0 Try the Demo

Vulnerability Scans

Scan your Docker images with Trivy on a schedule and see what to patch first.

Arcane scans your Docker images for known vulnerabilities (CVEs) with Trivy, an open-source vulnerability scanner, and saves the results for each image. It then ranks findings by risk so you know which images to fix first, and can patch some of them for you.

Review affected packages and available fixes, ordered by severity.

Turn on scanning

  1. Open Environments and select the environment.
  2. On the Features tab, make sure Vulnerability management is on.
  3. On the Automations tab, turn on the vulnerability scan job.
  4. Optional: change the job’s schedule. It uses 6-field cron syntax, with seconds first. The default 0 0 0 * * * runs daily at midnight. Changes apply without a restart.

To scan right away, open Security in the sidebar and click Scan all images.

Review results

Open Security in the sidebar. The overview shows the environment’s risk score and which images and CVEs to fix first. The Vulnerabilities tab lists every finding, and the Patches tab lets you apply supported fixes.

The overview contains:

Card What it shows
Risk score The environment score, its band, and the change from 7 days ago.
Highest-priority fix The fixable finding with the highest risk, with its image, package, and fixed version.
Trend Daily scores over 30 or 90 days.
Known exploited, Overdue KEV Findings in the CISA KEV catalog, and those past CISA’s remediation due date.
Likely exploited Findings with an EPSS probability of 10% or more.
Running critical/high, Images scanned Critical and high findings in running containers, and how many images have been scanned.
Findings by severity, Findings by exposure All findings, including ones without a fix.
Top vulnerabilities The 10 highest-risk CVEs. Sort by Prevalence to see which CVEs appear in the most images.
Images to prioritize The 5 highest-scoring images.

Filter and export results

Use Fixable in the Vulnerabilities table to show only findings with a known fixed version. This filters saved results and doesn’t change what future scans collect. To stop scans from recording unfixable findings at all, turn on Only Report Fixable Vulnerabilities (see Configure scans).

Click Export CSV to download every result that matches the current search and filters, including Show ignored and Fixable, across all pages.

Patch image vulnerabilities

Arcane can patch fixable OS-package vulnerabilities with Copacetic (copa), an image patching tool, instead of waiting for the image’s publisher to release a fixed version.

  1. Open Security → Patches. The table lists scanned images with their fixable CVE counts, last scan time, last patch status, and patched tag.
  2. Click Patch on a row. You can also patch from the image detail page or the Images table row menu.
  3. Follow progress in the Activity Center. Patches run in the background, one at a time, and need the images:patch permission.
  4. Redeploy your containers against the new tag to use the patched image.

What happens during a patch:

  • Arcane runs copa against the Docker daemon’s built-in BuildKit (Docker’s image build engine). No helper container is started, and Arcane’s stored registry credentials are used to pull.
  • If the image’s latest scan has a stored report, only the vulnerabilities in that report are patched. Without one, copa updates every outdated OS package in the image.
  • The result is tagged with a suffix, so nginx:1.25 becomes nginx:1.25-patched by default. It exists only in the local Docker daemon. Nothing is pushed, and running containers are not touched.
  • Arcane re-scans the patched image afterwards, and the Patches table shows the result.

What can’t be patched:

  • Vulnerabilities in language or application dependencies (npm, pip, Go modules, and so on). Only OS packages are patched; rebuild the image for the rest.
  • Locally built images with no registry source. Rebuild them instead.
  • Untagged images.

Schedule patching

Turn on Scheduled Image Patching under Environments → your environment → Security → Image Patching, and set the patch job’s schedule in Automations. The default 0 0 3 * * * runs daily at 03:00. Each run patches scanned images in the local Docker environment that have a stored report and haven’t been patched since their latest scan.

Configure scans

Scan settings live under Environments → your environment → Security → Vulnerability Scanning and apply to every scan in that environment. Run a new scan to refresh saved results after changing them.

  • Only Report Fixable Vulnerabilities records only vulnerabilities that have a known fixed version.
  • Trivy Config (YAML) takes the contents of a trivy.yaml file.
  • .trivyignore takes one vulnerability ID per line. Lines starting with # are comments.

Options Arcane passes on the command line win over the YAML: output format, timeout, cache directory, database or server settings, exit code, and the fixable-only setting.

CPU Limit (cores), Memory Limit (MB), and Concurrent Scan Containers cap the resources scans use; see Settings.

Use a remote Trivy server

Trivy can run as a server that holds the vulnerability database, so Arcane doesn’t have to download and load it on each host. This helps on small or 32-bit hosts, especially armv7, where the local database may fail to load.

  1. Turn on Use Remote Trivy Server.
  2. Set Trivy Server URL, for example http://trivy.example.com:4954.
  3. Optional: set Trivy Server Token if the server requires authentication.

Scan containers must be able to reach the server URL; Trivy Network controls their network. Arcane passes the token in the TRIVY_TOKEN environment variable, so it doesn’t show up in process arguments.

How scans run

  1. On schedule, Arcane checks whether the vulnerability scan job is on, and skips the run if not.
  2. It runs Trivy from the bundled tools image (ghcr.io/getarcaneapp/tools), which pins the Trivy version.
  3. Each image is scanned with the environment’s cache, network, resource, and server settings.
  4. Findings, severity counts, and scan duration are saved per image.

Threat intelligence

Arcane raises the priority of vulnerabilities that are exploited in practice, using two public sources:

  • The CISA Known Exploited Vulnerabilities (KEV) catalog, a list from the US Cybersecurity and Infrastructure Security Agency of CVEs known to be exploited.
  • FIRST EPSS (Exploit Prediction Scoring System) scores, the estimated probability that a CVE will be exploited soon.

The Vulnerability Risk job syncs both at most every 20 hours; run it from the environment’s Automations tab to sync now. Arcane downloads the KEV catalog from www.cisa.gov and requests EPSS scores from api.first.org for scanned CVE IDs only. If a sync fails, the previous data is kept.

For air-gapped installs, turn off Threat Intelligence under Environments → your environment → Security → Vulnerability Scanning. Scores then reflect only severity and container usage.

The Vulnerability Risk job also runs hourly to compute scores and records one snapshot per day in the TZ timezone. The 7-day change uses the latest snapshot that is 7–10 days old. Snapshots are kept for 400 days, and the trend restarts when the scoring formula changes.

Reference

Risk score

The risk score is a 0–100 number for each finding, image, and environment. It weights a vulnerability’s severity by whether it’s being exploited and whether a container uses the image.

risk = min(100, 10 × severity × threat × usage)

Severity is the CVSS (Common Vulnerability Scoring System) v3 score, or v2 if there’s no v3 score. Without either, Arcane uses the severity label: Critical 9.5, High 8, Medium 5.5, Low 2.5. Unknown is not scored.

Threat comes from threat intelligence:

Evidence Threat
In CISA KEV 1.0, and severity is raised to 10
FIRST EPSS p 0.7 + 0.3 × √p
No data 0.7

A KEV finding in a running container always scores 100. KEV and EPSS only cover CVE IDs, so other advisory IDs, such as GHSA (GitHub Security Advisory), DLA (Debian LTS Advisory), and DSA (Debian Security Advisory), always use 0.7. With threat intelligence off, every finding uses 0.7.

Usage is 1.0 when a running, paused, or restarting container uses the image, 0.8 when only stopped containers do, and 0.5 when none do. If Arcane can’t list containers, usage is 1.0.

Finding Risk
KEV, running 100
CVSS 9.8, no threat data, running 69
CVSS 7.5, EPSS 36%, running 66
CVSS 7.5, EPSS 36%, stopped 53
CVSS 9.8, EPSS 1%, unused 36

Image score

Only fixable findings (those with a fixed version) count. Each CVE counts once per image, at its highest risk. The image score weights the top four findings and adds a small term for the number of fixable findings n:

score = 0.70 × 1st + 0.15 × 2nd + 0.05 × 3rd + 0.02 × 4th + 8 × (1 − e^(−n/40))

The count term adds at most 8 points. For example, 12 fixable findings whose top four score 100, 66, 57, and 36 give 70 + 9.9 + 2.85 + 0.72 + 2.07 ≈ 86.

An image with no fixable findings scores 0. If none of its fixable findings can be scored, its score is unavailable. Non-CVE advisories with no rating are skipped.

Environment score

The environment score is the average of its scanned images’ scores, weighted by usage: running 3, stopped 2, unused or unknown 1. Images with no fixable findings count as 0. If a running image, or one with unknown usage, has a fixable KEV finding, the score is at least 70.

For example, a running image at 57, a stopped image at 53, and a clean unused image give (57 × 3 + 53 × 2 + 0) / 6 ≈ 46.

Scores only include images still on the host with a completed scan, and skip ignored findings.

Risk bands

Score Band
90–100 Critical
70–89 High
40–69 Medium
1–39 Low
0 None

Settings

Settings are on the Vulnerability Scanning and Image Patching sub-tabs of the environment’s Security tab; schedules are on the jobs in Automations.

Setting Purpose
Scheduled Vulnerability Scan Turn scheduled scans on or off.
Vulnerability Scan Interval Cron schedule for scans (default 0 0 0 * * *).
Trivy Config (YAML) YAML configuration applied to every scan.
.trivyignore Vulnerability IDs to exclude, one per line.
CPU Limit (cores) CPU cores per scan container, such as 0.5; 0 for no limit. Hosts using CPU affinity use whole cores.
Memory Limit (MB) Memory limit per scan container.
Concurrent Scan Containers Maximum scan containers running at once, across manual and scheduled scans.
Only Report Fixable Vulnerabilities Only record vulnerabilities that have a known fix.
Use Remote Trivy Server Scan through a remote Trivy server.
Trivy Server URL Remote Trivy server URL.
Trivy Server Token Optional remote Trivy server token.
Threat Intelligence Fetch CISA KEV and FIRST EPSS data for the risk score (default on).
Patched Image Tag Suffix Tag suffix for patched images (default patched).
Patch Timeout (seconds) Timeout for a single patch run (default 600).
Patch All Platforms Patch every platform of a multi-platform image, not just the server’s own.
Scheduled Image Patching Turn scheduled patching on or off.
Image Patch Interval Cron schedule for patching (default 0 0 3 * * *).