Azure Container registry how to see image vulnerability report for concrete image with a certain tag?

Viewed 58

I'd like to find an easy way to get list of vulnerabilities for few images I just imported.

The task is complicated because we already have some images with vulnerabilities so just going to Settings -> Security is not an option as way to many vulnerabilities will be displayed there.

What I'd like to go to Repositories find the particular image I'm interested and see report for that concrete instance with a concrete tag. I was not able to find any links from there.

So the approach I do so far is go to Settings -> Security, open a single vulnerability, then see list of images, click an image and it shows details of all vulnerabilities for this image. Then I copy URL and modify in that URL the image repository and sha256 of the image to get a report for the image I'm interested.

You can understand my pain it is way way not user friendly for the task I'm doing.

Is there a simple way to come to concrete docker image report in ACR?

1 Answers

I was thinking of couple of options: https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-container-registries-introduction#can-i-get-the-scan-results-via-rest-api

Option1: To start with we can try using the REST API as mentioned in the below document:

https://docs.microsoft.com/en-us/rest/api/securitycenter/sub-assessments/list?tabs=HTTP

GET https://management.azure.com/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/assessments/82e20e14-edc5-4373-bfc4-f13121257c37/subAssessments?api-version=2019-01-01-preview

It will list out all the image names with their Vulnerabilities.

Option2: We can make use of ARG (Azure Resource Graph Explorer)

Go to Container Registries -> RegistryName -> click on "Container registry images should have vulnerability findings resolved" -> Open Query

It will open up kusto query where you can try to manipulate different columns

Related