goharbor / goharbor/pluggable-scanner-spec
Extending Harbor's Pluggable Scanner specification to support Runtime Behavior Profiles
- Dominant language
- No language data
- Stars
- 26
- Forks
- 15
- PR merge metrics
- No merged PRs in 30d
Description
As one of the most widely adopted container registries, it is a critical component in modern software supply chains.
Goal is to enhance its security capabilities by extending Harbor's Pluggable Scanner specification to support Runtime Behavior Profiles (also known as a Behavior of Bill, or "BoB").
While Software Bill of Materials (SBOMs) describe what an artifact *contains*, a BoB describes how it *behaves* at runtime.
By integrating `kubescape-node-agent` as a scanner, Harbor will be able to retrieve, store, and display these runtime profiles for OCI artifacts. This allows software producers to ship secure-by-default configurations and provides consumers with a way to verify runtime behavior, detect anomalies, and report unexpected activity. This feature will create greater trust in artifacts and help users meet emerging compliance requirements, such as the EU's CyberResilience Act, by enabling active breach identification through anomaly detection.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reading the repository's current Pluggable Scanner OpenAPI specification and its existing artifact scan operations. Then map the kubescape-node-agent Runtime Behavior Profile requirements to the specification, including how Harbor would retrieve, store, and display profiles. Done means the proposed API extension is defined consistently and its expected behavior is documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- openapi
- Domain
- api, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100