The fallacies of Container image scanners - Marius Shekow

36:05 · 09 Sep 2025 – 11 Sep 2025 · YouTube

About this talk

This talk examines the limitations of popular vulnerability scanners like Trivy and Grype, which are often relied upon by application and security teams to identify insecure components within Docker and Container images. The speaker, Marius Shekow, analyzes the top eight images on Docker Hub using these tools, revealing surprising findings about their effectiveness. He explains the inner workings of these scanners, highlights the concepts of false positives and false negatives with real-world examples, and concludes with strategies for overcoming the inherent weaknesses of these tools. Marius is a DevOps and cloud engineer at SprintEins, where he focuses on cloud-related software engineering practices and regularly speaks at industry conferences.

From event

ContainerDays 2025

09 Sep 2025 – 11 Sep 2025

All event videos
Back to Watch