The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Foundations · Module 8: Security and safe-change basics · Lab

Triage a Fixture Scan Report with Risk and Workable Fixes

45 min hands-on · Core

A fixture vulnerability scan report (60-ish findings across app, base image and dev dependencies) under /tmp/dlab-m08-02.

Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.

Objectives

  • Rank every finding by reachability, exploitability and blast radius
  • Fix or mitigate the top findings with verification
  • Write dated, owned accepts for the remainder
  1. Step 1

    Rank by real risk

    Score each finding on reachability, exploitability and blast radius. Separate the handful that deserve the sprint from unreachable noise and unfixable notices, with reasons.

  2. Step 2

    Fix what works

    Apply workable fixes to the top findings (upgrade, rebuild from current base, or isolate) and verify each: trigger input now benign, rescan cleaner, or exclusion proven for runtime.

  3. Step 3

    Accept the rest properly

    Write accepts with expiry dates and owners for genuinely low risk, plus a note for unfixable notices. File the triage as the deliverable.

How to confirm it worked

  • Every finding ranked with stated reasons
  • Top findings fixed or mitigated with verification quoted
  • Remaining accepts dated, owned and expiring
  • Triage filed showing risk-first ordering, not score order