Container Vulnerability Scanning Sucks

  Рет қаралды 687

Latio Tech - Learn Product Security

Latio Tech - Learn Product Security

2 ай бұрын

Container Vulnerabilities present a nightmarish challenge in cybersecurity. In this video, we dive into why fixing things actually takes a fraction of the time, and the challenges with working with vulnerability scanning tools.
Docker image used in the video: github.com/latiotech/insecure...

Пікірлер: 4
@CK.23.
@CK.23. 2 ай бұрын
Proud to be No. 222.. Good job and good luck. Please try higher resolution for text..
@maxgraupner1049
@maxgraupner1049 2 ай бұрын
What are your thoughts on bumping versions and creating incompatibility, need for regression testing, etc. I agree the fixing can be THAT easy but then do you test every time there is a change?
@aviad-chen
@aviad-chen 2 ай бұрын
I would say yes. If you have a good test coverage in place, and no breaking changes in the minor upgrade of a package, why not? The idea is not to merge every day on every updatr, but if you do it on a weekly basis, per the new versions, it won't be that noisy
@latiotech
@latiotech 2 ай бұрын
All I can say is that this used to really scare me, but I've never had an image break from just running nightly builds with the same dockerfile auto-grabbing the latest patch version fixes. Conversely, this happens frequently with SCA type vulnerabilities bumping open source library versions.
Learn Jenkins! Complete Jenkins Course - Zero to Hero
1:08:28
DevOps Journey
Рет қаралды 691 М.
Checking out new CSS Features!
2:49:55
Dustin Goodman
Рет қаралды 276
100❤️ #shorts #construction #mizumayuuki
00:18
MY💝No War🤝
Рет қаралды 20 МЛН
Docker vulnerability scanning tool | Trivy
7:14
kubernetesWay
Рет қаралды 9 М.
Secure LLM Architecture - Testing LLM Guard
16:17
Latio Tech - Learn Product Security
Рет қаралды 616
WTF is CNAPP?
19:33
Latio Tech - Learn Product Security
Рет қаралды 388
Chat With MYSQL Database With PandasAI | Generative AI Tools
8:31
The Code Cruise
Рет қаралды 240
АСЛАНЯН: Китайский автопром - это обман россиян
7:57
Ходорковский LIVE
Рет қаралды 150 М.
Is runtime SCA reachability a gimmick? A look at Oligo Security
16:38
Latio Tech - Learn Product Security
Рет қаралды 282
Securing CI/CD Pipelines - Xygeni
16:10
Latio Tech - Learn Product Security
Рет қаралды 258
Do NOT Learn Kubernetes Without Knowing These Concepts...
13:01
Travis Media
Рет қаралды 219 М.
Не обзор DJI Osmo Pocket 3 Creator Combo
1:00
superfirsthero
Рет қаралды 1,3 МЛН
POCO F6 PRO - ЛУЧШИЙ POCO НА ДАННЫЙ МОМЕНТ!
18:51
Iphone or nokia
0:15
rishton vines😇
Рет қаралды 566 М.
How To Unlock Your iphone With Your Voice
0:34
요루퐁 yorupong
Рет қаралды 18 МЛН