diff --git a/wait-for-ecr-scan-and-get-sarif/findings_vs_enhanced_findings_attributes.txt b/wait-for-ecr-scan-and-get-sarif/enhancedFindings.txt similarity index 100% rename from wait-for-ecr-scan-and-get-sarif/findings_vs_enhanced_findings_attributes.txt rename to wait-for-ecr-scan-and-get-sarif/enhancedFindings.txt diff --git a/wait-for-ecr-scan-and-get-sarif/findings.txt b/wait-for-ecr-scan-and-get-sarif/findings.txt new file mode 100644 index 0000000..fca4b52 --- /dev/null +++ b/wait-for-ecr-scan-and-get-sarif/findings.txt @@ -0,0 +1,34 @@ +findings -> (list) + +The findings from the image scan. + +(structure) + +Contains information about an image scan finding. + +name -> (string) + +The name associated with the finding, usually a CVE number. +description -> (string) + +The description of the finding. +uri -> (string) + +A link containing additional details about the security vulnerability. +severity -> (string) + +The finding severity. +attributes -> (list) + +A collection of attributes of the host from which the finding is generated. + +(structure) + +This data type is used in the ImageScanFinding data type. + +key -> (string) + +The attribute key. +value -> (string) + +The value assigned to the attribute key.