Query Quay for security vulnerabilities during build pipeline
Issue
- Avoid building against base images with security vulnerabilities
- Are scans synchronous with adding new container image manifests?
- Can the security scan be incomplete?
- Force Clair to scan if it hasn't yet.
Environment
- Red Hat Quay (Quay) 3
- Quay Clair vulnerability scanning
- After Importing new base image manifest
- Running a build pipeline in GitOps
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.