Review ECR image vulnerability scanning

Scan stored images and address the findings.

Description

ECR can scan images for software vulnerabilities. Disabling scan on push does not rule out registry-level enhanced scanning or manual scans, so check the actual scanning coverage.

Potential impact

Images with known vulnerabilities may be deployed if scans are missing or their findings are not addressed.

Remediation

Configure basic or enhanced scanning for the repository and update vulnerable packages or images based on the results. Enabling scanning alone does not block deployment.

Examples

The examples show scan-on-push settings for basic scanning. Also check the registry-level scanning configuration.

Before

hcl
resource "aws_ecr_repository" "example" {
  name                 = "service-image"
  image_tag_mutability = "MUTABLE"

  image_scanning_configuration {
    scan_on_push = false
  }
}

After

hcl
resource "aws_ecr_repository" "example" {
  name                 = "service-image"
  image_tag_mutability = "MUTABLE"

  image_scanning_configuration {
    scan_on_push = true
  }
}

References