Review ECR image scanning configuration

Check registry scan coverage and actual results.

Description

Without suitable vulnerability scanning of ECR images, known package issues can be discovered late. Check registry settings, filters, and actual scan results together to establish coverage.

Potential impact

Images containing undiscovered vulnerabilities may be deployed.

Remediation

Configure the required scan type and frequency at registry level, and ensure filters include the intended repositories. Establish remediation and deployment decisions based on the results.

Examples

The examples use BASIC registry scanning for pushes to test-repository in place of the deprecated repository-level ImageScanningConfiguration. Preserve and manage any existing registry rules alongside this configuration.

Before

yaml
Resources:
  MyRepository3:
    Type: AWS::ECR::Repository
    Properties:
      RepositoryName: "test-repository"

After

yaml
Resources:
  MyRepository3:
    Type: AWS::ECR::Repository
    Properties:
      RepositoryName: "test-repository"


  RegistryScanning:
    Type: AWS::ECR::RegistryScanningConfiguration
    Properties:
      ScanType: BASIC
      Rules:
        - ScanFrequency: SCAN_ON_PUSH
          RepositoryFilters:
            - Filter: test-repository
              FilterType: WILDCARD

References