Your Container Has Vulnerabilities. Now What?

  Рет қаралды 8,639

Docker

Docker

Күн бұрын

--
You work hard to build the perfect image for your app and then you run your container image through a vulnerability scanner and you get a surprise: vulnerabilities...maybe hundreds of them! It can be overwhelming, particularly if it blocks your app from deployment. But it doesn't have to be and you don't need to become an operating system maintainer and build all your images from `scratch` to deal with vulnerabilities.
In this session I'll take you through a pattern for dealing with container image vulnerabilities. We'll look at real container images from the ecosystem and systematically deal with removing vulnerabilities including:
Deciding on a base image: other than just choosing a minimal base image, what can you do to build a set of trusted base images for your organization to use?
Dealing with vulnerabilities introduced by RUN, COPY, and ADD commands
Checking your own code & its dependencies
Dockerfile and docker build tips that will help you deal with vulnerabilities later on
Multistage builds - is there anything they can't do?
A brief look at scratch, distroless, and other advanced options
Speaker: Jim Armstrong, Synk
Twitter: @jdarmstro

Пікірлер: 3
Kubernetes at Datadog Scale
20:22
Docker
Рет қаралды 812
String Competition for iPhone! 😱
00:37
Alan Chikin Chow
Рет қаралды 30 МЛН
БАЙГАЙСТАН | 3 СЕРИЯ | ДУБАЙ |bayGUYS
44:17
bayGUYS
Рет қаралды 1,8 МЛН
New Colour Match Puzzle Challenge With Squid Game 2 - Incredibox Sprunki
00:30
Bungee Jumping With Rope In Beautiful Place:Asmr Bungee Jumping
00:14
Bungee Jumping Park Official
Рет қаралды 17 МЛН
What's the difference between container and SCA vulnerability scanning?
9:56
Latio Tech - Learn Product Security
Рет қаралды 625
My Container Image has 500 Vulnerabilities, Now What? - Matt Jarvis, Snyk
25:07
CNCF [Cloud Native Computing Foundation]
Рет қаралды 3,1 М.
Simplify All the Things with Docker Compose
29:31
Docker
Рет қаралды 34 М.
Best Practices for Compose-managed Python Apps
29:20
Docker
Рет қаралды 6 М.
Securing Your Containerized Applications with NGINX
22:31
Docker
Рет қаралды 16 М.
How to build 0 CVE docker images? Can there be a better solution?
17:23
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
Building a Docker Image Pipeline Using GitHub Actions
22:28
String Competition for iPhone! 😱
00:37
Alan Chikin Chow
Рет қаралды 30 МЛН