Secure Container Audit

Use when the user asks to perform a security audit, vulnerability scan, SBOM analysis, or supply-chain assessment of a container image (registry reference, payload image, or batch of images) using skopeo, syft, and grype — covering image configuration, known CVEs in shipped packages, signature/provenance posture, and drift between the image contents and its source repository.

openshift 3dc3ee6 34.9 KB Updated

File contents

openshift/traust/tree/main/harnessing/3-audit/secure-container-audit commit 3dc3ee6b13

Frequently asked questions

npx skillmds@latest add openshift/secure-container-audit