> ## Documentation Index
> Fetch the complete documentation index at: https://help.the-meridian.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability scan

After each production deploy, Meridian scans your container image for known vulnerabilities in its OS packages and dependencies. A result looks like this:

**Image:** `my-shopify-app:v2.4.1` · scanned 2 min ago · **14 vulnerabilities** (2 critical, 3 high, 6 medium, 3 low)

| Severity | CVE | Package | Installed | Fixed in |
| :- | :- | :- | :- | :- |
| Critical | CVE-2024-XXXXX | `openssl` | 3.0.11 | 3.0.13 |
| Critical | CVE-2024-XXXXX | `glibc` | 2.36-9 | 2.36-9+deb12u4 |
| High | CVE-2024-XXXXX | `libxml2` | 2.9.14 | 2.9.14+dfsg-1.3 |
| High | CVE-2024-XXXXX | `zlib` | 1.2.13 | 1.2.13.dfsg-1 |
| Medium | CVE-2024-XXXXX | `curl` | 7.88.1 | 7.88.1-10+deb12u5 |
| Low | CVE-2024-XXXXX | `tar` | 1.34 | No fix yet |

## When scans run

| | Lite | Pro | Enterprise |
| :- | :- | :- | :- |
| After every production deploy or rollback | ✓ | ✓ | ✓ |
| On demand with **Run scan**, on any environment | - | - | ✓ |

Development and staging deploys are not scanned automatically. On Lite and Pro the **Run scan** button stays visible but disabled. Automatic scans are free and never count against a limit.

The summary on the hosting dashboard always describes the **live** deployment, the one serving traffic, and names it: for example *Live deployment 8609eeb · scanned 2 h ago · 98 findings*. A deployment that failed or is still in flight does not replace it there, because the live image is still the one exposed. That deployment's own row in the deployments table shows its own scan state, such as **Not scanned**. Until a deployment has gone live, the summary is not shown. On development and staging, it appears only once you scan the live deployment with **Run scan**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.