Amazon Inspector expands ECR support for minimal container base images and enhanced detections
Share
Services
Today, we are excited to announce support for scratch, distroless (Debian/Ubuntu based), and Chainguard image scanning with Amazon Inspector. With the expanded support for ECR images, Amazon Inspector extends its security coverage to minimal and security-focused container bases, enabling teams to maintain robust security practices even with highly optimized container environments.
For ECR scanning, Amazon Inspector expands scanning to additional ecosystems including Go toolchain, Oracle JDK & JRE, Amazon Corretto, Apache Tomcat, Apache httpd, Wordpress (core, themes, plugins), Google Puppeteer (Chrome embedding), and Node.js runtime. This enhancement helps customers identify vulnerabilities in ecosystem components and gain visibility into third party software. The same functionality is also available via the Amazon Inspector SBOM Scan API.
Additionally, Amazon Inspector now supports identifying [discontinued operating systems](https://docs.aws.amazon.com/inspector/latest/user/supported.html#formerly-supported-os) running on Amazon EC2 instances and Amazon ECR container images. Amazon Inspector will generate a finding on resources using a discontinued operating system solely for informational purposes, aiding in the prioritization of risk mitigation strategies.
[Amazon Inspector](https://aws.amazon.com/inspector/) is a vulnerability management service that continually scans AWS workloads including Amazon EC2 instances, container images, and AWS Lambda functions for software vulnerabilities, code vulnerabilities, and unintended network exposure across your entire AWS organization.
Enhanced detections, and support for additional operating systems for ECR scanning is available in all commercial and AWS GovCloud (US) Regions where [Amazon Inspector is available](https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/).
What else is happening at Amazon Web Services?
Amazon Nova is now available in AWS GovCloud (US-West) Region
about 14 hours ago
Services
Share
AWS CloudFormation Hooks' new invocation targets and managed Hooks are available in the AWS GovCloud (US) Regions
about 14 hours ago
Services
Share
AWS CodeBuild now supports organization and enterprise level GitHub self-hosted runners
about 14 hours ago
Services
Share
Amazon Aurora PostgreSQL zero-ETL integration with Amazon Redshift now supports multiple integrations
about 14 hours ago
Services
Share
Amazon DynamoDB zero-ETL integration with Amazon Redshift now available in 3 additional regions
about 14 hours ago
Services
Share