Vulnerability Management
Cloudanix scans your container images for CVEs at build time and at runtime — organized by severity, down to the vulnerable package and version, across ECR, GCR, Artifact Registry, Docker Hub, Quay, Harbor, and ACR.
Finding vulnerabilities is the easy part; managing the decisions is where teams drown. Cloudanix adds a structured triage workflow:
- Acknowledge (with expiry) — "known, being fixed."
- Accept Risk (with expiry and justification) — a conscious, documented decision that resurfaces for re-review when the date passes.
- Not a Risk (with note) — false positive or not exploitable in your context, with the reasoning on record.
No suppress-forever. Every decision carries an owner and a history — a CVE register your auditors can actually read.
- Jira-integrated — create tickets per CVE or per package, with full vulnerability context, in the backlog engineering already uses.
- Context from the rest of the platform — vulnerabilities live in the same data plane as assets and misconfigurations, so "vulnerable images on internet-exposed hosts" is a filter, not a spreadsheet exercise.
Detailed documentation is coming soon. Contact us to learn more.