Calico Cloud Image Assurance Integration with DefectDojo
Calico Cloud Image Assurance Integration with DefectDojo
Calico Cloud is Tigera's managed security and observability platform for Kubernetes, and Image Assurance is its container image vulnerability scanning feature. Image Assurance scans images in registries and from the tigera-scanner CLI, identifying packages with known CVEs and reporting each vulnerability with its CVSS score, affected package, installed version, and fixed versions. DefectDojo accepts a JSON export of those results or, in DefectDojo Pro, pulls them from the Image Assurance API with a connector.
Calico Cloud Image Assurance Integration with DefectDojo
We already run Calico Cloud for our clusters, so Image Assurance was the obvious place to get image CVEs, and DefectDojo is where those CVEs turn into remediation work alongside everything else we track. Each vulnerability on each image becomes its own Finding, with a severity derived from the CVSS score rather than a per-tenant pass or fail verdict. That keeps our SLAs consistent, and because the same CVE in two images stays two Findings, the list reflects the actual rebuild work ahead of us.
Why Calico Cloud Image Assurance Matters
Container images ship an operating system userland plus application dependencies, and most teams inherit far more packages than they chose.
- Image Assurance scans images where they live, in registries, as well as in pipelines through
tigera-scanner, so coverage doesn't depend on every team wiring up a scanner. - It reports the fixed version for each vulnerable package, which is the detail an engineer needs to decide whether a base image update will clear the issue.
- For teams already running Calico Cloud, image vulnerability data comes from the same platform that handles their cluster networking and policy.
- Results on their own sit in the Calico Cloud console. Without a vulnerability management workflow behind them, there are no owners, deadlines, or history.
Advantages of This Integration
- Severity you can compare across tenants. The parser derives severity from the CVSS v3 base score and ignores Calico's Pass, Warn, and Fail verdict, which is per-tenant configuration. Calico's severity word is only a fallback when no score exists.
- Per-image identity. Each Finding's unique ID is
calico-cloud-<image id>-<vulnerability id>, so a CVE in two images remains two Findings, one per image to rebuild. - File and connector agree. The file parser uses the same scan type as the DefectDojo Pro connector, Calico Cloud Image Assurance Scan, so findings from an export and from an API sync deduplicate against each other.
- No partial scans recorded as complete. Images whose scan result is still Unknown are skipped entirely, matching the connector, so an unfinished registry scan never imports as a clean one.
- Platform workflow. Image CVEs get SLA timers, assignments, risk acceptance, and Jira pushes, and roll up with your other scanners in Asset metrics.
How This Integration Works
You can bring Image Assurance results in two ways: import a JSON export with UI Import, API Import, or Universal Importer, or configure the DefectDojo Pro API connector.
Option 1: Import a JSON export. Calico serves the image list and each image's vulnerabilities from two Image Assurance API endpoints, so an export combines both. The parser accepts vulnerabilities nested under each image in an images list, or an images list alongside a vulnerabilities map keyed by image ID. A bare array of images, or an object naming the list images, data, or results, also works. A file holding only the vulnerability response is accepted too, with an empty image ID.
Import it with the Calico Cloud Image Assurance Scan scan type. In the UI, choose Import Scan Results on the Engagement. With the API, in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Calico Cloud Image Assurance Scan"
-F "file=@calico-images.json"
-F "product_name=platform-images"
-F "engagement_name=Registry Scans"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Calico Cloud Image Assurance Scan"
--report-path "./calico-images.json"
--product-name "platform-images"
--engagement-name "Registry Scans"
--auto-create-context
Option 2: Use the API Connector (Pro). Get an Image Assurance API token from Image Assurance, Access Settings in the Calico Cloud UI (the same token tigera-scanner uses). In DefectDojo Pro, add the Calico Cloud connector, enter your Image Assurance API URL in Location (the value you would pass to tigera-scanner as --apiurl), enter the token, and optionally set a Minimum Severity. Each scanned image repository becomes a Record carrying the CVE results of its images, refreshed on each sync.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Calico Export | Notes |
|---|---|---|
| Title | Vulnerability id and name |
<id>: <name>, or whichever exists; a name repeating the ID isn't doubled |
| Severity | cvss3Score, then cvss.base_score, then severity |
9.0+ Critical, 7.0+ High, 4.0+ Medium, above 0 Low; negligible and unknown are Info |
| CVSS v3 Score | cvss3Score or cvss.base_score |
Quoted numbers accepted |
| Description | Advisory text, image reference, digest, package, versions | Image shown as <registry>/<repository>:<tag> when available |
| Mitigation | fixVersions or fix |
Upgrade <package> to <fix>.; empty when no fix |
| Component Name | package_name, else package |
|
| Component Version | version |
Installed version |
| References | url |
Advisory link |
| Vulnerability IDs | id |
Only when it is a CVE |
| Vuln ID from Tool | id |
Includes Calico's own advisory IDs |
| Unique ID from Tool | Image ID and vulnerability ID | calico-cloud-<image id>-<vulnerability id> |
| Date | resultTime, else scanned |
Image scan date |
| Finding type | Static, active | Image contents are analyzed, nothing is executed |
| Deduplication | Unique ID or hash code | Hash fields: title, severity, component_name, component_version |
Use Cases
For registry-wide visibility: The connector syncs every scanned repository as a Record. Mapping those Records to the Assets that own each image gives every service team its own open CVE list, with SLAs running from the date the image was scanned.
When rebuilding on a patched base image: A platform team updates a shared base image and rebuilds. The next sync or reimport shows which CVEs disappeared, image by image, and which remain because they come from application-installed packages.
In restricted environments: A team that can't grant DefectDojo Image Assurance API credentials exports the two API responses, combines them into one file, and imports it. Turning on the connector later doesn't create duplicates because the scan type is shared.
For audit evidence: Each Finding carries the image reference and digest in its description, so an auditor can trace a closed CVE to the exact image that was scanned.
Operational Tips
- Don't read a short Finding list as a coverage gap right away. Images still being scanned are skipped and will appear once Calico has results.
- Expect severities to differ from what the Calico console shows when your tenant thresholds don't match CVSS bands. That difference is deliberate.
- Calico advisories without a CVE don't get a vulnerability ID; search by Vuln ID from Tool to find them.
- Use the connector's Minimum Severity, or
minimum_severityon file imports, to hold back negligible and unknown CVEs, which import as Info. - Risk-accept CVEs with no fix version, with an expiration date, so they return for review when a fix is likely to exist.
- Tag file imports with the cluster or environment when one export covers images from several, so Findings can be filtered later.