db: database age 2.3 days; UpdatedAt=2026-09-08T19:09:56.811508+00:00 java-db: database age 2.0 days; UpdatedAt=2026-09-09T01:11:59.619689+00:00 2026-09-11T03:43:14+02:00 INFO [vuln] Vulnerability scanning is enabled 2026-09-11T03:43:16+02:00 WARN Third-party SBOM may lead to inaccurate vulnerability detection 2026-09-11T03:43:16+02:00 WARN Recommend using Trivy to generate SBOMs 2026-09-11T03:43:16+02:00 INFO [python] Licenses acquired from one or more METADATA files may be subject to additional terms. Use `--debug` flag to see all affected packages. 2026-09-11T03:43:18+02:00 INFO Detected OS family="debian" version="12.15" 2026-09-11T03:43:18+02:00 INFO [debian] Detecting vulnerabilities... os_version="12" pkg_num=522 2026-09-11T03:43:18+02:00 INFO Number of language-specific files num=3 2026-09-11T03:43:18+02:00 INFO [jar] Detecting vulnerabilities... 2026-09-11T03:43:18+02:00 INFO [node-pkg] Detecting vulnerabilities... 2026-09-11T03:43:18+02:00 INFO [python-pkg] Detecting vulnerabilities... 2026-09-11T03:43:18+02:00 WARN Using severities from other vendors for some vulnerabilities. Read https://trivy.dev/docs/v0.74/guide/scanner/vulnerability#severity-selection for details. 2026-09-11T03:43:18+02:00 INFO [vuln] Vulnerability scanning is enabled 2026-09-11T03:43:20+02:00 INFO Detected OS family="debian" version="12.15" 2026-09-11T03:43:20+02:00 INFO [debian] Detecting vulnerabilities... os_version="12" pkg_num=522 2026-09-11T03:43:20+02:00 INFO Number of language-specific files num=3 2026-09-11T03:43:20+02:00 INFO [jar] Detecting vulnerabilities... 2026-09-11T03:43:20+02:00 INFO [node-pkg] Detecting vulnerabilities... 2026-09-11T03:43:20+02:00 INFO [python-pkg] Detecting vulnerabilities... 2026-09-11T03:43:20+02:00 WARN Using severities from other vendors for some vulnerabilities. Read https://trivy.dev/docs/v0.74/guide/scanner/vulnerability#severity-selection for details. 2026-09-11T03:43:20+02:00 WARN [cyclonedx] Unable to marshal SPDX licenses license="CDDL + GPLv2 with classpath exception" 2026-09-11T03:43:20+02:00 WARN [cyclonedx] Unable to marshal SPDX licenses license="CDDL + GPLv2 with classpath exception" 2026-09-11T03:43:20+02:00 WARN [cyclonedx] Unable to marshal SPDX licenses license="CDDL + GPLv2 with classpath exception" 2026-09-11T03:43:20+02:00 WARN [cyclonedx] Unable to marshal SPDX licenses license="CDDL + GPLv2 with classpath exception" Trivy gate exit: 1 [0011] ERROR discovered vulnerabilities at or above the severity threshold Grype gate exit: 2 Trivy High/Critical findings: 509 Grype High/Critical findings: 451 PASS: actual image archive scanned offline by both tools; nonempty SBOMs parsed. Findings are not release approval.