This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What makes a Container Image scan 'invalid'?

I'm trying to scan container images in Cloud Optix from an ECR registry. However in the scan queue they are all listed as 'invalid'. The documentation states:

"If an image scan request is invalid, its status is shown as Invalid and the scan request is cancelled."

That's fine, but what would cause an invalid scan request? Can't seem to find anything within the documentation beyond what I've stated above....



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    The scanning engine works in two stages. The first one creates scan requests from different sources based on what it thinks is a docker image. The second one then tries to pull the image and scan it. When an image gets to stage 2, it might find that it is not accessible (for multiple reasons). In that case, it marks it as invalid.

    In other rare situations, it can be because other issues might lead to failure to scan the image.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Reply
  • Hello there,

    Thank you for contacting the Sophos Community.

    The scanning engine works in two stages. The first one creates scan requests from different sources based on what it thinks is a docker image. The second one then tries to pull the image and scan it. When an image gets to stage 2, it might find that it is not accessible (for multiple reasons). In that case, it marks it as invalid.

    In other rare situations, it can be because other issues might lead to failure to scan the image.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
Children
No Data