Description
ECR can scan images for software vulnerabilities. Disabling scan on push does not rule out registry-level enhanced scanning or manual scans, so check the actual scanning coverage.
Potential impact
Images with known vulnerabilities may be deployed if scans are missing or their findings are not addressed.
Remediation
Configure basic or enhanced scanning for the repository and update vulnerable packages or images based on the results. Enabling scanning alone does not block deployment.
Examples
The examples show scan-on-push settings for basic scanning. Also check the registry-level scanning configuration.
Before
hcl
resource "aws_ecr_repository" "example" {
name = "service-image"
image_tag_mutability = "MUTABLE"
image_scanning_configuration {
scan_on_push = false
}
}
After
hcl
resource "aws_ecr_repository" "example" {
name = "service-image"
image_tag_mutability = "MUTABLE"
image_scanning_configuration {
scan_on_push = true
}
}