4 ms·
At this point in time the tool is mostly relying on dynamic analysis though there's a bit of static analysis too when you want to include extra artifacts. The d
by kylequest 7y ago
At this point in time the tool is mostly relying on dynamic analysis though there's a bit of static analysis too when you want to include extra artifacts. The dynamic analysis part is done using a couple of different monitors that look at what files are accessed in the container and what system calls are made. Yes, there's a potential risk that something is missing, but you can mitigate this risk in a number of ways. First, you can run your own container test to ensure better coverage. Second, you can include additional artifacts by explicitly telling docker-slim what you want to keep regardless of what it sees.