Achieve Security and Compliance Goals with Policy Guardrails in Docker Scout

At DockerCon 2023, we announced the General Availability (GA) of Docker Scout. We built Docker Scout for modern application teams, to help developers navigate the complexities and challenges of the software supply chain through actionable insights. 

The Scout GA release introduced several new capabilities, including a policy-driven evaluation mechanism, aka guardrails, that helps developers prioritize their insights to better align their work with organizational standards and industry best practices. 

In this article, we will walk through how Docker Scout policies enable teams to identify, prioritize, and fix their software quality issues at the point of creation — the developer inner loop (i.e., local development, building, and testing) — so that they can meet their organization’s security and reliability standards without compromising their speed of execution and innovation. 

Prioritizing problems

When implementing software supply chain tools and processes, organizations often encounter a daunting wall of issues in their software. The sheer volume of these issues (ranging from vulnerabilities in code to malicious third-party dependencies, compromised build systems, and more) makes it difficult for development teams to balance shipping new features and improving their product. In such situations, policies play a crucial role in helping developers prioritize which problems to fix first by providing clear guidelines and criteria for resolution. 

Docker Scout’s out-of-the-box policies align with software supply chain best practices to maintain up-to-date base images, remove high-risk vulnerabilities, check for undesirable licenses, and look for other issues to help organizations maintain the quality of the artifacts they’re building or consuming (Figure 1). 

Figure 1: A summary of available policies in Docker Scout.

These policies bring developers critical insights about their container images and enable them to focus on prioritizing new issues as they come in and to identify which pre-existing issues require their attention. In fact, developers can get these insights right from their local machine, where it is much faster and less expensive to iterate than later in the supply chain, such as in CI, or even later in production (Figure 2).

Figure 2: Policy evaluation results in CLI.

Make things better

Docker Scout also adopts a more pragmatic and flexible approach when it comes to policy. Traditional policy solutions typically follow a binary pass/fail evaluation model that imposes rigid, one-size-fits-all targets, like mandating “fewer than 50 vulnerabilities” where failure is absolute. Such an approach overlooks nuanced situations or intermediate states, which can cause friction with developer workflows and become a main impediment to successful adoption of policies. 

In contrast, Docker Scout’s philosophy revolves around a simple premise: “Make things better.” This premise means the first step in every release is not to get developers to zero issues but to prevent regression. Our approach acknowledges that although projects with complex, extensive codebases have existing quality gaps, it is counterproductive to place undue pressure on developers to fix everything, everywhere, all at once.

By using Docker Scout, developers can easily track what has worsened in their latest builds (from the website, the CLI and CI pipelines) and only improve the issues relevant to their policies (Figures 3 and 4).

Figure 3: Outcomes driven by Docker Scout Policy.

Figure 4: Pull Request diff from the Scout GitHub Action.

But, finding and prioritizing the right problems is only half of the effort. For devs to truly “make things better,” the second step they must take is toward fixing these issues. According to a recent survey of 500 developers conducted by GitHub, the primary areas where development teams spend most of their time include writing code (32%) and identifying and addressing security vulnerabilities (31%). This is far from ideal, as it means that developers are spending less time driving innovation and user value. 

With Docker Scout, we aim to address this challenge head-on by providing developers access to automated, in-context remediation guidance (Figure 5). By actively suggesting upgrade and remediation paths, Docker Scout helps to bring teams’ container images back in line with policies, reducing their mean time to repair (MTTR) and freeing up more of their time to create value.

Figure 5: Example scenario for the ‘Base images not up to date’ policy.

While Docker Scout initially helps teams prioritize the direction of improvement, once all the existing critical software issues have been effectively addressed, developers can transition to employing the policies to achieve full compliance. This process ensures that going forward, all container images are void of the specific issues deemed vital to their organization’s code quality, compliance, and security goals. 

The Docker Scout team is excited to help our customers build software that meets the highest standards of safety, efficiency, and quality in a rapidly evolving ecosystem within the software supply chain. To get started with Docker Scout, visit our product page today.

Learn more

Visit the Docker Scout product page.

Looking to get up and running? Use our Quickstart guide.

Vote on what’s next! Check out the Docker Scout public roadmap.

Have questions? The Docker community is here to help.

New to Docker? Get started.

Quelle: https://blog.docker.com/feed/

Amazon EMR Studio bietet Unterstützung für interaktive Analysen auf Amazon EMR Serverless

Wir freuen uns, Ihnen heute mitteilen zu können, dass Sie interaktive Analysen für EMR-Serverless-Anwendungen aktivieren können. Mit diesem Start können Sie neben EMR auf EC2-Clustern und EMR auf virtuellen EKS-Clustern auch EMR Serverless-Anwendungen als Computer auswählen, um Jupyterlab Notebooks aus EMR-Studio-Workspaces auszuführen. Amazon EMR Studio ist eine integrierte Entwicklungsumgebung (IDE), die es Datenwissenschaftlern und Dateningenieuren leicht macht, Analytik-Anwendungen zu entwickeln, zu visualisieren und zu debuggen, die in R, Python, Scala und PySpark geschrieben wurden. Amazon EMR Serverless ist eine serverlose Option für Amazon EMR, die es einfach macht, Open-Source-Frameworks für Big-Data-Analysen, wie Apache Spark, auszuführen, ohne Cluster oder Server konfigurieren, verwalten und skalieren zu müssen.
Quelle: aws.amazon.com

Amazon EC2-Kapazitätsblöcke für ML

Heute kündigt AWS die allgemeine Verfügbarkeit von Amazon Elastic Compute Cloud (Amazon EC2)-Kapazitätsblöcken für ML an. Sie können EC2-Kapazitätsblöcke verwenden, um GPU-Instances in einem Amazon EC2 UltraCluster für einen zukünftigen Zeitpunkt für den Zeitraum zu reservieren, den Sie für die Ausführung Ihrer Machine Learning (ML)-Workloads benötigen. Dies ist eine innovative Methode zur Kapazitätsreservierung, bei der Sie GPU-Instances so planen können, dass sie an einem zukünftigen Datum genau für den Zeitraum verfügbar sind, für den Sie diese Instances benötigen. 
Quelle: aws.amazon.com

Ankündigung der Favorites-Funktion zur Organisation von AWS Systems Manager-Dokumenten und Runbooks in den Regionen AWS GovCloud (USA)

Heute freuen wir uns, Ihnen mitteilen zu können, dass Systems Manager Document Favorites in den AWS-Regionen GovCloud (USA) verfügbar ist. Favorites sind eine schnelle Möglichkeit für Kunden, ihre wichtigsten und am häufigsten verwendeten Dokumente und Runbooks zu finden und auszuführen. Dokumente und Runbooks definieren die Aktionen, die Systems Manager für Ihre verwalteten Instances und anderen AWS-Ressourcen ausführt. Jetzt können Sie bis zu 20 Ihrer bevorzugten Systems Manager-Dokumente oder Runbooks pro Kategorie auswählen, die dann auf einer zentralen Favoriten-Registerkarte in der Systems Manager Automation- oder Dokumente-Konsole angezeigt werden.
Quelle: aws.amazon.com

Amazon Translate führt die Anpassung der Kürze ein, um die Länge der Übersetzungsausgaben zu reduzieren

Amazon Translate ist ein neuraler, maschineller Übersetzungsservice, der schnelle, qualitativ hochwertige, erschwingliche und anpassbare Übersetzungen liefert. Heute stellen wir die Anpassung der Kürze vor, ein neues Feature von Amazon Translate, mit dem Kunden Übersetzungen im Vergleich zur Standardausgabe von Translate verkürzen können. Die Anpassung der Kürze reduziert die Kosten und den Aufwand, der für die manuelle Anpassung der Länge der maschinell übersetzten Ausgabe erforderlich ist.
Quelle: aws.amazon.com