DevSecOps EngineerAvailable
Container Scanning Essentials
About this course
Containers ship your code and its entire dependency tree. This course covers image scanning with Trivy, SBOM generation, distroless base images, runtime detection with Falco, and admission control to block vulnerable images before they reach production.
What you will learn
- Container image layers and how vulnerabilities accumulate
- Scanning with Trivy and Grype: interpreting results
- SBOM generation with Syft for supply chain visibility
- Base image selection: Alpine, distroless, and scratch
- Multi-stage builds for minimal production images
- Runtime threat detection with Falco
- Admission controllers that block vulnerable images
- Integrating scanning into CI/CD pipelines
Your instructor
Ayodele Ajayi
Principal Engineer
Principal Engineer based in Kent, UK, with extensive experience across cloud-native security, platform engineering, and distributed systems. Ayodele has led engineering teams at scale and writes about what he learns — with a bias towards things that actually work in production.