anchore-engine
outdated
anchore-engine | outdated | |
---|---|---|
3 | 3 | |
1,529 | 420 | |
- | 1.0% | |
4.0 | 0.0 | |
over 1 year ago | 9 months ago | |
Python | Go | |
Apache License 2.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
anchore-engine
-
A Tool To Advise What Apps Are Out Of Date Per Cluster?
There's also Anchore. - Also another thread w/ resources - https://www.reddit.com/r/kubernetes/comments/bx4w2h/track_outdated_images/.
-
How to Secure Your Kubernetes Clusters With Best Practices
Enable container image scanning in your CI/CD phase to catch known vulnerabilities using tools like clair or Anchore.
- What Vulnerability Scanning Services do you use?
outdated
-
A tool that scans repos and workout latest version and pull date of installed version + how to lock down repos (via some cluster policy?)
https://outdated.sh ?
-
A Tool To Advise What Apps Are Out Of Date Per Cluster?
I came across Outdated this week, which looks really good: https://github.com/replicatedhq/outdated
-
Weekly: Questions and advice
I found https://github.com/replicatedhq/outdated but I'd like to have something like this as a service/cronjob with reporting feature, maybe for multiple clusters.
What are some alternatives?
grype - A vulnerability scanner for container images and filesystems
ksniff - Kubectl plugin to ease sniffing on kubernetes pods using tcpdump and wireshark
dagda - a tool to perform static analysis of known vulnerabilities, trojans, viruses, malware & other malicious threats in docker images/containers and to monitor the docker daemon and running docker containers for detecting anomalous activities
krew - 📦 Find and install kubectl plugins
quay - Build, Store, and Distribute your Applications and Containers
kubelogin - kubectl plugin for Kubernetes OpenID Connect authentication (kubectl oidc-login)
aura - Python source code auditing and static analysis on a large scale
kubectx - Faster way to switch between clusters and namespaces in kubectl
jellyfin-session-kicker - Session kicker after X amount of watch time for Jellyfin
kubeclarity - KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems
docker-bench-security - The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
ThreatMapper - Open source cloud native security observability platform. Linux, K8s, AWS Fargate and more.