You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Audit of control mappings against most recent compliance frameworks
Compliance framework documentation
Registry Scanner (4 controls)
REGISTRY-001: insecure-registries entries in /etc/docker/daemon.json
detected during --daemon scans
REGISTRY-002: unauthenticated / http:// registry references flagged in
Dockerfile FROM, Compose image:, and Kubernetes pod specs; distinguishes
insecure (FAIL), anonymous Docker Hub (WARN), and authenticated private
registries (PASS) across ECR, GAR, ACR, GHCR, GitLab, Harbor
REGISTRY-003: ECR repository/registry policies granting Principal *,
GAR IAM bindings to allUsers/allAuthenticatedUsers, and ACR anonymous_pull_enabled = true flagged in Terraform scans
REGISTRY-004: missing lifecycle/retention policies on ECR, GAR, and ACR
flagged in Terraform scans