Skip to main content

Process of a Docker Images Plugin Scan

The Docker Images plugin scan performs the following steps as it executes:

StepDescription
1Contacts the Code Insight server to validate the connection and download a scanner.
2Extracts the Docker image file. (The extracted file hierarchy will be represented in the Codebase Files list in the Analysis Workbench .)
3Finds the Docker image layer information via the manifest file.
4Scans the extracted Docker image contents.
5Adds any Syft findings from the image to the inventory list.
6Sends the inventory results to the associated Code Insight instance.
note

Both support for incremental rescans and the application of scan profile settings from the Code Insight project are available starting with the Docker Images plugin version 2.3.1. See Application of Scan Profile Settings for details.