So I built one.
It’s powered by the popular open-source tool Trivy.
Show HN: I built ContainerCVE – a web tool to scan public Docker images
containercve.com
1–10 of 38 posts
So I built one.
It’s powered by the popular open-source tool Trivy.
Show HN: I built ContainerCVE – a web tool to scan public Docker images
containercve.com
How do you identify what is a safe Docker Hub image?
Surely it's not just reputation of the publisher of the image.
I think it’s a somewhat new product so it may not be too widespread yet, but it seems to work pretty well from my admittedly uninformed perspective.
It looks great. My main concern with Docker Hub images is what else is in the image that shouldn't be there. Not necessarily CVE issues, but just down right malicious code. How do you identify what is a safe Docker Hub image? Surely it's not just reputation of the publisher of the image.
It looks great. My main concern with Docker Hub images is what else is in the image that shouldn't be there. Not necessarily CVE issues, but just down right malicious code. How do you identify what is a safe Docker Hub image? Surely it's not just reputation of the publisher of the image.
It looks great. My main concern with Docker Hub images is what else is in the image that shouldn't be there. Not necessarily CVE issues, but just down right malicious code. How do you identify what is a safe Docker Hub image? Surely it's not just reputation of the publisher of the image.
(Whether the standard docker tooling or user decides to validate signatures is another thing.)
It looks great. My main concern with Docker Hub images is what else is in the image that shouldn't be there. Not necessarily CVE issues, but just down right malicious code. How do you identify what is a safe Docker Hub image? Surely it's not just reputation of the publisher of the image.
At the moment I'm rat-holing on apt package pinning, which doesn't work at all like I expected. Looking like I'm stuck between the Debian snapshot archive and vendoring .deb files (I don't like either).
Eventually this will go out on https://alexsci.com/blog/
you should include seed phrase and private key detection. a few crypto protocols that offer public docker images have been drained from accidentally committing keys to docker hub.
[1] https://aquasecurity.github.io/trivy/v0.27.1/docs/secret/sca...