Skip to content

Commit 2e9e5bc

Browse files
Merge pull request #226505 from bmansheim/container-vulnerability-rn
Move container vulnerability to GA from upcoming changes to RN
2 parents 97336fd + 263b9c0 commit 2e9e5bc

File tree

3 files changed

+8
-10
lines changed

3 files changed

+8
-10
lines changed

articles/defender-for-cloud/release-notes.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,15 @@ To learn about *planned* changes that are coming soon to Defender for Cloud, see
2020

2121
Updates in February include:
2222

23+
[Recommendation to find vulnerabilities in running container images released for General Availability (GA)](#recommendation-to-find-vulnerabilities-in-running-container-images-released-for-general-availability-ga)
2324
- [Announcing support for the AWS CIS 1.5.0 compliance standard](#announcing-support-for-the-aws-cis-150-compliance-standard)
2425

26+
### Recommendation to find vulnerabilities in running container images released for General Availability (GA)
27+
28+
The [Running container images should have vulnerability findings resolved](defender-for-containers-vulnerability-assessment-azure.md#view-vulnerabilities-for-images-running-on-your-aks-clusters) recommendation is now GA. The recommendation is used to identify unhealthy resources and is included in the calculations of your secure score.
29+
30+
We recommend that you use the recommendation to remediate vulnerabilities in your containers. Learn about [recommendation remediation](implement-security-recommendations.md).
31+
2532
### Announcing support for the AWS CIS 1.5.0 compliance standard
2633

2734
Defender for Cloud now supports the CIS Amazon Web Services Foundations v1.5.0 compliance standard. The standard can be [added to your Regulatory Compliance dashboard](update-regulatory-compliance-packages.md#add-a-regulatory-standard-to-your-dashboard), and builds on MDC's existing offerings for multicloud recommendations and standards.

articles/defender-for-cloud/supported-machines-endpoint-solutions-clouds-containers.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ The **tabs** below show the features that are available, by environment, for Mic
2121
| Compliance | Docker CIS | VM, Virtual Machine Scale Set | GA | - | Log Analytics agent | Defender for Servers Plan 2 | Commercial clouds<br><br> National clouds: Azure Government, Azure China 21Vianet |
2222
| Vulnerability Assessment <sup>[2](#footnote2)</sup> | Registry scan - OS packages | ACR, Private ACR | GA | Preview | Agentless | Defender for Containers | Commercial clouds<br><br> National clouds: Azure Government, Azure China 21Vianet |
2323
| Vulnerability Assessment <sup>[3](#footnote3)</sup> | Registry scan - language specific packages | ACR, Private ACR | Preview | - | Agentless | Defender for Containers | Commercial clouds |
24-
| Vulnerability Assessment | View vulnerabilities for running images | AKS | Preview | Preview | Defender profile | Defender for Containers | Commercial clouds |
24+
| Vulnerability Assessment | View vulnerabilities for running images | AKS | GA | GA | Defender profile | Defender for Containers | Commercial clouds |
2525
| Hardening | Control plane recommendations | ACR, AKS | GA | GA | Agentless | Free | Commercial clouds<br><br> National clouds: Azure Government, Azure China 21Vianet |
2626
| Hardening | Kubernetes data plane recommendations | AKS | GA | - | Azure Policy | Free | Commercial clouds<br><br> National clouds: Azure Government, Azure China 21Vianet |
2727
| Runtime protection| Threat detection (control plane)| AKS | GA | GA | Agentless | Defender for Containers | Commercial clouds<br><br> National clouds: Azure Government, Azure China 21Vianet |

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -18,20 +18,11 @@ If you're looking for the latest release notes, you'll find them in the [What's
1818

1919
| Planned change | Estimated date for change |
2020
|--|--|
21-
| [Recommendation to find vulnerabilities in running container images to be released for General Availability (GA)](#recommendation-to-find-vulnerabilities-in-running-container-images-to-be-released-for-general-availability-ga) | February 2023 |
2221
| [The built-in policy [Preview]: Private endpoint should be configured for Key Vault is will be deprecated](#the-built-in-policy-preview-private-endpoint-should-be-configured-for-key-vault-will-be-deprecated) | February 2023 |
2322
| [Three alerts in Defender for Three alerts in Defender for Azure Resource Manager plan will be deprecated](#three-alerts-in-defender-for-three-alerts-in-defender-for-azure-resource-manager-plan-will-be-deprecated) | March 2023 |
2423
| [Alerts automatic export to Log Analytics workspace will be deprecated](#alerts-automatic-export-to-log-analytics-workspace-will-be-deprecated) | March 2023 |
2524
| [Deprecation and improvement of selected alerts for Windows and Linux Servers](#deprecation-and-improvement-of-selected-alerts-for-windows-and-linux-servers) | April 2023 |
2625

27-
### Recommendation to find vulnerabilities in running container images to be released for General Availability (GA)
28-
29-
**Estimated date for change: February 2023**
30-
31-
The [Running container images should have vulnerability findings resolved](defender-for-containers-vulnerability-assessment-azure.md#view-vulnerabilities-for-images-running-on-your-aks-clusters) recommendation is currently in preview. While a recommendation is in preview, it doesn't render a resource unhealthy and isn't included in the calculations of your secure score.
32-
33-
We recommend that you use the recommendation to remediate vulnerabilities in your containers. Remediating the recommendation won't affect your secure score when the recommendation is released as GA. Learn about [recommendation remediation](implement-security-recommendations.md).
34-
3526
### The built-in policy \[Preview]: Private endpoint should be configured for Key Vault will be deprecated
3627

3728
**Estimated date for change: February 2023**

0 commit comments

Comments
 (0)