4 ms·
And the fun part there is that this image is effectively a workaround - node.js 20 is installed via curl | bash. That means CVE scanners and SCA tools can miss
by dlor 3y ago
And the fun part there is that this image is effectively a workaround - node.js 20 is installed via curl | bash. That means CVE scanners and SCA tools can miss node itself in that image.
As silly as it sounds, try running "snyk container test --print-deps" on that image, and look around for Node.
This approach works fine, but means that you might not be able to rely on most container security scanners to let you know when there's an issue.
- kristianpaul 3y agoYou can scan the file system, probably thats what AWS ECR does? At the end of they you need to keep an eye on file integrity, because of rootkits, config integrity… Yeah there are many wats to approach to this… with its corresponding costs of course
- xnyanta 3y agoSounds to me like CVE scanners aren't doing a great job if they can't pick up a nodejs installation from the official nodejs image distribution. Just looking at package manager metadata effectively won't give you the full picture.