A recipe tracks an image repo and a set of registry URLs. When upstream moves, nothing errors — the old repo just stops receiving tags and the recipe looks 'up to date' forever. plausible is the case: it tracked plausible/analytics on Docker Hub while upstream moved to ghcr.io/plausible/community-edition. Every survey said 'no upgrades available' while v3 shipped elsewhere. audit-sources.py reports the signals that catch it, per image and per registry URL: image gone quiet (newest tag older than --quiet-days), deprecation wording in the registry description, and GitHub repos that are archived, renamed or gone. Signals, not verdicts — a stable image can be quiet for good reason — so each finding says what was measured. First run over 22 recipes, 11 findings, 4 alerts. It independently re-derived the plausible case (analytics quiet 1126 days), and found: - drone: harness/drone now answers as harness/harness (the image is fine) - lasuite-docs, lasuite-drive: minio/minio is ARCHIVED on GitHub - lasuite-docs: docspecio/api is ARCHIVED - matrix-synapse: halfshot/matrix-appservice-discord image quiet 2078 days - mumble: NO cc-ci-plan/upstream/mumble.md at all That last one exposed a scanner bug. With no registry file there is no source to query, yet the scan still printed '0 identified by the deterministic scan' — and that 0 was published as a clean count in the 2026-08-11 CVE check. A scan with no usable source has measured nothing and must not report a number, least of all 0. It now returns UNKNOWN and says the registry file is missing. upstream/mumble.md added; mumble now scans 6 sources for a genuine 0.
1.6 KiB
1.6 KiB
Upstream sources — mumble
| service | image | source repo | releases / changelog |
|---|---|---|---|
| app | mumblevoip/mumble-server | https://github.com/mumble-voip/mumble | https://github.com/mumble-voip/mumble/releases |
| web | rankenstein/mumble-web | https://github.com/rankenstein/mumble-web | https://github.com/rankenstein/mumble-web/releases |
Standing notes
- This file was missing entirely until 2026-08-11. Without it the advisory scan had no source to
query, and still printed "0 identified by the deterministic scan" — which was then published as a
clean
0in the 2026-08-11 CVE check. The scan now refuses to emit a count when it has no usable source (it reports UNKNOWN), andaudit-sources.pyflags a missing registry file directly. mumblevoip/mumble-servertracks the upstream server releases and DOES publish GitHub security advisories, so it is the recipe's primary CVE source.rankenstein/mumble-webis a fork of the originalJohni0702/mumble-web, which has been dormant since 2023-05. The fork itself last pushed 2023-07 and its Docker tag0.5was last built well over five years ago. Neither is archived, but treat the web client as effectively unmaintained: if a CVE lands there, expect no upstream fix and plan a replacement rather than an upgrade.- The server image tag is
v<version>-<build>(e.g.v1.6.870-4); the trailing number is the image build, not an app version, and moves independently of upstream releases —abra recipe upgradereports "no new versions" for it, so useresolve-images.pyto see those bumps.