Document the new container scanning report
What does this MR do?
This MR documents the new container scanning report format implemented as part of #32934 (closed), and uses the Reports JSON format from the dependency scanning docs as a template.
The main changes from the Reports JSON format are the following:
-
vulnerabilities[].severityis changed to only list the levels thatklarprovides, which means we're removing theInfoandUndefinedseverity levels -
vulnerabilities[].location.operating_systemhas been added -
vulnerabilities[].location.imagehas been added -
remediationshas been simplified, since remediation data is currently an empty array
This MR should only be merged once #32934 (closed) has been closed.
Screenshots
Does this MR meet the acceptance criteria?
Conformity
-
Changelog entry -
Documentation (if required) -
Code review guidelines -
Merge request performance guidelines -
Style guides -
Database guides -
Separation of EE specific content
Availability and Testing
-
Review and add/update tests for this feature/bug. Consider all test levels. See the Test Planning Process. -
Tested in all supported browsers
Security
If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:
-
Label as security and @ mention @gitlab-com/gl-security/appsec -
The MR includes necessary changes to maintain consistency between UI, API, email, or other methods -
Security reports checked/validated by a reviewer from the AppSec team
Edited by Adam Cohen