Vulnerability scanner is a service that enables you to statically analyze a Docker image and compare its contents with the vulnerability databases in CVE.
Vulnerability scanner only works with Docker images from Container Registry. At the same time, you can scan Docker images that you have access to as a user.
For scanning, a Docker image is unpacked, and a search is performed for installed package versions (deb). The package versions identified are then checked against a database of known vulnerabilities.
Currently, Docker images are available and built for the following supported operating systems:
- Ubuntu 14.04
- Ubuntu 16.04
- Ubuntu 18.04
- Ubuntu 20.04
- Ubuntu 20.10