# Gitlab container scanning with Nexus Sonatype 3.66

**URL:** <https://community.sonatype.com/t/gitlab-container-scanning-with-nexus-sonatype-3-66/12444>\
**Category:** Sonatype Nexus Repository\
**Tags:** help\
**Created:** [April 18, 2024, 8:12pm UTC](https://community.sonatype.com/t/gitlab-container-scanning-with-nexus-sonatype-3-66/12444 "2024-04-18T20:12:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![venerayan](https://avatars.discourse-cdn.com/v4/letter/v/45deac/32.png) [@venerayan](https://community.sonatype.com/u/venerayan)\
**Post date:** [April 18, 2024, 8:12pm UTC](https://community.sonatype.com/t/gitlab-container-scanning-with-nexus-sonatype-3-66/12444/1 "2024-04-18T20:12:22Z")

</div>

Hi All,

I’m using this template in gitlab,

```auto
include:
  - template: Jobs/Container-Scanning.gitlab-ci.yml

```

to scan for image vulnerabilities with nexus-sonatype 3.66, only works fine if anonymous is enabled.

I will have this error if anonymous is disabled in nexus-sonatype,

```auto
[ERROR] [2024-04-14 00:41:08 +0000] [container-scanning] > Scanner has not created a file with results (tmp.json)
[INFO] [2024-04-14 00:41:08 +0000] [container-scanning] > Scan failed. Use `SECURE_LOG_LEVEL=debug` to see more details.
[ERROR] [2024-04-14 00:41:08 +0000] [container-scanning] > 2024-04-14T00:41:08.455Z	INFO	Vulnerability scanning is enabled
2024-04-14T00:41:08.470Z	FATAL	image scan error: scan error: unable to initialize a scanner: unable to initialize an image scanner: 4 errors occurred:
	* docker error: unable to inspect the image (nexus-server:5000/ubi-carvel:3778): Cannot connect to the Docker daemon at unix:///var/run/docker.sock. Is the docker daemon running?
	* containerd error: containerd socket not found: /run/containerd/containerd.sock
	* podman error: unable to initialize Podman client: no podman socket found: stat podman/podman.sock: no such file or directory
	* remote error: GET https://nexus-server:5000/v2/token?scope=repository%3Aubi-carvel%3Apull&service=https%3A%2F%2Fnexus-server%3A5000%2Fv2%2Ftoken: UNAUTHORIZED: access to the requested resource is not authorized

```

Either I use openshift buildconfigs or use buildah to build the image and both have almost the same errors on the container\_scanning stage.

Please help!  
Thanks,  
Vener

---

<div class="post-metadata">

**Author:** ![mpiggott](https://avatars.discourse-cdn.com/v4/letter/m/f0a364/32.png) [@mpiggott](https://community.sonatype.com/u/mpiggott)\
**Post date:** [April 19, 2024, 1:29pm UTC](https://community.sonatype.com/t/gitlab-container-scanning-with-nexus-sonatype-3-66/12444/2 "2024-04-19T13:29:49Z")

</div>

Hi, this seems like a question for the Lifecycle part of the forums - [http://community.sonatype.com/c/sonatype-lifecycle-firewall/7](http://community.sonatype.com/c/sonatype-lifecycle-firewall/7)

This is for Nexus Repository Manager.

---

<div class="post-metadata">

**Author:** ![venerayan](https://avatars.discourse-cdn.com/v4/letter/v/45deac/32.png) [@venerayan](https://community.sonatype.com/u/venerayan)\
**Post date:** [April 22, 2024, 1:45pm UTC](https://community.sonatype.com/t/gitlab-container-scanning-with-nexus-sonatype-3-66/12444/3 "2024-04-22T13:45:26Z")

</div>

You need to add the credential of Nexus,

```auto
 CS_REGISTRY_USER : xxxxx
 CS_REGISTRY_PASSWORD: xxxxx

```

On buildah, there’s warning (probably it could be fixed, didn’t try) but using Openshift buildconfig, all fine.
