Docker Scout health grade shows “A” despite outstanding vulnerabilities
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 32/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- docker
- Domain
- security
Research direction
Reproduce the result in the Docker Scout UI for dellhpcomniaaisolution/ubuntu-ldms:1.0 on linux/amd64, comparing the Health badge with the vulnerability panel and listed fixable CVEs. Trace how the health score is calculated and refreshed after vulnerability detection. Done means the grade and policy-related result account for the relevant outstanding vulnerabilities instead of showing A misleadingly.
Written by the indexing model from the issue text.
Description
Environment: Docker Hub / Docker Scout UI for image dellhpcomniaaisolution/ubuntu-ldms:1.0 (linux/amd64, based on ubuntu:24.04).
Issue: The Health badge at the top of the image view shows grade A, even though the vulnerability panel lists 968 total vulnerabilities (0 Critical, 3 High, 860 Medium, 44 Low) and highlights multiple fixable CVEs (e.g., CVE-2025-38666, CVE-2025-24049, CVE-2025-68973).
Expectation: Health grade should degrade from “A” when dozens/hundreds of Medium/Low issues exist, especially when Docker Scout marks them fixable.
Impact: Health grade misleads users into thinking the image is compliant; policy checks or automated gates that rely on the badge will incorrectly pass.
Please investigate how health scoring is calculated; it appears to ignore medium/low issues entirely or is not updated after new CVEs are detected.
- Dominant language
- Shell
- Stars
- 454
- Forks
- 134
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker/scout-cli
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
allstar
Difficulty 2/5 1-3 hours Newbie friendliness 45/100
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar exists Open
Difficulty 4/5 3-5 days Newbie friendliness 64/100
All issues in docker/scout-cli
Similar issues
-
docs(agents): strengthen the no-backslash-escaped-backticks rule with an issue-creation example Open
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
package-update
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
oSoWoSo/vOid_Community_repOsitory#148 · 1 comment ·
-
chore
Difficulty 1/5 Under an hour Newbie friendliness 91/100
alunduil/alunduil-chezmoi#792 ·
-
area: compat bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
zenhub-dev
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
OpenLiberty/ci.docker#747 ·