An arm64 image for an x86 service
A Dockerfile change can switch the base image or the build platform. The image still builds and passes tests on a laptop.
Proofline reads the platforms inside the image index from Amazon ECR or Artifact Registry. A deterministic check compares them with the CPU architecture and operating system the ECS task definition declares.
When the image offers no matching platform, the finding names the task definition and the image index. The check needs the release to pin the index digest. It reports a task definition with no declared platform as undeclared rather than as a match.
Images by digest
A tag can move after a build. Proofline records the digests that ECR, Artifact Registry, Cloud Build, and ECS report, so a finding can say which image a service runs.
Changes to a Dockerfile or another build definition bring the artifact identity domain into the review. The review then asks whether the deployed artifact contains the intended revision and the files the service needs.
Questions
Which container registries does Proofline support?
Proofline reads Amazon ECR and Google Artifact Registry. Reading the platforms inside a multi-platform image from Artifact Registry is an option you turn on.
Does Proofline check image platforms for Cloud Run?
No. The deterministic platform check compares images with ECS task definitions. Cloud Run does not report a platform for Proofline to compare.
Does Proofline pull or run my images?
No. Proofline reads image metadata from the registry. It does not pull or run the images your services deploy. A sandbox experiment can build and run the reviewed code in a disposable VM.
Connect your image registry.
Review changes against AWS or review GitHub Actions workflows.
Get Started with GitHub