Watchlists and vulnerability intelligence
Track important images and investigate cached vulnerability knowledge.
Watchlists schedule recurring scans of important images and summarize freshness and policy posture. Use them for images whose risk needs review even when a new build is not being released. The Vulnerability Knowledge Base is also the authenticated CVE Explorer: use /vulnkb to search CVEs, review current metadata, inspect normalized change history, and investigate findings from scans you can access. It is separate from the delta-based CVE Intelligence worker.
Configure an NVD API key when you need faster CVE enrichment. The cache lifetime is controlled by vuln_kb.cache_days. CVE Intelligence monitors changes to retained findings through the NVD change feed instead of refreshing every Vulnerability KB entry on every run. Review notification delivery and freshness expectations before treating a missed watchlist scan as an incident.
The CVE Explorer has separate Summary, Change history, Affected findings, and References tabs. History is available to all authenticated users as normalized change data. Affected findings are restricted to completed scans visible through personal ownership, organization access, or explicit sharing; the explorer does not reveal packages, scan names, or posture data from another user's scans. Use the Intelligence filter on Scan Details when triaging a specific result, and open the finding's Summary or History tab for scan-time/current comparisons and full per-finding events.