[ECR] [request]: add filter CLI -UI --ignore-unfixed-vulnerabilities
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
I cannot see from the documentation an option to exclude/ignore vulnerabilities that are not resolved in mainstream images then they will keep appearing on the UI and from the CLI.
https://docs.aws.amazon.com/cli/latest/reference/ecr/index.html
**Security disclosures**
If you think you’ve found a potential security issue, please do not post it in the Issues. Instead, please follow the instructions [here](https://aws.amazon.com/security/vulnerability-reporting/) or [email AWS security directly](mailto:aws-security@amazon.com).
-->
**Tell us about your request**
Would be great to exclude/ignore vulnerabilities that are not resolved by the owner maybe some extra option like
`--ignore-unfixed-vulnerabilities` would be great to add. It is important for SecDevOps to be able to automate via ci/cd before pushing the image to ECR.
**Which service(s) is this request for?**
ECR
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
It is difficult to automate a process via ci/cd as the CLI will keep appearing vulnerabilities that will not be resolved by the images owners/external companies
Contributor guide
Research direction
Start with the linked Amazon ECR CLI documentation and the issue's requested filtering behavior. Compare how unfixed vulnerabilities appear in the CLI and UI, then define consistent filtering and CI/CD acceptance criteria; done means users can exclude those findings through the requested interfaces.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cli, cloud, devops
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100