ยท 2 days agoยท Dev.to
India's Cloud Security Just Got a Reality Check with Trivy-Grype Overhaul
If you run Trivy or Grype in CI and triage the output by CVSS, this is the thing I wish I'd had two years ago. Quick recap. Trivy and Grype hand you a list of CVEs. CVSS is a score in a vacuum โ it doesn't know whether a service runs in a private subnet behind mTLS, or sits on the open internet hand
#cloud#cve#devops#security#vulnerability-management