SIGSEGV
SIGSEGV in prod-checkout-api
37s
mean time to core dump
cloud resource → container → image → Dockerfile → commit → line
Security findings — corefile.io repository, HEAD
The first five rows mirror a live wizcli scan dir run one-to-one — same rule IDs, weakness classes, and file:line; the scan lands on exactly these five HIGH findings (WARN_BY_POLICY). The highlighted row is what today's static ruleset misses: an unauthenticated SSRF caught at runtime (DAST) and in review — the case for layered coverage.
Build provenance
Artifact
checkout-api@sha256:9f2c…be1aBuilder
ci-runner-07 · SLSA L2Source
git@…/acme/checkout-api.git · commit 4d1f0e2Signed
cosign · verified“You can't trust code that you did not totally create yourself.” — Ken Thompson, Reflections on Trusting Trust, 1984