3 ms·
Although I understand reading the sources of all software we're running would take way too much time to be reasonable, running a quick docker inspect / docker h
by tbronchain 8y ago
Although I understand reading the sources of all software we're running would take way too much time to be reasonable, running a quick docker inspect / docker history on all images we use is, in addition to be interesting, probably a big first layer of protection.
Having a tool doing this for us - i.e a sort of docker anti-malware, that would inspect images and containers for us, without necessarily go through all the security stuff the official tool checks - would also be very handy.
- jacques_chester 8y agoThere is an entire genre of such tools now. Some names to look up are BlackDuck Hub[0] (commercial) and CoreOS Clair[1] (opensource). At Pivotal we use both -- BlackDuck is built into a number of our pipelines and Clair is shipped as part of PKS (in the Harbor registry[2] contributed by VMWare). A lot of our customers also use other security scanning tools that have expanded to include container scanning. [0] https://www.blackducksoftware.com/products/hub https://www.blackducksoftware.com/products/hub [1] https://github.com/coreos/clair https://github.com/coreos/clair [2] https://github.com/vmware/harbor https://github.com/vmware/harbor
- tbronchain 8y agoI didn't know them. Thanks for bringing them up!