[ECR] [Inspector scanning]: Support scanning Echo OS based container images
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Tell us about your request
Add support in AWS Inspector to scan container images based on Echo OS (a Debian-based OS used for secure container images).
### Which service(s) is this request for?
ECR, AWS Inspector (container image scanning)
### Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?
We want to use AWS Inspector as our primary container vulnerability scanner for images built on Echo OS.
Today, Inspector does not recognize or scan Echo OS images, which creates a coverage gap compared to other major scanners (e.g., Trivy, Grype, Wiz).
Echo OS publishes security advisories that are already consumed by those scanners, so the data exists and is actively used elsewhere. The lack of support forces teams to either accept blind spots in Inspector or run additional scanners, increasing operational complexity.
### Are you currently working around this issue?
Using alternative scanners that support Echo OS, alongside Inspector.
### Additional context
This impacts customers using Echo OS who rely on AWS-native security tooling and expect parity with commonly adopted third-party scanners.
Contributor guide
Research direction
No repository files, tests, or implementation entry points are mentioned. Start by reviewing how AWS Inspector currently recognizes ECR image operating systems and how Echo OS security advisories are published; done means Inspector can scan Echo OS-based container images and provide vulnerability coverage comparable to supported images.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100