Docs: Container scanning offline docs should emphasize image updates
-
Start this issue's title with Docs:orDocs feedback:.
Problem to solve
Using container scanning in an offline environment requires that the Grype and Trivy images be regularly updated in the offline container registry. If a container image is more than 5 days old, vunlerability scanning of containers may fail with something like the following message:
the vulnerability database was built 6 days ago (max allowed age is 5 days)
Further details
Proposal
Make it clear in the following docs section that container images stored in an offline container registry must be regularly updated.
Who can address the issue
Anyone
Other links/references
Edited by 🤖 GitLab Bot 🤖