Loading…
In-person + Virtual
16 -20 May
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Europe 2022 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Central European Summer Time (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change.
Thursday, May 19 • 14:30 - 15:05
Digging Into Your App's Container Image Layers for Sneaky Vulnerabilities - Pablo Galego, VMware

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.


Mitigating vulnerabilities in container images is, most of the time, a straight-forward task: update the base image, use a newer version of Node or Java, bump the patch version of a project dependency, etc. However, all useful pieces of software are complex and vulnerability scanning tools fall short on explaining why they are flagging some edge-cases. This session walks you through mitigating critical vulnerabilities in popular container images like Java-based ones, from the obvious to the sneaky ones, and how to leverage layer explorer tools to narrow the search field for the latter. It is meant to be a hands-on session, first we will use Aqua’s Trivy scanner to analyze an image generated for a Spring Boot app and then wagoodman's dive to explore in which layer we are introducing a version of a library with critical vulnerabilities, while Maven seems to tell us otherwise.

Click here to view captioning/translation in the MeetingPlay platform!

Speakers
avatar for Pablo Galego

Pablo Galego

Software Engineer, VMware
Pablo Galego works as software engineer in VMware. His short career to containers and security is, like many others, a bit unorthodox. First graduating in Law, decided to make a career switch to Computer Engineering and four years later started at Inditex's Engineering Productivity... Read More →



Thursday May 19, 2022 14:30 - 15:05 CEST
Pavilion 3, Room D | Level 2 | Central Forum Feria Valencia
  101 Track