Docker Scout ã䜿çšããä¿®æ£
Docker Scout ã®ä¿®æ£æ©èœã¯çŸåšããŒã¿çâã§ãã
Docker Scout ã¯ãããªã·ãŒè©äŸ¡çµæã«åºã¥ããæšå¥šã¢ã¯ã·ã§ã³ãæäŸããããšã§ããµãã©ã€ãã§ãŒã³ãã»ãã¥ãªãã£ã®åé¡ãä¿®æ£ããã®ã«åœ¹ç«ã¡ãŸããæšå¥šã¢ã¯ã·ã§ã³ã¯ãããªã·ãŒæºæ ã®æ¹åããDocker Scout ãããè¯ãè©äŸ¡çµæãæšå¥šã¢ã¯ã·ã§ã³ãæäŸã§ããããã«ããããã®ã¡ã¿ããŒã¿ã®è¿œå ãªã©ãå«ãŸããŸãã
Docker Scout ã¯ä»¥äžã®ããã©ã«ãããªã·ãŒã¿ã€ãã«ã€ããŠä¿®æ£ã¢ããã€ã¹ãæäŸããŸã:
ã«ã¹ã¿ã ããªã·ãŒã«ã¯ã¬ã€ãä»ãã®ä¿®æ£æ©èœã¯ãµããŒããããŠããŸããã
ããªã·ãŒéåã®ããã€ã¡ãŒãžã«ã¯ãæºæ åé¡ã®è§£æ±ºãéåä¿®æ£ã«çŠç¹ãåœãŠãæšå¥šãæ瀺ãããŸããDocker Scout ãæºæ ç¶æ ãå€æã§ããªãã€ã¡ãŒãžã«ã¯ãè©äŸ¡ãæåãããããã«å¿ èŠãªåææ¡ä»¶ãæºããããã®æšå¥šã¢ã¯ã·ã§ã³ã衚瀺ãããŸãã
æšå¥šã¢ã¯ã·ã§ã³ã®è¡šç€º
æšå¥šã¢ã¯ã·ã§ã³ã¯ãDocker Scout ããã·ã¥ããŒãã®ããªã·ãŒè©³çŽ°ããŒãžã«è¡šç€ºãããŸããã¢ã¯ã»ã¹ããã«ã¯ïŒ
- Docker Scout ããã·ã¥ããŒãã®ããªã·ãŒããŒãžâã«ç§»åããŸãã
- ãªã¹ãããããªã·ãŒãéžæããŸãã
ããªã·ãŒè©³çŽ°ããŒãžã§ã¯ãè©äŸ¡çµæãããªã·ãŒã®ç¶æ ã«å¿ããŠä»¥äžã®2ã€ã®ã¿ãã«åããããŠããŸãïŒ
- ViolationsïŒéåïŒ
- Compliance unknownïŒæºæ äžæïŒ
Violations ã¿ãã«ã¯ãéžæããããªã·ãŒã«æºæ ããŠããªãã€ã¡ãŒãžã衚瀺ãããŸããCompliance unknown ã¿ãã«ã¯ãDocker Scout ãæºæ ç¶æ³ãå€æã§ããªãã€ã¡ãŒãžã衚瀺ãããããã«ã¯ããã«æ å ±ãå¿ èŠã§ãã
ã€ã¡ãŒãžã®æšå¥šã¢ã¯ã·ã§ã³ã衚瀺ããã«ã¯ããªã¹ãå ã®ã€ã¡ãŒãžã«ã«ãŒãœã«ãåãããView fixes ãã¿ã³ãã¯ãªãã¯ããŸãã
View fixes ãã¿ã³ãã¯ãªãã¯ãããšãæšå¥šã¢ã¯ã·ã§ã³ã衚瀺ãããä¿®æ£ãµã€ãããã«ãéããŸãã
è€æ°ã®æšå¥šãããå Žåãäž»èŠãªæšå¥šã Recommended fix ãšããŠè¡šç€ºãããè¿œå ã®æšå¥šã Quick fixes ãšããŠãªã¹ããããŸããã¯ã€ãã¯ãã£ãã¯ã¹ã¯äžæçãªè§£æ±ºçãæäŸããããšãäžè¬çã§ãã
ãŸãããµã€ãããã«ã«ã¯å©çšå¯èœãªæšå¥šã«é¢é£ãããã«ãã»ã¯ã·ã§ã³ãå«ãŸããå ŽåããããŸãã
Up-to-Date Base Images ã®ä¿®æ£
Up-to-Date Base Images ããªã·ãŒã¯ã䜿çšããããŒã¹ã€ã¡ãŒãžãææ°ãã©ããã確èªããŸããä¿®æ£ãµã€ãããã«ã«è¡šç€ºãããæšå¥šã¢ã¯ã·ã§ã³ã¯ãDocker Scout ãã€ã¡ãŒãžã«ã€ããŠææ¡ããŠããæ å ±éã«äŸåããŸããå©çšå¯èœãªæ å ±ãå€ãã»ã©ãããé©åãªæšå¥šãæäŸãããŸãã
以äžã¯ãã€ã¡ãŒãžã«é¢ããæ å ±ã«åºã¥ããæšå¥šã¢ã¯ã·ã§ã³ã®ã·ããªãªã§ãã
ããããã³ã¹ã¢ãã¹ããŒã·ã§ã³ããªãå Žå
Docker Scout ããã®ããªã·ãŒãè©äŸ¡ããã«ã¯ãã€ã¡ãŒãžã«ããããã³ã¹ã¢ãã¹ããŒã·ã§ã³âãè¿œå ããå¿ èŠããããŸããã€ã¡ãŒãžã«ããããã³ã¹ã¢ãã¹ããŒã·ã§ã³ããªãå Žåãæºæ ç¶æ³ãå€æã§ããŸããã
ããããã³ã¹ã¢ãã¹ããŒã·ã§ã³ãããå Žå
ããããã³ã¹ã¢ãã¹ããŒã·ã§ã³ãè¿œå ãããŠãããšãDocker Scout ã¯äœ¿çšããŠããããŒã¹ã€ã¡ãŒãžã®ããŒãžã§ã³ãæ£ç¢ºã«æ€åºã§ããŸããã¢ãã¹ããŒã·ã§ã³ã§ç¢ºèªãããããŒãžã§ã³ã¯ã察å¿ããã¿ã°ã®çŸåšã®ããŒãžã§ã³ãšç §åãããææ°ã§ãããã©ãããå€æãããŸãã
ããªã·ãŒéåãããå Žåãæšå¥šã¢ã¯ã·ã§ã³ã¯ããŒã¹ã€ã¡ãŒãžãææ°ããŒãžã§ã³ã«æŽæ°ããç¹å®ã®ãã€ãžã§ã¹ãã«ãã³çãããæ¹æ³ã瀺ããŸãã詳现ã«ã€ããŠã¯ãããŒã¹ã€ã¡ãŒãžã®ããŒãžã§ã³ããã³çãâãåç §ããŠãã ããã
GitHub çµ±åãæå¹ãªå Žå
ã€ã¡ãŒãžã®ãœãŒã¹ã³ãŒãã GitHub ã§ãã¹ãã£ã³ã°ããŠããå ŽåãGitHub çµ±åãæå¹ã«ã§ããŸãããã®çµ±åã«ãããDocker Scout ã¯ããã«äŸ¿å©ãªä¿®æ£ã¢ããã€ã¹ãæäŸããDocker Scout ããã·ã¥ããŒãããçŽæ¥éåã«å¯Ÿããä¿®æ£ãéå§ã§ããŸãã
GitHub çµ±åãæå¹ãªå Žåãä¿®æ£ãµã€ãããã«ããã€ã¡ãŒãžã® GitHub ãªããžããªã«ãã«ãªã¯ãšã¹ããäœæã§ããŸãããã®ãã«ãªã¯ãšã¹ãã¯ãDockerfile å ã®ããŒã¹ã€ã¡ãŒãžããŒãžã§ã³ãææ°ããŒãžã§ã³ã«èªåã§æŽæ°ããŸãã
ãã®èªåä¿®æ£ã§ã¯ãããŒã¹ã€ã¡ãŒãžãç¹å®ã®ãã€ãžã§ã¹ãã«ãã³çãããæ°ããããŒãžã§ã³ãå©çšå¯èœã«ãªããã³ã«ææ°ã®ç¶æ ãç¶æã§ããããã«ããŸããããŒã¹ã€ã¡ãŒãžããã€ãžã§ã¹ãã«ãã³çãããããšã¯åçŸæ§ã®ããã«éèŠã§ããããµãã©ã€ãã§ãŒã³ã«æå³ããªãå€æŽãå ãããªãããã«ããŸãã
ããŒã¹ã€ã¡ãŒãžã®ãã³çãã«ã€ããŠã®è©³çŽ°ã¯ãããŒã¹ã€ã¡ãŒãžã®ããŒãžã§ã³ããã³çãâãåç §ããŠãã ããã
Supply Chain Attestations ã®ä¿®æ£
ããã©ã«ãã® Supply Chain Attestations ããªã·ãŒã¯ãã€ã¡ãŒãžã«å®å šãªããããã³ã¹ãš SBOM ã¢ãã¹ããŒã·ã§ã³ãããããšãèŠæ±ããŸããã¢ãã¹ããŒã·ã§ã³ãæ¬ ããŠããå ŽåããŸãã¯ã¢ãã¹ããŒã·ã§ã³ã«ååãªæ å ±ãå«ãŸããŠããªãå Žåã¯ãããªã·ãŒéåãšèŠãªãããŸãã
ä¿®æ£ãµã€ãããã«ã§æäŸãããæšå¥šã¯ãåé¡è§£æ±ºã®ããã«å¿
èŠãªã¢ã¯ã·ã§ã³ã«ã€ããŠã¬ã€ãããŸããããšãã°ãããããã³ã¹ã¢ãã¹ããŒã·ã§ã³ããããæ
å ±ãäžååãªå Žåãmode=max
ã®ããããã³ã¹ã䜿çšããŠã€ã¡ãŒãžãåãã«ãããããšãæšå¥šãããŸãã詳现ã«ã€ããŠã¯ãmode=max
ãåç
§ããŠãã ããã