Edit

View and remediate vulnerabilities for registry images

Defender for Cloud helps you identify and remediate vulnerabilities in container images stored in supported registries before deployment.

Vulnerability findings for registry images are shown as security recommendations in Defender for Cloud. The steps in this article use the Flat list recommendations view, which shows recommendations at the affected-resource level. Learn more about reviewing recommendations by title or by resource.

Note

During the transition from grouped to individual recommendations, you might see both recommendation formats in the portal. Learn more about transitioning from grouped to individual recommendations.

Prerequisites

Before you begin, make sure that Defender for Containers or Defender CSPM is enabled on your subscription with Registry access toggled on.

View and remediate vulnerabilities for registry images

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Recommendations.

  3. In the left pane, select Vulnerabilities.

  4. Select the Flat list view.

  5. Select Add filter.

  6. Select Resource type.

  7. Select Container Image.

    Screenshot of the Resource type filter in Microsoft Defender for Cloud Recommendations with Container image selected.

  8. Select Apply.

  9. Select a recommendation.

  10. Review the recommendation details, including the risk information, remediation guidance, and recommendation metadata.

  11. Select the Associated CVEs tab to review the CVEs associated with the recommendation.

  12. Select a CVE to view details such as severity, affected components, and fix version information.