Aqua MicroScanner checked a container image for known security vulnerabilities while the image was being built. Developers could add it to a Dockerfile so a serious finding stopped the build before the image was published. That made it useful even without control of a central build service. MicroScanner is now a retired integration, so this page explains what to preserve when moving its checks and release-blocking rules to a replacement.
Current guidance
The historical MicroScanner workflow downloaded a scanner during an image build and could fail that build on severe vulnerabilities. Aqua’s repository explicitly deprecates it from 1 April 2021 in favor of Trivy. Treat this as retirement of the old scanner and integration, not proof that an existing image has become safe or that a replacement will produce identical findings.
Choose where the new scan runs and what immutable image digest it evaluates. Review operating-system packages, application dependencies and any additional scanner types separately. Trivy’s severity, status and ignore filters change the effective policy; excluding unfixed vulnerabilities is a policy choice, not evidence that those vulnerabilities are harmless. Pin the tool and preserve database-update visibility so a failed update does not look like a clean assessment.
Trivy returns exit code 0 for detected security issues by default; configure a nonzero --exit-code for findings that should block the job. Test the CI gate with a known finding and a scanner execution failure, then confirm that the job reports the intended outcome. Keep registry credentials out of image layers and build logs. Compare report formats and suppression ownership before replacing dashboards or Jenkins integrations. Trivy Operator is an optional cluster-reporting deployment; a CI image scan does not require installing an operator or granting it cluster-wide permissions.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub marks aquasecurity/microscanner as archived. This confirms the repository's read-only archive state; any successor or supported distribution needs separate evidence. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
Aqua Security’s MicroScanner lets you check your container images for vulnerabilities. If your image has any known high-severity issue, MicroScanner can fail the image build, making it easy to include as a step in your CI/CD pipeline.
If you’re using Jenkins, you can find the plug-in for MicroScanner here.
Note: this freely-available Community Edition enables scanning by adding some lines to your Dockerfile, incorporating the microscanner binary as part of the image build. This is aimed at individual developers and open source projects who may not have control over the full CI/CD pipeline. The Aqua Security commercial solution scans container images without requiring any modification to the image or its Dockerfile, and is designed to be hooked into your CI/CD pipeline after the image build is complete, and/or to scan images from a public or private container registry.
Another note: this freely-available Community Edition of MicroScanner scans for vulnerabilities in the image’s installed packages. Aqua’s commercial customers have access to additional Enterprise Edition scanning features, such as scanning files for vulnerabilities, and scanning for sensitive data included in a container image.
Sources & further reading
Spotted something that needs another look?
Help improve this page →