Scan container images from Harbor in Snyk
Snyk tests and monitors your Harbor container images by evaluating its tags in your repositories. Once your container images are imported to Snyk, your image vulnerabilities are surfaced and can be triaged easily.
Follow the instructions on this page to add images from Harbor to Snyk.
Prerequisites for Harbor container image scanning
Have a Snyk account with access to the relevant organization (given by an administrator).
Harbor integration configured. To learn more about that, follow the steps in Container security with Harbor integration.
Steps in scanning Harbor images
Log in to your account and navigate to the relevant Group and Organization that you want to manage.
Under the Projects tab, click Add project. The list of integrations already configured on your account opens. Select the Harbor option or Other if Harbor does not appear.
Which images do you want to test? appears, displaying all of the available images for your connected registry, grouped by each of your repositories.
Select single or multiple images to be imported to Snyk, by choosing a specific image or selecting an entire repository. You can also search by image name to find specific images to import. To finish, click Add selected repositories on the top-right.
A status bar appears at the top of the page as the images are imported; you can continue working in the meantime.
When the import ends:
You can view the newly imported image in the Projects page (marked with a NEW tag). Images are grouped by repository and are each linked individually to a detailed Project page.
An import log becomes available, reachable from the top of the projects list.
To enrich the data and get recommendations regarding your base image, nuder Settings you can connect your Dockerfile to the image project. For more info, see Adding your Dockerfile and test your base image.
Harbor imports are indicated with a unique icon. You can also filter to view only the Harbor projects:

Last updated
Was this helpful?