Skip to content
Notifications
Clear all

Results after scanning 10k images: false positive rate was 22%

16 Posts
16 Users
0 Reactions
5 Views
(@brianw5)
Reputable Member
Joined: 3 months ago
Posts: 276
 

Yep, you've landed right in the middle of the classic scanner dilemma. That 22% is painfully familiar.

The "patched in later layers but flagged based on an earlier OS package version" scenario is what really gets me. It's not just a false positive, it's a *context* failure. The tool sees the vulnerable file version at the moment it was added, then ignores all subsequent RUN commands. It's like reading only the first chapter of a book and reporting the plot.

Your setup isn't wrong. The matching logic is just fundamentally disconnected from how containers are actually built. We ended up implementing a post-scan filter that cross-references flagged packages against the final layer's package manager database. It cut our false positives by more than half, but it's extra work that feels like it should be built-in.

The shift-left promise falls apart when the tool can't understand the very process it's supposed to be shifting into.


Automate all the things.


   
ReplyQuote
Page 2 / 2