The fallacies of Container image scanners - Marius Shekow
About this talk
This talk examines the limitations of popular vulnerability scanners like Trivy and Grype, which are often relied upon by application and security teams to identify insecure components within Docker and Container images. The speaker, Marius Shekow, analyzes the top eight images on Docker Hub using these tools, revealing surprising findings about their effectiveness. He explains the inner workings of these scanners, highlights the concepts of false positives and false negatives with real-world examples, and concludes with strategies for overcoming the inherent weaknesses of these tools. Marius is a DevOps and cloud engineer at SprintEins, where he focuses on cloud-related software engineering practices and regularly speaks at industry conferences.
More from this event
See all 108 talks →
Why are we still talking about containers? - Kelsey Hightower at ContainerDays 2025
46:56
Saxo Service Blueprint: Bridging Old and New World with Kubernetes Operators - Jinhong Brejnholt
36:25
Engineering Velocity, Building Trust: DevOps in 2025 - Stephan Stapel
33:17
Getting Started with eBPF Made Easy - Qasim Sarfraz & Michael Friese
33:05