The OS packages baked into the image you build on carry the bulk of your container risk, and they keep changing as new advisories land against tags you already pinned. Pragma Core scans the base images declared in your Dockerfiles and any image you import from a registry, then tracks every CVE through a clear lifecycle with real severities.
Both sources funnel into one inventory and are scanned the same way, so a base image from a repo and an image pulled from a registry live side by side.
No local Docker daemon, no build step. The scanner pulls each image, reads its packages, and matches them against the vulnerability database.
Base images and registry imports both carry a tail of CVEs that grows as new advisories land. Here is what the dashboard collapses that into.
Active CVEs per image, broken down by severity. The slim and distroless bases carry far less than a full distribution image, which is exactly the kind of decision this view is meant to inform.
Ranked by CVSS, with the package and the version that fixes each one. The fixed column tells you immediately whether a patch even exists yet, which is usually the first triage question.
| CVE | Severity | Package | Fixed in |
|---|---|---|---|
| CVE-2023-44487 | 9.8 | golang.org/x/net | 0.17.0 |
| CVE-2024-2961 | 8.1 | glibc | 2.36-9+deb12u7 |
| CVE-2023-5678 | 7.5 | openssl | 3.0.13 |
| CVE-2023-29491 | 6.5 | ncurses | 6.4-4 |
| CVE-2024-0567 | 5.3 | gnutls28 | 3.7.9-2+deb12u3 |
Token and password registries are handled natively. Cloud registries that need per-provider credential helpers are on the roadmap.
Enable container scanning on a repository or import an image from your registry, and see the CVEs you are shipping.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.