Project challenges / verified progress
Beacon: package it so anyone can run it

The engineering notebook

Inventory the image

How do you know what is inside an image you built?

Loading statusStage 7 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Phase 3 — Publish, inspect, prove

Step 01 of 06

Learn the concept

Log4Shell hurt partly because many teams did not know where Log4j was running. The panic was not only the bug; it was the inventory failure. An SBOM is the boring list you wish you already had when a CVE lands on a Friday.

ONE IMAGE THREE QUESTIONSBeacon imagedigest pinned artifactSBOMwhat packages existSyftScanwhich CVEs matchGrypeTriagefix or accept riskhuman
The image does not become safer because a scanner looked at it. It becomes more governable because you can name its contents, match advisories, and decide what actually needs a rebuild.
Step 01

The ideas this is made of

An SBOM is inventory, not a verdict

SPDX and CycloneDX documents list components, versions, relationships, and sometimes licences. They do not say the system is safe. They say what is present. That is still powerful: when CVE-2021-44228 landed, teams with inventories could search for Log4j versions. Teams without inventories searched production by folklore.

Scanners match databases to discovered packages

Grype and Trivy compare the SBOM or image contents with vulnerability databases. The output names a package, installed version, vulnerability ID, severity, and fixed version when known. If the package is not detected, the scanner cannot warn you. If the database is stale, the answer is stale. Tools are evidence, not oracles.

CVSS is a signal, not a pager policy

CVSS scores estimate technical severity. They do not know whether Beacon reaches the vulnerable code path, whether the container is exposed to untrusted input, or whether a fixed image exists. A critical CVE in an unused library and a medium CVE on an internet-facing parser can deserve opposite urgency. Triage beats panic.

Fixed-in matters more than fear

A useful scanner result says which version fixes the issue. If no fix exists, the answer may be mitigation: disable a feature, restrict exposure, or accept documented risk for a short window. Rebuilding the same Dockerfile against the same vulnerable base image changes the timestamp and little else.

Generate then scan an SBOM
syft beacon:runtime -o spdx-json=sbom.spdx.json
grype sbom:sbom.spdx.json --fail-on critical

The first command creates an inventory file. The second scans that inventory and exits non-zero only for critical matches, which is a policy choice you can state and review.

SBOM formats and scanners

Tool or formatPurposeTypical command

SPDX

Legal and package inventory

syft -o spdx-json

CycloneDX

Security inventory

syft -o cyclonedx-json

Syft

Generate the inventory

syft image:tag -o ...

Grype

Match CVEs

grype sbom:sbom.spdx.json

Trivy

Scan image or SBOM

trivy image image:tag

What these are called on the job

  • SBOM — Software Bill of Materials: an inventory of components in an artifact.

  • CVE — A public identifier for a known vulnerability, such as CVE-2021-44228.

  • CVSS — A scoring system estimating vulnerability severity from technical factors.

  • EPSS — A probability estimate that a vulnerability will be exploited in the wild.