Hi
Situation:
yesterday i discovered i have an image inside my on-prem quay with a high vulnerability (what a pain to get an overview over all organizations and all repos with quay) and my cluster showed me all green! on investigating, i found out the container-security-operator was never able to talk with my quay:
"x509: certificate signed by unknown authority"
on fixing this i'm stuck with "Request returned non-200 response: 401 UNAUTHORIZED"
and still everything green.
this is misleading, as green means everything ok. which is a completely different answer than "i don't know"... which is what i have with a broken setup.
The expected behavior if the container-security-operator is not able to get informations should NOT be "all green"!