ãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã»ãã¥ãªãã£
ããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ããšã¯ããœãããŠã§ã¢ã®éçºãããããã€ã¡ã³ããä¿å®ãŸã§ã®äžé£ã®ããã»ã¹ãæããŸãããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã»ãã¥ãªãã£ïŒSoftware Supply Chain Security, S3CïŒãšã¯ããã®ãµãã©ã€ãã§ãŒã³ã®ã³ã³ããŒãã³ããããã»ã¹ãä¿è·ããããã®å®è·µã§ãã
S3Cã¯ãOrganization ããœãããŠã§ã¢ã»ãã¥ãªãã£ã«åãçµãæ¹æ³ã«ãããæ ¹æ¬çãªå€é©ã§ããåŸæ¥ããœãããŠã§ã¢æ¥çã§ã¯ãã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã¯åŸåãã«ãããã¡ã§ãäž»ã«ãœãããŠã§ã¢ã®é ä¿¡ããªãªãŒã¹æ®µéã§èæ ®ãããŠããŸãããããããS3Cã§ã¯ãã»ãã¥ãªãã£ã¯ãœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«å šäœã«çµ±åãããŠãããéçºãšãã¹ãã®å åŽã®ã«ãŒããããåºè·ãšç£èŠã®å€åŽã®ã«ãŒããŸã§é¢äžããŠããŸãã
æ¥çã®ãã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã管çããããšã¯ãã»ãã¥ãªãã£è åšãã³ã³ãã©ã€ã¢ã³ã¹ãªã¹ã¯ããã®ä»ã®è匱æ§ãããœãããŠã§ã¢ãä¿è·ããããã«éèŠã§ãããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯ãå®è£ ããããšã§ããããžã§ã¯ãã«é¢ããå©å®³é¢ä¿è éã§ã®å¯èŠæ§ãã³ã©ãã¬ãŒã·ã§ã³ããã¬ãŒãµããªãã£ãåäžããŸããããã«ãããOrganizationã¯è åšãããå¹æçã«æ€åºã察å¿ãä¿®æ£ããããšãã§ããŸãã
ãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã®ã»ãã¥ãªãã£åŒ·å
ã»ãã¥ã¢ãªãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ãæ§ç¯ããã«ã¯ã次ã®ãããªäž»èŠãªã¹ããããå¿ èŠã§ãïŒ
- ã¢ããªã±ãŒã·ã§ã³ã®æ§ç¯ãšå®è¡ã«äœ¿çšããããœãããŠã§ã¢ã³ã³ããŒãã³ããäŸåé¢ä¿ãç¹å®ããã
- ãœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«å šäœã§ã»ãã¥ãªãã£ãã¹ããèªååããã
- ãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã«å¯Ÿããã»ãã¥ãªãã£è åšãç£èŠããã
- ãœãããŠã§ã¢ã®æ§ç¯æ¹æ³ãå«ãŸããã³ã³ããŒãã³ãã管çããã»ãã¥ãªãã£ããªã·ãŒãå®è£ ããã
çŸä»£ã®ãœãããŠã§ã¢ã¯å€ãã®ç°ãªããœãŒã¹ããã®ã³ã³ããŒãã³ãã䜿çšããŠæ§ç¯ãããããããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã®ç®¡çã¯è€éã§ããOrganization ã¯ã䜿çšãããœãããŠã§ã¢ã³ã³ããŒãã³ããšããã«é¢é£ããã»ãã¥ãªãã£ãªã¹ã¯ãæ確ã«ææ¡ããå¿ èŠããããŸãã
Docker Scout
Docker Scoutã¯ãOrganization ããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ãã»ãã¥ã¢ã«ä¿ã€ããã«èšèšããããã©ãããã©ãŒã ã§ãããœãããŠã§ã¢è³ç£ãããªã·ãŒã®ç¹å®ãšç®¡çãã»ãã¥ãªãã£è åšã®èªåä¿®æ£ã®ããã®ããŒã«ãšãµãŒãã¹ãæäŸããŸãã
åŸæ¥ã®ã»ãã¥ãªãã£ããŒã«ã¯ããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ã®ç¹å®ã®æ®µéã§ã¹ã±ãžã¥ãŒã«ãããã¿ã€ãã³ã°ã§ã¹ãã£ã³ãå®æœãããã®ã§ããããDocker Scoutã¯ããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³å šäœãã«ããŒããã€ãã³ãé§ååã®ææ°ã¢ãã«ã䜿çšããŠããŸããããã«ãããã€ã¡ãŒãžã«åœ±é¿ãäžããæ°ããè匱æ§ãå ¬éããããšãã«ããªã¹ã¯è©äŸ¡ãæ°ç§ä»¥å ã«æŽæ°ãããéçºããã»ã¹ã®æ©ã段éã§åæ ãããŸãã
Docker Scoutã¯ãã€ã¡ãŒãžã®æ§æãåæããŠãœãããŠã§ã¢éšåè¡š (SBOM) ãäœæããŸããSBOMã¯ã»ãã¥ãªãã£ã¢ããã€ã¶ãªãšç §åãããã€ã¡ãŒãžã«åœ±é¿ãäžããCVEãç¹å®ãããŸããDocker Scoutã¯ã20以äžã®ç°ãªãã»ãã¥ãªãã£ã¢ããã€ã¶ãªãšçµ±åãããªã¢ã«ã¿ã€ã ã§è匱æ§ããŒã¿ããŒã¹ãæŽæ°ããŸããããã«ãããææ°ã®æ å ±ã䜿ã£ãŠã»ãã¥ãªãã£ç¶æ³ãåæ ãããŸãã