0confirmed unpatched
Critical / High findings
Within the reviewed scope
Artifact checks, dependency analysis and focused security tests found no confirmed unpatched Critical or High vulnerability. This is a Globalesm assessment, not an independent certification or a guarantee that no vulnerabilities exist.
One Medium issue remains open. See the finding below before installation on a shared server.
Review coverage and limitations
Trivy 0.75.0 used fresh October 5 vulnerability data and identified 372 of 511 JAR paths. The 139 unidentified paths include first-party and legacy components and still need inventory coverage. A scanner match count is not a complete application security assessment.
The isolated runtime checks used macOS ARM64. Windows runtime and ACLs, other architectures, service lifecycle, the cloud Hub backend, production configuration, customer channel code and separately installed Java/OS components were outside this review. All 230 signatures passed integrity verification but use a self-signed development certificate. They do not establish a trusted production publisher.
Restrict PHI must be enabled and verified on the actual connection. Mock tests are not an end-to-end cloud data-flow audit. The setting does not contain arbitrary channel scripts or external systems. A paired staging verification with synthetic data remains pending.