Skip to content

[K9VULN-12533][k9-cloud-vm] Added Link Dockerfile to vulnerabilities section#35332

Draft
LucasChevrierGit wants to merge 2 commits intomasterfrom
lucas.chevrier/K9VULN-12533-Add-documentation-to-link-Dockerfile-to-vulnerabilities
Draft

[K9VULN-12533][k9-cloud-vm] Added Link Dockerfile to vulnerabilities section#35332
LucasChevrierGit wants to merge 2 commits intomasterfrom
lucas.chevrier/K9VULN-12533-Add-documentation-to-link-Dockerfile-to-vulnerabilities

Conversation

@LucasChevrierGit
Copy link

@LucasChevrierGit LucasChevrierGit commented Mar 17, 2026

What does this PR do? What is the motivation?

This PR adds documentation for linking container image vulnerabilities back to their originating Dockerfile using OCI annotations.

It introduces a new section explaining the required annotations:
• org.opencontainers.image.source
• org.opencontainers.image.revision
• com.datadoghq.image.source_path

The goal is to make vulnerability findings more actionable by enabling source-level traceability (repo, commit, Dockerfile) instead of relying only on image metadata.

Also includes:
• a concrete docker build example
• a link to the OCI annotations specification

image

Merge instructions

Merge readiness:

  • Ready for merge

For Datadog employees:

Your branch name MUST follow the <name>/<description> convention and include the forward slash (/). Without this format, your pull request will not pass CI, the GitLab pipeline will not run, and you won't get a branch preview. Getting a branch preview makes it easier for us to check any issues with your PR, such as broken links.

If your branch doesn't follow this format, rename it or create a new branch and PR.

[6/5/2025] Merge queue has been disabled on the documentation repo. If you have write access to the repo, the PR has been reviewed by a Documentation team member, and all of the required checks have passed, you can use the Squash and Merge button to merge the PR. If you don't have write access, or you need help, reach out in the #documentation channel in Slack.

AI assistance

Additional notes

@LucasChevrierGit LucasChevrierGit changed the title [K9VULN-12533] Added Link Dockerfile to vulnerabilities section [K9VULN-12533][k9-cloud-vm] Added Link Dockerfile to vulnerabilities section Mar 17, 2026
@LucasChevrierGit LucasChevrierGit force-pushed the lucas.chevrier/K9VULN-12533-Add-documentation-to-link-Dockerfile-to-vulnerabilities branch 2 times, most recently from 3983c43 to b152ca8 Compare March 17, 2026 14:16
@github-actions
Copy link
Contributor

@LucasChevrierGit LucasChevrierGit force-pushed the lucas.chevrier/K9VULN-12533-Add-documentation-to-link-Dockerfile-to-vulnerabilities branch from b152ca8 to 0d54fee Compare March 17, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant