Stop managing vulnerabilities and start managing scanner assumptions

Stop managing vulnerabilities and start managing scanner assumptions

Security leaders have invested heavily in vulnerability management programs. Scanners are running. SBOMs are being generated. Dashboards are showing numbers. And yet, most programs are operating on a foundational assumption that does not hold: that scanner output is authoritative. It is not.

Run two industry-standard scanners on the same container image and you will not get two versions of the same answer. You will get two entirely different answers. In a recent experiment using a Red Hat 8 image, Grype surfaced 852 CVEs while Trivy surfaced 3,719.

Lexi Selldorff

Head of Engineering at Manifest.

Leave a Reply

Your email address will not be published. Required fields are marked *