Victoriametrics 1.111

locked latest
Full version: 1.111.0 Analyzed: 2026-02-11
Size Reduction -165% 32.6 MB to 86.5 MB (-53.9 MB saved)
Component Reduction 0% 37 to 37 packages (0 removed)
Vulnerability Reduction 15% 34 to 29 vulnerabilities (5 eliminated)

Image Comparison

Propertyupstreamlocked
Imagedocker.io/victoriametrics/victoria-metrics:v1.111.0ghcr.io/armorred/victoriametrics:1.111.0-locked
Size32.6 MB86.5 MB
Layers316
Components3737
Vulnerabilities3429
Runtime Userroot999

Vulnerability Analysis

upstream 34 total
3high
4medium
2low
locked 29 total
2high
4medium
Upstream vulnerability details (34)
CVE IDSeverityPackageVersionFixed In
ALPINE-CVE-2024-58251lowbusybox1.37.0-r91.36.1-r21
ALPINE-CVE-2025-46394lowbusybox1.37.0-r91.36.1-r21
GO-2025-3503mediumgolang.org/x/netv0.34.00.36.0
GO-2025-3595mediumgolang.org/x/netv0.34.00.38.0
GO-2026-4440unknowngolang.org/x/netv0.34.00.45.0
GO-2026-4441unknowngolang.org/x/netv0.34.00.45.0
GHSA-qxp5-gwg8-xv66mediumgolang.org/x/netv0.34.00.36.0
GHSA-vvgc-356p-c3xwmediumgolang.org/x/netv0.34.00.38.0
GO-2025-3488highgolang.org/x/oauth2v0.25.00.27.0
GHSA-6v2p-p543-phr9highgolang.org/x/oauth2v0.25.00.27.0
ALPINE-CVE-2025-26519highmusl1.2.5-r81.2.3-r4
GO-2025-3447unknownstdlib1.23.51.22.12
GO-2025-3563unknownstdlib1.23.51.23.8
GO-2025-3750unknownstdlib1.23.51.23.10
GO-2025-3751unknownstdlib1.23.51.23.10
GO-2025-3849unknownstdlib1.23.51.23.12
GO-2025-3956unknownstdlib1.23.51.23.12
GO-2025-4006unknownstdlib1.23.51.24.8
GO-2025-4007unknownstdlib1.23.51.24.9
GO-2025-4008unknownstdlib1.23.51.24.8
GO-2025-4009unknownstdlib1.23.51.24.8
GO-2025-4010unknownstdlib1.23.51.24.8
GO-2025-4011unknownstdlib1.23.51.24.8
GO-2025-4012unknownstdlib1.23.51.24.8
GO-2025-4013unknownstdlib1.23.51.24.8
GO-2025-4014unknownstdlib1.23.51.24.8
GO-2025-4015unknownstdlib1.23.51.24.8
GO-2025-4155unknownstdlib1.23.51.24.11
GO-2025-4175unknownstdlib1.23.51.24.11
GO-2026-4337unknownstdlib1.23.51.24.13
GO-2026-4340unknownstdlib1.23.51.24.12
GO-2026-4341unknownstdlib1.23.51.24.12
GO-2026-4342unknownstdlib1.23.51.24.12
GO-2026-4403unknownstdlib1.23.51.23.9
Locked vulnerability details (29)
CVE IDSeverityPackageVersionFixed In
GO-2025-3503mediumgolang.org/x/netv0.34.00.36.0
GO-2025-3595mediumgolang.org/x/netv0.34.00.38.0
GO-2026-4440unknowngolang.org/x/netv0.34.00.45.0
GO-2026-4441unknowngolang.org/x/netv0.34.00.45.0
GHSA-qxp5-gwg8-xv66mediumgolang.org/x/netv0.34.00.36.0
GHSA-vvgc-356p-c3xwmediumgolang.org/x/netv0.34.00.38.0
GO-2025-3488highgolang.org/x/oauth2v0.25.00.27.0
GHSA-6v2p-p543-phr9highgolang.org/x/oauth2v0.25.00.27.0
GO-2025-3750unknownstdlib1.23.81.23.10
GO-2025-3751unknownstdlib1.23.81.23.10
GO-2025-3849unknownstdlib1.23.81.23.12
GO-2025-3956unknownstdlib1.23.81.23.12
GO-2025-4006unknownstdlib1.23.81.24.8
GO-2025-4007unknownstdlib1.23.81.24.9
GO-2025-4008unknownstdlib1.23.81.24.8
GO-2025-4009unknownstdlib1.23.81.24.8
GO-2025-4010unknownstdlib1.23.81.24.8
GO-2025-4011unknownstdlib1.23.81.24.8
GO-2025-4012unknownstdlib1.23.81.24.8
GO-2025-4013unknownstdlib1.23.81.24.8
GO-2025-4014unknownstdlib1.23.81.24.8
GO-2025-4015unknownstdlib1.23.81.24.8
GO-2025-4155unknownstdlib1.23.81.24.11
GO-2025-4175unknownstdlib1.23.81.24.11
GO-2026-4337unknownstdlib1.23.81.24.13
GO-2026-4340unknownstdlib1.23.81.24.12
GO-2026-4341unknownstdlib1.23.81.24.12
GO-2026-4342unknownstdlib1.23.81.24.12
GO-2026-4403unknownstdlib1.23.81.23.9

Software Bill of Materials

upstream components (37)
  • alpine-baselayout 3.6.8-r1
  • alpine-baselayout-data 3.6.8-r1
  • alpine-keys 2.5-r0
  • alpine-release 3.21.2-r0
  • apk-tools 2.14.6-r2
  • busybox 1.37.0-r9
  • busybox-binsh 1.37.0-r9
  • ca-certificates-bundle 20241121-r1
  • cloud.google.com/go/compute/metadata v0.6.0
  • github.com/VictoriaMetrics/VictoriaMetrics UNKNOWN
  • github.com/VictoriaMetrics/easyproto v0.1.4
  • github.com/VictoriaMetrics/fastcache v1.12.2
  • github.com/VictoriaMetrics/metrics v1.35.1
  • github.com/VictoriaMetrics/metricsql v0.83.0
  • github.com/cespare/xxhash/v2 v2.3.0
  • github.com/golang/snappy v0.0.4
  • github.com/klauspost/compress v1.17.11
  • github.com/valyala/bytebufferpool v1.0.0
  • github.com/valyala/fastjson v1.6.4
  • github.com/valyala/fastrand v1.1.0
  • github.com/valyala/fasttemplate v1.2.2
  • github.com/valyala/gozstd v1.21.2
  • github.com/valyala/histogram v1.2.0
  • github.com/valyala/quicktemplate v1.8.0
  • golang.org/x/net v0.34.0
  • golang.org/x/oauth2 v0.25.0
  • golang.org/x/sys v0.29.0
  • golang.org/x/text v0.21.0
  • gopkg.in/yaml.v2 v2.4.0
  • libcrypto3 3.3.2-r4
  • libssl3 3.3.2-r4
  • musl 1.2.5-r8
  • musl-utils 1.2.5-r8
  • scanelf 1.3.8-r1
  • ssl_client 1.37.0-r9
  • stdlib go1.23.5
  • zlib 1.3.1-r2
locked components (37)
  • acl 2.3.2
  • attr 2.5.2
  • cloud.google.com/go/compute/metadata v0.6.0
  • coreutils-full 9.5
  • gcc 13.3.0
  • gcc 13.3.0
  • github.com/VictoriaMetrics/VictoriaMetrics UNKNOWN
  • github.com/VictoriaMetrics/easyproto v0.1.4
  • github.com/VictoriaMetrics/fastcache v1.12.2
  • github.com/VictoriaMetrics/metrics v1.35.1
  • github.com/VictoriaMetrics/metricsql v0.83.0
  • github.com/cespare/xxhash/v2 v2.3.0
  • github.com/golang/snappy v0.0.4
  • github.com/klauspost/compress v1.17.11
  • github.com/valyala/bytebufferpool v1.0.0
  • github.com/valyala/fastjson v1.6.4
  • github.com/valyala/fastrand v1.1.0
  • github.com/valyala/fasttemplate v1.2.2
  • github.com/valyala/gozstd v1.21.2
  • github.com/valyala/histogram v1.2.0
  • github.com/valyala/quicktemplate v1.8.0
  • glibc 2.40-66
  • gmp-with-cxx 6.3.0
  • golang.org/x/net v0.34.0
  • golang.org/x/oauth2 v0.25.0
  • golang.org/x/sys v0.29.0
  • golang.org/x/text v0.21.0
  • gopkg.in/yaml.v2 v2.4.0
  • iana-etc 20240318
  • libidn2 2.3.7
  • libunistring 1.2
  • mailcap 2.1.54
  • openssl 3.3.3
  • stdlib go1.23.8
  • tzdata 2025b
  • victoriametrics 1.111.0
  • xgcc 13.3.0

Usage

$ podman pull ghcr.io/armorred/victoriametrics:1.111-locked

Verify Signature

$ cosign verify --key https://armorred.org/cosign.pub ghcr.io/armorred/victoriametrics:1.111-locked