Skip to content

Feature/lab7#568

Open
nikolashinamary wants to merge 4 commits intoinno-devops-labs:mainfrom
nikolashinamary:feature/lab7
Open

Feature/lab7#568
nikolashinamary wants to merge 4 commits intoinno-devops-labs:mainfrom
nikolashinamary:feature/lab7

Conversation

@nikolashinamary
Copy link

@nikolashinamary nikolashinamary commented Mar 15, 2026

Goal

Complete Lab 7 by analyzing the Juice Shop container image, reviewing Docker host CIS benchmark results, and
comparing default vs hardened deployment profiles.

Changes

  • Added labs/submission7.md with Task 1-3 analysis.
  • Added Lab 7 scan artifacts under labs/lab7/scanning/, labs/lab7/hardening/, and labs/lab7/analysis/.
  • Documented vulnerability findings, CIS benchmark observations, deployment hardening trade-offs, and
    recommendations.

Testing

  • Ran Docker Scout CVE scan on bkimminich/juice-shop:v19.0.0.
  • Ran Snyk image scan and compared results.
  • Ran Dockle configuration scan.
  • Ran Docker Bench Security for CIS benchmark checks.
  • Verified default, hardened, and production container profiles returned HTTP 200.

Artifacts & Screenshots

  • labs/submission7.md
  • labs/lab7/scanning/scout-cves.txt
  • labs/lab7/scanning/snyk-results.txt
  • labs/lab7/scanning/dockle-results.txt
  • labs/lab7/hardening/docker-bench-results.txt
  • labs/lab7/analysis/deployment-comparison.txt

Checklist

  • Clear title provided
  • Documentation updated if needed
  • No secrets or large temporary files included

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant