
Linter de imágenes de contenedor para seguridad, ayudando a construir la imagen Docker de mejores prácticas, fácil de empezar.
Dockle - Linter de imágenes de contenedor para seguridad, ayudando a construir la imagen Docker de mejores prácticas, fácil de empezar
Dockle te ayuda a:
Consulte [Instalación](#installation) y [Ejemplos comunes](#common-examples)
<img src="https://assets.kitploit.com/production/public/readmes/4137/343598bd4d53296c6d6d23acde8c2917d5727f03e7b3a34c1ff0865c435bb974.png" width="800">
# Comparación de Checkpoints
<img src="https://assets.kitploit.com/production/public/readmes/4137/4f4835c3a5fd70f436d9d8ea656fd8a521112fece4e35977288064d3f6f4510a.png" width="800">
<img src="https://assets.kitploit.com/production/public/readmes/4137/7bee9da0b061957af6a175a3b975dca82813c27f72ab6921dfe8ab2d6747322b.png" width="800">
# Índice
- [Características](#features)
- [Comparación](#comparison)
- [Instalación](#installation)
- [Homebrew (Mac OS X / Linux y WSL)](#homebrew-mac-os-x--linux-and-wsl)
- [RHEL/CentOS](#rhelcentos)
- [Debian/Ubuntu](#debianubuntu)
- [Arch Linux](#arch-linux)
- [Windows](#windows)
- [Microsoft PowerShell 7](#microsoft-powershell-7)
- [Binario](#binary)
- [asdf](#asdf)
- [mise](#mise)
- [Desde el código fuente](#from-source)
- [Usar Docker](#use-docker)
- [Inicio Rápido](#quick-start)
- [Básico](#basic)
- [Docker](#docker)
- [Resumen de Puntos de Control](#checkpoint-summary)
- [Ejemplos Comunes](#common-examples)
- [Escanear una imagen](#scan-an-image)
- [Escanear un archivo de imagen](#scan-an-image-file)
- [Obtener o guardar los resultados como JSON](#get-or-save-the-results-as-json)
- [Obtener o guardar los resultados como SARIF](#get-or-save-the-results-as-sarif)
- [Especificar código de salida](#specify-exit-code)
- [Especificar nivel de salida](#specify-exit-level)
- [Ignorar los puntos de control especificados](#ignore-the-specified-checkpoints)
- [Aceptar `variables de entorno` / `archivos` / `extensiones de archivo` sospechosas](#accept-suspicious-environment-variables--files--file-extensions)
- [Rechazar `variables de entorno` / `archivos` / `extensiones de archivo` sospechosas](#reject-suspicious-environment-variables--files--file-extensions)
- [Integración Continua](#continuous-integration-ci)
- [GitHub Action](#github-action)
- [Travis CI](#travis-ci)
- [CircleCI](#circleci)
- [GitLab CI](#gitlab-ci)
- [Autorización para registro privado de Docker](#authorization-for-private-docker-registry)
- [Docker Hub](#docker-hub)
- [Amazon ECR (Elastic Container Registry)](#amazon-ecr-elastic-container-registry)
- [GCR (Google Container Registry)](#gcr-google-container-registry)
- [Registro autohospedado (BasicAuth)](#self-hosted-registry-basicauth)
- [Contribuyentes](#contributors)
- [Contribuyentes de código](#code-contributors)
- [Contribuyentes financieros](#financial-contributors)
- [Individuos](#individuals)
- [Organizaciones](#organizations)
- [Licencia](#license)
- [Autor](#author)
# Características
- Detectar vulnerabilidades del contenedor
- Ayudar a construir Dockerfiles con mejores prácticas
- Uso simple
- Especificar solo el nombre de la imagen
- Consulte [Inicio Rápido](#quick-start) y [Ejemplos Comunes](#common-examples)
- Soporte de benchmarks CIS
- Alta precisión
- DevSecOps
- Adecuado para CI como Travis CI, CircleCI, Jenkins, etc.
- Consulte [Ejemplo de CI](#continuous-integration-ci)
# Comparación
| | [Dockle](https://github.com/goodwithtech/dockle) | [Hadolint](https://github.com/hadolint/hadolint) | [Docker Bench for Security](https://github.com/docker/docker-bench-security) | [Clair](https://github.com/coreos/clair) |
|--- |---:|---:|---:|---:|
| Objetivo | Imagen | Dockerfile | Host<br/>Demonio Docker<br/>Imagen<br/>Runtime del contenedor | Imagen |
| Cómo ejecutar | Binario | Binario | Script Shell | Binario |
| Dependencia | No | No | Algunas dependencias | No |
| Adecuado para CI | ✓ | ✓ | x | x |
| Propósito | Auditoría de seguridad<br/>Linting de Dockerfile | Linting de Dockerfile | Auditoría de seguridad<br/>Linting de Dockerfile | Escanear vulnerabilidades |
# Instalación
## Homebrew (Mac OS X / Linux y WSL)
Puede usar Homebrew en [Mac OS X](https://brew.sh/) o [Linux y WSL (Subsistema de Windows para Linux)](https://docs.brew.sh/Homebrew-on-Linux).```bash
$ brew install goodwithtech/r/dockle
VERSION=$(
curl --silent "https://api.github.com/repos/goodwithtech/dockle/releases/latest" |
grep '"tag_name":' |
sed -E 's/."v([^"]+)"./\1/'
) && rpm -ivh https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Linux-64bit.rpm
## Debian/Ubuntu```bash
VERSION=$(
curl --silent "https://api.github.com/repos/goodwithtech/dockle/releases/latest" | \
grep '"tag_name":' | \
sed -E 's/.*"v([^"]+)".*/\1/' \
) && curl -L -o dockle.deb https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Linux-64bit.deb
$ sudo dpkg -i dockle.deb && rm dockle.deb
dockle se puede instalar desde el Arch User Repository usando el paquete dockle o dockle-bin.```
git clone https://aur.archlinux.org/dockle-bin.git
cd dockle-bin
makepkg -sri
## Windows```bash
VERSION=$(
curl --silent "https://api.github.com/repos/goodwithtech/dockle/releases/latest" | \
grep '"tag_name":' | \
sed -E 's/.*"v([^"]+)".*/\1/' \
) && curl -L -o dockle.zip https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Windows-64bit.zip
$ unzip dockle.zip && rm dockle.zip
$ ./dockle.exe [IMAGE_NAME]
if (((Invoke-WebRequest "https://api.github.com/repos/goodwithtech/dockle/releases/latest").Content) -match '"tag_name":"v(?[^"]+)"') { $VERSION=$Matches.ver && Invoke-WebRequest "https://github.com/goodwithtech/dockle/releases/download/v${VERSION}/dockle_${VERSION}_Windows-64bit.zip" -OutFile dockle.zip && Expand-Archive dockle.zip && Remove-Item dockle.zip }
## Binario
Puedes obtener la última versión binaria desde la [página de versiones](https://github.com/goodwithtech/dockle/releases/latest).
Descarga el archivo comprimido para tu sistema operativo/arquitectura. Descomprime el archivo y coloca el binario en algún lugar dentro de tu `$PATH` (en sistemas tipo UNIX, `/usr/local/bin` o similar).
- NOTA: Asegúrate de que los bits de ejecución estén activados. (`chmod +x dockle`)
## asdf