Docker Image Vulnerability Triage
Runs Trivy against a Docker image and produces a prioritized CVE list grouped by severity with fix availability. Filters out CVEs with no available fix. Outputs a structured report suitable for Jira or GitHub Issues.
Installation
Use the upstream install or setup path that matches your environment:
- Docker Engine releases are tagged with a docker- prefix (e.g. docker-v29.0.0 for Docker Engine 29.0.0).
Requirements and caveats from upstream:
Moby is an open-source project created by Docker to enable and accelerate software containerization.
Relationship with Docker
The components and tools in the Moby Project are initially the open source components that Docker and the community have built for the Docker Project.
Source: https://github.com/moby/moby
Extracted from upstream docs: https://raw.githubusercontent.com/moby/moby/HEAD/README.md