jfrog / jfrog/jfrog-cli-security
jf docker scan supporting IMAGE ID or not ?
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 13
- Forks
- 50
- Avg merge
- 3d 48m
- Merged PRs (30d)
- 26
Description
Describe the bug
Placing jf docker scan command line with either image:tag or related IMAGE ID argument does not give the same result.
I do agree that related Jfrog doc only reference command line with image:tag arg ... but what about the support of IMAGE ID format ? Thx
Current behavior
According to my tests, using IMAGE ID always returns No security violations were found albeit the Docker image actually includes many critical CVEs
Reproduction steps
No response
Expected behavior
No response
JFrog CLI version
jf version 2.78.3
Operating system type and version
Ubuntu 24.04.3 LTS
JFrog Artifactory version
No response
JFrog Xray version
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Reproduce jf docker scan with the reported image:tag and IMAGE ID forms using JFrog CLI 2.78.3 on Ubuntu 24.04.3, then trace the security scan command to determine whether IMAGE ID input is supported and verify the resulting scan behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, go
- Domain
- cli, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100