grypeใฏ่ๅผฑๆงๆค็ฅใใผใซใฎไธใคใงใใ๏ผSBOMใในใญใฃใณใใใใจใงๅใฝใใใฆใงใขใใฉใฎใใใช่ๅผฑๆงใซ่
ใใใใฆใใใใๆค็ฅใงใใพใใใพใ๏ผgrypeใฎ้็บๅ
ใฏsyftใจๅใใงใใ๏ผsyftใจ้ฃๆบใใใใจใ่ใไฝใใใฆใใพใใ
grypeๅ
ฌๅผใใญใฅใกใณใใซใฏใgrypeใฎๆงใ
ใชๆฉ่ฝ่ฉณ็ดฐใไปๆงใ็ฐๅขๅคๆฐใฎ่จญๅฎใซใคใใฆ่จ่ฟฐใใใฆใใพใใใใฎ่จไบใงใฏใ่ชๅใไฝฟใไธใงใไฝฟ็จ้ ปๅบฆใฎ้ซใๆฉ่ฝใซใคใใฆใ็ดนไปใใพใใ
ๆค่จผ็ฐๅข
- Ubuntu 22.04.3 LTS (WSL2)
| ใณใณใใผใใณใ | ใใผใธใงใณ | ไฝฟ็จ็จ้ |
|---|---|---|
| Docker | 24.0.5 | ใณใณใใใคใกใผใธใฎใใซใ |
| syft | v0.91.0 | SBOM็ๆใใผใซ |
| grype | v0.69.0 | ่ๅผฑๆงๆค็ฅ |
installๆนๆณ
ใพใใgrypeใไฝฟใใใใซใใฎใคใณในใใผใซๆนๆณใซใคใใฆ่ชฌๆใใพใใใคใณในใใผใซๆนๆณใฏsyftใฎๅ ดๅใจใปใผๅใใงใใ
0. ่งฃๅ็จใฎไธๆ็ใชใใกใคใซใฎไฝๆ
ใพใใgrypeใ่งฃๅใใใใใฎไธๆ็ใชใใฃใฌใฏใใชใไฝๆใใใใฎใใฃใฌใฏใใชใธ็งปๅใใพใ๏ผ
$ mkdir /tmp/grype/ && cd /tmp/grype/
1. grypeใฎใใคใใชใใกใคใซใฎๅๅพ
grypeใฎใชใชใผในๆ
ๅ ฑใใใใขใผใซใคใใใกใคใซใๅๅพใใพใใ
ไปๅใฏใgrype-v0.69.0ใใใใใผใธใงใณ0.69.0ใฎgrypeใฎใขใผใซใคใใงใใgrype_0.69.0_linux_amd64.tar.gzใๅๅพใใพใ๏ผ
$ wget https://github.com/anchore/grype/releases/download/v0.69.0/grype_0.69.0_linux_amd64.tar.gz
2. grypeใฎใใคใใชใใกใคใซใฎ่งฃๅ
ใใใฆใ่งฃๅ่กใใพใ๏ผ
$ tar xvf grype_0.69.0_linux_amd64.tar.gz
่งฃๅๅพใไปฅไธใฎใใใซ็ตๆใๅบๅใใใพใ๏ผ
CHANGELOG.md
LICENSE
README.md
grype
3. grypeใฎpathใ้ใ
ๆๅพใซgrypeใๅฎ่กใใใใใซ้ฉๅใชๅ ดๆใธgrypeใใคใใชใ็งปๅใใพใ๏ผ
$ sudo mv grype /usr/local/bin
ไปๅใฏใ/usr/local/binใธgrypeใ้
็ฝฎใใพใใใ
ไธๆ็ใชใใฃใฌใฏใใช/tmp/grypeใฏๅฟ
่ฆใชใใฎใงๅ้คใใฆใใพใฃใฆใใใใงใ๏ผ
$ cd ~
$ rm -rf /tmp/grype/
grypeใฎๅ ดๆใจใใผใธใงใณใ็ขบ่ชใใไปฅไธใฎใใใซๅบๅใใใฆใใใฐใgrypeใฎใคใณในใใผใซใฏๆๅใงใ๏ผ
$ grype version
Application: grype
Version: 0.69.0
BuildDate: 2023-09-20T20:56:04Z
GitCommit: da3de94842f51059f32409289d863792726f83ba
GitDescription: v0.69.0
Platform: linux/amd64
GoVersion: go1.21.1
Compiler: gc
Syft Version: v0.91.0
Supported DB Schema: 5
$ which grype
/usr/local/bin/grype
grype DB (ใใผใฟใใผใน)
grypeใฏๅฐ็จใฎ่ๅผฑๆงใใผใฟใใผในใ็จใใฆใ่ๅผฑๆงใฎในใญใฃใณใ่กใใพใใใใใงใฏใgrypeใงในใญใฃใณใใใๅใซใgrype DBใฎไฝฟใๆนใ่ชฌๆใใพใใgrypeใใคใณในใใผใซๅพใ่ชๅใฎใญใผใซใซ็ฐๅขใซgrype DBใ้
็ฝฎใใๅฟ
่ฆใใใใพใใgrype dbใณใใณใใ็จใใฆgrypeใใผใฟใใผในใซ้ขใใๆไฝใ่กใใใจใใงใใพใใ
1. DBใชในใๅๅพ
ใพใใไปฅไธใฎใณใใณใใงใgrype DBใฎใชในใใๅๅพใใพใ๏ผ
grype db list
ใใฎใจใใไปฅไธใฎใใใซgrype DBใฎไธ่ฆงใๅๅพใงใใพใ
Built: 2023-10-06 01:24:11 +0000 UTC
URL: https://toolbox-data.anchore.io/grype/databases/vulnerability-db_v5_2023-10-06T01:24:11Z_3efb2852b6383a7809d2.tar.gz
Checksum: sha256:c38ff0785a05c528d2038333c397f4a1e2164bc0ebe5f429484110ffc9e5a980
Built: 2023-10-05 01:24:28 +0000 UTC
URL: https://toolbox-data.anchore.io/grype/databases/vulnerability-db_v5_2023-10-05T01:24:28Z_17b232c51ce3734f92f5.tar.gz
Checksum: sha256:d842e5fd5c1f2ca0a0864e8a98698727ca6b0fb49928cc55ec14f752bfaeda68
Built: 2023-10-04 01:25:27 +0000 UTC
URL: https://toolbox-data.anchore.io/grype/databases/vulnerability-db_v5_2023-10-04T01:25:27Z_22681858d0461218ab2a.tar.gz
Checksum: sha256:86afbdc332df0360e9775d71b97a75a0510dfe13529111abd9e206df1088034c
.............
.............
grypeใฎใใผใฟใใผในใฏๆฏๆฅๆดๆฐใใใฆใใพใใ
2. grype DBใฎ่จญ็ฝฎ
ใชในใใๅๅพๅพใไปฅไธใฎใณใใณใใ็จใใฆๆๆฐใฎใใผใฟใใผในใๅๅพใใ้ ็ฝฎใใพใ๏ผ
$ wget https://toolbox-data.anchore.io/grype/databases/vulnerability-db_v5_2023-10-06T01:24:11Z_3efb2852b6383a7809d2.tar.gz
$ grpye db import <่ๅผฑๆงDBใฎtar.gz>
Vulnerability database imported
่ชๅใฎๅ ดๅใ่ๅผฑๆงDBใฎtar.gzใฏvulnerability-db_v5_2023-10-06T01:24:11Z_3efb2852b6383a7809d2.tar.gzใงใใใ
ใใใงใใญใผใซใซไธใซgrype DBใ่จญ็ฝฎใใใใจใใงใใพใใใDBใฎๅ ดๆใฏใฆใผใถใผใฎใใฃใฌใฏใใชhome/usrๅใฎ.cache/grypeใจใใใใฃใฌใฏใใชใซๅญๅจใใฆใใพใใ
3. grype DBใฎใใผใธใงใณ็ขบ่ช
ไปฅไธใฎใณใใณใใๅฎ่กใใใจใ็พๅจไฝฟ็จใใฆใใgrype DBใฎๆ ๅ ฑใ่ฆใใใจใใงใใพใ๏ผ
$ grype db status
Location: /home/usrๅ/.cache/grype/db/5
Built: 2023-10-06 01:24:11 +0000 UTC
Schema: 5
Checksum: sha256:bf2bcf8cedf4230cb37bf1e3a322a1d251a51683829968bd7554ff8e81995930
Status: valid
grype DB็ฎก็็จใฎใณใใณใ
gryoe DBใ็ฎก็ใใใใใฎใณใใณใใใใใงใพใจใใฆใใใพใ
grype db status : ็พๅจใฎgrype DBใฎ็ถๆ
ใ็ขบ่ชใงใใใDBใฎๅ ดๆใใใซใใใใๆฅไปใchecksumใ็ขบ่ชใงใใใ
grype db check DBใซๅฏพใใฆใใขใใใใผใใๅฏ่ฝใใฉใใใ่ฆใใใจใใงใใพใใ
grype db update : ๆๆฐใฎlatestใฎDBใ.cacheใใฃใฌใฏใใชใธใใฆใณใญใผใใใใใใใใฉใซใใงgrypeใงใฏในใญโใฃใณใใใใณใซๆๆฐใฎDBใซใขใใใใผใใใใใ
grype db list : ใใฆใณใญใผใๅฏ่ฝใชDBใใใฎURLใ็ขบ่ชใใใใจใใงใใใ
grype db import : grype DBใฎใขใผใซใคใใไฝฟใฃใฆใDBใใใฆใณใญใผใใงใใใ
grype db --help : ใณใใณใใซ้ขใใๆ
ๅ ฑใ็ขบ่ชใใใใจใใงใใใ
grype DBใฎๆณจๆ็น
grype DBใฏๆฏๆฅๆๆฐใฎDBใซๆดๆฐใใใฆใใใๆญฃ็ขบใช่ๅผฑๆง็ถใๆใซๅ ฅใใใใใซใgrypeในใญใฃใณๆใซๆๆฐใฎDBใซใขใใใใผใใใฆใใๅฟ ่ฆใใใใพใใใพใใใญใผใซใซใฎDBใ้ๅป5ๆฅไปฅๅ ใซbuildใใใฆใใชใๅ ดๅใgrypeใฎในใญใฃใณๅฎ่กใซๅคฑๆใใใใๆณจๆใๅฟ ่ฆใงใใ
grypeใงSBOMใในใญใฃใณใใฆใฟใ
ใใฅใผใใชใขใซใจใใฆใSBOM็ๆใใผใซsyftใง็ๆใใSBOMใในใญใฃใณใใ่ๅผฑๆงใใผใฟใ่ฆใฆใใใพใใๅๅใฎ่จไบSBOM็ๆใใผใซSyftใฎไฝฟใๆนใงไฝๆใใใใฃใฌใฏใใชsyft-testใธ็งปๅใใฆใใ ใใใใใใซๅๅไฝๆใใSBOM syft-python.jsonใใใใฏใใงใใใใฎSBOMใซๅฏพใใฆใไปฅไธใฎใณใใณใใๅฎ่กใใใใจใงในใญใฃใณใงใใพใ๏ผ
$ grype sbom:./syft-python.json -o table=scan.txt
โ Vulnerability DB [no update available]
โ Scanned for vulnerabilities [791 vulnerability matches]
โโโ by severity: 3 critical, 60 high, 227 medium, 30 low, 453 negligible (18 unknown)
โโโ by status: 21 fixed, 770 not-fixed, 0 ignored
grype DBใใ791ไปถใฎไธ่ดใใ่ๅผฑๆงใ็บ่ฆใใใใใจใใใใใพใใ
ในใญใฃใณ็ตๆscan.txtใ่ฆใฆใฟใใจใไปฅไธใฎใใใซใชใฃใฆใใพใใไปๅใฏๆ็ฒใใฆๆฒ่ผใใพใ๏ผ
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
apt 2.6.1 deb CVE-2011-3374 Negligible
libc-bin 2.36-9+deb12u1 2.36-9+deb12u3 deb CVE-2023-4911 High
libwmf-dev 0.2.12-5.1 deb CVE-2007-3476 Low
linux-libc-dev 6.1.52-1 deb CVE-2023-25775 Critical
python3.11 3.11.2-6 deb CVE-2023-40217 Medium
...........
...........
...........
ใใใงใในใญใฃใณ็ตๆใฎๆณจ็ฎใในใ็นๅพดใซใคใใฆ่ชฌๆใใพใใใพใใในใญใฃใณใใผใใซใฎใใใใผใฎ้ ็ฎใฏใใใใไปฅไธใ่กจใใฆใใพใ๏ผ
- NAME : ใใใฑใผใธใฎๅๅ
- INSTALLED : ใคใณในใใผใซใใใฆใใใใใฑใผใธใฎใใผใธใงใณ
- FIXED-IN : ใฝใใใฆใงใขใฎ่ๅผฑๆงใไฟฎๆญฃใใใใปใญใฅใชใใฃใใใใ้ฉ็จใใใใใผใธใงใณ
- TYPE : ใใใฑใผใธใฎใฟใคใ
- VULNERABILITY : ่ๅผฑๆงใซๅฏพใใฆใคใใใใ่ญๅฅๅญใๅบๅใใใใไปๅใฎในใญใฃใณใงใฏใCVE่ญๅฅ็ชๅทใจๅผใฐใใ่ญๅฅๅญใใคใใใใฆใใใ
- SEVERITY : Critical, High, Medium, Low, Negligibleใฎใฌใใซใงๅ้กใใใฆใใใHighใCriticalใจๅคๅฎใใใใใใฑใผใธใซๅฏพใใฆใฏใใใฎ่ๅผฑๆงใ่ชฟในใๅฏพ็ญใใใใจใๆจๅฅจใใใฆใใใ
้่ฆใชFIXED-INใซใคใใฆใ่ฉณใใ่ชฌๆใใพใใๆฅๆฌ่ชใงใฏใไฟฎๆญฃใใใใใจใใๆๅณใงใใใไฟฎๆญฃใใใใใจใฏใใฝใใใฆใงใขใฎ่ๅผฑๆงใไฟฎๆญฃใใใใปใญใฅใชใใฃใใใใ้ฉ็จใใใใใจใๆๅณใใพใใใคใพใใ่ๅผฑๆงใซๅฏพใใใปใญใฅใชใใฃใขใใใใผใใๆไพใใใฆใใใFIXED-INใงใฏใใใฎใขใใใใผใใ้ฉ็จใใใใใผใธใงใณใๅญๅจใใฆใใใใใฎใใผใธใงใณใซใคใใฆ่จ่ฟฐใใใฆใใพใใ
ไพใใฐใไปๅใฎไพใ่ฆใฆใฟใพใใใ๏ผ
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
libc-bin 2.36-9+deb12u1 2.36-9+deb12u3 deb CVE-2023-4911 High
ใใใงใฏใlibc-binใจใใใใใฑใผใธใฎใใผใธใงใณ 2.36-9+deb12u1 ใซๅฏพใใฆใ่ๅผฑๆงใๆค็ฅใใใฆใใพใใใใใฆใใใผใธใงใณ 2.36-9+deb12u1 ใซๅญๅจใใ CVE-2023-4911ใจใใ่ๅผฑๆงใใใใผใธใงใณ 2.36-9+deb12u3 ใงไฟฎๆญฃใใใใปใญใฅใชใใฃใฎๅ้กใ่งฃๆฑบใใใใใจใๆๅณใใฆใใพใใ
ใใใใฃใฆใใใงใซไฟฎๆญฃใใใ่ๅผฑๆงใซใคใใฆใฏใใฆใผใถใผใFIXED-INใ่ฆใฆใใใใซ่จ่ฟฐใใใใใผใธใงใณใใคใณในใใผใซใใใใจใงใ่ๅผฑๆงใซใใใปใญใฅใชใใฃใฎๅ้กใ่งฃๆฑบใใใใจใใงใใใไธๆนใFIXED-IN้
็ฎใ็ฉบๆฌใซใชใฃใฆใใใใใชใใกใใไฟฎๆญฃใใใฆใใชใใ่ๅผฑๆงใฏใใปใญใฅใชใใฃใขใใใใผใใใพใ ๆไพใใใฆใใใใ่ๅผฑๆงใไพ็ถใจใใฆๅญๅจใใ็ถๆ
ใๆใใฆใใพใใ
่ๅผฑๆงใไฟฎๆญฃใใใใใใฑใผใธใฎใฟใๅบๅใใใๅ ดๅใฏใgrypeใฎใณใใณใใซใใฉใฐ--only-fixedใไฝฟใใฐใใใไธๆนใ่ๅผฑๆงใไฟฎๆญฃใใใฆใใชใใใใฑใผใธใฎใฟใๅบๅใใใๅ ดๅใฏ--only-notfixedใใฉใฐใไฝฟใใพใใ
ๅฎ่กไพใงใ่ฆใใใใซgrypeใซใใในใญใฃใณใฏใๅคง้ใฎ่ๅผฑๆงใๆค็ฅใใพใใใใฎใใใFIXED-IN้
็ฎใ่ๅผฑๆงใฎใฌใใซใ่ฆณๆธฌใใ้่ฆใชใใฎใ ใๆฝๅบใใใใจใง็ขบ่ชใในใ่ๅผฑๆงใฎๆฐใๆธใใใใใจใใงใใใใใใgrypeใฎ้็จใซใใใฆ้่ฆใซใชใใพใใ
Comments
Let's comment your feelings that are more than good