A method, system, device and medium for constructing a trusted repository based on mirror vulnerability assessment
Patent Information
- Application Number
- CN202610730998.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-26
- Publication Date
- 2026-09-04
AI Technical Summary
应用发布无镜像来源校验、可信标签核验的双技术强制校验,无法阻止非法镜像、篡改镜像、非授信镜像的发布请求
[0015]The present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of a method for constructing a trusted repository based on mirror vulnerability assessment.
Smart Images

Figure CN122693006A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of container image security management technology, specifically to a method, system, device, and medium for constructing a trusted repository based on image vulnerability assessment. Background Technology
[0002] With the widespread deployment of power grid edge clouds, the centralized cloud management and distributed edge architecture pose challenges to image security control. Container images are the carriers of containerized business applications, and their security is crucial to the stable operation of power grid edge cloud nodes. Current general image management solutions applied to power grid edge clouds have several shortcomings. They lack a dual-warehouse physical and logical isolation architecture for trusted and untrusted images, resulting in a lack of permission boundary control during image upload, storage, and distribution, allowing untrusted initial images to directly enter the distribution chain. Vulnerability scanning is decoupled from the image repository process, lacking automatic triggering, result binding, and permission locking mechanisms; scan status and submission are not forcibly correlated. Trust is granted based on subjective human judgment, lacking standardized technical criteria, process control, approval traces, status synchronization, and image tagging. Application releases lack mandatory dual-technical verification of image source and trusted label verification, failing to prevent the release requests of illegal, tampered, or untrusted images. Currently, there is no comprehensive technical closed-loop management mechanism for the power grid edge cloud, including dual-warehouse isolation, vulnerability scanning and authorization, dynamic trust determination, and mandatory verification at the publishing end. Security access support for the entire lifecycle of image uploading, detection, trust, synchronization, and distribution is insufficient. Summary of the Invention
[0003] In view of the aforementioned existing problems, the present invention provides a method, system, device and medium for constructing a trusted repository based on mirror vulnerability assessment.
[0004] Therefore, the technical problem solved by this invention is: how to combine different methods such as dual-warehouse isolation, vulnerability scanning, hard binding of submission permissions, dynamic trust, trusted tags, and publishing end verification to achieve closed-loop technical management and control over the entire lifecycle of the power grid edge cloud image, including image uploading, detection, trust, synchronization, and distribution, to block untrusted and tampered images from flowing into edge services.
[0005] To address the aforementioned technical problems, this invention provides the following technical solution: a method for constructing a trusted repository based on mirror vulnerability assessment, comprising, Establish a dual-warehouse isolation architecture and set different operation permissions; The image is uploaded to the dual-warehouse isolation architecture, a first check is performed, and the status of the image is updated; In response to the result of the image status update, the submission permission is unlocked and a submission work order is generated; The submitted work orders are approved, the approval process is recorded, and the approval status is marked. In response to the approval of the submitted work order, a first tag is generated for the image and transmitted to the dual-warehouse isolation architecture to complete the first tagging; In response to an edge deployment request, a dual verification is performed on the image, and the image is deployed based on the result of the dual verification.
[0006] As a preferred embodiment of the trusted repository construction method based on image vulnerability assessment described in this invention, the following steps are included: performing a first detection and updating the state of the image, including... The image is pushed to the repository through the platform's operation interface. The repository's built-in engine then performs the scan, generates a scan report, and updates the image's status based on different scanning strategy configurations.
[0007] As a preferred embodiment of the trusted repository construction method based on image vulnerability assessment described in this invention, in response to the result of the image status update, the submission permission is unlocked, and a submission work order is generated, including: The pre-submission qualification engine performs a mandatory judgment, allowing images that have completed scanning and have no security vulnerabilities to unlock submission permissions, initiate a submission application, and generate a submission work order.
[0008] As a preferred embodiment of the trusted repository construction method based on mirror vulnerability assessment described in this invention, the following steps are included: approving the submitted work orders, recording the approval process, and marking the approval status, including... The preset image security judgment criteria are used as the basis for judging image vulnerabilities. The submitted work orders are approved, the approval process is recorded, and the approval status is marked according to the approval result.
[0009] As a preferred embodiment of the trusted repository construction method based on image vulnerability assessment described in this invention, the method includes: generating a first tag for the image and transmitting it to the dual-repository isolation architecture to complete the first tagging, including: The first tag is generated for the approved image, and the image data is synchronized in a dual-warehouse isolation architecture through an encrypted transmission channel; Once synchronization is complete, verify the integrity of the image and the validity of the tags, and update the dual-warehouse image status; When synchronization fails, a retry mechanism is triggered, and alarms and exception logs are recorded based on the retry results.
[0010] As a preferred embodiment of the trusted repository construction method based on image vulnerability assessment described in this invention, the method includes: in response to an edge deployment request, performing dual verification on the image, and deploying the image based on the result of the dual verification, including: After receiving the deployment request from the edge node, the platform performs dual verification on the image; When the dual verification passes, the image can be distributed to edge nodes for deployment. When the double verification fails, the system rejects the deployment request, returns the reason for the interception, and pushes a security alert.
[0011] As a preferred embodiment of the trusted repository construction method based on mirror vulnerability assessment described in this invention, the establishment of a dual-repository isolation architecture and the setting of different operation permissions include, The cloud-based image repository uses technical means to establish a dual-warehouse isolation architecture to store initially uploaded, untested images and trusted images that have passed the verification process, and configures hierarchical operation permissions based on role-based access control technology.
[0012] This invention enables fully automated closed-loop management of the entire process from detection and authorization to approval by performing mirror vulnerability detection and updating the status, unlocking submission permissions and generating a submission work order in response to a no-vulnerability result, and then approving, recording the process and marking the status of the work order according to preset security standards.
[0013] This invention provides a trusted repository construction system based on mirror vulnerability assessment, comprising: The dual-warehouse isolation module creates untrusted and trusted warehouses, configures their respective operation permissions, and achieves logical isolation between storage and access. The detection and status update module provides an image upload interface, calls the built-in detection engine to perform vulnerability scanning on the image, and updates the image's scan status and vulnerability status. The submission access control module makes a mandatory judgment based on the scanning status and vulnerability status of the image. It unlocks the submission entry only when the image has been scanned and no vulnerabilities are found, and generates a standardized submission work order. The approval management module loads preset security judgment standards, approves submitted work orders, records approval operation logs, and marks the approval status of the image. The tagging and synchronization module generates the first tag for approved images, synchronizes the images and tags to the trusted repository through an encrypted channel, and performs integrity verification and exception retry. The deployment verification module performs source verification and trusted label verification on the image when it receives a deployment request on the edge container platform, and decides whether to allow distribution and deployment based on the verification results.
[0014] The present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of a trusted repository construction method based on mirror vulnerability assessment.
[0015] The present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of a method for constructing a trusted repository based on mirror vulnerability assessment.
[0016] Compared with existing technologies, the beneficial effects of this invention are as follows: By implementing dual-warehouse isolation, vulnerability scanning, hard binding of submission qualifications, dynamic trust assessment, trusted label generation and cross-warehouse encrypted synchronization, and dual verification at the publishing end, this invention solves the problems of lack of isolation in image management, separation of scanning and processes, lack of technical judgment standards for trust, and lack of verification in publishing in the power grid edge cloud scenario. Through dual-warehouse project isolation (non-trusted and trusted), storage partitioning, and RBAC hierarchical permissions, it blocks untrusted container images from entering the distribution chain at the source. A self-developed vulnerability scanning engine enables automatic and manual layered detection, with the absence of vulnerabilities as the sole unlocking condition for submission, replacing manual verification. Auditable trust approval is conducted through quantitative standards, generating globally unique trusted labels for images and encrypting and synchronizing them to the trusted warehouse. The edge publishing process verifies the image's source and label validity. This invention achieves closed-loop management of the entire image process, reducing false alarms while improving anomaly interception capabilities and security access reliability. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is an implementation diagram of a trusted repository construction method based on mirror vulnerability assessment, provided as an embodiment of the present invention.
[0019] Figure 2 This is an overall flowchart of a trusted repository construction method based on mirror vulnerability assessment, provided as an embodiment of the present invention.
[0020] Figure 3 This is a flowchart illustrating the image vulnerability scanning and pre-approval process for a trusted repository construction method based on image vulnerability assessment, provided as an embodiment of the present invention.
[0021] Figure 4 This is a flowchart illustrating the edge application deployment image dual verification and deployment control process of a trusted repository construction method based on image vulnerability assessment, provided as an embodiment of the present invention. Detailed Implementation
[0022] To make the above-mentioned objects, features, and advantages of the present invention more readily understood, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0023] Example 1, referring to Figure 1 This is the first embodiment of the present invention, providing a method for constructing a trusted repository based on mirror vulnerability assessment, comprising: S1: Establish a dual-warehouse isolation architecture and set different operation permissions.
[0024] S2: Upload the image to the dual-warehouse isolation architecture, perform the first check, and update the image status.
[0025] S3: In response to the result of the image status update, unlock the submission permission and generate a submission work order.
[0026] S4: Approve submitted work orders, record the approval process, and mark the approval status.
[0027] S5: In response to the approval of the submitted work order, generate the first tag for the image and transmit it to the dual-warehouse isolation architecture to complete the first tagging.
[0028] S6: In response to edge deployment requests, performs double verification on the image and deploys the image based on the result of the double verification.
[0029] It should be noted that the power grid edge cloud container platform features centralized cloud-based management and distributed edge deployment. The aforementioned image management method lacks control measures for four types of issues: dual-warehouse isolation, separation of scanning and submission, reliance on subjective human verification for trust, and manual verification during deployment. This means that the possibility of untrusted images flowing into edge operations still exists, disrupting the chain of stable system operation. Therefore, the management of untrusted container images is also a crucial aspect.
[0030] This embodiment also provides technical solutions for the problems of dual-warehouse isolation for non-trusted and trusted applications, separation of scanning results and submission for review, and subjective determination of trust by humans. Specifically, this embodiment adopts a standardized process for trust applications, generates a unique trusted label and encrypts cross-warehouse transmission, forming a closed-loop management and blocking illegal distribution and deployment throughout the entire lifecycle of image uploading, detection, trust, and distribution.
[0031] Example 2, refer to Figure 1 — Figure 4 This is one embodiment of the present invention. Based on the above embodiment, a method for constructing a trusted repository based on image vulnerability assessment is provided.
[0032] In this embodiment of the application, step S1 establishes a dual-warehouse isolation architecture and sets different operation permissions, specifically including the following steps A1-A2: A1: Establish a dual-warehouse isolation architecture.
[0033] It should be noted that, as Figure 2 As shown, the cloud mirror repository uses project isolation technology to create two repository projects: a non-trusted repository (edge-power-non-credit) and a trusted repository (edge-power-credit). Each project is allocated an independent storage partition, and the mirror data is physically isolated, forming a dual-warehouse isolation architecture.
[0034] A2: Configure hierarchical operation permissions.
[0035] It should be noted that the untrusted image repository has open permissions for image push, image upload, and image deletion interfaces, but closes permissions for image distribution and edge node pull. It is only used to store initially uploaded, untested images. The authorized image repository disables direct image push / upload interface permissions, and only opens cross-warehouse synchronous migration, image distribution, and edge node pull permissions. It only stores trusted images that have passed compliance assessment.
[0036] Furthermore, role-based access control (RBAC) technology is adopted to configure tiered permissions for repository administrators, image uploaders, approvers, and edge deployment users, prohibiting unauthorized operations. Image administrators can perform global repository management, developers are allowed to perform image uploads, security approvers are responsible for authorization and approval, and operations and maintenance personnel can perform edge deployments.
[0037] Based on step S1, this embodiment uses a triple isolation system of independent projects in untrusted and trusted warehouses, storage partitioning, and access control to prevent unscanned images from entering the production chain from the perspectives of storage structure, access restrictions, and distribution interfaces. Untrusted warehouses are not allowed to pull, only to upload. Trusted warehouses are not allowed to upload, only to allow compliant migration. Edge pulls are not allowed to upload directly, thus preventing risky images from being deployed directly to the power grid edge nodes without testing and improving the cloud warehouse's security access capabilities for edge businesses.
[0038] In this embodiment of the invention, step S2 involves uploading the image to a dual-warehouse isolation architecture, performing a first detection, and updating the image's status, specifically including the following steps B1-B2: B1: Perform the first test.
[0039] It should be noted that, as Figure 2 As shown, the image uploader pushes the business image to the untrusted image repository through the container platform's image operation interface. The system automatically records the image name, version number, upload time, upload account, and image hash value (SHA-256) metadata.
[0040] The untrusted image repository has a built-in self-developed vulnerability scanning engine that supports both automatic and manual triggering scanning strategies. Automatic triggering: After the image is uploaded, the repository server uses an event listening mechanism to call the scanning engine in real time to perform a full vulnerability scan; Manual trigger: Users initiate a scan command through the platform's interface, and the engine executes the detection after receiving the command.
[0041] B2: Generate a scan report and update the image status.
[0042] It should be noted that, through image layering and parsing technology, the system traverses the image file system, dependency packages, and configuration files, compares them with the national information security vulnerability database, identifies high-risk, medium-risk, and low-risk vulnerabilities, and generates a scan report containing the number of vulnerabilities, vulnerability level, vulnerability location, and remediation suggestions. After the scan is completed, the scan results are sent back to the untrusted repository management module to update the image scan status and vulnerability information.
[0043] Based on step S2, this embodiment uses a self-developed engine to achieve automatic / manual layered detection and transmits the scanning status back and binds it in real time, which solves the technical problems of vulnerability scanning being disconnected from the repository process and the inability to forcibly associate the results for review.
[0044] In this embodiment of the invention, step S3, in response to the result of the mirror status update, unlocks the submission permission and generates a submission work order, specifically including the following steps C1-C2: C1: Unlock submission permission.
[0045] It should be noted that, as Figure 3 As shown, the system establishes a pre-qualification verification engine for submissions, reads the image scan status and vulnerability status in real time, and performs mandatory technical judgments: Judgment condition 1: The mirror scan status is "scanned"; Judgment condition 2: The image vulnerability status is no security vulnerability.
[0046] When both judgment conditions are met simultaneously, the system unlocks the submission button, allowing the user to initiate a credit approval submission application; If either "unscanned" or "vulnerable" is detected, the system will gray out and lock the submission portal, refuse to accept submission applications, and return a technical alert.
[0047] C2: Generate a submission work order.
[0048] It should be noted that after the application is submitted, the system automatically associates the image metadata and scan report, generates a submission work order, and synchronizes it to the dynamic credit assessment module.
[0049] Based on step S3, this embodiment forcibly locks the submission entry point through the pre-verification engine, allowing only images without vulnerabilities to initiate applications, thus solving the technical problems of the disconnect between the scanning and approval processes and the submission of undetected images for review.
[0050] In this embodiment of the application, step S4 involves approving the submitted work order, recording the approval process, and marking the approval status. Specifically, this includes the following steps D1-D2: D1: Use the preset image security judgment criteria as the basis for judging image vulnerabilities.
[0051] It should be noted that the preset image security judgment criteria include: zeroing out image vulnerabilities, compliance of upload source, compliance of version with business specifications, and compliance of image format.
[0052] Furthermore, the mirror site has been cleared of vulnerabilities: there are no high-risk, medium-risk, or low-risk security vulnerabilities. Upload source compliance: The uploading account is an authorized account, and the mirror hash value has not been tampered with; Version complies with business specifications: Complies with the power grid edge business version management specifications; Image format compliance: Meets the runtime format requirements of the edge container platform.
[0053] D2: Approve the submitted work order, record the approval process, and mark the approval status.
[0054] It should be noted that the approver views all information of the submitted work order through the approval workbench and performs an approval / rejection operation based on the preset mirror security judgment criteria: Approval passed: The system marks the approval status as passed and records the approver's account, approval time, and approval comments; Approval rejection: The system marks the approval status as rejected, records the reason for rejection, and returns the image to a non-authorized repository.
[0055] Furthermore, the module employs process engine technology to achieve fully automated workflow synchronization of "submission for review - approval - status", with all operations written to the audit log.
[0056] Based on step S4, this embodiment embeds standardized judgment criteria such as vulnerability clearing and source compliance into the approval process to achieve automated flow and full-process auditing, solving the technical problems of credit approval relying on subjective judgment, lack of traceability and synchronization.
[0057] In this embodiment of the application, in step S5, in response to the approval of the submission work order, a first tag is generated for the image and transmitted to the dual-warehouse isolation architecture to complete the first tagging, specifically including the following steps E1-E2: E1: Generate the first tag for the approved image.
[0058] It should be noted that for approved images, the system calls the trusted tag generation engine to generate a globally unique trusted tag as the first tag. The first tag includes: image ID, image version, authorization time, approval number, and hash verification value. The tag is bound to the image and cannot be modified or deleted.
[0059] E2: Synchronize the mirrored data in a dual-warehouse isolation architecture.
[0060] It should be noted that by activating the cross-warehouse secure synchronization service, images, trusted tags, and associated metadata are synchronized from the untrusted image repository to the trusted image repository through an encrypted transmission channel.
[0061] Furthermore, after synchronization is complete, the system verifies the integrity of the image and the validity of the tag. If the verification is successful, it is marked as trusted and available, and the dual-warehouse image status is updated synchronously. If synchronization fails, a retry mechanism is triggered. If the retry fails after 3 attempts, an alarm is issued and an exception log is recorded.
[0062] Based on step S5, this embodiment achieves the migration of the image from an untrusted to a trusted repository by generating a globally unique trusted label and using an encrypted transmission method, which solves the problems of the image having a globally modifiable label that is easy to tamper with and the inability to verify the copying process.
[0063] In this embodiment of the application, step S6, in response to the edge deployment request, performs dual verification on the image, and deploys the image based on the result of the dual verification, specifically including the following steps F1-F2: F1: After receiving the edge node deployment request, the platform performs dual verification on the image.
[0064] It should be noted that, as Figure 4 As shown, the edge container platform application deployment module embeds a deployment verification interceptor, which performs dual technical verification upon receiving a deployment request from an edge node: First layer: Image source verification, only images from trusted image repositories are allowed to be selected, and images from non-trusted repositories are directly blocked; The second layer: trusted label verification, which verifies the validity, integrity, and expiration of the trusted labels bound to the image, and blocks images without labels or with invalid labels.
[0065] F2: Deploy the image based on the results of the dual verification.
[0066] It should be noted that when the dual verification passes, the image is allowed to be distributed to edge nodes for deployment. When the verification fails, the system rejects the deployment request, returns the reason for the interception, and pushes a security alert. After deployment is complete, the system records the deployment node, deployment time, and image information, forming a deployment audit log.
[0067] Based on step S6, this embodiment solves the problem of not being able to verify the legitimacy of the image identity and illegal images flowing into edge nodes by intercepting the source and verifying the source and trusted tags.
[0068] Example 3 is the third embodiment of the present invention, which differs from the previous two embodiments in that: This embodiment also provides a trusted repository construction system based on mirror vulnerability assessment, including: The dual-warehouse isolation module creates untrusted and trusted warehouses, configures their respective operation permissions, and achieves logical isolation between storage and access. The detection and status update module provides an image upload interface, calls the built-in detection engine to perform vulnerability scanning on the image, and updates the image's scan status and vulnerability status. The submission access control module makes a mandatory judgment based on the scanning status and vulnerability status of the image. It unlocks the submission entry only when the image has been scanned and no vulnerabilities are found, and generates a standardized submission work order. The approval management module loads preset security judgment standards, approves submitted work orders, records approval operation logs, and marks the approval status of the image. The tagging and synchronization module generates the first tag for approved images, synchronizes the images and tags to the trusted repository through an encrypted channel, and performs integrity verification and exception retry. The deployment verification module performs source verification and trusted label verification on the image when it receives a deployment request on the edge container platform, and decides whether to allow distribution and deployment based on the verification results.
[0069] This embodiment also provides an electronic device applicable to the construction of a trusted repository based on mirror vulnerability assessment, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the trusted repository construction method based on mirror vulnerability assessment proposed in the above embodiment.
[0070] This embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements a trusted repository construction method based on image vulnerability assessment as proposed in the above embodiments.
[0071] The storage medium proposed in this embodiment and the method for constructing a trusted repository based on mirror vulnerability assessment proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0072] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0073] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for constructing a trusted repository based on mirror vulnerability assessment, characterized in that: include, Establish a dual-warehouse isolation architecture and set different operation permissions; The image is uploaded to the dual-warehouse isolation architecture, a first check is performed, and the status of the image is updated; In response to the result of the image status update, the submission permission is unlocked and a submission work order is generated; The submitted work orders are approved, the approval process is recorded, and the approval status is marked. In response to the approval of the submitted work order, a first tag is generated for the image and transmitted to the dual-warehouse isolation architecture to complete the first tagging; In response to an edge deployment request, a dual verification is performed on the image, and the image is deployed based on the result of the dual verification.
2. The method for constructing a trusted repository based on mirror vulnerability assessment as described in claim 1, characterized in that: Perform the first detection and update the state of the image, including: The image is pushed to the repository through the platform's operation interface. The repository's built-in engine then performs the scan, generates a scan report, and updates the image's status based on different scanning strategy configurations.
3. The method for constructing a trusted repository based on mirror vulnerability assessment as described in claim 2, characterized in that: In response to the image status update, the submission permission is unlocked, and a submission work order is generated. include, The pre-submission qualification engine performs a mandatory judgment, allowing images that have completed scanning and have no security vulnerabilities to unlock submission permissions, initiate a submission application, and generate a submission work order.
4. The method for constructing a trusted repository based on mirror vulnerability assessment as described in claim 3, characterized in that: The submitted work orders are reviewed and approved, and the approval process is recorded, including marking the approval status. The preset image security judgment criteria are used as the basis for judging image vulnerabilities. The submitted work orders are approved, the approval process is recorded, and the approval status is marked according to the approval result.
5. The method for constructing a trusted repository based on mirror vulnerability assessment as described in claim 4, characterized in that: A first tag is generated for the image and transmitted to the dual-warehouse isolation architecture to complete the first tagging, including: The first tag is generated for the approved image, and the image data is synchronized in a dual-warehouse isolation architecture through an encrypted transmission channel; Once synchronization is complete, verify the integrity of the image and the validity of the tags, and update the dual-warehouse image status; When synchronization fails, a retry mechanism is triggered, and alarms and exception logs are recorded based on the retry results.
6. The method for constructing a trusted repository based on mirror vulnerability assessment as described in claim 5, characterized in that: In response to an edge deployment request, perform dual verification on the image, and deploy the image based on the result of the dual verification, including: After receiving the deployment request from the edge node, the platform performs dual verification on the image; When the dual verification passes, the image can be distributed to edge nodes for deployment. When the double verification fails, the system rejects the deployment request, returns the reason for the interception, and pushes a security alert.
7. The method for constructing a trusted repository based on mirror vulnerability assessment as described in claim 6, characterized in that: The establishment of a dual-warehouse isolation architecture and the setting of different operation permissions include... The cloud-based image repository uses technical means to establish a dual-warehouse isolation architecture to store initially uploaded, untested images and trusted images that have passed the verification process, and configures hierarchical operation permissions based on role-based access control technology.
8. A trusted repository construction system based on mirror vulnerability assessment, employing the trusted repository construction method based on mirror vulnerability assessment as described in any one of claims 1 to 7, characterized in that, include: The dual-warehouse isolation module creates untrusted and trusted warehouses, configures their respective operation permissions, and achieves logical isolation between storage and access. The detection and status update module provides an image upload interface, calls the built-in detection engine to perform vulnerability scanning on the image, and updates the image's scan status and vulnerability status. The submission access control module makes a mandatory judgment based on the scanning status and vulnerability status of the image. It unlocks the submission entry only when the image has been scanned and no vulnerabilities are found, and generates a standardized submission work order. The approval management module loads preset security judgment standards, approves submitted work orders, records approval operation logs, and marks the approval status of the image. The tagging and synchronization module generates the first tag for approved images, synchronizes the images and tags to the trusted repository through an encrypted channel, and performs integrity verification and exception retry. The deployment verification module performs source verification and trusted label verification on the image when it receives a deployment request on the edge container platform, and decides whether to allow distribution and deployment based on the verification results.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the trusted repository construction method based on mirror vulnerability assessment as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the trusted repository construction method based on image vulnerability assessment as described in any one of claims 1 to 7.