image-scanning
Safeguard articles tagged "image-scanning" — guides, analysis, and best practices for software supply chain and application security.
40 articles
Container Security Best Practices That Actually Reduce Risk
Container security best practices come down to a small set of high-leverage habits: minimal images, non-root users, scanned dependencies, and least-privilege runtime. Here is the working list.
Docker and Containers: A Practical Security Guide
Docker and containers share the host kernel, so their security model is different from virtual machines. Here is how to build, run, and scan containers safely.
How to Choose a Container Image Vulnerability Tool
A container image vulnerability tool scans the layers, packages, and metadata inside an image so you catch known CVEs before they ship to production. Here is how to pick and use one well.
How to Secure Docker Containers: A Practical Hardening Guide
A working checklist to secure Docker containers, from non-root users and minimal base images to capability drops, read-only filesystems, and image scanning.
State of Container Security 2026: Survey Summary
A survey-style summary of container security in 2026: what production teams actually ship, where image security stands, and which runtime controls moved the needle.
Snyk Container Security: What It Scans and How
Snyk Container scans Docker and OCI images for OS and dependency vulnerabilities and recommends better base images. Here is how it works and where its limits are.
Choosing a Container Security Tool in 2026: What Actually Matters
A container security tool should cover the image, the registry, and the running workload — not just spit out a CVE list. Here is how to evaluate one without the marketing gloss.
How to Secure a Docker Container: A Practical Hardening Guide
A secure Docker container starts with a minimal base image, a non-root user, and a scanned, pinned dependency set. Here's the hardening checklist that actually holds up in production.
How to Improve Security for Docker Containers
Practical security for Docker containers: minimal base images, non-root users, image scanning, and runtime hardening you can apply to any Dockerfile today.
Securing Docker Containers: A Practical Hardening Guide
Securing Docker containers is less about one setting and more about a chain of defaults: slim base images, non-root users, scanned layers, and locked-down runtime privileges.
Deep Dive: Safeguard Container Scanning
Container images are supply chain artifacts. Safeguard's container scanning analyzes every layer -- base images, OS packages, and application dependencies -- for a complete risk picture.
Kubernetes Container Security Scanner: How It Works and What to Use
A Kubernetes container security scanner checks images, manifests, and running workloads for known vulnerabilities and misconfigurations. Here is how the pieces fit and where to place them in a pipeline.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.