<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Container &#x2F; Docker scanning]]></title><description><![CDATA[<p dir="auto">One more question from the same Enterprise trial evaluation, Noncompliant container images don't seem to be blocked on pull or promotion</p>
<p dir="auto">Detection itself works very well: we pushed nginx:1.14.0 to a Docker feed, and ProGet correctly inventoried it — 108 packages, 66 with vulnerabilities, 521 real CVEs (via Ubuntu Security Notices).</p>
<p dir="auto">We then escalated one of those findings to Contain (confirmed Noncompliant in the audit view), with Feeds.AllowNoncompliantDownloads set to false at the global level — the same setting that correctly blocks NuGet/npm/PyPI packages once they're assessed Noncompliant in our testing.</p>
<p dir="auto">For the container image, though:</p>
<ul>
<li>A fresh docker pull of the same image from the source feed succeeded anyway.</li>
<li>Promoting the same image to a second feed also succeeded.</li>
</ul>
<p dir="auto">Layer Scanning was already enabled on the feed. We re-tested this twice more to rule out a fluke: once by reconfirming the original image's assessment was still genuinely Contain and re-pulling (same result), and once on an entirely different image (httpd:2.4.29, 95 packages, 314 vulnerabilities) end-to-end (same result).</p>
<p dir="auto">Is there a separate setting that governs blocking specifically for container/Docker feeds, distinct from AllowNoncompliantDownloads? Or is policy-based blocking for container images not yet supported the same way it is for package feeds on this version?<br />
We want to make sure we're not missing a config option before we document this as a gap in our evaluation.</p>
<p dir="auto">Thanks,<br />
Sai</p>
]]></description><link>https://forums.inedo.com/topic/5836/container-docker-scanning</link><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 21:20:23 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5836.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 15 Sep 2026 14:45:45 GMT</pubDate><ttl>60</ttl></channel></rss>