-
Notifications
You must be signed in to change notification settings - Fork 8.1k
dhi: add scanner integration #23952
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
dhi: add scanner integration #23952
Conversation
✅ Deploy Preview for docsdocker ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
126cfc7 to
90349ae
Compare
Bkblodget
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
made a few suggestions, overall looks great!
| - Scanner flexibility: Switch between any VEX-enabled scanner (Docker Scout, | ||
| Trivy, Grype, etc.) without losing vulnerability context or rebuilding | ||
| exclusion lists. | ||
| - Consistent results: All VEX-enabled scanners interpret the same data the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would remove "all" here.
"VEX-enabled scanners interpret the same data...."
| lists to replicate what VEX statements already document. | ||
| - Higher false positive rates: Expect to see more reported vulnerabilities | ||
| that don't represent real risks. | ||
| - Increased investigation time: Security teams spend time researching why |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This may not be the right place, but when I read this bullet point, I was thinking we could add something like "security experts at docker manage this investigation for you, and thoroughly vet each justification before adding it to a VEX statement."
Description
Added topic about scanner integrations and moved conceptual info from how to scan to that topic.
Refreshed how to scan and vex core concept topics.
Pending Wiz updates.
Related issues or tickets
ENGDOCS-3137
Reviews