mirror of https://github.com/docker/docs.git
Merge pull request #17207 from ChrisChinchilla/chrisward/scout-combine
Move Scout package ecosystem section
This commit is contained in:
commit
730d8cbccc
|
@ -19,21 +19,6 @@ exposures (CVEs) for the image in the **Tags** section. The **Tags** tab shows a
|
||||||
|
|
||||||
The **Images** section of Docker Desktop shows an overview of CVEs for an image and the details view shows all vulnerabilities.
|
The **Images** section of Docker Desktop shows an overview of CVEs for an image and the details view shows all vulnerabilities.
|
||||||
|
|
||||||
Advanced image analysis supports the following package ecosystems:
|
|
||||||
|
|
||||||
- .NET
|
|
||||||
- GitHub packages
|
|
||||||
- Go
|
|
||||||
- Java
|
|
||||||
- JavaScript
|
|
||||||
- PHP
|
|
||||||
- Python
|
|
||||||
- RPM
|
|
||||||
- Ruby
|
|
||||||
- `alpm` (Arch Linux)
|
|
||||||
- `apk` (Alpine Linux)
|
|
||||||
- `deb` (Debian Linux and derivatives)
|
|
||||||
|
|
||||||
## Activate Advanced image analysis
|
## Activate Advanced image analysis
|
||||||
|
|
||||||
Advanced image analysis is an early access feature and activated on a
|
Advanced image analysis is an early access feature and activated on a
|
||||||
|
|
|
@ -1,6 +1,6 @@
|
||||||
---
|
---
|
||||||
description: More details on the Docker Scout Advisory Database and CVE-to-package matching service.
|
description: More details on the Docker Scout Advisory Database and CVE-to-package matching service.
|
||||||
keywords: scanning, vulnerabilities, Hub, supply chain, security
|
keywords: scanning, analysis, vulnerabilities, Hub, supply chain, security
|
||||||
title: Advisory Database sources and matching service
|
title: Advisory Database sources and matching service
|
||||||
---
|
---
|
||||||
|
|
||||||
|
@ -61,7 +61,7 @@ images that Docker Scout can then match to CVEs. Find more details on how this
|
||||||
works in the [Advanced image analysis
|
works in the [Advanced image analysis
|
||||||
document](http://./advanced-image-analysis.md).
|
document](http://./advanced-image-analysis.md).
|
||||||
|
|
||||||
Docker Scout is ideal for scanning images in Docker Desktop and Docker Hub, but
|
Docker Scout is ideal for analyzing images in Docker Desktop and Docker Hub, but
|
||||||
the flexibility of the approach also means it can integrate with other image
|
the flexibility of the approach also means it can integrate with other image
|
||||||
sources, for example, [JFrog
|
sources, for example, [JFrog
|
||||||
Artifactory](https://docs.docker.com/scout/artifactory/).
|
Artifactory](https://docs.docker.com/scout/artifactory/).
|
||||||
|
@ -73,7 +73,6 @@ Many other tools use fuzzy [Common Product Enumeration
|
||||||
wild cards to known vulnerabilities with the versions of software packages they affect.
|
wild cards to known vulnerabilities with the versions of software packages they affect.
|
||||||
This can return a lot of false positives which you need to triage.
|
This can return a lot of false positives which you need to triage.
|
||||||
|
|
||||||
|
|
||||||
The typical structure of a CPE match looks like this:
|
The typical structure of a CPE match looks like this:
|
||||||
|
|
||||||
```
|
```
|
||||||
|
@ -103,3 +102,20 @@ system versions to make more precise matches.
|
||||||
|
|
||||||
In summary, Docker Scout’s technique improves matching accuracy and reduces the
|
In summary, Docker Scout’s technique improves matching accuracy and reduces the
|
||||||
number of results that turn out to be false-positives.
|
number of results that turn out to be false-positives.
|
||||||
|
|
||||||
|
## Package ecosystems supported by the Docker Scout Advisory Database
|
||||||
|
|
||||||
|
By sourcing vulnerability data from the providers above, Docker Scout is able to support analyzing the following package ecosystems:
|
||||||
|
|
||||||
|
- .NET
|
||||||
|
- GitHub packages
|
||||||
|
- Go
|
||||||
|
- Java
|
||||||
|
- JavaScript
|
||||||
|
- PHP
|
||||||
|
- Python
|
||||||
|
- RPM
|
||||||
|
- Ruby
|
||||||
|
- `alpm` (Arch Linux)
|
||||||
|
- `apk` (Alpine Linux)
|
||||||
|
- `deb` (Debian Linux and derivatives)
|
||||||
|
|
Loading…
Reference in New Issue