mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-07-23 21:21:00 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
+16
@@ -0,0 +1,16 @@
|
||||
# Standards - Distroless Container Images
|
||||
|
||||
## NIST SP 800-190
|
||||
- Section 3.1.1: Minimize image content to reduce attack surface
|
||||
- Section 4.1.1: Use minimal base images for container builds
|
||||
|
||||
## CIS Docker Benchmark v1.6
|
||||
- 4.1: Ensure a user for the container has been created
|
||||
- 4.2: Ensure containers use trusted base images
|
||||
- 4.6: Ensure HEALTHCHECK instructions have been added
|
||||
- 4.9: Ensure COPY is used instead of ADD
|
||||
|
||||
## OWASP Docker Security
|
||||
- D2: Patch Management Strategies (fewer packages = fewer patches)
|
||||
- D3: Network Segmentation and Firewalling
|
||||
- D4: Secure Defaults and Hardening (no shell = hardened by default)
|
||||
+19
@@ -0,0 +1,19 @@
|
||||
# Workflows - Distroless Container Images
|
||||
|
||||
## Migration Workflow
|
||||
1. Identify current base image and its package footprint
|
||||
2. Select appropriate distroless variant for your runtime
|
||||
3. Create multi-stage Dockerfile with build and runtime stages
|
||||
4. Test application functionality with distroless base
|
||||
5. Scan both old and new images to compare CVE counts
|
||||
6. Update debugging procedures (ephemeral containers, debug variants)
|
||||
7. Deploy to staging and validate
|
||||
8. Roll out to production
|
||||
|
||||
## Image Build Pipeline
|
||||
1. Build application in builder stage (full SDK image)
|
||||
2. Copy only runtime artifacts to distroless stage
|
||||
3. Set non-root user via `:nonroot` tag
|
||||
4. Scan final image with Trivy/Grype
|
||||
5. Sign image with cosign
|
||||
6. Push to registry with digest pinning
|
||||
Reference in New Issue
Block a user