Skip to content

Releases: slimtoolkit/slim

Bug fixes and UX improvements

21 Jun 03:41
@kcq kcq
Compare
Choose a tag to compare

Improvements

  • Ability to detect additional shells.
  • Saving command report to /tmp directory if it's not possible to save it in the current working directory.
  • Printing tag information for build command.

Bug Fixes

  • Default continue-after value handling fix (remove probe mode if http probing is disabled).
  • Sensor not exiting when it's trying to copy a directory it already copied.

Binaries

Build them from source or download from a CDN location:

Many new xray capabilities including duplicate file, utf8 file and shell detection

14 Jun 18:05
@kcq kcq
Compare
Choose a tag to compare

New Features

  • Ability to find duplicate files for xray (--detect-duplicates, --show-duplicates)
  • Ability to find all utf8 encoded files for xray using the --detect-utf8 flag (optionally dumping them to console, directory or tar file).
  • Ability to find the files with special permissions (--show-special-perms).
  • Ability to find all installed shells for xray.
  • Container entry information for xray with file detection.
  • Inherited image instructions (aka ONBUILD instructions) for xray.
  • More image level stats for xray.

Improvements

  • Multiple tags for the build command.
  • --http-probe-off flag for the build command to provide a shortcut to disable HTTP probing.
  • Flexible target image handling to use non-default tags if the latest tag doesn't exist and no explicit tag is provided.

Binaries

Build them from source or download from a CDN location:

New XRAY capabilities, application probing enhancements, many new build, runtime and optimization flags and colors for the console output.

15 Apr 03:20
@kcq kcq
Compare
Choose a tag to compare

New Features

  • Console color output (on by default; disable with no-color)
  • Loading http probe request data from separate files
  • Ability to execute external probe commands (--http-probe-exec and --http-probe-exec-file flags)
  • Ability to preserve original files in the target container discarding its test runtime data (--preserve-path and --preserve-path-file)
  • Ability to pull container images if they don't exist locally yet (--pull and --show-plogs)
  • File hashing for xray (--hash-data)
  • Additional flags to control the xray command executions (--top-changes-max, --reuse-saved-image)
  • Ability to match by file path, file data and file hash for xray (--change-path value, --change-data value, --change-data-hash value)

Improvements

  • Lots of additional container build flags (--tag-fat, --cbo-add-host, --cbo-build-arg, --cbo-label, --cbo-target, --cbo-network, --cbo-cache-from).
  • Additional container runtime flags (--cro-runtime)
  • sigint should kill the running container (#186)

Bug Fixes

  • Various xray image layer inspection bug fixes

Binaries

Build them from source or download from a CDN location:

New XRAY command flags, bug fixes and UX improvements

29 Jan 22:40
@kcq kcq
Compare
Choose a tag to compare

New Features

  • New xray flags to control what layer change data to include in the generated reports (layer-changes-max, all-changes-max, add-changes-max, modify-changes-max, delete-changes-max)

Improvements

  • host network flag handling enhancements.
  • Returning non-zero exit codes on failures
  • Additional image checks to catch missing ENTRYPOINT/CMD instructions

Bug Fixes

  • Fixed container image listing bug that broke the --target value suggestions in the interactive prompt mode.

Binaries

Build them from source or download from a CDN location:

exec/exec-file build flags, cleanup and bug fixes

15 Dec 18:45
@kcq kcq
Compare
Choose a tag to compare

New Features

  • Ability to interact with the temporary containers using the new --exec and --exec-file flags (thanks to @nathants).

Improvements

  • NPM support enhancements
  • Various bug fixes

Binaries

Build them from source or download from a CDN location:

seccomp generation and external test integration improvements

24 Aug 07:47
@kcq kcq
Compare
Choose a tag to compare

New Features

  • Mapping container ports to specific host ports analyzing image at runtime (--publish-port and --publish-exposed-ports flags)

Improvements

  • seccomp security profile generation capability updates
  • User namespace handling improvements (thanks to @solarnz)

Binaries

Build them from source or download from a CDN location:

Experimental lint command, HTTP crawling and other improvements

27 Jul 21:48
@kcq kcq
Compare
Choose a tag to compare

New Features

  • lint command (initial Dockerfile linting capabilities with a basic set of checks)
  • HTTP probe crawler (automatically probes additional endpoints referenced in the processed targets; see the --http-probe-crawl and related flags)

Improvements

  • ARM64 support (need more people to test!)
  • --http-probe-exit-on-failure flag to exit execution when all HTTP probe calls fail
  • --include-bin-file and --include-exe-file flags to make it easier to specify multiple binaries and executables loading them from files
  • xray command report enhancements

Binaries

Build them from source or download from a CDN location:

Interactive CLI prompt and xray command improvements

18 Mar 19:25
@kcq kcq
Compare
Choose a tag to compare

New Features

  • Interactive CLI prompt. For more info about the interactive prompt see go-prompt.

Improvements

  • xray command output improvements
  • Additional image data saved with the xray command reports (--add-image-manifest and --add-image-config flags)

Binaries

Build them from source or download from a CDN location:

xray command improvements with more information and more command parameters

10 Mar 01:57
@kcq kcq
Compare
Choose a tag to compare

New Features (includes 1.28.0)

  • xray command enhancements to show the detailed container image information including its layers and their files and directories (initial version).

Enhancements

  • New xray parameters to control how much to show when it's printing the layer details (--changes value and --layer value)
  • Image history enhancements and more data saved in the xray command reports
  • The --exclude-pattern build parameter to filter/exclude the artifacts in the optimized container.

Binaries

Build them from source or download from a CDN location:

Enhanced xray command to show the detailed container image information including its layers and their files and directories

07 Mar 07:34
@kcq kcq
Compare
Choose a tag to compare

Status

Outdated (use the new 1.28.1 release instead)

New Features

  • xray command enhancements to show the detailed container image information including its layers and their files and directories (initial version).

Enhancements

  • The --exclude-pattern build parameter to filter/exclude the artifacts in the optimized container.

Binaries

Build them from source or download from a CDN location: