🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: ha-process-engine4
Branch: feature/dev-2
Build: #126
Date: 2026-02-20 16:31:18

0

Critical

1

High

1

Medium

0

Low

5

Secrets

1

Misconfig

🔴 Vulnerabilities (1)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.47 11.0.14, 10.1.49, 9.0.112 tomcat: Client certificate verification bypass due to virtual host mapping
🔑 Secrets (5)
TypeFileLineMatch
AWS .env 16 # S3_ACCESS_ID=********************...
AWS security-reports/gitleaks-report.json 9 "Match": "********************",...
AWS security-reports/gitleaks-report.json 10 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 198 "Match": "********************",...
AWS security-reports/gitleaks-report.json 199 "Secret": "********************",...
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)