[ECR] [request]: Image scan should expose fix information
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
What do you want us to build?
Let the user know if there's a fix available for the reported CVEs. Clair already provides the "FixedIn" data in it's database.
**Which service(s) is this request for?**
ECR
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
The user should be able to know if there's a fix available for the mentioned CVEs. This way it's easy to know if an image rebuild will solve the problem. I guess it would be possible to query the Clair database separately to find the fix to the CVE.
**Are you currently working around this issue?**
No, but we're comparing container scanning solutions and this is a major let down compared to others.
Contributor guide
Research direction
Start with the ECR image scan behavior and the Clair FixedIn data described in the request. Define done as scan results exposing whether each reported CVE has a fix available, so users can tell whether rebuilding the image may help.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100