Showing posts with label container images. Show all posts
Showing posts with label container images. Show all posts

Wednesday, October 18, 2023

Bitnami Vulnerability Database integrated with Trivy

A journey towards comprehensive vulnerability assessment

Authored by Juan Ariza, Senior member of technical staff


Bitnami images and the CVE Security Feed for Bitnami Components

Bitnami-packaged container images are well-known and trusted for being secure, hardened, and ready to use. They are built with best practices, put through extensive automated tests and verifications to run in their target platforms with the expected behavior and performance, and delivered as ready-to-use packages. Furthermore, they are kept up to date with the latest official upstream application versions and this has enabled Bitnami to offer updates including security fixes even before CVEs were announced or detected by the scanners on numerous occasions. In addition, they are continuously scanned to detect security vulnerabilities in the sources and components used by the application. The results of all these tests and validations are available for the enterprise version of these packages through the VMware Tanzu Application Catalog UI. 

Open Source Software (OSS) scanners have consistently identified most of the CVEs that impact our images. Nevertheless, because of Bitnami components’ custom build and packaging, some vulnerability scanners have struggled to detect vulnerabilities in them.

To better enable vulnerability scanners to detect vulnerabilities in our components, we have launched the Bitnami Vulnerability Database, a public CVE security feed available on GitHub with extensive information about the vulnerabilities on Bitnami components. 

Behind the scenes of Bitnami Vulnerability Database

In July 2023, Bitnami published its first CVE security feed — Bitnami Vulnerability Database — which is available on its public GitHub repository.

As part of getting this vulnerability database set up and ready to go, our team had to analyze how some popular scanners work, identify gaps in them, research how to make those scanners locate Bitnami Software Bill of Materials (SBoM), explore available vulnerabilities sources; and took inspiration from other public CVE security feeds available on GitHub such as the Golang Vulnerability database. After collecting the needed information, we created a cron job that uses the data from the National Vulnerability Database (NVD). This cronjob would extract all the CVE data required for analyzing Bitnami’s packaged applications, tools, and libraries, which enables us to report the vulnerabilities affecting each Bitnami component, and periodically update them.

Bitnami Vulnerability Database follows the Open Source Vulnerability schema — a standard format for distributing vulnerability information for open source — to create the JSON files that will assemble the security feed. Additionally, this enables the inclusion of the Bitnami Vulnerability Database as a part of the aggregated vulnerability database available at the Open Source Vulnerability Database (OSV). We see this as a significant accomplishment that can benefit our users as this initiative has been developed in collaboration with Open Source communities and has been adopted by several important security advisories. Also, this makes it possible for any security scanner that supports OSV schema to consume the Bitnami CVE security feed. 

As a culmination of all this work, we have been able to set up the Bitnami CVE security feed on GitHub, which can be browsed by anyone to find information about vulnerabilities in Bitnami components.

Integration of Bitnami Vulnerability database with Trivy

Trivy v0.42.0 came with support for analyzing Bitnami images’ SPDX files, and since then Trivy has been able to detect Bitnami SBOMs. However, Trivy couldn’t report vulnerabilities affecting the Bitnami components described in the SBOMs till now, as there was not a Bitnami CVE security feed available. 

After the Bitnami Vulnerability Database was published, the Bitnami team actively collaborated with Trivy to include this security feed as a part of its scanning capabilities. This enhancement was added as an experimental feature on version v0.45.0 and highlighted on Trivy release notes:



Trivy announcement of the Bitnami Vulnerability database integration 

Bitnami container images have a long-standing reputation for trustworthiness and security, consistently adhering to industry best security practices. We take pride in this integration, as it enhances users' awareness of Bitnami components, which have been specifically designed to contribute to a more secure software supply chain.

Trivy becomes the first security scanner to consume Bitnami Vulnerability Database but the journey doesn't end here. We will continue working on ensuring other popular security scanners consume it. Meanwhile, users who don’t use Trivy as their primary vulnerability scanner can also consume it since it is publicly available and works with any security scanner that supports OSV schema, and there are already a few scanners that have capabilities for detecting Bitnami SBOMs.

Support and Resources

Refer to the Bitnami and VMware Tanzu Application Catalog documentation to learn more about Kubernetes and Bitnami Helm charts and containers. 

To solve the problems you may have with the Bitnami community packages — including deployment support, operational support, and bug fixes — please open an issue in the Bitnami Helm charts or containers GitHub repository.  Also, if you want to contribute to the catalog, feel free to send us a pull request, and the team will check it and guide you in the process for a successful merge.   

If you are interested in learning more about the enterprise version of Bitnami packages — VMware Tanzu Application Catalog —  check out the product webpage, Tech Zone page,  application library, and additional resources. If you would like to get in touch,  contact us.

Friday, February 24, 2023

Bitnami ARM containers available at Docker Hub

VMware’s Bitnami team has achieved another big step in moving further its commitment to the development ecosystem:

🎉🎉 Bitnami containers have support for ARM and they are available at Docker Hub! 🎉🎉

Our Catalog has more than 200 million monthly pulls of our containers just from Docker Hub (and growing), so we had to do this effort thinking about our users. On the other hand, the team did its best to support the current catalog but in some cases, for example MongoDB, wasn’t able because there are no ARM binaries available for Debian 11.

More than a year and a half ago (mid 2021), Bitnami users started requesting us to provide support for ARM because Apple started with their M1 and also in the Hyperscalers the ARM adoption was planned to be done. So, after analyzing the needed efforts and seeing how important this feature was for our end users, we proceed to implement this.

Hyperscalers in 2022 provided their customers ARM architecture support (Google Cloud, AWS, and Azure) and there is also a great article written by Percona’s team doing an economical comparison of using different EC2 types in AWS, in the end, we can see how in terms of costs, Graviton (EC2 with ARM support) is a good choice in terms of pricing vs performance for database usage.

From VMware’s Bitnami team, we are happy to face this challenge and keep our aim committed to our users’ needs. We will keep working, as usual, thinking about end users' needs and, for sure, being vigilant to ensure the quality of our products become better.

From a technical point of view, the Bitnami container images are built as multi-arch images:

Bitnami etc Docker Hub view

This means users don’t need to specify anything when pulling the container images from Docker Hub, Docker (or any other software) will automatically pull the container image matching the host platform from which the pull command was issued.

Thanks for keeping your trust in us. Enjoy the ARM support!




Wednesday, July 28, 2021

VMware Joins Docker Verified Publisher Program with its Bitnami, Tanzu and Spring Cloud Products

“VMware is pleased to join the Docker Verified Publisher’s program. This provides developers unrestricted access to our artifacts and allows them to safely adopt the popular open-source technologies we’ve made available. We are excited that VMware Tanzu customers, in particular, will benefit from a wider range of complementary services they can leverage as they quickly get apps to market.” - Ashok Aletty, VP Engineering, VMware

In May 2021, Docker, IncTM announced the launch of its Docker Verified Publisher Program which helps developers recognize trusted publisher software. For development teams, this is huge, since this program simplifies the consumption of secure and verified components for them, as they build their applications.  

What is the Docker Verified Publisher Program? 

When building container-based applications or deployment templates such as Helm charts, it is a frequent practice to grab pre-built building blocks to quickly create application images. A common concern among developers is to make sure that the pieces being used to build their applications are secure, reliable, maintained and up to date. Nobody wants to spend time fixing security issues or exposing their software supply chain to malicious content.  

To make it easier to select robust, trusted, and reliable software when navigating through Docker Hub, Docker has launched the Docker Verified Publisher Program. With more than 200 ISVs and thousands of individual contributors delivering software through Docker Hub, the creation of a “Verified Publisher” badge enables development teams to quickly recognize trustworthy containerized images. Docker’s differentiated and trusted content can be used as reliable building blocks for quickly building, sharing, and running applications with complete confidence.  

In addition, developers will benefit from being exempt from rates limiting. This means that regardless of the Docker Hub subscription they opted for, they will have unlimited container image requests for Bitnami, Tanzu, and Spring cloud repositories.  



How can I find VMware Images Labelled “Verified Publisher”? 

VMware with its Bitnami, Tanzu, and Spring Cloud products has joined the Docker Verified Publisher program to enable developers to find trusted content for use in their application delivery pipeline.  

This will allow developers to have unlimited access to VMware’s robust and secure components.

From now on, all users, especially VMware Tanzu customers, will be able to accelerate time to market for their applications by accessing an extended offering of complementary services.  

As a part of VMware’s open-source offerings, Bitnami delivers more than 250 images labelled as “Verified Publisher” in Docker Hub. To discover them, navigate to Docker Hub and enable the “Verified Publisher” filter. You will see the “Verified Publisher” badge in the upper right corner of each image.  

Support and Resources 


Both the Tanzu Developer Center and the Bitnami Documentation Tutorials site are full of handy resources that will enable you to benefit from using VMware’s Docker Verified Publisher images when building your applications.  

Also, check out the VMware and Bitnami GitHub official repositories to contribute to these projects and to solve the problems you may have by opening an issue. Our support teams will be happy to help you there! 



Tuesday, September 8, 2015

Redis Security Release


Today, Redis released Redis 3.0.4, which patches several critical security issues. Redis suggests that all users upgrade to this new version.

Due to these security issues, we have released Bitnami Redis 3.0.4 in Google Cloud Platform and a Bitnami Redis container that fixes these issues. 

Have questions about Bitnami Redis or the security issue? Post to our community forum, and we would be happy to help you.

Tuesday, June 23, 2015

Bitnami Container Images for Docker - Now in Beta

We’re very happy to announce availability of the first set of Bitnami container images focused on the needs of application developers. We’ve been using containers internally for close to a year and have found them useful, both for local and cloud-based development and testing.

Bitnami container images can help you:
  • Reduce the time it takes to setup a developer on a new project
  • Reduce friction when sharing environments - experience less “but it worked on my machine?” 
  • Mix and match languages for specific projects - with consistency, regardless of the components you select
As with any rapidly evolving technology, we’ve run into a few bumps along the way, but believe that containers offer an interesting way to collaborate on your next software project and that they are complementary to our existing installers, virtual machines, and cloud images.

We’re starting small and initially focused on the needs of Web developers. Today we’re announcing beta Bitnami container images for nginx, php-fpm, mariadb, memcached, node, redis, apache, and ruby.

Our container images have been built around some key ideas we wanted, but found lacking, in other publicly available container images. Bitnami containers for Docker:
  • Share a common base OS (initially Ubuntu 14.04) to minimize time-to-get-started
  • Are kept up-to-date with consistent version tagging
  • Are easy to combine into a multi-tier application because they are consistently documented and take a standardized approach to configuration, bootstrapping, and logging
  • Separate data from code to enable upgrading of individual components
  • Include run-time notification of new versions
Bitnami container images are available now on the Docker Hub Registry and on GitHub. A walk-through of  how to use these container images to package a real-world application is also available.

We’re very interested in feedback from you on how these container images could be improved. Please open issues with ideas for enhancements or use cases on GitHub. We welcome contributions to the code, so please open a pull request if you have code to share.

Click here to get Bitnami container images for Docker.