Summary
Tern is an SBOM Generator for Docker Images on Linux. Tern makes use of various shell scripts to parse through the various layers used to build Docker Containers to create very detailed reports about each layers respective dependencies. The tool can also can create a series of SBOMs, including SPDX and CycloneDX SBOMs. Additionally, Tern has a Docker-Lock feature, which takes Dockerfiles and converts them into more runtime-accurate versions like other lock files. In this video, we will demonstrate how to use Tern to its fullest.
Chapters
0:00 Intro
0:39 Installation and Setup: pip
1:23 Scan Docker Image
1:50 Scan Docker File
2:40 More About Tern Layers
3:24 Output Formats
3:58 Write to File
4:27 Generating Docker Lock Files
5:30 Installation and Setup: Docker
6:14 Docker: Printing to stdout
6:44 Docker: Writing to Files
7:37 Tern Plugins: Overview
8:06 Tern Runtime Disclaimer
8:42 Tern Plugins: Scancode Overview
9:24 Tern Plugins: cve-bin-tool Overview
9:51 Tern GitHub Action Overview
10:18 Final Thoughts
10:41 Thank You for Watching!
Resources
🎯 GitHub: https://github.com/tern-tools/tern
🎯 Tern GitHub Action: https://github.com/marketplace/action...
🎯 Tern GitHub Action Demo Repo: https://github.com/JeroenKnoops/tern-...
🎯 Scancode: https://github.com/nexB/scancode-toolkit
🎯 cve-bin-tool: https://github.com/intel/cve-bin-tool
🎯 Learn More About CycloneDX: https://cyclonedx.org/
🎯 Learn More About SPDX: https://spdx.dev/
More Great SBOM Resources!
🌐 https://learnsbom.com
Contact Us!
📨 [email protected]
#DockerImages #SecurityScanner #Linux