Docker

Reclaim Developer Hours through Smarter Vulnerability Prioritization with Docker and Mend.io

5.5内容质量
Reclaim Developer Hours through Smarter Vulnerability Prioritization with Docker and Mend.io

TL;DR · AI 摘要

Docker 与 Mend.io 合作推出漏洞优先级排序方案,旨在减少开发者处理安全问题的时间消耗。

核心要点

  • Docker 集成 Mend.io 提供更智能的漏洞优先级排序
  • 目标是减少开发者在低风险漏洞上浪费的时间
  • 强调通过上下文感知提升修复效率
#Docker#Mend.io#软件供应链安全#漏洞管理#DevSecOps
打开原文

Reclaim Developer Hours through Smarter Vulnerability Prioritization with Docker and Mend.io | Docker

Skip to content

Image 6
Image 6

Insights on the state of AI agents from 800+ builders and leaders. Download your copy

[](http://www.docker.com/)

  • AI

AI

More resources for developers

![Image 7: Featured image Docker Brings Compose to the Agent Era: Building AI Agents is Now Easy Docker Accelerates Agent Development Read more](http://www.docker.com/blog/build-ai-agents-with-docker-compose/)

Products

![Image 8 Secure Agent Execution with NanoClaw and Docker Sandboxes NanoClaw integrates with Docker Sandboxes to run AI Read more](http://www.docker.com/blog/nanoclaw-docker-sandboxes-agent-security/)

  • Developers

Developers

More resources for developers

![Image 9 Introducing Docker Model Runner A faster, simpler way to run and test AI models locally Read more](http://www.docker.com/blog/introducing-docker-model-runner/)![Image 10 Deliver Quickly. Build Securely. Stay Competitive. Meet growing demands for speed and security with integrated, efficient solutions Read more](http://www.docker.com/resources/reducing-every-day-complexities-for-more-efficient-software-development-white-paper/)

Get the latest Docker news

Company

![Image 11 Docker Announces SOC 2 Type 2 Attestation & ISO 27001 Certification Learn what this means for Docker security and compliance Read more](http://www.docker.com/blog/docker-announces-soc-2-type-2-attestation-iso-27001-certification/)

Search

Sign InGet Started

Toggle menu

Reclaim Developer Hours through Smarter Vulnerability Prioritization with Docker and Mend.io

Posted Apr 8, 2026

Image 12: Posts by Adam Dawson
Image 12: Posts by Adam Dawson
Image 13: Posts by Dor Hayun
Image 13: Posts by Dor Hayun

Adam Dawson and Dor Hayun

We recently announced the integration between Mend.io and Docker Hardened Images (DHI) provides a seamless framework for managing container security. By automatically distinguishing between base image vulnerabilities and application-layer risks, it uses VEX statements to differentiate between exploitable vulnerabilities and non-exploitable vulnerabilities, allowing your team to prioritize what really matters.

**TL;DR: The Developer Value Proposition**

The hallmark of this integration is its zero-configuration setup.

  • Automatic Detection: Mend.io identifies DHI base images automatically upon scanning. No manual tagging or configuration is required by the developer.
  • Visual Indicators: Within the Mend UI, DHI-protected packages are marked with a dedicated Docker icon and informative tooltips, providing immediate transparency into which components are managed by Docker’s hardened foundation.

Transparent Layers: Users can inspect findings by package, layer, and risk factor, ensuring a clear audit trail from the base OS to the custom application binaries.

**Dynamic Risk Triage: VEX + Reachability**

Standard scanners flag thousands of vulnerabilities that are present in the file system but never executed. This integration uses two layers of intelligence to filter the noise:

  • Risk Factor Integration: Mend.io incorporates Docker’s [VEX (Vulnerability Exploitability eXchange](https://docs.docker.com/dhi/core-concepts/vex/)) data as a primary source of “Risk Factor” identification.
  • The “Not Affected” Filter: If a CVE is marked as not_affected by Docker’s VEX data or determined to be Unreachable by Mend’s analysis, it is deprioritized.

Bulk Suppression: Developers can suppress non-functional risks in bulk—potentially clearing thousands of non-exploitable vulnerabilities with a single click—allowing teams to focus on the 1% of reachable, exploitable risks in their custom layers.

**Operationalizing Security with Workflows**

Mend.io allows organizations to move beyond simple scanning into automated governance:

  • SLA & Violation Management: Automatically trigger violations and set remediation deadlines (SLAs) based on vulnerability severity.
  • Custom Alerts: Configure workflows to receive instant notifications (via email or Jira) whenever a new DHI is added to the environment.

Pipeline Gating: Use Mend’s workflow engine to fail builds only when high-risk, reachable vulnerabilities are introduced in custom code, keeping the CI/CD pipeline moving.

**Continuous Patching & AI-Assisted Migration**

  • Automated Synchronization: For Enterprise DHI users, patched base images are automatically mirrored to Docker Hub private repositories. Mend.io verifies these updates, confirming that base-level risks have been mitigated without requiring a manual Pull Request.
  • Ask Gordon: Leverage Docker’s AI agent to analyze existing Dockerfiles and recommend the most suitable DHI foundation, reducing the friction of migrating legacy applications to a secure environment.

The Mend.io and Docker integration operationalizes this by providing an auditable trail of security declarations, ensuring compliance is a byproduct of the standard development workflow rather than a separate, manual task.

Learn more

Learn more about the integration and Docker’s VEX statements in the following links:

Read Mend’s point of view on the benefits of VEX: https://www.mend.io/blog/benefits-of-vex-for-sboms/

Docker Hardened Imagessoftware supply chain securityVEXPartnershipsProducts

Table of contents

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.docker.com%2Fblog%2Freclaim-developer-hours-through-smarter-vulnerability-prioritization-with-docker-and-mend-io%2F "Visit this Linkedin profile")[](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.docker.com%2Fblog%2Freclaim-developer-hours-through-smarter-vulnerability-prioritization-with-docker-and-mend-io%2F "Visit this X profile")[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.docker.com%2Fblog%2Freclaim-developer-hours-through-smarter-vulnerability-prioritization-with-docker-and-mend-io%2F "Visit this Facebook profile")

Related Posts

Products

Features

Developers

Pricing

Company

Languages

  • [](http://twitter.com/docker)
  • [](https://www.linkedin.com/company/docker)
  • [](https://www.instagram.com/dockerinc/)
  • [](http://www.youtube.com/user/dockerrun)
  • [](https://www.facebook.com/docker.run)
  • [](http://www.docker.com/blog/feed)

© 2026 Docker Inc. All rights reserved

Terms of ServicePrivacyLegal

Cookies Settings

By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.

Cookies Settings Reject All Accept All Cookies

Image 20: Company Logo
Image 20: Company Logo

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

More information

Allow All

Manage Consent Preferences

#### Functional Cookies

  • [x] Functional Cookies

These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.

#### Strictly Necessary Cookies

Always Active

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

#### Performance Cookies

  • [x] Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.

#### Targeting Cookies

  • [x] Targeting Cookies

These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Cookie List

Clear

  • [x] checkbox label label

Apply Cancel

Consent Leg.Interest

  • [x] checkbox label label
  • [x] checkbox label label
  • [x] checkbox label label

Reject All Confirm My Choices

Image 21: Powered by Onetrust
Image 21: Powered by Onetrust

Image 22Image 23