PageSourceSearch

https://ratify.dev/assets/js/e241187c.d8b6cbb4.js

js ratify.dev collected 2026-09-24 19:29:23 UTC 27,595 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[4370],{28453(e,n,i){i.d(n,{R:()=>s,x:()=>l});var r=i(96540);const t={},a=r.createContext(t);function s(e){const n=r.useContext(a);return r.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function l(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:s(e.components),r.createElement(a.Provider,{value:n},e.children)}},83349(e,n,i){i.r(n),i.d(n,{assets:()=>o,contentTitle:()=>l,default:()=>h,frontMatter:()=>s,metadata:()=>r,toc:()=>c});const r=JSON.parse('{"id":"plugins/verifier/vulnerabilityreport","title":"Vulnerability Report","description":"This document outlines how Ratify can be used to verify vulernability reports. The vulnerabilityreport verifier is added as a plugin to the Ratify verification framework. Currently the vulnerability report verifier supports the following report types:","source":"@site/versioned_docs/version-1.4/plugins/verifier/vulnerabilityreport.md","sourceDirName":"plugins/verifier","slug":"/plugins/verifier/vulnerabilityreport","permalink":"/docs/plugins/verifier/vulnerabilityreport","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.4/plugins/verifier/vulnerabilityreport.md","tags":[],"version":"1.4","sidebarPosition":4,"frontMatter":{"sidebar_position":4},"sidebar":"tutorialSidebar","previous":{"title":"SBOM Validation","permalink":"/docs/plugins/verifier/sbom"},"next":{"title":"Schema Validator","permalink":"/docs/plugins/verifier/schemavalidator"}}');var t=i(74848),a=i(28453);const s={sidebar_position:4},l="Vulnerability Report",o={},c=[{value:"Table of Contents",id:"table-of-contents",level:2},{value:"Example Scenario",id:"example-scenario",level:2},{value:"Recording",id:"recording",level:3},{value:"Walkthrough",id:"walkthrough",level:3},{value:"Configuration",id:"configuration",level:2},{value:"Kubernetes",id:"kubernetes",level:3},{value:"CLI",id:"cli",level:3},{value:"Vulnerability Report with Signature Validation",id:"vulnerability-report-with-signature-validation",level:2},{value:"Passthrough Mode",id:"passthrough-mode",level:2}];function d(e){const n={a:"a",blockquote:"blockquote",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",img:"img",li:"li",ol:"ol",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,a.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(n.header,{children:(0,t.jsx)(n.h1,{id:"vulnerability-report",children:"Vulnerability Report"})}),"\n",(0,t.jsxs)(n.p,{children:["This document outlines how Ratify can be used to verify vulernability reports. The ",(0,t.jsx)(n.code,{children:"vulnerabilityreport"})," verifier is added as a plugin to the Ratify verification framework. Currently the vulnerability report verifier supports the following report types:"]}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:"Reports attached to the subject image as a referrer artifact"}),"\n",(0,t.jsx)(n.li,{children:"Reports in SARIF format"}),"\n",(0,t.jsxs)(n.li,{children:["Reports generated by ",(0,t.jsx)(n.a,{href:"https://aquasecurity.github.io/trivy/v0.47/",children:"Trivy"})," or ",(0,t.jsx)(n.a,{href:"https://github.com/anchore/grype",children:"Grype"})]}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"table-of-contents",children:"Table of Contents"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.a,{href:"#vulnerability-report",children:"Vulnerability Report"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#table-of-contents",children:"Table of Contents"})}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.a,{href:"#example-scenario",children:"Example Scenario"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#recording",children:"Recording"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#walkthrough",children:"Walkthrough"})}),"\n"]}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.a,{href:"#configuration",children:"Configuration"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#kubernetes",children:"Kubernetes"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#cli",children:"CLI"})}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#vulnerability-report-with-signature-validation",children:"Vulnerability Report with Signature Validation"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"#passthrough-mode",children:"Passthrough Mode"})}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"example-scenario",children:"Example Scenario"}),"\n",(0,t.jsx)(n.p,{children:"Alice has a Kubernetes cluster. She wants to enable vulnerability report verification. In particular, she wants to make sure all c
1ontainer images used in K8s resources have at least one valid vulnerability report attached to the image. She only wants to consider the latest vulnerability report that was generated. The report must:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:"be in SARIF format"}),"\n",(0,t.jsx)(n.li,{children:"generated from Trivy or Grype"}),"\n",(0,t.jsx)(n.li,{children:"created less than 24 hours ago"}),"\n",(0,t.jsx)(n.li,{children:"has no HIGH or CRITICAL severity level vulnerabilities in the report"}),"\n",(0,t.jsx)(n.li,{children:"does not contain the log4shell CVE"}),"\n"]}),"\n",(0,t.jsx)(n.h3,{id:"recording",children:"Recording"}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.a,{href:"https://asciinema.org/a/622368",children:(0,t.jsx)(n.img,{src:"https://asciinema.org/a/622368.svg",alt:"asciicast"})})}),"\n",(0,t.jsx)(n.h3,{id:"walkthrough",children:"Walkthrough"}),"\n",(0,t.jsxs)(n.p,{children:["First, only follow the first step of the ",(0,t.jsx)(n.a,{href:"/docs/quickstarts/quickstart-manual",children:"manual quickstart"}),", which installs Gatekeeper on the cluster."]}),"\n",(0,t.jsx)(n.p,{children:"Second, install Ratify with the vulnerability report verifier enabled and configured."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:'helm repo add ratify https://notaryproject.github.io/ratify\nhelm install ratify \\\n    ratify/ratify --atomic \\\n    --namespace gatekeeper-system \\\n    --set featureFlags.RATIFY_CERT_ROTATION=true \\\n    --set vulnerabilityreport.enabled=true \\\n    --set vulnerabilityreport.maximumAge="24h" \\\n    --set vulnerabilityreport.disallowedSeverities="{"high","critical"}" \\\n    --set vulnerabilityreport.denylistCVEs={"CVE-2021-44228"}\n'})}),"\n",(0,t.jsx)(n.p,{children:'Next, install the vulnerability report constraint template and constraint. The Constraint Template defines the policy "all container images used in K8s resources have at least one valid most recent vulnerability report attached to the image and the report has a valid Notary Project signature"'}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"kubectl apply -f https://raw.githubusercontent.com/deislabs/ratify/23b143d07a53fd61557703c9836e486353959530/library/vulnerability-report-validation/template.yaml\n\nkubectl apply -f https://raw.githubusercontent.com/deislabs/ratify/v1.1.0/library/vulnerability-report-validation/samples/constraint.yaml\n"})}),"\n",(0,t.jsxs)(n.p,{children:["An image ",(0,t.jsx)(n.code,{children:"myregistry.io/vuln/alpine:3.18.2"})," is scanned and a vulnerability report is generated. A reference artifact is generated:"]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["Use Trivy to scan ",(0,t.jsx)(n.code,{children:"myregistry.io/vuln/alpine:3.18.2"})," and output a report in SARIF format","\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"trivy image -q -f sarif myregistry.io/vuln/alpine:3.18.2 > trivy-sarif.json\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["A tool such as ",(0,t.jsx)(n.code,{children:"oras"})," is used to package, attach, and then push the report to registry","\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.code,{children:"artifact-type"})," MUST be ",(0,t.jsx)(n.code,{children:"application/sarif+json"})]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.code,{children:"org.opencontainers.image.created"})," annotation with RFC3339 formatted current timestamp"]}),"\n"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"oras attach \\\n    --artifact-type application/sarif+json \\\n    --annotation \"org.opencontainers.image.created=$(date -u +'%Y-%m-%dT%H:%M:%SZ')\" \\\n    myregistry.io/vuln/alpine:3.18.2 \\\n    trivy-sarif.json\n"})}),"\n"]}),"\n"]}),"\n",(0,t.jsx)(n.p,{children:"The resulting image will have a single SARIF vulnerability report artifact attached:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"> oras discover myregistry.io/vuln/alpine:3.18.2 -o tree\nmyregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70\n\u2514\u2500\u2500 application/sarif+json\n    \u2514\u2500\u2500 sha256:6170ef41e5a7c7088f86e3bc6b9c370cf97e613f7c7e359628c0119ec7d3d5f4\n"})}),"\n",(0,t.jsxs)(n.p,{children:["Finally we will attempt to deploy our test image ",(0,t.jsx)(n.code,{children:"myregistry.io/vuln/alpine:3.18.2"}),". We expect this to FAIL since our vulnerability report indicates multiple HIGH and CRITICAL level severities:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:'> kubectl run vuln-alpine-image -n default --image=myregistry.io/vuln/alpine:3.18.2\nError from server (Forbidden): admission webhook "validation.gatekeeper.sh" denied the request: [vulnerability-report-validation-constraint] Subject failed verification: myregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70\n'})}),"\n",(0,t.jsx)(n.p,{children:"Taking a look at the Ratify logs reveals the failing report:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-json",children:'> kubectl logs deploy/ratify -n gatekeeper-system\ntime=2023-11-20T12:00:00Z level=info msg=verify result for subject myregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70: {\n  "verifierReports": [\n    {\n      "subject": "myregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70",\n      "isSuccess": false,\n      "name": "vulnerabilityreport",\n      "message": "vulnerability report validation failed",\n      "extensions": {\n        "scanner": "trivy",\n        "severityViolations": [\n          {\n            "defaultConfiguration": {\n              "level": "error"\n            },\n            "fullDescription": {\n              "text": "There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution."\n            },\n            "help": {\n              "markdown": "**Vulnerability CVE-2022-48174**\\n| Severity | Package | Fixed Version | Link |\\n| --- | --- | --- | --- |\\n|CRITICAL|ssl_client|1.36.1-r1|[CVE-2022-48174](https://avd.aquasec.com/nvd/cve-2022-48174)|\\n\\nThere is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.",\n              "text": "Vulnerability CVE-2022-48174\\nSeverity: CRITICAL\\nPackage: ssl_client\\nFixed Version: 1.36.1-r1\\nLink: [CVE-2022-48174](https://avd.aquasec.com/nvd/cve-2022-48174)\\nThere is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution."\n            },\n            "helpUri": "https://avd.aquasec.com/nvd/cve-2022-48174",\n            "id": "CVE-2022-48174",\n            "name": "OsPackageVulnerability",\n            "properties": {\n              "precision": "very-high",\n              "security-severity": "9.8",\n              "tags": [\n                "vulnerability",\n                "security",\n                "CRITICAL"\n              ]\n            }
1,\n            "shortDescription": {\n              "text": "stack overflow vulnerability in ash.c leads to arbitrary code execution"\n            }\n          },\n          ...\n        ]\n      }\n    }\n  ]\n}\n\n'})}),"\n",(0,t.jsx)(n.h2,{id:"configuration",children:"Configuration"}),"\n",(0,t.jsx)(n.h3,{id:"kubernetes",children:"Kubernetes"}),"\n",(0,t.jsx)(n.p,{children:"Sample YAML"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-json",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Verifier\nmetadata:\n  name: verifier-vulnerabilityreport\nspec:\n  name: vulnerabilityreport\n  artifactTypes: application/sarif+json\n  parameters:\n    maximumAge: 24h\n    disallowedSeverities:\n      - high\n      - critical\n    denylistCVEs:\n      - CVE-2021-44228 # Log4Shell\n"})}),"\n",(0,t.jsxs)(n.table,{children:[(0,t.jsx)(n.thead,{children:(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.th,{children:"Name"}),(0,t.jsx)(n.th,{children:"Required"}),(0,t.jsx)(n.th,{children:"Path"}),(0,t.jsx)(n.th,{children:"Description"}),(0,t.jsx)(n.th,{children:"Default Value"})]})}),(0,t.jsxs)(n.tbody,{children:[(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:"maximumAge"}),(0,t.jsx)(n.td,{children:"No"}),(0,t.jsx)(n.td,{children:"spec.parameters.maximumAge"}),(0,t.jsx)(n.td,{children:"The string formatted max age of report"}),(0,t.jsx)(n.td,{children:'""'})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:"disallowedSeverities"}),(0,t.jsx)(n.td,{children:"No"}),(0,t.jsx)(n.td,{children:"spec.parameters.disallowedSeverities"}),(0,t.jsxs)(n.td,{children:["String array of disallowed severities. Verification fails if ANY specified severity found. Most common severities: ",(0,t.jsx)(n.code,{children:"low"}),", ",(0,t.jsx)(n.code,{children:"medium"}),", ",(0,t.jsx)(n.code,{children:"high"}),", ",(0,t.jsx)(n.code,{children:"critical"}),", ",(0,t.jsx)(n.code,{children:"unknown"})]}),(0,t.jsx)(n.td,{children:"[]"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:"denylistCVEs"}),(0,t.jsx)(n.td,{children:"No"}),(0,t.jsx)(n.td,{children:"spec.parameters.denylistCVEs"}),(0,t.jsxs)(n.td,{children:["String array of CVE IDs. Verification fails if ANY specified CVE ID found. Find CVEs ",(0,t.jsx)(n.a,{href:"https://nvd.nist.gov/vuln/search",children:"here"})]}),(0,t.jsx)(n.td,{children:"[]"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:"passthrough"}),(0,t.jsx)(n.td,{children:"No"}),(0,t.jsx)(n.td,{children:"spec.parameters.passthrough"}),(0,t.jsxs)(n.td,{children:["Bypasses all verification except for ",(0,t.jsx)(n.code,{children:"maximumAge"}),". Report content in extension section's ",(0,t.jsx)(n.code,{children:"report"})," field of verifier report. Refer to ",(0,t.jsx)(n.a,{href:"#passthrough-mode",children:"Passthrough Mode"})," section for more details."]}),(0,t.jsx)(n.td,{children:"false"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:"createdAnnotationName"}),(0,t.jsx)(n.td,{children:"No"}),(0,t.jsx)(n.td,{children:"spec.parameters.createdAnnotationName"}),(0,t.jsx)(n.td,{children:"The annotation name which specifies the artifact's creation timestamp. Note: Timestamp must use RFC3339"}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"org.opencontainers.image.created"})})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:"schemaURL"}),(0,t.jsx)(n.td,{children:"No"}),(0,t.jsx)(n.td,{children:"spec.parameters.schemaURL"}),(0,t.jsx)(n.td,{children:"URL for a JSON schema to validate report against. Default SARIF version 2.1.0 is used."}),(0,t.jsx)(n.td,{children:'""'})]})]})]}),"\n",(0,t.jsx)(n.h3,{id:"cli",children:"CLI"}),"\n",(0,t.jsx)(n.p,{children:"Sample JSON"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-json",children:'{\n    "store": {\n        "version": "1.0.0",\n        "plugins": [\n            {\n                "name": "oras",\n            }\n        ]\n    },\n    "policy": {\n        "version": "1.0.0",\n        "plugin": {\n            "name": "configPolicy"\n        }\n    },\n    "verifier": {\n        "version": "1.0.0",\n        "plugins": [\n            {\n                "name": "vulnerabilityreport",\n                "artifactTypes": "application/sarif+json",\n                "maximumAge": "24h",\n                "disallowedSeverities": ["high", "critical"],\n                "denyl
1istCVEs": ["CVE-2021-44228"]\n            }\n        ]\n    }\n}\n'})}),"\n",(0,t.jsx)(n.h2,{id:"vulnerability-report-with-signature-validation",children:"Vulnerability Report with Signature Validation"}),"\n",(0,t.jsx)(n.p,{children:"Alice has a Kubernetes cluster. She wants to enable vulnerability report verification. In particular, she wants to make sure all container images used in K8s resources have the most recent vulnerability report attached to the image be valid. The report must:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:"be in SARIF format"}),"\n",(0,t.jsx)(n.li,{children:"generated from Trivy or Grype"}),"\n",(0,t.jsx)(n.li,{children:"created less than 24 hours ago"}),"\n",(0,t.jsx)(n.li,{children:"has no HIGH or CRITICAL severity level vulnerabilities in the report"}),"\n",(0,t.jsx)(n.li,{children:"does not contain the log4shell CVE"}),"\n"]}),"\n",(0,t.jsx)(n.p,{children:"Furthermore, the most recent report being validated must have a verified Notary Project signature attached to it."}),"\n",(0,t.jsxs)(n.p,{children:["First, follow the first step of the ",(0,t.jsx)(n.a,{href:"/docs/quickstarts/quickstart-manual",children:"manual quickstart"})," to install Gatekeeper."]}),"\n",(0,t.jsx)(n.p,{children:"Second, install Ratify with the vulnerability report verifier enabled and configured. The notation verifier must also be configued and cert provided. Here, we will assume the report is signed using the quickstart image's signing key."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:'helm repo add ratify https://notaryproject.github.io/ratify\n# download the notary verification certificate\ncurl -sSLO https://raw.githubusercontent.com/deislabs/ratify/main/test/testdata/notation.crt\nhelm install ratify \\\n    ratify/ratify --atomic \\\n    --namespace gatekeeper-system \\\n    --set featureFlags.RATIFY_CERT_ROTATION=true \\\n    --set-file notationCerts={./notation.crt} \\\n    --set vulnerabilityreport.enabled=true \\\n    --set vulnerabilityreport.maximumAge="24h" \\\n    --set vulnerabilityreport.notaryProjectSignatureRequired=true \\\n    --set vulnerabilityreport.disallowedSeverities="{"high","critical"}" \\\n    --set vulnerabilityreport.denylistCVEs={"CVE-2021-44228"}\n'})}),"\n",(0,t.jsx)(n.p,{children:'Next, install the vulnerability report constraint template and constraint. The Constraint Template defines the policy "all container images used in K8s resources have at least one valid most recent vulnerability report attached to the image and the report has a valid Notary Project signature"'}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"curl https://raw.githubusercontent.com/deislabs/ratify/23b143d07a53fd61557703c9836e486353959530/library/vulnerability-report-validation/template.yaml | sed 's/require_signature := false/require_signature := true/' | kubectl apply -f -\n\nkubectl apply -f https://raw.githubusercontent.com/deislabs/ratify/v1.1.0/library/vulnerability-report-validation/samples/constraint.yaml\n"})}),"\n",(0,t.jsxs)(n.p,{children:["An image ",(0,t.jsx)(n.code,{children:"myregistry.io/vuln/alpine:3.18.2"})," is scanned and a vulnerability report is generated. A reference artifact is generated:"]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["Use Trivy to scan ",(0,t.jsx)(n.code,{children:"myregistry.io/vuln/alpine:3.18.2"})," and output a report in SARIF format","\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"trivy image -q -f sarif myregistry.io/vuln/alpine:3.18.2 > trivy-sarif.json\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["A tool such as ",(0,t.jsx)(n.code,{children:"oras"})," is used to package, attach, and then push the report to registry","\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.code,{children:"artifact-type"})," MUST be ",(0,t.jsx)(n.code,{children:"application/sarif+json"})]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.code,{children:"org.opencontainers.image.created"})," annotation with RFC3339 formatted current timestamp"]}),"\n"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"oras attach \\\n    --artifact-type application/sarif+json \\\n    --annotation \"org.opencontainers.image.created=$(date -u +'%Y-%m-%dT%H:%M:%SZ')\" \\\n    myregistry.io/vuln/alpine:3.18.2 \\\n    trivy-sarif.json\n"})}),"\n"]}),"\n",(0,t.jsxs)(n.li,{children:["Use ",(0,t.jsx)(n.a,{href:"https://notaryproject.dev/",children:(0,t.jsx)(n.code,{children:"notation"})})," to sign the report"]}),"\n"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:'report_digest=$(oras discover myregistry.io/vuln/alpine:3.18.2 -o json | jq .manifests[0].digest | tr -d \\")\nnotation sign myregistry.io/vuln/alpine@$report_digest\n'})}),"\n",(0,t.jsx)(n.p,{children:"The resulting image will have a single SARIF vulnerability report artifact attached with Notary Project signature attached to the report:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:"> oras discover myregistry.io/vuln/alpine:3.18.2 -o tree\nmyregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70\n\u2514\u2500\u2500 application/sarif+json\n    \u2514\u2500\u2500 sha256:6170ef41e5a7c7088f86e3bc6b9c370cf97e613f7c7e359628c0119ec7d3d5f4\n        \u2514\u2500\u2500 application/vnd.cncf.notary.signature\n            \u2514\u2500\u2500 sha256:1f89580da5b08d943ed0a403f1629928a21aec3f51bce7c38b0bea8b187b83a7\n"})}),"\n",(0,t.jsxs)(n.p,{children:["Finally we will attempt to deploy our test image ",(0,t.jsx)(n.code,{children:"myregistry.io/vuln/alpine:3.18.2"}),". We expect this to FAIL since our vulnerability report indicates multiple HIGH and CRITICAL level severities:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-shell",children:'> kubectl run vuln-alpine-image -n default --image=myregistry.io/vuln/alpine:3.18.2\nError from server (Forbidden): admission webhook "validation.gatekeeper.sh" denied the request: [vulnerability-report-validation-constraint] Subject failed verification: myregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70\n'})}),"\n",(0,t.jsx)(n.p,{children:"Taking a look at the Ratify logs reveals the failing report. Note how the report includes a successful Notary Project signature verification."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-json",children:'> kubectl logs deploy/ratify -n gatekeeper-system\ntime=2023-11-20T12:00:00Z level=info msg=verify result for subject myregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70: {\n  "verifierReports": [\n    {\n      "subject": "myregistry.io/vuln/alpine@sha256:25fad2a32ad1f6f510e528448ae1ec69a28ef81916a004d3629874104f8a7f70",\n      "isSuccess": false,\n      "name": "vulnerabilityreport",\n      "message": "vulnerability report validation failed",\n      "extensions": {\n        "scanner": "trivy",\n        "severityViolations": [\n          {\n            "defaultConfiguration": {\n              "level": "error"\n            },\n            "fullDescription": {\n              "text": "There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution."\n            },\n            "help": {\n              "markdown": "**Vulnerability CVE-2022-48174**\\n| Severity | Package | Fixed Version | Link |\\n| --- | --- | --- | --- |\\n|CRITICAL|ssl_client|1.36.1-r1|[CVE-2022-48174](https://avd.aquasec.com/nvd/cve-2022-48174)|\\n\\nThere is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.",\n              "text": "Vulnerability CVE-2022-48174\\nSeverity: CRITICAL\\nPackage: ssl_client\\nFixed Version: 1.36.1-r1\\nLink: [CVE-2022-48174](https://avd.aquasec.com/nvd/cve-2022-48174)\\nThere is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution."\n            },\n            "helpUri": "https://avd.aquasec.com/nvd/cve-2022-48174",\n            "id": "CVE-2022-48174",\n            "name": "OsPackageVulnerability",\n            "properties": {\n              "precision": "very-high",\n              "security-severity": "9.8",\n              "tags": [\n                "vulnerability",\n                "security",\n                "CRITICAL"\n              ]\n            }
1,\n            "shortDescription": {\n              "text": "stack overflow vulnerability in ash.c leads to arbitrary code execution"\n            }\n          },\n          ...\n        ]\n      },\n      "nestedResults": [\n        {\n          "subject": "myregistry.io/vuln/alpine@sha256:6170ef41e5a7c7088f86e3bc6b9c370cf97e613f7c7e359628c0119ec7d3d5f4",\n          "isSuccess": true,\n          "name": "notation",\n          "message": "signature verification success",\n          "extensions": {\n            "Issuer": "CN=wabbit-networks.io,O=Notary,L=Seattle,ST=WA,C=US",\n            "SN": "CN=wabbit-networks.io,O=Notary,L=Seattle,ST=WA,C=US"\n          },\n          "artifactType": "application/vnd.cncf.notary.signature"\n        }\n      ],\n    }\n  ]\n}\n\n'})}),"\n",(0,t.jsx)(n.h2,{id:"passthrough-mode",children:"Passthrough Mode"}),"\n",(0,t.jsxs)(n.p,{children:["There may be scenarios where the current vulnerability report rules enforced are not sufficient. Passthrough mode allows for the entire contents of the vulnerability report to be outputted in the resulting verifier report. Users can then apply custom Rego parsing the report contents either in the built-in ",(0,t.jsx)(n.a,{href:"https://ratify.dev/docs/1.0/reference/crds/policies#regopolicy",children:"Ratify Rego Policy"})," provider or Gatekeeper's ",(0,t.jsx)(n.code,{children:"ConstraintTemplate"}),"."]}),"\n",(0,t.jsxs)(n.p,{children:["To enable, set the ",(0,t.jsx)(n.code,{children:"passthrough"})," parameter to ",(0,t.jsx)(n.code,{children:"true"})," in the verifier configuration (JSON config or CRD)."]}),"\n",(0,t.jsxs)(n.blockquote,{children:["\n",(0,t.jsxs)(n.p,{children:["Note: ALL other configuration parameters for the ",(0,t.jsx)(n.code,{children:"vulnerabilityreport"})," verifier are NOT considered, EXCEPT for the ",(0,t.jsx)(n.code,{children:"maximumAge"})," parameter."]}),"\n"]})]})}function h(e={}){const{wrapper:n}={...(0,a.R)(),...e.components};return n?(0,t.jsx)(n,{...e,children:(0,t.jsx)(d,{...e})}):d(e)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.