Add container image scanning workflow #17
amazon-cloudwatch-observability-image-scan.yaml
on: pull_request
Matrix: ContainerImageScan
Annotations
5 errors and 14 warnings
|
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
2024-08-13T17:54:05Z INFO Vulnerability scanning is enabled
2024-08-13T17:54:05Z INFO Secret scanning is enabled
2024-08-13T17:54:05Z INFO If your scanning is slow, please try '--scanners vuln' to disable secret scanning
2024-08-13T17:54:05Z INFO Please see also https://aquasecurity.github.io/trivy/v0.53/docs/scanner/secret#recommendation for faster secret detection
2024-08-13T17:54:05Z FATAL Fatal error image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: unable to find the specified image "public.ecr.aws/aws-observability/adot-autoinstrumentation-dotnet:v1.1.0" in ["docker" "containerd" "podman" "remote"]: 4 errors occurred:
* docker error: unable to inspect the image (public.ecr.aws/aws-observability/adot-autoinstrumentation-dotnet:v1.1.0): Error response from daemon: No such image: public.ecr.aws/aws-observability/adot-autoinstrumentation-dotnet:v1.1.0
* containerd error: failed to initialize a containerd client: failed to dial "/run/containerd/containerd.sock": connection error: desc = "transport: error while dialing: dial unix /run/containerd/containerd.sock: connect: permission denied"
* podman error: unable to inspect the image (public.ecr.aws/aws-observability/adot-autoinstrumentation-dotnet:v1.1.0): failed to find image public.ecr.aws/aws-observability/adot-autoinstrumentation-dotnet:v1.1.0: public.ecr.aws/aws-observability/adot-autoinstrumentation-dotnet:v1.1.0: No such image
* remote error: GET https://public.ecr.aws/v2/aws-observability/adot-autoinstrumentation-dotnet/manifests/sha256:2e5a3f1821d9fac4b842809afc1d2fc4f6ec02f10506c9038fc200a47e3527df: TOOMANYREQUESTS: Rate exceeded
|
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
|
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
|
ContainerImageScan (.dcgmExporter.image.repositoryDomainMap.public, .dcgmExporter.image.repositor...
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
|
ContainerImageScan (.agent.image.repositoryDomainMap.public, .agent.image.repository, .agent.imag...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.agent.image.repositoryDomainMap.public, .agent.image.repository, .agent.imag...
Dockerfile not provided. Skipping sarif scan result.
|
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.manager.autoInstrumentationImage.dotnet.repositoryDomain, .manager.autoInstr...
Dockerfile not provided. Skipping sarif scan result.
|
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.manager.image.repositoryDomainMap.public, .manager.image.repository, .manage...
Dockerfile not provided. Skipping sarif scan result.
|
ContainerImageScan (.manager.autoInstrumentationImage.python.repositoryDomain, .manager.autoInstr...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.manager.autoInstrumentationImage.python.repositoryDomain, .manager.autoInstr...
Dockerfile not provided. Skipping sarif scan result.
|
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.neuronMonitor.image.repositoryDomainMap.public, .neuronMonitor.image.reposit...
Dockerfile not provided. Skipping sarif scan result.
|
ContainerImageScan (.manager.autoInstrumentationImage.java.repositoryDomain, .manager.autoInstrum...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.manager.autoInstrumentationImage.java.repositoryDomain, .manager.autoInstrum...
Dockerfile not provided. Skipping sarif scan result.
|
ContainerImageScan (.dcgmExporter.image.repositoryDomainMap.public, .dcgmExporter.image.repositor...
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@v3. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
|
ContainerImageScan (.dcgmExporter.image.repositoryDomainMap.public, .dcgmExporter.image.repositor...
Dockerfile not provided. Skipping sarif scan result.
|