Docker Scout ã®ããªã·ãŒç¶æ ã確èªãã
ã¢ãŒãã£ãã¡ã¯ãã®ããªã·ãŒç¶æ ãDocker Scout ããã·ã¥ããŒããŸãã¯CLIã䜿çšããŠç¢ºèªã§ããŸãã
ããã·ã¥ããŒã
Docker Scout ããã·ã¥ããŒãâã® Overview ã¿ãã«ã¯ããªããžããªã®ããªã·ãŒã®æè¿ã®å€æŽãèŠçŽè¡šç€ºãããŸãããã®èŠçŽã«ã¯ãææ°ã®ã€ã¡ãŒãžãšãã®åã®ã€ã¡ãŒãžã®éã§ããªã·ãŒè©äŸ¡ãæãå€åããã€ã¡ãŒãžã衚瀺ãããŸãã
ãªããžããªããšã®ããªã·ãŒç¶æ
Images ã¿ãã§ã¯ãéžæããç°å¢å ã®ãã¹ãŠã®ã€ã¡ãŒãžã«ã€ããŠãçŸåšã®ããªã·ãŒç¶æ ãšæè¿ã®ããªã·ãŒãã¬ã³ãã衚瀺ãããŸãããªã¹ãå ã® Policy status åã«ã¯æ¬¡ã®æ å ±ã瀺ãããŸãïŒ
- æºããããããªã·ãŒã®æ°ãšç·ããªã·ãŒæ°
- æè¿ã®ããªã·ãŒãã¬ã³ã
ããªã·ãŒãã¬ã³ãã¯ãåãç°å¢å ã®åã®ã€ã¡ãŒãžãšæ¯èŒããŠãããªã·ãŒãè¯ããªã£ãããæªåãããããŸãã¯å€åããªããã瀺ããŸãã
- ç·ã®äžåãç¢å°ã¯ãææ°ã®ããã·ã¥ã€ã¡ãŒãžã§æ¹åããããªã·ãŒæ°ã瀺ããŸãã
- èµ€ã®äžåãç¢å°ã¯ãææ°ã®ããã·ã¥ã€ã¡ãŒãžã§æªåããããªã·ãŒæ°ã瀺ããŸãã
- åæ¹åã®ç°è²ã®ç¢å°ã¯ãææ°ããŒãžã§ã³ã®ã€ã¡ãŒãžã§å€æŽããªãã£ãããªã·ãŒæ°ã瀺ããŸãã
ãªããžããªãéžæãããšãPolicy ã¿ãã§ãææ°ã®åææžã¿ã€ã¡ãŒãžãšãã®åã®ã€ã¡ãŒãžã®ããªã·ãŒå·®åã«ã€ããŠè©³çŽ°ãªèª¬æã衚瀺ãããŸãã
詳现ãªçµæãšä¿®æ£
ã€ã¡ãŒãžã®å®å šãªè©äŸ¡çµæã衚瀺ããã«ã¯ãDocker Scout ããã·ã¥ããŒãã®ã€ã¡ãŒãžã¿ã°ã«ç§»åã㊠Policy ã¿ããéããŸããããã«ãããçŸåšã®ã€ã¡ãŒãžã®ãã¹ãŠã®ããªã·ãŒéåã詳现ã«è¡šç€ºãããŸãã
ãã®ãã¥ãŒã§ã¯ãéåããããªã·ãŒã®æ¹åæ¹æ³ã«ã€ããŠã®æšå¥šã¢ã¯ã·ã§ã³ãæäŸãããŸãã
è匱æ§é¢é£ã®ããªã·ãŒã§ã¯ãä¿®æ£ããŒãžã§ã³ãå©çšå¯èœãªå Žåããã®ããŒãžã§ã³ã衚瀺ãããããã±ãŒãžããŒãžã§ã³ãä¿®æ£ããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãããããšã§åé¡ã解決ã§ããŸãã
ã©ã€ã»ã³ã¹é¢é£ã®ããªã·ãŒã§ã¯ãããªã·ãŒåºæºãæºãããªãã©ã€ã»ã³ã¹ãæã€ãã¹ãŠã®ããã±ãŒãžããªã¹ããããŸããåé¡ã解決ããããã«ãã©ã€ã»ã³ã¹éåã®ããã±ãŒãžã®äŸåé¢ä¿ãåé€ããæ¹æ³ãæ€èšããŸããããšãã°ãããé©åãªã©ã€ã»ã³ã¹ã§é åžãããŠãã代æ¿ããã±ãŒãžãæ¢ããŸãã
CLI
CLI ããã€ã¡ãŒãžã®ããªã·ãŒç¶æ
ã確èªããã«ã¯ãdocker scout policy
ã³ãã³ãã䜿çšããŸãã
$ docker scout policy \
--org dockerscoutpolicy \
--platform linux/amd64 \
dockerscoutpolicy/email-api-service:0.0.2
â Pulled
â Policy evaluation results found
## Overview
â Analyzed Image
âââââââââââââââŒââââââââââââââââââââââââââââââââââââââââââââââ
Target â dockerscoutpolicy/email-api-service:0.0.2
digest â 17b1fde0329c
platform â linux/amd64
## Policies
Policy status FAILED (2/8 policies met, 3 missing data)
Status â Policy â Results
âââââââââââŒââââââââââââââââââââââââââââââââââââââââââââââââââââââŒââââââââââââââââââââââââââââââ
â â No copyleft licenses â 0 packages
! â Default non-root user â
! â No fixable critical or high vulnerabilities â 2C 1H 0M 0L
â â No high-profile vulnerabilities â 0C 0H 0M 0L
? â No outdated base images â No data
â â Learn more â
? â SonarQube quality gates passed â No data
â â Learn more â
! â Supply chain attestations â 2 deviations
? â No unapproved base images â No data
...
ã³ãã³ãã®è©³çŽ°ã«ã€ããŠã¯ãCLI ãªãã¡ã¬ã³ã¹âãåç §ããŠãã ããã