{"id":1259,"date":"2026-09-14T12:39:39","date_gmt":"2026-09-14T12:39:39","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1259"},"modified":"2026-09-14T12:39:39","modified_gmt":"2026-09-14T12:39:39","slug":"container-security","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/container-security\/","title":{"rendered":"Container Security"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CONTAINER SECURITY\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A container image is a frozen snapshot. It does not get patched, it gets rebuilt, and almost everything that makes container security different follows from that.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Cloud<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Container security covers three separate things: the image you build, the container running from it, and the orchestrator scheduling them. Each fails differently. Images carry inherited vulnerabilities, running containers are usually over-privileged, and orchestrators are commonly deployed with permissive defaults that nobody revisits.<\/p>\n<\/div>\n\n<p>Container security that stops at image scanning has covered one layer of three.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#layers\">The three container security layers<\/a><\/li>\n    <li><a href=\"#snapshot\">Images are not patched<\/a><\/li>\n    <li><a href=\"#where\">Where container security findings come from<\/a><\/li>\n    <li><a href=\"#runtime\">Runtime and orchestrator risks<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"layers\">The three container security layers<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Layer<\/th><th>What goes wrong<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Image<\/td><td>Inherited vulnerabilities from the base image, unnecessary packages, embedded credentials, and no record of what is inside<\/td><\/tr>\n    <tr><td>Runtime<\/td><td>Containers running as root, granted more privilege than the workload needs, or able to reach every other container on the network<\/td><\/tr>\n    <tr><td>Orchestrator<\/td><td>Permissive defaults, exposed control plane, over-broad service accounts and no segmentation between workloads<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"snapshot\" class=\"c-sage\">Images are not patched<\/h2>\n\n<p>The habit that shapes container security most is one borrowed from servers, where it no longer applies.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 214\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"A server is patched in place in two steps, while a container image must be updated, rebuilt and redeployed to receive the same fix.\">\n  <defs><marker id=\"ct\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <text x=\"14\" y=\"18\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">A SERVER<\/text>\n  <rect x=\"14\" y=\"26\" width=\"220\" height=\"44\" rx=\"11\" fill=\"#e2eff7\"\/>\n  <text x=\"124\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#2f6f96\">Patch in place<\/text>\n  <line x1=\"238\" y1=\"48\" x2=\"258\" y2=\"48\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ct)\"\/>\n  <rect x=\"266\" y=\"26\" width=\"480\" height=\"44\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"506\" y=\"53\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">Fixed, still running<\/text>\n\n  <text x=\"14\" y=\"98\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#6b7086\">A CONTAINER<\/text>\n  <rect x=\"14\" y=\"106\" width=\"140\" height=\"44\" rx=\"11\" fill=\"#fbe9dc\"\/>\n  <text x=\"84\" y=\"133\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">Update base<\/text>\n  <line x1=\"158\" y1=\"128\" x2=\"176\" y2=\"128\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ct)\"\/>\n  <rect x=\"184\" y=\"106\" width=\"130\" height=\"44\" rx=\"11\" fill=\"#fbe9dc\"\/>\n  <text x=\"249\" y=\"133\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">Rebuild<\/text>\n  <line x1=\"318\" y1=\"128\" x2=\"336\" y2=\"128\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ct)\"\/>\n  <rect x=\"344\" y=\"106\" width=\"130\" height=\"44\" rx=\"11\" fill=\"#fbe9dc\"\/>\n  <text x=\"409\" y=\"133\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#a2603a\">Redeploy<\/text>\n  <line x1=\"478\" y1=\"128\" x2=\"496\" y2=\"128\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#ct)\"\/>\n  <rect x=\"504\" y=\"106\" width=\"242\" height=\"44\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"625\" y=\"133\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#3a6f5d\">Fixed, and it is a new container<\/text>\n\n  <rect x=\"14\" y=\"164\" width=\"732\" height=\"46\" rx=\"11\" fill=\"#efe4f0\"\/>\n  <text x=\"380\" y=\"184\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#6b4576\">A scan at build time describes that day only.<\/text>\n  <text x=\"380\" y=\"201\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#6b4576\">An image running six months later has known flaws nobody has looked at since.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>This inverts how most teams approach container security, because it inverts <a href=\"https:\/\/www.osto.one\/resources\/glossary\/patch-management\/\">patch management<\/a>. There is nothing to update inside a running container, and updating one by hand produces a machine that no longer matches its image, which is worse than leaving it alone.<\/p>\n\n<div class=\"callout\">\n  <p class=\"k\">Scanning at build is not enough on its own<\/p>\n  <p>A clean scan proves the image had no known vulnerabilities on the day it was created. Vulnerabilities are disclosed continuously, so the same image is quietly less safe every week it stays deployed, without anything changing. Two habits close the gap. Rescan images already in your registry on a schedule rather than only at build, and rebuild long-lived services periodically even when the application code has not changed, so the base layer picks up fixes.<\/p>\n<\/div>\n\n<h2 id=\"where\" class=\"c-plum\">Where container security findings come from<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Source<\/th><th>What it means for the fix<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>The base image<\/td><td>Usually the largest share by a wide margin. A general-purpose base carries a full operating system, most of which your application never calls. The fix is choosing a smaller base, not repairing anything<\/td><\/tr>\n    <tr><td>System packages<\/td><td>Tools added during the build for convenience, such as shells and package managers, which remain in the shipped image and are useful to an attacker<\/td><\/tr>\n    <tr><td>Application dependencies<\/td><td>The libraries your code imports, which is the same problem <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> addresses outside containers<\/td><\/tr>\n    <tr><td>Your own code<\/td><td>Typically the smallest share of reported findings, and the part <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> covers<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The practical consequence surprises people. Moving from a general-purpose base image to a minimal or distribution-free one frequently removes most reported vulnerabilities in a single change, because the packages carrying them are simply no longer present. That is usually a better first move than working through a findings list, and a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">software bill of materials<\/a> is what tells you which layer each finding came from.<\/p>\n\n<h2 id=\"runtime\" class=\"c-sky\">Runtime and orchestrator risks<\/h2>\n\n<p>Container security beyond the image is mostly a question of what a workload is permitted to do once it is running.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Risk<\/th><th>Why it matters<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Running as root<\/td><td>The default in many images. If the application is compromised, the attacker holds root inside the container and is one weakness away from the host<\/td><\/tr>\n    <tr><td>Privileged containers<\/td><td>Granted for convenience during debugging and rarely removed. Effectively removes the boundary the container was providing<\/td><\/tr>\n    <tr><td>Secrets in environment variables<\/td><td>Visible to anyone who can inspect the container and frequently printed into logs. See <a href=\"https:\/\/www.osto.one\/resources\/glossary\/secrets-management\/\">secrets management<\/a><\/td><\/tr>\n    <tr><td>Flat internal networking<\/td><td>By default every workload can reach every other. One compromised container then has the whole cluster available to it<\/td><\/tr>\n    <tr><td>Exposed control plane<\/td><td>An orchestrator API or dashboard reachable from the internet is a direct route to scheduling anything you like<\/td><\/tr>\n    <tr><td>Over-broad service accounts<\/td><td>Default accounts often carry more cluster rights than the workload needs, which turns a single compromise into cluster access<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Most of these are defaults rather than mistakes, which is why they survive so long. Nobody chose them, so nobody reviews them, and container security work at this layer is largely a matter of going through the settings once.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto has no container runtime agent and no Kubernetes posture module. If you are running a large orchestrated estate and need admission control, pod-level policy and runtime enforcement inside the cluster, that is a dedicated product and this is not it.<\/p>\n\n<p>What Osto covers is the parts of container security that sit outside the cluster boundary, which for most teams running a handful of services is the majority of the real exposure. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">Dependency scanning<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> generation handle the libraries inside your images and give you the inventory to answer which services are affected when a component is found vulnerable. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud posture management<\/a> covers the infrastructure the cluster runs on, including the managed service configuration, the network rules around it and the roles attached to nodes.<\/p>\n\n<p>Access to the control plane is handled through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">zero trust access<\/a>, so the orchestrator API is reachable only from a managed device rather than from the internet, which removes the exposed control plane row above rather than monitoring for it. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">Identity and access management<\/a> narrows what the roles around the cluster can reach, and events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a> alongside everything else. That evidence supports the configuration and vulnerability management expectations in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Cover what sits around the cluster<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Dependency scanning and SBOM for your images, cloud posture for the infrastructure, and zero trust access to the control plane.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is container security?<\/summary>\n  <p>Protecting three layers: the image being built, the container running from it, and the orchestrator scheduling them. Each has distinct failure modes, and covering only image scanning leaves two uncovered.<\/p>\n<\/details>\n\n<details>\n  <summary>How do you patch a container?<\/summary>\n  <p>You do not. Update the base image, rebuild and redeploy. Patching inside a running container produces something that no longer matches its image, which will be replaced on the next deployment anyway.<\/p>\n<\/details>\n\n<details>\n  <summary>Why do image scans report so many vulnerabilities?<\/summary>\n  <p>Most come from the base image rather than your code. A general-purpose base ships a full operating system your application never uses. Switching to a minimal base often removes the majority of findings in one change.<\/p>\n<\/details>\n\n<details>\n  <summary>Should containers run as root?<\/summary>\n  <p>No, although many images default to it. Running as a non-root user means a compromised application does not hold root inside the container, which removes the easiest path toward the host.<\/p>\n<\/details>\n\n<details>\n  <summary>Is container security just image scanning?<\/summary>\n  <p>No. A build-time scan reflects the day the image was built. New vulnerabilities are disclosed continuously, so rescan images in your registry on a schedule and rebuild long-lived services periodically even when the code has not changed.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cloud-security\/\">Cloud Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cnapp\/\">CNAPP<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ci-cd-security\/\">CI\/CD Security<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/patch-management\/\">Patch Management<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A container image is a frozen snapshot. It does not get patched, it gets rebuilt, and almost everything that makes\u2026<\/p>\n","protected":false},"author":8,"featured_media":1260,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[651,516,650,652],"class_list":["post-1259","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-base-image-vulnerabilities","tag-container-image-scanning","tag-container-security","tag-running-containers-as-root"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1259","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1259"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1259\/revisions"}],"predecessor-version":[{"id":1261,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1259\/revisions\/1261"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1260"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}