You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用AWS Inspector批量查询指定ECR镜像及标签的漏洞?

解决AWS Inspector批量查询指定镜像(名称+标签)的AND逻辑问题

核心问题分析

你当前的代码逻辑是把所有镜像仓库名放在ecrImageRepositoryName(内部为OR匹配)、所有标签放在ecrImageTags(内部为OR匹配),最终查询逻辑是 (仓库名1 OR 仓库名2 ...) AND (标签1 OR 标签2 ...),这会匹配到不符合预期的组合(比如仓库名A+标签B)。而你需要的是 (仓库名1 AND 标签1) OR (仓库名2 AND 标签2) ... 的精准配对逻辑,这需要用到AWS Inspector的FilterGroup特性。

解决思路

AWS Inspector的FilterCriteria支持多个FilterGroup:

  • 单个FilterGroup内的所有条件是AND逻辑(必须同时满足)
  • 多个FilterGroup之间是OR逻辑(满足任意一组即可)

我们可以为每一对「仓库名+标签」创建一个独立的FilterGroup,这样就能实现精准的配对查询,再对FilterGroup分批处理(AWS限制单请求最多10个FilterGroup)。

修改后的代码实现

1. 拆分镜像对并创建FilterGroup

首先将输入的镜像字符串(如images/hello-world-api:1.0.0)拆分为仓库名和标签,为每一对创建FilterGroup:

// 假设imageNames是逗号分隔的"仓库名:标签"字符串
String[] imagePairs = imageNames.split(",");
List<FilterGroup> filterGroups = new ArrayList<>();

for (String pair : imagePairs) {
    // 只拆分第一个冒号,避免标签含冒号的情况
    String[] repoTagPair = pair.trim().split(":", 2);
    if (repoTagPair.length != 2) {
        // 跳过格式无效的镜像条目
        continue;
    }
    String repoName = repoTagPair[0].trim();
    String tag = repoTagPair[1].trim();
    
    if (repoName.isBlank() || tag.isBlank()) {
        continue;
    }
    
    // 创建当前镜像的FilterGroup:仓库名AND标签
    FilterGroup group = FilterGroup.builder()
            .stringFilters(
                    StringFilter.builder()
                            .key(StringFilterKey.ECR_IMAGE_REPOSITORY_NAME)
                            .comparison(StringComparison.EQUALS)
                            .value(repoName)
                            .build(),
                    StringFilter.builder()
                            .key(StringFilterKey.ECR_IMAGE_TAGS)
                            .comparison(StringComparison.EQUALS)
                            .value(tag)
                            .build()
            )
            .build();
    filterGroups.add(group);
}

2. 分批查询FilterGroup

由于AWS限制单请求最多10个FilterGroup,需要分批处理并分页获取结果:

// 按10个FilterGroup为一批拆分
List<List<FilterGroup>> groupChunks = Lists.partition(filterGroups, 10);

for (List<FilterGroup> chunk : groupChunks) {
    boolean hasMore = true;
    String nextToken = null;
    
    ListFindingsRequest.Builder requestBuilder = ListFindingsRequest.builder()
            .filterCriteria(
                    FilterCriteria.builder()
                            .filterGroups(chunk)
                            .build()
            );
    
    while (hasMore) {
        ListFindingsRequest request = requestBuilder.build();
        ListFindingsResponse response = inspectorClient.listFindings(request);
        findings.addAll(response.findings());
        
        nextToken = response.nextToken();
        if (nextToken != null) {
            requestBuilder.nextToken(nextToken);
        } else {
            hasMore = false;
        }
    }
}

额外注意事项

  • 如果你的标签可能包含冒号,必须用split(":", 2)只拆分第一个冒号,避免标签被截断。
  • 加入格式校验,跳过空仓库名、空标签或无效格式的镜像条目,避免无效查询。
  • 若你是通过仓库名-标签的映射表(而非拼接字符串)获取数据,只需遍历映射表的entrySet,为每个entry创建FilterGroup即可。

内容的提问来源于stack exchange,提问作者Eugene Berman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 03:49:55