Category: Security

  • Static Analysis of Docker image vulnerabilities with Clair

    Static Analysis of Docker image vulnerabilities with Clair

    In a previous article, we described how to build a Docker Registry. Today we look at Clair – a tool that does static analysis of vulnerabilities in a docker image. What is Clair? Clair is a popular open source vulnerability scanning solution for docker images made by CoreOS. Clair is also integrated with quay.io public…

    Petr Kohut
    Security | 13th November 2018
  • Putting security into DevOps Practices

    DevOps: 7 Reasons to Automate Security in your Pipelines

    The DevSecOps Evolution: Incorporating Security into DevOps Practices According to IDC estimates, the worldwide DevOps software market achieved a level of $2.9 billion in 2017 and is forecast to reach $6.6 billion in 2022. Driven by the need for faster innovation, a shift towards microservices architectures, and the evolution of automation and collaboration tooling, the…

    David Gonzalez
    Security | 1st October 2018
  • Public Docker Registry in Kubernetes

    How to run a Public Docker Registry in Kubernetes

    Introduction As a member of NearForm’s DevOps team, I spend a lot of my time working with containers in Kubernetes. In the article, I will cover the creation of publicly accessible Docker Registry running in Kubernetes. For the sake of keeping things simple and short, I will use basic authentication for the registry and Kubernetes…

    Petr Kohut
    Security | 12th September 2018
  • Zed Attack Proxy in a CI Pipeline?

    Adding Automated Penetration Testing to Continuous Integration Pipelines Testing, particularly around security, is a core part of the ethos of all nearForm development teams. In many organisations, penetration testing can often happen just before a product first pushes to production, and periodically thereafter. Penetration testing is performed by external teams and is focused on finding…

    Mihovil Rister
  • Comparing NPM Audit with SNYK

    Comparing npm audit with Snyk

    At NearForm, we specialize in building practical software solutions for our clients and part of designing and building a modern solution is making it secure. In today’s world where almost everything is connected and operated by computers, adding security on-top, as an afterthought no longer works. As software architects and engineers, we also focus on…

    Igor Shmukler
    Security | 17th August 2018
  • Dynamic Intrusion Detection for Authorisation Systems like Udaru

    Dynamic Intrusion Detection for Authorisation Systems like Udaru

    Developing an automated intrusion detection system for Udaru using statistical modelling.

    Andreas Madsen
    Data Visualisation, Security | 11th June 2018
  • How NearForm approaches SQL Injection Prevention

    What are SQL injections and how nearForm fights with them?

    Ivan Jovanovic
    Security | 26th March 2018
  • Making Promises safer in Node.js

    Making Promises safer in Node.js

    Promises can be a powerful choice for a Node.js project, but there are some pitfalls to be aware of.

    Matteo Collina
    Node.js, Security | 27th November 2017
  • Top