Product · Container

Image CVEs without leaving the runner

Scan built images for OS and library CVEs - offline, air-gap-friendly, with SARIF upload.

Capabilities

What Container does

OS + library CVEs

dpkg/apk package analysis, layered findings.

CIS config

Image configuration checks (root user, exposed ports…).

BYO scanner

Bring-your-own scanner runs on your runner; the image never leaves the host - we ingest SARIF.

How it works

Scan built images for OS and library CVEs without the image ever leaving your host. apPosture analyzes packages offline and checks image configuration against CIS-style hardening.

01

Read layers

Parse OS package databases (dpkg/apk) and language libraries from the image.

02

Match

Correlate packages to CVEs from the offline feed.

03

Harden

Flag risky image configuration - root user, exposed ports, missing healthcheck.

What you get

  • Offline OS and library CVE detection
  • CIS-style image configuration checks
  • Layered findings tied to the introducing package
  • Bring-your-own scanner on the runner via SARIF ingest
  • Air-gap friendly: the image never leaves the host
  • Feeds the same unified posture as every other source
Part of one platform

Container feeds your unified posture

Every Container finding deduplicates into one risk-weighted posture, correlates into attack-chains, and can block the build at the CI gate.

DAST API Security SAST SCA IaC Kubernetes Posture Secrets AI Pentest Threat Modeling ASPM CI/CD Gate

See Container on your own app

From discovery to a proven attack chain. A PoC in your own environment.