Back to the line that added it
Every package is attributed to the layer and Dockerfile instruction that installed it, so the fix is an edit to a file your team owns.
Scan container images and their layers for vulnerable OS and language packages, trace each one back to the Dockerfile line that added it, and pick the smallest base-image change that fixes the most.
| Layer | Vulns |
|---|---|
FROM node:18-bullseyeBase image | 29 |
RUN apt-get install -y imagemagick | 7 |
COPY package*.json . && npm ci | 2 |
USER rootRuns as root | 0 |
| 1 | −FROM node:18-bullseye | |
| 1 | +FROM node:22-bookworm-slim |
Read images from your registry or build them from the Dockerfile.
Inventory OS and language packages layer by layer.
Tie each package to the instruction that installed it.
Recommend the base image and edits that fix the most.
Every package is attributed to the layer and Dockerfile instruction that installed it, so the fix is an edit to a file your team owns.
Most image vulnerabilities come from the base. winfunc compares candidate base images and recommends the one that removes the most risk for the least change.
Findings are weighed against what the service actually runs, so a vulnerable library the process never loads does not outrank one it calls on every request.
Image findings sit beside the code, dependency, and IaC findings for the same service, with the same statuses and the same pull-request fixes.
Continue the evaluation
Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.
