3 ms·
I'm struggling with this now too. It gets even crazier when you have dozens of microservices, each in their own container. Imagine being mandated by InfoSec to
by mac-chaffee 5y ago
I'm struggling with this now too. It gets even crazier when you have dozens of microservices, each in their own container.
Imagine being mandated by InfoSec to scan ~24 images or ~10 GB every release.
The images are a mixture of python services and some upstream images like redis and mysql. If anyone has an idea on how to make this less painful, I'm all ears.
- itamarst 5y ago1. Install security updates (`apt-get upgrade`, or equivalent). 2. Only scan for security problems that _have updates available_. If there are no updates ... there's nothing you can do. Many security problems will never get updates, because it's an obscure problem that e.g. only happens if you install a NFS server in your container (which I assume you're not), or the upstream maintainer has closed it as WONTFIX. Some scanners (e.g. Trivy) have this as a command-line option, or a switch you can toggle in the UI. Long version of the latter: https://pythonspeed.com/articles/docker-security-scanner/ https://pythonspeed.com/articles/docker-security-scanner/