Container Image Scanning: Finding Vulnerabilities Before They Ship
A container image is an operating system distribution, a language runtime, a set of libraries, and your application, all frozen into one artifact. Scanning it means answering a question that spans every one of those layers: what known vulnerabilities are inside this thing we are about to run in production, and which of them actually matter. Two different inventories in one artifact Image scanners have to handle two package worlds at once. The operating system layer is enumerated from the distribution's package database — the same metadata the package manager uses. Matching those against distribution security advisories is reliable, provided the scanner understands backported patches. Distribution maintainers routinely fix a vulnerability without changing the upstream version number, so a naive version comparison reports flaws that were patched weeks ago. The application layer is enumerated from language-specific manifests and lock files. This is ordinary software compositio...