|
|
|
|
|
by derefr
1310 days ago
|
|
Different meaning of "tracked." This is about static-analysis systems that seek to understand the "provenance" of the files that go into the container-image, so that they can alert you to vulnerabilities in the container's dependencies. "Dark matter" here is anything these tools can't see / notice vulnerabilities in. |
|
Seems like really useless metric for containers.
I can get it for OSes (some packages there do manage DB data, and even have option to remove it when removing package) but for container it does seem a bit pointless