Tag
Echo and NanoClaw collaborated to eliminate 1,400 CVEs in NanoClaw's container images through scanning, patching, and backporting fixes. The article details their agentic hardening process, including safe version bumps and manual patch research.
The author praises Lu Qi for his insights on sandbox/container security from a year ago, which have since been validated, emphasizing the core role of sandboxes in observing reward hacking.
Trivy is a comprehensive, open-source security scanner by Aqua Security that detects vulnerabilities, misconfigurations, secrets, and license issues across containers, filesystems, git repos, and Kubernetes.