<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Supply Chain Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/</link><description>Recent content on Supply Chain Findings</description><language>en</language><lastBuildDate>Thu, 01 Oct 2026 11:53:24 +0100</lastBuildDate><image><url> https://docs.sysdig.com/icons/sysdig-horizontal.png</url><title>Supply Chain Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/</link><description>Sysdig logo</description></image><item><title>Supply Chain Findings - Overview</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#overview</link><description>The Supply Chain Findings page lists the license and end-of-life (EOL) findings on the resources that Sysdig scans. Use it to find components that:</description><content:encoded><![CDATA[<p>The <strong>Supply Chain Findings</strong> page lists the license and end-of-life (EOL) findings on the resources that Sysdig scans. Use it to find components that:</p>

<ul>

<li>Use a license that puts obligations or restrictions on your organization, such as a copyleft, proprietary, or commercial-restriction license.</li>

<li>Have reached end of life, or reach end of life within 90 days.</li>
</ul>


<p>Sysdig raises these findings from the same scans that Vulnerability Management uses. You do not need to install or configure a separate scanner.</p>
<div class='row alert d-flex infobox infobox--note'>
  <div class="ps-0 col-md-auto">
  <i class='fas fa-info-circle fa-lg'></i>
  </div>
  <div class="ps-0 col infobox__contents">
  
<p class="infobox__title">Feature Availability</p>
  
<p>Supply Chain Findings is in <strong>Technical Preview</strong>. It is still in active development and can change significantly in future releases.</p>

<p>This feature is available to all Sysdig Secure SaaS deployments.</p>
  </div>
</div>]]></content:encoded><guid isPermaLink="false">Overview</guid></item><item><title>Supply Chain Findings - Prerequisites</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#prerequisites</link><description>A Sysdig Secure SaaS account. Supply Chain Findings is not available on-premises. A role with the Scan Results (Read) permission or the legacy Scanning (Read) permission. For more information, see Detailed Role Permissions. At least one scan of a pipeline, registry, or runtime resource.</description><content:encoded><![CDATA[<ul>

<li>A Sysdig Secure SaaS account. Supply Chain Findings is not available on-premises.</li>

<li>A role with the <strong>Scan Results</strong> (Read) permission or the legacy <strong>Scanning</strong> (Read) permission. For more information, see <a href="/en/administration/role_permissions/">Detailed Role Permissions</a>.</li>

<li>At least one scan of a pipeline, registry, or runtime resource.</li>
</ul>]]></content:encoded><guid isPermaLink="false">Prerequisites</guid></item><item><title>Supply Chain Findings - Access Supply Chain Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#access-supply-chain-findings</link><description>Select Attack Surface &amp;gt; Supply Chain Findings.</description><content:encoded><![CDATA[<p>Select <strong>Attack Surface</strong> &gt; <strong>Supply Chain Findings</strong>.</p>]]></content:encoded><guid isPermaLink="false">Access Supply Chain Findings</guid></item><item><title>Supply Chain Findings - Finding Types</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#finding-types</link><description>Each finding has a type, a name, and a severity. Sysdig sets the severity from the finding name. You cannot change it.</description><content:encoded><![CDATA[<p>Each finding has a type, a name, and a severity. Sysdig sets the severity from the finding name. You cannot change it.</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Finding Type</th>
					<th style="text-align: left">Finding Name</th>
					<th style="text-align: left">Severity</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses a network copyleft license</td>
					<td style="text-align: left">Critical</td>
			</tr>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses a license that restricts commercial use</td>
					<td style="text-align: left">Critical</td>
			</tr>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses a proprietary license</td>
					<td style="text-align: left">Medium</td>
			</tr>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses a license that restricts use</td>
					<td style="text-align: left">Medium</td>
			</tr>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses a copyleft license</td>
					<td style="text-align: left">Medium</td>
			</tr>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses a license with ambiguous terms</td>
					<td style="text-align: left">Low</td>
			</tr>
			<tr>
					<td style="text-align: left">License</td>
					<td style="text-align: left">Component uses an unrecognized license</td>
					<td style="text-align: left">Negligible</td>
			</tr>
			<tr>
					<td style="text-align: left">End of Life</td>
					<td style="text-align: left">Component has reached end of life</td>
					<td style="text-align: left">High</td>
			</tr>
			<tr>
					<td style="text-align: left">End of Life</td>
					<td style="text-align: left">Component is approaching end of life</td>
					<td style="text-align: left">Medium</td>
			</tr>
	</tbody>
</table>

<p>For license findings:</p>

<ul>

<li>Sysdig raises at most one license finding for each component. The table lists the license findings in precedence order. When a component has more than one license, the first matching row sets the finding.</li>

<li>Permissive and weak copyleft licenses raise no finding.</li>

<li>A component with no license metadata raises no finding.</li>
</ul>


<p>For more information on license categories, see <a href="/en/sysdig-secure/license-classification/">License Classification</a>.</p>

<p>For EOL findings:</p>

<ul>

<li>Sysdig raises EOL findings for operating systems and for the Go runtime only. Other runtimes, libraries, and packages raise no EOL finding.</li>

<li>Packages that an operating system package manager installs do not inherit the EOL date of the operating system.</li>

<li>A component is approaching end of life when its EOL date is 90 days away or less. This window is fixed.</li>

<li>A component with no EOL data raises no finding.</li>
</ul>


<p>For the list of supported operating systems, see <a href="/en/sysdig-secure/vm-lifecycle-visibility/#supported-coverage">Software Lifecycle and End-of-Life Visibility</a>.</p>]]></content:encoded><guid isPermaLink="false">Finding Types</guid></item><item><title>Supply Chain Findings - Where Findings Come From</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#where-findings-come-from</link><description>Each finding belongs to one stage:</description><content:encoded><![CDATA[<p>Each finding belongs to one stage:</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Stage</th>
					<th style="text-align: left">Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>Pipeline</strong></td>
					<td style="text-align: left">Images that you scan in your CI/CD pipeline.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Registry</strong></td>
					<td style="text-align: left">Images that you scan in your container registries.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Runtime</strong></td>
					<td style="text-align: left">Kubernetes workloads, containers, hosts, and virtual machines that Sysdig scans at runtime.</td>
			</tr>
	</tbody>
</table>

<p>Sysdig uses only the most recent scan of each resource. When Sysdig scans a resource again, the new findings replace the earlier ones. The page does not refresh automatically, so reload it to see the results of new scans.</p>]]></content:encoded><guid isPermaLink="false">Where Findings Come From</guid></item><item><title>Supply Chain Findings - Understand the Findings Table</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#understand-the-findings-table</link><description>By default, each row is one finding on one component in one resource. The table shows these columns:</description><content:encoded><![CDATA[<p>By default, each row is one finding on one component in one resource. The table shows these columns:</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Column</th>
					<th style="text-align: left">Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>Finding</strong></td>
					<td style="text-align: left">The finding name, with an icon in the color of its severity.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Component</strong></td>
					<td style="text-align: left">The type of the component, such as an operating system package or a Java package.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Component Name / Path</strong></td>
					<td style="text-align: left">The name and version of the component, and the path where Sysdig found it. Operating system packages show no path.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Resource</strong></td>
					<td style="text-align: left">The name and type of the resource that contains the component.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Resource Context</strong></td>
					<td style="text-align: left">Where the resource runs. For example, the cluster and namespace, or the cloud account and region.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Severity</strong></td>
					<td style="text-align: left">The severity of the finding.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>First Seen</strong></td>
					<td style="text-align: left">When Sysdig first detected the finding on the resource.</td>
			</tr>
	</tbody>
</table>

<p>The table sorts by <strong>Severity</strong>, with the highest first. You can also sort by <strong>First Seen</strong>. The table loads 50 rows at a time. Select <strong>Load more</strong> to see more rows.</p>

<p>The page URL keeps your filters, grouping, and sort order. Copy the URL to share the same view.</p>

<h3 id="group-findings">Group Findings</h3>
<p>Use <strong>Group by</strong> to change what each row represents:</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Group by</th>
					<th style="text-align: left">Each row shows</th>
					<th style="text-align: left">Columns</th>
					<th style="text-align: left">Select a row to open</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>None</strong></td>
					<td style="text-align: left">One finding. This is the default.</td>
					<td style="text-align: left">See the table above.</td>
					<td style="text-align: left">The finding details.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Package</strong></td>
					<td style="text-align: left">One component and its findings across all resources.</td>
					<td style="text-align: left">Component, Component Context, Licenses, Findings, Resources, First Seen</td>
					<td style="text-align: left">The Component Details drawer.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Image</strong></td>
					<td style="text-align: left">One image in one stage. An image in more than one stage has one row for each stage.</td>
					<td style="text-align: left">Resource, Resource Context, Stage, Resources, Findings, First Seen</td>
					<td style="text-align: left">The image details.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Runtime Resource</strong></td>
					<td style="text-align: left">One runtime resource, such as a workload or host.</td>
					<td style="text-align: left">Resource, Resource Context, Findings, First Seen</td>
					<td style="text-align: left">The Resource Details drawer.</td>
			</tr>
	</tbody>
</table>

<p>When you group findings, the table sorts by the number of findings, with the highest first.</p>
<div class='row alert d-flex infobox infobox--note'>
  <div class="ps-0 col-md-auto">
  <i class='fas fa-info-circle fa-lg'></i>
  </div>
  <div class="ps-0 col infobox__contents">

<p>The <strong>Image</strong> grouping does not include hosts, virtual machines, or serverless functions. The <strong>Runtime Resource</strong> grouping includes runtime resources only, so the <strong>Stage</strong> filter does not appear.</p>
  </div>
</div>]]></content:encoded><guid isPermaLink="false">Understand the Findings Table</guid></item><item><title>Supply Chain Findings - Filter Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#filter-findings</link><description>Use filters to focus on the findings that matter to you. Select values from a list, or type a value for the filters that take text.</description><content:encoded><![CDATA[<p>Use filters to focus on the findings that matter to you. Select values from a list, or type a value for the filters that take text.</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Filter</th>
					<th style="text-align: left">Values</th>
					<th style="text-align: left">Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>Zone</strong></td>
					<td style="text-align: left">Your zones</td>
					<td style="text-align: left">Shows findings on resources in the selected zones.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Severity</strong></td>
					<td style="text-align: left"><code>Critical</code>, <code>High</code>, <code>Medium</code>, <code>Low</code>, <code>Negligible</code></td>
					<td style="text-align: left">Shows findings of the selected severities.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Stage</strong></td>
					<td style="text-align: left"><code>Pipeline</code>, <code>Registry</code>, <code>Runtime</code></td>
					<td style="text-align: left">Shows findings from the selected stages.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Finding Type</strong></td>
					<td style="text-align: left"><code>License</code>, <code>End of Life</code></td>
					<td style="text-align: left">Shows license findings, EOL findings, or both.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Finding Name</strong></td>
					<td style="text-align: left">The nine finding names</td>
					<td style="text-align: left">Shows findings with the selected names. See <a href="/en/sysdig-secure/supply-chain-findings/#finding-types">Finding Types</a>.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>License Category</strong></td>
					<td style="text-align: left"><code>Copyleft</code>, <code>Network Copyleft</code>, <code>Restricted Use</code>, <code>Commercial Restriction</code>, <code>Proprietary</code>, <code>Ambiguous</code>, <code>Unknown</code></td>
					<td style="text-align: left">Shows license findings in the selected categories.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>License Name</strong></td>
					<td style="text-align: left">Text, such as <code>GPL-3.0</code></td>
					<td style="text-align: left">Shows license findings for a license. Type the exact SPDX identifier.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Cluster Name</strong></td>
					<td style="text-align: left">Text</td>
					<td style="text-align: left">Shows findings on resources in the cluster.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Namespace</strong></td>
					<td style="text-align: left">Text</td>
					<td style="text-align: left">Shows findings on resources in the namespace.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Resource Name</strong></td>
					<td style="text-align: left">Text</td>
					<td style="text-align: left">Shows findings on the resource.</td>
			</tr>
	</tbody>
</table>]]></content:encoded><guid isPermaLink="false">Filter Findings</guid></item><item><title>Supply Chain Findings - Review a Finding in Detail</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#review-a-finding-in-detail</link><description>Select a finding to open the finding details. The header shows the finding name, its severity, the affected resource, and when Sysdig first saw the finding. The Highlights tab has three sections. Each section shows a field only when the finding has a value for it.</description><content:encoded><![CDATA[<p>Select a finding to open the finding details. The header shows the finding name, its severity, the affected resource, and when Sysdig first saw the finding. The <strong>Highlights</strong> tab has three sections. Each section shows a field only when the finding has a value for it.</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Section</th>
					<th style="text-align: left">Field</th>
					<th style="text-align: left">Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><strong>Affected Resource Summary</strong></td>
					<td style="text-align: left"><strong>Affected Resource</strong></td>
					<td style="text-align: left">The resource that contains the component. Select it to open the resource or image details.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>Resource Context</strong></td>
					<td style="text-align: left">Where the resource runs.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>Stage</strong></td>
					<td style="text-align: left">The stage of the scan: pipeline, registry, or runtime.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Finding Summary</strong></td>
					<td style="text-align: left"><strong>Finding Name</strong></td>
					<td style="text-align: left">The name of the finding.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>Severity</strong></td>
					<td style="text-align: left">The severity of the finding.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>Licenses</strong></td>
					<td style="text-align: left">For a license finding, the number of licenses on the component. Hover over it to see the SPDX identifier of each license.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>EOL</strong></td>
					<td style="text-align: left">For an EOL finding, <code>EOL</code> or <code>Approaching EOL</code>.</td>
			</tr>
			<tr>
					<td style="text-align: left"><strong>Component Details</strong></td>
					<td style="text-align: left"><strong>Component Name</strong></td>
					<td style="text-align: left">The name of the component. Select it to open the Component Details drawer.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>Component Category</strong></td>
					<td style="text-align: left">The type of the component.</td>
			</tr>
			<tr>
					<td style="text-align: left"></td>
					<td style="text-align: left"><strong>Path</strong></td>
					<td style="text-align: left">The path where Sysdig found the component.</td>
			</tr>
	</tbody>
</table>

<p>The finding details do not show the EOL date. To see the EOL date of a component, open the component from the <strong>Components</strong> tab of the Resource Details drawer. For more information, see <a href="/en/sysdig-secure/vm-lifecycle-visibility/#where-lifecycle-information-appears">Software Lifecycle and End-of-Life Visibility</a>.</p>]]></content:encoded><guid isPermaLink="false">Review a Finding in Detail</guid></item><item><title>Supply Chain Findings - Supply Chain Findings in Other Drawers</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#supply-chain-findings-in-other-drawers</link><description>The Resource Details drawer and the Component Details drawer each have a Supply Chain Findings tab. The tab shows the same table and filters, limited to that resource, image, or component. For more information on the Resource Details drawer, see View Resource Details.</description><content:encoded><![CDATA[<p>The Resource Details drawer and the Component Details drawer each have a <strong>Supply Chain Findings</strong> tab. The tab shows the same table and filters, limited to that resource, image, or component. For more information on the Resource Details drawer, see <a href="/en/sysdig-secure/inventory-resources/#view-resource-details">View Resource Details</a>.</p>]]></content:encoded><guid isPermaLink="false">Supply Chain Findings in Other Drawers</guid></item><item><title>Supply Chain Findings - Limitations</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#limitations</link><description>In this Technical Preview, the Supply Chain Findings page does not:</description><content:encoded><![CDATA[<p>In this Technical Preview, the Supply Chain Findings page does not:</p>

<ul>

<li>Let you accept the risk of a finding or add an exception.</li>

<li>Export findings.</li>

<li>Show whether a finding fails a policy. To enforce rules on EOL components, use a Component Lifecycle rule in a vulnerability policy. For more information, see <a href="/en/sysdig-secure/vm-lifecycle-visibility/#use-lifecycle-data-in-policies">Use Lifecycle Data in Policies</a>.</li>

<li>Support a free-text search. Use the filters instead.</li>
</ul>]]></content:encoded><guid isPermaLink="false">Limitations</guid></item><item><title>Supply Chain Findings - Related Content</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain-findings/#related-content</link><description>Supply Chain Security License Classification Software Lifecycle and End-of-Life Visibility Run CLI Scanner in VM Mode Vulnerability Findings</description><content:encoded><![CDATA[<ul>

<li><a href="/en/sysdig-secure/supply-chain/">Supply Chain Security</a></li>

<li><a href="/en/sysdig-secure/license-classification/">License Classification</a></li>

<li><a href="/en/sysdig-secure/vm-lifecycle-visibility/">Software Lifecycle and End-of-Life Visibility</a></li>

<li><a href="/en/sysdig-secure/cli-scanner-vm-mode/#license-information">Run CLI Scanner in VM Mode</a></li>

<li><a href="/en/docs/sysdig-secure/vulnerabilities/vulnerability-findings/">Vulnerability Findings</a></li>
</ul>]]></content:encoded><guid isPermaLink="false">Related Content</guid></item></channel></rss>