Assess container vulnerabilities in the context of the real application.
Farion scans operating-system packages and application dependencies in containers and VMs, then connects the resulting inventory to source dependencies, services, and the applications that deploy them.
Scan images where they are built or where they run.
Use the Farion scanner as a GitHub Action, as a CI/CD pipeline job, or install it inside a Kubernetes cluster for continuous inventory and vulnerability scanning.
GitHub Action
Generate the image inventory as part of the repository workflow and submit the resulting component data to Farion.
Pipeline job
Add container and VM scanning to GitLab, Azure DevOps, or another supported CI/CD workflow.
Kubernetes deployment
Run the scanner inside the cluster to collect updated image inventories as workloads change.
Analyze operating-system packages and application dependencies together.
Farion detects packages from supported Linux distributions alongside application dependencies from ecosystems such as Maven, Gradle, npm, pip, Go Modules, Cargo, NuGet, and RubyGems.
Connect the image to the code and service that produced it.
Remote SBOM subjects are merged with source dependency graphs and application metadata. Teams can see which service contains the image, which application dependencies are present, and which source context is available for exploitability assessment.
Coverage across common Linux and hardened-container ecosystems.
AlmaLinux
Alpaquita
Alpine
Azure Linux
BellSoft Hardened Containers
Bitnami
Chainguard
CleanStart
Debian
Echo
Linux
Mageia
MinimOS
openEuler
openSUSE
Red Hat
Rocky Linux
SUSE
Ubuntu
Wolfi
What this solution covers
Farion provides container and VM inventory, SCA, vulnerability intelligence, and correlation with the source application. It is not a runtime-protection, admission-control, Kubernetes-configuration-scanning, CNAPP, or image-hardening product. VEX is available for application dependency findings, not for operating-system package findings.
Frequently asked questions
Yes. Application dependencies are analyzed alongside operating-system packages and can be correlated with the source dependency graph.
No. Farion focuses on container and VM inventory, vulnerability analysis, application correlation, and supply-chain context.
Related capabilities
See how Farion works on your application.
Request a guided evaluation or walk through the relevant workflow with our technical team.