Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Docker scout is misreading base image version number

オープン
#84 コメント 2 件 リアクション 0 件 担当者 1 名 GitHub で見る

@mikeparker がすでに取り組んでいます。

2024年1月10日 から。

評価

この issue はまだ評価されていません。

説明

I just started looking into docker scout and ran it over one of my Golang based images and found an issue that could be blocking if run in a CI/CD pipeline.

it can be reproduced with this dockerfile

FROM golang:1.21-alpine
WORKDIR /app
RUN echo foo > bar.txt
ENTRYPOINT [ "sh", "cat", "/app/bar.txt" ]

As of today (2024-01-09) 1.21-alpine is the latest tag, this is important.

Then use the following command to build an image:

docker build --pull --force-rm -t test_scout:latest .

And finally run docker scout to check for any vulnerability with its various options:
First, out of precaution, clear docker scout's cache with docker scout cache prune --sboms

$ docker scout cache prune --sboms        
? Are you sure you want to delete all temporary data and all cached SBOMs? Yes
    ✓ Temporary data deleted
    ✓ Cached SBOMs deleted

Then docker scout quickview test_scout:latest gives:

$ docker scout quickview test_scout:latest
    ✓ Image stored for indexing
    ✓ Indexed 41 packages

  Target             │  test_scout:latest   │    0C     0H     0M     0L   
    digest           │  ae018a575642        │                              
  Base image         │  golang:1-alpine     │    0C     0H     0M     0L   
  Updated base image │  golang:1.20-alpine  │    0C     0H     0M     0L   
                     │                      │                              

What's Next?
  View base image update recommendations → docker scout recommendations test_scout:latest
  Include policy results in your quickview by supplying an organization → docker scout quickview test_scout:latest --org <organization>

And docker scout recommendations test_scout:latest gives:

$ docker scout recommendations test_scout:latest
    ✓ SBOM of image already cached, 41 packages indexed

  Target   │  test_scout:latest   
    digest │  ae018a575642        

## Recommended fixes

  Base image is  golang:1-alpine 

  Name            │  1-alpine                                                                  
  Digest          │  sha256:c56d095992c4857b6cf532808dc847d50d24fe0fc7be1cdc0beacc7ad3da9f1b   
  Vulnerabilities │    0C     0H     0M     0L                                                 
  Pushed          │ 2 weeks ago                                                                
  Size            │ 68 MB                                                                      
  Packages        │ 41                                                                         
  Flavor          │ alpine                                                                     
  OS              │ 3.19                                                                       

                                                                                                                                                                         
  │ The base image is also available under the supported tag(s)  1-alpine3.19 ,  1.21-alpine ,  1.21-alpine3.19 ,  1.21.5-alpine ,  1.21.5-alpine3.19 ,  alpine ,  alpine3.19
  .                                                                                                                                                                      
  │ If you want to display recommendations specifically for a different tag, please re-run the command using the  --tag  flag.                                            



Refresh base image
  Rebuild the image using a newer base image version. Updating this may result in breaking changes.

  ✓ This image version is up to date.


Change base image
  The list displays new recommended tags in descending order, where the top results are rated as most suitable.


              Tag              │                               Details                                │   Pushed    │       Vulnerabilities        
───────────────────────────────┼──────────────────────────────────────────────────────────────────────┼─────────────┼──────────────────────────────
   1.20-alpine                 │ Benefits:                                                            │ 1 month ago │    0C     0H     0M     0L   
  Minor runtime version update │ • Same OS detected                                                   │             │                              
  Also known as:               │ • Minor runtime version update                                       │             │                              
  • 1.20.12-alpine             │ • Image has same number of vulnerabilities                           │             │                              
  • 1.20.12-alpine3.19         │ • Image contains similar number of packages                          │             │                              
  • 1.20-alpine3.19            │ • 1.20-alpine is the third most popular tag with 11K pulls per month │             │                              
                               │                                                                      │             │                              
                               │ Image details:                                                       │             │                              
                               │ • Size: 100 MB                                                       │             │                              
                               │ • Flavor: alpine                                                     │             │                              
                               │ • OS: 3.19                                                           │             │                              
                               │ • Runtime: 1.20.12                                                   │             │                              
                               │                                                                      │             │                              
                               │                                                                      │             │                              
                               │                                                                      │             │                                                    

From what I read here (or maybe I misinterpreting the result), docker scout seems to suggest I should 'change' my base image to 1.20-alpine which is older than the 1.21-alpine I use. To me this could create false positives in CI/CD contexts and exceptions to document when we are dealing with customers requesting image audits.

主要言語
Shell
スター
454
フォーク
134
PR マージ指標
30日以内にマージされた PR はありません

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

docker/scout-cli のほかの issue

docker/scout-cli の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。