Supply Chain Findings
Overview
The Supply Chain Findings page lists the license and end-of-life (EOL) findings on the resources that Sysdig scans. Use it to find components that:
- Use a license that puts obligations or restrictions on your organization, such as a copyleft, proprietary, or commercial-restriction license.
- Have reached end of life, or reach end of life within 90 days.
Sysdig raises these findings from the same scans that Vulnerability Management uses. You do not need to install or configure a separate scanner.
Feature Availability
Supply Chain Findings is in Technical Preview. It is still in active development and can change significantly in future releases.
This feature is available to all Sysdig Secure SaaS deployments.
Prerequisites
- A Sysdig Secure SaaS account. Supply Chain Findings is not available on-premises.
- A role with the Scan Results (Read) permission or the legacy Scanning (Read) permission. For more information, see Detailed Role Permissions.
- At least one scan of a pipeline, registry, or runtime resource.
Access Supply Chain Findings
Select Attack Surface > Supply Chain Findings.
Finding Types
Each finding has a type, a name, and a severity. Sysdig sets the severity from the finding name. You cannot change it.
| Finding Type | Finding Name | Severity |
|---|---|---|
| License | Component uses a network copyleft license | Critical |
| License | Component uses a license that restricts commercial use | Critical |
| License | Component uses a proprietary license | Medium |
| License | Component uses a license that restricts use | Medium |
| License | Component uses a copyleft license | Medium |
| License | Component uses a license with ambiguous terms | Low |
| License | Component uses an unrecognized license | Negligible |
| End of Life | Component has reached end of life | High |
| End of Life | Component is approaching end of life | Medium |
For license findings:
- Sysdig raises at most one license finding for each component. The table lists the license findings in precedence order. When a component has more than one license, the first matching row sets the finding.
- Permissive and weak copyleft licenses raise no finding.
- A component with no license metadata raises no finding.
For more information on license categories, see License Classification.
For EOL findings:
- Sysdig raises EOL findings for operating systems and for the Go runtime only. Other runtimes, libraries, and packages raise no EOL finding.
- Packages that an operating system package manager installs do not inherit the EOL date of the operating system.
- A component is approaching end of life when its EOL date is 90 days away or less. This window is fixed.
- A component with no EOL data raises no finding.
For the list of supported operating systems, see Software Lifecycle and End-of-Life Visibility.
Where Findings Come From
Each finding belongs to one stage:
| Stage | Source |
|---|---|
| Pipeline | Images that you scan in your CI/CD pipeline. |
| Registry | Images that you scan in your container registries. |
| Runtime | Kubernetes workloads, containers, hosts, and virtual machines that Sysdig scans at runtime. |
Sysdig uses only the most recent scan of each resource. When Sysdig scans a resource again, the new findings replace the earlier ones. The page does not refresh automatically, so reload it to see the results of new scans.
Understand the Findings Table
By default, each row is one finding on one component in one resource. The table shows these columns:
| Column | Description |
|---|---|
| Finding | The finding name, with an icon in the color of its severity. |
| Component | The type of the component, such as an operating system package or a Java package. |
| Component Name / Path | The name and version of the component, and the path where Sysdig found it. Operating system packages show no path. |
| Resource | The name and type of the resource that contains the component. |
| Resource Context | Where the resource runs. For example, the cluster and namespace, or the cloud account and region. |
| Severity | The severity of the finding. |
| First Seen | When Sysdig first detected the finding on the resource. |
The table sorts by Severity, with the highest first. You can also sort by First Seen. The table loads 50 rows at a time. Select Load more to see more rows.
The page URL keeps your filters, grouping, and sort order. Copy the URL to share the same view.
Group Findings
Use Group by to change what each row represents:
| Group by | Each row shows | Columns | Select a row to open |
|---|---|---|---|
| None | One finding. This is the default. | See the table above. | The finding details. |
| Package | One component and its findings across all resources. | Component, Component Context, Licenses, Findings, Resources, First Seen | The Component Details drawer. |
| Image | One image in one stage. An image in more than one stage has one row for each stage. | Resource, Resource Context, Stage, Resources, Findings, First Seen | The image details. |
| Runtime Resource | One runtime resource, such as a workload or host. | Resource, Resource Context, Findings, First Seen | The Resource Details drawer. |
When you group findings, the table sorts by the number of findings, with the highest first.
The Image grouping does not include hosts, virtual machines, or serverless functions. The Runtime Resource grouping includes runtime resources only, so the Stage filter does not appear.
Filter Findings
Use filters to focus on the findings that matter to you. Select values from a list, or type a value for the filters that take text.
| Filter | Values | Description |
|---|---|---|
| Zone | Your zones | Shows findings on resources in the selected zones. |
| Severity | Critical, High, Medium, Low, Negligible | Shows findings of the selected severities. |
| Stage | Pipeline, Registry, Runtime | Shows findings from the selected stages. |
| Finding Type | License, End of Life | Shows license findings, EOL findings, or both. |
| Finding Name | The nine finding names | Shows findings with the selected names. See Finding Types. |
| License Category | Copyleft, Network Copyleft, Restricted Use, Commercial Restriction, Proprietary, Ambiguous, Unknown | Shows license findings in the selected categories. |
| License Name | Text, such as GPL-3.0 | Shows license findings for a license. Type the exact SPDX identifier. |
| Cluster Name | Text | Shows findings on resources in the cluster. |
| Namespace | Text | Shows findings on resources in the namespace. |
| Resource Name | Text | Shows findings on the resource. |
Review a Finding in Detail
Select a finding to open the finding details. The header shows the finding name, its severity, the affected resource, and when Sysdig first saw the finding. The Highlights tab has three sections. Each section shows a field only when the finding has a value for it.
| Section | Field | Description |
|---|---|---|
| Affected Resource Summary | Affected Resource | The resource that contains the component. Select it to open the resource or image details. |
| Resource Context | Where the resource runs. | |
| Stage | The stage of the scan: pipeline, registry, or runtime. | |
| Finding Summary | Finding Name | The name of the finding. |
| Severity | The severity of the finding. | |
| Licenses | For a license finding, the number of licenses on the component. Hover over it to see the SPDX identifier of each license. | |
| EOL | For an EOL finding, EOL or Approaching EOL. | |
| Component Details | Component Name | The name of the component. Select it to open the Component Details drawer. |
| Component Category | The type of the component. | |
| Path | The path where Sysdig found the component. |
The finding details do not show the EOL date. To see the EOL date of a component, open the component from the Components tab of the Resource Details drawer. For more information, see Software Lifecycle and End-of-Life Visibility.
Supply Chain Findings in Other Drawers
The Resource Details drawer and the Component Details drawer each have a Supply Chain Findings tab. The tab shows the same table and filters, limited to that resource, image, or component. For more information on the Resource Details drawer, see View Resource Details.
Limitations
In this Technical Preview, the Supply Chain Findings page does not:
- Let you accept the risk of a finding or add an exception.
- Export findings.
- Show whether a finding fails a policy. To enforce rules on EOL components, use a Component Lifecycle rule in a vulnerability policy. For more information, see Use Lifecycle Data in Policies.
- Support a free-text search. Use the filters instead.