We Expand Our Open Source Security Solution for Containerized Applications with Continuous Image Scanning

WhiteSource, the leader in open source security and license compliance management announced today a further enhancement of its support for containerized applications.

Supporting all versions of Windows and Linux operating systems, WhiteSource now expands its Docker container analysis tool to support full image scanning throughout all the image layers and packages within the image. This new capability adds to the existing support for detecting open source vulnerabilities both in the container body and the installed software.

This new capability expands the visibility for software development and security teams on their containerized applications earlier in the Software Development Lifecycle. This is an important capability that becomes necessary for many organizations as they expand their usage of Docker and other container services.

β€œAs a part of expanding our insights into the security of containers, including those that are in repositories, we can monitor the images at rest,” explains David Habusha, WhiteSource’s VP of Product. β€œEven if nothing changes within an image, users will receive alerts if new vulnerabilities are discovered, providing them with accurate remediation advice.”

A key feature that the company has included in the latest edition of their security product is full automation for monitoring images without the need to run them as active containers. The enhanced Docker container analysis tools now support container images that are hosted in repositories like DockerHub, Artifactory, and GitHub.

β€œWe are now scanning Docker images that are stored within the repositories, maintaining continuous security for containers throughout the CI/CD process. WhiteSource now allows customers to make sure that they run and store safe containers and images,” Habusha notes, addressing the customers’ need to provide the widest coverage possible across their various microservices, which have become standard across the industry.

We Expand Our Open Source Security Solution for Containerized Applications with Continuous Image Scanning - aHViPTcyNTE0JmNtZD1pdGVtZWRpdG9yaW1hZ2UmZmlsZW5hbWU9aXRlbWVkaXRvcmltYWdlXzVjN2QwMWJjMGQzMDEuanBnJnZlcnNpb249MDAwMCZzaWc9NDk2NGRjMTA2ZTY0MDJiOTE1M2I2ZTk3MGQ5ZjViZGM3D

About Mend.io

Mend.io is a leading application security solution that helps organizations fix less and reduce risk faster. Built for both AI-driven and modern development workflows, Mend.io gives teams visibility into all code – human-written, AI-generated, open source, third-party and container components – and helps them prioritize and remediate the risks that matter most.

Mend.io @ RSAC 2026

See what’s next for AI Security Testing and AppSec.