A CVE just hit your base image. Your scanner won't tell you which repos to fix.
In January 2026, CVE-2026-0861 landed in glibc. An integer overflow in the memalign family, rated high, present in every glibc from 2.30 to 2.42. Which is to say: present in debian:bookworm-slim, and
riftmap.hashnode.dev11 min read