Container Vulnerability Data Sources and Operating System Coverage

Container Vulnerability Data Sources and Operating System Coverage

Lifecycle's container scanning feature analyzes both operating system (OS)-level packages and application dependencies within container images using Sonatype vulnerability intelligence.

Container scanning combines OS-specific vulnerability data sources with Sonatype’s broader vulnerability intelligence platform to identify known vulnerabilities across the full container stack.

Application and Open-Source Component Vulnerability Sources

Lifecycle scans application dependencies and open-source components within container images using Sonatype’s full vulnerability intelligence dataset.

Sonatype vulnerability intelligence is generated through a proprietary automated detection and research system that continuously monitors, aggregates, correlates, and analyzes publicly available security information. Sonatype supplements automated analysis with human security research to improve vulnerability precision and reduce false positives and false negatives.

Sonatype’s vulnerability sources include public vulnerability databases, ecosystem advisory feeds, vendor security advisories, exploit intelligence, open-source project disclosures, and Sonatype security research.

For additional details about Sonatype vulnerability intelligence and research processes, see Sonatype Vulnerability Data.

Operating System Vulnerability Sources

OS-level vulnerability detection uses third-party vulnerability intelligence sources that collect and normalize security advisory data from OS vendors and open-source ecosystems. These sources may include the following:

The resulting data is used to identify known vulnerabilities present in container operating system packages and dependencies.

Supported Operating System Sources

Current OS-level container vulnerability coverage includes data for the following distributions and operating systems:

Distribution / OS Coverage Source Type
Debian Vendor advisories / OVAL
Alpine Vendor advisories
Ubuntu Vendor advisories / OVAL
CentOS / RHEL Red Hat OVAL
Amazon Linux Vendor advisories
Oracle Linux Oracle OVAL
Photon OS Vendor advisories
Rocky Linux Vendor advisories
SUSE Linux Enterprise Server (SLES) SUSE OVAL
Mariner Mariner OVAL

Additional Vulnerability Sources

Container vulnerability intelligence may also include advisory data from broader ecosystem and community sources where applicable.

Examples of advisory ecosystems commonly referenced by vulnerability providers include the following:

These sources help improve vulnerability detection breadth, accuracy, and timeliness across container ecosystems.

Data Update Cadence

Sonatype continuously updates vulnerability intelligence as new security information becomes available.

OS-level coverage availability depends on OS vendors and ecosystems publishing and maintaining upstream vulnerability definitions. Update cadence is based on their publication schedules and synchronization processes. Sonatype does not independently author vendor OVAL definitions.

Application and component vulnerability intelligence is updated through Sonatype automated processing pipelines and security research workflows. Newly identified vulnerabilities may first become available through automated processing and later be refined through deeper research and validation processes.

As a result, newly disclosed vulnerabilities or newly released OS versions may not appear immediately in scan results, particularly when upstream vendors have not yet published vulnerability metadata or definitions.