DevSecOps EngineerAvailable

Container Scanning Essentials

About this course

Containers ship your code and its entire dependency tree. This course covers image scanning with Trivy, SBOM generation, distroless base images, runtime detection with Falco, and admission control to block vulnerable images before they reach production.

What you will learn

  • Container image layers and how vulnerabilities accumulate
  • Scanning with Trivy and Grype: interpreting results
  • SBOM generation with Syft for supply chain visibility
  • Base image selection: Alpine, distroless, and scratch
  • Multi-stage builds for minimal production images
  • Runtime threat detection with Falco
  • Admission controllers that block vulnerable images
  • Integrating scanning into CI/CD pipelines

Your instructor

Ayodele Ajayi

Principal Engineer

Principal Engineer based in Kent, UK, with extensive experience across cloud-native security, platform engineering, and distributed systems. Ayodele has led engineering teams at scale and writes about what he learns — with a bias towards things that actually work in production.

Continue building your skills in this area.

CI/CD Security Hardening

8 lessons

Kubernetes Production Patterns

8 lessons