Everyday
Images
What is on each host, and what is wrong with it.
The list
- Every image on the selected host, with its size and tags.
- A severity column carrying the result of the most recent vulnerability scan.
- Pull, prune and remove, behind the same confirmation and audit trail as everything else.
Scanning
- Scanning runs the real Trivy CLI, through the same proxy a Compose deploy uses — so an image is scanned exactly as it exists on the target daemon, not as it exists somewhere convenient.
- The findings view lists each CVE with its identifier linking to the real advisory.
- Results export as SARIF, for whatever already consumes your scan output.
Air-gapped
- Vulnerability databases are carried in. The offline bundle can include fresh Trivy and Grype databases — about 500 MB of it — and the installer sets scanning to Offline.
- Keep them current by importing the archives from a newer bundle, or by exporting them from a MangoDock that does have a connection.
- If your registry hosts trivy-db, point at it as an internal mirror instead.
- Their age is always shown, and offline they are used however old they get rather than refused — a stale scan beats no scan.