Security Scanning
Scan images for vulnerabilities and keep your containers secure.
Overview
Nautilus includes built-in vulnerability scanning powered by Trivy. Scan any local image to detect CVEs across all layers.
Scanning an Image
- Go to Images in the sidebar
- Select an image
- Click Scan for Vulnerabilities
- Wait for the scan to complete (cached for faster re-scans)
Understanding Results
Vulnerabilities are classified by severity:
- Critical - Immediate action required
- High - Should be fixed soon
- Medium - Fix when possible
- Low - Minimal risk
- Negligible - Informational
Each vulnerability shows: CVE ID, CVSS score, affected package, and fix version if available.
Best Practices
- Scan images before deploying to production
- Use minimal base images (Alpine, distroless)
- Keep base images updated
- Review and address Critical/High vulnerabilities