3 ms·
This seems like intentionally misunderstanding a technology in order to make an inflammatory headline. Docker images are versioned, just like any distribution m
by AlexB138 6y ago
This seems like intentionally misunderstanding a technology in order to make an inflammatory headline. Docker images are versioned, just like any distribution mechanism. Go through indexes for any package mechanism and count how many of the old packages have vulnerabilities. It will be a lot, because old software has vulnerabilities. That's why you update your packages, and why you update your Docker images.
- Voloskaya 6y agoI had the same initial reaction but after digging into their report, they only analyse `latest` tag of all images: > By default, Prevasio Analyzer first attempts to find the “latest” tag of a container image. If the “latest” tag is missing, it picks up the last tag enlisted in the JSON file So it's 51% of the "up to date" docker images that have critical vulnerabilities.
- oftenwrong 6y ago`latest` is applied to the most recent image built without an explicit tag (or one explicitly tagged as `latest`); it does not necessarily mean that image is the most "up to date" in any sense. For example, you could have a very old `latest` image, which was built before many explicitly tagged images. Whoever came up with this heuristic probably did not really understand `latest`. To be fair, though, it is a fairly misleading and confusing "feature".