Continuous CVE Scanning with Trivy Operator - Vitaliy Schreibmann
About this talk
This talk addresses the critical need for timely identification and remediation of software vulnerabilities in critical infrastructure environments. The speaker discusses the limitations of traditional CI pipeline approaches that often overlook security gaps in production. He shares insights from the implementation of the Trivy Operator for continuous and periodic vulnerability scanning of production images, including the challenges faced during integration and the management of CVEs, with a focus on handling false positive alerts. Vitaliy Schreibmann, a consultant at Senacor Technologies AG, brings his expertise in DevOps and large transformation projects to this session.
More from this event
See all 77 talks →
Fireside Chat with Kelsey Hightower & Sebastian Scheele
44:16
Coping with Zero Days with Cilium Tetragon - Liz Rice
42:15
Building Trust in Fintech: DevSecOps Strategies at Saxo Bank - Jinhong Brejnholt
35:35
Seven years and counting – The DevOps journey at Hermes Germany - Stephan Stapel
34:16