Skip to main content

Scan vulnerabilities

TL;DR

Log in to the Marketplace to access vulnerability and SBOM reports from an intuitive dashboard.

🌟 Status: Live

Did you know?

Even though the Compute running this service is on Testnet, it enjoys the same level of underlying security and orchestration that will be provided via Mainnet.

Overview​

The NopeOps Marketplace Dashboard provides an integrated vulnerability scanner to allow you to verify the integrity of:

  • 🚧 Codebases / repositories
  • Public Docker images (including Marketplace templates)

Prerequisites​

  • Marketplace account
  • For recurring scans, a registered email
  • Publicly-available resource to assess

Scan for vulnerabilities with Security Hub​

This guide supports you to understand how to scan for vulnerabilities with the NodeOps Marketplace Security Hub. Use the video or steps to understand the flow.

Step 1: Access the tool​

Logged in from your account, navigate the left hand menu to Security Hub.

Show me
Scan your resources for vulnerabilities with popular scanning tools from your NodeOps network Dashboard

Step 2: Scan your resource​

  1. Click Upload for Scanning.
Show me
Name docker image resource to scan for vulnerabilities in NodeOps Network Security Hub Dashboard
  1. Enter a publicly-available Docker image name and choose scan type:
  • Vulnerability
  • SBOM
Show me
Image showing process to request scan of a resource within NodeOps Network Dashboard
  1. (Optional) Click Enable Recurring Scan. This requires that you have an email linked to your Marketplace account to receive alerts on.

Step 3: Review the analysis​

tip

You may view the scan's progress by clicking the resource name.

Show me
Image showing scanned resource in the NodeOps Network Dashboard
  1. Once the scan is complete, click the resource name to view a summary.

Reload the page if necessary.

Show me
Image showing scanned resource in the NodeOps Network Dashboard
  1. Click the summary block to deep dive into the scan details.
Show me
Image showing scan summary providing total number of vulnerability issues detected and critical status of the issues in the NodeOps network Dashboard

Congratulations: you can now deep-dive into the vulnerabilites identified by the scanner.

Image showing details of the vulnerability issues detected and severity statuses of the issues with a resource scanned by  the NodeOps network Dashboard

What next?​