Slide 37
Slide 37 text
INFOレベルの検出項目調査 37
{
"code": "CIS-DI-0005",
"title": "Enable Content trust for Docker",
"level": "INFO",
"alerts": [
"export DOCKER_CONTENT_TRUST=1 before docker pull/build"
]
},
{
"code": "CIS-DI-0006",
"title": "Add HEALTHCHECK instruction to the container image",
"level": "INFO",
"alerts": [
"not found HEALTHCHECK statement"
]
},
{
"code": "CIS-DI-0008",
"title": "Confirm safety of setuid/setgid files",
"level": "INFO",
"alerts": [
"setuid file: urwxr-xr-x usr/bin/chfn",
"setuid file: urwxr-xr-x usr/bin/su",
"setuid file: urwxr-xr-x usr/bin/chsh",
"setgid file: grwxr-xr-x usr/bin/wall",
"setuid file: urwxr-xr-x usr/bin/passwd",
"setgid file: grwxr-xr-x usr/bin/expiry",
"setuid file: urwxr-xr-x usr/bin/mount",
"setgid file: grwxr-xr-x usr/bin/chage",
"setuid file: urwxr-xr-x usr/bin/umount",
"setuid file: urwxr-xr-x usr/bin/newgrp",
"setgid file: grwxr-xr-x usr/sbin/unix_chkpwd",
"setuid file: urwxr-xr-x usr/bin/gpasswd"
]
}
- 検出項目
- CIS-DI-0005:Docker コンテントトラストを有効にしているか
- 検出項目
- CIS-DI-0006:Dockerfile内にHEALTHCHECKを導入しているか
- 検出項目
- CIS-DI-0008:setuidとsetgidを使っていないか
CodeBuild Log