🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: UI_platfrom1
Branch: feature/vulnerabilities-scan1
Build: #81
Date: 2026-02-13 17:56:18

0

Critical

4

High

4

Medium

0

Low

0

Secrets

5

Misconfig

🔴 Vulnerabilities (3)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-13465 lodash 4.17.21 4.17.23 lodash: prototype pollution in _.unset and _.omit functions
MEDIUM CVE-2025-30359 webpack-dev-server 4.15.2 5.2.1 webpack-dev-server: webpack-dev-server information exposure
MEDIUM CVE-2025-30360 webpack-dev-server 4.15.2 5.2.1 webpack-dev-server: webpack-dev-server information exposure
🔑 Secrets (0)
TypeFileLineMatch
✅ No secrets found
⚙️ Misconfigurations (5)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
MEDIUM DS-0001 ':latest' tag used node_modules/@surma/rollup-plugin-off-main-thread/Dockerfile Specify a tag in the 'FROM' statement for image 'selenium/node-chrome'
HIGH DS-0002 Image user should not be 'root' node_modules/@surma/rollup-plugin-off-main-thread/Dockerfile Last USER command in Dockerfile should not be 'root'
HIGH DS-0017 'RUN update' instruction alone node_modules/@surma/rollup-plugin-off-main-thread/Dockerfile The instruction 'RUN update' should always be followed by ' insta
HIGH DS-0002 Image user should not be 'root' node_modules/jsonpath/Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)