BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeDesigning and Implementing Microsoft DevOps Solutions (AZ-400)Automating container scanning — quick notes
Quick Notes96 words

Automating container scanning — quick notes

Container scanning — quick notes

TargetFinds
Base image / OS packagesInherited CVEs
Application code insideVulnerable patterns (CodeQL)
  • Scan before push → keep vulnerable images out of the registry.
  • Scan in the registry continuously → catch CVEs disclosed after build.
  • CodeQL in a container requires advanced setup — default setup cannot express it.
  • Most base-image findings are fixed by rebuilding on a patched base.

Trap: scanning only at build time. The image ages even when your code does not.

All Designing and Implementing Microsoft DevOps Solutions (AZ-400) Study Resources

Related Notes

  • Agent and runner infrastructure421 words
  • Agent and runner infrastructure — quick notes150 words
  • Alerting on pipeline events255 words
  • Alerting on pipeline events — quick notes94 words
  • Analyzing usage and application performance241 words
  • Analyzing usage and application performance — quick notes73 words
  • Appropriate access levels217 words
  • Appropriate access levels — quick notes85 words
  • Automating container scanning277 words
  • Automating documentation from Git history191 words
  • Automating documentation from Git history — quick notes55 words
  • AZ-400 — exam map — roadmap403 words

Ready to study Designing and Implementing Microsoft DevOps Solutions (AZ-400)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Designing and Implementing Microsoft DevOps Solutions (AZ-400)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Designing and Implementing Microsoft DevOps Solutions (AZ-400) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.