issues
search
AnalogJ
/
thesparktree-blog
github pages.
https://blog.thesparktree.com
0
stars
1
forks
source link
Topic: Secure Docker Images
#140
Open
AnalogJ
opened
3 years ago
AnalogJ
commented
3 years ago
public Docker Images are insecure (show vulns reports)
alpine
distroless
CI/CD integration (snyk/Anchore)
supply chain attacks -
investigate
https://www.open-scap.org/
https://github.com/genuinetools/bane
https://github.com/dev-sec/cis-docker-benchmark
https://github.com/quay/clair
https://github.com/google/docker-explorer
https://github.com/docker/docker-bench-security
https://github.com/aquasecurity/trivy
https://github.com/sigstore/cosign
AnalogJ
commented
3 years ago
https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html
https://brianchristner.io/how-to-use-docker-scan/
https://snyk.io/blog/10-docker-image-security-best-practices/
http://crunchtools.com/comparison-linux-container-images/