è匱æ§äŸå€ã®ç®¡ç
ã³ã³ããã€ã¡ãŒãžã§èŠã€ãã£ãè匱æ§ã«ã¯ãè¿œå ã®ã³ã³ããã¹ããå¿ èŠãªå ŽåããããŸããã€ã¡ãŒãžã«è匱ãªããã±ãŒãžãå«ãŸããŠããŠããå¿ ããããã®è匱æ§ãæªçšå¯èœã§ãããšã¯éããŸãããDocker Scout ã® äŸå€ æ©èœã䜿ããšãã€ã¡ãŒãžåæã«ãããŠåãå ¥ãå¯èœãªãªã¹ã¯ãèªèãããã誀æ€åºãä¿®æ£ãããããããšãã§ããŸãã
é©çšãããªãè匱æ§ãç¡å¹åããããšã§ãã€ã¡ãŒãžã«ãããè匱æ§ã®ã»ãã¥ãªãã£ãžã®åœ±é¿ããå©çšè ãããŠã³ã¹ããªãŒã ã®ãŠãŒã¶ãŒãããç解ãããããªããŸãã
Docker Scout ã§ã¯ãäŸå€ãåæçµæã«èªåçã«åæ ãããŸãããã CVE ãé©çšå€ãšããŠãã©ã°ãç«ãŠãäŸå€ãèšå®ãããŠããå Žåããã® CVE ã¯åæçµæããé€å€ãããŸãã
äŸå€ãäœæãã
ã€ã¡ãŒãžã«äŸå€ãèšå®ããæ¹æ³ã¯ä»¥äžã®éãã§ãïŒ
- Docker Scout ããã·ã¥ããŒãã Docker Desktop ã®GUI ã䜿çšããã
- VEXããã¥ã¡ã³ããäœæãããããã€ã¡ãŒãžã«æ·»ä»ããã
äŸå€ãäœæããæšå¥šæ¹æ³ã¯ Docker Scout ããã·ã¥ããŒãã Docker Desktop ã® GUI ã䜿çšããããšã§ããGUI ã¯äœ¿ããããã€ã³ã¿ãŒãã§ãŒã¹ãæäŸããè€æ°ã®ã€ã¡ãŒãžãçµç¹å šäœã«äžåºŠã«äŸå€ãé©çšããããšãå¯èœã§ãã
äŸå€ã衚瀺ãã
ã€ã¡ãŒãžã®äŸå€ã衚瀺ããã«ã¯ãé©åãªæš©éãå¿ èŠã§ãã
- GUI ã䜿çšããŠäœæãããäŸå€ã¯ãDocker Organizationã®ã¡ã³ããŒã«è¡šç€ºãããŸããèªèšŒãããŠããªããŠãŒã¶ãŒã Organization ã®ã¡ã³ããŒã§ãªããŠãŒã¶ãŒã«ã¯è¡šç€ºãããŸããã
- VEX ããã¥ã¡ã³ãã䜿çšããŠäœæãããäŸå€ã¯ãã€ã¡ãŒãžããã«ã§ãããŠãŒã¶ãŒãªã誰ã§ã確èªã§ããŸãããã㯠VEX ããã¥ã¡ã³ããã€ã¡ãŒãžã®ãããã§ã¹ãããã¡ã€ã«ã·ã¹ãã ã«æ ŒçŽãããŠããããã§ãã
Docker Scout ããã·ã¥ããŒãã Docker Desktop ã§äŸå€ã衚瀺ãã
Docker Scout ããã·ã¥ããŒãã® Exceptions ã¿ãã§ã¯ãOrganization å ã®ãã¹ãŠã®ã€ã¡ãŒãžã«å¯ŸããäŸå€ãäžèŠ§è¡šç€ºãããŸãããããããåäŸå€ã®è©³çŽ°ãæå¶ãããŠãã CVEãäŸå€ãé©çšãããŠããã€ã¡ãŒãžãäŸå€ã®çš®é¡ãäœææ¹æ³ãªã©ã®æ å ±ã確èªã§ããŸãã
GUI ã䜿çšããŠäœæãããäŸå€ã®å Žåãã¢ã¯ã·ã§ã³ã¡ãã¥ãŒããäŸå€ãç·šéãŸãã¯åé€ã§ããŸãã
ç¹å®ã®ã€ã¡ãŒãžã¿ã°ã«å¯Ÿãããã¹ãŠã®äŸå€ã衚瀺ããã«ã¯ïŒ
Docker Scout ããã·ã¥ããŒã
- ã€ã¡ãŒãžããŒãžâã«ç§»åããŸãã
- 調æ»ãããã¿ã°ãéžæããŸãã
- Exceptions ã¿ããéããŸãã
CLI ã§äŸå€ã衚瀺ãã
CLI ã§ã®äŸå€è¡šç€ºã¯å®éšçãªæ©èœã§ããææ°ããŒãžã§ã³ã® Docker Scout CLI ãã©ã°ã€ã³ãå¿ èŠã§ããäžéšã®äŸå€ã¯æ£ãã衚瀺ãããªãå¯èœæ§ããããŸãã
docker scout cves <image>
ã³ãã³ããå®è¡ãããšãCLI ã«äŸå€ããã€ã©ã€ã衚瀺ãããŸããäŸå€ã§æå¶ããã CVE ã«ã¯ãCVE ID ã®æšªã« SUPPRESSED
ã©ãã«ã衚瀺ãããäŸå€ã®è©³çŽ°ã衚瀺ãããŸãã
CLI ã§äŸå€ã衚瀺ããã«ã¯ãäŸå€ãäœæãã Docker Organization ãšåã Organization ã CLI ã«èšå®ããå¿ èŠããããŸãã
CLI ã« Organization ãèšå®ããã«ã¯ã次ã®ã³ãã³ããå®è¡ããŸã:
$ docker scout configure organization <organization>
<organization>
ã Docker Organization ã®ååã«çœ®ãæããŠãã ããã
ãŸããâorg ãã©ã°ã䜿çšããŠãã³ãã³ãããšã« Organizationãæå®ããããšãã§ããŸã:
$ docker scout cves --org <organization> <image>
æå¶ããã CVE ãåºåããé€å€ããã«ã¯ã--ignore-suppressed
ãã©ã°ã䜿çšããŸã:
$ docker scout cves --ignore-suppressed <image>