5 ms·
.016% of the images they scanned were malicious. the rest of that 51% had vulnerabilities of some sort. now, while I understand the value of these analysis to
by compsciphd 6y ago
.016% of the images they scanned were malicious.
the rest of that 51% had vulnerabilities of some sort.
now, while I understand the value of these analysis tools, I dislike these hyperbole they put around them.
why?
many of those vulnerabilities might be in the base image that is not actually actively used. now, this isn't great, a point of docker is to limit your base environment, but people do take fatter based images in order to make their life easier.
Lets take an example, imagine you have a base image with curl installed. the application actually never uses curl or libcurl itself, but the version of curl installed has a cve against it (perhaps even a critical one). is this a "good" situation. Not really, but the application itself as provided by the docker image isn't really vulnerable in practice as it doesn't use curl.
But, all these vulnerability scanning tools have no way to determine if curl is used or not, so they just scream "security vulnerability". Where a more nuanced take would be, the application probably isn't vulnerable due to curl being installed, but it probably be better to create a leaner image.