Patch container images directly based on vulnerability scan results
Tool to directly patch container images given the vulnerability scanning results
copa$ copa patch -i image:tag -r trivy-report.json -t patched-image:tag$ copa patch -i vulnerable-app:1.0 -r scan-results.json --output-report patch-report.json$ copa patch -i myapp:latest -r vulnerabilities.json -t myapp:patched --skip-errors