Unhardened: docker.io/nanoco/nanoclaw:agent-alpha
71 packages, 344 unique CVEs, linux/arm64
PACKAGE VERSION TYP C H M L N TOT
-----------------------------------------------------------
expat 2.5.0 deb 0 4 18 1 2 25
curl 7.88.1 deb 4 4 6 0 7 21
hono 4.12.14 npm 0 1 18 2 0 21
libtiff 4.5.0 deb 0 2 1 1 15 20
perl 5.36.0 deb 5 6 3 0 3 17
pnpm 10.33.0 npm 0 8 7 0 0 15
glibc 2.36 deb 1 2 2 1 7 13
openjpeg 2.5.0 deb 0 0 3 1 9 13
cups 2.4.2 deb 0 2 8 0 1 11
glib2 2.74.6 deb 1 7 1 0 1 10
tar 1.34(+2) deb 1 1 7 0 1 10
llvm 15.0.6 deb 0 0 0 1 9 10
sqlite3 3.40.1 deb 1 2 3 0 3 9
nss 3.87.1 deb 1 0 3 0 4 8
avahi 0.8 deb 0 0 8 0 0 8
util-linux 2.38.1 deb 0 0 3 0 2 7
elf 0.188 deb 0 0 0 0 7 7
libssh2 1.10.0 deb 1 4 1 0 0 6
openldap 2.5.13 deb 0 1 0 0 5 6
chromium 151.0.7922.108 deb 0 5 0 0 0 5
-----------------------------------------------------------
UNIQUE CVEs 16 68 121 17 119 344
(+51 more packages, 102 findings)
C/H/M/L/N = critical/high/medium/low/negligible.
Counts are unique CVEs: binaries from one source package are
grouped (libcurl4 + libcurl3-gnutls + curl = curl), so a CVE
hitting three of them counts once, not three times.This is why it’s good to exclude things you don’t need. The less there is, the fewer places there are for problems to lurk.
Scanning companies should be sophisticated enough to distinguish invalid CVEs and back ported fixes.
It's not a real number, and, worse, it obscures the real figure of merit (/demerit). The Node ecosystem does have a real problem with its culture of sprawling dependencies. But it's not the first-order issue with this "1400" number.
The answer to this was something called polyfills, a library that did something as simple as element.center() with just 500 lines of code to make it consistent on all browsers, and all the places you want to center that element are updated by the polyfill authors and your code doesn't need to be touched.
All the sites that weren't using good polyfills broke (or at least looked terrible) for days every time there was a new $browser update.
Since thats the javascript environment node was born into, the style was carried over by inertia and habit, for better and worse.
It is pretty much the lowest common denominator for code.
It's like asking why Claude Code is written with react, because the devs getting paid >$500k a year clearly know better d'uh.
> NanoClaw is a secure, lightweight alternative to OpenClaw.
Yes, this is mostly a joke, I am able to understand the difference between base distros.