ã€ã¡ãŒãžè©³çްãã¥ãŒ
ã€ã¡ãŒãžè©³çްãã¥ãŒã§ã¯ãDocker Scout ã®åæçµæã詳现ã«è¡šç€ºãããŸããDocker Scout ããã·ã¥ããŒããDocker Desktop ã® Images ãã¥ãŒãããã³ Docker Hub ã®ã€ã¡ãŒãžã¿ã°ããŒãžããã€ã¡ãŒãžãã¥ãŒã«ã¢ã¯ã»ã¹ã§ããŸããã€ã¡ãŒãžè©³çްã«ã¯ãã€ã¡ãŒãžã®éå±€æ§é ïŒããŒã¹ã€ã¡ãŒãžïŒãã€ã¡ãŒãžã¬ã€ã€ãŒãããã±ãŒãžãããã³è匱æ§ã®å èš³ã衚瀺ãããŸãã

Docker Desktop ã¯ãŸãã€ã¡ãŒãžãããŒã«ã«ã§åæãããœãããŠã§ã¢éšå衚ïŒSBOMïŒãçæããŸããDocker DesktopãDocker HubãDocker Scout ããã·ã¥ããŒããããã³ CLI ã¯ãã¹ãŠããã® SBOM å ã®ããã±ãŒãž URLïŒPURLïŒãªã³ã¯Â ã䜿çšããŠãDocker Scout ã®ã¢ããã€ã¶ãªããŒã¿ããŒã¹ã§äžèŽããè匱æ§ïŒCVEïŒãç §äŒããŸãã
ã€ã¡ãŒãžéå±€æ§é
調æ»å¯Ÿè±¡ã®ã€ã¡ãŒãžã«ã¯ãImage hierarchy ã«è¡šç€ºããã 1 ã€ä»¥äžã®ããŒã¹ã€ã¡ãŒãžãå«ãŸããå ŽåããããŸããããã¯ãã€ã¡ãŒãžã®äœæè ãã€ã¡ãŒãžã®äœææã«ä»ã®ã€ã¡ãŒãžãåºçºç¹ãšããŠäœ¿çšããããšãæå³ããŸãããããã®ããŒã¹ã€ã¡ãŒãžã¯ãDebianãUbuntuãAlpine ãªã©ã® OS ã€ã¡ãŒãžããPHPãPythonãJava ãªã©ã®ããã°ã©ãã³ã°èšèªã®ã€ã¡ãŒãžã§ããããšãå€ãã§ãã
ãã§ãŒã³å ã®åã€ã¡ãŒãžãéžæãããšãåããŒã¹ã€ã¡ãŒãžã«ç±æ¥ããã¬ã€ã€ãŒã確èªã§ããŸããALL è¡ãéžæãããšããã¹ãŠã®ã¬ã€ã€ãŒãšããŒã¹ã€ã¡ãŒãžãéžæãããŸãã
å©çšå¯èœãªæŽæ°ãããããŒã¹ã€ã¡ãŒãžã«ã¯ãImage hierarchy ã®å³åŽã«æŽæ°ã®éç¥ã衚瀺ãããã»ãã¥ãªãã£ããããªã©ã®è匱æ§ãåé€ããæŽæ°ãå«ãŸããŠããå ŽåããããŸãã
ã¬ã€ã€ãŒ
Docker ã€ã¡ãŒãžã¯ã¬ã€ã€ãŒã§æ§æãããŠããŸããã€ã¡ãŒãžã¬ã€ã€ãŒã¯äžããäžã«ãªã¹ããããæãå€ãã¬ã€ã€ãŒãäžçªäžã«ãææ°ã®ã¬ã€ã€ãŒãäžçªäžã«ãããŸãããªã¹ãã®äžäœã®ã¬ã€ã€ãŒã¯ããŒã¹ã€ã¡ãŒãžããã®ãã®ã§ããããªã¹ãäžäœã®ã¬ã€ã€ãŒã¯ãDockerfile ã®ã³ãã³ãã䜿çšããŠã€ã¡ãŒãžã®äœæè ã远å ãããã®ãå€ãã§ããImage hierarchy ã§ããŒã¹ã€ã¡ãŒãžãéžæãããšããã®ããŒã¹ã€ã¡ãŒãžããã®ã¬ã€ã€ãŒããã€ã©ã€ããããŸãã
åå¥ã®ã¬ã€ã€ãŒãè€æ°ã®ã¬ã€ã€ãŒãéžæãããšãå³åŽã®ããã±ãŒãžããã³è匱æ§ããã£ã«ã¿ãªã³ã°ãããéžæããã¬ã€ã€ãŒã«ãã£ãŠè¿œå ããããã®ã®ã¿ã衚瀺ãããŸãã
è匱æ§
Vulnerabilities ã¿ãã«ã¯ãã€ã¡ãŒãžã§æ€åºãããè匱æ§ããšã¯ã¹ããã€ãã®äžèЧã衚瀺ãããŸãããªã¹ãã¯ããã±ãŒãžããšã«ã°ã«ãŒãåãããé倧床é ã«ãœãŒããããŠããŸãã
ãªã¹ãã¢ã€ãã ãå±éãããšãè匱æ§ããšã¯ã¹ããã€ãã«é¢ãã詳现æ å ±ããä¿®æ£ãå©çšå¯èœãã©ããã確èªã§ããŸãã
ä¿®æ£æšå¥šäºé
Docker Desktop ãŸã㯠Docker Hub ã§ã€ã¡ãŒãžã調æ»ãããšãDocker Scout ãããã®ã€ã¡ãŒãžã®ã»ãã¥ãªãã£æ¹åã«é¢ããæšå¥šäºé ãæäŸãããŸãã
Docker Desktop ã§ã®æšå¥šäºé
Docker Desktop ã§ã€ã¡ãŒãžã®ã»ãã¥ãªãã£æšå¥šäºé ã衚瀺ããæé ïŒ
- Docker Desktop ã® Images ãã¥ãŒã«ç§»åããŸãã
- æšå¥šäºé ã衚瀺ãããã€ã¡ãŒãžã¿ã°ãéžæããŸãã
- äžéšã«ãã Recommended fixes ããããããŠã³ãã¿ã³ãéžæããŸãã
ããããããŠã³ã¡ãã¥ãŒã§ã¯ãçŸåšã®ã€ã¡ãŒãžãããããæ§ç¯ããéã«äœ¿çšãããããŒã¹ã€ã¡ãŒãžã«å¯Ÿããæšå¥šäºé ã衚瀺ãããéžæã§ããŸãïŒ
- Recommendations for this image ã¯ãçŸåšèª¿æ»ããŠããã€ã¡ãŒãžã«å¯Ÿããæšå¥šäºé ãæäŸããŸãã
- Recommendations for base image ã¯ãã€ã¡ãŒãžã®æ§ç¯ã«äœ¿çšãããããŒã¹ã€ã¡ãŒãžã«å¯Ÿããæšå¥šäºé ãæäŸããŸãã
調æ»ããŠããã€ã¡ãŒãžã«é¢é£ããããŒã¹ã€ã¡ãŒãžããªãå ŽåãããããããŠã³ã¡ãã¥ãŒã«ã¯çŸåšã®ã€ã¡ãŒãžã«å¯Ÿããæšå¥šäºé ã®ã¿ã衚瀺ãããŸãã
Docker Hub ã§ã®æšå¥šäºé
Docker Hub ã§ã€ã¡ãŒãžã®ã»ãã¥ãªãã£æšå¥šäºé ã衚瀺ããæé ïŒ
- Docker Scout ã€ã¡ãŒãžåæãæå¹ã«ããã€ã¡ãŒãžã®ãªããžããªããŒãžã«ç§»åããŸãã
- Tags ã¿ããéããŸãã
- æšå¥šäºé ã衚瀺ãããã¿ã°ãéžæããŸãã
- View recommended base image fixes ãã¿ã³ãéžæããŸãã
çŸåšã®ã€ã¡ãŒãžã«å¯Ÿããæšå¥šäºé
çŸåšã®ã€ã¡ãŒãžãã¥ãŒã«å¯Ÿããæšå¥šäºé ã¯ã䜿çšããŠããã€ã¡ãŒãžããŒãžã§ã³ãææ°ãã©ããã倿ããã®ã«åœ¹ç«ã¡ãŸãã䜿çšããŠããã¿ã°ãå€ããã€ãžã§ã¹ããåç §ããŠããå Žåãææ°ããŒãžã§ã³ã®ååŸãæšå¥šããã¡ãã»ãŒãžã衚瀺ãããŸãã
Pull new image ãã¿ã³ãéžæããŠææ°ããŒãžã§ã³ãååŸããŸãããã§ãã¯ããã¯ã¹ããªã³ã«ãããšãææ°ããŒãžã§ã³ããã«ããåŸã«å€ãããŒãžã§ã³ãåé€ãããŸãã
ããŒã¹ã€ã¡ãŒãžã«å¯Ÿããæšå¥šäºé
ããŒã¹ã€ã¡ãŒãžã«å¯Ÿããæšå¥šãã¥ãŒã«ã¯ãæšå¥šäºé ã®ç°ãªãçš®é¡ãåãæ¿ããããã® 2 ã€ã®ã¿ãããããŸãïŒ
- Refresh base image
- Change base image
ãããã®ããŒã¹ã€ã¡ãŒãžã«é¢ããæšå¥šã¯ã調æ»å¯Ÿè±¡ã®ã€ã¡ãŒãžã®äœæè ã®ã¿ãå®è¡å¯èœã§ããã€ã¡ãŒãžã®ããŒã¹ã€ã¡ãŒãžã倿Žããã«ã¯ãDockerfile ã®æŽæ°ãšã€ã¡ãŒãžã®åãã«ããå¿ èŠã«ãªãããã§ãã
ããŒã¹ã€ã¡ãŒãžã®æŽæ°
ãã®ã¿ãã«ã¯ãéžæããããŒã¹ã€ã¡ãŒãžã¿ã°ãææ°ããŒãžã§ã³ããå€ãããŒãžã§ã³ãã衚瀺ãããŸãã
çŸåšã®ã€ã¡ãŒãžã®ãã«ãã«äœ¿çšãããŠããããŒã¹ã€ã¡ãŒãžã¿ã°ãææ°ã§ãªãå Žåããã®ãŠã£ã³ããŠã«ããŒãžã§ã³ã®å·®åã衚瀺ãããŸããå·®åæ å ±ã«ã¯æ¬¡ã®å 容ãå«ãŸããŸãïŒ
- æšå¥šãããïŒæ°ããïŒããŒãžã§ã³ã®ã¿ã°åãšãšã€ãªã¢ã¹
- çŸåšã®ããŒã¹ã€ã¡ãŒãžããŒãžã§ã³ã®çµéæ¥æ°
- å©çšå¯èœãªææ°ããŒãžã§ã³ã®çµéæ¥æ°
- åããŒãžã§ã³ã«åœ±é¿ãäžãã CVE ã®æ°
ãŠã£ã³ããŠã®äžéšã«ã¯ãææ°ããŒãžã§ã³ã䜿çšããŠã€ã¡ãŒãžãåãã«ãããããã®ã³ãã³ãã¹ããããã衚瀺ãããŸãã
ããŒã¹ã€ã¡ãŒãžã®å€æŽ
ãã®ã¿ãã«ã¯äœ¿çšå¯èœãªå¥ã®ã¿ã°ã衚瀺ãããåã¿ã°ããŒãžã§ã³ã®å©ç¹ã𿬠ç¹ã瀺ãããŸããããŒã¹ã€ã¡ãŒãžãéžæãããšããã®ã¿ã°ã«å¯Ÿããæšå¥šãªãã·ã§ã³ã衚瀺ãããŸãã
ããšãã°ã調æ»ããŠããã€ã¡ãŒãžãå€ãããŒãžã§ã³ã® debian ãããŒã¹ã€ã¡ãŒãžãšããŠäœ¿çšããŠããå Žåãããæ°ããã»ãã¥ã¢ãª debian ããŒãžã§ã³ã®äœ¿çšãæšå¥šãããŸããè€æ°ã®éžæè¢ãæäŸããããšã§ãåãªãã·ã§ã³ãæ¯èŒããã©ãã䜿çšããããæ±ºå®ã§ããŸãã

ã¿ã°æšå¥šãéžæãããšãæšå¥šäºé ã®è©³çްã衚瀺ãããŸããã¿ã°ã®å©ç¹ãšæœåšçãªæ¬ ç¹ãæšå¥šçç±ãããã³ Dockerfile ããã®ããŒãžã§ã³ã«æŽæ°ããæ¹æ³ã瀺ãããŸãã