From 15c7101e0b8c3de4eac7ebd54657a932fac42399 Mon Sep 17 00:00:00 2001 From: "Andoni A." <14891798+andoniaf@users.noreply.github.com> Date: Mon, 9 Feb 2026 15:40:40 +0100 Subject: [PATCH] docs(image): update getting-started guide for input validation and v5.19.0 - Update version badge and prerequisite to 5.19.0 - Add image name validation requirements and OCI format reference - Document image list file limits - Add troubleshooting section for common Trivy errors --- .../providers/image/getting-started-image.mdx | 30 +++++++++++++++++-- 1 file changed, 28 insertions(+), 2 deletions(-) diff --git a/docs/user-guide/providers/image/getting-started-image.mdx b/docs/user-guide/providers/image/getting-started-image.mdx index 53cbff5a1e..ece4d822c6 100644 --- a/docs/user-guide/providers/image/getting-started-image.mdx +++ b/docs/user-guide/providers/image/getting-started-image.mdx @@ -8,7 +8,7 @@ Prowler's Image provider enables comprehensive container image security scanning ## Prowler CLI - + The Image provider is currently available in Prowler CLI only. @@ -18,7 +18,7 @@ The Image provider is currently available in Prowler CLI only. Before using the Image provider, ensure the following requirements are met: -- **Prowler CLI**: Version 5.18.0 or later +- **Prowler CLI**: Version 5.19.0 or later - **Trivy installed**: Trivy must be installed and available in the system PATH - **Container images accessible**: Images must be pullable from container registries or available locally - **Registry authentication** (for private registries): Valid Docker credentials configured via `docker login` @@ -90,6 +90,23 @@ python:3.12-slim node:20-bookworm ``` + +Image list files are limited to a maximum of 10,000 lines. Individual image names exceeding 500 characters are automatically skipped with a warning. + + +#### Image Name Requirements + +Image names must follow the OCI reference format. Valid names start with an alphanumeric character and contain only letters, digits, periods, hyphens, underscores, slashes, colons, and `@` symbols. + +Valid examples: +* `alpine:3.18` +* `myregistry.io/myapp:v1.0` +* `ghcr.io/org/image@sha256:abc123...` + + +Image names containing shell metacharacters (`;`, `|`, `&`, `$`, `` ` ``) are rejected to prevent command injection. + + ### Scan Configuration #### Scanner Types @@ -168,3 +185,12 @@ prowler image -I myregistry.io/myapp:v1.0 ``` Trivy automatically uses credentials from Docker's credential store (`~/.docker/config.json`). + +### Troubleshooting + +The Image provider categorizes common Trivy errors with actionable guidance: + +* **Authentication failure (401/403):** Registry credentials are missing or invalid. Run `docker login` for the target registry and retry the scan. +* **Image not found (404):** The specified image name, tag, or registry is incorrect. Verify the image reference exists and is accessible. +* **Rate limited (429):** The container registry is throttling requests. Wait before retrying, or authenticate to increase rate limits. +* **Network issue:** Trivy cannot reach the registry due to connectivity problems. Check network access, DNS resolution, and firewall rules.