Key Takeaways

  • Container scanning is becoming a lifecycle discipline as Kubernetes and production-container use expand.
  • Scan findings require context: a vulnerable package may be absent from runtime, patched through a backport, or irrelevant to an application's exposure.
  • RapidFort's new Aqua Trivy integration is designed to make RapidFort Curated Images' remediation status visible to the scanner.
  • Image scanning remains necessary but cannot replace provenance, admission controls, runtime hardening and continuous remediation.

Container security teams face a growing signal-to-noise problem. As organizations put more applications into containers, scanners can identify vulnerable packages, secrets and misconfigurations before deployment, but a finding alone does not establish whether a package is exploitable, present at runtime or already patched through a distribution-specific remediation.

That distinction matters as cloud-native operations scale. CNCF's 2025 Annual Cloud Native Survey, published in 2026, found that 98% of surveyed organizations had adopted cloud-native techniques, while 82% of container users ran Kubernetes in production, up from 66% in 2023. Organizations using containers for most or all production applications rose from 41% in 2023 to 56% in 2025.

The exposure is not merely theoretical. The State of Cloud Native Security ebook reports that 97% of surveyed organizations experienced at least one cloud-native security incident in the previous year, with known vulnerabilities and cloud misconfiguration among the leading incident types. It also found that 74% said security concerns delayed or slowed application releases.

Why Accurate Vulnerability Context Matters

A CVE database record and a deployable risk are related but different things. Package version metadata can produce alerts even when a maintainer has backported a fix from another distribution, adapted a patch from an otherwise incompatible version, or removed the reachable code path. That does not mean teams should dismiss scanner findings; it means they need evidence that a remediation is present and an operational process to decide what must be rebuilt or updated.

Sysdig's 2025 research found that fewer than 6% of vulnerabilities rated critical or high were present at runtime in observed environments, even though 87% of production container images contained at least one high- or critical-severity vulnerability. These figures measure different things: individual vulnerabilities present at runtime versus images with at least one finding. The 87% figure comes from secondary coverage of Sysdig's report and should be verified against the primary source.

The broader trend supports more frequent reassessment. Publications | ENISA indicates that ENISA's Threat Landscape 2025 analyzed 4,875 incidents from July 2024 through June 2025 and reported more than 48,000 newly assigned CVEs in 2025, a 22% year-over-year increase. A clean scan at build time can age quickly as new vulnerabilities are assigned.

RapidFort and Aqua Trivy Focus on Remediation Visibility

Against that backdrop, RapidFort announced on September 29, 2026, that it has partnered with Aqua Security through Trivy Partner Connect. According to RapidFort's press release, Aqua Trivy will integrate RapidFort security advisories so the scanner can recognize remediation status in RapidFort Curated Images, including fixes extracted from other distributions or adapted from otherwise incompatible versions.

The practical aim is to reduce cases in which a scanner reports a package as vulnerable because it cannot interpret the vendor's remediation metadata. RapidFort's press release says the integration is generally available immediately and is intended to help development and security teams begin with near-zero CVE images while reducing time spent sorting scanner findings.

"Joint customers benefit from more accurate vulnerability results, less noise, and greater confidence in the security of the images they deploy. RapidFort brings differentiated remediation capabilities and a level of advisory detail that enables Trivy to recognize packages RapidFort has already patched even when those fixes are sourced from other distributions or adapted from versions that would otherwise be incompatible. By combining Trivy's trusted open-source scanning with RapidFort near-zero CVE images and transparent remediation data, we are helping development and security teams spend less time investigating false positives and more time delivering secure software." Matt Richards, Chief Operating Officer, Aqua Security

For buyers, the differentiator is not simply another scanning integration. It is whether remediation data can be independently inspected, mapped to the exact image digest and package inventory, and retained as auditable evidence when a finding is closed.

Scanning Must Connect to Supply-Chain Controls

Image scanning is a preventive control, not a complete container-security program. Teams still need to maintain software bills of materials, rebuild images as dependencies change, rescan registries and deployed workloads, and enforce policy at admission to a Kubernetes cluster. They also need runtime monitoring because scanners do not by themselves identify every kernel, orchestrator, registry, configuration or container-escape risk.

Frameworks from NIST, including the Secure Software Development Framework in SP 800-218 and container guidance in SP 800-190, provide useful structure for those practices. SPDX and CycloneDX support SBOM interchange, while Sigstore Cosign and in-toto attestations can provide signing and provenance evidence. FedRAMP's 2025 Continuous Monitoring Playbook also requires vulnerability monitoring for container technologies and sets remediation targets of 30 days for Critical/High findings, 90 days for Moderate findings and 180 days for Low findings.

"Trivy is one of the most downloaded open-source security scanners, and we are pleased to partner with Aqua Security to enhance the productivity of developers, who get a true assessment of security risks and can now focus on development without worrying about fixing CVEs. RapidFort is truly transparent about its curated images and enables partners to accurately assess images for any CVE risks. Partnering with companies like Aqua Security gives developers confidence that they are working with up to 99.9 percent CVE-free code before applications are ever deployed into production." George Manuelian, Chief Strategy Officer, RapidFort

That up to 99.9% claim is RapidFort's own statement and should be assessed by prospective users against their selected images, dependency requirements and operational environment.

Common Questions

Can Aqua Trivy now identify RapidFort-applied package fixes?

According to RapidFort's press release, the Trivy Partner Connect integration incorporates RapidFort security advisories and remediation data. The stated purpose is to help Trivy recognize patched packages even when fixes were extracted or adapted from other distributions.

Does a near-zero CVE image eliminate container risk?

No. Image findings are only one layer of risk management. Organizations still need configuration scanning, provenance, admission controls, runtime safeguards, continuous rescanning and timely updates to base components.

How should teams prioritize a large number of scan findings?

Teams should prioritize exploitability and runtime relevance rather than CVE severity alone. The fewer-than-6% runtime observation from Sysdig's research reinforces the need to correlate image findings with deployed workloads, application reachability and compensating controls.

The Next Test Is Operational Evidence

As container use becomes more central to production software delivery, the value of a scanner will increasingly depend on the quality of remediation evidence behind its results. RapidFort's Aqua Trivy integration addresses one recurring friction point (scanner visibility into curated-image fixes) but buyers should evaluate it as part of a broader program that connects image hygiene, verifiable provenance, deployment controls and runtime security.