Sure. And 99.99% of them aren't exploitable.
I have a Python-based pod that polls an internal API endpoint. Why should I care if the Python container has a critical vulnerability completely unrelated to what it does?
I have a Python-based pod that polls an internal API endpoint. Why should I care if the Python container has a critical vulnerability completely unrelated to what it does?
1.) https://en.wikipedia.org/wiki/Swiss_cheese_model
2.) Our own blind spots + unknown unknowns
CON:
1.) There are many false alarms or not critical issues :
see: https://github.com/search?q=org%3Adocker-library+CVE&type=is...