Security warnings all over the place.
Posted by ickydevil
I obviously don't mind being warned about security issues but having 3 major components of my stack telling me I have hundreds of security issues and vulnerabilitie sounds pretty bad. Is this how it looks at all times or are updates just that far behind? My question: What does this even mean? I have three security warning s in TomSparkbox. they are listed for core, media and tailscale. All have generally the same warning saying something like what I have quoted. "media: 14 critical problems and 425 high-severity problems - a newer version would fix them You are already on the newest media that SparkBox ships, so there is nothing to click. Fixes exist upstream - SparkBox needs to ship a newer media image." SparkBox AI replied: Yeah, the wording is dramatic. It doesn’t mean your box has been hacked. It means SparkBox’s security scanner found known vulnerabilities in software packages inside the Docker images: - Core, media, and Tailscale are the affected module groups. - “14 critical / 425 high” is a package-vulnerability count, often including duplicates and components that aren’t reachable in your setup. - “A newer version would fix them” means patched packages exist upstream. - “Nothing to click” means you already have the newest images currently approved by SparkBox. Restarting or pulling random images won’t fix it. I checked the box. All 17 containers are healthy, the VPN is running, Tailscale’s inbound path works, and the admin interfaces are limited to your local network. So there’s no sign here of an active compromise or a broken service. The actual next step is for SparkBox to ship refreshed images. That part’s on us. Since this warning comes from SparkBox’s own dashboard, click Share to dem …(reply truncated — full chat sent to Tom)
2 replies
Chris wrote:
That card reports known security advisories in the image; it is not confirmation that your box has been compromised. Its "nothing to click" wording means SparkBox does not currently ship a newer image for that component, so restarting or pulling containers would not resolve it. I also cannot verify the AI’s claimed health check from this forum post. Please reply with your SparkBox version so I can check whether a matching update is actually available.
Chris wrote:
Your report exposed a real problem in our Security page. v1.6.662 is now available: it scans the actual running images, shows package details, and stops claiming every advisory has an available fix. It also updates Homepage, Prowlarr and Tailscale. Some upstream advisories remain, so this is not an all-clear. Update SparkBox, then run ‘Check my apps’ to refresh the saved report.