https://github.com/shaarli/Shaarli/actions/workflows/trivy-release.yml runs daily security security scans against dependencies of the latest release.
But it doesn't verify that the master branch/latest docker image is free of vulnerable dependencies.