goharbor / goharbor/pluggable-scanner-spec

Extending Harbor's Pluggable Scanner specification to support Runtime Behavior Profiles

Open
#22 2 comments 2 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
26
Forks
15
PR merge metrics
No merged PRs in 30d

Description

As one of the most widely adopted container registries, it is a critical component in modern software supply chains.

Goal is to enhance its security capabilities by extending Harbor's Pluggable Scanner specification to support Runtime Behavior Profiles (also known as a Behavior of Bill, or "BoB").

While Software Bill of Materials (SBOMs) describe what an artifact *contains*, a BoB describes how it *behaves* at runtime.

By integrating `kubescape-node-agent` as a scanner, Harbor will be able to retrieve, store, and display these runtime profiles for OCI artifacts. This allows software producers to ship secure-by-default configurations and provides consumers with a way to verify runtime behavior, detect anomalies, and report unexpected activity. This feature will create greater trust in artifacts and help users meet emerging compliance requirements, such as the EU's CyberResilience Act, by enabling active breach identification through anomaly detection.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the repository's current Pluggable Scanner OpenAPI specification and its existing artifact scan operations. Then map the kubescape-node-agent Runtime Behavior Profile requirements to the specification, including how Harbor would retrieve, store, and display profiles. Done means the proposed API extension is defined consistently and its expected behavior is documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
openapi
Domain
api, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.