docker/docker-bench-security
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
ShellApache-2.0
Issues
- 32
Execute benchmark on rootless docker
#556 opened by osorito - 3
- 3
- 3
- 1
Docker daemon socket security
#544 opened by Nethaji-nethu - 1
1.1.9 Is checking the wrong file
#554 opened by Yaytay - 11
- 9
- 13
Exit Code Control, and Output Format Options
#482 opened by AErmie - 3
- 1
Sed error when specifying checks to include and exclude when runnning on a Mac
#503 opened by gavinmporter - 1
404: functions_lib.sh link is invalid
#507 opened by Wenzel - 17
Docker Benchmark support v1.4.x / v1.5.x
#512 opened by ktsowes - 5
- 2
Docker 1.6.0 is the latest version
#534 opened by anubhav1992 - 1
Definition of the assessment status
#545 opened by saikumark - 4
- 9
when jq output is equal "null", is not handled well and checks return a wrong PASS. Also, when jq is not available, cat does not handle well complex values like for example 'default-ulimits'
#537 opened by halfluke - 3
- 1
Ensure image sprawl is avoided miscalculation
#532 opened by halfluke - 3
Update required programs check to use tr command instead of truncate command
#527 opened by manojrkrish - 3
- 0
- 6
- 6
- 3
Feature request: TAP output files
#509 opened by knaapjvd - 4
Ubuntu does not use /etc/sysconfig/docker for its service config - checks 3.20 and 3.21
#502 opened by scottbrunza - 5
2.7 false positive when log_opt set
#498 opened by dhrapson - 4
Support Number of Checks / Score By Group
#486 opened by AErmie - 6
Error at 1.1.14-1.1.18, Audit rule applied but still mentioned not applied
#484 opened by Styleeeeez - 7
Can't seem to capture the output in a log file
#483 opened by poencho - 15
Docker-bench-security check 2.2 icc issue
#480 opened by fbinliu - 2
Autodetect host configuration
#479 opened by thediveo - 2
- 6
docker.service file permission is 640 but it is still giving a WARN notification
#459 opened by adespain - 2
- 7
Running docker-bench-security under WSL1
#446 opened by sbutt - 7
- 1
- 4
- 5
1.2.1 is listed as 1.1 in the results, and userns-remap causes 1.2.1 to fail.
#462 opened by adespain - 2
Invalid check for socket existence
#477 opened by drmaciej - 0
bash not available within Alpine:3.13
#473 opened by denhamparry - 1
Run failed on MacOS(Big Sur 11.4) with /etc/hostname: operation not permitted: unknown
#472 opened by oslook - 2
"[dumb-init] docker-bench-security.sh: No such file or directory" on Windows 10 when trying to build locally
#470 opened by pxds - 4
- 3
- 6
excluding group not working
#453 opened by Constantin07 - 5
Test 4.6 does not always output affected images
#450 opened by scenthound - 1