> For the complete documentation index, see [llms.txt](https://docs.nullify.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullify.ai/configuration/configuration-containers.md).

# Container Configuration

## Overview

Container hardening findings are produced by Software Composition Analysis (SCA) and configured from the Nullify dashboard — there is no checked-in config file. Query findings with `GET /sca/containers/findings`; fetch a single finding with `GET /sca/containers/findings/{findingId}`, and update one with `PATCH /sca/containers/findings/{findingId}`.

## SBOM

Retrieve the software bill of materials for a repository's container images:

```
GET /sca/repositories/{repositoryId}/sbom
```

## Ignore findings

Suppress a container finding by allowlisting it per-finding from the dashboard or via the API:

```
POST /sca/containers/findings/{findingId}/allowlist
```

Request body:

```json
{
  "allowlistReason": "Base image patched in next release",
  "allowlistType": "UserAssumeRisk"
}
```

`allowlistType` is one of `AI`, `UserFixed`, `UserAssumeRisk`, `UserFalsePositive`, or `UserOther`. Dependency findings are configured separately — see [Configuration – Dependencies](/configuration/configuration-dependencies.md).
