From 28d96877a26cb68b98dbc25dc40b2cfd0c3a10be Mon Sep 17 00:00:00 2001 From: Ralph Bean Date: Thu, 25 Sep 2025 11:56:01 -0400 Subject: [PATCH] Set cpe label on bundle and operator images Clair needs access to a name and cpe label that it can use to look up the image in VEX statements. --- build/Dockerfile.openshift | 1 + bundle.openshift.Dockerfile | 1 + 2 files changed, 2 insertions(+) diff --git a/build/Dockerfile.openshift b/build/Dockerfile.openshift index 503bfce43..0bfd6c70f 100644 --- a/build/Dockerfile.openshift +++ b/build/Dockerfile.openshift @@ -31,6 +31,7 @@ LABEL \ maintainer="Red Hat ISC " \ License="GPLv2+" \ name="compliance/openshift-file-integrity-rhel8-operator" \ + cpe="cpe:/a:redhat:openshift_file_integrity_operator:1::el9" \ com.redhat.component="openshift-file-integrity-operator-container" \ io.openshift.maintainer.product="OpenShift Container Platform" \ io.openshift.maintainer.component="File Integrity Operator" \ diff --git a/bundle.openshift.Dockerfile b/bundle.openshift.Dockerfile index 836eb6b89..6d23340fb 100644 --- a/bundle.openshift.Dockerfile +++ b/bundle.openshift.Dockerfile @@ -21,6 +21,7 @@ FROM scratch ARG FIO_NEW_VERSION LABEL name="compliance/openshift-file-integrity-operator-bundle" +LABEL cpe="cpe:/a:redhat:openshift_file_integrity_operator:1::el9" LABEL version=${FIO_NEW_VERSION} LABEL summary='OpenShift File Integrity Operator' LABEL maintainer='Infrastructure Security and Compliance Team '