Company
Date Published
Author
Dustin Van Buskirk
Word count
451
Language
English
Hacker News points
None

Summary

Codefresh has developed a custom step to enhance Docker image security by integrating with Clair, an open-source project for vulnerability scanning. This step allows users to quickly scan Docker images for vulnerabilities and generate reports to determine if the build should pass or fail based on configured vulnerability thresholds. The integration requires an instance of Clair and provides enriched metadata on vulnerabilities for Docker images in the Codefresh registry. Users can also upload reports to storage and connect them with the Codefresh registry for additional metadata enrichment. The process is streamlined, requiring minimal setup, and Codefresh offers resources such as a webinar and a Helm Chart by the CoreOS Team to assist users in deploying Clair on Kubernetes.