Examining a container image's OS packages and libraries for known vulnerabilities.
It's typically automated as part of a CI/CD pipeline at build time, using tools like Trivy or Snyk. This is a representative example of a "shift-left" security practice, catching and blocking a vulnerable image before it's ever deployed to production.
© 2026 ITBGM