IP Library › Granted Patent US 12,579,280
Granted Patent B2
US 12,579,280 · App. 18/489,174 · Granted Mar 17, 2026

Systems and methods for vulnerability scanning of dependencies in containers

Inventors: Sebastian Lekies (Zürich, CH); Yousef Alowayed (New York, NY)
Assignee: Google LLC
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,280
App. No.
18/489,174
Filed
Oct 18, 2023
Granted
Mar 17, 2026
Kind
B2
Art Unit
2494
USPC
726/25
Abstract

A method includes identifying, by a processing device, a set of parameters to generate a container image for a container. The parameters comprise one or more dependencies associated with running the container in a cloud-based environment. A manifest file referencing the one or more dependencies is obtained and the container image is generated based on the set of parameters, wherein the manifest file is stored in a predetermined location associated with the container.

Claims (42)

1 . A method, comprising:

obtaining a manifest file from a container image, wherein the manifest file references one or more dependencies associated with running a container deployed from the container image in a cloud-based environment;

identifying one or more vulnerabilities associated with the one or more dependencies referenced in the manifest file;

generating a security scanning report referencing the one or more vulnerabilities; and

excluding, from the security scanning report, a vulnerability based on an indication in the manifest file that the vulnerability includes a patch.

2 . The method of claim 1 ,

wherein the manifest file is obtained from the container image by a security scanner tool.

3 . The method of claim 1 , further comprising:

generating the manifest file, wherein generating the manifest file comprises identifying which dependencies are selected for the container image and listing the identified dependencies in the manifest file.

4 . The method of claim 1 , further comprising:

generating the manifest file based on received user input referencing the one or more dependencies.

5 . The method of claim 1 , wherein the manifest file comprises a set of records indicating, for a dependency of the one or more dependencies, a version of the dependency, a distribution type of the dependency, a corresponding location in a directory structure, and patch data related to a vulnerability of the dependency.

6 . The method of claim 1 , wherein the manifest file is stored in a predetermined location associated with the container.

7 . A system comprising:

a memory device; and

a processing device coupled to the memory device, the processing device to perform operations comprising:

obtaining a manifest file from a container image, wherein the manifest file references one or more dependencies associated with running a container deployed from the container image in a cloud-based environment;

identifying one or more vulnerabilities associated with the one or more dependencies referenced in the manifest file;

generating a security scanning report referencing the one or more vulnerabilities; and

excluding, from the security scanning report, a vulnerability based on an indication in the manifest file that the vulnerability includes a patch.

8 . The system of claim 7 , wherein the operations further comprise:

identifying the one or more dependencies to generate the container image;

obtaining the manifest file referencing the one or more dependencies; and

generating the container image based on the one or more dependencies, wherein the manifest file is stored in a predetermined location associated with the container.

9 . The system of claim 7 , wherein the operations further comprise:

generating the manifest file, wherein generating the manifest file comprises identifying which dependencies are selected for the container image and listing the identified dependencies in the manifest file.

10 . The system of claim 7 , wherein the operations further comprise:

generating the manifest file based on received user input referencing the one or more dependencies.

11 . The system of claim 7 , wherein the manifest file comprises a set of records indicating, for a dependency of the one or more dependencies, a version of the dependency, a distribution type of the dependency, a corresponding location in a directory structure, and patch data related to a vulnerability of the dependency.

12 . The system of claim 8 , wherein the predetermined location comprises a location in a directory structure of the container image.

13 . A non-transitory computer-readable medium comprising instructions that, responsive to execution by a processing device, cause the processing device to perform operations comprising:

obtaining a manifest file from a container image, wherein the manifest file references one or more dependencies associated with running a container deployed from the container image in a cloud-based environment;

identifying one or more vulnerabilities associated with the one or more dependencies referenced in the manifest file;

generating a security scanning report referencing the one or more vulnerabilities; and

excluding, from the security scanning report, a vulnerability based on an indication in the manifest file that the vulnerability includes a patch.

14 . The non-transitory computer-readable medium of claim 13 , wherein

the manifest file is obtained from the container image by a security scanner tool.

15 . The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

generating the manifest file, wherein generating the manifest file comprises identifying which dependencies are selected for the container image and listing the identified dependencies in the manifest file.

16 . The non-transitory computer-readable medium of claim 13 , wherein the operations further comprise:

generating the manifest file based on received user input referencing the one or more dependencies.

17 . The non-transitory computer-readable medium of claim 13 , wherein the manifest file comprises a set of records indicating, for a dependency of the one or more dependencies, a version of the dependency, a distribution type of the dependency, a corresponding location in a directory structure, and patch data related to a vulnerability of the dependency.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2023
From: LEKIES, SEBASTIAN; ALOWAYED, YOUSEF
To: GOOGLE LLC
Reel/Frame 065263/0419 →
Continuity (1)
Related Publication 20250131096A1 · Apr 24, 2025
References Cited (13)
US 11276911B2 · Li · 2022 [cited by examiner]
US 11809575B1 · Reddy · 2023 [cited by examiner]
US 20160350081A1 · Kumar · 2016 [cited by examiner]
US 20170068676A1 · Jayachandran · 2017 [cited by examiner]
US 20170177860A1 · Suarez · 2017 [cited by examiner]
US 20170255462A1 · Azagury · 2017 [cited by examiner]
US 20170329277A1 · Ushikubo · 2017 [cited by examiner]
US 20180173502A1 · Biskup · 2018 [cited by examiner]
US 20190005246A1 · Cherny · 2019 [cited by examiner]
US 20190260716A1 · Lerner · 2019 [cited by examiner]
US 20200117434A1 · Biskup · 2020 [cited by examiner]
US 20250030719A1 · Das · 2025 [cited by examiner]
Anais Urlichs, “Software Supply Chain Security with Trivy: Generating SBOMs”, AquaSec Blog, Apr. 12, 2022. (Year: 2022). [cited by examiner]