetKind argument. Upstream cloudbeat adopted the new API only from the 9.2 line; 8.17.10 is the latest release in its stream, so the fix cannot be consumed without a source patch. Pending upstream backport.
Status