<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Michelle McAveety on</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/contributors/michelle-mcaveety/</link><description>Recent content in Michelle McAveety on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 14 Sep 2023 16:59:04 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/contributors/michelle-mcaveety/index.xml" rel="self" type="application/rss+xml"/><item><title>False positives and false negatives with container image scanners</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/false-results/</link><pubDate>Thu, 14 Sep 2023 16:59:04 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/chainguard/containers/security-and-compliance/working-with-scanners/false-results/</guid><description>&lt;p&gt;A &lt;em&gt;vulnerability scanner&lt;/em&gt; is a tool that analyzes your software components and reports any &lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve"&gt;CVEs&lt;/a&gt; it finds. Using a vulnerability scanner to find CVEs that impact your system is a critical step in &lt;a href="https://www.chainguard.dev/supply-chain-security-101/cve-remediation-explained"&gt;software vulnerability remediation&lt;/a&gt;, but as you begin to triage scanner-reported vulnerabilities, you may find that your scanner&amp;rsquo;s results are not perfectly accurate.&lt;/p&gt;
&lt;p&gt;The goal of a vulnerability scanner is to identify the vulnerabilities that impact your container images, which can be considered &lt;em&gt;true positive vulnerabilities&lt;/em&gt;. Sometimes, a scanner surfaces CVEs which are not actually impacting your images, which are called &lt;em&gt;false positive vulnerabilities&lt;/em&gt;. Your scanner may even miss some vulnerabilities that are impacting you, termed &lt;em&gt;false negative vulnerabilities&lt;/em&gt;.&lt;/p&gt;</description></item><item><title>Infamous software vulnerabilities</title><link>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/software-security/cves/infamous-cves/</link><pubDate>Fri, 21 Jul 2023 19:16:39 +0000</pubDate><guid>https://chainguard-docs-preview-git-fork-eslerm-eslerm-custom-id-f0ac5e.chainguard.app/software-security/cves/infamous-cves/</guid><description>&lt;p&gt;&lt;a href="https://www.chainguard.dev/supply-chain-security-101/what-is-a-cve"&gt;Software vulnerabilities&lt;/a&gt; vary in their severity – some are difficult to exploit and have minimal implications, while others can be exploited easily, giving an attacker significant leverage over a computer system. In cases where widely-implemented software contains high-severity vulnerabilities, the damage caused by their exploitation can affect millions of developers and services worldwide.&lt;/p&gt;
&lt;p&gt;In this article, you will learn how the KEV Catalog tracks known exploited software vulnerabilities, and how it serves as a tool for developers and federal agencies. In addition, you will explore Log4Shell, Heartbleed, and Shellshock, three infamous software vulnerabilities which have had major impacts on software security worldwide.&lt;/p&gt;</description></item></channel></rss>