Copa (Project Copacetic)
Project Copacetic (Copa) is an open source command line tool that patches container images directly using BuildKit, without requiring a full image rebuild. Copa parses vulnerability scan reports from Trivy and other scanners, applies the corresponding OS package updates via the appropriate package manager (apt, apk, dnf, tdnf, yum, zypper), and produces a new container image with a patched layer. Copa supports multi-platform images, distroless images, and custom scanner plugins through the Vulnerability Exchange (VEX) and pluggable scanner interface.
Copa (Project Copacetic) publishes 3 APIs on the APIs.io network. Tagged areas include BuildKit, CLI, CNCF Sandbox, Container Patching, and Containers.
Copa (Project Copacetic)’s developer surface includes documentation, changelog, and 6 more developer resources.
Kin Score
APIs 3
Individual APIs this provider publishes, each with its own machine-readable definition.
Copa CLI
The copa command line interface used to patch container images. The core subcommand `copa patch` accepts an image reference and an optional vulnerability report and produces a n...
Copa Scanner Plugin Interface
Copa exposes a plugin interface that allows third-party vulnerability scanners to feed reports into the patcher. Out of the box, Copa supports Trivy JSON reports and provides do...
Copa VEX Output
Copa can emit a Vulnerability Exchange (VEX) document describing which CVEs were patched. VEX documents help security teams and downstream consumers verify that an image has bee...
Pricing Plans 1
Published pricing tiers and plan structures.
Copa Plans Pricing
PLANSRate Limits 1
Documented rate limits and quota policies.
Copa Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Copa Finops
FINOPSResources
Documentation 1
Reference material describing how the API behaves
Build 2
SDKs, sample code, and the tooling you integrate with
Operate 3
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 1
The organization behind the API