chainguard-dev / edu

Educational Resources for Software Supply Chain Security
https://edu.chainguard.dev
Other
74 stars 62 forks source link

Text4Shell Demo tutorial #184

Closed SharpRake closed 1 year ago

SharpRake commented 1 year ago

What topic are you requesting a resource about?

Proposed title: "Using Chainguard Enforce to Detect the Log4Shell Vulnerability"

Description: A companion piece to the Log4Shell demo tutorial that walks readers through how they can use Chainguard Enforce for Kubernetes to detect the Text4Shell vulnerability

amdawson commented 1 year ago

i had a video in today's announcement that probably covers this

dlorenc commented 1 year ago

Can we close this one now?

ltagliaferri commented 1 year ago

@SharpRake is adding a section to the Log4Shell tutorial but it has not been merged yet

@amdawson — do you think we should cross-post these videos into Academy?

amdawson commented 1 year ago

That's up to you

amdawson commented 1 year ago

Whatever you think is best.

dlorenc commented 1 year ago

Any updates on this one?

SharpRake commented 1 year ago

I have a draft that's nearing completion. Landing on the overall structure has been a little tricky, and I've been delayed by some debugging on my end.

SharpRake commented 1 year ago

This was held up due to me being away for the holidays. Getting back into it this week, I began running into some consistent issues with the demo image. @johnfosborneiii is helping to get the problem squared away and once he does I should be able to complete my testing for this update.

ltagliaferri commented 1 year ago

the text4shell demo is not currently working as expected, but it should be squared away sometime next week

dlorenc commented 1 year ago

It sounds like there's still an issue with the image - @johnfosborneiii or @mattmoor - are you looking into it?

ltagliaferri commented 1 year ago

The image has been updated and @SharpRake is going back to test the writeup

johnfosborneiii commented 1 year ago

I have resolved this (requires cosign 2.x). The instructions on the README are updated. I believe this can be closed.

dlorenc commented 1 year ago

Can this be closed?

ltagliaferri commented 1 year ago

We will close when the tutorial is published, it needs to go through review

amdawson commented 1 year ago

should be soon now, i paired with Mark on it a bit today, i think he's good.