SOFTWARE IMAGE UPDATE MANAGEMENT PLATFORM
A system and method for software image management. A method includes generating a plurality of software packages, wherein each software package is generated using a respective set of code; building a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding software image; and storing the plurality of software images in a repository.
1 . A method for software image management, comprising:
generating a plurality of software packages, wherein each software package is generated using a respective set of code;
building a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding software image; and
storing the plurality of software images in a repository.
2 . The method of claim 1 , further comprising:
configuring each of the plurality of software images based on the plurality of files, wherein the set of instructions for each file further defines a configuration for the corresponding software image.
3 . The method of claim 1 , further comprising:
monitoring for changes to a plurality of portions of code among the plurality of software packages;
identifying an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and
rebuilding at least one software image of the plurality of software images using a new version of the at least one portion of code.
4 . The method of claim 3 , further comprising:
classifying the identified update into a classification; and
selecting the at least one software image to be rebuilt based on the classification.
5 . The method of claim 4 , wherein the classification indicates that the change in the at least one portion of code is a change to patch a vulnerability.
6 . The method of claim 1 , wherein the plurality of software images corresponds to a plurality of software components, further comprising:
ingesting cybersecurity data from a computing environment in which the plurality of software components is deployed;
identifying a vulnerability being exploited based on the ingested cybersecurity data; and
rebuilding at least one software image of the plurality of software images, wherein the rebuilt at least one software image include a vulnerable software package of the plurality of software packages, wherein the vulnerable software package has the identified vulnerability.
7 . The method of claim 6 , further comprising:
redeploying the rebuilt at least one software image.
8 . The method of claim 1 , wherein each software package is a code unit defined with respect to at least one function.
9 . The method of claim 1 , wherein the set of code used to generate each software package of the plurality of software packages includes at least one binary and at least one associated file.
10 . A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:
generating a plurality of software packages, wherein each software package is generated using a respective set of code;
building a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding software image; and
storing the plurality of software images in a repository.
11 . A system for software image management, comprising:
a processing circuitry; and
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
generate a plurality of software packages, wherein each software package is generated using a respective set of code;
build a plurality of software images based on a plurality of files, wherein building each software image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding software image; and
store the plurality of software images in a repository.
12 . The system of claim 11 , wherein the system is further configured to:
configure each of the plurality of software images based on the plurality of files, wherein the set of instructions for each file further defines a configuration for the corresponding software image.
13 . The system of claim 11 , wherein the system is further configured to:
monitor for changes to a plurality of portions of code among the plurality of software packages;
identify an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and
rebuild at least one software image of the plurality of software images using a new version of the at least one portion of code.
14 . The system of claim 13 , wherein the system is further configured to:
classify the identified update into a classification; and
select the at least one software image to be rebuilt based on the classification.
15 . The system of claim 14 , wherein the classification indicates that the change in the at least one portion of code is a change to patch a vulnerability.
16 . The system of claim 11 , wherein the plurality of software images corresponds to a plurality of software components, wherein the system is further configured to:
ingest cybersecurity data from a computing environment in which the plurality of software components is deployed;
identify a vulnerability being exploited based on the ingested cybersecurity data; and
rebuild at least one software image of the plurality of software images, wherein the rebuilt at least one software image include a vulnerable software package of the plurality of software packages, wherein the vulnerable software package has the identified vulnerability.
17 . The system of claim 16 , wherein the system is further configured to:
redeploy the rebuilt at least one software image.
18 . The system of claim 11 , wherein each software package is a unit of code defined with respect to at least one function.
19 . The system of claim 11 , wherein the set of code used to generate each software package of the plurality of software packages includes at least one binary and at least one associated file.