FROM ghcr.io/openclaw/openclaw@sha256:... + apt-get upgrade -- no app-code changes. Same
pattern as patched-images/fireflyiii-core.
Upstream (Debian 12/bookworm base) scanned at 136 HIGH/CRITICAL findings across two
targets: 109 OS-level Debian packages (16 fixed, the rest with no fix yet) and 27 Node.js/
npm findings (all fixed upstream, but in OpenClaw's own lockfile -- not something
apt-get upgrade touches, and out of scope for a patch layer that doesn't change app code).
The apt-get upgrade layer clears the 16 fixable Debian findings, leaving 120 (54 unique
CVE IDs: Debian tracker gaps + the 27 Node.js findings) documented in
trivyignore-entries.yml.
Used by home-k8s-config's openclaw_image.
Content type
Image
Digest
sha256:89a50c09b…
Size
1 GB
Last updated
6 days ago
docker pull gschaetz/openclaw