Image scanning

A scan tells you about known issues in known components, at the moment you ran it.

New flaws are published constantly, so an image clean at build time is not clean a month later, and nothing re-runs automatically unless you arrange it. Scanning at build and again continuously in the registry are different activities, and only doing the first is common.

Checked against the primary source.

More on Containers & Kubernetes