Secure code with Sysdig Secure and VS Code
Bring security directly into the developer workflow with the Sysdig Secure extension for Visual Studio Code. Sysdig helps developers identify vulnerabilities, misconfigurations, and compliance policy violations while they write code—before changes reach CI/CD pipelines or production.
With the extension, directly within VS Code developers can scan:
- container images
- Dockerfiles
- Docker Compose files
- Kubernetes manifests
- Terraform projects, and other Infrastructure as Code (IaC) resources .
In addition, you can also evaluate projects against Sysdig Secure Vulnerability Management policies and view findings in context, helping you understand what needs to be fixed and where.
Getting started is simple: install Sysdig Scanner from the VS Code Marketplace, authenticate with a Sysdig Secure API token, and connect to your Sysdig Secure endpoint. Once configured, you apply managed or custom policies, upload scan results, and use standalone scanning when working offline.
Shift security left without slowing development. With Sysdig Secure and VS Code, developers can find and fix risks earlier, while security teams gain consistent policy enforcement across the software lifecycle.
Learn More
Check out our documentation to learn more and get started.
