> Sure, I can query the docker daemon for what images are running, but that's not enough to tell me which images are vulnerable.
If you can query what images are running, you can tie it with list of deployed
software. Then you can compare that list with database of known
vulnerabilities; obviously, you'd do the same if you were assessing the host
OS without Docker. What's easier is that you already have an API that can be
called remotely.
> Also, on any linux host, I don't need a daemon to tell me about deployed software - the package manager can do just that
But you need to get to each of these hosts somehow and get the data out of
package manager, so a report can be prepared. This is the part that makes it
easier to assess what you have in the case of Docker. Then there is also
software that was not installed with OS-supplied package system, because
programmers somehow dislike those and work around them with virtualenv or
npm-du-jour.
> [...] the tool used for scanning in this article appears to just query the package manager, which would work just as well on any linux host outside of docker.
I haven't read the article, but most probably you're right.