Images and publishing
Container images
Mirror images from Docker Hub and other registries, scan what is inside, and refuse vulnerable ones.
- Settings, Registries: switch on container images.
- Add an image registry. For Docker Hub use
https://registry-1.docker.ioand a token written asusername:access-tokento avoid anonymous pull limits. - Write image rules: pattern
nginx, versionsstable-alpine || 1.27.*. - Developers pull
packages.example.com/nginx:stable-alpine.
- On Docker Hub,
nginxandlibrary/nginxare the same image, and a deny or kill on either covers both. - A tag is checked on every pull. A digest is only served when a tag the rules allow points at it, so a denied tag cannot be pulled by digest.
- Refused tag pulls open a request. Digest pulls do not.
- Publishers can push images under reserved names. See Reserved names and publishing.
Image scanning
With Scan the images people pull on, each pulled image is read layer by layer to list the operating system packages and the npm and Python packages inside, then checked against the advisories for Debian, Ubuntu, Alpine, Wolfi, Chainguard, Red Hat, Rocky and AlmaLinux.
- Scan before serving: an image nobody has scanned yet answers "try again in a minute" until the scan finishes.
- Only count what has a fix: refusals only count advisories an upgrade fixes.
- Refusals only happen with Safe version resolution on. A waiver on the digest or any of its tags lets the image through.
1
- Pick images to walk an image