aws-ecr-image-manifest-content

OCI/Docker image manifests and embedded labels or annotations can contain sensitive build metadata or credentials.

awshigh service: aws:ecr emits ContainsCredential

Where it sits

locationBatchGetImage.images[].imageManifest
location kindcode_artifact
data kindssource_code_secret credential password api_key sensitive_data
emits edgeContainsCredential
serviceECR (aws:ecr)

Collection recipe

access moderead_api
operationBatchGetImage
response pathimages[].imageManifest
encodingjson
params{"imageIds": [{"imageTag": "\u003ctag\u003e"}], "repositoryName": "\u003crepository\u003e"}

Required permissions

ecr:BatchGetImage

References

move · open · esc close