
Minimus advisories showing affected images and packages, severity, status, etc.
Affected images only refer to production images. Development image variants (for example, an image tagged
latest-dev) are excluded by default.Refer to version-specific vulnerability reports for information about vulnerabilities affecting development images. Learn moreOverview
Before you dive into the details, examine the metrics in the top section:- Total number of new vulnerabilities detected in the past 7 days in Minimus packages
- Total number of vulnerabilities detected over the past year in Minimus packages that are currently known as active exploits (i.e. they are on the CISA KEV list)
- Total number of vulnerabilities detected over the past year in Minimus images that are currently labeled as likely exploits (i.e. they have a high EPSS probability score and are likely targets for exploitation).
- Total number of critical severity vulnerabilities detected over the past year in Minimus images.
Advisories table
The advisories table lists all affected packages. Some vulnerabilities affect multiple packages, so you will notice the same vulnerability listed on a separate line for each impacted package. When the affected package is mapped to a Minimus image, the image information and fixed version will appear as well. The advisories table shows the following:The detection timestamp indicating when the scanner first flagged the vulnerability is shown in the advisory drill down window. The detection date may be after the package was already fixed, as in a silent fix.
Filtering, searching, and sorting advisories
- Filtering options You can filter the advisories list by affected images, severity, exploitability, status, detection date and last update. The filters are friendly UI elements, and do not require complex syntax. The Affected Images filter has the following options:
- My images (Default)
- Any
- Specific images (Searchable list of images)
- Remove this filter to include also advisories for packages that are not mapped to any image.
- Search options You can search the advisories by a full or partial vulnerability ID and/or a package and image name. You can combine search terms with filtering criteria.
- Sorting options You may sort the advisories by their severity and last update.
Drill down on an advisory
Click on an advisory in the table to view its detailed listing. When drilling down from the advisories table, two filters are applied by default for the origin package and specific affected package.