live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

AWS scanning adds native support for Red Hat Hardened Images

InspectorScan can gate hardened images during builds, while ECR Basic scanning continues vulnerability checks after they reach the registry.

Build-time versus registry-time scanning for hardened images.
AI-generated illustration
By The News Desk· Aug 25, 2026

AWS has added support for Red Hat Hardened Images to two native container-security paths: the InspectorScan API used in build pipelines and Basic scanning in Amazon Elastic Container Registry. The integration lets teams scan Red Hat’s minimized runtime images without moving vulnerability analysis outside their existing AWS workflow.

What changed

The InspectorScan API accepts a software bill of materials generated from container images, archives or compiled binaries and returns a vulnerability report with NVD and CVSS scoring. Development teams can call it during a CI/CD build and use the result as a gate before an image reaches a registry.

ECR Basic scanning covers the later stage. It can scan an image automatically when it is pushed to Amazon ECR or on demand, then surface findings in the ECR console and through Amazon EventBridge. Used together, the two services provide a pre-registry check and continued detection for stored images.

Red Hat says both paths now recognize its Hardened Images catalog. That catalog contains nearly 60 core images and more than 150 variants built with a reduced package set to limit attack surface and vulnerability noise.

Who is affected

The change is aimed at application and security teams already using ECR or AWS-native build automation. It removes the need for a separate scanning path solely because the base image comes from Red Hat’s hardened catalog.

The images come in three variants. The default runtime image omits a shell and package manager. A builder variant restores development tools for multi-stage builds, with the resulting binary copied into a cleaner runtime image. A FIPS variant uses validated cryptographic modules when it runs on a FIPS-enabled host cluster.

What teams should do

Teams using InspectorScan can add an image or SBOM scan before the registry push and set a policy for findings that should block promotion. Teams relying on ECR should verify whether automatic scan-on-push is enabled and route EventBridge findings into their existing remediation workflow.

The integration does not make an image vulnerability-free. It does make Red Hat’s minimized images visible to the same AWS controls used for other build and registry artifacts, reducing the operational exception that teams would otherwise have to maintain.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.