DEVOPS

Open a weekly PR to bump base images with available CVE fixes

Weekly, finds base images carrying CVEs that have a patched upstream tag available and opens a ready-to-review GitHub PR bumping each one.

CategoryDevOps
Enginesim
Difficultyintermediate
Triggerschedule
Steps5
Setup~15 min

How it runs

The automated pipeline, trigger to output.

  • TriggerWeekly schedule
  • ActionPair open CVEs with fixed upstream tagsGitHubGitHub
  • LogicFilter to images with an available fix
  • ActionEdit Dockerfile FROM to patched tagGitHubGitHub
  • OutputOpen bump PR listing resolved CVEsGitHubGitHub

What it does

Enforcing a CVE budget creates a backlog of images that need bumping. This workflow does the legwork: each week it scans your base images, identifies which CVEs have a fixed version published upstream, and opens a pull request bumping the `FROM` tag to the patched release. The PR body lists exactly which CVEs the bump clears so reviewers can approve with confidence.

When to use it

Use it to stay ahead of the gate instead of being blocked by it. Rather than discovering a budget breach mid-deploy, you get a steady stream of small, pre-vetted upgrade PRs you can merge on your own schedule.

How it works

  1. 1A weekly schedule starts the run.
  2. 2An action scans each base image and pairs open CVEs with available fixed tags.
  3. 3A filter drops images where no patched upstream tag exists yet.
  4. 4For each fixable image, an action edits the Dockerfile `FROM` to the patched tag.
  5. 5The workflow opens a GitHub PR per image listing the resolved CVEs.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect GitHubRepos, issues, pull requests, actions.
  2. 2
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  3. 3
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  4. 4
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.