Skip to main content

新しくなったSnyk Container CLI

container scans

2020年10月29日

0 分で読めます

アプリケーションのパッケージ化にコンテナを採用する方が増えるなか、リリース前にコンテナ内の脆弱性を特定することが非常に重要になっています。

Snykでは1年以上前から、CLIを使ってDockerイメージをテストできる機能を提供しています。CLIの最新リリースでは、コンテナを利用するユーザーの使いやすさを向上させるとともに、上級ユーザー向けの便利な機能を追加しました。

新しいcontainerサブコマンド

現在、コンテナイメージをテストするには、--dockerフラグをsnyk testまたはsnyk monitorに指定します。多くのユーザーにとって便利な方法であり、この動作を変更する予定はありません。ただし、インラインヘルプを確認する場合など、いくつかの不便な点もあります。

コンテナイメージのテストだけを行いたい場合でも、該当するオプションを見つけるために多くの項目を確認する必要があります。そこで、snykに新しいサブコマンドを追加しました。次のコマンドで、コンテナイメージの脆弱性をテストできます。

snyk container test <your-image>

その情報をSnykに送信すると、結果を表示できるほか、今後新たな脆弱性が見つかった際に通知を受け取れます。その場合はmonitorコマンドも利用できます。

snyk container monitor <your-image>

Snykなら、イメージがどこにあっても簡単にテストできます。イメージがローカルのDockerデーモンにある場合は、そのイメージをテストします。リモートレジストリにある場合は、イメージをプルしてテストします。テストするマシンにDockerがインストールされていなくても問題ありません。コンテナのワークフローはさまざまですが、Snykなら普段の作業方法に合わせて簡単にイメージをテストできます。

改めてお伝えすると、従来の--dockerフラグは引き続き使用でき、新しい機能も含めて新コマンドのエイリアスとして動作します。Snykは後方互換性を重視しており、CLIツールを使った自動化を妨げることはありません。

コンテナ専用のヘルプ

新しいcontainerサブコマンドでは、コンテナ専用のヘルプをCLIから直接確認できます。イメージのビルドに使ったDockerfileの指定方法、ベースイメージで見つかった脆弱性の除外方法、重大度の高い脆弱性だけを報告する方法など、CLIの使い方がすぐに分かるため、より簡単に利用できます。

$ snyk container --help
Usage:

  $ snyk container [command] [options] [image]

Find vulnerabilities in your container images.

Commands:

  test ............... Test for any known vulnerabilities.
  monitor ............ Record the state of dependencies and any
                       vulnerabilities on snyk.io.

Options:

  --exclude-base-image-vulns .............. Exclude from display base image vulnerabilities.
  --file=<string> ......................... Include the path to the image's Dockerfile for more detailed advice.
  -h, --help
  --platform=<string> ..................... For multi-architecture images, specify the platform to test. Options are:
                                            [linux/amd64, linux/arm64, linux/riscv64, linux/ppc64le, linux/s390x,
                                            linux/386, linux/arm/v7 orlinux/arm/v6]
  --json  .................................. Return results in JSON format.
  --json-file-output=<string>
                       (test command only)
                       Save test output in JSON format directly to the specified file, regardless of whether or not you use the `--json` option.
                       This is especially useful if you want to display the human-readable test output via stdout and at the same time save the JSON format output to a file.
  --sarif ................................. Return results in SARIF format.
  --sarif-file-output=<string>
                       (test command only)
                       Save test output in SARIF format directly to the specified file, regardless of whether or not you use the `--sarif` option.
                       This is especially useful if you want to display the human-readable test output via stdout and at the same time save the SARIF format output to a file.
  --print-deps ............................ Print the dependency tree before sending it for analysis.
  --project-name=<string> ................. Specify a custom Snyk project name.
  --policy-path=<path> .................... Manually pass a path to a snyk policy file.
  --severity-threshold=<low|medium|high>... Only report vulnerabilities of provided level or higher.

Examples:

  $ snyk container test alpine
  $ snyk container test --platform=linux/arm64 debian
  $ snyk container monitor alpine
  $ snyk container test docker-archive:archive.tar
  $ snyk container test oci-archive:archive.tar

Pro tip: use `snyk container test --file=Dockerfile` for more detailed advice.

For more information see https://snyk.io

Pro tip: use `snyk container test --file=Dockerfile` for more detailed advice.

For more information see https://snyk.io

新たに追加された機能

新しいsnyk containerサブコマンドには、上級ユーザー向けの新機能も追加されています。

イメージではなくコンテナアーカイブを直接扱っている場合も、Snykで脆弱性をテストできるようになりました。

たとえば、Dockerからアーカイブを保存し、次のように生成されたアーカイブファイルをテストできます。

docker save ubuntu:18.04 -o ubuntu.tar
snyk container test docker-archive:ubuntu.tar

標準のOCI(Open Container Initiative)イメージを直接扱っている場合も、同様にテストできます。

snyk container test oci-archive:ubuntu.tar

さらに、SnykはDistrolessイメージのテストにも対応しました。DistrolessはGoogleの興味深いプロジェクトで、セキュリティ向上のためシェルやパッケージマネージャーを含めず、Debianパッケージをベースにしたコンテナ用ベースイメージを提供しています。これにより、Distrolessのベースイメージや、それを使ってビルドしたイメージも、通常どおりSnykでテストできるようになりました。

$ snyk container test gcr.io/distroless/base | head                                                                                                           
Testing gcr.io/distroless/base...

✗ Low severity vulnerability found in openssl/libssl1.1
  Description: Cryptographic Issues
  Info: https://snyk.io/vuln/SNYK-DEBIAN9-OPENSSL-374708
  Introduced through: openssl/libssl1.1@1.1.0l-1~deb9u1, openssl@1.1.0l-1~deb9u1
  From: openssl/libssl1.1@1.1.0l-1~deb9u1
  From: openssl@1.1.0l-1~deb9u1 > openssl/libssl1.1@1.1.0l-1~deb9u1
  From: openssl@1.1.0l-1~deb9u

次のステップ

Snykは、CLIツール、Snykサービス、API、さまざまな開発者ツールとのインテグレーションを通じて、常にユーザーエクスペリエンスの向上に取り組んでいます。新しいsnyk containerコマンドにより、コンテナを中心に作業する際もSnykを簡単に利用できるようになります。このインターフェースには、今後も便利で興味深い機能を追加していく予定です。

CTFを始めよう

オンデマンドのバーチャル入門ワークショップで、CTFチャレンジの解き方を学びましょう。