Project Intern
Project Title: Container Image Vulnerability and Compliance Automation Framework Using CI/CD at IMGEOS.
• Technologies:Jenkins,Docker, Bash, Linux
• Tools & Platforms: Trivy, Skopeo, inotify-tools, Private Container Registry.
• Concepts Applied: CI/CD, DevSecOps, Container Security, Compliance Automation.
• Designed and Implemented a robust DevSecOps solution at IMGEOS to automate vulnerability detection and compliance verification for container images using a jenkins driven CI/CD pipeline
• Streamlined image processing workflows by automating the transfer and real-time monitoring of tar image archives via inotify-tools and NFS, reducing manual effort and improving operational efficiency.
• Integrated Trivy for container vulnerability scanning and Skopeo for compliance checks, with custom logic to flag and alert on critical CVEs (23), enforcing internal security policies.
• Ensured secure deployment by promoting only validated and compliant container images to a private registry, with full pipeline logging for traceability and audit readiness