We check every version of an image for known vulnerabilities before it starts for the first time (Security in Container Hosting). The Security tab of your project summarises the results of all containers. You see at a glance where action is needed and which vulnerabilities can already be fixed. The number on the tab shows the critical findings in the whole project.
The overview
At the top you see how many containers your project has and how many of them have been checked. Three cards follow below:
- Total vulnerabilities - all known vulnerabilities of your containers, split by severity: critical, high, medium and low. The text above states how many critical and high findings already have a fix.
- Containers with the most findings - the containers with the most critical and high findings. Clicking the name opens the container page.
- Most dangerous vulnerabilities - the vulnerabilities with the highest rating, with severity, CVSS score, affected package and the containers that contain them. The name of the vulnerability (for example
CVE-2025-12345) links to the public description.
All critical and high findings
The list below shows every critical and high finding individually: the vulnerability with a short description, the container, the severity, the CVSS score, the affected package with its version and the version in which the vulnerability is fixed. Use the filters to narrow down the list:
- Severity - only critical or only high findings.
- Container - only the findings of one container.
- Search - for a CVE number, a package or a container.
- Only with fix - only findings that already have a fix. This is the best place to start.
With many findings you browse page by page and choose whether 25, 50 or 100 findings appear per page.
Assessing and fixing findings
The findings come from packages in the image, often from the bundled operating system. Whether your application is affected depends on whether it uses the package. Proceed as follows:
- Findings with a fix first - if the column Fixed in shows a version, a newer state of the image usually helps. Create a snapshot beforehand (Backup and snapshot).
- New state of the same version - click Recreate on the container page. The container then takes over the most recently checked state of its version.
- New version - if the vulnerability remains, enter a newer version in the container settings (Updating containers). If there is a checked version with fewer findings, the Security tab points this out and the container page suggests it.
Findings marked no fix yet have not yet been fixed by the vendor. They usually disappear with one of the next states. Until then, reduce the risk by publishing only the services you need and running databases in an internal network (Networks and firewall).
Where do I start?
- Critical findings with a fix in containers that can be reached from the internet.
- High findings with a fix in these containers.
- Findings in containers that can only be reached internally, such as databases.
A medium or low finding is rarely urgent. It is usually fixed along with the next update.