Container Vulnerability Scanning episode artwork

EPISODE · Apr 19, 2018 · 25 MIN

Container Vulnerability Scanning

from PodCTL - Enterprise Kubernetes · host Brian Gracely & Tyler Britten

Show: 32Show Overview:Tyler and Aaron Delp talk with Liz Rice (@lizrice, Technology Evangelist @AquaSecTeam) about what's easy—and what's not—about finding and patching security vulnerabilities in containers. This is a cross-over show with @TheCloudcastNet podcast. Show Notes:Liz’s talk at Velocity Conf - “What’s so hard about container vulnerability scanning?”Use code CLOUD to get 20% off Velocity or OSCON ticketsAqua Security HomepageLiz Rice’s Blog[Video] Kubernetes, Metadata and You (KubeCon 2017 Austin)Topic 1 - Welcome to the show Liz. Tell us a little bit about your background and the types of things that you’re working on these days.Topic 2 - Let’s start with the basics. A container is defined by a file (e.g. Dockerfile) that the user/developer/operator defines. How can a vulnerability get into that file?Topic 3 - Is it up to the CI/CD system or  host OS (where the container runs) or container orchestrator (e.g. Kubernetes) or container registry to figure out if a vulnerability exists?Topic 4 - How do most container registries today manage vulnerability lists, container scanning and potential mitigations? What are the difficult parts of those tasks?Topic 5 - Most containers today are Linux containers. Are you seeing anything happening (yet) around how to manage Windows containers vulnerabilities? Is the assumption that Microsoft will fix this through one of their existing tools, or are things happening in the open source community as well? Feedback?Email: PodCTL at gmail dot comTwitter: @PodCTL Web: http://podctl.com

Episode metadata supplied by the publisher feed · Published Apr 19, 2018

Show: 32 Show Overview:Tyler and Aaron Delp talk with Liz Rice (@lizrice, Technology Evangelist @AquaSecTeam) about what's easy—and what's not—about finding and patching security vulnerabilities in containers. This is a cross-over show with @TheCloudcastNet podcast. Show Notes: Liz’s talk at Velocity Conf - “What’s so hard about container vulnerability scanning?”Use code CLOUD to get 20% off Velocity or OSCON ticketsAqua Security HomepageLiz Rice’s Blog[Video] Kubernetes, Metadata and You...

PodParley-generated summary based on available episode metadata and transcript content.

NOW PLAYING

Container Vulnerability Scanning

0:00 25:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

The Chad James Podcast Chad James Join veteran business coach, Chad James as he challenges you to turn your Boring Old Business into the amazing enterprise you always hoped it would be. Chad shares lessons, stories and strategies from over 20 years of helping small business owners, entrepreneurs and leaders succeed faster, live better and create the lives they always imagined. Everything VR & AR The VRAR Association Everything VR & AR is a weekly podcast covering technologists, enthusiasts, and companies with real world deployments of virtual reality and augmented reality experiences. Learn from interviews with the leaders in gaming, entertainment, productivity, enterprise, social, education, medicine, software, hardware, psychology and more. This podcast covers everything that is VR and AR including the hottest topics and news in virtual reality and augmented reality. Nathan Pettyjohn, Founder of the VR/AR Association is your host. Intel Conversations in the Cloud Intel Intel Conversations in the Cloud is a weekly podcast with IT leaders who are driving the future of a software-defined infrastructure based data center. Featuring members of the Intel Builders programs, Intel experts, and industry analysts, this recurring podcast series provides information on delivering, deploying, and managing cloud computing, technology, and services in the data center and enterprise. Podcast Archive - Today's Business Radio Thomas W Lyons Welcome to TodaysBusinessRadio.com. We are a combination of an on air radio show at KTLK AM 1130, Minneapolis, MN and our online and on demand “business reference library” of over 100 interviews with business advisors, in podcast format. Our mission is to help business owners to: increase enterprise value, improve profitability, control expenses and formulate an exit strategy for the business.

Frequently Asked Questions

How long is this episode of PodCTL - Enterprise Kubernetes?

This episode is 25 minutes long.

When was this PodCTL - Enterprise Kubernetes episode published?

This episode was published on April 19, 2018.

What is this episode about?

Show: 32Show Overview:Tyler and Aaron Delp talk with Liz Rice (@lizrice, Technology Evangelist @AquaSecTeam) about what's easy—and what's not—about finding and patching security vulnerabilities in containers. This is a cross-over show with...

Can I download this PodCTL - Enterprise Kubernetes episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!