Aws
ecr-image-scan-gate — fail CI when an ECR image has a HIGH CVE
CLI that reads Amazon ECR image scan findings for a given repo/tag and gates CI on vulnerability severity. Summarizes counts per severity, supports a --fail-on threshold, and can run offline against a describe-image-scan-findings JSON dump for pure, unit-testable classification.
Loading…