Evaluates whether image scanning is enabled for a Container Registry instance. If so, the resource is compliant.
Scenarios
Scanning container images helps identify and fix vulnerabilities, improving overall system security.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
If image scanning is enabled for a Container Registry instance, the evaluation result is Compliant.
Rule details
|
Parameter |
Description |
|
Rule Template Name |
cr-repository-image-scanning-enabled |
|
Rule Template Identifier |
|
|
Tag |
Image |
|
Automatic remediation |
Not supported |
|
Invoke Type |
Periodic: Every 24 hours |
|
Supported resource type |
Container Registry instance (ACS::CR::Instance) |
|
Input parameter |
N/A |
Non-compliance remediation
Enable the image scanning feature for a Container Registry instance. For more information, see Scan container images.