How it works
- Continuous scanning: Domino continuously scans product container images using multiple vulnerability scanning tools, with scans run on a weekly cadence.
- Risk validation: Findings are reviewed to confirm applicability, exploitability, and potential impact within the Domino architecture, using the CVSS environmental score framework rather than relying on the base score alone.
- Prioritization: Vulnerabilities are prioritized based on severity, available fixes, exposure, and practical risk to customers.
- Remediation: Applicable vulnerabilities are addressed through package upgrades, configuration changes, or other security controls.
- Release policy: Domino does not ship a release with an open High or Critical CVE that has an available fix. Fixes for other findings are tracked across supported releases and rolled into future releases.
- Customer transparency: Domino provides point-in-time vulnerability reports, mitigation details, and remediation status to customers for each release at its GA date.