A Security Review of Docker Official Images: Which Do You Trust?
ID: 889efa89-1b2e-5cbe-8792-39d496248a91
STIX ID: report--889efa89-1b2e-5cbe-8792-39d496248a91
Feed Name: Aqua Security Blog
This research examines 167 Docker Official Images using Trivy and the Docker Hub API, finding a number of official images that are deprecated or unmaintained and several with large numbers of unpatched vulnerabilities (examples: nuxeo 186, backdrop 173, centos 86). The report notes that deprecation notices are not always visible in the official image listing, documents download counts showing continued heavy usage of some vulnerable images (e.g., centos ~7.3M pulls), and recommends maintaining controlled base images and tracking image maintenance to mitigate supply-chain risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
