Get a Demo
Under Attack?
An illustration featuring a crane lifting several server racks with Kubernetes and Keycloak logos. The background includes large digital storage units. Labels on the racks display data strings and the name Upwind.

Pinpoint Vulnerability Origins With Complete Visibility into Container Image Layers

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Denise Ashur February 21, 2024

Pinpoint Vulnerability Origins With Complete Visibility into Container Image Layers

We are excited to release an important new capability – container image layer visibility.

A Docker build consists of a series of ordered build instructions. A layer, or image layer, is a change in an image, or an intermediate image. Every command specified (FROM, RUN, COPY, etc.) in a Dockerfile causes the previous image to change, thus creating a new layer.

This new capability provides a detailed breakdown of each container image by:

  • Highlighting specific image layers
  • Identifying image changes between layers
  • Pinpointing the introduction layer for every package

Understanding and tracking container image layers is crucial for identifying when and where vulnerabilities were first introduced and can also be used to discover package drifts related to packages installed outside the base image layer.

layers-details-1-1024x661

In addition to layer visibility and the ability to pinpoint vulnerabilities origins, you can also use this capability for:

1. Streamlined scans of large images, leveraging our ability to break the scan per layer

2. More efficient scans that only scan the last layer

3. Faster and easier scanning for your organization

Use this capability for increased transparency into your running container images, helping you rapidly identify and track how image layers introduce or resolve vulnerabilities and how this impacts your overall cloud security.

Contents

Further Reading

OpenAI Breach

Everyone Read the OpenAI Breach as a Model Story, But It Was a Runtime Story

Key Takeaways Autonomous AI agents can now break out of a sandbox, cross an internal network, and breach a production system with no human at the keyboard. OpenAI's evaluation that hacked Hugging Face this month is the clearest proof on record. Most of the coverage read it as a story about a model turning dangerous.…
upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS