Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    Problems with Clair integration for scanning docker images

    Scheduled Pinned Locked Moved Support
    2 Posts 2 Posters 9 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      karsten.meichsner_9039
      last edited by

      Hi,

      we have clair installed and it seems to be running fine so far. Initially we had some problems with reaching the sources that clair needs (e.g. nist.gov, alpinelinux.org, ...) but it all works now. There are no more such errors in the clair log. But I get the following messages in Proget when running the VulnerabilityDownloader task:

      Requested vulnerability information for 38 total package versions.
      Sending last 38 coordinates as a final request...
      Request returned 38 vulnerability records.
      Clair returned error ProxyAuthenticationRequired for layer sha256:2db29710...
      Clair returned error ProxyAuthenticationRequired for layer sha256:31a7f9b4d..
      ...
      

      An image with log4j in it is not detected. Any idea?

      Cheers

      Karsten

      stevedennisS 1 Reply Last reply Reply Quote 0
      • stevedennisS Offline
        stevedennis inedo-engineer @karsten.meichsner_9039
        last edited by

        Hi @karsten-meichsner_9039,

        I haven't seen that error before, but based on the text ("ProxyAuthenticationRequired for layer"), I think that Clair is trying to download an external layer?

        Some container image manifests (especially Windows, but not entirely) will point to a URL outside of the registry. This is often done for licensing reasons. What this means is that, Clair (or the docker client) downloads the layers from a url instead of ProGet.

        I'm not familiar enough with container scanners (Clair) to know how they search for vulnerabilities; I believe it's done by looking at the packages installed on the system. Log4j is not a package installed on the system (I think), but a library used in some applications.

        Cheers,
        Steve

        1 Reply Last reply Reply Quote 0

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        • 1 / 1
        • First post
          Last post
        Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation