Agentless SCAP/DISA STIG + CVE scanning for containers, Kubernetes, VM disks, and hosts.
736
Agentless SCAP / DISA STIG compliance and CVE vulnerability scanning for containers,
Kubernetes workloads, VM disks, and hosts — a single self-contained Go binary on a hardened,
STIG'd Rocky 9 base. Offline-capable: vulnerability feeds are read from a mounted cache by
default and refreshed from the TYCHON feed origin (HTTPS, SHA-256 verified) when -vulnFetch
is enabled.
-watch -watchLive) that
discovers every running container via the shared host PID namespace (/proc/<pid>/root,
runtime-agnostic: containerd, CRI-O, Docker) and scans each for CVEs and STIG compliance,
emitting to Elastic Cloud Security Posture and to kubectl-visible VulnerabilityReport /
ConfigAuditReport custom resources.-dormantDiskDirs, report failing CVEs/STIG on stopped-VM
DataVolumes and unattached PVCs, kept separate from the live "running-only" findings.-harborAdapter) that fills Harbor's own
Vulnerabilities/SBOM columns, plus a full registry sweep (-scanRegistry) for images at rest.-scanRoot),
including the DISA Kubernetes STIG on the cluster's own control-plane node.docker run --rm --pid=host --privileged \
-v /var/lib/tychon/feeds:/feeds:ro \
-v /var/lib/tychon/reports:/reports \
docker.io/tychoncorp/vulnerability-scanner:dev
The default entrypoint runs the continuous node agent
(-watch -watchStig -watchStigDir=/stig -vulnCache=/feeds -vulnFetch -watchReports=/reports).
Deploy as a DaemonSet — see deploy/kubernetes/ (rbac.yaml, crd.yaml, daemonset.yaml) and
the Harbor + Kubernetes + Elastic deployment manual in the TYCHON user guide for the complete,
step-by-step runbook (active running workloads + dormant at-rest disks → Elastic).
CVE/OVAL and STIG content refresh from the TYCHON cloud feed origin (domain-restricted HTTPS,
every artifact SHA-256 verified). Enable with -vulnFetch; air-gapped sites stage a
-feedBundle instead and never touch the network.
dev — development build (this tag). For production, pin a released version tag.Content type
Image
Digest
sha256:3357bdb40…
Size
180.6 MB
Last updated
5 days ago
docker pull tychoncorp/vulnerability-scanner:dev