How it works
- Continuous scanning: Domino continuously scans product container images using multiple vulnerability scanning tools, with scans run on a weekly cadence.
- Risk validation: Findings are reviewed to confirm applicability, exploitability, and potential impact within the Domino architecture, using the CVSS environmental score framework rather than relying on the base score alone.
- Prioritization: Vulnerabilities are prioritized based on severity, available fixes, exposure, and practical risk to customers.
- Remediation: Applicable vulnerabilities are addressed through package upgrades, configuration changes, or other security controls.
- Release policy: Domino does not ship a release with an open High or Critical CVE that has an available fix. Fixes for other findings are tracked across supported releases and rolled into future releases.
- Customer transparency: Domino provides point-in-time vulnerability reports, mitigation details, and remediation status to customers for each release at its GA date.
Vulnerability transparency reports
After a release reaches general availability (GA), Domino publishes a transparency report for that release. The report lists every CVE found during scanning and states the risk disposition or exemption for each High and Critical CVE with a fix available.Cloud infrastructure
Domino runs a continuous vulnerability management program across its managed cloud infrastructure for Domino Cloud customers. The focus and methodology for these vulnerabilities is in line with product and container vulnerability management.How it works
- Continuous scanning: Domino continuously scans its cloud infrastructure accounts and assets on a weekly cadence.
- Risk validation: Findings are reviewed to confirm applicability, exploitability, and potential impact within the Domino environment, using the CVSS environmental score framework rather than relying on the base score alone.
- Prioritization: Vulnerabilities are prioritized based on severity, available fixes, exposure, and practical risk to customers.
- Remediation: Applicable vulnerabilities are addressed through package upgrades, configuration changes, OS updates, or other security controls.
- Release policy: Domino releases patched images for nodes regularly to ensure infrastructure is frequently patched.