Aikido security scanner now integrates with Docker Hardened Images (DHI) using built-in VEX (Vulnerability Exploitability eXchange) support. When scanning DHI, Aikido reads Docker's signed OpenVEX attestations and automatically filters out CVEs that Docker has verified as non-exploitable or already patched. The workflow uses signed SPDX 2.3 SBOMs retrieved via OCI 1.1 referrer lookup for accurate component cataloging of distroless images, then matches components against Docker's OSV feed. The result is a dramatically reduced triage queue showing only genuinely applicable vulnerabilities, with suppressed findings retained for audit and compliance purposes (FedRAMP, SOC 2). Setup requires an Aikido account, DHI access, and a Docker Hub Personal Access Token.

5m read timeFrom docker.com
Post cover image
Table of contents
Why teams are drowning in CVEsBefore you beginConnect Docker Hub to AikidoScan a Docker Hardened ImageHow VEX status shows upWhat you see in AikidoWhat the result looks likeRecapLearn more about the integration:Resources
363 Impressions