Skip to content

Add AWS ECR registry evidence gates#1205

Open
z707693052 wants to merge 1 commit into
UnitOneAI:mainfrom
z707693052:improve/aws-ecr-registry-evidence
Open

Add AWS ECR registry evidence gates#1205
z707693052 wants to merge 1 commit into
UnitOneAI:mainfrom
z707693052:improve/aws-ecr-registry-evidence

Conversation

@z707693052
Copy link
Copy Markdown

Closes #1204

Summary

  • Add supplemental Amazon ECR container registry hardening gates to aws-review without counting them as CIS AWS Foundations controls.
  • Cover tag immutability, scan-on-push/enhanced scanning, repository policy exposure, encryption, lifecycle cleanup, and rollback evidence.
  • Add detailed ECR-REG checklist entries for Terraform/registry evidence.

Validation

  • git diff --check
  • Markdown fence balance check for both edited files
  • Marker checks for Amazon ECR, image_tag_mutability, scan_on_push, and aws_ecr_registry_scanning_configuration

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] aws-review: add ECR tag immutability and scanning evidence gates

1 participant