Skip to main content

Vulnerability Management

Cloudanix scans your container images for CVEs at build time and at runtime — organized by severity, down to the vulnerable package and version, across ECR, GCR, Artifact Registry, Docker Hub, Quay, Harbor, and ACR.

Finding vulnerabilities is the easy part; managing the decisions is where teams drown. Cloudanix adds a structured triage workflow:

  • Acknowledge (with expiry) — "known, being fixed."
  • Accept Risk (with expiry and justification) — a conscious, documented decision that resurfaces for re-review when the date passes.
  • Not a Risk (with note) — false positive or not exploitable in your context, with the reasoning on record.

No suppress-forever. Every decision carries an owner and a history — a CVE register your auditors can actually read.

  • Jira-integrated — create tickets per CVE or per package, with full vulnerability context, in the backlog engineering already uses.
  • Context from the rest of the platform — vulnerabilities live in the same data plane as assets and misconfigurations, so "vulnerable images on internet-exposed hosts" is a filter, not a spreadsheet exercise.

Detailed documentation is coming soon. Contact us to learn more.