Dalarna University's logo and link to the university's website

du.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • chicago-author-date
  • chicago-note-bibliography
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Jämförande analys av containerimage skanningsverktyg för användning i Azure DevOps-pipelines: Sårbarhetsidentifiering, gradering och tidsmässig effektivitet
Dalarna University, School of Information and Engineering.
Dalarna University, School of Information and Engineering.
2025 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesisAlternative title
Comparative analysis of container image scanning tools for use in Azure DevOps-pipelines : Vulnerability detection, severity grading and time efficiency (English)
Abstract [sv]

Inom mjukvaruutveckling är DevOps som arbetsmetod en förutsättning för att vara konkurrenskraftig. Många företag tillhandahåller mer eller mindre kompletta lösningar för att implementera DevOps och en av dessa är Microsofts AzureDevOps. En av fördelarna med denna lösning är möjligheten att automatisera delar av arbetsprocessen i en så kallad pipeline. Detta kan dock ske på bekostnad av säkerheten. För att säkerställa säkerheten behöver även skanningsverktyg implementeras i automatiseringen.

Som en del processen är det även vanligt virtualisera applikationer med hjälp av container-teknik. En container kan dock vara sårbar mot säkerhetshot vilket kan upptäckas vid säkerhetsskanningar. Genom att implementera virtualiseringen och skanningen i samma pipeline ökar man säkerheten samtidigt som man bibehåller effektiviteten.

Denna studie undersöker hur fyra populära skanningsverktygen skiljer sig åt i Azure DevOps-pipelines. Verktygen jämförs utifrån sårbarhetsidentifiering, gradering av sårbarheterna, implementationskomplexiteten samt exekveringstiden av skanningen. Detta utförs genom att använda en grundläggande YAML-kod för skapandet av en container-image och därefter implementeras samtliga verktyg i varsin pipeline. De verktyg som användes i studien är Docker Scout, Grype, Snyk och Trivy.

Experimentet genererade rapporter av de olika skanningsverktygen som sedan bidrar med information för att svara på forskningsfrågorna. De visade att det finns en marginell skillnad mellan Grype, Snyk och Trivy i antal identifierade sårbarheter. Docker Scout sticker ut från mängden med 80–85% färre identifierade sårbarheter än de andra verktygen.

Vidare syns en skillnad i hur verktygen graderar sårbarheterna. Snyk graderar 96% av sårbarheterna till lägsta allvarlighetsgraden, vilket är 28% fler än nästkommande verktyg (Trivy). Både Docker Scout och Snyk har fler steg innan användning, därför anses deras implementationskomplexitet högre än både Grype och Trivy.

Även tiden för de utförda skanningarna av verktygen varierade. Trivy var mest tidseffektiv då Grype och Snyk var 16% långsammare. Docker Scout däremot tog nästan 6 gånger längre tid för skanningen jämfört med Trivy.

Abstract [en]

DevOps is essential for competitiveness in software development; Azure DevOpsis one platform for this method. One of the advantages of DevOps is the ability to automate parts of the workflow in CI/CD pipelines. However, this can introduce security risks, making it necessary to integrate scanning tools. Applications are often virtualized using containers, which may contain vulnerabilities that can be identified by using these tools.

This study examines how four scanning tools differ in Azure DevOps pipelines. The tools are compared based on vulnerability identification, vulnerability grading, implementation complexity and scan execution time. The tools used in the study are Docker Scout, Grype, Snyk and Trivy.

The result shows that there is a marginal difference between Grype, Snyk and Trivyin the number of identified vulnerabilities. Docker Scout stands out by reporting 80–85% fewer vulnerabilities than the other tools.

Furthermore, it’s a clear difference in how the tools grade the vulnerabilities. Snyk grades 96% of the vulnerabilities to the lowest severity level, which is 28% more than the next tool (Trivy). Both Docker Scout and Snyk require more steps before they can be used, which makes their implementation more complex compared to Grype and Trivy.

The time for the scans performed by the tools also varied. Trivy was the most efficient as Grype and Snyk were 16% slower. Docker Scout, on the other hand, took almost 6 times longer to scan compared to Trivy. 

Place, publisher, year, edition, pages
2025.
Keywords [en]
Virtualization, implementation complexity, security, ci/cd
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:du-50763OAI: oai:DiVA.org:du-50763DiVA, id: diva2:1975493
Subject / course
Microdata Analysis
Available from: 2025-06-24 Created: 2025-06-24 Last updated: 2025-10-09

Open Access in DiVA

fulltext(977 kB)70 downloads
File information
File name FULLTEXT01.pdfFile size 977 kBChecksum SHA-512
0dbe141389ddd1a52369682238b490e232ce0b3818b2bd14d1fad12263c1a3f113d2395addfdc21c93080d2dd445fd70f22f443d6c8d71d95fbe2ccd6039cba5
Type fulltextMimetype application/pdf

By organisation
School of Information and Engineering
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 70 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 123 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • chicago-author-date
  • chicago-note-bibliography
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf