> For the complete documentation index, see [llms.txt](https://docs.opsmx.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.opsmx.com/integrations/integrating-security-scanning-tools/package-vulnerability-scan.md).

# Package Vulnerability Scan

Package Vulnerability Scan is a vulnerability scanning tool specifically designed for container images. It helps identify vulnerabilities within Docker containers and other container formats.

## Usage of Package Vulnerability Scan in Delivery Shield

* Delivery Shield mandates security scans on images using Package Vulnerability Scan. It connects with Package Vulnerability Scan to see if the required version of the image has been scanned by and if not done, SSD generates a security issue.
* Once the Package Vulnerability Scan is done, Delivery Shield pulls container security scan results from Package Vulnerability Scan, and this data is used to calculate the overall security status of the images and application, to generate alerts and remediation.
* The scan results fetched by Delivery Shield will be displayed in the Vulnerability Management page, Artifact section of the DBOM and View Open Security Issues page.

## To Manage Package Vulnerability Scan:

1. Navigate to **Setup** > **Integrations**.

<figure><img src="https://591284771-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FxDmLTMQiowMHZ4CQPCvT%2Fuploads%2FQP21UK913a2SUFJIaEGC%2Fpackage%20vulnerability%201a.png?alt=media&amp;token=6283b9e0-ebfc-419e-9579-0e0d7031785b" alt=""><figcaption></figcaption></figure>

2. In the **Artifact** panel, click **Package Vulnerability Scan**. The Package Vulnerability Scan integration page is displayed.
3. Click **+New Account**.

<figure><img src="https://591284771-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FxDmLTMQiowMHZ4CQPCvT%2Fuploads%2Ful8zXrZmW7XpvQiYEJB8%2Fpackage%20vulnerability%201.png?alt=media&amp;token=fbec7a08-0b43-4dd2-af2d-6ae5d63d8c47" alt=""><figcaption></figcaption></figure>

4. In the popup that appears:

<figure><img src="https://591284771-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FxDmLTMQiowMHZ4CQPCvT%2Fuploads%2FF7Sq6ZLhEMrwZP2ANObI%2Fpackage%202.png?alt=media&amp;token=54e91529-3e8d-463a-9917-552dff7b38eb" alt=""><figcaption></figcaption></figure>

4. Enter the account name.
5. Enable the **Vulnerability Scan** toggle button.
6. Select the **Teams** and the corresponding **Environments** from the dropdown for which you want the integration to be available. The integration will be available for the selected teams and environment only. You can select up to 5 teams for the integration to be displayed.

* An example is given below for reference:

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeuMZQzZsZQuulVdW9B9OuffNPoEXqbcpcAkYtKVyb7YiTQxbVIt1L4Gh-zshqX2J9MFKIat8x4oWFIGxdg3j1XVagyUNhUAlD_52soyMyd1cy53p6XiYi0LsTjIBfHcybRWl61?key=D9EXoOdGF7oYOBvYaW2GnRWJ)

* In the example above,
  * if **Team 1**, **Team 2**, and **Team 3** are selected, only applications associated with these teams can access the integration. Any applications belonging to other teams, such as **Team 4**, will not have access to this account.
* Even if the user who created this account is also an admin for **Team 4**, the integration account remains restricted and is not available for **Team 4**.
* Access to the account is strictly limited to the specified **Teams** and **Environments** selected during account creation.
* **For Organization Admins:**
  * When an **Organization Admin** creates an account without selecting specific **Teams** and **Environments**, the account will be universally applicable, granting access to **all teams** and **all environments** by default.
* **For Team Admins with Multiple Teams:**
  * If a **Team Admin** who manages multiple teams creates an account without specifying particular **Teams** and **Environments**, the account will only be accessible to the teams for which the logged-in user holds admin privileges.

7. Click **Save**. The tool is connected.
8. You can edit the entered values by clicking the **Edit** option as shown below:

<figure><img src="https://591284771-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FxDmLTMQiowMHZ4CQPCvT%2Fuploads%2FyriPvFv0FgDT348TXHC2%2Fpackage%203.png?alt=media&amp;token=91511502-de72-465c-9120-136587b36d23" alt=""><figcaption></figcaption></figure>

7. Enable or disable the Vulnerability Scan toggle button and click **Update**.

<figure><img src="https://591284771-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FxDmLTMQiowMHZ4CQPCvT%2Fuploads%2FWBIIEsEBE5kidbMSpqdZ%2Fpackage%204.png?alt=media&amp;token=087e9880-ef34-4faa-b4d3-84ef51172497" alt=""><figcaption></figcaption></figure>

The new setting gets updated.
