Kubevuln is an in-cluster component of the Kubescape security platform. It scans container images for vulnerabilities, using Grype as its engine.
active 2025-06-16 → 2026-08-08 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 419 days from 2025-06-16 to 2026-08-08. Pushes: 80 total, peak 4 in a day. Pull requests: 45 total, peak 5 in a day. Issues: 4 total, peak 2 in a day. Comments: 62 total, peak 7 in a day. Stars: 2 total, peak 1 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| matthyx | 97 | 61 | 24 | 5 |
| coderabbitai[bot] | 37 | 0 | 0 | 25 |
| github-actions[bot] | 19 | 0 | 0 | 19 |
| Copilot | 15 | 4 | 0 | 7 |
| dependabot[bot] | 15 | 1 | 14 | 0 |
| slashben | 10 | 5 | 1 | 2 |
| kooomix | 7 | 6 | 0 | 0 |
| bhuvan-somisetty | 7 | 0 | 3 | 3 |
| amirmalka | 3 | 2 | 1 | 0 |
| mkm29 | 2 | 0 | 1 | 0 |
| h30s | 1 | 0 | 0 | 1 |
| bvolovat | 1 | 1 | 0 | 0 |
| jnathangreeg | 1 | 0 | 0 | 0 |
| harshitg927 | 1 | 0 | 1 | 0 |
Recent activity
Latest issues, pull requests and releases
- Pull request#504bhuvan-somisetty2026-08-08 03:11
- Issue comment#502bhuvan-somisetty2026-08-07 18:29fix(services): pass filtered manifests to StoreVEX in ScanCP (#501)
- Issue comment#502coderabbitai[bot]2026-08-07 17:59fix(services): pass filtered manifests to StoreVEX in ScanCP (#501)
- Issue comment#482h30s2026-08-07 17:45fix: include SecurityException-suppressed CVEs in generated VEX document
- Issue comment#502bhuvan-somisetty2026-08-07 17:31fix(services): pass filtered manifests to StoreVEX in ScanCP (#501)
- Issue comment#502coderabbitai[bot]2026-08-07 16:51fix(services): pass filtered manifests to StoreVEX in ScanCP (#501)
- Pull request#502bhuvan-somisetty2026-08-07 16:50
- Issue#484matthyx2026-08-07 16:40Bug: ScanRegistry bypasses SecurityException filtering, in-cluster storage, and VEX generation
- Pull request#485bhuvan-somisetty2026-08-07 16:40
- Issue#501bhuvan-somisetty2026-08-07 16:34Bug: ScanCP passes unfiltered manifests to StoreVEX and omits VEX updates on cached exception re-evaluation
- Issue comment#485bhuvan-somisetty2026-08-07 16:19fix(core): enable storage, exception filtering, and VEX generation in ScanRegistry (#484)
- Pull request#370harshitg9272026-06-05 06:24
- Pull request#361mkm292026-05-07 22:27
- Issue#359mkm292026-05-07 01:01proxyRegistryMap does not truly work
- Issue comment#357coderabbitai[bot]2026-05-04 08:24add debug log for grype DB url
- Pull request#357matthyx2026-05-04 08:24
- Issue comment#355matthyx2026-04-28 08:38perf: switch to kubescape/syft v1.32.0-ks.2 + disable file catalogers
- Issue comment#353coderabbitai[bot]2026-04-20 05:57fix(exceptions): normalize vulnerability ID casing and trim whitespace
- Issue comment#351github-actions[bot]2026-04-20 05:39feat: GCP Workload Identity fallback for 401 Unauthorized
- Pull request#350matthyx2026-04-17 12:11
- Issue comment#349slashben2026-04-17 06:00Fix: enable SecurityException CRDs in keepLocal mode
- Pull request#347matthyx2026-04-16 07:04
- Issue comment#342coderabbitai[bot]2026-04-12 11:30Integrate SecurityException CRDs into vulnerability scanning
- Issue comment#341coderabbitai[bot]2026-04-09 10:40Add SecurityException CRD design doc and review
- Issue comment#334github-actions[bot]2026-04-02 06:05feat: add scan failure reporting (SUB-7105)
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 2 stars here means stars gained during the window, not the repo's star count.