Docker Hardened Images (DHI) and Mend.io have integrated to streamline container vulnerability management. The integration automatically detects DHI base images, uses VEX (Vulnerability Exploitability eXchange) statements combined with Mend's reachability analysis to filter out non-exploitable CVEs, and enables bulk suppression of thousands of irrelevant findings. Teams can configure SLA-based violation workflows, CI/CD pipeline gating that only fails builds on reachable high-risk vulnerabilities, and automated base image patching for Enterprise DHI users. Docker's AI agent 'Ask Gordon' can also assist with migrating legacy Dockerfiles to hardened images.
Table of contents
TL;DR: The Developer Value PropositionDynamic Risk Triage: VEX + ReachabilityOperationalizing Security with WorkflowsContinuous Patching & AI-Assisted MigrationLearn moreSort: