> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/set-up-sto-scans/container-scanning/container-scanning.md).

# Container Scanning

Set up Container scanning using STO

Container Scanning is a security testing practice that analyzes your container images for potential vulnerabilities. It is a critical step in identifying and addressing security risks early in the software development lifecycle (SDLC).

With Harness Security Testing Orchestration (STO), easily perform container scanning using a wide range of [integrated scanners](#supported-scanners-for-container-scanning). STO also applies its own features, such as results normalization, deduplication of findings within each scanner, and formatting results to make them actionable.

### Set up Container Scanning with Harness STO <a href="#set-up-container-scanning-with-harness-sto" id="set-up-container-scanning-with-harness-sto"></a>

You can use any of the [integrated scanners](#supported-scanners-for-container-scanning) that perform Container Scanning, or you can leverage the Harness STO [Built-in Scanner workflow](/security-testing-orchestration/3.0/use-sto/set-up-sto-scans/built-in-scanners.md). The Built-in Scanner step enables you to set up scans without requiring paid licenses or complex configurations. Alternatively, select any scanner from the list below for detailed configuration steps.

{% embed url="<https://youtu.be/__42LZDVZIo?si=_jYgcj86q0aS7oJ->" %}

#### Supported Scanners for Container Scanning <a href="#supported-scanners-for-container-scanning" id="supported-scanners-for-container-scanning"></a>

Below is the list of supported scanners for Container Scanning in Harness STO:

If the scanner you use for container scanning is not listed, you can explore additional [scanners](/security-testing-orchestration/3.0/use-sto/sto-custom-scanning-and-ingestion/custom-scan-reference.md) that are compatible with the [Custom Scan step](/security-testing-orchestration/3.0/use-sto/sto-custom-scanning-and-ingestion/custom-scan-reference.md). If the Custom Scan step does not support the scanner you need, you can use the [Custom Ingestion](/security-testing-orchestration/3.0/use-sto/sto-custom-scanning-and-ingestion/custom-ingest-reference.md) step to ingest and process your scan results.

### Next steps <a href="#next-steps" id="next-steps"></a>

{% @harness-feedback/feedback %}
