Skip to main content

25 docs tagged with "rules"

Detailed explanation of rule evaluation and JSON logic.

View all tags

age

Image should be less than expected days old.

cve-count

Max allowed violations for a given severity level.

env-blacklist

Image must not contain forbidden environment variables.

fix-available

All vulnerabilities should be fixed if a patch exists.

has-sbom

Image must provide a Software Bill of Materials.

license-blocklist

Image must not include components with licenses from the configured blocklist.

min-score

OpenSSF Scorecard score is above the threshold.

Playbook customisation

Playbooks let you define your own security policies and customise the structure of your reports.

Rules

This reference lists all built-in criteria shipped with Regis. For a conceptual overview of how rules and criteria work, how to override defaults, and how to bind a criterion, see Concepts → Rules and criteria.

Rules and criteria

Rules are the evaluation heart of Regis. A rule is the policy decision your

secret-scan

No secrets or credentials should be embedded in the image.

verified-secrets

No verified, active credentials should be embedded in the image.