Container Scanning

Cut container image vulnerability noise up to 90%

Endor Labs uses full-stack reachability analysis to help you patch what runs and prune the rest.
Loved by security teams, painless for developers at:

How it works

Full-stack reachability
Combine static and dynamic analysis of container images to identify which OS packages are reachable in your base images.
Lower FedRAMP costs
Avoid double filings with automatic deduplication across SCA and container image findings. One ticket, one fix.
Single pane of glass
See all your SAST, SCA, and container findings in one place with central management and visibility.
Our FedRAMP environment requires more rigor than you would normally get in any other kind of product release, with near zero tolerance for vulnerabilities. Endor Labs’ reachability analysis and consolidated findings reduced the number of true positives requiring remediation, which is a huge time- and money-saver.”
Marty Garvin
Head of Security, Rubrik
Prioritize risks with full-stack reachability
Cut through vulnerability noise with full-stack reachability that extends Endor Labs’ proven reachability analysis from application code down through container image runtime and OS layers.
Slash false positives: Determine which container image OS dependencies are used by the application and reachable at runtime.
Correlate alerts: Deduplicate findings across application (SCA) and container image scans to reduce alerts.
Cross-layer risk grouping: Group findings to identify common risks and determine which issues have the most significant impact on your security posture.
Gain unparalleled visibility
Maintain a complete inventory of your container ecosystem while mapping the complex relationships between base and derived images.
Complete container inventory: Automatically catalog all container images in use and map the relationships between base and derived images across your environment.
Base-to-derived image mapping: Trace how vulnerabilities in base images propagate to derived images, so you understand the full blast radius of every risk.
Layer-by-layer analysis: Pinpoint exactly when specific libraries were introduced and identify the vulnerabilities associated with each layer of a container.
Meet strict remediation SLAs
Shorten mean time to remediation (MTTR) by routing fixes to the right team with full traceability and upgrade guidance.
Identify the owner of each vulnerability: Trace risks discovered in running containers back to the exact layer, so platform engineering and app development teams can remediate where it matters.
Automated remediation guidance: Get recommended upgrade paths to remove vulnerable code in the application layer, so developers know exactly what to fix.
Stay compliant: Meet FedRAMP and other compliance SLA requirements by prioritizing remediation of reachable, critical vulnerabilities within the required 30-day windows.
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
All Secured

Lean how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

What is the Developer Edition?

Developer Edition is a free tier that gives individual developers access to the AURI MCP Server and CLI. It includes SAST, SCA, secrets detection, and malicious open source package detection — the core scanning capabilities you need to write secure code from day one.

What does the MCP Server actually do?

The MCP Server connects AURI's security intelligence to your AI coding assistant. When you or your AI writes code, the server scans for vulnerabilities, insecure patterns, hardcoded secrets, and risky dependencies in real time — then helps fix them inline, right where you're working.

Which editors and tools are supported?

The MCP server works with Cursor, VS Code, Windsurf, Claude Code, and any MCP-compatible client. It also integrates with asynchronous AI tools like GitHub Copilot and OpenAI Codex for agent-driven workflows.

Is Developer Edition really free?

Yes. Developer Edition requires no credit card and no paid subscription. You authenticate once via GitHub, GitLab, or Google and you're up and running. There's no trial period — it's free to use, forever.

What kinds of scans does it run?

Developer Edition includes four core scan types: static application security testing (SAST) for code-level issues, software composition analysis (SCA) for dependency vulnerabilities, secrets detection for exposed credentials, and malicious package detection to catch supply chain attacks before they reach your environment.

Does my code leave my machine?

No. All scans run locally. The MCP Server accesses AURI's vulnerability database for intelligence (read-only), but your source code stays on your machine and is never uploaded to Endor Labs' platform.

How is this different from other free security MCP servers?

Most free MCP servers focus on code scanning alone. The AURI Developer Edition is the only free offering that combines code scanning (SAST and secrets) with full supply chain security — including CVE detection and malicious open source package identification in your dependencies.

Do I need to install anything besides the MCP Server?

No. The MCP Server fetches everything it needs on demand, including the Endor Labs CLI. There's no separate installation step, no pre-configuration, and no dependency management required to get started.

Can I use Developer Edition with my team?

Developer Edition is designed for individual developers. If your team needs shared policies, centralized reporting, or platform-level visibility, Endor Labs offers team and enterprise tiers that build on the same scanning engine with collaboration and governance features.

What's the difference between Developer Edition and the full Endor Labs platform?

Developer Edition gives you the core scanning tools — MCP Server and CLI — with default security policies and local-only results. The full platform adds a web UI, custom policies, centralized reporting, team management, and integrations with SIEM and vulnerability management tools for organization-wide security programs.