turbot/terraform_aws_compliance

Control: ECR repository should use image scanning

Description

One of the best practices when making containers available through AWS ECR is to scan them for vulnerabilities before sharing or using them.

Usage

Run the control in your terminal:

powerpipe control run terraform_aws_compliance.control.ecr_repository_use_image_scanning

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run terraform_aws_compliance.control.ecr_repository_use_image_scanning --share

SQL

This control uses a named query:

ecr_repository_use_image_scanning

Tags