Description
Without suitable vulnerability scanning of ECR images, known package issues can be discovered late. Check registry settings, filters, and actual scan results together to establish coverage.
Potential impact
Images containing undiscovered vulnerabilities may be deployed.
Remediation
Configure the required scan type and frequency at registry level, and ensure filters include the intended repositories. Establish remediation and deployment decisions based on the results.
Examples
The examples use BASIC registry scanning for pushes to test-repository in place of the deprecated repository-level ImageScanningConfiguration. Preserve and manage any existing registry rules alongside this configuration.
Before
yaml
Resources:
MyRepository3:
Type: AWS::ECR::Repository
Properties:
RepositoryName: "test-repository"
After
yaml
Resources:
MyRepository3:
Type: AWS::ECR::Repository
Properties:
RepositoryName: "test-repository"
RegistryScanning:
Type: AWS::ECR::RegistryScanningConfiguration
Properties:
ScanType: BASIC
Rules:
- ScanFrequency: SCAN_ON_PUSH
RepositoryFilters:
- Filter: test-repository
FilterType: WILDCARD