{"id":12854,"date":"2026-08-19T10:00:22","date_gmt":"2026-08-19T08:00:22","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=12854"},"modified":"2026-08-19T10:00:30","modified_gmt":"2026-08-19T08:00:30","slug":"lista-de-verificare-pentru-securitatea-imaginilor-de-container-trivy-grype-docker-scout-si-controale-la-nivel-de-registru","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/","title":{"rendered":"Lista de verificare privind securitatea imaginilor de containere: Trivy, Grype, Docker Scout \u0219i controalele registrului"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Container image security should apply controls at every stage, from base image selection to production deployment. A repeatable process combines vulnerability scanning, secret and malware detection, software bills of materials (SBOMs), image signing, registry policies, severity thresholds, exception handling, and recurring rescans.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Docker packages applications with the code, libraries, and dependencies needed to run them inside containers. This makes the image itself an important security boundary: the contents selected during the build can move through testing and into production. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/ce-este-docker-elementul-central-al-containerizarii-moderne\/\">Docker builds and runs applications inside containers<\/a>, and <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/intelegerea-arhitecturii-de-containerizare-a-docker\/\">container isolation depends on packaging an application with its dependencies<\/a>.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#1_Set_a_base-image_policy\" >1. Set a base-image policy<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#2_Scan_images_before_they_reach_the_registry\" >2. Scan images before they reach the registry<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#3_Define_severity_thresholds\" >3. Define severity thresholds<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#4_Check_for_secrets_and_malware\" >4. Check for secrets and malware<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#5_Generate_and_retain_an_SBOM\" >5. Generate and retain an SBOM<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#6_Sign_images_and_enforce_registry_controls\" >6. Sign images and enforce registry controls<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#7_Handle_exceptions_as_controlled_decisions\" >7. Handle exceptions as controlled decisions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#8_Rescan_images_after_publication\" >8. Rescan images after publication<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/container-image-security-checklist-trivy-grype-docker-scout-and-registry-controls\/#Final_release_checklist\" >Final release checklist<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Set_a_base-image_policy\"><\/span>1. Set a base-image policy<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-3684178535\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Start each image review with the base image. Record which base image the build uses and apply the same approval rules to every repository. The policy should define:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Which base images are allowed.<\/li>\n\n\n\n<li>Who can approve a new base image.<\/li>\n\n\n\n<li>When a base image must be replaced or rebuilt.<\/li>\n\n\n\n<li>Which vulnerability results block the build.<\/li>\n\n\n\n<li>How the selected base image is tracked in the image record and SBOM.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Keep the build focused on the packages and dependencies required by the application. Every dependency included in the image becomes part of the security review. A base-image change should therefore trigger a new scan and a new review of the resulting SBOM.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Scan_images_before_they_reach_the_registry\"><\/span>2. Scan images before they reach the registry<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Add a vulnerability scan after the image is built and before it is accepted by the registry. Trivy, Grype, and Docker Scout are examples of tools that can be used for this stage. Select a tool or tool combination, then apply the same pass and fail rules in every pipeline.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Build the container image from the approved base image.<\/li>\n\n\n\n<li>Run the configured vulnerability scanner against the built image.<\/li>\n\n\n\n<li>Store the scan result with the image build record.<\/li>\n\n\n\n<li>Compare findings with the repository&#8217;s severity threshold.<\/li>\n\n\n\n<li>Stop publication when a finding meets the blocking rule and has no approved exception.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The pipeline should evaluate the image that will actually be published. Scanning only a source repository or only the base image does not replace scanning the final image, because the final image contains the application and its selected dependencies.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Define_severity_thresholds\"><\/span>3. Define severity thresholds<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Severity thresholds turn scan results into a consistent release decision. Define the minimum severity that blocks publication and apply that rule to both new findings and findings that remain unresolved from earlier builds.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Result<\/th><th>Required pipeline action<\/th><\/tr><\/thead><tbody><tr><td>Finding below the blocking threshold<\/td><td>Record the result and continue according to the repository policy.<\/td><\/tr><tr><td>Finding at or above the blocking threshold<\/td><td>Stop publication unless an approved exception applies.<\/td><\/tr><tr><td>Finding covered by an approved exception<\/td><td>Record the exception, its owner, its reason, and its review date before allowing the defined release path.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Keep the threshold policy visible to the team. A scanner result should not require an individual developer to decide what \u201chigh risk\u201d means for each build.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"4_Check_for_secrets_and_malware\"><\/span>4. Check for secrets and malware<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vulnerability scanning is only one part of the image review. Add separate checks for secrets and malware before publication.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Scan image contents and build output for credentials, tokens, private keys, and other secrets.<\/li>\n\n\n\n<li>Scan image contents for malware using the security checks selected by your organisation.<\/li>\n\n\n\n<li>Block publication when a secret or malware result meets the repository&#8217;s blocking rule.<\/li>\n\n\n\n<li>Record the result of each check with the image build record.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not treat a vulnerability scan as evidence that the image passed secret and malware checks. Keep these results as distinct controls so that each one has a clear pass or fail outcome.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"5_Generate_and_retain_an_SBOM\"><\/span>5. Generate and retain an SBOM<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Generate a software bill of materials for every image that is considered for publication. The SBOM should represent the final image and list the application components, libraries, and dependencies included in it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Store the SBOM with the image&#8217;s build record and connect it to the image identifier. Regenerate it when the image is rebuilt, when the base image changes, or when dependencies change. Use the SBOM as the component record for vulnerability review, exception decisions, and recurring rescans.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"6_Sign_images_and_enforce_registry_controls\"><\/span>6. Sign images and enforce registry controls<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sign an image after the required build checks pass. The registry policy should accept deployment only for images that meet the signing requirement and the configured scan policy.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Allow publication only from approved build pipelines.<\/li>\n\n\n\n<li>Require a valid signature before deployment.<\/li>\n\n\n\n<li>Keep scan results and the SBOM linked to the published image.<\/li>\n\n\n\n<li>Prevent deployment of images that fail the severity threshold.<\/li>\n\n\n\n<li>Use the same controls for every production image repository.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These controls connect the build decision to the deployment decision. An image that was scanned or signed at one point should not bypass the registry policy when it is later selected for production.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"7_Handle_exceptions_as_controlled_decisions\"><\/span>7. Handle exceptions as controlled decisions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An exception should be a recorded security decision, not an informal approval in chat or a pipeline setting that stays disabled. For each exception, record:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The image and finding covered.<\/li>\n\n\n\n<li>The reason the release is allowed.<\/li>\n\n\n\n<li>The owner responsible for the decision.<\/li>\n\n\n\n<li>The compensating action, if one is defined by policy.<\/li>\n\n\n\n<li>The review or expiry date.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Make the pipeline check that the exception is still active. When it expires, the normal severity threshold should apply again. Reassess the exception when the image, dependency set, or vulnerability result changes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"8_Rescan_images_after_publication\"><\/span>8. Rescan images after publication<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Run recurring rescans for images that remain available in the registry and images that are deployed. New vulnerability information can change the result for an image that previously passed the pipeline, so the initial build scan is not the end of the review.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Select the images and repositories included in recurring scans.<\/li>\n\n\n\n<li>Run the configured vulnerability, secret, and malware checks again.<\/li>\n\n\n\n<li>Compare new results with the repository severity threshold.<\/li>\n\n\n\n<li>Open remediation work for newly blocking findings.<\/li>\n\n\n\n<li>Restrict deployment when a published image no longer meets policy.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Keep the recurring scan result, SBOM, signature status, and exception record connected to the same image identity. This gives the team one audit trail from build through deployment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Final_release_checklist\"><\/span>Final release checklist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Approved base image selected and recorded.<\/li>\n\n\n\n<li>Final image scanned with Trivy, Grype, Docker Scout, or the approved scanning combination.<\/li>\n\n\n\n<li>Severity threshold applied consistently.<\/li>\n\n\n\n<li>Secret detection completed.<\/li>\n\n\n\n<li>Malware detection completed.<\/li>\n\n\n\n<li>SBOM generated for the final image.<\/li>\n\n\n\n<li>Image signed after successful checks.<\/li>\n\n\n\n<li>Registry policy enforces scan and signature requirements.<\/li>\n\n\n\n<li>Exceptions are owned, documented, and time-bound.<\/li>\n\n\n\n<li>Recurring rescans are scheduled for retained and deployed images.<\/li>\n<\/ul>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[42],"manual_kb_tag":[],"class_list":["post-12854","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-miscellaneous"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/12854","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/12854\/revisions"}],"predecessor-version":[{"id":12855,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/12854\/revisions\/12855"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=12854"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=12854"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=12854"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}