Skip to main content

Container Registry asset operations

Container Registry assets cover container images integrated via FPT Container Registry or Harbor.

For general asset actions (Disable, Enable, Delete), see Manage assets.

Add a Container Registry asset

  1. In Workspace, click Add Asset.
  2. Select FPT Container Registry or Harbor.

Container Registry — Add Asset: select registry and image

note

The Add Asset popup only shows registries that have been integrated in the Integration screen.

  1. Select the image and image tag, then click Add.

After adding, the system automatically runs the first scan and displays results in the All Assets tab.

View asset overview

Click any Container Registry asset name to open the Asset Overview screen.

Container Registry — Asset Overview

The overview shows:

  • General information: Asset Name, Asset Access (Public/Private), Status, Owner, Added By, Added At
  • Metadata: Image ID, Manifest Digest, Image Tag, Image VPC, Base Image, Platform, Target OS, Image Size
  • Issue overview: Scan Type, Scan Time, Total Open Issues, Severity counts, Scanning Times By Day (last 7 days)
  • Latest requests: up to 3 most recent scan requests

View scan history

Select the History tab on the Asset Overview screen.

Container Registry — Asset scan history

View the issue list

Select the Issue tab on an asset to view issues by scan type.

Container Registry — Issue list

Each issue card shows: Severity, Package Name, Issue Title, CWE/CVE/CVSS references, Score (0–10), Issue Status, Exploit Status, Image Layer, Fixed in Version.

Filter by: Severity, Status, Priority Score, Issue Type, "Fixed in" available, Image Layer, Exploit Maturity, Exploit Status.

Sort by: Severity (C→H→M→L), Score, Created Time. Default: Score descending.

View issue details

Click Details on any issue card to open the Issue Detail popup.

Container Registry — Issue details

The Issue Detail shows: Severity, Package Name, Vulnerability Type, Issue Status, Issue Description, Issue Remediation (Current package, Fixed in version), Security Information (CVSS score, attack vector), References, Manifest Layer, Code Block, and Activity log.