Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Container Security with Trivy
Search
Masahiro331
June 11, 2022
Technology
250
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Container Security with Trivy
Masahiro331
June 11, 2022
More Decks by Masahiro331
See All by Masahiro331
Model Context Protocol 勉強会
masahiro331
0
98
OSSに新機能を追加するまでの苦労話
masahiro331
0
240
Analyze Filesystem in Virtual Machine Image
masahiro331
0
230
SBOMを利用したソフトウェアサプライチェーンの保護
masahiro331
4
2.8k
Introduction Supply Chain Security
masahiro331
0
190
VirtualMachine Image scanning PoC with Molysis
masahiro331
0
200
Other Decks in Technology
See All in Technology
就職⽀援サービスにおけるキャリアアドバイザーのシフトスケジューリング
recruitengineers
PRO
1
140
「速く作る」から「正しく作る」へ ─ 生成AI時代の開発フロー改革の ロードマップと実行 ─
starfish719
0
9.8k
Agentic Web
dynamis
1
200
RAG を使わないという選択肢
tatsutaka
1
180
Amazon Bedrock AgentCore ワークショップ JAWS UG TOHOKU / amazon-bedrock-agentcore-workshop-jawsug-tohoku-2026
gawa
9
670
Building applications in the Gemini API family.
line_developers_tw
PRO
0
2.9k
protovalidate-es を導入してみた
bengo4com
0
170
作って終わりにしない タイミーのセマンティックレイヤー育成の現在地
chanyou0311
3
2.2k
ポケモンの型をTypeScriptの型システムで表現してみた
subroh0508
0
370
地球に⽣きるAI —GeoAIと「中間領域」— / AI Living on Earth — GeoAI and the “Intermediate Layer” —
ykiyota
0
280
Claude Code×Terraform IaC テンプレート駆動開発
itouhi
1
490
日本 Fintech 未来予測レポート 2027〜2028年(手動編集版)
8maki
0
1.7k
Featured
See All Featured
Claude Code どこまでも/ Claude Code Everywhere
nwiizo
65
56k
Marketing to machines
jonoalderson
1
5.4k
How STYLIGHT went responsive
nonsquared
100
6.2k
Lightning Talk: Beautiful Slides for Beginners
inesmontani
PRO
2
570
Building Applications with DynamoDB
mza
96
7.1k
How to build a perfect <img>
jonoalderson
1
5.6k
A Soul's Torment
seathinner
6
2.9k
Docker and Python
trallard
47
3.9k
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
0
1.7k
Abbi's Birthday
coloredviolet
2
8k
A brief & incomplete history of UX Design for the World Wide Web: 1989–2019
jct
2
390
B2B Lead Gen: Tactics, Traps & Triumph
marketingsoph
0
140
Transcript
ίϯςφηΩϡϦςΟπʔϧ 5SJWZͷհ ౻ଜڡ߂ʢʣ
࣍ w ࣗݾհ w ҆શͳίϯςφͱ w ίϯςφεΩϟφπʔϧ w 5SJWZͷհ w
5SJWZͷΈʹ͍ͭͯ
ࣗݾհ
౻ଜ ڡ߂ # Trivy/helmͷίϯτϦϏϡʔλ Github: @masahiro331
ࠓճͷͷഎܠ ίϯςφΞϓϦέʔγϣϯͷ ੬ऑੑΛཧ҆͠શʹ͍ͨ͠
ຊ
҆શͳίϯςφͱʁ
৴པ͞Εͨݸਓஂମ͕อक ҆શͳύοέʔδΛར༻
৴པ͞Εͨݸਓஂମ͕อक ҆શͳύοέʔδΛར༻
ίϯςφͰར༻͞ΕΔύοέʔδ w 04ύοέʔδ 31.ύοέʔδ EFCύοέʔδ FUD w ΞϓϦέʔγϣϯύοέʔδ
OQNύοέʔδ HFNύοέʔδ FUD
ίϯςφͰར༻͞ΕΔύοέʔδ w 04ύοέʔδ 31.ύοέʔδ EFCύοέʔδ FUD w ΞϓϦέʔγϣϯύοέʔδ
OQNύοέʔδ HFNύοέʔδ FUD ͜ΕΒͷύοέʔδʹ੬ऑੑ͕ແ͍͔ɺ ͘͠Өڹ͠ͳ͍͜ͱஅ͢Δඞཁ͕͋Δ
ύοέʔδͷ੬ऑੑΛೝࣝ͢Δඞཁ͕͋Δ ͦͷͨΊʹ
ύοέʔδͷ੬ऑੑΛೝࣝ͢Δඞཁ͕͋Δ ίϯςφεΩϟϯπʔϧͰ੬ऑੑͷࣗಈݕ ͦͷͨΊʹ
ίϯςφͷεΩϟϯπʔϧҰཡ w 5SJWZ w $MBJS w "ODIPSF&OHJOF w 2VBZ w
.JDSP4DBOOFS w %PDLFS)VC w ($3
ίϯςφεΩϟϯπʔϧͱͯ͠5SJWZΛ࠾༻
5SJWZͱ w LORZGࢯ͕։ൃͨ͠ίϯς φεΩϟϯπʔϧ w ଞͷεΩϟϯπʔϧͱൺֱͯ͠ ಋೖ͕༰қ w ΞϓϦέʔγϣϯύοέʔδͷ ੬ऑੑݕՄೳ
w ಠࣗͷํ๏Ͱ"MQJOFͷ੬ऑੑΛ ݕ͍ͯ͠ΔͨΊਫ਼͕ߴ͍ LORZGࢯ
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX ΞϓϦέʔγϣϯ ύοέʔδΈΕΔ
5SJWZͷରԠύοέʔδ w (FN fi MFMPDL SVCZ w 1JQ fi
MFMPDL QZUIPO w 1PFUSZMPDL QZUIPO w $PNQPTFSMPDL 1)1 w 1BDLBHFMPDLKTPO KBWBTDSJQU w ZBSOMPDL KBWBTDSJQU w $BSHPMPDL 3VTU
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX ಋೖ͕༰қ
5SJWZͷಋೖ
5SJWZͷ͍ํ
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX ݕਫ਼͕ߴ͍
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX $*্Ͱ͍͍͢
5SJWZͷΈʹ͍ͭͯհ
5SJWZͷߏ %PDLFS3FHJTUSZ ᶅ੬ऑੑݕ ੬ऑੑ%# ᶃ੬ऑੑใͷऔಘ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
੬ऑੑ%# %PDLFS3FHJTUSZ ᶃ੬ऑੑใͷऔಘ ᶅ੬ऑੑݕ ੬ऑੑ%#ʹ͍ͭͯ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
੬ऑੑ%#ʹ͍ͭͯ w ੬ऑੑใHJUIVCϦϙδτϦͰཧ͍ͯ͠Δ w 5SJWZॳճىಈ࣌ʹ੬ऑੑใΛDMPOF͢Δ w ࣍ճىಈҎ߱HJUͷࠩΞοϓσʔτ w ϩʔΧϧͷσʔλϕʔεͱͯ͠CCPMU%#Λ༻
ॳճ࣮ߦ࣌ʹHJUIVC͔Β੬ऑੑใΛऔಘ ੬ऑੑϦϙδτϦ $BDIFWVMOMJTU HJUDMPOF
࣍ճҎ߱HJUQVMMͰͷࠩߋ৽ ੬ऑੑϦϙδτϦ $BDIFWVMOMJTU HJUQVMM
੬ऑੑใ$JSDMF$*Ͱఆظߋ৽ ੬ऑੑϦϙδτϦ $BDIFWVMOMJTU $SPO+PCͰͷߋ৽ ੬ऑੑσʔλιʔε 5SBWJT$*
HJUϦϙδτϦΛܦ༝͢Δཧ༝ w ੬ऑੑσʔλιʔε 3FE)BU4FDVSJUZ%BUB ͳͲ ͷλΠϜΞτ͕ϢʔβʹӨڹ͢ΔͷΛΛ͙ͨΊ w ߋ৽σʔλΛࠩΞοϓσʔτ͢Δ͜ͱ͕Մೳ
%PDLFS*NBHFͷղੳʹ͍ͭͯ
੬ऑੑ%# %PDLFS3FHJTUSZ ᶃ੬ऑੑใͷऔಘ ᶅ੬ऑੑݕ %PDLFS*NBHFͷղੳʹ͍ͭͯ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
%PDLFS*NBHFͷղੳʹ͍ͭͯ w 5SJWZҎԼͷεςοϓͰ%PDLFS*NBHFΛղੳ %PDLFS3FHJTUSZ͔Β*NBHF-BZFSΛऔಘ *NBHF-BZFSΛΈཱͯͯϑΝΠϧΛऔΓग़͢ ੬ऑੑݕʹඞཁͳϑΝΠϧΛऔಘ ECJOTUBMMFE
(FN fi MFMPDLͳͲ w "MQJOFʹ͍ͭͯ36/ίϚϯυղੳ͢ΔͨΊελςΟοΫϦ ϯΫ͞ΕͨϥΠϒϥϦͷ੬ऑੑݕ
'30.DPNQPTFSBMQJOF "%%DPNQPTFSMPDLQIQBQQDPNQPTFSMPDL $.%<CJOCBTI> ྫ͑͜Μͳ%PDLFS fi MF
*NBHF-BZFSΛऔಘ͢Δ '30.DPNQPTFS "%%DPNQPTFSMPDL 36/CJOCBTI
*NBHF-BZFSΛੵΈॏͶ*NBHFΛ࡞ %PDLFS*NBHF '30.DPNQPTFS "%%DPNQPTFSMPDL 36/CJOCBTI
*NBHF͔Βొͨ͠ϑΝΠϧΛऔΓग़͢ %PDLFS*NBHF $PNQPTFSMPDL BMQJOFSFMFBTF ECJOTUBMMFE '30.DPNQPTFS "%%DPNQPTFSMPDL 36/CJOCBTI
੬ऑੑ%# %PDLFS3FHJTUSZ ᶃ੬ऑੑใͷऔಘ ᶅ੬ऑੑݕ ੬ऑੑݕʹ͍ͭͯ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
(FN fi MFMPDL ΠϯετʔϧࡁΈύοέʔδΛύʔε (&. SFNPUFIUUQTSVCZHFNTPSH TQFDT BDUJPODBCMF
BDUJPOQBDL OJPS d XFCTPDLFUESJWFS BDUJPONBJMFS BDUJPOQBDL BDUJPOWJFX BDUJWFKPC NBJM d SBJMTEPNUFTUJOH d 1JQ fi MFMPDL BNRQ\ IBTIFT< TIBCFC TIBBCD > WFSTJPO ^ BVUPQFQ\ IBTIFT< TIBECC > WFSTJPO ^ $2C[FL,/CH/R6K$S%+LPH71%H 1MJCTTM 7DS "Y@ 4 * 544-TIBSFEMJCSBSJFT 6IUUQTXXXPQFOTTMPSH -0QFO44- PPQFOTTM N5JNP5FSBTUJNPUFSBT!JLJ fi U DCCCCDEDBCCFFFCC %TPMJCDNVTMY@TPTPMJCDSZQUPTP QTPMJCTTMTP SMJCSFTTM 'MJC 3MJCTTMTP B ;24I29.-(31(CR%Q8;/-Y/N#V5 'VTS 'VTSMJC 3MJCTTMTP B ;2KQFZQ)0H.JIXM(1NND ECJOTUBMMFE
੬ऑੑ%#͔Βऔಘͨ͠σʔλͱಥ߹ (FN fi MFMPDL (&. SFNPUFIUUQTSVCZHFNTPSH TQFDT BDUJPODBCMF
BDUJPOQBDL OJPS d XFCTPDLFUESJWFS BDUJPONBJMFS BDUJPOQBDL BDUJPOWJFX 1JQ fi MFMPDL BNRQ\ IBTIFT< TIBCFC TIBBCD > WFSTJPO ^ BVUPQFQ\ $2C[FL,/CH/R6K$S%+LPH71%H 1MJCTTM 7DS "Y@ 4 * 544-TIBSFEMJCSBSJFT 6IUUQTXXXPQFOTTMPSH -0QFO44- PPQFOTTM N5JNP5FSBTUJNPUFSBT!JLJ fi U DCCCCDEDBCCFFFC C %TPMJCDNVTMY@TPTPMJCDSZQUPTP QTPMJCTTMTP SMJCSFTTM 'MJC 3MJCTTMTP ECJOTUBMMFE ੬ऑੑใ
࠷ޙʹ w 5SJWZγϯϓϧͳ੬ऑੑݕ͚ͩΛఏڙ w ͜ͷػೳΛར༻ͯ͠৽ͨͳ%FW4FD0QTπʔ ϧͷ։ൃͳͲظͰ͖Δ w ͜ͷػೳΛར༻ͯ͠LVCFSOFUFTڥͷ੬ऑੑ ݕΛࣗಈԽ͍ͨ͠
͓ΘΓ