Tools like Trivy, Grype, Snyk, AWS ECR scanning, GitHub
Dependabot scan container images for known CVEs. The point is to:
A) Make builds slower.
B) Catch known-vulnerable base images and dependencies BEFORE they
ship to prod, and fail the CI pipeline if HIGH/CRITICAL CVEs are
found above an agreed threshold.
C) Replace runtime monitoring.
D) Prove the image is unhackable.Sign in to save your code and track progress across devices.