Bug 1779679 - Image security dashboard card should make it clear we only check images from quay
Summary: Image security dashboard card should make it clear we only check images from ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Management Console
Version: 4.3.0
Hardware: Unspecified
OS: Unspecified
unspecified
low
Target Milestone: ---
: 4.3.0
Assignee: Samuel Padgett
QA Contact: Yadan Pei
URL:
Whiteboard:
Depends On: 1768496
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-12-04 13:54 UTC by Samuel Padgett
Modified: 2020-01-23 11:18 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of: 1768496
Environment:
Last Closed: 2020-01-23 11:17:47 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
fixed (38.68 KB, image/png)
2019-12-05 08:26 UTC, shahan
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github openshift console pull 3659 0 'None' 'open' '[release-4.3] Bug 1779679: Clarify message about Quay image scanning' 2019-12-04 13:54:54 UTC
Red Hat Product Errata RHBA-2020:0062 0 None None None 2020-01-23 11:18:04 UTC

Description Samuel Padgett 2019-12-04 13:54:36 UTC
+++ This bug was initially created as a clone of Bug #1768496 +++

The dashboard card from the security operator plugin doesn't make it clear that it only scans images from quay. This could give users a false sense of security when it says there are no vulnerabilities. It's possible containers running images from other registries are vulnerable.

We should add a statement in the UI that only images from quay are scanned.

--- Additional comment from Samuel Padgett on 2019-11-21 14:32:20 UTC ---

This is not release blocking. Moving to low severity.

--- Additional comment from Peter Kreuser on 2019-11-22 19:55:36 UTC ---

Status text: Quay Image Security
Popover title: Quay Image Security breakdown (Breakdown can be dropped if too long.)
Popover description: Container images from quay are analyzed to identify vulnerabilities. Images from other registries will not be scanned.

Comment 2 shahan 2019-12-05 08:24:39 UTC
verified this bug. detail display see attachment .4.3.0-0.nightly-2019-12-04-214544

Comment 3 shahan 2019-12-05 08:26:39 UTC
Created attachment 1642296 [details]
fixed

Comment 5 errata-xmlrpc 2020-01-23 11:17:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:0062


Note You need to log in before you can comment on or make changes to this bug.