MockzillaMockzilla

Security reports

Updated Sep 29, 2026·3 min read

Every build comes with a report on what that exact image holds. It covers only the code built into that image, so the report matches the version you pull.

Where to find it

Open the backend under Self-hosted and choose Security. It shows the newest build. To see another, pick it under Build.

Known vulnerabilities

The image's own code, scanned with govulncheck. Each finding shows its id, a summary, the module and version it was found in, and the version that fixes it. It also shows how close the image's code comes to it:

  • called: the image's code calls the affected function.
  • imported: the image imports the affected package, but does not call the affected function.
  • required: the affected module is in the build, but its affected package is not imported.

Next to a finding, we say what it means for this image: not affected, with the reason, or affected.

With nothing found, the report says how many modules were scanned.

The base it runs on

The packages the image's base installs, scanned on their own. Each finding shows the package, its version and the version that fixes it, with what we say about it. Some are marked as ones the distribution calls unimportant.

Components

Every component the image holds, for each platform, from its SBOM.

Release files

The files of the release the image was built from, each with its SHA-256.

Read it from the image

The image carries the same paperwork. List what it holds:

docker run --rm <image> about

Here <image> stands for your image and its version, such as <your-org>.registry.mockzilla.org/ci-payments:v2026.09.23.3. Then print one part by its name:

  • build: what the image is: its type, version, platform and license.
  • services: every service, and whether this image includes it.
  • sbom: the software bill of materials, as CycloneDX.
  • spdx: the same, as SPDX.
  • vulns: known vulnerabilities in the image's Go modules, from govulncheck.
  • base-vulns: known vulnerabilities in the packages its base installs.
  • vex: what we say about each of them, as OpenVEX.
  • changes: what changed since the previous release.

For example:

docker run --rm <image> about vex

The same files ship next to the image in your registry, in each platform's folder.

See Pull your image.

Where to go next

Was this page helpful?