Supply Chain Findings

Find the components in your pipeline, registry, and runtime resources that use a risky license or that have reached or are approaching end of life

Overview

The Supply Chain Findings page lists the license and end-of-life (EOL) findings on the resources that Sysdig scans. Use it to find components that:

  • Use a license that puts obligations or restrictions on your organization, such as a copyleft, proprietary, or commercial-restriction license.
  • Have reached end of life, or reach end of life within 90 days.

Sysdig raises these findings from the same scans that Vulnerability Management uses. You do not need to install or configure a separate scanner.

Feature Availability

Supply Chain Findings is in Technical Preview. It is still in active development and can change significantly in future releases.

This feature is available to all Sysdig Secure SaaS deployments.

Prerequisites

  • A Sysdig Secure SaaS account. Supply Chain Findings is not available on-premises.
  • A role with the Scan Results (Read) permission or the legacy Scanning (Read) permission. For more information, see Detailed Role Permissions.
  • At least one scan of a pipeline, registry, or runtime resource.

Access Supply Chain Findings

Select Attack Surface > Supply Chain Findings.

Finding Types

Each finding has a type, a name, and a severity. Sysdig sets the severity from the finding name. You cannot change it.

Finding TypeFinding NameSeverity
LicenseComponent uses a network copyleft licenseCritical
LicenseComponent uses a license that restricts commercial useCritical
LicenseComponent uses a proprietary licenseMedium
LicenseComponent uses a license that restricts useMedium
LicenseComponent uses a copyleft licenseMedium
LicenseComponent uses a license with ambiguous termsLow
LicenseComponent uses an unrecognized licenseNegligible
End of LifeComponent has reached end of lifeHigh
End of LifeComponent is approaching end of lifeMedium

For license findings:

  • Sysdig raises at most one license finding for each component. The table lists the license findings in precedence order. When a component has more than one license, the first matching row sets the finding.
  • Permissive and weak copyleft licenses raise no finding.
  • A component with no license metadata raises no finding.

For more information on license categories, see License Classification.

For EOL findings:

  • Sysdig raises EOL findings for operating systems and for the Go runtime only. Other runtimes, libraries, and packages raise no EOL finding.
  • Packages that an operating system package manager installs do not inherit the EOL date of the operating system.
  • A component is approaching end of life when its EOL date is 90 days away or less. This window is fixed.
  • A component with no EOL data raises no finding.

For the list of supported operating systems, see Software Lifecycle and End-of-Life Visibility.

Where Findings Come From

Each finding belongs to one stage:

StageSource
PipelineImages that you scan in your CI/CD pipeline.
RegistryImages that you scan in your container registries.
RuntimeKubernetes workloads, containers, hosts, and virtual machines that Sysdig scans at runtime.

Sysdig uses only the most recent scan of each resource. When Sysdig scans a resource again, the new findings replace the earlier ones. The page does not refresh automatically, so reload it to see the results of new scans.

Understand the Findings Table

By default, each row is one finding on one component in one resource. The table shows these columns:

ColumnDescription
FindingThe finding name, with an icon in the color of its severity.
ComponentThe type of the component, such as an operating system package or a Java package.
Component Name / PathThe name and version of the component, and the path where Sysdig found it. Operating system packages show no path.
ResourceThe name and type of the resource that contains the component.
Resource ContextWhere the resource runs. For example, the cluster and namespace, or the cloud account and region.
SeverityThe severity of the finding.
First SeenWhen Sysdig first detected the finding on the resource.

The table sorts by Severity, with the highest first. You can also sort by First Seen. The table loads 50 rows at a time. Select Load more to see more rows.

The page URL keeps your filters, grouping, and sort order. Copy the URL to share the same view.

Group Findings

Use Group by to change what each row represents:

Group byEach row showsColumnsSelect a row to open
NoneOne finding. This is the default.See the table above.The finding details.
PackageOne component and its findings across all resources.Component, Component Context, Licenses, Findings, Resources, First SeenThe Component Details drawer.
ImageOne image in one stage. An image in more than one stage has one row for each stage.Resource, Resource Context, Stage, Resources, Findings, First SeenThe image details.
Runtime ResourceOne runtime resource, such as a workload or host.Resource, Resource Context, Findings, First SeenThe Resource Details drawer.

When you group findings, the table sorts by the number of findings, with the highest first.

The Image grouping does not include hosts, virtual machines, or serverless functions. The Runtime Resource grouping includes runtime resources only, so the Stage filter does not appear.

Filter Findings

Use filters to focus on the findings that matter to you. Select values from a list, or type a value for the filters that take text.

FilterValuesDescription
ZoneYour zonesShows findings on resources in the selected zones.
SeverityCritical, High, Medium, Low, NegligibleShows findings of the selected severities.
StagePipeline, Registry, RuntimeShows findings from the selected stages.
Finding TypeLicense, End of LifeShows license findings, EOL findings, or both.
Finding NameThe nine finding namesShows findings with the selected names. See Finding Types.
License CategoryCopyleft, Network Copyleft, Restricted Use, Commercial Restriction, Proprietary, Ambiguous, UnknownShows license findings in the selected categories.
License NameText, such as GPL-3.0Shows license findings for a license. Type the exact SPDX identifier.
Cluster NameTextShows findings on resources in the cluster.
NamespaceTextShows findings on resources in the namespace.
Resource NameTextShows findings on the resource.

Review a Finding in Detail

Select a finding to open the finding details. The header shows the finding name, its severity, the affected resource, and when Sysdig first saw the finding. The Highlights tab has three sections. Each section shows a field only when the finding has a value for it.

SectionFieldDescription
Affected Resource SummaryAffected ResourceThe resource that contains the component. Select it to open the resource or image details.
Resource ContextWhere the resource runs.
StageThe stage of the scan: pipeline, registry, or runtime.
Finding SummaryFinding NameThe name of the finding.
SeverityThe severity of the finding.
LicensesFor a license finding, the number of licenses on the component. Hover over it to see the SPDX identifier of each license.
EOLFor an EOL finding, EOL or Approaching EOL.
Component DetailsComponent NameThe name of the component. Select it to open the Component Details drawer.
Component CategoryThe type of the component.
PathThe path where Sysdig found the component.

The finding details do not show the EOL date. To see the EOL date of a component, open the component from the Components tab of the Resource Details drawer. For more information, see Software Lifecycle and End-of-Life Visibility.

Supply Chain Findings in Other Drawers

The Resource Details drawer and the Component Details drawer each have a Supply Chain Findings tab. The tab shows the same table and filters, limited to that resource, image, or component. For more information on the Resource Details drawer, see View Resource Details.

Limitations

In this Technical Preview, the Supply Chain Findings page does not:

  • Let you accept the risk of a finding or add an exception.
  • Export findings.
  • Show whether a finding fails a policy. To enforce rules on EOL components, use a Component Lifecycle rule in a vulnerability policy. For more information, see Use Lifecycle Data in Policies.
  • Support a free-text search. Use the filters instead.