Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    Container / Docker scanning

    Scheduled Pinned Locked Moved Support
    1 Posts 1 Posters 2 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      sai.pabbareddy
      last edited by

      One more question from the same Enterprise trial evaluation, Noncompliant container images don't seem to be blocked on pull or promotion

      Detection itself works very well: we pushed nginx:1.14.0 to a Docker feed, and ProGet correctly inventoried it — 108 packages, 66 with vulnerabilities, 521 real CVEs (via Ubuntu Security Notices).

      We then escalated one of those findings to Contain (confirmed Noncompliant in the audit view), with Feeds.AllowNoncompliantDownloads set to false at the global level — the same setting that correctly blocks NuGet/npm/PyPI packages once they're assessed Noncompliant in our testing.

      For the container image, though:

      • A fresh docker pull of the same image from the source feed succeeded anyway.
      • Promoting the same image to a second feed also succeeded.

      Layer Scanning was already enabled on the feed. We re-tested this twice more to rule out a fluke: once by reconfirming the original image's assessment was still genuinely Contain and re-pulling (same result), and once on an entirely different image (httpd:2.4.29, 95 packages, 314 vulnerabilities) end-to-end (same result).

      Is there a separate setting that governs blocking specifically for container/Docker feeds, distinct from AllowNoncompliantDownloads? Or is policy-based blocking for container images not yet supported the same way it is for package feeds on this version?
      We want to make sure we're not missing a config option before we document this as a gap in our evaluation.

      Thanks,
      Sai

      1 Reply Last reply Reply Quote 0

      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

      With your input, this post could be even better 💗

      Register Login
      • 1 / 1
      • First post
        Last post
      Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation