Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit containerized environments #361

Open
fridex opened this issue Dec 7, 2021 · 9 comments
Open

Audit containerized environments #361

fridex opened this issue Dec 7, 2021 · 9 comments
Labels
kind/feature Categorizes issue or PR as related to a new feature. lifecycle/frozen Indicates that an issue or PR should not be auto-closed due to staleness. needs-triage Indicates an issue or PR lacks a `triage/...` label and requires one. priority/backlog Higher priority than priority/awaiting-more-evidence. sig/stack-guidance Categorizes an issue or PR as relevant to SIG Stack Guidance.

Comments

@fridex
Copy link
Contributor

fridex commented Dec 7, 2021

Is your feature request related to a problem? Please describe.

As a user of Thoth, I would like to submit my container image to Thoth services and Thoth should give me results of analyses that will tell me if content in the containerized environment is known and if there are any issues associated with the container image and its security.

Describe the solution you'd like

Extend container image analyses so that it not only explores what is present in the containerized environment, but can judge if the container image is find with respect to its content, libraries installed, provenance, and so.

Describe alternatives you've considered

Let users validate their container images, but that is too prone to errors.

Related: thoth-station/micropipenv#206
Related: https://discuss.python.org/t/pip-installation-reports/12316

@fridex fridex added kind/feature Categorizes issue or PR as related to a new feature. needs-triage Indicates an issue or PR lacks a `triage/...` label and requires one. labels Dec 7, 2021
@fridex
Copy link
Contributor Author

fridex commented Feb 15, 2022

Related: #366

@goern
Copy link
Member

goern commented Mar 4, 2022

/sig stack-guidance

@sesheta sesheta added the sig/stack-guidance Categorizes an issue or PR as relevant to SIG Stack Guidance. label Mar 4, 2022
@codificat
Copy link
Member

Testing if project assignment works:
/project SIG-Stack-Guidance

@codificat
Copy link
Member

/project SIG-Stack-Guidance New

@goern
Copy link
Member

goern commented May 16, 2022

/priority backlog

@sesheta sesheta added the priority/backlog Higher priority than priority/awaiting-more-evidence. label May 16, 2022
@mayaCostantini
Copy link
Contributor

/assign

@codificat
Copy link
Member

Reviewed in sig-sg meeting 2022-06-27:

  • this will likely turn into an epic
  • it seems to involve extending package-extract so it generates additional results/output

@sesheta
Copy link
Member

sesheta commented Sep 25, 2022

Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

/lifecycle stale

@sesheta sesheta added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Sep 25, 2022
@harshad16
Copy link
Member

/remove-lifecycle stale
/lifecycle frozen

@sesheta sesheta added lifecycle/frozen Indicates that an issue or PR should not be auto-closed due to staleness. and removed lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. labels Oct 4, 2022
@mayaCostantini mayaCostantini removed their assignment Dec 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/feature Categorizes issue or PR as related to a new feature. lifecycle/frozen Indicates that an issue or PR should not be auto-closed due to staleness. needs-triage Indicates an issue or PR lacks a `triage/...` label and requires one. priority/backlog Higher priority than priority/awaiting-more-evidence. sig/stack-guidance Categorizes an issue or PR as relevant to SIG Stack Guidance.
Projects
Status: 📋 Backlog
Development

No branches or pull requests

6 participants