Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Container Security with Trivy
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Masahiro331
June 11, 2022
Technology
250
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Container Security with Trivy
Masahiro331
June 11, 2022
More Decks by Masahiro331
See All by Masahiro331
Model Context Protocol 勉強会
masahiro331
0
98
OSSに新機能を追加するまでの苦労話
masahiro331
0
240
Analyze Filesystem in Virtual Machine Image
masahiro331
0
230
SBOMを利用したソフトウェアサプライチェーンの保護
masahiro331
4
2.8k
Introduction Supply Chain Security
masahiro331
0
190
VirtualMachine Image scanning PoC with Molysis
masahiro331
0
200
Other Decks in Technology
See All in Technology
ポケモンの型をTypeScriptの型システムで表現してみた
subroh0508
0
370
2026TECHFRESH畢業分享會 - 原生還是跨平台? App 開發踩坑實錄
line_developers_tw
PRO
0
800
RSA暗号を手計算したくなること、ありますよね?? (20260615_orestudy6_rsa)
thousanda
0
220
Chainlitで作るお手軽チャットUI
ynt0485
0
200
脆弱性対応、どこで線を引くか
rymiyamoto
0
360
Amazon Bedrock AgentCore ワークショップ JAWS UG TOHOKU / amazon-bedrock-agentcore-workshop-jawsug-tohoku-2026
gawa
9
670
連合学習と機密コンピューティング
lycorptech_jp
PRO
0
100
機械学習を「社会実装」するということ 2026年夏版 / Social Implementation of Machine Learning June 2026 Version
moepy_stats
4
1.5k
スキルと MCP ツール、責務をどう分けるか? AI が迷わないインターフェース設計の戦略
cdataj
1
950
Claude Code の Sandbox 機能を Anthropic Sandbox Runtime(srt) で試そう!/lets-play-anthropic-sandbox-runtime
tomoki10
1
540
RAG を使わないという選択肢
tatsutaka
1
180
Oracle AI Database@AWS:サービス概要のご紹介
oracle4engineer
PRO
4
2.9k
Featured
See All Featured
brightonSEO & MeasureFest 2025 - Christian Goodrich - Winning strategies for Black Friday CRO & PPC
cargoodrich
3
730
Jess Joyce - The Pitfalls of Following Frameworks
techseoconnect
PRO
1
160
The Limits of Empathy - UXLibs8
cassininazir
1
350
エンジニアに許された特別な時間の終わり
watany
107
250k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
Site-Speed That Sticks
csswizardry
13
1.2k
Design of three-dimensional binary manipulators for pick-and-place task avoiding obstacles (IECON2024)
konakalab
0
450
Evolution of real-time – Irina Nazarova, EuRuKo, 2024
irinanazarova
9
1.4k
[RailsConf 2023] Rails as a piece of cake
palkan
59
6.7k
Agile Leadership in an Agile Organization
kimpetersen
PRO
0
160
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
430
The Art of Programming - Codeland 2020
erikaheidi
57
14k
Transcript
ίϯςφηΩϡϦςΟπʔϧ 5SJWZͷհ ౻ଜڡ߂ʢʣ
࣍ w ࣗݾհ w ҆શͳίϯςφͱ w ίϯςφεΩϟφπʔϧ w 5SJWZͷհ w
5SJWZͷΈʹ͍ͭͯ
ࣗݾհ
౻ଜ ڡ߂ # Trivy/helmͷίϯτϦϏϡʔλ Github: @masahiro331
ࠓճͷͷഎܠ ίϯςφΞϓϦέʔγϣϯͷ ੬ऑੑΛཧ҆͠શʹ͍ͨ͠
ຊ
҆શͳίϯςφͱʁ
৴པ͞Εͨݸਓஂମ͕อक ҆શͳύοέʔδΛར༻
৴པ͞Εͨݸਓஂମ͕อक ҆શͳύοέʔδΛར༻
ίϯςφͰར༻͞ΕΔύοέʔδ w 04ύοέʔδ 31.ύοέʔδ EFCύοέʔδ FUD w ΞϓϦέʔγϣϯύοέʔδ
OQNύοέʔδ HFNύοέʔδ FUD
ίϯςφͰར༻͞ΕΔύοέʔδ w 04ύοέʔδ 31.ύοέʔδ EFCύοέʔδ FUD w ΞϓϦέʔγϣϯύοέʔδ
OQNύοέʔδ HFNύοέʔδ FUD ͜ΕΒͷύοέʔδʹ੬ऑੑ͕ແ͍͔ɺ ͘͠Өڹ͠ͳ͍͜ͱஅ͢Δඞཁ͕͋Δ
ύοέʔδͷ੬ऑੑΛೝࣝ͢Δඞཁ͕͋Δ ͦͷͨΊʹ
ύοέʔδͷ੬ऑੑΛೝࣝ͢Δඞཁ͕͋Δ ίϯςφεΩϟϯπʔϧͰ੬ऑੑͷࣗಈݕ ͦͷͨΊʹ
ίϯςφͷεΩϟϯπʔϧҰཡ w 5SJWZ w $MBJS w "ODIPSF&OHJOF w 2VBZ w
.JDSP4DBOOFS w %PDLFS)VC w ($3
ίϯςφεΩϟϯπʔϧͱͯ͠5SJWZΛ࠾༻
5SJWZͱ w LORZGࢯ͕։ൃͨ͠ίϯς φεΩϟϯπʔϧ w ଞͷεΩϟϯπʔϧͱൺֱͯ͠ ಋೖ͕༰қ w ΞϓϦέʔγϣϯύοέʔδͷ ੬ऑੑݕՄೳ
w ಠࣗͷํ๏Ͱ"MQJOFͷ੬ऑੑΛ ݕ͍ͯ͠ΔͨΊਫ਼͕ߴ͍ LORZGࢯ
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX ΞϓϦέʔγϣϯ ύοέʔδΈΕΔ
5SJWZͷରԠύοέʔδ w (FN fi MFMPDL SVCZ w 1JQ fi
MFMPDL QZUIPO w 1PFUSZMPDL QZUIPO w $PNQPTFSMPDL 1)1 w 1BDLBHFMPDLKTPO KBWBTDSJQU w ZBSOMPDL KBWBTDSJQU w $BSHPMPDL 3VTU
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX ಋೖ͕༰қ
5SJWZͷಋೖ
5SJWZͷ͍ํ
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX ݕਫ਼͕ߴ͍
֤εΩϟϯπʔϧͷݕূ݁Ռ ࢀߟใIUUQTHJUIVCDPNLORZGUSJWZPWFSWJFX $*্Ͱ͍͍͢
5SJWZͷΈʹ͍ͭͯհ
5SJWZͷߏ %PDLFS3FHJTUSZ ᶅ੬ऑੑݕ ੬ऑੑ%# ᶃ੬ऑੑใͷऔಘ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
੬ऑੑ%# %PDLFS3FHJTUSZ ᶃ੬ऑੑใͷऔಘ ᶅ੬ऑੑݕ ੬ऑੑ%#ʹ͍ͭͯ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
੬ऑੑ%#ʹ͍ͭͯ w ੬ऑੑใHJUIVCϦϙδτϦͰཧ͍ͯ͠Δ w 5SJWZॳճىಈ࣌ʹ੬ऑੑใΛDMPOF͢Δ w ࣍ճىಈҎ߱HJUͷࠩΞοϓσʔτ w ϩʔΧϧͷσʔλϕʔεͱͯ͠CCPMU%#Λ༻
ॳճ࣮ߦ࣌ʹHJUIVC͔Β੬ऑੑใΛऔಘ ੬ऑੑϦϙδτϦ $BDIFWVMOMJTU HJUDMPOF
࣍ճҎ߱HJUQVMMͰͷࠩߋ৽ ੬ऑੑϦϙδτϦ $BDIFWVMOMJTU HJUQVMM
੬ऑੑใ$JSDMF$*Ͱఆظߋ৽ ੬ऑੑϦϙδτϦ $BDIFWVMOMJTU $SPO+PCͰͷߋ৽ ੬ऑੑσʔλιʔε 5SBWJT$*
HJUϦϙδτϦΛܦ༝͢Δཧ༝ w ੬ऑੑσʔλιʔε 3FE)BU4FDVSJUZ%BUB ͳͲ ͷλΠϜΞτ͕ϢʔβʹӨڹ͢ΔͷΛΛ͙ͨΊ w ߋ৽σʔλΛࠩΞοϓσʔτ͢Δ͜ͱ͕Մೳ
%PDLFS*NBHFͷղੳʹ͍ͭͯ
੬ऑੑ%# %PDLFS3FHJTUSZ ᶃ੬ऑੑใͷऔಘ ᶅ੬ऑੑݕ %PDLFS*NBHFͷղੳʹ͍ͭͯ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
%PDLFS*NBHFͷղੳʹ͍ͭͯ w 5SJWZҎԼͷεςοϓͰ%PDLFS*NBHFΛղੳ %PDLFS3FHJTUSZ͔Β*NBHF-BZFSΛऔಘ *NBHF-BZFSΛΈཱͯͯϑΝΠϧΛऔΓग़͢ ੬ऑੑݕʹඞཁͳϑΝΠϧΛऔಘ ECJOTUBMMFE
(FN fi MFMPDLͳͲ w "MQJOFʹ͍ͭͯ36/ίϚϯυղੳ͢ΔͨΊελςΟοΫϦ ϯΫ͞ΕͨϥΠϒϥϦͷ੬ऑੑݕ
'30.DPNQPTFSBMQJOF "%%DPNQPTFSMPDLQIQBQQDPNQPTFSMPDL $.%<CJOCBTI> ྫ͑͜Μͳ%PDLFS fi MF
*NBHF-BZFSΛऔಘ͢Δ '30.DPNQPTFS "%%DPNQPTFSMPDL 36/CJOCBTI
*NBHF-BZFSΛੵΈॏͶ*NBHFΛ࡞ %PDLFS*NBHF '30.DPNQPTFS "%%DPNQPTFSMPDL 36/CJOCBTI
*NBHF͔Βొͨ͠ϑΝΠϧΛऔΓग़͢ %PDLFS*NBHF $PNQPTFSMPDL BMQJOFSFMFBTF ECJOTUBMMFE '30.DPNQPTFS "%%DPNQPTFSMPDL 36/CJOCBTI
੬ऑੑ%# %PDLFS3FHJTUSZ ᶃ੬ऑੑใͷऔಘ ᶅ੬ऑੑݕ ੬ऑੑݕʹ͍ͭͯ ᶄ%PDLFS-BZFSΛऔಘ͠ *NBHFΛΈཱͯΔ
(FN fi MFMPDL ΠϯετʔϧࡁΈύοέʔδΛύʔε (&. SFNPUFIUUQTSVCZHFNTPSH TQFDT BDUJPODBCMF
BDUJPOQBDL OJPS d XFCTPDLFUESJWFS BDUJPONBJMFS BDUJPOQBDL BDUJPOWJFX BDUJWFKPC NBJM d SBJMTEPNUFTUJOH d 1JQ fi MFMPDL BNRQ\ IBTIFT< TIBCFC TIBBCD > WFSTJPO ^ BVUPQFQ\ IBTIFT< TIBECC > WFSTJPO ^ $2C[FL,/CH/R6K$S%+LPH71%H 1MJCTTM 7DS "Y@ 4 * 544-TIBSFEMJCSBSJFT 6IUUQTXXXPQFOTTMPSH -0QFO44- PPQFOTTM N5JNP5FSBTUJNPUFSBT!JLJ fi U DCCCCDEDBCCFFFCC %TPMJCDNVTMY@TPTPMJCDSZQUPTP QTPMJCTTMTP SMJCSFTTM 'MJC 3MJCTTMTP B ;24I29.-(31(CR%Q8;/-Y/N#V5 'VTS 'VTSMJC 3MJCTTMTP B ;2KQFZQ)0H.JIXM(1NND ECJOTUBMMFE
੬ऑੑ%#͔Βऔಘͨ͠σʔλͱಥ߹ (FN fi MFMPDL (&. SFNPUFIUUQTSVCZHFNTPSH TQFDT BDUJPODBCMF
BDUJPOQBDL OJPS d XFCTPDLFUESJWFS BDUJPONBJMFS BDUJPOQBDL BDUJPOWJFX 1JQ fi MFMPDL BNRQ\ IBTIFT< TIBCFC TIBBCD > WFSTJPO ^ BVUPQFQ\ $2C[FL,/CH/R6K$S%+LPH71%H 1MJCTTM 7DS "Y@ 4 * 544-TIBSFEMJCSBSJFT 6IUUQTXXXPQFOTTMPSH -0QFO44- PPQFOTTM N5JNP5FSBTUJNPUFSBT!JLJ fi U DCCCCDEDBCCFFFC C %TPMJCDNVTMY@TPTPMJCDSZQUPTP QTPMJCTTMTP SMJCSFTTM 'MJC 3MJCTTMTP ECJOTUBMMFE ੬ऑੑใ
࠷ޙʹ w 5SJWZγϯϓϧͳ੬ऑੑݕ͚ͩΛఏڙ w ͜ͷػೳΛར༻ͯ͠৽ͨͳ%FW4FD0QTπʔ ϧͷ։ൃͳͲظͰ͖Δ w ͜ͷػೳΛར༻ͯ͠LVCFSOFUFTڥͷ੬ऑੑ ݕΛࣗಈԽ͍ͨ͠
͓ΘΓ