Overview
Track unresolved Caddy image vulnerabilities after remediation pass 1 in issue #428.
Context
Caddy was upgraded from 2.10 to 2.10.2 and findings improved:
- Before (
2.10): 18 HIGH, 6 CRITICAL
- After (
2.10.2): 14 HIGH, 4 CRITICAL
Remaining HIGH/CRITICAL findings are in upstream Caddy binary dependencies.
Goals
- Verify whether newer Caddy tags further reduce unresolved CVEs
- Track upstream advisories and dependency fixes
- Recommend upgrade strategy (patch/minor/major) for deployer templates
Acceptance Criteria
Related
Overview
Track unresolved Caddy image vulnerabilities after remediation pass 1 in issue #428.
Context
Caddy was upgraded from
2.10to2.10.2and findings improved:2.10): 18 HIGH, 6 CRITICAL2.10.2): 14 HIGH, 4 CRITICALRemaining HIGH/CRITICAL findings are in upstream Caddy binary dependencies.
Goals
Acceptance Criteria
./scripts/pre-commit.shRelated