Container Vulnerability Scanning
Automated daily scanning of container images to identify security vulnerabilities.
What Is Vulnerability Scanning?
Every container image (like nginx:1.20 or python:3.11) contains software that might have known security vulnerabilities. We automatically scan all your images daily to find these issues and provide:
- Clear vulnerability descriptions with context
- Severity ratings to help prioritize fixes
- Affected images and their locations in your cluster
- Recommendations for updating to secure versions
No Security Expertise Required
We translate CVE severity scores and technical details into clear risk levels. You'll understand what matters without needing to be a security expert.
How Scanning Works
Automatic & Daily: Every 24 hours, we scan all publicly available container images running in your cluster using Trivy, an industry-standard open-source vulnerability scanner.
What We Scan:
- Operating system packages (Alpine, Debian, Ubuntu, RHEL, etc.)
- Application dependencies (npm, pip, gem, Maven, etc.)
- Language-specific libraries
Zero Configuration: Scanning starts automatically when you install ClusterPirate, no further setup required.
Scan Process
- Image Discovery: Platform identifies all container images in use
- Daily Scan: Trivy scans each image for known vulnerabilities
- CVE Database: Results compared against latest CVE databases
- Portal Update: Findings displayed in the CVE Scans section
Viewing Scan Results
Via Web Console
Access CVE scan results through the portal:
- Navigate to portal.cloudpirates.io
- Select your workspace
- Choose cluster
- Go to CVE Scans section
Scan Results Display
Dashboard Features:
- Total vulnerability count by severity
- Affected images list
- CVE details and descriptions
- Remediation recommendations
- Scan timestamps
Scan Coverage
Private Images
Private registries are supported through secure credential management, alongside public images.
Scan Frequency
Daily Scans: Images are scanned once per 24-hour period.
On-Demand Scans: Trigger a scan at any time.
False Positives
Some CVEs may not be exploitable in your specific context:
Review Factors:
- Is the vulnerable component actually used?
- Does the attack vector apply to your deployment?
- Are mitigating controls in place?