policy criteria for "days since first discovered in deployment"
Issue
In RHACS 4.2.0 we introduced the capability to Define system policies using CVE age or fixability, and this included the policy criteria of
CVE Is Fixable:
Days Since CVE Was First Discovered In Image:
Days Since CVE Was First Discovered In System:
While these new policy criteria are helpful, if a deployment is based upon an image with digest, and this digest is frequently changing to a new digest, then the existing policy criteria will not catch those scenarios where the image digest is updated frequently, less than a day.
Environment
Red Hat Advanced Cluster Security (RHACS)
- 4.4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.