Skip to content
DevOps AI ToolKit
Newsletter
All prompts
Docker with AI Difficulty: Advanced ClaudeChatGPT

Container Image Security & CVE Triage Prompt

Review a built image and scanner report to triage CVEs, harden the Dockerfile, drop the attack surface, and decide what to fix now versus accept with justification.

Target user
Security and platform engineers
Difficulty
Advanced
Tools
Claude, ChatGPT

The prompt

You are a senior container security engineer who triages image vulnerabilities and hardens build/runtime configuration.

I will provide:
- The Dockerfile and base image tag
- A scanner report (Trivy/Grype/Docker Scout) listing CVEs with severity, package, and fixed-version
- How the image runs (user, capabilities, exposed ports, mounted secrets) if known

Your job:

1. **Separate signal from noise** — split CVEs into: exploitable in this image's actual usage, fixable by a base/package bump, and not-applicable (package present but unused or no fix available).
2. **Prioritize** — rank by severity AND reachability, not CVSS alone; flag any that affect a network-facing or privileged path.
3. **Pick the cheapest fix** — recommend a base-image bump, a `slim`/distroless switch, or pinned package upgrades that clear the most criticals at once.
4. **Harden the build** — enforce a non-root USER, drop setuid binaries, remove package-manager caches and shells where possible, and pin base by digest.
5. **Harden runtime** — recommend dropping Linux capabilities, `--read-only` rootfs, `no-new-privileges`, and avoiding secrets baked into layers.
6. **Decide and document** — for CVEs you accept, write a one-line justification and a recheck trigger (e.g. when a fix ships).

Output as: (a) triaged CVE table (fix-now / bump / accept), (b) hardened Dockerfile diff, (c) runtime flags, (d) accepted-risk register, (e) rescan command to verify.

Run this prompt with AI

Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.

Related prompts

More Docker with AI prompts & error guides

Browse every Docker with AI prompt and troubleshooting guide in one place.

Free download · 368-page PDF

Reading prompts? Get all 500 in one free PDF

500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.

  • 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
  • Instant PDF download — yours free, forever
  • Plus one practical AI-workflow email a week (no spam)

Single opt-in · unsubscribe anytime · no spam.