The paper introduces ChimangoScan, a pipeline that crawls 12.7 million Docker Hub repositories, reconstructs a layer graph with 54.4 million dependency edges, and scans 52,895 high-exposure repositories representing 84.7% of recorded pulls with six tools. Reported vulnerabilities and CIS misconfigurations are nearly universal, but scanner agreement is weak: 66.8% of 80.7 million distinct vulnerability-package groups appear in only one of three vulnerability scanners. Manual labeling also finds that 99.7% of 1,100 sampled TruffleHog detections are not credentials, highlighting severe measurement and false-positive risks.
No heat snapshots are available in the last 24 hours.