redisinsight

Patched
Databases & Caching from mirror.gcr.io/redis/redisinsight
Pull Reference
ghcr.io/verity-org/redis/redisinsight
docker pull ghcr.io/verity-org/redis/redisinsight
Copa-Patched Image

Patched in-place from the upstream image using Copa . OS-level vulnerabilities are fixed without rebuilding \u2014 same layers, same behavior, fewer CVEs.

Signed SLSA L3 SBOM Rekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/verity-org/redis/redisinsight:3.0.2
Build provenance
gh attestation verify \
  oci://ghcr.io/verity-org/redis/redisinsight:3.0.2 \
  --owner verity-org

Vulnerability Scan

Found 74 vulnerabilit ies in the original image. 39 fixed by Copa. 35 remaining after patching.

2CRITICAL35HIGH28MEDIUM9LOW

Fix available — pending patch

These vulnerabilities have upstream fixes but could not be automatically patched.

IDPackageInstalledFixedSeverity
CVE-2026-25639axios1.12.21.13.5, 0.30.3 HIGH
CVE-2026-26996minimatch3.1.210.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 HIGH
CVE-2026-27903minimatch3.1.210.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 HIGH
CVE-2026-27904minimatch3.1.210.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 HIGH
CVE-2026-26996minimatch9.0.510.2.1, 9.0.6, 8.0.5, 7.4.7, 6.2.1, 5.1.7, 4.2.4, 3.1.3 HIGH
CVE-2026-27903minimatch9.0.510.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.3 HIGH
CVE-2026-27904minimatch9.0.510.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, 3.1.4 HIGH
CVE-2026-2359multer2.0.22.1.0 HIGH
CVE-2026-3304multer2.0.22.1.0 HIGH
CVE-2026-3520multer2.0.22.1.1 HIGH
CVE-2026-4926path-to-regexp8.2.08.4.0 HIGH
CVE-2026-33671picomatch4.0.34.0.4, 3.0.2, 2.3.2 HIGH
CVE-2026-33151socket.io-parser4.2.43.3.5, 3.4.4, 4.2.6 HIGH
CVE-2026-23745tar6.2.17.5.3 HIGH
CVE-2026-23950tar6.2.17.5.4 HIGH
CVE-2026-24842tar6.2.17.5.7 HIGH
CVE-2026-26960tar6.2.17.5.8 HIGH
CVE-2026-29786tar6.2.17.5.10 HIGH
CVE-2026-31802tar6.2.17.5.11 HIGH
CVE-2026-33750brace-expansion1.1.125.0.5, 3.0.2, 2.0.3, 1.1.13 MEDIUM
CVE-2026-33750brace-expansion2.0.25.0.5, 3.0.2, 2.0.3, 1.1.13 MEDIUM
CVE-2026-33750brace-expansion2.0.25.0.5, 3.0.2, 2.0.3, 1.1.13 MEDIUM
CVE-2026-31808file-type16.5.421.3.1 MEDIUM
CVE-2026-31808file-type20.4.121.3.1 MEDIUM
CVE-2026-32630file-type20.4.121.3.2 MEDIUM
CVE-2025-13465lodash4.17.214.17.23 MEDIUM
CVE-2026-4923path-to-regexp8.2.08.4.0 MEDIUM
CVE-2026-33672picomatch4.0.34.0.4, 3.0.2, 2.3.2 MEDIUM
CVE-2025-15284qs6.13.06.14.1 MEDIUM
CVE-2025-15284qs6.14.06.14.1 MEDIUM
CVE-2026-33532yaml2.4.12.8.3, 1.10.3 MEDIUM
CVE-2026-3449@tootallnate/once1.1.23.0.1 LOW
CVE-2026-24001diff4.0.28.0.3, 5.2.2, 4.0.4, 3.5.1 LOW
CVE-2026-2391qs6.13.06.14.2 LOW
CVE-2026-2391qs6.14.06.14.2 LOW
Source
Copa (in-place patch)
Platforms
linux/amd64, linux/arm64
Registry
ghcr.io/verity-org
Upstream
mirror.gcr.io/redis/redisinsight