Description | Clicking the link to view a Container image ID dossier may take you to a page that includes a different repository than the one you have selected. Similarly when following the “Active Containers in last 24 hours” link, you may observe active containers from different registries than the one selected when viewing the vulnerability report. |
Scope | Container images, Kubernetes |
Solution |
An image can be committed to many repositories but it is still the same image, this means that when you ask the UI to take you to the Image ID Dossier it will take you to the latest scan that was performed matching the image ID.
The scan of this image may not be associated with the repository you were launching your container from originally, but rather from a different repository.
By scanning each image once and only once according to your configured schedule, assessment for image vulnerabilities is conducted in a fast and reliable fashion, no matter which repository they reside in.
|
Labels: