Secure

Vulnerability management: a work queue, not a report

Deduplicate the findings, rank them by whether they are actually reachable, give each one an owner and a remediation, and track it until a rescan confirms it is gone.

Short answer

What is Vulnerability Management?

DevOpsArk vulnerability management is the module that consolidates vulnerability findings from every scanner, deduplicates and prioritises them by real exposure, assigns ownership, and tracks each finding through remediation to verified closure.

Why it matters

What Vulnerability Management is for

The conditions this module removes. If none of these are familiar, you probably do not need it yet.

  • The vulnerability report has 12,000 rows and produces no decisions.
  • The same base-image CVE is counted 300 times because 300 services share the layer.
  • Severity is CVSS, which does not know whether the affected code is ever loaded.
  • A finding has no owner, so it stays open until someone runs the report again.
  • A fixed vulnerability reappears next month because the fix was applied to a running container rather than the image.
How it works

Findings from every scanner and every source are consolidated into one model and deduplicated: a vulnerability in a shared base image becomes one item affecting many services rather than many identical items. Each item is then scored on exposure (is the workload internet-reachable, is the vulnerable package actually loaded at runtime, does the workload hold credentials, what data can it reach), which reorders the list into something worth working from top to bottom. Ownership comes from the application catalogue, so a finding arrives at a team rather than in a queue. Remediation is stated concretely: the base image version to move to, the dependency version to bump, or the configuration to change, together with the number of services the same action would fix. Closure is verified by rescan of the rebuilt artifact, so a fix applied to a running container without rebuilding the image does not count as closed.

Capabilities

What Vulnerability Management does

The 8 capabilities that make up Vulnerability Management.

Consolidation and deduplication

One item per distinct vulnerability, with the list of affected services attached rather than one item per service.

Exposure-based risk scoring

Reachability, runtime loading, credential access and data sensitivity, combined with severity to produce a working order.

Owner assignment

Findings reach the team that owns the affected service, with escalation when a service level target is at risk.

Concrete remediation

The specific version or configuration change, plus how many other services the same change resolves.

Verified closure

A finding closes when a rescan of the rebuilt artifact confirms it, not when someone marks it done.

Remediation SLAs

Time-to-fix targets per severity and exposure class, with ageing visible per team.

Risk acceptance with expiry

Accept a risk explicitly, with a justification, an approver and an expiry date after which it returns.

Backlog trend

Whether the backlog is shrinking, and which teams are keeping pace with inflow.

Architecture

How Vulnerability Management fits together

Sources
Image scansDependency scansIaC scansCloud postureThird-party scanners
Vulnerability management
ConsolidationExposure scoringOwnership routingSLA tracking
Remediation
Base image rebuildDependency bumpConfiguration change
Verification
RescanVerified closureTrend reporting
Vulnerability Management architecture within the DevOpsArk control plane.

Outcomes

  • 12,000 rows become a few hundred distinct problems.
  • The top of the list is genuinely the most urgent work.
  • Fixing one base image closes hundreds of findings in one action.
  • Closure is verified, so the number reflects reality.
  • Accepted risks expire instead of quietly becoming permanent.
How to use it

Using Vulnerability Management, step by step

The path from connecting a source to getting value, in the order it happens.

  1. 1
    Ingest findings

    Results from every scanner and source arrive in one model.

  2. 2
    Deduplicate

    Distinct vulnerabilities are separated from repeated ones.

  3. 3
    Score exposure

    Reachability, loading, credentials and data access set the working order.

  4. 4
    Assign and target

    Owners are set from the catalogue and SLA clocks start.

  5. 5
    Remediate

    The stated change is applied through the normal delivery path.

  6. 6
    Verify

    A rescan of the rebuilt artifact confirms closure.

Use cases

Where teams apply Vulnerability Management

Security

Turn a scan report into a work queue

Deduplicate, prioritise by exposure and assign owners so the list produces action.

Platform engineering

Fix hundreds of findings at once

Identify the shared base image behind the largest cluster of findings and rebuild the affected services in one pass.

Engineering leadership

Track remediation performance

Watch time-to-fix and backlog trend by team rather than a single organisation-wide count.

Compliance

Evidence a remediation process

Show SLA adherence, verified closures and expiring risk acceptances from one record.

Supported technologies

What Vulnerability Management works with

Named integrations link to their own page. The rest are supported runtimes and formats.

Do not see your stack? DevOpsArk works over standard interfaces: the Kubernetes API, OCI images, OpenTelemetry and cloud provider APIs, so most environments are supported without a bespoke connector. Ask us about yours.
FAQ

Vulnerability Management: frequently asked questions

The 8 questions teams ask most often before adopting Vulnerability Management.

See Vulnerability Management against your own environment

A 30-minute walkthrough with a platform engineer, not a sales deck. Bring a cluster and a problem.