junicast · @junicast
23 followers · 287 posts · Server noc.social

People who maintain images in (public) registries should consider using a vulnerability scanner like

I just scanned some of the containers I get from registries and the situation seems VERY bad.

#security #trivy #container

Last updated 1 year ago

devguy :verified: · @developerguy
365 followers · 564 posts · Server hachyderm.io

💊Every treatment starts with accepting the diagnosis! Embrace the truth☝️
"You can be the next victim of the Software Supply Chain Attacks" UNLESS...
✍️Sign your software ()
🔔Do vulnerability scanning ( )
🚨 Protection at runtime ( )

#Cosign #trivy #grype #kyverno #policycontroller

Last updated 1 year ago

radiotux · @radiotux
107 followers · 87 posts · Server jit.social

Das folgende richtet sich an alle, die mehr für ihre suchen. Mit kann man sich auf die Suche nach in seinem begeben. Praktisch ist es, Repositorys auf solche Probleme scannen zu können um Sicherheitsprobleme bei verwendeter Software zu entdecken.

aquasecurity.github.io/trivy/v

#security #toolsday #git #code #sicherheitsproblemen #trivy #software #sicherheit #tool

Last updated 1 year ago

ToddySM · @toddysm
7 followers · 16 posts · Server twit.social

It was a full room today at our talk with @itaysk about vulnerability management with and at ! Thanks to all who joined us!

#trivy #oci #kubecon2023 #kubeconeu

Last updated 2 years ago

Arthur Lutz (Zenika) · @arthurzenika
366 followers · 558 posts · Server pouet.chapril.org

The demo was a bit too fast, I'll have to dig into the code github.com/itaysk/kubeconeu23-

#trivy #regctl #oci #kubeconeu #kubecon

Last updated 2 years ago

Arthur Lutz (Zenika) · @arthurzenika
366 followers · 557 posts · Server pouet.chapril.org

🔏 📦 "Improve Vulnerability Management with OCI Artifacts - It's That Easy !" by Aqua Security & Azure Containers

#devsecops #notary #helm #docker #oci #SBOM #trivy #security #kubeconeu #kubecon

Last updated 2 years ago

Max Jonas Werner · @makkes
120 followers · 243 posts · Server hachyderm.io
Dennis Irsigler · @dirsigler
151 followers · 367 posts · Server infosec.exchange

I saw now several talks about companies using to restrict deployments made to production.
They only allow deployments where or other scanners report a certain low amount of vulnerabilities. Also are checked for existence. Sometimes even more restrictions apply.

How do these companies handle then third party images needed ? For example some official Python images?
Having some kind of automatic mirror of requested applications to fetch them and build the needed things on their own systems ?
Just blocking and tell them “yeah please wait few days until we work on that ticket”

It seems I am confusing or missing something…

#Kyverno #trivy #SBOMs #docker

Last updated 2 years ago

Comfortably Numb · @ygalanter
1637 followers · 166 posts · Server hachyderm.io

Anybody knows how to write a Trivy exception in Rego to suppress a specific CloudFormation rule for a specific resource? Kinda new at this.

#trivy #cloudformation #Rego

Last updated 2 years ago

Andy Tinkham · @andytinkham
184 followers · 18 posts · Server infosec.exchange

Trivy users: if you’re suddenly seeing trivy timeout when scanning your containers, you’re probably scanning some Java files. Search.maven.org is returning intermittent 504 errors which leads to trivy timeouts. Fix is to include the —offline-scans option in your trivy call. This will still download the trivy db but not go out to maven for Java files.

(In our case, I didn’t even think we were scanning Java but a Ruby gem had a jar file deep in its instant folder that trivy was scanning.)

#appsec #trivy #java

Last updated 2 years ago

prabhu · @prabhu
7 followers · 7 posts · Server infosec.exchange

Early Black Friday deal: ( Generator) 5.0.1 is out now with support for:
✅ docker/OCI images with OS packages (Powered by )
✅ Rust binary (Powered by Cargo Auditable)

github.com/AppThreat/cdxgen

#cdxgen #cyclonedx #SBOM #trivy

Last updated 2 years ago

devguy :verified: · @developerguy
139 followers · 130 posts · Server hachyderm.io

Let's learn more about how we can combine these two excellent projects @AquaSecTeam's and @projectsigstore tools, to generate and sign 👇 Thanks to @itaysk for sharing such great details with us 🥳

≫ 📸 youtu.be/i_9bV08CTao
≫ 🧵 twitter.com/itaysk/status/1588

#trivy #SBOMs

Last updated 2 years ago

Monica Colangelo · @monica
76 followers · 101 posts · Server hachyderm.io

This morning starts with the same problem I had yesterday. A really weird error on trying to integrate with . According to the documentation it should be very simple -- and it is, except for this permissions error that is misleading, since I apparently have all possible permissions.
BTW — Is it weird that I feel happier when I spend time fixing technical problems instead of doing things that work first time? 😅

#aws #trivy #SecurityHub #iam

Last updated 2 years ago

Josh Long · @starbuxman
1577 followers · 221 posts · Server mastodon.online

RT @techadvoguy
For those interested in @VMwareTanzu Application Platform (TAP), and custom integration capabilities around image & source code scanners, this is a must-read from the @VRAbbi_IL blog on how one could do this with as an example:
vrabbi.cloud/post/integrating-

#trivy

Last updated 2 years ago

wget :verified: · @wget
770 followers · 1486 posts · Server framapiaf.org

RT @djerfy@twitter.com

Elasticsearch 8.5.0 est sortie hier, mais cependant restez attentifs. CVE-2020-9488 (log4j-core) + CVE-2021-45105 (log4j-api), et non présent sur la précédente version (8.4.3). Scan 👍

🐦🔗: twitter.com/djerfy/status/1587

#trivy

Last updated 2 years ago