Skip to main content

Free 30-min security demo Book Now

Container security · Cloud demo

Inspect what you ship.
Understand what needs fixing.

Assess a container image archive, software bill of materials or Kubernetes resource manifest before release. Review package advisories and configuration findings with the identity and scope of the artifact you supplied.

Static uploaded-artifact assessment. Live cluster, registry and runtime protection requirements need a separate scope discussion.

Three inputs. Three useful security questions.

Choose the input that matches your decision. An image, an SBOM and a deployment manifest provide different evidence; review them together when your release uses all three.

Container image archive

Which supported packages in this image have known advisories?

Supply a Docker or OCI image archive. Inspect identified package versions, advisory information and available fixed versions before planning a rebuild.

Cloud demo input: .tar or .tar.gz · up to 500 MiB

Software bill of materials

Which listed components need an advisory review?

Supply a CycloneDX or SPDX JSON inventory. Results depend on the package identity and version information in that SBOM; missing components cannot be assessed.

Cloud demo input: CycloneDX / SPDX JSON · up to 16 MiB

Kubernetes resource manifests

Which uploaded configuration choices deserve attention?

Supply YAML or JSON resource manifests to review supported security checks. This describes declared configuration, not the state or behavior of a running cluster.

Cloud demo input: .yaml, .yml or .json · up to 8 MiB

Archive layout, compression, content and expanded-size limits also apply. Start with one Linux image per archive. Use resource manifests, not kubeconfig files or cluster credentials. Confirm the supported format before uploading sensitive artifacts.

Make the result useful to the release owner

  1. 1. Identify the exact artifact. Record the image or package build and compare it with the uploaded artifact identity.
  2. 2. Inspect coverage and freshness. Review analyzed package inventory or configuration-check coverage and the advisory snapshot used.
  3. 3. Investigate before prioritizing. Read affected versions, advisory conditions and configuration evidence. An advisory match alone does not demonstrate exploitability.
  4. 4. Rebuild and reassess. Apply a relevant upgrade or configuration change, repeat the assessment and keep the evidence with your release decision.

Container scanning questions

What does Offensive360 container security scan?

The cloud demo accepts Docker or OCI image archives, CycloneDX or SPDX JSON SBOMs, and Kubernetes resource manifests. Image and SBOM analysis identifies advisory matches for supported packages. Manifest analysis checks the uploaded configuration for security issues. Availability and limits should be confirmed for your intended deployment.

Does this connect to a live Kubernetes cluster?

No. This workflow assesses uploaded artifacts and resource manifests. It does not use kubeconfig credentials, connect to a cluster, pull images referenced in manifests, or observe running workloads. Discuss live-cluster or registry requirements separately during evaluation.

Are uploaded container images executed?

No. The artifact workflow inspects the image archive without booting or executing the uploaded image. It evaluates supported package information using the available advisory snapshot.

Is a package vulnerability the same as an exploitable application?

An advisory match identifies a potentially affected package version. Confirm the deployed version, application use, exposure and relevant advisory conditions before deciding exploitability. Test upgrades and rebuild the artifact before rescanning.

How should I evaluate image and Kubernetes scanning?

Use a representative artifact, a known affected package or unsafe manifest, and a patched control. Verify artifact identity, analyzed inventory or executed checks, advisory freshness, evidence and the result after remediation. Record unsupported or incomplete analysis explicitly.

Reviewed by The Offensive360 Team · October 3, 2026. Explore supply chain evaluation or review source-code analysis.