ã¢ããã€ã¶ãªããŒã¿ããŒã¹ã®ãœãŒã¹ãšãããã³ã°ãµãŒãã¹
ä¿¡é Œæ§ã®é«ãæ å ±æºã¯ãDocker Scout ããœãããŠã§ã¢ã¢ãŒãã£ãã¡ã¯ãã«é¢ããæ£ç¢ºãªè©äŸ¡ãæäŸããããã®éµã§ããæ¥çã«ãããæ å ±æºãšææ³ã®å€æ§æ§ãããè匱æ§è©äŸ¡çµæã«ãããå·®ç°ãçºçããããšããããŸãããã®ããŒãžã§ã¯ãDocker Scout ã®ã¢ããã€ã¶ãªããŒã¿ããŒã¹ãšãã® CVE-to-ããã±ãŒãžãããã³ã°ã¢ãããŒãã«ã€ããŠèª¬æããããããå·®ç°ã«å¯ŸåŠããæ¹æ³ã玹ä»ããŸãã
ã¢ããã€ã¶ãªããŒã¿ããŒã¹ã®ãœãŒã¹
Docker Scout ã¯è€æ°ã®æ å ±æºããè匱æ§ããŒã¿ãéçŽããŠããŸãããã®ããŒã¿ã¯ç¶ç¶çã«æŽæ°ãããã»ãã¥ãªãã£ç¶æ ããªã¢ã«ã¿ã€ã ã§ææ°ã®æ å ±ã«åºã¥ããŠè¡šç€ºãããããã«ãªã£ãŠããŸãã
Docker Scout ã¯æ¬¡ã®ããã±ãŒãžãªããžããªããã³ã»ãã¥ãªãã£ãã©ãã«ãŒã䜿çšããŠããŸãïŒ
- Alpine secdbâ
- AlmaLinux Security Advisoryâ
- Amazon Linux Security Centerâ
- Bitnami Vulnerability Databaseâ
- CISA Known Exploited Vulnerability Catalogâ
- CISA Vulnrichmentâ
- Debian Security Bug Trackerâ
- Exploit Prediction Scoring System (EPSS)â
- GitHub Advisory Databaseâ
- GitLab Advisory Databaseâ
- Golang VulnDBâ
- inTheWild - ã³ãã¥ããã£äž»å°ã®è匱æ§ãšã¯ã¹ããã€ãããŒã¿ããŒã¹â
- National Vulnerability Databaseâ
- Oracle Linux Securityâ
- Python Packaging Advisory Databaseâ
- RedHat Security Dataâ
- Rocky Linux Security Advisoryâ
- RustSec Advisory Databaseâ
- SUSE Security CVRFâ
- Ubuntu CVE Trackerâ
- Wolfi Security Feedâ
- Chainguard Security Feedâ
Docker Scout ã Docker Organization ã§æå¹åãããšãæ°ããããŒã¿ããŒã¹ã€ã³ã¹ã¿ã³ã¹ã Docker Scout ãã©ãããã©ãŒã äžã«ããããžã§ãã³ã°ãããŸãããã®ããŒã¿ããŒã¹ã«ã¯ãã€ã¡ãŒãžã«é¢ãããœãããŠã§ã¢éšåè¡šïŒSBOMïŒããã³ãã®ä»ã®ã¡ã¿ããŒã¿ãæ ŒçŽãããŸããè匱æ§ã«é¢ããæ°ããæ å ±ãã»ãã¥ãªãã£ã¢ããã€ã¶ãªã«è¿œå ããããšãSBOM ã CVE æ å ±ãšç §åãããããããŠãŒã¶ãŒã«ã©ã®ãããªåœ±é¿ãäžããããæ€åºãããŸãã
ã€ã¡ãŒãžåæã®ä»çµã¿ã«ã€ããŠã®è©³çŽ°ã¯ãã€ã¡ãŒãžåæããŒãžãåç §ããŠãã ããã
è匱æ§ãããã³ã°
åŸæ¥ã®ããŒã«ã¯äžè¬ã«åºç¯ãªCommon Product EnumerationïŒCPEïŒâãããã³ã°ã«äŸåããŠããŸãããããã«ããå€ãã®èª€æ€åºãçºçããå¯èœæ§ããããŸãã
Docker Scout ã¯ããã±ãŒãž URL (PURL)âã䜿çšã㊠CVE ã«å¯Ÿããããã±ãŒãžã®ãããã³ã°ãè¡ããããè匱æ§ã®èå¥ç²ŸåºŠãåäžããŸããPURL ã䜿çšããããšã§ã誀æ€åºã®å¯èœæ§ãå€§å¹ ã«äœæžãããå®éã«åœ±é¿ãåããããã±ãŒãžã®ã¿ã察象ãšãªããŸãã
察å¿ããŠããããã±ãŒãžãšã³ã·ã¹ãã
Docker Scout ã¯æ¬¡ã®ããã±ãŒãžãšã³ã·ã¹ãã ããµããŒãããŠããŸãïŒ
- .NET
- GitHub packages
- Go
- Java
- JavaScript
- PHP
- Python
- RPM
- Ruby
alpm
(Arch Linux)apk
(Alpine Linux)deb
(Debian Linux ããã³ãã®æŽŸç)