klar icon indicating copy to clipboard operation
klar copied to clipboard

Feature: Klar should be able to scan OCI images

Open HarvyNBB opened this issue 1 year ago • 0 comments

Brief:

On January 9th Buildx v0.10 was released. The release notes included the following warning:

Buildx v0.10 enables support for a minimal SLSA Provenance 1 attestation, which requires support for OCI-compliant multi-platform images. Klar does not support oci images hence the Clair scan for any image that is build using buildx v0.10 fails. It's possible to optionally disable the default provenance attestation functionality using --provenance=false in the buildx which will generate docker images instead of OCI images.

Error received by Klar when scanning an OCI image

{"errors":[\{"code":"MANIFEST_UNKNOWN","message":"OCI index found, but accept header does not support OCI indexes"}
--
]}
Can't pull fsLayers

KLAR_VERSION=2.4.0

Feature request:

Klar should support OCI images format

HarvyNBB avatar May 08 '23 13:05 HarvyNBB