15.3. Alternative scanners
- Clair: Scanner V4 in RHACS offers functionality provided by Claircore, which also powers the Clair V4 scanner. You can configure RHACS to use Clair V4 instead of Scanner V4 by configuring an integration.
- Google Artifact Analysis
- Red Hat Quay
Scanner V4 is the preferred image vulnerability scanner to use with RHACS, because only Scanner V4 provides full functionality and features.
If you use one of these alternative scanners in your DevOps workflow, you can use the RHACS portal to configure an integration with your vulnerability scanner. After the integration, the RHACS portal shows the image vulnerabilities and you can triage them easily. However, Scanner V4 provides functionality and features that alternative scanners might not offer.
If multiple scanners are configured, RHACS tries to use the non-StackRox/RHACS and non-Clair scanners. If those scanners fail, RHACS tries to use a configured Clair scanner. If that fails, RHACS tries to use Scanner V4. If Scanner V4 is not enabled, RHACS tries to use the StackRox Scanner.