anaconda3:2024.10-1 container isolation score: 48/100 (grade D)¶
Run with plain docker run continuumio/anaconda3:2024.10-1 defaults, no hardening flags, the anaconda3 image scores 48/100, grade D (porous) on IronClaw's seven-dimension container containment scale. Higher is safer. This is what you get straight out of a copy-pasted docker run; the fixes below show where the lost points are.
Graded from a read-only inspect of a running container started from
continuumio/anaconda3:2024.10-1at digestsha256:b2c5350cc4e2338a1705c15dcca4fff520b1728f49752d390d92aaec02cf8c3awith plaindocker rundefaults, its entrypoint overridden withsleeppurely to keep it alive. The scan itself executes nothing inside the container. Scoring an image reference instead of a running container yields a different, non-comparable result. How scoring works →
How it scores, dimension by dimension¶
| Dimension | Verdict | Score | What the scan found |
|---|---|---|---|
| Non-root user (uid != 0) | ❌ FAIL | 0/15 | runs as root (user "0 (default)"); a container escape starts with host-uid 0 |
| Dropped capabilities | ❌ FAIL | 4/20 | default capability set retained (includes CAP_NET_RAW, CAP_MKNOD, …) |
| Seccomp profile | ✅ PASS | 15/15 | seccomp profile active (syscall surface filtered) |
| Network isolation / egress | ⚠️ WARN | 4/15 | network=bridge: outbound egress is possible; prefer network=none |
| Read-only root filesystem | ❌ FAIL | 0/10 | root filesystem is writable: tamper/persistence surface |
| No docker.sock exposure | ✅ PASS | 15/15 | no docker.sock / OCI control socket mounted |
| No shared host namespaces | ✅ PASS | 10/10 | no host PID/IPC/network namespace sharing |
Harden it: the highest-value fixes¶
Applying these to your docker run anaconda3 targets the biggest gaps first (most points at stake first):
- Dropped capabilities,
--cap-drop=ALL
Drop every Linux capability; add back only what the workload provably needs. - Non-root user (uid != 0),
--user 65532:65532
Pin a non-root uid so a container escape does not begin as host uid 0. - Network isolation / egress,
--network=none
Cut egress so a compromised workload cannot reach the network or exfiltrate. - Read-only root filesystem,
--read-only --tmpfs /tmp
Make the root filesystem read-only to remove the tamper/persistence surface.
The fixes above, plus the rest of IronClaw's recommended flag set, as one command:
docker run -d --name anaconda3-hardened \
--user 65532:65532 \
--cap-drop=ALL \
--security-opt=no-new-privileges \
--read-only --tmpfs /tmp \
--network=none \
continuumio/anaconda3:2024.10-1
This image has not been re-scanned under those flags, so this page states no hardened score for it. The one hardened run this survey measures is nginx:1.27-alpine, which reaches 100/100 (grade A) on exactly this flag set. Expect to adjust, and expect a ceiling: --network=none is not an option for a service that has to accept connections, and dropping it leaves the network-isolation dimension exactly where the table above has it. A container that writes outside /tmp will not boot read-only until you add a --tmpfs for each path it needs (some want a writable mode, e.g. --tmpfs /data:rw,mode=1777). Re-run ironctl scan on the result to see where yours actually lands.
Scan your own container¶
These grades come from ironctl scan, a single, credential-free command that audits any running container, docker-compose service, or Kubernetes manifest, not just this image:
# install (Homebrew)
brew install ironsecco/ironclaw/ironclaw
# grade your own anaconda3 the same way this page was generated
ironctl scan my-anaconda3
- Scan any container →, the full command reference.
- Add an isolation-score badge to your repo →
- The State of Container Isolation, 2026 →, the full survey this directory is built from.
- Run untrusted code in a real sandbox →, IronClaw wraps every AI-agent session in a gVisor/Kata isolation boundary with
network=noneby default.
Badge this image¶
Maintain anaconda3 (or run it)? Show its default-config isolation score with a badge that links back to this scorecard:
[](https://ironsecco.github.io/ironclaw/scores/anaconda3/)
The badge is a plain shields.io URL: no server, no build step, nothing to host. It reflects this page's default-configuration grade. Hardened your own deployment? Generate a live badge of your config with ironctl scan --badge-json, or compare every image on the leaderboard.
Part of the Container Isolation Scores directory, default-configuration containment grades for the most-pulled public images.