We are currently doing a security assessment related to the upcoming Cyber Resilience Act requirements. Would it be possible to resolve the fixable vulnerabilities on your level?
lyrical-ros-base currently inherits 8 vulnerabilities from ubuntu:26.04 and introduces 60 with ros:lyrical-ros-core.
59 of the 68 should be easily fixable by upgrading some packages (especially golang's stdlib) according to Docker Scout.
kilted (1.456 vulns), jazzy (1.456 vulns) and humble (2.490 vulns) are basically broken beyond repair security-wise. So I think focusing on lyrical and rolling should be enough.
We are currently doing a security assessment related to the upcoming Cyber Resilience Act requirements. Would it be possible to resolve the fixable vulnerabilities on your level?
lyrical-ros-base currently inherits 8 vulnerabilities from
ubuntu:26.04and introduces 60 withros:lyrical-ros-core.59 of the 68 should be easily fixable by upgrading some packages (especially golang's stdlib) according to Docker Scout.
kilted (1.456 vulns), jazzy (1.456 vulns) and humble (2.490 vulns) are basically broken beyond repair security-wise. So I think focusing on
lyricalandrollingshould be enough.