GitLab: DevSecOps: Part 6/12: How to use Container Scanning

Опубликовано: 29 Апрель 2026
на канале: Romano Roth
9,158
70

How to do Container Scanning 📦 in GitLab?
Session 6: In this video, Padi and I will show you how to find vulnerabilities in your container images with GitLab.

▬▬▬▬▬▬ T I M E S T A M P S ⏰ ▬▬▬▬▬▬
00:00 Welcome
00:12 Intro
00:17 DevSecOps with GitLab
01:03 What is container scanning?
02:24 How to enable Container Scanning in GitLab
03:02 How to create the docker image
03:51 How to push the container image to the registry
05:15 How to use Docker in Docker (dind)
05:41 Make the image name available in the container scan job
06:14 Demo
06:42 Change the docker image
07:35 Enable Container Scanning in GitLab
08:49 Add the build image job
11:01 Recap
11:57 Pipeline results
12:09 container_scanning job results
12:23 Discussion why the pipeline is not failing
15:12 Security tab
15:45 Vulnerability report
16:06 Summary

▬▬▬▬▬▬ L I N K S 🔗▬▬▬▬▬▬
Source Code
https://gitlab.com/romano_roth/gitlab...
Blog-Post
https://www.romanoroth.com/post/gitla...
GitLab
https://about.gitlab.com/
Patrick Steger
  / patrick-steger-ch  
Container Scanning in GitLab
https://docs.gitlab.com/ee/user/appli...

▬▬▬▬▬▬ Want to learn more? 🚀 ▬▬▬▬▬▬
Session 1: What is GitLab 🦊? | The fundamental concepts
   • GitLab: DevSecOps: Part 1/12: What is GitL...  
Session 2: Introduction to GitLab 🦊 | Creating a simple project
   • GitLab: DevSecOps: Part 2/12: Introduction...  
Session 3: What is Software Composition Analysis (SCA) 🧩 in GitLab?
   • GitLab: DevSecOps: Part 3/12: Learn How to...  
Session 4: How to ensure License Compliance 📜 in GitLab?
   • GitLab: DevSecOps: Part 4/12: How to ensur...  
Session 5: How to do Static Application Security Testing (SAST) 🛡️ in GitLab?
   • GitLab: DevSecOps: Part 5/12: Protect your...  
Session 6: How to do Container Scanning 📦 in GitLab?
   • GitLab: DevSecOps: Part 6/12: How to use C...  
Session 7: What is Secret Detection 🤫?
   • GitLab: DevSecOps: Part 7/12: How to find ...  
Session 8: Dynamic Application Security Testing (DAST)
   • GitLab: DevSecOps: Part 8/12: How to use D...  
Session 9: What is Vulnerability Management 📝?
   • GitLab: DevSecOps: Part 9/12: Overcoming V...  
Session 10: How to do a Merge Request in GitLab
   • GitLab: DevSecOps: Part 10/12: How to do a...  
Session 11: How to do a Schedule Pipeline in GitLab?
   • GitLab: DevSecOps: Part 11/12: How to buil...  
Session 12: Our Recommendations
   • GitLab: DevSecOps: Part 12/12: How to buil...  

▬▬▬▬▬▬ S U B S C R I B E 🔔 ▬▬▬▬▬▬
╔═╦╗╔╦╗╔═╦═╦╦╦╦╗╔═╗
║╚╣║║║╚╣╚╣╔╣╔╣║╚╣═╣
╠╗║╚╝║║╠╗║╚╣║║║║║═╣
╚═╩══╩═╩═╩═╩╝╚╩═╩═╝
   / @romanoroth  

▬▬▬▬▬▬ Connect with me 👋 ▬▬▬▬▬▬
LINKEDIN ►   / romanoroth  
TWITTER ►   / romanoroth  
INSTAGRAM ►   / romanoroth  
FACEBOOK ►  / romanoroth  
MEETUP ► https://www.meetup.com/de-DE/DevOps-M...
CONFERNCE ►https://www.devopsdays.ch/
HOMEPAGE ► https://www.romanoroth.com/

▬▬▬▬▬▬ P L A Y L I S T S ▶️ ▬▬▬▬▬▬
Software Testing    • Quality Assurance  
Extreme Programing    • Playlist  
Business Process Management    • Playlist  

#DevSecOps #DevOps #GitLab #RomanoRoth