gitea/act_runner:0.2.11-dind-rootless container image
Docker HubScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.Docker Hub all tags of gitea/act_runner
gitea/act_runner:0.2.11-dind-rootless resolved to 6120b1165f3a, scanned 14 Sept 2026: 242 findings, 2 critical, 1 on KEV; deployed by 1 chart, among them act-runner.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
242 distinct on this digest
Findings for digest 6120b1165f3a as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-hrxh-6v49-42gf | google.golang.org/ | 1.82.1 |
| Low | ALPINE-CVE-2026-34743 | xz | 5.8.3-r0 |
| Low | GHSA-xmrv-pmrh-hhx2 | github.com/ | 1.7.8 |
| Low | GHSA-xmrv-pmrh-hhx2 | github.com/ | 1.65.0 |
| Low | GHSA-9m57-25v3-79x9 | golang.org/ | 0.52.0 |
| Low | GHSA-pwhc-rpq9-4c8w | github.com/ | 1.7.29 |
| Low | GHSA-x86f-5xw2-fm2r | github.com/ | no fix listed |
| Low | GO-2024-3333 | golang.org/ | 0.33.0 |
| Low | GHSA-9h8m-3fm2-qjrq | go.opentelemetry.io/ | 1.40.0 |
| Low | GHSA-389r-gv7p-r3rp | github.com/ | 5.19.0 |
| Low | ALPINE-CVE-2024-11053 | curl | 8.11.1-r0 |
| Low | GHSA-2464-8j7c-4cjm | github.com/ | 2.4.0 |
| Low | GHSA-7236-3392-c5c6 | github.com/ | 0.31.1 |
| Low | GHSA-m6hq-p25p-ffr2 | github.com/ | 1.7.29 |
| Low | GO-2026-4981 | stdlib | 1.25.10 |
| Low | GO-2025-3563 | stdlib | 1.23.8 |
| Low | GO-2026-4977 | stdlib | 1.25.10 |
| Low | GO-2026-4986 | stdlib | 1.25.10 |
| Low | GO-2026-4918 | stdlib | 1.25.10 |
| Low | GO-2026-4918 | golang.org/ | 0.53.0 |
| Low | GO-2026-4337 | stdlib | 1.24.13 |
| Low | GHSA-crhj-59gh-8x96 | github.com/ | 5.19.1 |
| Low | GHSA-36gq-35j3-p9r9 | github.com/ | 2.4.1 |
| Low | GO-2026-4601 | stdlib | 1.25.8 |
| Low | ALPINE-CVE-2025-4516 | python3 | 3.12.10-r1 |
| Low | GO-2026-5026 | stdlib | 1.25.13 |
| Low | GO-2026-5026 | golang.org/ | 0.55.0 |
| Low | GO-2025-3420 | stdlib | 1.22.11 |
| Low | GO-2026-4342 | stdlib | 1.24.12 |
| Low | GO-2025-3751 | stdlib | 1.23.10 |
| Low | ALPINE-CVE-2024-13176 | openssl | 3.3.2-r2 |
| Low | GHSA-2v4p-qf9q-27wj | google.golang.org/ | 1.82.2 |
| Low | GO-2025-4116 | golang.org/ | 0.43.0 |
| Low | GO-2026-4870 | stdlib | 1.25.9 |
| Low | GO-2025-4009 | stdlib | 1.24.8 |
| Low | GO-2026-4947 | stdlib | 1.25.9 |
| Low | GHSA-rg2x-37c3-w2rh | github.com/ | no fix listed |
| Low | GO-2025-4006 | stdlib | 1.24.8 |
| Low | GO-2026-5037 | stdlib | 1.25.11 |
| Low | GO-2026-4971 | stdlib | 1.25.10 |
| Low | GO-2026-5972 | stdlib | 1.25.13 |
| Low | GO-2026-6088 | stdlib | 1.25.13 |
| Low | GO-2026-6089 | stdlib | 1.25.13 |
| Low | GO-2026-6090 | stdlib | 1.25.13 |
| Low | ALPINE-CVE-2026-27171 | zlib | 1.3.2-r0 |
| Low | ALPINE-CVE-2026-32777 | expat | 2.7.5-r0 |
| Low | GO-2026-5038 | stdlib | 1.25.11 |
| Low | GO-2026-5942 | golang.org/ | 0.56.0 |
| Low | GHSA-qxp5-gwg8-xv66 | golang.org/ | 0.36.0 |
| Low | GO-2025-4012 | stdlib | 1.24.8 |
Used by
1 chart
| Chart | Version | Tag | Containers |
|---|---|---|---|
| act-runnergringolitoVerified publisher | 0.2.0 | 0.2.11-dind-rootless | 1 |
Counts are over the indexed charts’ latest versions, rendered with default values, and say nothing about images outside the indexed set.