Whats wrong with current distros vuln assesment and security reporting to have another one?
Whats wrong with current distros vuln assesment and security reporting to have another one?
If you "apt-get install nodejs", you can only have Node.js v18, in the very very recently released Debian bookworm. If your devs need Node.js v20, or even v22 which will both be LTS releases during the bookworm release cycle, you're out of luck.
You can go install those outside of the Debian package manager, but then you're on your own for vuln assessment and security fixes. Worse - many scanners don't actually even "see" packages that are installed outside of package managers, so you may not know that these exist or are installed.
We designed Wolfi to be more flexible around package versions. This is a very very hard problem to solve in general, but since we're focused on immutable containers, we can skip a lot of the complexity around conflicts, upgrade/downgrade scenarios, and cross-version compatibility.
It's going to be hard to scale, but we're going to at least try! We have a lot of ideas on how to make this work that I'm excited to try out.
I'm betting that with enough automation we can get there :)
As silly as it sounds, try running "snyk container test --print-deps" on that image, and look around for Node.
This approach works fine, but means that you might not be able to rely on most container security scanners to let you know when there's an issue.
At the end of they you need to keep an eye on file integrity, because of rootkits, config integrity…
Yeah there are many wats to approach to this… with its corresponding costs of course