chainguard-dev / vulnerability-scanner-support

Resources to help vulnerability scanners
Apache License 2.0
2 stars 1 forks source link

AWS logo is misleading #1

Open jbergstroem opened 7 months ago

jbergstroem commented 7 months ago

On the scanner page the AWS logo is showing (https://www.chainguard.dev/scanners), but after uploading a chainguard image (I tried node-lts:latest, sha256:d40e810c66fce05225a68aa6350f7365dd258e3f12434d310ff7fc1a308c60f5) to the ECR registry it is flagged as unsupported. Which is it?

UnsupportedImageError: The operating system and/or package manager are not supported.

luhring commented 7 months ago

Hey @jbergstroem, thanks for the issue!

AWS has added support for Chainguard Images in AWS Inspector, but they started with just the CI/CD integrations for AWS Inspector, so it's not rolled out to all services quite yet (like ECR). They've committed to finishing the rollout within 2024H2.

I'm talking with our marketing folks about clarifying this on the scanners page.