容器镜像的漏洞修复方法、装置、设备及介质

By obtaining the target application identifier of the container image and automatically adding vulnerability patching code, the problem of low automation in the container image vulnerability patching process is solved, realizing full-process automated patching, meeting the needs of rapid iteration and instant response, and improving the security and configuration consistency of container images.

CN119397554BActive Publication Date: 2026-07-17CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD
Filing Date
2024-11-04
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In existing technologies, the vulnerability remediation of container images is difficult to meet the needs of rapid iteration and immediate response. It lacks an automated remediation and verification process, especially in continuous integration/continuous deployment pipelines where the integration level is low, resulting in a cumbersome and error-prone remediation process.

Method used

By obtaining the target application identifier in the container image, using the vulnerability remediation library to determine the vulnerability remediation code, and automatically adding it to the build documentation, the remediated target container image is built, achieving fully automated remediation throughout the entire process.

Benefits of technology

It enables automated patching of container image vulnerabilities, reduces manual intervention, meets the needs of rapid iteration and immediate response, and ensures the configuration consistency and security of container images in different environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119397554B_ABST
    Figure CN119397554B_ABST
Patent Text Reader

Abstract

本公开实施例涉及一种容器镜像的漏洞修复方法、装置、设备及介质,该方法包括:获取待修复容器镜像中目标应用程序的目标应用标识;在漏洞修复库中,根据目标应用标识确定对目标应用程序进行漏洞修复的漏洞修复代码;将漏洞修复代码添加至待修复容器镜像的第一层构建文档中,得到第二层构建文档;根据第二层构建文档构建目标容器镜像;其中,目标容器镜像为基于待修复容器镜像完成漏洞修复得到的容器镜像。由此,实现了基于现有漏洞对层构建文档的自动化修改,降低了漏洞修复过程中的人工干预,根据修改后的层构建文档生成对原始漏洞完成修复的容器镜像,实现了容器镜像漏洞的全流程自动化修复,能够较好的满足快速迭代和即时响应的需求。
Need to check novelty before this filing date? Find Prior Art