DevOps Foundations · Module 8: Security and safe-change basics · Lab
Triage a Fixture Scan Report with Risk and Workable Fixes
45 min hands-on · Core
A fixture vulnerability scan report (60-ish findings across app, base image and dev dependencies) under /tmp/dlab-m08-02.
Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.
Objectives
- Rank every finding by reachability, exploitability and blast radius
- Fix or mitigate the top findings with verification
- Write dated, owned accepts for the remainder
Step 1
Rank by real risk
Score each finding on reachability, exploitability and blast radius. Separate the handful that deserve the sprint from unreachable noise and unfixable notices, with reasons.
Step 2
Fix what works
Apply workable fixes to the top findings (upgrade, rebuild from current base, or isolate) and verify each: trigger input now benign, rescan cleaner, or exclusion proven for runtime.
Step 3
Accept the rest properly
Write accepts with expiry dates and owners for genuinely low risk, plus a note for unfixable notices. File the triage as the deliverable.
How to confirm it worked
- Every finding ranked with stated reasons
- Top findings fixed or mitigated with verification quoted
- Remaining accepts dated, owned and expiring
- Triage filed showing risk-first ordering, not score order