Container image review

Proofline matches the platforms in a container image to the declared runtime, and follows images by digest from the build to the running service. The image a pull request builds has to match what will run it.

An arm64 image for an x86 service

A Dockerfile change can switch the base image or the build platform. The image still builds and passes tests on a laptop.

Proofline reads the platforms inside the image index from Amazon ECR or Artifact Registry. A deterministic check compares them with the CPU architecture and operating system the ECS task definition declares.

When the image offers no matching platform, the finding names the task definition and the image index. The check needs the release to pin the index digest. It reports a task definition with no declared platform as undeclared rather than as a match.

Images by digest

A tag can move after a build. Proofline records the digests that ECR, Artifact Registry, Cloud Build, and ECS report, so a finding can say which image a service runs.

Changes to a Dockerfile or another build definition bring the artifact identity domain into the review. The review then asks whether the deployed artifact contains the intended revision and the files the service needs.

Questions

Which container registries does Proofline support?

Proofline reads Amazon ECR and Google Artifact Registry. Reading the platforms inside a multi-platform image from Artifact Registry is an option you turn on.

Does Proofline check image platforms for Cloud Run?

No. The deterministic platform check compares images with ECS task definitions. Cloud Run does not report a platform for Proofline to compare.

Does Proofline pull or run my images?

No. Proofline reads image metadata from the registry. It does not pull or run the images your services deploy. A sandbox experiment can build and run the reviewed code in a disposable VM.

Connect your image registry.

Review changes against AWS or review GitHub Actions workflows.

Get Started with GitHub