Docker scout is misreading base image version number
@mikeparker がすでに取り組んでいます。
2024年1月10日 から。
評価
この issue はまだ評価されていません。
説明
I just started looking into docker scout and ran it over one of my Golang based images and found an issue that could be blocking if run in a CI/CD pipeline.
it can be reproduced with this dockerfile
FROM golang:1.21-alpine
WORKDIR /app
RUN echo foo > bar.txt
ENTRYPOINT [ "sh", "cat", "/app/bar.txt" ]
As of today (2024-01-09) 1.21-alpine is the latest tag, this is important.
Then use the following command to build an image:
docker build --pull --force-rm -t test_scout:latest .
And finally run docker scout to check for any vulnerability with its various options:
First, out of precaution, clear docker scout's cache with docker scout cache prune --sboms
$ docker scout cache prune --sboms
? Are you sure you want to delete all temporary data and all cached SBOMs? Yes
✓ Temporary data deleted
✓ Cached SBOMs deleted
Then docker scout quickview test_scout:latest gives:
$ docker scout quickview test_scout:latest
✓ Image stored for indexing
✓ Indexed 41 packages
Target │ test_scout:latest │ 0C 0H 0M 0L
digest │ ae018a575642 │
Base image │ golang:1-alpine │ 0C 0H 0M 0L
Updated base image │ golang:1.20-alpine │ 0C 0H 0M 0L
│ │
What's Next?
View base image update recommendations → docker scout recommendations test_scout:latest
Include policy results in your quickview by supplying an organization → docker scout quickview test_scout:latest --org <organization>
And docker scout recommendations test_scout:latest gives:
$ docker scout recommendations test_scout:latest
✓ SBOM of image already cached, 41 packages indexed
Target │ test_scout:latest
digest │ ae018a575642
## Recommended fixes
Base image is golang:1-alpine
Name │ 1-alpine
Digest │ sha256:c56d095992c4857b6cf532808dc847d50d24fe0fc7be1cdc0beacc7ad3da9f1b
Vulnerabilities │ 0C 0H 0M 0L
Pushed │ 2 weeks ago
Size │ 68 MB
Packages │ 41
Flavor │ alpine
OS │ 3.19
│ The base image is also available under the supported tag(s) 1-alpine3.19 , 1.21-alpine , 1.21-alpine3.19 , 1.21.5-alpine , 1.21.5-alpine3.19 , alpine , alpine3.19
.
│ If you want to display recommendations specifically for a different tag, please re-run the command using the --tag flag.
Refresh base image
Rebuild the image using a newer base image version. Updating this may result in breaking changes.
✓ This image version is up to date.
Change base image
The list displays new recommended tags in descending order, where the top results are rated as most suitable.
Tag │ Details │ Pushed │ Vulnerabilities
───────────────────────────────┼──────────────────────────────────────────────────────────────────────┼─────────────┼──────────────────────────────
1.20-alpine │ Benefits: │ 1 month ago │ 0C 0H 0M 0L
Minor runtime version update │ • Same OS detected │ │
Also known as: │ • Minor runtime version update │ │
• 1.20.12-alpine │ • Image has same number of vulnerabilities │ │
• 1.20.12-alpine3.19 │ • Image contains similar number of packages │ │
• 1.20-alpine3.19 │ • 1.20-alpine is the third most popular tag with 11K pulls per month │ │
│ │ │
│ Image details: │ │
│ • Size: 100 MB │ │
│ • Flavor: alpine │ │
│ • OS: 3.19 │ │
│ • Runtime: 1.20.12 │ │
│ │ │
│ │ │
│ │ │
From what I read here (or maybe I misinterpreting the result), docker scout seems to suggest I should 'change' my base image to 1.20-alpine which is older than the 1.21-alpine I use. To me this could create false positives in CI/CD contexts and exceptions to document when we are dealing with customers requesting image audits.
- 主要言語
- Shell
- スター
- 454
- フォーク
- 134
- PR マージ指標
- 30日以内にマージされた PR はありません
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
docker/scout-cli のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
-
allstar
難易度 2/5 1〜3時間 初心者へのやさしさ 45/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
-
panic: nil deref in createVCS() scanning multi-arch image by tag when no attestation sidecar exists オープン
難易度 4/5 3〜5日 初心者へのやさしさ 64/100
docker/scout-cli の issue をすべて見る
似ている issue
-
Bob Shell support オープンenhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
-
tooling
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
openSUSE/python-rpm-macros#219 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
YunoHost-Apps/adguardhome_ynh#258 ·
-
steam-short-session-tracker: incorrect registry backup path resets settings during automatic repair オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 80/100
ValveSoftware/SteamOS#2829 ·