Skip to content

aws.ecr.describe_images

Example SQL Queries

SELECT * FROM
aws.ecr.describe_images
WHERE
"repository_name" = 'VALUE';

Description

Returns metadata about the images in a repository.

Beginning with Docker version 1.9, the Docker client compresses image layers before pushing them to a V2 Docker registry. The output of the docker images command shows the uncompressed image size, so it may return a larger image size than the image sizes returned by DescribeImages.

Table Definition

Column NameColumn Data Type
repository_name Required Input Column

The name of the repository to which this image belongs.

VARCHAR
filter Input Column

The filter key and value with which to filter your DescribeImages results.

STRUCT(
"tag_status" VARCHAR
)
Show child fields
filter.tag_status

The tag status with which to filter your DescribeImages results. You can filter results based on whether they are TAGGED or UNTAGGED.

image_ids Input Column

The list of image IDs for the requested repository.

STRUCT(
"image_digest" VARCHAR,
"image_tag" VARCHAR
)[]
Show child fields
image_ids[]
Show child fields
image_ids[].image_digest

The sha256 digest of the image manifest.

image_ids[].image_tag

The tag used for the image.

registry_id Input Column

The Amazon Web Services account ID associated with the registry to which this image belongs.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

artifact_media_type

The artifact media type of the image.

VARCHAR
image_digest

The sha256 digest of the image manifest.

VARCHAR
image_manifest_media_type

The media type of the image manifest.

VARCHAR
image_pushed_at

The date and time, expressed in standard JavaScript date format, at which the current image was pushed to the repository.

TIMESTAMP_S
image_scan_findings_summary

A summary of the last completed image scan.

STRUCT(
"image_scan_completed_at" TIMESTAMP_S,
"vulnerability_source_updated_at" TIMESTAMP_S,
"finding_severity_counts" MAP(VARCHAR, BIGINT)
)
Show child fields
image_scan_findings_summary.finding_severity_counts

The image vulnerability counts, sorted by severity.

image_scan_findings_summary.image_scan_completed_at

The time of the last completed image scan.

image_scan_findings_summary.vulnerability_source_updated_at

The time when the vulnerability data was last scanned.

image_scan_status

The current state of the scan.

STRUCT(
"status" VARCHAR,
"description" VARCHAR
)
Show child fields
image_scan_status.description

The description of the image scan status.

image_scan_status.status

The current state of an image scan.

image_size_in_bytes

The size, in bytes, of the image in the repository.

If the image is a manifest list, this will be the max size of all manifests in the list.

Beginning with Docker version 1.9, the Docker client compresses image layers before pushing them to a V2 Docker registry. The output of the docker images command shows the uncompressed image size, so it may return a larger image size than the image sizes returned by DescribeImages.

BIGINT
image_tags

The list of tags associated with this image.

VARCHAR[]
Show child fields
image_tags[]
last_recorded_pull_time

The date and time, expressed in standard JavaScript date format, when Amazon ECR recorded the last image pull.

Amazon ECR refreshes the last image pull timestamp at least once every 24 hours. For example, if you pull an image once a day then the lastRecordedPullTime timestamp will indicate the exact time that the image was last pulled. However, if you pull an image once an hour, because Amazon ECR refreshes the lastRecordedPullTime timestamp at least once every 24 hours, the result may not be the exact time that the image was last pulled.

TIMESTAMP_S