imagebuilder / Paginator / ListImageScanFindings

ListImageScanFindings

class imagebuilder.Paginator.ListImageScanFindings
paginator = client.get_paginator('list_image_scan_findings')
paginate(**kwargs)

Creates an iterator that will paginate through responses from imagebuilder.Client.list_image_scan_findings().

See also: AWS API Documentation

Request Syntax

response_iterator = paginator.paginate(
    filters=[
        {
            'name': 'string',
            'values': [
                'string',
            ]
        },
    ],
    PaginationConfig={
        'MaxItems': 123,
        'PageSize': 123,
        'StartingToken': 'string'
    }
)
Parameters:
  • filters (list) –

    An array of name value pairs that you can use to filter your results. You can use the following filters to streamline results:

    • imageBuildVersionArn – Filters findings by the image build version that was scanned.

    • imagePipelineArn – Filters findings by the pipeline that created the scanned image.

    • vulnerabilityId – Filters findings by vulnerability ID, for example a CVE ID.

    • severity – Filters findings by severity level.

    If you don’t request a filter, then all findings in your account are listed.

    • (dict) –

      A name value pair that Image Builder applies to streamline results from the vulnerability scan findings list action.

      • name (string) –

        The name of the image scan finding filter. Filter names are case-sensitive. Valid filter names are:

        • imageBuildVersionArn – Filters findings by the image build version that was scanned.

        • imagePipelineArn – Filters findings by the pipeline that created the scanned image.

        • vulnerabilityId – Filters findings by vulnerability ID, for example a CVE ID.

        • severity – Filters findings by severity level.

      • values (list) –

        The filter values. Filter values are case-sensitive.

        • (string) –

  • PaginationConfig (dict) –

    A dictionary that provides parameters to control pagination.

    • MaxItems (integer) –

      The total number of items to return. If the total number of items available is more than the value specified in max-items then a NextToken will be provided in the output that you can use to resume pagination.

    • PageSize (integer) –

      The size of each page.

    • StartingToken (string) –

      A token to specify where to start paginating. This is the NextToken from a previous response.

Return type:

dict

Returns:

Response Syntax

{
    'requestId': 'string',
    'findings': [
        {
            'awsAccountId': 'string',
            'imageBuildVersionArn': 'string',
            'imagePipelineArn': 'string',
            'type': 'string',
            'description': 'string',
            'title': 'string',
            'remediation': {
                'recommendation': {
                    'text': 'string',
                    'url': 'string'
                }
            },
            'severity': 'string',
            'firstObservedAt': datetime(2015, 1, 1),
            'updatedAt': datetime(2015, 1, 1),
            'inspectorScore': 123.0,
            'inspectorScoreDetails': {
                'adjustedCvss': {
                    'scoreSource': 'string',
                    'cvssSource': 'string',
                    'version': 'string',
                    'score': 123.0,
                    'scoringVector': 'string',
                    'adjustments': [
                        {
                            'metric': 'string',
                            'reason': 'string'
                        },
                    ]
                }
            },
            'packageVulnerabilityDetails': {
                'vulnerabilityId': 'string',
                'vulnerablePackages': [
                    {
                        'name': 'string',
                        'version': 'string',
                        'sourceLayerHash': 'string',
                        'epoch': 123,
                        'release': 'string',
                        'arch': 'string',
                        'packageManager': 'string',
                        'filePath': 'string',
                        'fixedInVersion': 'string',
                        'remediation': 'string'
                    },
                ],
                'source': 'string',
                'cvss': [
                    {
                        'baseScore': 123.0,
                        'scoringVector': 'string',
                        'version': 'string',
                        'source': 'string'
                    },
                ],
                'relatedVulnerabilities': [
                    'string',
                ],
                'sourceUrl': 'string',
                'vendorSeverity': 'string',
                'vendorCreatedAt': datetime(2015, 1, 1),
                'vendorUpdatedAt': datetime(2015, 1, 1),
                'referenceUrls': [
                    'string',
                ]
            },
            'fixAvailable': 'string'
        },
    ],
    'NextToken': 'string'
}

Response Structure

  • (dict) –

    • requestId (string) –

      The request ID that uniquely identifies this request.

    • findings (list) –

      The image scan findings for your account that meet your request filter criteria.

      • (dict) –

        Contains details about a vulnerability scan finding that Amazon Inspector generated for an image.

        • awsAccountId (string) –

          The Amazon Web Services account ID that’s associated with the finding.

        • imageBuildVersionArn (string) –

          The Amazon Resource Name (ARN) of the image build version that’s associated with the finding.

        • imagePipelineArn (string) –

          The Amazon Resource Name (ARN) of the image pipeline that’s associated with the finding.

        • type (string) –

          The type of the finding. Image Builder looks for findings of the type PACKAGE_VULNERABILITY that apply to output images, and excludes other types.

        • description (string) –

          The description of the finding.

        • title (string) –

          The title of the finding.

        • remediation (dict) –

          An object that contains the details about how to remediate the finding.

          • recommendation (dict) –

            An object that contains information about the recommended course of action to remediate the finding.

            • text (string) –

              The recommended course of action to remediate the finding.

            • url (string) –

              A link to more information about the recommended remediation for this vulnerability.

        • severity (string) –

          The severity of the finding. For more information, see Severity levels for Amazon Inspector findings in the Amazon Inspector User Guide.

        • firstObservedAt (datetime) –

          The date and time when the finding was first observed.

        • updatedAt (datetime) –

          The timestamp when the finding was last updated.

        • inspectorScore (float) –

          The score that Amazon Inspector assigned for the finding.

        • inspectorScoreDetails (dict) –

          An object that contains details of the Amazon Inspector score.

          • adjustedCvss (dict) –

            The CVSS score that Amazon Inspector assigned to the finding after applying its adjustments. It includes the score source, CVSS version, scoring vector, and the adjustments applied.

            • scoreSource (string) –

              The source for the CVSS score.

            • cvssSource (string) –

              The source of the CVSS data that the Amazon Inspector score for the finding is based on, for example NVD or a vendor security feed.

            • version (string) –

              The CVSS version that generated the score.

            • score (float) –

              The CVSS score.

            • scoringVector (string) –

              A vector that measures the severity of the vulnerability.

            • adjustments (list) –

              The adjustments that Amazon Inspector applied to the base CVSS score to produce its own score for the finding. The list is empty when Amazon Inspector made no adjustments.

              • (dict) –

                Details about an adjustment that Amazon Inspector made to the CVSS score for a finding.

                • metric (string) –

                  The metric that Amazon Inspector used to adjust the CVSS score.

                • reason (string) –

                  The reason for the CVSS score adjustment.

        • packageVulnerabilityDetails (dict) –

          An object that contains the details of a package vulnerability finding.

          • vulnerabilityId (string) –

            A unique identifier for this vulnerability.

          • vulnerablePackages (list) –

            The packages that this vulnerability impacts.

            • (dict) –

              Information about a vulnerable package that Amazon Inspector identifies in a finding.

              • name (string) –

                The name of the vulnerable package.

              • version (string) –

                The version of the vulnerable package.

              • sourceLayerHash (string) –

                The source layer hash of the vulnerable package.

              • epoch (integer) –

                The epoch of the vulnerable package.

              • release (string) –

                The release of the vulnerable package.

              • arch (string) –

                The architecture of the vulnerable package.

              • packageManager (string) –

                The package manager of the vulnerable package.

              • filePath (string) –

                The file path of the vulnerable package.

              • fixedInVersion (string) –

                The version of the package that contains the vulnerability fix.

              • remediation (string) –

                The code to run in your environment to update packages with a fix available.

          • source (string) –

            The source of the vulnerability information.

          • cvss (list) –

            The CVSS scores for the vulnerability in this finding, as published by the vulnerability sources. Sources include NVD and the operating system vendor, and scores can span CVSS versions.

            • (dict) –

              A CVSS score for the vulnerability, as published by the vulnerability source. Sources include the National Vulnerability Database (NVD) and the operating system vendor’s security feed. A finding can include CVSS scores from multiple sources and CVSS versions.

              • baseScore (float) –

                The CVSS base score.

              • scoringVector (string) –

                The vector string of the CVSS score.

              • version (string) –

                The CVSS version that generated the score.

              • source (string) –

                The source of the CVSS score.

          • relatedVulnerabilities (list) –

            Vulnerabilities that are often related to the findings for the package.

            • (string) –

          • sourceUrl (string) –

            A link to the source of the vulnerability information.

          • vendorSeverity (string) –

            The severity that the vendor assigned to this vulnerability type.

          • vendorCreatedAt (datetime) –

            The date and time when this vulnerability was first added to the vendor’s database.

          • vendorUpdatedAt (datetime) –

            The date and time when the vendor last updated this vulnerability in their database.

          • referenceUrls (list) –

            Links to web pages that contain details about the vulnerabilities that Amazon Inspector identified for the package.

            • (string) –

        • fixAvailable (string) –

          Details about whether a fix is available for any of the packages that are identified in the finding through a version update. Valid values include:

          • YES – A fix is available for all of the packages identified in the finding.

          • NO – No fix is available.

          • PARTIAL – A fix is available for some, but not all, of the packages identified in the finding.

    • NextToken (string) –

      A token to resume pagination.