Not sure if this is the right place to file the issue.
The vulnerability check for the crate image shows a false positive for CVE-2016-10109, see https://hub.docker.com/r/library/crate/tags/1.0.6/
CVE-2016-10109 was already fixed in alpine 3.2.4, crate users alpine 3.4 as base image. pcsc-lite 1.8.20 is not effected by the vulnerability, however it is shown as major severity.

This is fine for now, but it looks like they prefer you to open an issue through the Docker support website, based on what I could find.
I'm going to CC @toli in here, and leave it to him.
Thanks for bringing this to our attention. We checked with our alpine maintainer contacts, and this indeed looks like a false positive.
We'll work on fixing this, give us a few days.
@Moghedrin is right - it may be faster to open a support case, or just go through Provide Feedback link on the scan page itself, it'll send us a direct email.
Meanwhile, thanks for letting us know and we'll work on cleaning up the false positives.
@andreif - nginx is a different story, it has significantly more/different vulnerabilities in non-base layers. feel free to open a separate case for that if you believe they are false positives.
Thanks @toli! 鉂わ笍
Most helpful comment
Thanks for bringing this to our attention. We checked with our
alpine maintainercontacts, and this indeed looks like a false positive.We'll work on fixing this, give us a few days.
@Moghedrin is right - it may be faster to open a
support case, or just go throughProvide Feedbacklink on the scan page itself, it'll send us a direct email.Meanwhile, thanks for letting us know and we'll work on cleaning up the false positives.
@andreif -
nginxis a different story, it has significantly more/different vulnerabilities in non-base layers. feel free to open a separate case for that if you believe they are false positives.