9.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable dependency is pinned to a major version in the upstream source, and the fixed release is a semver-incompatible major bump requiring source changes that have not been made upstream — the latest upstream release still carries the affected version. Pending an upstream update that adopts the fixed dependency.
Status