Oct. 2, 2022, 10:01 a.m. | Thodoris Velmachos

DEV Community dev.to

Hello, I believe every Developer needs to use Cli Tools Like Anchore/Grype and Anchore/Syft before pushing an Docker Image to the any Docker Registry.


Grype Ref: https://lnkd.in/d4NB3uv3

Syft Ref: https://lnkd.in/drK3jZmx


Youtube References, see them in action to understand why you need to use them.

Grype Ref: https://lnkd.in/dfvJAxvX

Syft Ref: https://lnkd.in/dPEgw9i3


Screenshot from Grype Vulnerability Report.


assessments devjournal devops docker images sbom security vulnerability

Principal - Cyber Risk and Assurance - Infra/Network

@ GSK | Bengaluru Luxor North Tower

Staff Security Engineer

@ Airwallex | AU - Melbourne

Chief Information Security Officer

@ Australian Payments Plus | Sydney, New South Wales, Australia

TW Test Automation Engineer (Access Control & Intrusion Systems)

@ Bosch Group | Taipei, Taiwan

Consultant infrastructure sécurité H/F

@ Hifield | Sèvres, France

SOC Analyst

@ Wix | Tel Aviv, Israel