Skip to content

Scan all or most containers with Trivy / Dockle #60

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
sylus opened this issue May 19, 2020 · 4 comments
Closed

Scan all or most containers with Trivy / Dockle #60

sylus opened this issue May 19, 2020 · 4 comments
Assignees
Labels
area/engineering Requires attention from engineering: focus on foundational components or platform DevOps area/security kind/feature New feature or request priority/soon size/M 2-3 days

Comments

@sylus
Copy link
Member

sylus commented May 19, 2020

In order to more fully comply with security compliance, we should try to scan most of our containers with Trivy / Dockle using Azure Container-Scan.

https://github.com/Azure/container-scan

@sylus sylus self-assigned this May 19, 2020
@sylus sylus added area/security area/engineering Requires attention from engineering: focus on foundational components or platform DevOps size/M 2-3 days labels May 19, 2020
@sylus
Copy link
Member Author

sylus commented May 20, 2020

I'll be handling this one

@blairdrummond
Copy link
Contributor

Any plans for containers already in our registry?

Should this be applied to daaas-containers as well? I think some of the images in daaas-containers run as root. (Which we probably can+should change)

@sylus
Copy link
Member Author

sylus commented May 20, 2020

Scope is small first then can be expanded out.

@brendangadd brendangadd added kind/feature New feature or request priority/soon labels May 27, 2020
@sylus
Copy link
Member Author

sylus commented May 29, 2020

Only kubeflow-containers is left looking to see if is feasible given how large tomorrow.

@sylus sylus closed this as completed Jun 2, 2020
@wg102 wg102 mentioned this issue Jul 12, 2022
14 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/engineering Requires attention from engineering: focus on foundational components or platform DevOps area/security kind/feature New feature or request priority/soon size/M 2-3 days
Projects
None yet
Development

No branches or pull requests

3 participants