count critical vulnerabilities with a fix available in this server's packages
These flaws are public and already fixed. Installing the updates closes them.
sudo apt-get update && sudo apt-get upgradeReferenceThe 22 checks
Security checkvulnerabilities
System packages and container images, checked by Trivy if it is already installed. Kiyesi never downloads Trivy or its database during a scan.
It needs root for part of what it reads. Trivy needs root to read every system package and the Docker socket. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.
The report lists it as passed, in these words:
count critical vulnerabilities with a fix available in this server's packages
These flaws are public and already fixed. Installing the updates closes them.
sudo apt-get update && sudo apt-get upgradecount critical vulnerabilities with a fix available in image image
These flaws are public and already fixed in newer packages for this image.
Update the base image of image, rebuild it, and restart its containersA skipped check never counts as passed. The report says why, in one of these sentences: