Docs: Container scanning offline docs should emphasize image updates

  • Start this issue's title with Docs: or Docs feedback:.

Problem to solve

Using container scanning in an offline environment requires that the Grype and Trivy images be regularly updated in the offline container registry. If a container image is more than 5 days old, vunlerability scanning of containers may fail with something like the following message:

the vulnerability database was built 6 days ago (max allowed age is 5 days)

Further details

Proposal

Make it clear in the following docs section that container images stored in an offline container registry must be regularly updated.

Who can address the issue

Anyone

Other links/references

Edited by 🤖 GitLab Bot 🤖