Artifact Scan
The Artifact Scan, scans the artifacts from the selected platforms or the configured ones.
This page explains the process of Adhoc Artifact Scan for Amazon Elastic Container Registry (ECR).
Before starting with the scan, you need to integrate ECR with the OpsMx platform. Follow the steps provided in Integrating ECR to complete the process.
If ECR data needs to be mapped to a specific team, you need to create the team first. If no team-level segregation is required, skip this step. Follow the steps provided in Managing Teams to complete the process.
To Access Artifact Scan
Click on Scan Now button at the top right corner of the screen.

In the screen that appears, select Artifact Scan from the left panel.

If the ECR account needs to be associated with a specific team, select the Teams before proceeding else, the ECR account will be added at the organization level.

Now you can Add Project or Upload Project and proceed with the scan.
To Add a Project
To add or update a new project with artifact scan configurations, click Add Project.
The Create Project details page is displayed as shown below. Enter the details for the following fields:

Name : Enter a name for the project.
Team : Select the desired team from the dropdown menu.
Scan Type : The default type is Artifact Scan.
Platform : Select the platform type, ECR.
Account : Choose the needed account that has been integrated for the selected platform. If no account is available for the selected platform then click Add Account.
The integration page is displayed. You can add a new account.
Registry: Select the Registry URL from the dropdown menu.
Organization / Workspace : Choose the organization or workspace that the selected account has access to.
Scan Level : Select the scan level; either organization level or repository level that needs to be scanned.
Artifact Configuration : Set the configuration details, and schedule the auto scan time.
Artifact Name: Select the artifact name from the dropdown menu.
Artifact Tag: Choose one of the three available options based on your requirement: All, Latest , Tags Pattern
Click Save.
The project gets added for scanning.
To Upload a Project
To upload a project from your local, click Upload Project.
Click Upload File and select the json file you want to add for scanning.

The project gets added for scanning.
To View and Interpret Scan Results
Once the scan is complete, a confirmation message is updated within the project and OpsMx generates the overall results. They are displayed as shown below:
Repos Registered
Total Artifact Tags
Total Scans
Total Projects
Auto Scan Enabled Repos

The panel at the bottom displays the project details. On expanding each project you can view the complete details of it.
If the scan fails, the error message will be displayed in the project's message section as shown:

To edit the configuration details of the project, click the Edit Configuration button.
Click the View option in the Action button, to view the SAST and SCA scan results of the project.

Click the Download button to download the scan results.

Last updated