policy criteria for "days since first discovered in deployment"

Solution Verified - Updated -

Issue

In RHACS 4.2.0 we introduced the capability to Define system policies using CVE age or fixability, and this included the policy criteria of

CVE Is Fixable:
Days Since CVE Was First Discovered In Image:
Days Since CVE Was First Discovered In System: 

While these new policy criteria are helpful, if a deployment is based upon an image with digest, and this digest is frequently changing to a new digest, then the existing policy criteria will not catch those scenarios where the image digest is updated frequently, less than a day.

Environment

Red Hat Advanced Cluster Security (RHACS)
- 4.4.x

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content