Enhancing the Container Image Scanning Tool - GRYPE
R. Kalaiselvi, Shruthi Ravisankar, M V Varun, Dharanipriya Ravindran · 2023
Due to less time consumption for starting up containers, the use of container technology has grown compared to virtual machines usage. Though many container platforms exist, Docker is the widely used container platform as it let developers easily pack, transport, and run applications using lightweight, portable and self- sufficient containers that can execute in any environment. To use Docker containers, the images are downloaded from a registry called the Docker hub. Since container technology shares the OS-kernel with the host, it is extremely important to strengthen and monitor the security of containers and the images they run from. As a result, there are numerous tools for container scanning that helps to find the security vulnerabilities exist in containers. Grype proves to be the most accurate tool among various other container image tools exist like Trivy, Dagda etc. It still misses significant of vulnerabilities while scanning an image. Addressing this kind of inefficiency scanning is vital to ensure the security of the host machine which runs the container. Complete understanding of the Grype tool and resolving some of the persistent issues in Grype like failing to detect all the vulnerabilities in an image and the absence of a user interface is focused. A comparative analysis on existing scanning tools and proposed scanning tool is presented to showcase the strength of the proposed tool.