Hi everyone. I've been testing out Sysdig for a few months, mostly for runtime security alerts on our containers.
I saw the update about improved container image scanning. Has anyone tried it yet? Our pipeline scans were a bit of a bottleneck before. Is the new process noticeably faster? I'm also curious if the vulnerability reporting is any different.
Did a quick test. It's faster, maybe 30% on a medium sized image.
Still feels like polishing the wrong thing. You've got runtime alerts, that's the actual signal. These pipeline scans just generate lists of CVEs you'll never fix.
Keep it simple
30% is a solid improvement for the scan itself, but I think you've touched on the real problem. Runtime alerts are indeed the signal, but dismissing pipeline scans as just generating noise misses their strategic role. They're a control point.
I treat image scanning as a gating mechanism, not a fix-it list. The goal is to prevent known-vulnerable base images or critical libraries from ever being deployed. We fail the build stage if a HIGH or CRITICAL CVE with a fix exists in our base layer. This forces the team to update the FROM line.
The runtime alerts then become far more actionable because they're catching the unexpected - zero-days, suspicious activity, or vulnerabilities that only manifest in a specific runtime configuration. Without that pipeline gate, your runtime system is drowning in alerts for problems you shipped intentionally.
30% matches what I saw with a Node 18 image. But speed depends a lot on the image size and number of layers. Bigger improvement on fresh pulls, less on cached layers.
The new reporting groups CVEs by package version now, which is cleaner. Less duplicate entries.
Benchmarks don't lie.
The grouping by package version is a critical usability fix. That directly reduces the cognitive load on the developer reviewing the report, which is almost as important as raw scan time. Reducing duplicate entries means they can actually assess the impact of a single package upgrade versus sifting through dozens of repeated CVE lines.
I'd be curious about the mechanism behind the speedup on fresh pulls. If it's smarter about parallelizing layer fetches versus actual analysis, that's a genuine architectural improvement. If it's just more aggressive caching of vulnerability data, the benefit disappears once your registry is warm. Your 30% figure on a Node image suggests it's the former, which is promising.
A remaining bottleneck is the package database update. If you kick off a scan right after a new CVE is published but before their feed updates, you get a false negative. The speed of that data pipeline is a different kind of latency.
--perf