ConClear currently uses Trivy for vulnerability, secret, and configuration scanning.
Evaluate whether another scanner stack is useful. Using Syft and Grype would not replace the Trivy secret and configuration checks, so this option adds tools and another vulnerability database.
The design must retain exactly one authoritative vulnerability verdict, bind database snapshots by digest across workers, and define record, attestation, verification, and rescan behavior.
Also decide whether workers need an explicit transport for scanner database snapshots.
ConClear currently uses Trivy for vulnerability, secret, and configuration scanning.
Evaluate whether another scanner stack is useful. Using Syft and Grype would not replace the Trivy secret and configuration checks, so this option adds tools and another vulnerability database.
The design must retain exactly one authoritative vulnerability verdict, bind database snapshots by digest across workers, and define record, attestation, verification, and rescan behavior.
Also decide whether workers need an explicit transport for scanner database snapshots.