elastisys / welkin

Documentation for the Welkin project - a Kubernetes-based platform for software critical to society
https://elastisys.io/
Apache License 2.0
122 stars 32 forks source link

Clarify that we do both "offline" and "online" image scanning #422

Open llarsson opened 2 years ago

llarsson commented 2 years ago

Describe the bug

When it comes to vulnerability management documentation, we only talk about Trivy, which does "offline" scanning of images at rest in Harbor. But we also do "online" scanning of the images that are deployed via Starboard, and we also have Grafana dashboard capabilities that show the results.

We should make it clear that we offer both kinds of vulnerability scanning, offline as well as online.

Screenshots

N/A

Additional context

We have had people looking at our documentation and not understanding that this is something we offer. Had they not spoken up and asked, they would have wrongfully assumed that we don't have it, and perhaps walked away from us. So this matters.

viktor-f commented 2 years ago

Note that in starboard it is actually trivy that scans the images.