inflearn logo
๊ฐ•์˜

Course

Instructor

[DevOps Basics 3] Building CI Properly with GitHub Actions

Vulnerability Checking and SBOM Management Using Aqua Trivy and Dependency Track

๐Ÿ™‹๐Ÿป Trivy์™€ Dependency Track์ด ์†Œ๊ฐœ๋˜๋Š” ์„ธ์…˜ ๋๋ถ€๋ถ„์— ๊ฒฐ๊ณผ ์˜์ƒ์ด ์ž˜๋ฆฐ ๊ฒƒ ๊ฐ™์•„์š”

750

Jeongyeol Lee

1 asked

0

์•ˆ๋…•ํ•˜์„ธ์š”. ๊ฐ•์˜ ์ž˜ ๋ณด๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค!

Aqua Trivy๋กœ ์Šค์บ”๋œ sarif ํฌ๋งท์„ GitHub์— ์ „์†กํ•œ ๊ฒฐ๊ณผ์™€ Dependency Track์— ์ „๋‹ฌ๋œ ๊ฒฐ๊ณผ๋ฅผ ํ™•์ธํ•˜๋Š” ๊ณผ์ • ์˜์ƒ์ด ๋ˆ„๋ฝ๋œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ๋Œ€์ƒ ์„ธ์…˜์€ Aqua Trivy์™€ Dependency Track์„ ์ด์šฉํ•œ ์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฐ SBOM ๊ด€๋ฆฌ ์ž…๋‹ˆ๋‹ค.

์ฒดํฌ ํ•œ๋ฒˆ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค :)

Answer 1

1

JeongSuk Lee

์•ˆ๋…•ํ•˜์„ธ์š”,

ํ•ด๋‹น ๋ถ€๋ถ„์„ ํ™•์ธํ•ด๋ณธ ๊ฒฐ๊ณผ, Dependency Track์œผ๋กœ ์ „๋‹ฌํ•˜๋Š” ๊ณผ์ •์€ ""Container ๊ธฐ๋ฐ˜์˜ Custom Action ๊ตฌ์„ฑ" ํŒŒํŠธ์—์„œ ๋ˆ„๋ฝ๋œ ๋ถ€๋ถ„์„ ์ปค๋ฒ„ํ•˜๊ณ  ์žˆ๋Š” ๊ฒƒ์„ ํ™•์ธํ•˜์˜€์Šต๋‹ˆ๋‹ค.

๊ฐ•์˜์— ๋งŽ์€ ๊ด€์‹ฌ์„ ๊ฐ€์ ธ์ฃผ์…”์„œ ๊ฐ์‚ฌ๋“œ๋ฆฌ๋ฉฐ, ์ถ”ํ›„ ๊ธฐํšŒ๊ฐ€ ๋˜๋Š”๋Œ€๋กœ ๋ˆ„๋ฝ๋œ ๋ถ€๋ถ„์— ๋Œ€ํ•œ ์™„์„ฑ๋„๋ฅผ ๋†’์—ฌ๋ณด๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

 

๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

 

 

0

Jeongyeol Lee

๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค! ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค :)

๊ฐ•์˜ ์ถ”์ฒœํ•ด์ฃผ์„ธ์š”

2

25

1

์ผ€์ดํ…Œ์ŠคํŠธ ์„œ๋ฒ„ ์šด์˜ ๋ฐฉ๋ฒ•

2

44

1

์‹ค์Šต ํŒŒ์ผ ์—…๋กœ๋“œ ์•ˆ๋œ ๊ฒƒ ๊ฐ™์•„์š” ์ด๊ฑฐ ๊ฐ•์‚ฌ๋‹˜ํ•œํ…Œ ๋ณด์—ฌ์ฃผ์„ธ์š”

1

24

2

์  ํ‚จ์Šค๋ฒ„์ „๊ณผ ํ”Œ๋Ÿฌ๊ทธ์ธ์„ค์น˜

1

36

2