For the complete documentation index, see llms.txt. This page is also available as Markdown.

View Vulnerability Scan Results

Each Private Container Registry can provide a detailed analysis of Common Vulnerabilities and Exposures (CVEs) that may be exploitable in your artifacts. For more information, see Enable Vulnerability Scanning.

Vulnerability scan results provide detailed information about the security of your artifacts at different levels. The following sections provide more information.

Search the Private Container Registry for a specific vulnerability

When new vulnerabilities are identified, you may want to search your entire Private Container Registry to see if any of the artifacts are vulnerable. To do this, you will need the Common Vulnerabilities and Exposures (CVE) number. Every published vulnerability or security issue is assigned a unique CVE number.

1. In the DCD, go to Menu > Containers > Container Registry.

2. In the Container Registry window, select the Private Container Registry by clicking on its name, and select the Vulnerability Search tab. Alternatively, from the OPTIONS column > select Options menu > Vulnerabilities.

Search for a specific vulnerability in a Private Container Registry

3. Search for a specific vulnerability by entering its full CVE number in the Vulnerability Search tab.

Search for a specific vulnerability

Summarize Vulnerability Scan results by Repository

To secure your artifacts and the software supply chain, review vulnerability scan results periodically. First, identify which repositories contain vulnerabilities.

1. In the DCD, go to Menu > Containers > Container Registry.

2. In the Container Registry window, click the name of your target Private Container Registry and select the Repositories tab. Alternatively, from the OPTIONS column > select Options menu > Repositories.

Select a Private Container Registry
Repositories listed with vulnerabilities

Note: Depending on the content of your Private Container Registry, there may be too many repositories to list on a single page. Remember to use the per page to set the number of repositories displayed per page and to navigate between pages using < and >.

Summarize Vulnerability Scan results by Artifact

You can review specific artifacts within a repository to identify vulnerability exposure. This view highlights artifacts with known fixes and displays the last push date (the update timestamp) and the last pull date—which often aligns with environment deployments.

1. In the DCD, go to Menu > Containers > Container Registry.

2. In the Container Registry window, click the name of your target Private Container Registry and select the Repositories tab. Alternatively, from the OPTIONS column > select Options menu > Repositories.

Select a Private Container Registry

3. In the Repositories tab, click the name of the repository to select and review it. Alternatively, select Options menu > View Repository.

Select a Repository
View and sort artifacts

Note: Depending on the content of your repository, there may be too many artifacts to list on a single page. Remember to use per page to set the number of artifacts displayed per page and to navigate between pages using < and >.

View Vulnerability Scan Results for a specific Artifact

1. In the DCD, go to Menu > Containers > Container Registry.

2. In the Container Registry window, click the name of your target Private Container Registry and select the Repositories tab. Alternatively, from the OPTIONS column > select Options menu > Repositories.

Select a Private Container Registry

3. In the Repositories tab, click the name of the repository to select and review it. Alternatively, select Options menu > View Repository.

Select a Repository

4. Select the artifact you want to view.

Select an Artifact
View Artifact Vulnerabilities

View Details of a specific CVE

When you have found a specific CVE, either by viewing vulnerability scan results for a specific artifact or by finding artifacts that are vulnerable to a specific CVE, you can see more details about the CVE by clicking on the CVE identification number. This will provide additional information about the vulnerability and may include references to third-party sites where additional information can be found.

Search for Vulnerabilities

Last updated

Was this helpful?