Skip to content
winfunc
Containers
Available

Know what is inside every image you ship.

Scan container images and their layers for vulnerable OS and language packages, trace each one back to the Dockerfile line that added it, and pick the smallest base-image change that fixes the most.

  1. acme
  2. /Images
  3. /billing-api:2026.09.24
38 vulnerabilities
408 packages
LayerVulns
FROM node:18-bullseyeBase image29
RUN apt-get install -y imagemagick7
COPY package*.json . && npm ci2
USER rootRuns as root0
Recommended base imageRemoves 29 of 38
Dockerfile+1−1
1−FROM node:18-bullseye
1+FROM node:22-bookworm-slim
Containers · image layersIllustrative data
What it does

Capabilities.

  • OS packages across Alpine, Debian, Ubuntu, Red Hat, and distroless images
  • Language packages installed inside the image
  • Layer-by-layer attribution back to the Dockerfile instruction
  • Base-image recommendations ranked by vulnerabilities removed
  • Images from Docker Hub, Amazon ECR, Google Artifact Registry, Azure Container Registry, and GitHub Packages
  • Secrets and misconfigurations baked into image layers
  • Running-as-root, exposed ports, and other runtime settings
  • Image SBOM export in CycloneDX and SPDX
How it works

From inventory to a verified upgrade.

  1. Step 1

    Pull

    Read images from your registry or build them from the Dockerfile.

  2. Step 2

    Unpack

    Inventory OS and language packages layer by layer.

  3. Step 3

    Attribute

    Tie each package to the instruction that installed it.

  4. Step 4

    Rebase

    Recommend the base image and edits that fix the most.

Why it matters

Built for decisions, not queues.

01

Back to the line that added it

Every package is attributed to the layer and Dockerfile instruction that installed it, so the fix is an edit to a file your team owns.

02

The base image, first

Most image vulnerabilities come from the base. winfunc compares candidate base images and recommends the one that removes the most risk for the least change.

03

Reachable in your service

Findings are weighed against what the service actually runs, so a vulnerable library the process never loads does not outrank one it calls on every request.

04

One workspace

Image findings sit beside the code, dependency, and IaC findings for the same service, with the same statuses and the same pull-request fixes.

Continue the evaluation

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified