<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://xinux.net/index.php?action=history&amp;feed=atom&amp;title=Cve_scanner</id>
	<title>Cve scanner - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://xinux.net/index.php?action=history&amp;feed=atom&amp;title=Cve_scanner"/>
	<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=Cve_scanner&amp;action=history"/>
	<updated>2026-08-23T17:26:12Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://xinux.net/index.php?title=Cve_scanner&amp;diff=72587&amp;oldid=prev</id>
		<title>Thomas.will am 11. August 2026 um 11:26 Uhr</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=Cve_scanner&amp;diff=72587&amp;oldid=prev"/>
		<updated>2026-08-11T11:26:56Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 11. August 2026, 11:26 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l27&quot; &gt;Zeile 27:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 27:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Image scannen (alle Severities)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy image nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy image nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Nur kritische und hohe Findings anzeigen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy image --severity CRITICAL,HIGH nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy image --severity CRITICAL,HIGH nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Lokales Dateisystem/Repo-Checkout scannen (z.B. installierte Pakete, Sprach-Dependencies wie package-lock.json, requirements.txt)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy fs /pfad/zum/repo&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy fs /pfad/zum/repo&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;IaC-Definitionen auf Fehlkonfigurationen prüfen (z.B. offene Security Groups, fehlende Verschlüsselung)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy config /pfad/zu/terraform&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy config /pfad/zu/terraform&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Remote-Git-Repo direkt scannen, ohne vorher zu klonen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy repo https://github.com/beispiel/projekt&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* trivy repo https://github.com/beispiel/projekt&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l54&quot; &gt;Zeile 54:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 64:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;SBOM aus dem Image erzeugen und als JSON-Datei speichern (Inventar: welche Pakete/Bibliotheken stecken im Image)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* syft nginx:latest -o json &amp;gt; sbom.json&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* syft nginx:latest -o json &amp;gt; sbom.json&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Gespeicherte SBOM gegen die Vulnerability-DB scannen (Bewertung: welche CVEs betreffen die im Inventar erfassten Pakete)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* grype sbom:sbom.json&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* grype sbom:sbom.json&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;* grype nginx:latest (direkter &lt;/del&gt;Scan ohne separate SBOM, für schnelle Checks&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;;Direkter &lt;/ins&gt;Scan ohne separate SBOM&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;-Datei&lt;/ins&gt;, für schnelle &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Ad-hoc-&lt;/ins&gt;Checks&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* grype nginx:latest&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Best Practice&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Best Practice&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l73&quot; &gt;Zeile 73:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 89:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;CVEs eines Images auflisten&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* docker scout cves nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* docker scout cves nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Zwei Image-Versionen gegeneinander vergleichen (zeigt, welche CVEs durch das Update behoben bzw. neu hinzugekommen sind)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* docker scout compare nginx:latest --to nginx:1.25&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* docker scout compare nginx:latest --to nginx:1.25&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Konkrete Handlungsempfehlungen anzeigen (z.B. &amp;quot;auf neueres Base-Image wechseln&amp;quot;)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* docker scout recommendations nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* docker scout recommendations nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l103&quot; &gt;Zeile 103:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 125:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Projektverzeichnis scannen und HTML-Report erzeugen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* dependency-check --project MeinProjekt --scan /pfad/zum/projekt --format HTML --out ./report&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* dependency-check --project MeinProjekt --scan /pfad/zum/projekt --format HTML --out ./report&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l121&quot; &gt;Zeile 121:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 145:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Grundlegende Nutzung&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Dependencies im aktuellen Projektverzeichnis scannen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* snyk test&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* snyk test&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;Container-Image scannen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* snyk container test nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* snyk container test nginx:latest&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;;IaC-Dateien (Terraform, Kubernetes, CloudFormation) auf Fehlkonfigurationen prüfen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* snyk iac test&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* snyk iac test&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;* snyk monitor (&lt;/del&gt;kontinuierliches Monitoring&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;, &lt;/del&gt;meldet &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;neue &lt;/del&gt;CVEs &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;auch nach dem initialen Scan&lt;/del&gt;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;;Projekt bei Snyk registrieren für &lt;/ins&gt;kontinuierliches Monitoring &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;(&lt;/ins&gt;meldet &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;auch neu bekanntgewordene &lt;/ins&gt;CVEs &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;für bereits gescannte, unveränderte Projekte&lt;/ins&gt;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* snyk monitor&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Best Practice&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;;Best Practice&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://xinux.net/index.php?title=Cve_scanner&amp;diff=72586&amp;oldid=prev</id>
		<title>Thomas.will: Die Seite wurde neu angelegt: „== CVE-Scanner: Container, Dependencies und Compliance ==  Diese Seite vergleicht die gängigen Open-Source- und kommerziellen Scanner für Container-Images, S…“</title>
		<link rel="alternate" type="text/html" href="https://xinux.net/index.php?title=Cve_scanner&amp;diff=72586&amp;oldid=prev"/>
		<updated>2026-08-11T11:22:22Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „== CVE-Scanner: Container, Dependencies und Compliance ==  Diese Seite vergleicht die gängigen Open-Source- und kommerziellen Scanner für Container-Images, S…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== CVE-Scanner: Container, Dependencies und Compliance ==&lt;br /&gt;
&lt;br /&gt;
Diese Seite vergleicht die gängigen Open-Source- und kommerziellen Scanner für Container-Images, Software-Abhängigkeiten und System-Compliance. Für jedes Tool: Funktionsweise, Installation, Nutzung und Best Practices aus der Kurspraxis.&lt;br /&gt;
&lt;br /&gt;
=== Trivy ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
Trivy (Aqua Security) scannt Container-Images, Dateisysteme, Git-Repositories und IaC-Definitionen (Terraform, Kubernetes-Manifeste, Dockerfiles) auf bekannte CVEs, hartcodierte Secrets und Fehlkonfigurationen. Die Vulnerability-Daten stammen aus mehreren Quellen (NVD, GitHub Security Advisories, distributionsspezifische Feeds wie Debian/RHEL Security Tracker) und werden in einer lokalen SQLite-DB gecacht.&lt;br /&gt;
&lt;br /&gt;
;Installation (Debian/Ubuntu)&lt;br /&gt;
* sudo apt-get install wget apt-transport-https gnupg lsb-release&lt;br /&gt;
* wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key | sudo gpg --dearmor -o /usr/share/keyrings/trivy.gpg&lt;br /&gt;
* echo &amp;quot;deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb $(lsb_release -sc) main&amp;quot; | sudo tee -a /etc/apt/sources.list.d/trivy.list&lt;br /&gt;
* sudo apt-get update&lt;br /&gt;
* sudo apt-get install trivy&lt;br /&gt;
&lt;br /&gt;
;Installation (Rocky Linux/RHEL)&lt;br /&gt;
* sudo tee /etc/yum.repos.d/trivy.repo &amp;lt;&amp;lt;EOF&lt;br /&gt;
* [trivy]&lt;br /&gt;
* name=Trivy repository&lt;br /&gt;
* baseurl=https://aquasecurity.github.io/trivy-repo/rpm/releases/$releasever/$basearch/&lt;br /&gt;
* gpgcheck=1&lt;br /&gt;
* enabled=1&lt;br /&gt;
* gpgkey=https://aquasecurity.github.io/trivy-repo/rpm/public.key&lt;br /&gt;
* EOF&lt;br /&gt;
* sudo dnf install trivy&lt;br /&gt;
&lt;br /&gt;
;Grundlegende Nutzung&lt;br /&gt;
* trivy image nginx:latest&lt;br /&gt;
* trivy image --severity CRITICAL,HIGH nginx:latest&lt;br /&gt;
* trivy fs /pfad/zum/repo&lt;br /&gt;
* trivy config /pfad/zu/terraform&lt;br /&gt;
* trivy repo https://github.com/beispiel/projekt&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* In CI/CD als Quality Gate einbauen, damit Builds mit kritischen Findings fehlschlagen:&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
trivy image --exit-code 1 --severity CRITICAL,HIGH myapp:latest&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
* Akzeptierte Risiken über &amp;lt;code&amp;gt;.trivyignore&amp;lt;/code&amp;gt; dokumentieren statt Severity-Filter pauschal herunterzudrehen – so bleibt nachvollziehbar, warum ein Finding ignoriert wird&lt;br /&gt;
* DB regelmäßig separat aktualisieren, besonders wenn viele Scans hintereinander laufen:&lt;br /&gt;
* trivy image --download-db-only&lt;br /&gt;
* Für Kursumgebungen ideal als Einstiegstool, da Ergebnis innerhalb von 1–2 Minuten ohne Account oder Cloud-Anbindung sichtbar ist&lt;br /&gt;
* SARIF- oder JSON-Ausgabe (&amp;lt;code&amp;gt;--format json&amp;lt;/code&amp;gt;) eignet sich gut, um Ergebnisse später mit &amp;lt;code&amp;gt;jq&amp;lt;/code&amp;gt; auszuwerten oder in ein SIEM (z.B. Wazuh) einzuspeisen&lt;br /&gt;
&lt;br /&gt;
=== Grype ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
Grype (Anchore) verfolgt einen ähnlichen Ansatz wie Trivy, ist aber konzeptionell auf Zusammenspiel mit Syft ausgelegt: Syft erzeugt eine Software Bill of Materials (SBOM), Grype scannt anschließend gegen diese SBOM statt direkt gegen das Image. Das entkoppelt Inventarisierung (was ist überhaupt installiert) von Bewertung (welche CVEs betreffen das).&lt;br /&gt;
&lt;br /&gt;
;Installation&lt;br /&gt;
* curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sudo sh -s -- -b /usr/local/bin&lt;br /&gt;
* curl -sSfL https://raw.githubusercontent.com/anchore/syft/main/install.sh | sudo sh -s -- -b /usr/local/bin&lt;br /&gt;
&lt;br /&gt;
;Grundlegende Nutzung&lt;br /&gt;
* syft nginx:latest -o json &amp;gt; sbom.json&lt;br /&gt;
* grype sbom:sbom.json&lt;br /&gt;
* grype nginx:latest (direkter Scan ohne separate SBOM, für schnelle Checks)&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* SBOM einmal erzeugen und archivieren, dann wiederholt gegen aktualisierte Vulnerability-DB scannen – spart Zeit und liefert einen Audit-Trail, wann welche Komponenten im Image steckten&lt;br /&gt;
* SBOM-Datei als Artefakt in der CI/CD-Pipeline ablegen, nicht nur den Scan-Report – für Lieferketten-Nachweise (Supply Chain Security) zunehmend relevant&lt;br /&gt;
* Gut geeignet, um im Kurs den Unterschied zwischen &amp;quot;Inventar erstellen&amp;quot; (Syft) und &amp;quot;Inventar bewerten&amp;quot; (Grype) als zwei getrennte Schritte zu demonstrieren&lt;br /&gt;
&lt;br /&gt;
=== Docker Scout ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
Docker Scout ist direkt in Docker Desktop und die Docker CLI integriert und braucht daher kein separates Tool, wenn Docker ohnehin im Einsatz ist. Es zeigt CVEs an, vergleicht Image-Versionen gegeneinander und gibt Empfehlungen (z.B. &amp;quot;neueres Base-Image verwenden&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
;Installation&lt;br /&gt;
* Ab Docker CLI 24 ist das Plugin standardmäßig vorhanden&lt;br /&gt;
* Falls nicht vorhanden: sudo apt-get install docker-scout-plugin&lt;br /&gt;
&lt;br /&gt;
;Grundlegende Nutzung&lt;br /&gt;
* docker scout cves nginx:latest&lt;br /&gt;
* docker scout compare nginx:latest --to nginx:1.25&lt;br /&gt;
* docker scout recommendations nginx:latest&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* &amp;lt;code&amp;gt;docker scout compare&amp;lt;/code&amp;gt; eignet sich besonders gut für Kursvorführungen zum Thema Patch-Management: &amp;quot;ist mein neues Image besser oder schlechter als das alte&amp;quot;&lt;br /&gt;
* Kostenlose Nutzung ist pro Nutzer/Organisation limitiert – vor dem Kurs prüfen, ob die Free-Tier-Grenzen für die Teilnehmerzahl reichen&lt;br /&gt;
* Da es in der Docker-Toolchain &amp;quot;mitläuft&amp;quot;, eignet es sich gut, um zu zeigen, dass Security-Scanning kein Extra-Tool sein muss, sondern in bestehende Workflows integriert werden kann&lt;br /&gt;
&lt;br /&gt;
=== Clair ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
Clair läuft als Backend-Service (eigener API-Server plus PostgreSQL-Datenbank) und wird meist hinter einer Registry wie Harbor oder Quay betrieben statt als CLI-Tool für Ad-hoc-Scans genutzt. Images werden automatisch beim Push in die Registry gescannt.&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* Nicht für schnelle Kurs-Demos geeignet – der Setup-Aufwand (DB, API-Server, Registry-Anbindung) steht in keinem guten Verhältnis zum Lerneffekt gegenüber Trivy/Grype&lt;br /&gt;
* Sinnvoll als Beispiel für &amp;quot;Enterprise-Registry-Scanning&amp;quot;, falls Harbor oder Quay bereits Teil der Kursumgebung ist&lt;br /&gt;
* Bei Zeitdruck im Kurs zugunsten von Trivy/Grype überspringen&lt;br /&gt;
&lt;br /&gt;
=== OWASP Dependency-Check ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
Prüft Software-Abhängigkeiten (Schwerpunkt Java/.NET, aber auch Node.js, Python, Ruby, PHP) gegen die NVD und identifiziert Bibliotheken mit bekannten CVEs. Läuft als eigenständige CLI, als Maven-/Gradle-Plugin oder als Jenkins-Plugin.&lt;br /&gt;
&lt;br /&gt;
;Installation&lt;br /&gt;
* wget https://github.com/jeremylong/DependencyCheck/releases/download/v10.0.0/dependency-check-10.0.0-release.zip&lt;br /&gt;
* unzip dependency-check-10.0.0-release.zip -d /opt/&lt;br /&gt;
* ln -s /opt/dependency-check/bin/dependency-check.sh /usr/local/bin/dependency-check&lt;br /&gt;
&lt;br /&gt;
;Grundlegende Nutzung&lt;br /&gt;
* dependency-check --project MeinProjekt --scan /pfad/zum/projekt --format HTML --out ./report&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* NVD-API-Key kostenlos beantragen (https://nvd.nist.gov/developers/request-an-api-key) und über &amp;lt;code&amp;gt;--nvdApiKey&amp;lt;/code&amp;gt; übergeben – ohne Key ist das Rate-Limiting beim ersten DB-Update sehr streng und der Download kann eine Stunde oder länger dauern&lt;br /&gt;
* Ersten DB-Download vor Kursbeginn anstoßen und den Cache-Ordner (&amp;lt;code&amp;gt;~/.m2/repository/org/owasp&amp;lt;/code&amp;gt; bzw. &amp;lt;code&amp;gt;data&amp;lt;/code&amp;gt;-Verzeichnis) für alle Teilnehmer-VMs vorbereiten, statt live im Kurs zu warten&lt;br /&gt;
* HTML-Report eignet sich gut zum gemeinsamen Durchgehen, da er CVSS-Score, betroffene Datei und Beschreibung übersichtlich verknüpft&lt;br /&gt;
* Bei False Positives &amp;lt;code&amp;gt;suppression.xml&amp;lt;/code&amp;gt; nutzen statt Findings zu ignorieren – macht Ausnahmen dokumentiert und nachvollziehbar&lt;br /&gt;
&lt;br /&gt;
=== Snyk ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
Snyk deckt Dependencies, Container-Images, Infrastructure-as-Code und eigenen Anwendungscode (SAST) ab und bietet sehr gute Entwicklerintegration (VS Code, GitHub, GitLab, Jenkins). Betrieben als Freemium-SaaS mit monatlichem Test-Limit in der kostenlosen Stufe.&lt;br /&gt;
&lt;br /&gt;
;Installation&lt;br /&gt;
* sudo npm install -g snyk&lt;br /&gt;
* snyk auth&lt;br /&gt;
&lt;br /&gt;
;Grundlegende Nutzung&lt;br /&gt;
* snyk test&lt;br /&gt;
* snyk container test nginx:latest&lt;br /&gt;
* snyk iac test&lt;br /&gt;
* snyk monitor (kontinuierliches Monitoring, meldet neue CVEs auch nach dem initialen Scan)&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* Account-Erstellung und Auth-Flow vor Kursbeginn klären – im Gegensatz zu Trivy ist Snyk nicht ohne Login sofort nutzbar, das kostet sonst Unterrichtszeit&lt;br /&gt;
* &amp;lt;code&amp;gt;snyk monitor&amp;lt;/code&amp;gt; eignet sich gut als Kontrastpunkt zu einmaligen CLI-Scans: zeigt, wie kontinuierliches Vulnerability-Monitoring in echten Teams aussieht (Snyk meldet auch neu bekanntgewordene CVEs für bereits gescannte, unveränderte Projekte)&lt;br /&gt;
* Free-Tier-Limits vorher prüfen, wenn mehrere Teilnehmer parallel mit eigenen Accounts arbeiten&lt;br /&gt;
&lt;br /&gt;
=== OpenSCAP ===&lt;br /&gt;
&lt;br /&gt;
;Was es macht&lt;br /&gt;
OpenSCAP ist kein reiner CVE-Scanner im engeren Sinn, sondern ein Compliance- und Configuration-Scanner nach dem SCAP-Standard (Security Content Automation Protocol). Es prüft Systeme gegen Policies wie CIS Benchmarks, DISA STIG oder PCI-DSS. Zusätzlich kann es über OVAL-Definitionen (Open Vulnerability and Assessment Language) auch klassisches CVE-Scanning durchführen, sofern die jeweilige Distribution offizielle OVAL-Feeds bereitstellt – bei RHEL-basierten Systemen (RHEL, Rocky, CentOS) ist das der Fall.&lt;br /&gt;
&lt;br /&gt;
;Zwei Anwendungsfälle&lt;br /&gt;
* '''Configuration Compliance''': prüft z.B. ob SSH-Root-Login deaktiviert ist oder Passwort-Policies den Vorgaben entsprechen&lt;br /&gt;
* '''Vulnerability Scanning via OVAL''': nutzt distributionsspezifische OVAL-Feeds, um installierte Pakete gegen bekannte CVEs zu prüfen&lt;br /&gt;
&lt;br /&gt;
;Installation (Rocky Linux/RHEL)&lt;br /&gt;
* sudo dnf install openscap-scanner scap-security-guide&lt;br /&gt;
&lt;br /&gt;
;CVE-Scan gegen offiziellen Red-Hat-OVAL-Feed&lt;br /&gt;
* wget https://www.redhat.com/security/data/oval/v2/RHEL9/rhel-9.oval.xml.bz2&lt;br /&gt;
* bzip2 -d rhel-9.oval.xml.bz2&lt;br /&gt;
* oscap oval eval --results scan-results.xml rhel-9.oval.xml&lt;br /&gt;
&lt;br /&gt;
;Compliance-Scan gegen CIS-Benchmark&lt;br /&gt;
&amp;lt;syntaxhighlight lang=&amp;quot;bash&amp;quot;&amp;gt;&lt;br /&gt;
oscap xccdf eval \&lt;br /&gt;
  --profile cis \&lt;br /&gt;
  --results results.xml \&lt;br /&gt;
  --report report.html \&lt;br /&gt;
  /usr/share/xml/scap/ssg/content/ssg-rl9-ds.xml&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
;Verfügbare Profile anzeigen&lt;br /&gt;
* oscap info /usr/share/xml/scap/ssg/content/ssg-rl9-ds.xml&lt;br /&gt;
&lt;br /&gt;
;Best Practice&lt;br /&gt;
* Thematisch sehr passend für den Rocky-Linux-Kurs, da &amp;lt;code&amp;gt;scap-security-guide&amp;lt;/code&amp;gt; fertige Profile für Rocky/RHEL mitbringt und keine Zusatzkonfiguration braucht&lt;br /&gt;
* Im Kurs gut geeignet, um den Unterschied zwischen Vulnerability Scanning (Trivy, Grype, Snyk – &amp;quot;welche bekannte Schwachstelle steckt in dieser Software&amp;quot;) und Compliance/Baseline Scanning (OpenSCAP – &amp;quot;entspricht dieses System einer Sicherheitsrichtlinie&amp;quot;) klarzumachen; die beiden werden von Teilnehmern häufig verwechselt&lt;br /&gt;
* HTML-Report (&amp;lt;code&amp;gt;report.html&amp;lt;/code&amp;gt;) ist sehr anschaulich für die Vorführung, zeigt Pass/Fail pro Regel inklusive Begründung und Referenz auf den Benchmark-Punkt&lt;br /&gt;
* Remediation-Skripte lassen sich direkt aus dem Profil generieren:&lt;br /&gt;
* oscap xccdf generate fix --profile cis --output remediate.sh /usr/share/xml/scap/ssg/content/ssg-rl9-ds.xml&lt;br /&gt;
* Remediation-Skripte im Kurs ausschließlich auf einer Wegwerf-VM testen, nie auf einer produktiv genutzten Maschine, da Änderungen (z.B. an SSH- oder PAM-Konfiguration) Systeme aussperren können&lt;br /&gt;
&lt;br /&gt;
=== Übersicht ===&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
! Tool !! Scope !! Setup-Aufwand !! Kosten&lt;br /&gt;
|-&lt;br /&gt;
| Trivy || Images, Filesystem, IaC || sehr gering || kostenlos&lt;br /&gt;
|-&lt;br /&gt;
| Grype || Images (via SBOM) || gering || kostenlos&lt;br /&gt;
|-&lt;br /&gt;
| Docker Scout || Images (Docker-integriert) || sehr gering || Freemium&lt;br /&gt;
|-&lt;br /&gt;
| Clair || Images (Registry-Backend) || hoch || kostenlos&lt;br /&gt;
|-&lt;br /&gt;
| OWASP Dependency-Check || Code-Dependencies || mittel (erster DB-Download) || kostenlos&lt;br /&gt;
|-&lt;br /&gt;
| Snyk || Dependencies, Images, IaC, Code || mittel (Account nötig) || Freemium&lt;br /&gt;
|-&lt;br /&gt;
| OpenSCAP || System-Compliance + OVAL-CVEs || gering (RHEL-Familie) || kostenlos&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Kategorie:Sicherheit]]&lt;br /&gt;
[[Kategorie:CVE-Scanner]]&lt;/div&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
</feed>