Search across all documentation pages
7 pages in this section.
Understand the container vulnerability lifecycle, how CVEs enter images via base layers and dependencies, and where policy intercepts them.
Scan container images with Trivy and Grype, interpret their output, and integrate severity thresholds into CI to fail builds with vulnerable images.
Learn to pin base images by digest for reproducible builds. Understand tag mutability, rebuild cadence, and how to implement digest pinning.
Learn image policy best practices for vulnerability management across build, registry, and cluster, including pinning base images by digest.
A single-page roundup of every highlight bullet from the 6 pages in the Image Policy & CVEs section, grouped by source page so you can scan all 36 takeaways without opening each article individually.