Docker
Sign
Generating Keys
# Generating Keys
docker trust key generate my-keySigning
Sign and push
export DOCKER_CONTENT_TRUST=1
docker push registry.example.com/my-image:latestVerifying
Verifying Trusted Images
export DOCKER_CONTENT_TRUST=1
docker pull registry.example.com/my-image:latestScan
Vulnerability scanning for Docker local images
docker scan --dependency-tree debian:buster
# Excluding the base image
docker scan --file Dockerfile --exclude-base docker-scan:e2e
# Checking the dependency tree
docker scan --dependency-tree debian:buster
# Provider authentication
docker scan --login --token SNYK_AUTH_TOKENRef
Last updated
Was this helpful?