🛡️ Security Scan Report

Trivy Vulnerability & Secret Scanner
Service: ha-process-engine
Branch: feature/dev-2
Build: #139
Date: 2026-02-23 18:33:45

0

Critical

1

High

1

Medium

0

Low

5

Secrets

1

Misconfig

🔴 Vulnerabilities (1)
SeverityCVE IDPackageInstalledFixed InDescription
MEDIUM CVE-2025-66614 org.apache.tomcat.embed:tomcat-embed-core 10.1.47 11.0.14, 10.1.49, 9.0.112 tomcat: Client certificate verification bypass due to virtual host mapping
🔑 Secrets (5)
TypeFileLineMatch
AWS .env 16 # S3_ACCESS_ID=********************...
AWS security-reports/gitleaks-report.json 93 "Match": "********************",...
AWS security-reports/gitleaks-report.json 94 "Secret": "********************",...
AWS security-reports/gitleaks-report.json 114 "Match": "********************",...
AWS security-reports/gitleaks-report.json 115 "Secret": "********************",...
⚙️ Misconfigurations (1)
SeverityIDCheckFileMessage
HIGH DS-0002 Image user should not be 'root' Dockerfile Specify at least 1 USER command in Dockerfile with non-root user as argument
📄 Raw JSON Report (click to expand)