Scan Dependency Vulnerabilities
The built-in Osv Source Scanner scans dependency manifests and lock files, publishes a vulnerability report, and fails the build when findings reach your chosen severity threshold.
Scan Image Vulnerability Before Push
Build a multi-platform image into an OCI layout, scan each platform, and push only if the scan passes.
Promote Image If No Vulnerabilities Found
Pull an existing image into an OCI layout, scan it, and publish that same layout to a release repository only when it passes the configured threshold.