Image Scanning

Finds vulnerabilities, misconfiguration, and embedded secrets in container images before they ship — CVE scanning in the pipeline, gate-versus-warn policy, base image freshness, and separating fixable findings from noise. Use this whenever the user asks about CVEs, Trivy, Grype, or Snyk scans, wants a pipeline to block on critical vulnerabilities, is triaging a scan report, or asks if an image is safe to deploy. For fixing image structure use `containerization`; for the org-wide vulnerability program use `vulnerability-management`; for signing use `container-registry`.

arjunprabhulal Updated

File contents

arjunprabhulal/devops-skills/tree/main/skills/containers/image-scanning commit 1da5d2d233

Frequently asked questions

npx skillmds@latest add arjunprabhulal/image-scanning