Skip to content

ReferenceThe 22 checks

Known vulnerabilities

Security checkvulnerabilities

What it reads

System packages and container images, checked by Trivy if it is already installed. Kiyesi never downloads Trivy or its database during a scan.

Does it need root?

It needs root for part of what it reads. Trivy needs root to read every system package and the Docker socket. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • No critical vulnerability with a fix available

What it can find

Warning

count critical vulnerabilities with a fix available in this server's packages

These flaws are public and already fixed. Installing the updates closes them.

Fix
sudo apt-get update && sudo apt-get upgrade
Warning

count critical vulnerabilities with a fix available in image image

These flaws are public and already fixed in newer packages for this image.

Fix
Update the base image of image, rebuild it, and restart its containers

When it is skipped

A skipped check never counts as passed. The report says why, in one of these sentences:

  • Trivy is not installed. Install Trivy 0.74.0 or newer to check
  • Trivy has no vulnerability database here, and Kiyesi never downloads one during a scan. Run trivy image --download-db-only once, then scan again
  • Trivy version is a compromised release from March 2026. Remove it and install 0.74.0 or newer
  • Trivy could not finish: reason