Workload security
Scan containers and inspect vulnerable packages
Scan a registry image or review local images reported by a self-managed host, then inspect packages and vulnerability findings.
Reviewed
Before you start
For a cloud image scan, select a connected cloud account and an accessible image reference. For local images, connect a host with Container Security capability.
Choose the image source
Open Container Security. Cloud registry images are pulled and scanned by Secorvia. Self-managed hosts scan their local images using the agent’s Trivy and upload the SBOM; the image stays on the host.
Submit a cloud image scan
Under Scan a Container Image, select Cloud Account and enter Image Reference, such as a registry/repository tag or digest. Start the scan and watch Scan in Progress and Scan History for completion.
Inspect the image and packages
Search by image reference and open Image Detail. Review the package inventory, installed version, Fixed in version when supplied, and vulnerability signals such as CVSS, EPSS, and KEV. No package inventory means correlation lacks a required input.
Review local host images
For self-managed hosts, check Host, Runtime, Containers, Images, and Last Inventory. The agent discovers images and uploads SBOMs automatically. Use Manage to investigate a host that is not reporting.
Verify an updated image
Build or obtain the patched image through your normal workflow, deploy the intended version, and scan that reference again. Confirm the updated package inventory before treating a previous vulnerability match as resolved.
Where you are now
You can trace a container finding to an image, installed package, scan result, and candidate fix version.
WHEN SOMETHING LOOKS OFF
A few things to check
No packages recorded
Inspect Scan History for errors and confirm the image was accessible and scanned successfully.
Local images are missing
Check the host’s Container Security capability, Docker access, Trivy installation, and Last Inventory.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.