Docker Scout ã®ã€ã¡ãŒãžåæ
ãªããžããªã§ã€ã¡ãŒãžåæãæå¹åãããšãDocker Scout ã¯ãã®ãªããžããªã«ããã·ã¥ãããæ°ããã€ã¡ãŒãžãèªåçã«åæããŸãã
ã€ã¡ãŒãžåæã§ã¯ããœãããŠã§ã¢éšåè¡šïŒSBOMïŒããã®ä»ã®ã€ã¡ãŒãžã¡ã¿ããŒã¿ãæœåºããã»ãã¥ãªãã£ã¢ããã€ã¶ãªã®è匱æ§ããŒã¿ãšç §åããŸãã
CLI ã Docker Desktop ã§äžåºŠã ãã€ã¡ãŒãžåæãå®è¡ããå ŽåãDocker Scout ã¯ã€ã¡ãŒãžã«é¢ããããŒã¿ãä¿åããŸãããããããã³ã³ããã€ã¡ãŒãžãªããžããªã§ Docker Scout ãæå¹åããå ŽåãDocker Scout ã¯åæåŸã«ã€ã¡ãŒãžã®ã¡ã¿ããŒã¿ã¹ãããã·ã§ãããä¿åããŸããæ°ããè匱æ§ããŒã¿ãå©çšå¯èœã«ãªããšããã®ã¡ã¿ããŒã¿ã¹ãããã·ã§ããã䜿çšããŠãªã¢ã«ã¿ã€ã ã§ã»ãã¥ãªãã£ç¶æ ãæŽæ°ããŸãããã®åçè©äŸ¡ã«ãããæ°ãã CVE æ å ±ãå ¬éãããŠãã€ã¡ãŒãžãååæããå¿ èŠããããŸããã
Docker Scout ã®ã€ã¡ãŒãžåæ㯠Docker Hub ãªããžããªã«ããã©ã«ãã§å©çšå¯èœã§ãããµãŒãããŒãã£ã¬ãžã¹ããªãä»ã®ãµãŒãã¹ãšãçµ±åã§ããŸãã詳现ã«ã€ããŠã¯ãDocker Scout ã®ä»ã·ã¹ãã ãšã®çµ±åãåç §ããŠãã ããã
ãªããžããªã§ Docker Scout ãæå¹åãã
Docker Scout ã®ç¡æãã©ã³ã§ã¯ãDocker çµç¹ããšã«æ倧 3 ã€ã®ãªããžããªãå©çšã§ããŸããè¿œå ã®ãªããžããªãå¿ èŠãªå ŽåãDocker Scout ã®ãã©ã³ãæŽæ°ã§ããŸãã詳现ã¯ãDocker Scout ã®è«æ±âãåç §ããŠãã ããã
ãµãŒãããŒãã£ã®ã¬ãžã¹ããªå ã®ãªããžããªã§ã€ã¡ãŒãžåæãæå¹åããã«ã¯ãDocker Scout ãšãã®ã¬ãžã¹ããªãçµ±åããå¿ èŠããããŸããDocker Hub ã¯ããã©ã«ãã§çµ±åãããŠããŸãã詳现ã«ã€ããŠã¯ãã³ã³ããã¬ãžã¹ããªã®çµ±åãåç §ããŠãã ããã
Docker Organization 㧠Editor ãŸã㯠Owner ã®æš©éãæã€ãŠãŒã¶ãŒã®ã¿ããªããžããªã§ã€ã¡ãŒãžåæãæå¹åã§ããŸãã
ã€ã¡ãŒãžåæãæå¹åããæé ïŒ
- Docker Scout ããã·ã¥ããŒãã®ãªããžããªèšå®âã«ç§»åããŸãã
- æå¹åããããªããžããªãéžæããŸãã
- Enable image analysis ãéžæããŸãã
ãªããžããªã«æ¢ã«ã€ã¡ãŒãžãå«ãŸããŠããå ŽåãDocker Scout ã¯ææ°ã®ã€ã¡ãŒãžãèªåçã«ååŸããŠåæããŸãã
ã¬ãžã¹ããªã€ã¡ãŒãžãåæãã
ã¬ãžã¹ããªå ã®ã€ã¡ãŒãžã®åæãããªã¬ãŒããã«ã¯ãDocker Scout ãšçµ±åãããã¬ãžã¹ããªã«ãã€ã¡ãŒãžåæãæå¹åããããªããžããªã«ã€ã¡ãŒãžãããã·ã¥ããŸãã
Docker Scout ãã©ãããã©ãŒã ã§ã®ã€ã¡ãŒãžåæã«ã¯ãSBOM ã¢ãã¹ããŒã·ã§ã³ããªãå Žåãã€ã¡ãŒãžãã¡ã€ã«ãµã€ãºã®äžéã 10 GB ã§ãã詳现ã¯ã€ã¡ãŒãžã®æ倧ãµã€ãºãåç §ããŠãã ããã
-
docker login
ã³ãã³ããŸã㯠Docker Desktop ã® Sign in ãã¿ã³ã§ Docker ID ã§ãµã€ã³ã€ã³ããŸãã -
åæãããã€ã¡ãŒãžããã«ãããŠããã·ã¥ããŸãã
$ docker build --push --tag <org>/<image:tag> --provenance=true --sbom=true .
--provenance=true
ãš--sbom=true
ãã©ã°ãæå®ããŠãã«ããããšãã€ã¡ãŒãžã«ãã«ãã¢ãã¹ããŒã·ã§ã³âãè¿œå ãããŸããDocker Scout ã¯ã¢ãã¹ããŒã·ã§ã³ã䜿çšããŠãã詳现ãªåæçµæãæäŸããŸããããã©ã«ãã®
docker
ãã©ã€ãã¯ãcontainerd ã€ã¡ãŒãžã¹ãã¢âã䜿çšããå Žåã«ã®ã¿ãã«ãã¢ãã¹ããŒã·ã§ã³ããµããŒãããŸãã -
Docker Scout ããã·ã¥ããŒãã®ã€ã¡ãŒãžããŒãžâã«ç§»åããŸãã
ã€ã¡ãŒãžã¯ã¬ãžã¹ããªã«ããã·ã¥ããŠããéããªããªã¹ãã«è¡šç€ºãããåæçµæã衚瀺ããããŸã§æ°åãããããšããããŸãã
ããŒã«ã«ã§ã€ã¡ãŒãžãåæãã
Docker Scout ã䜿çšã㊠Docker Desktop ãŸã㯠docker scout
ã³ãã³ãã§ããŒã«ã«ã€ã¡ãŒãžãåæã§ããŸãã
Docker Desktop
Docker Desktop ã®ããã¯ã°ã©ãŠã³ãã€ã³ããã¯ã¹äœæã¯æ倧 10 GB ã®ã€ã¡ãŒãžã«å¯Ÿå¿ããŠããŸãã詳现ã¯ã€ã¡ãŒãžã®æ倧ãµã€ãºãåç §ããŠãã ããã
Docker Desktop GUI ã䜿çšããŠããŒã«ã«ã§ã€ã¡ãŒãžãåæããã«ã¯ïŒ
-
åæãããã€ã¡ãŒãžããã«ãŸãã¯ãã«ãããŸãã
-
Docker ããã·ã¥ããŒãã® Images ãã¥ãŒã«ç§»åããŸãã
-
ãªã¹ãããããŒã«ã«ã€ã¡ãŒãžã®ãããããéžæããŸãã
ããã«ãããã€ã¡ãŒãžè©³çŽ°ãã¥ãŒãéããDocker Scout ã®åæã§æ€åºãããããã±ãŒãžãè匱æ§ã®å èš³ã衚瀺ãããŸãã
CLI
docker scout CLI ã³ãã³ãã䜿çšããŠãã¿ãŒããã«ãã Docker Scout ãæäœã§ããŸãã
docker scout quickview
: æå®ããã€ã¡ãŒãžã®æŠèŠã衚瀺ããŸãã詳现ã¯Quickviewãåç §docker scout cves
: æå®ããã€ã¡ãŒãžã®ããŒã«ã«åæãè¡ããŸãã詳现ã¯CVEsãåç §docker scout compare
: 2ã€ã®ã€ã¡ãŒãžãåæããŠæ¯èŒããŸãã
ããã©ã«ãã§ã¯ãçµæã¯æšæºåºåã«è¡šç€ºãããŸãããŸããæ§é å圢åŒã§ãã¡ã€ã«ã«çµæããšã¯ã¹ããŒãããããšãå¯èœã§ãïŒSARIF 圢åŒãªã©ïŒã
Quickview
docker scout quickview
ã³ãã³ãã¯ãæå®ããã€ã¡ãŒãžããã³ãã®ããŒã¹ã€ã¡ãŒãžã§æ€åºãããè匱æ§ã®æŠèŠãæäŸããŸãã
$ docker scout quickview traefik:latest
â SBOM of image already cached, 311 packages indexed
Your image traefik:latest â 0C 2H 8M 1L
Base image alpine:3 â 0C 0H 0M 0L
ããŒã¹ã€ã¡ãŒãžãå€ãå Žåãquickview
ã³ãã³ãã¯ããŒã¹ã€ã¡ãŒãžãæŽæ°ããå Žåã®è匱æ§ã®å€åã衚瀺ããŸãã
$ docker scout quickview postgres:13.1
â Pulled
â Image stored for indexing
â Indexed 187 packages
Your image postgres:13.1 â 17C 32H 35M 33L
Base image debian:buster-slim â 9C 14H 9M 23L
Refreshed base image debian:buster-slim â 0C 1H 6M 29L
â -9 -13 -3 +6
Updated base image debian:stable-slim â 0C 0H 0M 17L
â -9 -14 -9 -6
CVEs
docker scout cves
ã³ãã³ãã¯ãã€ã¡ãŒãžå
ã®ãã¹ãŠã®è匱æ§ã®å®å
šãªãªã¹ããæäŸããŸãããã®ã³ãã³ãã«ã¯ãé倧床ãããã±ãŒãžã¿ã€ããªã©ã§è匱æ§ãçµã蟌ãããã®ãã©ã°ãããã€ããããŸãã
$ docker scout cves --format only-packages --only-vuln-packages \
--only-severity critical postgres:13.1
â SBOM of image already cached, 187 packages indexed
â Detected 10 vulnerable packages with a total of 17 vulnerabilities
Name Version Type Vulnerabilities
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
dpkg 1.19.7 deb 1C 0H 0M 0L
glibc 2.28-10 deb 4C 0H 0M 0L
gnutls28 3.6.7-4+deb10u6 deb 2C 0H 0M 0L
libbsd 0.9.1-2 deb 1C 0H 0M 0L
libksba 1.3.5-2 deb 2C 0H 0M 0L
libtasn1-6 4.13-3 deb 1C 0H 0M 0L
lz4 1.8.3-1 deb 1C 0H 0M 0L
openldap 2.4.47+dfsg-3+deb10u5 deb 1C 0H 0M 0L
openssl 1.1.1d-0+deb10u4 deb 3C 0H 0M 0L
zlib 1:1.2.11.dfsg-1 deb 1C 0H 0M 0L
ãããã®ã³ãã³ããšãã®äœ¿çšæ¹æ³ã«ã€ããŠã®è©³çŽ°ã¯ãCLI ãªãã¡ã¬ã³ã¹ããã¥ã¡ã³ããåç §ããŠãã ããïŒ
è匱æ§ã®é倧床è©äŸ¡
Docker Scout ã¯ãã¢ããã€ã¶ãªãœãŒã¹ã®è匱æ§ããŒã¿ã«åºã¥ããŠè匱æ§ã«é倧床ãå²ãåœãŠãŸããã¢ããã€ã¶ãªã¯ã圱é¿ãåããããã±ãŒãžã®çš®é¡ã«å¿ããŠã©ã³ã¯ä»ãããã³åªå é äœä»ããããŸããããšãã°ãè匱æ§ã OS ããã±ãŒãžã«åœ±é¿ãäžããå Žåããã£ã¹ããªãã¥ãŒã·ã§ã³ã®ã¡ã³ãããŒã«ãã£ãŠå²ãåœãŠãããé倧床ã¬ãã«ãåªå ãããŸãã
åªå
ãããã¢ããã€ã¶ãªãœãŒã¹ã CVE ã«é倧床ãå²ãåœãŠãŠããã CVSS ã¹ã³ã¢ãæäŸããŠããªãå ŽåãDocker Scout ã¯ä»ã®ãœãŒã¹ããã® CVSS ã¹ã³ã¢ã衚瀺ããŸããã¢ããã€ã¶ãªã«ãã£ãŠå²ãåœãŠãããé倧床ãšãä»ã®ã¢ããã€ã¶ãªã«ãã CVSS ã¹ã³ã¢ãäžç·ã«è¡šç€ºããããããé倧床ã LOW
ã§ãããªãã CVSS ã¹ã³ã¢ã 9.8 ã«ãªãå ŽåããããŸãã
ãããã®ãœãŒã¹ã§ã CVSS ã¹ã³ã¢ãå²ãåœãŠãããŠããªãè匱æ§ã¯ãUnspecifiedïŒUïŒã«åé¡ãããŸãã
Docker Scout ã¯ç¬èªã®è匱æ§è©äŸ¡ã·ã¹ãã ãå®è£ ããŠãããããã¹ãŠã®ã¡ããªã¯ã¹ã¯çµ±åãããŠããã»ãã¥ãªãã£ã¢ããã€ã¶ãªããç¶æ¿ããŠããŸããã¢ããã€ã¶ãªã«ãã£ãŠã¯ç°ãªãè匱æ§åé¡åºæºã䜿çšãããŠããŸãããå€ã㯠CVSS v3.0 ä»æ§ã«åŸã£ãŠããã以äžã®è¡šã«ç€ºãããã« CVSS ã¹ã³ã¢ãé倧床ã«ãããã³ã°ããŠããŸãã
CVSS ã¹ã³ã¢ | é倧床 |
---|---|
0.1 - 3.9 | Low (L) |
4.0 - 6.9 | Medium (M) |
7.0 - 8.9 | High (H) |
9.0 - 10.0 | Critical (C) |
詳现ã¯ãè匱æ§ã¡ããªã¯ã¹ (NIST)âãåç §ããŠãã ããã
å è¿°ã®ã¢ããã€ã¶ãªã®åªå é äœä»ããšãã©ãŒã«ããã¯ã¡ã«ããºã ã«ãããDocker Scout ã«è¡šç€ºãããé倧床è©äŸ¡ããã®è©äŸ¡ã·ã¹ãã ãšç°ãªãå ŽåããããŸãã
ã€ã¡ãŒãžã®æ倧ãµã€ãº
Docker Scout ãã©ãããã©ãŒã ã§ã®ã€ã¡ãŒãžåæãããã³ Docker Desktop ã®ããã¯ã°ã©ãŠã³ãã€ã³ããã¯ã¹äœæã«ããåæã«ã¯ãã€ã¡ãŒãžãã¡ã€ã«ãµã€ãºã®äžéã 10 GBïŒå§çž®ãããŠããªãç¶æ ïŒã«èšå®ãããŠããŸãããã以äžã®ãµã€ãºã®ã€ã¡ãŒãžãåæããã«ã¯ã次ã®ããããã®æ¹æ³ãéžæã§ããŸãã
- ãã«ãæã« SBOM ã¢ãã¹ããŒã·ã§ã³âãæ·»ä»ãã
- CLI ã䜿çšããŠããŒã«ã«ã§ã€ã¡ãŒãžãåæãã
CLI ã§ããŒã«ã«åæããã€ã¡ãŒãžããã³ SBOM ã¢ãã¹ããŒã·ã§ã³ãããã€ã¡ãŒãžã«ã¯ããã¡ã€ã«ãµã€ãºã®äžéããããŸããã