Menu

Post image 1
Post image 2
1 / 2
0

War Story: I Deployed a Broken Docker Image to Production and How I Fixed It with Trivy 0.50 and Harbor 2.10

DEV Community·ANKUSH CHOUDHARY JOHAL·about 1 month ago
#R4FHxfgx
#tip#story#deployed#broken#trivy#harbor
Reading 0:00
15s threshold

At 14:32 UTC on March 12, 2024, our team deployed a Docker image with 14 critical CVEs and a misconfigured entrypoint to production, causing a 100% error rate for 47 minutes, $42k in SLA penalties, and 12 angry customer support tickets. 🔴 Live Ecosystem Stats ⭐ moby/moby — 71,512 stars, 18,922 forks Data pulled live from GitHub and npm. 📡 Hacker News Top Stories Right Now Ghostty is leaving GitHub (2031 points) Bugs Rust won't catch (56 points) Before GitHub (342 points) How ChatGPT serves ads (219 points) Show HN: Auto-Architecture: Karpathy's Loop, pointed at a CPU (46 points) Key Insights Trivy 0.50 reduced CVE scan time by 62% compared to 0.48 in our 1.2GB image benchmarks Harbor 2.10's new OCI artifact signing integrates natively with Trivy 0.50's SBOM output Implementing pre-push Trivy scans in our CI pipeline saved $18k/month in SLA penalties within 30 days By 2025, 70% of enterprise container registries will enforce mandatory SBOM signing for all production pushes, up from 12% today # Broken CI…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More