Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automated image vulnerability scan #614

Open
c0c0n3 opened this issue Jan 5, 2022 · 3 comments
Open

Automated image vulnerability scan #614

c0c0n3 opened this issue Jan 5, 2022 · 3 comments
Assignees

Comments

@c0c0n3
Copy link
Member

c0c0n3 commented Jan 5, 2022

Is your feature request related to a problem? Please describe.

Should we get a tool to scan the Docker images we build to sniff out any security vulnerabilities?

Describe the solution you'd like

Here's a nice example contributed by @jason-fox of a GitHub action to run Anchore scanner over an image:

The action outputs a bunch of CVE alerts you can then decide how to deal with, as shown in the image below

image

Describe alternatives you've considered

N/A

Additional context

N/A

@c0c0n3
Copy link
Member Author

c0c0n3 commented Jan 6, 2022

PR #588 actually implemented a vulnerability scan through the CodeQL Action. I haven't used myself any of those actions, so I've got no clue which one would be best for us and if they do pretty much the same thing.

@chicco785 is the scan done by the CodeQL action comparable to Anchore's? If so can we close this issue?

@chicco785
Copy link
Contributor

not sure it's comparable (i.e. all the same feature are covered) but the tools analyse dependencies and code vulnerabilities

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants